{"resultsPerPage":127,"startIndex":0,"totalResults":127,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-05T10:45:47.017","vulnerabilities":[{"cve":{"id":"CVE-2023-23376","sourceIdentifier":"secure@microsoft.com","published":"2023-02-14T20:15:16.907","lastModified":"2026-08-05T05:16:35.650","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Windows Common Log File System Driver Elevation of Privilege Vulnerability"}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 10 Version 1809","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.4010","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 1809","platforms":["ARM64-based Systems"],"versions":[{"version":"10.0.0","lessThan":"10.0.17763.4010","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2019","platforms":["x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.4010","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2019 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.4010","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2022","platforms":["x64-based Systems"],"versions":[{"version":"10.0.20348.0","lessThan":"10.0.20348.1547","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 20H2","platforms":["32-bit Systems","ARM64-based Systems"],"versions":[{"version":"10.0.0","lessThan":"10.0.19042.2604","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 21H2","platforms":["x64-based Systems","ARM64-based Systems"],"versions":[{"version":"10.0.0","lessThan":"10.0.22621.1574","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 21H2","platforms":["32-bit Systems","ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.19043.0","lessThan":"10.0.19044.2604","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 22H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.22621.0","lessThan":"10.0.22621.1265","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 22H2","platforms":["x64-based Systems","ARM64-based Systems","32-bit Systems"],"versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.2604","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 1507","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.10240.0","lessThan":"10.0.10240.19747","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 1607","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.5717","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2016","platforms":["x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.5717","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2016 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.5717","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2","platforms":["32-bit Systems"],"versions":[{"version":"6.0.6003.0","lessThan":"6.0.6003.21915","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2 (Server Core installation)","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"6.0.6003.0","lessThan":"6.0.6003.21915","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008  Service Pack 2","platforms":["x64-based Systems"],"versions":[{"version":"6.0.6003.0","lessThan":"6.0.6003.21915","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1","platforms":["x64-based Systems"],"versions":[{"version":"6.1.7601.0","lessThan":"6.1.7601.26366","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.1.7601.0","lessThan":"6.1.7601.26366","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012","platforms":["x64-based Systems"],"versions":[{"version":"6.2.9200.0","lessThan":"6.2.9200.24116","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.2.9200.0","lessThan":"6.2.9200.24116","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 R2","platforms":["x64-based Systems"],"versions":[{"version":"6.3.9600.0","lessThan":"6.3.9600.20821","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 R2 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.3.9600.0","lessThan":"6.3.9600.20821","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-02-09T00:00:00+00:00","id":"CVE-2023-23376","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-02-14","cisaActionDue":"2023-03-07","cisaRequiredAction":"Apply updates per vendor instructions.","cisaVulnerabilityName":"Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability","weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.10240.19747","matchCriteriaId":"A4172403-C3DE-4F91-8E9D-37785290064B"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.14393.5717","matchCriteriaId":"092A553E-DA52-4E5A-A166-9C864BE93D12"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.17763.4010","matchCriteriaId":"3722D98C-C6B5-4ABF-8CDF-0BDC53B77067"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.19042.2604","matchCriteriaId":"0D1FA28A-5C8A-4D01-9F32-5B60D3FCB460"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.19044.2604","matchCriteriaId":"D50EAB5C-9A36-411D-8197-CE19808CB4C2"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.19045.2604","matchCriteriaId":"82A1E621-0421-4B4F-831E-620A7EB1F364"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.22000.1574","matchCriteriaId":"9AB5B24D-432F-43AC-8659-3517FEEF96DF"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.22621.1265","matchCriteriaId":"A070FDF1-7167-4320-9CC7-4B21EC9E3F7F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*","matchCriteriaId":"5F422A8C-2C4E-42C8-B420-E0728037E15C"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*","matchCriteriaId":"AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.14393.5717","matchCriteriaId":"87DDADC1-AC56-4E32-A2A5-8CF10ECD6C49"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.17763.4010","matchCriteriaId":"707CAC89-AB43-499A-A20A-FFFE51CA45DD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.20348.1540","matchCriteriaId":"81B940DB-34F5-4D52-AE8C-2830E4514840"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23376","source":"secure@microsoft.com","tags":["Patch","Vendor Advisory"]},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23376","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23376","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-28461","sourceIdentifier":"cve@mitre.org","published":"2023-03-15T23:15:10.070","lastModified":"2026-08-05T05:16:37.477","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated \"a new Array AG release with the fix will be available soon.\""}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"arraynetworks","product":"arrayos_ag","defaultStatus":"unknown","cpes":["cpe:2.3:o:arraynetworks:arrayos_ag:-:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThanOrEqual":"9.4.0.481","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-25T00:00:00+00:00","id":"CVE-2023-28461","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2024-11-25","cisaActionDue":"2024-12-16","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:*","versionEndIncluding":"9.4.0.481","matchCriteriaId":"D704D079-D1AF-40EA-98E7-BE1E01371B11"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1000:-:*:*:*:*:*:*:*","matchCriteriaId":"EBE11A77-8C2F-46CA-87BA-47624380FFC1"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1000t:-:*:*:*:*:*:*:*","matchCriteriaId":"5ED51E1F-3155-40C6-B61C-73D6A9F64987"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1000v5:-:*:*:*:*:*:*:*","matchCriteriaId":"F0BC33CF-FA0B-4556-B11E-61FF9B14880A"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1100v5:-:*:*:*:*:*:*:*","matchCriteriaId":"A9C8C9AE-AF59-4E5A-93CD-A394F1A31FA0"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1150:-:*:*:*:*:*:*:*","matchCriteriaId":"5E025A9D-6B7C-42B6-95EA-0A5726A919F4"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1200:-:*:*:*:*:*:*:*","matchCriteriaId":"0771D54C-15DF-403C-8CFA-B1E7D0136F50"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1200v5:-:*:*:*:*:*:*:*","matchCriteriaId":"7C9F6B87-E3D2-419A-B086-B981EF912F80"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1500:-:*:*:*:*:*:*:*","matchCriteriaId":"D385DBD0-C4A9-4168-82C2-832E0E40F42D"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1500fips:-:*:*:*:*:*:*:*","matchCriteriaId":"01569AB3-736D-47FE-86DD-F08ACDDCD11E"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1500v5:-:*:*:*:*:*:*:*","matchCriteriaId":"22E45185-071F-414A-AF78-4739F15A1D93"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1600:-:*:*:*:*:*:*:*","matchCriteriaId":"C6F0988E-5E75-486A-9229-956D38A51C35"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:ag1600v5:-:*:*:*:*:*:*:*","matchCriteriaId":"1D09E2CC-C1B5-40DC-AD1A-7C6AB20525DC"},{"vulnerable":false,"criteria":"cpe:2.3:h:arraynetworks:vxag:-:*:*:*:*:*:*:*","matchCriteriaId":"6E149796-E3D7-4FAF-AB64-8D273E701861"}]}]}],"references":[{"url":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf","source":"cve@mitre.org","tags":["Mitigation","Vendor Advisory"]},{"url":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28461","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-3519","sourceIdentifier":"secure@citrix.com","published":"2023-07-19T18:15:11.513","lastModified":"2026-08-05T05:16:39.130","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Unauthenticated remote code execution"}],"affected":[{"source":"secure@citrix.com","affectedData":[{"vendor":"Citrix","product":"NetScaler ADC","defaultStatus":"unaffected","versions":[{"version":"13.1","lessThan":"49.13","versionType":"patch","status":"affected"},{"version":"13.0","lessThan":"91.13","versionType":"patch","status":"affected"},{"version":"13.1-FIPS","lessThan":"37.159","versionType":"patch","status":"affected"},{"version":"12.1-FIPS","lessThan":"55.297","versionType":"patch","status":"affected"},{"version":"12.1-NDcPP","lessThan":"55.297","versionType":"patch","status":"affected"}]},{"vendor":"Citrix","product":"NetScaler Gateway","defaultStatus":"unaffected","versions":[{"version":"13.1","lessThan":"49.13","versionType":"patch","status":"affected"},{"version":"13.0","lessThan":"91.13","versionType":"patch","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@citrix.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-07-19T00:00:00+00:00","id":"CVE-2023-3519","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-07-19","cisaActionDue":"2023-08-09","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability","weaknesses":[{"source":"secure@citrix.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*","versionStartIncluding":"12.1","versionEndExcluding":"12.1-55.297","matchCriteriaId":"8927B2FA-F87E-4D81-AC29-9032184ECB7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*","versionStartIncluding":"12.1","versionEndExcluding":"12.1-55.297","matchCriteriaId":"9845E7B1-5604-497D-8241-048E91987C13"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*","versionStartIncluding":"13.0","versionEndExcluding":"13.0-91.13","matchCriteriaId":"AD949674-8DC1-4B0D-8C0C-F593539E12F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*","versionStartIncluding":"13.1","versionEndExcluding":"13.1-37.159","matchCriteriaId":"BD0739E3-F7A4-463C-96B0-9D7BDBF218C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*","versionStartIncluding":"13.1","versionEndExcluding":"13.1-49.13","matchCriteriaId":"FCEED8AC-F9A9-4F75-BB32-F53967A8E9A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0","versionEndExcluding":"13.0-91.13","matchCriteriaId":"BC825A83-8D84-42C7-868F-0470FF79D497"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1","versionEndExcluding":"13.1-49.13","matchCriteriaId":"442F6925-199D-4E5B-84C1-05C4D8108B62"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/173997/Citrix-ADC-NetScaler-Remote-Code-Execution.html","source":"secure@citrix.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467","source":"secure@citrix.com","tags":["Vendor Advisory"]},{"url":"http://packetstormsecurity.com/files/173997/Citrix-ADC-NetScaler-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-3519","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-35078","sourceIdentifier":"support@hackerone.com","published":"2023-07-25T07:15:10.897","lastModified":"2026-08-05T05:16:38.037","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication."},{"lang":"es","value":"Una vulnerabilidad de omisión de autenticación en Ivanti EPMM permite a usuarios no autorizados acceder a funciones o recursos restringidos de la aplicación sin la autenticación adecuada."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"Ivanti","product":"Endpoint Manager Mobile","defaultStatus":"affected","versions":[{"version":"11.10","lessThanOrEqual":"11.10","versionType":"semver","status":"unaffected"},{"version":"11.9","lessThanOrEqual":"11.9","versionType":"semver","status":"unaffected"},{"version":"11.8","lessThanOrEqual":"11.8","versionType":"semver","status":"unaffected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"ivanti","product":"endpoint_manager_mobile","defaultStatus":"unknown","cpes":["cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*"],"versions":[{"version":"11.10.0.1","lessThan":"11.10.0.2","versionType":"semver","status":"affected"},{"version":"11.9.1.0","lessThan":"11.9.1.1","versionType":"semver","status":"affected"},{"version":"11.8.1.0","lessThan":"11.8.1.1","versionType":"semver","status":"affected"},{"version":"0","lessThanOrEqual":"11.8.1.0","versionType":"semver","status":"affected"}]},{"vendor":"ivanti","product":"endpoint_manager_mobile","defaultStatus":"unknown","cpes":["cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*"],"versions":[{"version":"11.10.0.1","lessThan":"11.10.0.2","versionType":"semver","status":"affected"},{"version":"11.9.1.0","lessThan":"11.9.1.1","versionType":"semver","status":"affected"},{"version":"11.8.1.0","lessThan":"11.8.1.1","versionType":"semver","status":"affected"},{"version":"0","lessThanOrEqual":"11.8.1.0","versionType":"semver","status":"affected"}]},{"vendor":"ivanti","product":"endpoint_manager_mobile","defaultStatus":"unknown","cpes":["cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*"],"versions":[{"version":"11.10.0.1","lessThan":"11.10.0.2","versionType":"semver","status":"affected"},{"version":"11.9.1.0","lessThan":"11.9.1.1","versionType":"semver","status":"affected"},{"version":"11.8.1.0","lessThan":"11.8.1.1","versionType":"semver","status":"affected"},{"version":"0","lessThanOrEqual":"11.8.1.0","versionType":"semver","status":"affected"}]},{"vendor":"ivanti","product":"endpoint_manager_mobile","defaultStatus":"unknown","cpes":["cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*"],"versions":[{"version":"11.10.0.1","lessThan":"11.10.0.2","versionType":"semver","status":"affected"},{"version":"11.9.1.0","lessThan":"11.9.1.1","versionType":"semver","status":"affected"},{"version":"11.8.1.0","lessThan":"11.8.1.1","versionType":"semver","status":"affected"},{"version":"0","lessThanOrEqual":"11.8.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV30":[{"source":"support@hackerone.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-07-28T00:00:00+00:00","id":"CVE-2023-35078","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-07-25","cisaActionDue":"2023-08-15","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*","versionEndExcluding":"11.8.1.1","matchCriteriaId":"7C48786C-399D-4B0C-8082-64112C4DA5C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*","versionStartIncluding":"11.9.0","versionEndExcluding":"11.9.1.1","matchCriteriaId":"50C1A12C-5862-48B6-ADA3-4222516DA152"},{"vulnerable":true,"criteria":"cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*","versionStartIncluding":"11.10","versionEndExcluding":"11.10.0.2","matchCriteriaId":"76DAE9E0-15F0-40AB-8D03-E64423AD0E07"}]}]}],"references":[{"url":"https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-CVE-2023-35078","source":"support@hackerone.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.cisa.gov/news-events/alerts/2023/07/24/ivanti-releases-security-updates-endpoint-manager-mobile-epmm-cve-2023-35078","source":"support@hackerone.com","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://www.ivanti.com/blog/cve-2023-35078-new-ivanti-epmm-vulnerability","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-CVE-2023-35078","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.cisa.gov/news-events/alerts/2023/07/24/ivanti-releases-security-updates-endpoint-manager-mobile-epmm-cve-2023-35078","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://www.ivanti.com/blog/cve-2023-35078-new-ivanti-epmm-vulnerability","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35078","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-38831","sourceIdentifier":"cve@mitre.org","published":"2023-08-23T17:15:43.863","lastModified":"2026-08-05T05:16:38.580","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023."},{"lang":"es","value":"RARLAB WinRAR anterior a la versión 6.23 permite a los atacantes ejecutar código arbitrario cuando un usuario intenta ver un archivo benigno dentro de un archivo ZIP. El problema se produce porque un archivo ZIP puede incluir un archivo benigno (como un archivo .JPG normal) y también una carpeta que tiene el mismo nombre que el archivo benigno, y el contenido de la carpeta (que puede incluir contenido ejecutable) se procesa durante un intento de acceder únicamente al archivo benigno. Esto se explotó de forma activa entre abril y octubre de 2023."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"rarlab","product":"winrar","defaultStatus":"unknown","cpes":["cpe:2.3:a:rarlab:winrar:-:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"6.23","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-08-23T00:00:00+00:00","id":"CVE-2023-38831","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-08-24","cisaActionDue":"2023-09-14","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"RARLAB WinRAR Code Execution Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-345"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-351"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*","versionEndExcluding":"6.23","matchCriteriaId":"A586AE4C-6F08-4E96-B74C-AA0A7BF4F2DD"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.html","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://news.ycombinator.com/item?id=37236100","source":"cve@mitre.org","tags":["Issue Tracking"]},{"url":"https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/","source":"cve@mitre.org","tags":["Exploit","Press/Media Coverage","Third Party Advisory"]},{"url":"https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/","source":"cve@mitre.org","tags":["Exploit","Press/Media Coverage","Third Party Advisory"]},{"url":"http://packetstormsecurity.com/files/174573/WinRAR-Remote-Code-Execution.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://news.ycombinator.com/item?id=37236100","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"]},{"url":"https://www.bleepingcomputer.com/news/security/winrar-zero-day-exploited-since-april-to-hack-trading-accounts/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Press/Media Coverage","Third Party Advisory"]},{"url":"https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Press/Media Coverage","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38831","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-41265","sourceIdentifier":"cve@mitre.org","published":"2023-08-29T23:15:09.170","lastModified":"2026-08-05T05:16:39.700","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13."},{"lang":"es","value":"Una vulnerabilidad de HTTP Request Tunneling detectada en Qlik Sense Enterprise para Windows, para las versiones Mayo 2023 Parche 3 y anteriores, Febrero 2023 Parche 7 y anteriores, Noviembre 2022 Parche 10 y anteriores, y Agosto 2022 Parche 12 y anteriores permite a un atacante remoto escalar privilegios tunelizando peticiones HTTP en la petición HTTP sin procesar. Esto le permite enviar peticiones que son ejecutadas por el servidor del backend que aloja la aplicación de repositorio. Esto se soluciona en la versión Agosto de 2023 IR, Mayo de 2023 Parche 4, Febrero de 2023 Parche 8, Noviembre de 2022 Parche 11, y Agosto de 2022 Parche 13."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"qlik","product":"qlik_sense","defaultStatus":"unknown","cpes":["cpe:2.3:a:qlik:qlik_sense:may_2023:-:*:*:enterprise:windows:*:*"],"versions":[{"version":"0","lessThanOrEqual":"may_2023","versionType":"custom","status":"affected"}]},{"vendor":"qlik","product":"qlik_sense","defaultStatus":"unknown","cpes":["cpe:2.3:a:qlik:qlik_sense:february_2023:patch_7:*:*:enterprise:windows:*:*"],"versions":[{"version":"0","lessThanOrEqual":"february_2023","versionType":"custom","status":"affected"}]},{"vendor":"qlik","product":"qlik_sense","defaultStatus":"unknown","cpes":["cpe:2.3:a:qlik:qlik_sense:august_2022:patch_12:*:*:enterprise:windows:*:*"],"versions":[{"version":"0","lessThanOrEqual":"august_2022","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-11-29T00:00:00+00:00","id":"CVE-2023-41265","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-12-07","cisaActionDue":"2023-12-28","cisaRequiredAction":"Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.","cisaVulnerabilityName":"Qlik Sense HTTP Tunneling Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-444"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-444"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:-:*:*:enterprise:windows:*:*","matchCriteriaId":"41AEA1CA-D344-48DB-92D8-05D0EDC8487D"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"FC12BB7A-366F-4EE2-AABF-19E83B5B9EC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_10:*:*:enterprise:windows:*:*","matchCriteriaId":"5F601CFC-70D0-450B-AE49-058E6B887E15"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_11:*:*:enterprise:windows:*:*","matchCriteriaId":"17E7F947-3322-46BB-9B89-689F1B792D89"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_12:*:*:enterprise:windows:*:*","matchCriteriaId":"37AF6E89-73F0-49E8-82F4-08084A5EBE2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"E4C7CBBB-C6A0-460E-95DC-C1855826C7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_3:*:*:enterprise:windows:*:*","matchCriteriaId":"BD491E32-270C-452B-AC1E-FB8F509B916E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_4:*:*:enterprise:windows:*:*","matchCriteriaId":"EDE2809B-4234-443E-9E6A-6B402D258617"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_5:*:*:enterprise:windows:*:*","matchCriteriaId":"155F0D6F-2E4A-40E7-9145-7D130334466B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_6:*:*:enterprise:windows:*:*","matchCriteriaId":"D733F495-E0EF-4F25-8532-2773415EFB8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_7:*:*:enterprise:windows:*:*","matchCriteriaId":"578092D7-0F52-45C1-B7E2-FC5AF86AB8ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_8:*:*:enterprise:windows:*:*","matchCriteriaId":"1B3164BA-0BDB-41F9-B51C-4FB0489A125A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_9:*:*:enterprise:windows:*:*","matchCriteriaId":"E0D31C35-50DC-4CDF-AFD4-311EAF5BBBD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:-:*:*:enterprise:windows:*:*","matchCriteriaId":"95BBBA68-269F-4385-9D14-A736F2CD707E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"E6E1046C-35F4-451A-BFF1-2FC6EB01B547"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"D9AB037B-EE88-47CD-B387-42651CBAAFF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_3:*:*:enterprise:windows:*:*","matchCriteriaId":"3D28B87A-B36A-428E-A93B-255CFD62036F"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_4:*:*:enterprise:windows:*:*","matchCriteriaId":"9AD961D6-A315-493C-926F-1441E51C1742"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_5:*:*:enterprise:windows:*:*","matchCriteriaId":"1EFEBD77-7968-4649-8E9B-DAB24DC36E64"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_6:*:*:enterprise:windows:*:*","matchCriteriaId":"E6D033E6-C022-4C6B-9EAC-95ABF6CA9BA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_7:*:*:enterprise:windows:*:*","matchCriteriaId":"761B402F-4E98-46A4-A8E3-87F167CF01D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:-:*:*:enterprise:windows:*:*","matchCriteriaId":"9E7034FB-5E64-47AD-B4A4-8428474C48C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"29158A06-3DE9-487B-9BC5-B4A690864F4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"272C2CFE-0D8E-46CE-92B6-2BA8658C951B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:patch3:*:*:enterprise:windows:*:*","matchCriteriaId":"039E4C03-89CA-4E77-8D79-39D22E85A299"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:-:*:*:enterprise:windows:*:*","matchCriteriaId":"72D56C24-9CEF-486B-8E46-6111D7B1676A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"338E52B2-AD7D-43F3-B707-E0E5976B269E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_10:*:*:enterprise:windows:*:*","matchCriteriaId":"D216C67A-F124-49F0-90EA-B0C8B663D760"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"FA68ADC7-9E20-4BD3-9235-6D76D4519512"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_3:*:*:enterprise:windows:*:*","matchCriteriaId":"B41A9B8C-FAD3-46F1-8973-DF1FA408064B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_4:*:*:enterprise:windows:*:*","matchCriteriaId":"EE23F5BD-579C-488D-965A-AE916C32976A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_5:*:*:enterprise:windows:*:*","matchCriteriaId":"E9C90120-93D1-43B0-B541-F07EB8FD44EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_6:*:*:enterprise:windows:*:*","matchCriteriaId":"450F236B-4673-403C-9E23-736C0ED92F6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_7:*:*:enterprise:windows:*:*","matchCriteriaId":"D5E431DE-26E2-4DA2-AD0B-1479D0C95B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_8:*:*:enterprise:windows:*:*","matchCriteriaId":"0D6F6570-970B-4E49-9D92-65FAFCC71360"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_9:*:*:enterprise:windows:*:*","matchCriteriaId":"38116465-3485-44D3-9097-F2C821D8278F"}]}]}],"references":[{"url":"https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41265","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2023-41266","sourceIdentifier":"cve@mitre.org","published":"2023-08-29T23:15:09.380","lastModified":"2026-08-05T05:16:40.290","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13."},{"lang":"es","value":"Una vulnerabilidad de limitación incorrecta de una ruta a un directorio restringido (path traversal) detectada en Qlik Sense Enterprise para Windows, para las versiones Mayo 2023 Parche 3 y anteriores, Febrero 2023 Parche 7 y anteriores, Noviembre 2022 Parche 10 y anteriores, y Agosto 2022 Parche 12 y anteriores, permite a un atacante remoto no autenticado generar una sesión anónima. Esto le permite transmitir peticiones HTTP a endpoints no autorizados. Esto se ha corregido en la IR de Agosto de 2023, el Parche 4 de Mayo de 2023, el Parche 8 de febrero de 2023, el Parche 11 de Noviembre de 2022 y el Parche 13 de Agosto de 2022."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"qlik","product":"qlik_sense","defaultStatus":"unknown","cpes":["cpe:2.3:a:qlik:qlik_sense:august_2022:patch_12:*:*:enterprise:windows:*:*"],"versions":[{"version":"0","lessThanOrEqual":"august_2022","versionType":"custom","status":"affected"}]},{"vendor":"qlik","product":"qlik_sense","defaultStatus":"unknown","cpes":["cpe:2.3:a:qlik:qlik_sense:may_2023:patch3:*:*:enterprise:windows:*:*"],"versions":[{"version":"0","lessThanOrEqual":"may_2023","versionType":"custom","status":"affected"}]},{"vendor":"qlik","product":"qlik_sense","defaultStatus":"unknown","cpes":["cpe:2.3:a:qlik:qlik_sense:february_2023:patch_7:*:*:enterprise:windows:*:*"],"versions":[{"version":"0","lessThanOrEqual":"february_2023","versionType":"custom","status":"affected"}]},{"vendor":"qlik","product":"qlik_sense","defaultStatus":"unknown","cpes":["cpe:2.3:a:qlik:qlik_sense:november_2022:patch_10:*:*:enterprise:windows:*:*"],"versions":[{"version":"0","lessThanOrEqual":"november_2022","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2023-11-29T00:00:00+00:00","id":"CVE-2023-41266","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2023-12-07","cisaActionDue":"2023-12-28","cisaRequiredAction":"Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.","cisaVulnerabilityName":"Qlik Sense Path Traversal Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:-:*:*:enterprise:windows:*:*","matchCriteriaId":"41AEA1CA-D344-48DB-92D8-05D0EDC8487D"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"FC12BB7A-366F-4EE2-AABF-19E83B5B9EC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_10:*:*:enterprise:windows:*:*","matchCriteriaId":"5F601CFC-70D0-450B-AE49-058E6B887E15"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_11:*:*:enterprise:windows:*:*","matchCriteriaId":"17E7F947-3322-46BB-9B89-689F1B792D89"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_12:*:*:enterprise:windows:*:*","matchCriteriaId":"37AF6E89-73F0-49E8-82F4-08084A5EBE2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"E4C7CBBB-C6A0-460E-95DC-C1855826C7F8"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_3:*:*:enterprise:windows:*:*","matchCriteriaId":"BD491E32-270C-452B-AC1E-FB8F509B916E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_4:*:*:enterprise:windows:*:*","matchCriteriaId":"EDE2809B-4234-443E-9E6A-6B402D258617"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_5:*:*:enterprise:windows:*:*","matchCriteriaId":"155F0D6F-2E4A-40E7-9145-7D130334466B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_6:*:*:enterprise:windows:*:*","matchCriteriaId":"D733F495-E0EF-4F25-8532-2773415EFB8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_7:*:*:enterprise:windows:*:*","matchCriteriaId":"578092D7-0F52-45C1-B7E2-FC5AF86AB8ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_8:*:*:enterprise:windows:*:*","matchCriteriaId":"1B3164BA-0BDB-41F9-B51C-4FB0489A125A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:august_2022:patch_9:*:*:enterprise:windows:*:*","matchCriteriaId":"E0D31C35-50DC-4CDF-AFD4-311EAF5BBBD0"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:-:*:*:enterprise:windows:*:*","matchCriteriaId":"95BBBA68-269F-4385-9D14-A736F2CD707E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"E6E1046C-35F4-451A-BFF1-2FC6EB01B547"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"D9AB037B-EE88-47CD-B387-42651CBAAFF9"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_3:*:*:enterprise:windows:*:*","matchCriteriaId":"3D28B87A-B36A-428E-A93B-255CFD62036F"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_4:*:*:enterprise:windows:*:*","matchCriteriaId":"9AD961D6-A315-493C-926F-1441E51C1742"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_5:*:*:enterprise:windows:*:*","matchCriteriaId":"1EFEBD77-7968-4649-8E9B-DAB24DC36E64"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_6:*:*:enterprise:windows:*:*","matchCriteriaId":"E6D033E6-C022-4C6B-9EAC-95ABF6CA9BA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:february_2023:patch_7:*:*:enterprise:windows:*:*","matchCriteriaId":"761B402F-4E98-46A4-A8E3-87F167CF01D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:-:*:*:enterprise:windows:*:*","matchCriteriaId":"9E7034FB-5E64-47AD-B4A4-8428474C48C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"29158A06-3DE9-487B-9BC5-B4A690864F4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"272C2CFE-0D8E-46CE-92B6-2BA8658C951B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:may_2023:patch3:*:*:enterprise:windows:*:*","matchCriteriaId":"039E4C03-89CA-4E77-8D79-39D22E85A299"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:-:*:*:enterprise:windows:*:*","matchCriteriaId":"72D56C24-9CEF-486B-8E46-6111D7B1676A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_1:*:*:enterprise:windows:*:*","matchCriteriaId":"338E52B2-AD7D-43F3-B707-E0E5976B269E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_10:*:*:enterprise:windows:*:*","matchCriteriaId":"D216C67A-F124-49F0-90EA-B0C8B663D760"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_2:*:*:enterprise:windows:*:*","matchCriteriaId":"FA68ADC7-9E20-4BD3-9235-6D76D4519512"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_3:*:*:enterprise:windows:*:*","matchCriteriaId":"B41A9B8C-FAD3-46F1-8973-DF1FA408064B"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_4:*:*:enterprise:windows:*:*","matchCriteriaId":"EE23F5BD-579C-488D-965A-AE916C32976A"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_5:*:*:enterprise:windows:*:*","matchCriteriaId":"E9C90120-93D1-43B0-B541-F07EB8FD44EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_6:*:*:enterprise:windows:*:*","matchCriteriaId":"450F236B-4673-403C-9E23-736C0ED92F6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_7:*:*:enterprise:windows:*:*","matchCriteriaId":"D5E431DE-26E2-4DA2-AD0B-1479D0C95B98"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_8:*:*:enterprise:windows:*:*","matchCriteriaId":"0D6F6570-970B-4E49-9D92-65FAFCC71360"},{"vulnerable":true,"criteria":"cpe:2.3:a:qlik:qlik_sense:november_2022:patch_9:*:*:enterprise:windows:*:*","matchCriteriaId":"38116465-3485-44D3-9097-F2C821D8278F"}]}]}],"references":[{"url":"https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41266","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2024-24919","sourceIdentifier":"cve@checkpoint.com","published":"2024-05-28T19:15:10.060","lastModified":"2026-08-05T05:16:41.323","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available."},{"lang":"es","value":"Potencialmente, permitir que un atacante lea cierta información en Check Point Security Gateways una vez conectado a Internet y habilitado con VPN de acceso remoto o software Blades de acceso móvil. Hay disponible una solución de seguridad que mitiga esta vulnerabilidad."}],"affected":[{"source":"cve@checkpoint.com","affectedData":[{"vendor":"checkpoint","product":"Check Point Quantum Gateway, Spark Gateway and CloudGuard Network","versions":[{"version":"Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40 and Check Point Spark versions R81.10, R80.20.","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"checkpoint","product":"quantum_security_gateway_firmware","defaultStatus":"affected","cpes":["cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"quantum_security_gateway_firmware","defaultStatus":"affected","cpes":["cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"quantum_security_gateway_firmware","defaultStatus":"affected","cpes":["cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"quantum_security_gateway_firmware","defaultStatus":"affected","cpes":["cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"cloudguard_network","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:cloudguard_network:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"cloudguard_network","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:cloudguard_network:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"cloudguard_network","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:cloudguard_network:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"cloudguard_network","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:cloudguard_network:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"quantum_spark_appliances","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:quantum_spark_appliances:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"quantum_spark_appliances","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:quantum_spark_appliances:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"quantum_spark_appliances","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:quantum_spark_appliances:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]},{"vendor":"checkpoint","product":"quantum_spark_appliances","defaultStatus":"unknown","cpes":["cpe:2.3:a:checkpoint:quantum_spark_appliances:r80.40:*:*:*:*:*:*:*"],"versions":[{"version":"r80.40","status":"affected"},{"version":"r81","status":"affected"},{"version":"r81.10","status":"affected"},{"version":"r81.20","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@checkpoint.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-30T00:00:00+00:00","id":"CVE-2024-24919","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2024-05-30","cisaActionDue":"2024-06-20","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Check Point Quantum Security Gateways Information Disclosure Vulnerability","weaknesses":[{"source":"cve@checkpoint.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_spark_firmware:r80.40:*:*:*:*:*:*:*","matchCriteriaId":"362E95B3-0727-4516-A80F-A48CC96D60FC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*","matchCriteriaId":"FC94897D-88D2-4F56-BEBC-04899FE17197"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_spark_firmware:r81:*:*:*:*:*:*:*","matchCriteriaId":"CA87CADC-39F9-45F9-9795-02C496691997"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*","matchCriteriaId":"FC94897D-88D2-4F56-BEBC-04899FE17197"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r80.40:*:*:*:*:*:*:*","matchCriteriaId":"A0002A29-8B42-445D-9EC4-58BC93194241"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*","matchCriteriaId":"9016DDF6-285C-4E64-88D0-29ECCEF048F8"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:checkpoint:cloudguard_network_security:r80.40:*:*:*:*:*:*:*","matchCriteriaId":"A382E0DC-2BBA-4EC9-A695-8062C3DC405D"},{"vulnerable":true,"criteria":"cpe:2.3:a:checkpoint:cloudguard_network_security:r81:*:*:*:*:*:*:*","matchCriteriaId":"BB6D99AA-2186-44F1-A1B0-C9F9EEDE8CF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:checkpoint:cloudguard_network_security:r81.10:*:*:*:*:*:*:*","matchCriteriaId":"4FCE5DC3-745A-4FC4-A2EF-AC4931E2A630"},{"vulnerable":true,"criteria":"cpe:2.3:a:checkpoint:cloudguard_network_security:r81.20:*:*:*:*:*:*:*","matchCriteriaId":"121E2863-57A8-41F1-B7E0-B41600959A5E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.20:*:*:*:*:*:*:*","matchCriteriaId":"26705EAD-B1B6-40DB-8C10-1070E92E86F3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*","matchCriteriaId":"9016DDF6-285C-4E64-88D0-29ECCEF048F8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81.10:*:*:*:*:*:*:*","matchCriteriaId":"AD9F864E-435C-4753-9831-EDBE4ABD7B31"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*","matchCriteriaId":"9016DDF6-285C-4E64-88D0-29ECCEF048F8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_security_gateway_firmware:r81:*:*:*:*:*:*:*","matchCriteriaId":"3B0EDB21-9305-4601-AB96-A77BD00F311D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*","matchCriteriaId":"9016DDF6-285C-4E64-88D0-29ECCEF048F8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_spark_firmware:r81.10:*:*:*:*:*:*:*","matchCriteriaId":"BD5A3388-8310-4FA4-AD07-771F2E983674"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*","matchCriteriaId":"FC94897D-88D2-4F56-BEBC-04899FE17197"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:checkpoint:quantum_spark_firmware:r80.20:*:*:*:*:*:*:*","matchCriteriaId":"0F325578-5CB0-486A-BD44-18E4BFB52441"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*","matchCriteriaId":"FC94897D-88D2-4F56-BEBC-04899FE17197"}]}]}],"references":[{"url":"https://support.checkpoint.com/results/sk/sk182336","source":"cve@checkpoint.com","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"https://support.checkpoint.com/results/sk/sk182336","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-24919","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]},{"url":"https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-51378","sourceIdentifier":"cve@mitre.org","published":"2024-10-29T23:15:04.083","lastModified":"2026-08-05T05:16:41.870","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected."},{"lang":"es","value":" getresetstatus en dns/views.py y ftp/views.py en CyberPanel (también conocido como Cyber Panel) anterior a 1c0c6cb permite a atacantes remotos omitir la autenticación y ejecutar comandos arbitrarios a través de /dns/getresetstatus o /ftp/getresetstatus omitiendo secMiddleware (que es solo para una solicitud POST) y utilizando metacaracteres de shell en la propiedad statusfile, como lo explotó PSAUX en octubre de 2024. Las versiones hasta 2.3.6 y 2.3.7 (sin parchear) se ven afectadas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"cyberpanel","product":"cyberpanel","defaultStatus":"unknown","cpes":["cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"2.3.9","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-05T00:00:00+00:00","id":"CVE-2024-51378","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2024-12-04","cisaActionDue":"2024-12-25","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"CyberPanel Incorrect Default Permissions Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*","versionEndExcluding":"2.3.8","matchCriteriaId":"4AF5FFC6-208E-4DD5-B298-56EFD7047F47"}]}]}],"references":[{"url":"https://cwe.mitre.org/data/definitions/420.html","source":"cve@mitre.org","tags":["Not Applicable"]},{"url":"https://cwe.mitre.org/data/definitions/78.html","source":"cve@mitre.org","tags":["Not Applicable"]},{"url":"https://cyberpanel.net/KnowledgeBase/home/change-logs/","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://cyberpanel.net/blog/detials-and-fix-of-recent-security-issue-and-patch-of-cyberpanel","source":"cve@mitre.org","tags":["Product"]},{"url":"https://github.com/usmannasir/cyberpanel/commit/1c0c6cbcf71abe573da0b5fddfb9603e7477f683","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://refr4g.github.io/posts/cyberpanel-command-injection-vulnerability/","source":"cve@mitre.org","tags":["Exploit"]},{"url":"https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/","source":"cve@mitre.org","tags":["Exploit","Press/Media Coverage"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-51378","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2024-11667","sourceIdentifier":"security@zyxel.com.tw","published":"2024-11-27T10:15:04.210","lastModified":"2026-08-05T05:16:40.797","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL."},{"lang":"es","value":"Una vulnerabilidad de directory traversal en la interfaz de administración web de las versiones de firmware de la serie Zyxel ATP V5.00 a V5.38, las versiones de firmware de la serie USG FLEX V5.00 a V5.38, las versiones de firmware de la serie USG FLEX 50(W) V5.10 a V5.38 y las versiones de firmware de la serie USG20(W)-VPN V5.10 a V5.38 podría permitir que un atacante descargue o cargue archivos a través de una URL manipulada específicamente."}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"ATP series firmware","defaultStatus":"unaffected","versions":[{"version":"versions V5.00 through V5.38","status":"affected"}]},{"vendor":"Zyxel","product":"USG FLEX series firmware","defaultStatus":"unaffected","versions":[{"version":"versions V5.00 through V5.38","status":"affected"}]},{"vendor":"Zyxel","product":"USG FLEX 50(W) series firmware","defaultStatus":"unaffected","versions":[{"version":"versions V5.10 through V5.38","status":"affected"}]},{"vendor":"Zyxel","product":"USG20(W)-VPN series firmware","defaultStatus":"unaffected","versions":[{"version":"versions V5.10 through V5.38","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"zyxel","product":"usg_flex_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:usg_flex_100h_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_100hp_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_200h_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_200hp_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_500h_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_500w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_50ax_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_50_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_60ax_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_700h_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:usg_flex_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"5.00","lessThanOrEqual":"5.38","versionType":"custom","status":"affected"}]},{"vendor":"zyxel","product":"atp_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:atp800_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:zyxel:atp_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"5.00","lessThanOrEqual":"5.38","versionType":"custom","status":"affected"}]},{"vendor":"zyxel","product":"usg20-vpn_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:usg20-vpn_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"5.10","lessThanOrEqual":"5.38","versionType":"custom","status":"affected"}]},{"vendor":"zyxel","product":"usg_flex_50w_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:usg_flex_50w_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"5.10","lessThan":"5.38","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-05T00:00:00+00:00","id":"CVE-2024-11667","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2024-12-03","cisaActionDue":"2024-12-24","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Zyxel Multiple Firewalls Path Traversal Vulnerability","weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*","versionStartIncluding":"5.00","versionEndIncluding":"5.38","matchCriteriaId":"18B592F1-F584-4573-AD75-398CE03F6627"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:atp:-:*:*:*:*:*:*:*","matchCriteriaId":"788B28B2-E2EE-4D98-8862-15B121009B6E"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*","matchCriteriaId":"7F7654A1-3806-41C7-82D4-46B0CD7EE53B"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*","matchCriteriaId":"47398FD0-6C5E-4625-9EFD-DE08C9AB7DB2"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*","matchCriteriaId":"D68A36FF-8CAF-401C-9F18-94F3A2405CF4"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*","matchCriteriaId":"2818E8AC-FFEE-4DF9-BF3F-C75166C0E851"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*","matchCriteriaId":"0B41F437-855B-4490-8011-DF59887BE6D5"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*","matchCriteriaId":"66B99746-0589-46E6-9CBD-F38619AD97DC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*","versionStartIncluding":"5.00","versionEndIncluding":"5.38","matchCriteriaId":"18B592F1-F584-4573-AD75-398CE03F6627"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex:-:*:*:*:*:*:*:*","matchCriteriaId":"E4EDCC3C-8EE5-43D3-8739-34987F025DF2"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:*","matchCriteriaId":"2B30A4C0-9928-46AD-9210-C25656FB43FB"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_100ax:-:*:*:*:*:*:*:*","matchCriteriaId":"03036815-04AE-4E39-8310-DA19A32CFA48"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:*","matchCriteriaId":"D74ABA7E-AA78-4A13-A64E-C44021591B42"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:*","matchCriteriaId":"F93B6A06-2951-46D2-A7E1-103D7318D612"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_50:-:*:*:*:*:*:*:*","matchCriteriaId":"646C1F07-B553-47B0-953B-DC7DE7FD0F8B"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:*","matchCriteriaId":"92C697A5-D1D3-4FF0-9C43-D27B18181958"},{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:*","matchCriteriaId":"9D1396E3-731B-4D05-A3F8-F3ABB80D5C29"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndIncluding":"5.38","matchCriteriaId":"CBEE7B76-74EB-4570-9A5B-071BA9E36DB9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_flex_50w:-:*:*:*:*:*:*:*","matchCriteriaId":"110A1CA4-0170-4834-8281-0A3E14FC5584"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10","versionEndIncluding":"5.38","matchCriteriaId":"CBEE7B76-74EB-4570-9A5B-071BA9E36DB9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:usg_20w-vpn:-:*:*:*:*:*:*:*","matchCriteriaId":"6BEA412F-3DA1-4E91-9C74-0666147DABCE"}]}]}],"references":[{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024","source":"security@zyxel.com.tw","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11667","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2024-55956","sourceIdentifier":"cve@mitre.org","published":"2024-12-13T21:15:13.767","lastModified":"2026-08-05T05:16:42.863","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory."},{"lang":"es","value":"En Cleo Harmony anterior a 5.8.0.24, VLTrader anterior a 5.8.0.24 y LexiCom anterior a 5.8.0.24, un usuario no autenticado puede importar y ejecutar comandos Bash o PowerShell arbitrarios en el sistema host aprovechando la configuración predeterminada del directorio Autorun."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-16T00:00:00+00:00","id":"CVE-2024-55956","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2024-12-17","cisaActionDue":"2025-01-07","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Cleo Multiple Products Unauthenticated File Upload Vulnerability","weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cleo:harmony:*:*:*:*:*:*:*:*","versionEndExcluding":"5.8.0.24","matchCriteriaId":"20C7BC5F-D07F-4B6C-A674-4F9DDE6179FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:cleo:lexicom:*:*:*:*:*:*:*:*","versionEndExcluding":"5.8.0.24","matchCriteriaId":"6C1727B4-B497-4F87-87B9-E4D0B63EECA1"},{"vulnerable":true,"criteria":"cpe:2.3:a:cleo:vltrader:*:*:*:*:*:*:*:*","versionEndExcluding":"5.8.0.24","matchCriteriaId":"1A6FB799-062D-4C25-91DA-4712774293BF"}]}]}],"references":[{"url":"https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Advisory-CVE-Pending","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55956","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2024-55591","sourceIdentifier":"psirt@fortinet.com","published":"2025-01-14T14:15:34.450","lastModified":"2026-08-05T05:16:42.380","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module."},{"lang":"es","value":"Una vulnerabilidad de omisión de autenticación mediante una ruta o canal alternativo [CWE-288] que afecta a FortiOS versión 7.0.0 a 7.0.16 y FortiProxy versión 7.0.0 a 7.0.19 y 7.2.0 a 7.2.12 permite que un atacante remoto obtenga privilegios de superadministrador mediante solicitudes manipuladas al módulo websocket Node.js."}],"affected":[{"source":"psirt@fortinet.com","affectedData":[{"vendor":"Fortinet","product":"FortiOS","defaultStatus":"unaffected","cpes":["cpe:2.3:o:fortinet:fortios:7.0.16:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.15:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.14:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.13:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.0.0","lessThanOrEqual":"7.0.16","versionType":"semver","status":"affected"}]},{"vendor":"Fortinet","product":"FortiProxy","defaultStatus":"unaffected","cpes":["cpe:2.3:a:fortinet:fortiproxy:7.2.12:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.11:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.10:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.9:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.8:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.7:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.19:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.18:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.17:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.16:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.15:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.14:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.13:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.12:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.11:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.10:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.2.0","lessThanOrEqual":"7.2.12","versionType":"semver","status":"affected"},{"version":"7.0.0","lessThanOrEqual":"7.0.19","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-22T00:00:00+00:00","id":"CVE-2024-55591","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2025-01-14","cisaActionDue":"2025-01-21","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability","weaknesses":[{"source":"psirt@fortinet.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0","versionEndExcluding":"7.0.20","matchCriteriaId":"1B14CD59-F557-48A0-8458-BECD3AD7DB3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2.0","versionEndExcluding":"7.2.13","matchCriteriaId":"EDC18768-0891-465E-9900-3DF5D22A5CB3"},{"vulnerable":true,"criteria":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0","versionEndExcluding":"7.0.17","matchCriteriaId":"BD357034-B2FD-4C2E-97FE-2C54D686D885"}]}]}],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-24-535","source":"psirt@fortinet.com","tags":["Mitigation","Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55591","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2025-24472","sourceIdentifier":"psirt@fortinet.com","published":"2025-02-11T17:15:34.867","lastModified":"2026-08-05T05:16:43.473","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests."},{"lang":"es","value":"Una vulnerabilidad de omisión de autenticación mediante una ruta o canal alternativo [CWE-288] que afecta a FortiOS 7.0.0 a 7.0.16 y FortiProxy 7.2.0 a 7.2.12, 7.0.0 a 7.0.19 puede permitir que un atacante remoto obtenga privilegios de superadministrador a través de solicitudes de proxy CSF manipuladas."}],"affected":[{"source":"psirt@fortinet.com","affectedData":[{"vendor":"Fortinet","product":"FortiOS","defaultStatus":"unaffected","cpes":["cpe:2.3:o:fortinet:fortios:7.0.16:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.15:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.14:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.13:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.12:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.11:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.10:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.9:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortios:7.0.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.0.0","lessThanOrEqual":"7.0.16","versionType":"semver","status":"affected"}]},{"vendor":"Fortinet","product":"FortiProxy","defaultStatus":"unaffected","cpes":["cpe:2.3:a:fortinet:fortiproxy:7.2.12:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.11:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.10:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.9:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.8:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.7:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.19:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.18:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.17:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.16:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.15:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.14:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.13:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.12:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.11:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.10:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortiproxy:7.0.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.2.0","lessThanOrEqual":"7.2.12","versionType":"semver","status":"affected"},{"version":"7.0.0","lessThanOrEqual":"7.0.19","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@fortinet.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-02-12T00:00:00+00:00","id":"CVE-2025-24472","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2025-03-18","cisaActionDue":"2025-04-08","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability","weaknesses":[{"source":"psirt@fortinet.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0","versionEndExcluding":"7.0.20","matchCriteriaId":"1B14CD59-F557-48A0-8458-BECD3AD7DB3A"},{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2.0","versionEndExcluding":"7.2.13","matchCriteriaId":"EDC18768-0891-465E-9900-3DF5D22A5CB3"},{"vulnerable":true,"criteria":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0.0","versionEndExcluding":"7.0.17","matchCriteriaId":"BD357034-B2FD-4C2E-97FE-2C54D686D885"}]}]}],"references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-24-535","source":"psirt@fortinet.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24472","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2025-26633","sourceIdentifier":"secure@microsoft.com","published":"2025-03-11T17:16:43.390","lastModified":"2026-08-05T05:16:43.977","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally."},{"lang":"es","value":"La neutralización incorrecta en Microsoft Management Console permite que un atacante no autorizado eluda una función de seguridad localmente."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 10 Version 1507","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.10240.0","lessThan":"10.0.10240.20947","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 1607","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.7876","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 1809","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.7009","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 21H2","platforms":["32-bit Systems","ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.19044.0","lessThan":"10.0.19044.5608","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 22H2","platforms":["32-bit Systems","ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.5608","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 22H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.22621.0","lessThan":"10.0.22621.5039","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 22H3","platforms":["ARM64-based Systems"],"versions":[{"version":"10.0.22631.0","lessThan":"10.0.22631.5039","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 23H2","platforms":["x64-based Systems"],"versions":[{"version":"10.0.22631.0","lessThan":"10.0.22631.5039","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 24H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.3476","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1","platforms":["x64-based Systems"],"versions":[{"version":"6.1.7601.0","lessThan":"6.1.7601.27618","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.1.7601.0","lessThan":"6.1.7601.27618","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"6.0.6003.0","lessThan":"6.0.6003.23168","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2 (Server Core installation)","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"6.0.6003.0","lessThan":"6.0.6003.23168","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012","platforms":["x64-based Systems"],"versions":[{"version":"6.2.9200.0","lessThan":"6.2.9200.25368","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.2.9200.0","lessThan":"6.2.9200.25368","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 R2","platforms":["x64-based Systems"],"versions":[{"version":"6.3.9600.0","lessThan":"6.3.9600.22470","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 R2 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.3.9600.0","lessThan":"6.3.9600.22470","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2016","platforms":["x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.7876","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2016 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.7876","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2019","platforms":["x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.7009","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2019 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.7009","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2022","platforms":["x64-based Systems"],"versions":[{"version":"10.0.20348.0","lessThan":"10.0.20348.3328","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2022, 23H2 Edition (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.25398.0","lessThan":"10.0.25398.1486","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.3476","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.3476","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-13T00:00:00+00:00","id":"CVE-2025-26633","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2025-03-11","cisaActionDue":"2025-04-01","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability","weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-707"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.10240.20947","matchCriteriaId":"6997DE6E-CBAD-4690-A68C-8F10E477DCC2"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.10240.20947","matchCriteriaId":"3CBCF6D9-5085-473C-82F5-98BC246A9C4C"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.14393.7876","matchCriteriaId":"0CF0E174-4692-4AA3-B72E-12E73A1BDBE5"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.14393.7876","matchCriteriaId":"340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.17763.7009","matchCriteriaId":"67C8DCD7-90C4-431F-BD03-FDFDE170E748"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.17763.7009","matchCriteriaId":"05169574-28AB-4E42-B3DE-710574BB1AD3"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19044.5608","matchCriteriaId":"714C0D5E-BE31-45AB-A729-FF55DE59F593"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19044.5608","matchCriteriaId":"0C8B2D45-7059-4FA0-A46C-64A171D287DA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19044.5608","matchCriteriaId":"5569800D-B907-47CC-86D2-EC0118157916"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19045.5608","matchCriteriaId":"A84E706C-3A65-4920-8F80-2A684D3CB110"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19045.5608","matchCriteriaId":"ED157557-37C1-4802-8746-B87120BA16FA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19045.5608","matchCriteriaId":"BE8F0EF2-EED3-4791-AE26-D24D97B673D6"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22621.5039","matchCriteriaId":"C8949B3E-5847-42F8-A15A-D7515F0EE305"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22621.5039","matchCriteriaId":"84D4F97D-3BA2-4B7A-B650-5772DE49CE97"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22631.5039","matchCriteriaId":"82807292-1736-4453-B805-3D471BF94A35"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22631.5039","matchCriteriaId":"E19130AD-ECD6-4FC4-B2C8-AB058BDEF928"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26100.3403","matchCriteriaId":"B7ADF37E-1DD3-4539-8922-1E059955FEF1"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.3403","matchCriteriaId":"E0A74D52-ABC0-4733-B892-F8688B6AEBA7"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*","matchCriteriaId":"2127D10C-B6F3-4C1D-B9AA-5D78513CC996"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*","matchCriteriaId":"AB425562-C0A0-452E-AABE-F70522F15E1A"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*","matchCriteriaId":"AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.14393.7876","matchCriteriaId":"C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.17763.7009","matchCriteriaId":"D271422D-A29F-4DBF-BF72-BCD90E393A5A"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.20348.3270","matchCriteriaId":"AAACC9C4-DDC5-4059-AFE3-A49DB2347A86"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.25398.1486","matchCriteriaId":"96046A7B-76A1-4DCF-AEA5-25344D37E492"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.3403","matchCriteriaId":"CE542697-31D8-4EC2-8135-F0468431FD19"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-detection-script","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-mitigation-script","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26633","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2025-5278","sourceIdentifier":"secalert@redhat.com","published":"2025-05-27T21:15:23.197","lastModified":"2026-08-05T06:16:34.940","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data."},{"lang":"es","value":"Se encontró una falla en GNU Coreutils. La función begfield() de la utilidad sort es vulnerable a una lectura insuficiente del búfer del montón. El programa puede acceder a memoria fuera del búfer asignado si un usuario ejecuta un comando manipulado con el formato de clave tradicional. Una entrada maliciosa podría provocar un fallo o la filtración de datos confidenciales."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://cgit.git.savannah.gnu.org/cgit/coreutils.git/","packageName":"coreutils","versions":[{"version":"7.2","lessThan":"9.8","versionType":"semver","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"coreutils","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:9.5-8.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"coreutils","cpes":["cpe:/o:redhat:enterprise_linux:9::baseos"],"versions":[{"version":"0:8.32-41.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Cost Management Metrics Operator 4","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"costmanagement/costmanagement-metrics-rhel9-operator","cpes":["cpe:/a:redhat:cost_management:4::el9"],"versions":[{"version":"1783539156","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Discovery 2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"discovery/discovery-ui-rhel9","cpes":["cpe:/a:redhat:discovery:2::el9"],"versions":[{"version":"1782756541","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Discovery 2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"discovery/discovery-server-rhel9","cpes":["cpe:/a:redhat:discovery:2::el9"],"versions":[{"version":"1784821670","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Insights proxy 1.5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"insights-proxy/insights-proxy-container-rhel9","cpes":["cpe:/a:redhat:insights_proxy:1.5::el9"],"versions":[{"version":"1782890503","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-gateway-opa-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1782501180","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-gateway-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1782501200","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-jaeger-query-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1782498923","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-operator-bundle","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1782510941","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-query-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1782501220","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1782501196","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-rhel9-operator","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1782501195","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-collector-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1785704636","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.10.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-rhel9-operator","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"],"versions":[{"version":"1785704547","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/cds-kubernetes-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1784794818","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/cds-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1784794778","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/haproxy-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1784795112","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/installer-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1784794289","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Update Infrastructure 5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhui5/rhua-rhel9","cpes":["cpe:/a:redhat:rhui:5::el9"],"versions":[{"version":"1784795076","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"coreutils","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"coreutils","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"coreutils","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcos","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-28T13:46:35.101788Z","id":"CVE-2025-5278","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:28911","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:33124","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:33313","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:33612","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:34102","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:39981","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:44481","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:46836","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50205","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-5278","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2368764","source":"secalert@redhat.com"},{"url":"https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","source":"secalert@redhat.com"},{"url":"https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507","source":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/27/2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/29/1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2025/05/29/2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security-tracker.debian.org/tracker/CVE-2025-5278","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-34486","sourceIdentifier":"security@apache.org","published":"2026-04-09T20:16:25.063","lastModified":"2026-08-05T05:17:00.297","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.\n\nThis issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.\n\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Tomcat","defaultStatus":"unaffected","versions":[{"version":"11.0.20","versionType":"semver","status":"affected"},{"version":"10.1.53","versionType":"semver","status":"affected"},{"version":"9.0.116","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"1:10.1.49-3.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat9","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"1:9.0.117-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"1:10.1.36-2.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat9","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"1:9.0.87-6.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7 Extended Lifecycle Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/o:redhat:rhel_els:7"],"versions":[{"version":"0:7.0.76-18.el7_9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"1:9.0.87-2.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:rhel_tus:8.8"],"versions":[{"version":"1:9.0.87-2.el8_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:rhel_e4s:8.8"],"versions":[{"version":"1:9.0.87-2.el8_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"1:9.0.117-2.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:rhel_e4s:9.2"],"versions":[{"version":"1:9.0.87-2.el9_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"1:9.0.87-2.el9_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"1:9.0.87-4.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Web Server 7.0.0","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:jboss_enterprise_web_server:7.0"]},{"vendor":"Red Hat","product":"Red Hat JBoss Web Server 7.0 on RHEL 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"jws7-tomcat","cpes":["cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10"],"versions":[{"version":"0:11.0.21-5.redhat_00004.1.el10jws","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Web Server 7.0 on RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"jws7-tomcat","cpes":["cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8"],"versions":[{"version":"0:11.0.21-5.redhat_00004.1.el8jws","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Web Server 7.0 on RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"jws7-tomcat","cpes":["cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9"],"versions":[{"version":"0:11.0.21-5.redhat_00004.1.el9jws","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat6","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"pki-deps:10.6/pki-servlet-engine","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"pki-servlet-engine","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat JBoss Web Server 5","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:jboss_enterprise_web_server:5"]},{"vendor":"Red Hat","product":"Red Hat JBoss Web Server 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tomcat","cpes":["cpe:/a:redhat:jboss_enterprise_web_server:6"]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-34486","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-08-04","cisaActionDue":"2026-08-07","cisaRequiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","cisaVulnerabilityName":"Apache Tomcat Missing Encryption of Sensitive Data Vulnerability","weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-311"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-807"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.116:*:*:*:*:*:*:*","matchCriteriaId":"CC160F23-A9D6-42DA-92E6-886B1B1F48A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.1.53:*:*:*:*:*:*:*","matchCriteriaId":"0E7A0CE9-EBDF-4305-9C06-E7D4521AF422"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.20:*:*:*:*:*:*:*","matchCriteriaId":"64BAAE4D-2355-43D8-83E5-01CA71D5DC0B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_web_server:7.0.0:*:*:*:*:*:*:*","matchCriteriaId":"F764C52A-4533-4C39-A5A2-A5E1FE20960C"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"F4CFF558-3C47-480D-A2F0-BABF26042943"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"7F6FB57C-2BC7-487C-96DD-132683AEB35D"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_els:7.0:*:*:*:*:*:*:*","matchCriteriaId":"0460F769-D90A-4446-AC00-24F66BDBF526"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_eus:10.0:*:*:*:*:*:*:*","matchCriteriaId":"34990D09-125F-48CA-B85E-9D9F0EB4BC07"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_tus:8.8:*:*:*:*:*:*:*","matchCriteriaId":"22D28543-C7C5-46B0-B909-20435AF7A501"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:8.8:*:*:*:*:*:*:*","matchCriteriaId":"01ED4F33-EBE7-4C04-8312-3DA580EFFB68"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.2:*:*:*:*:*:*:*","matchCriteriaId":"1FD9BF0E-7ACF-4A83-B754-6E3979ED903F"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.4:*:*:*:*:*:*:*","matchCriteriaId":"18B7F648-9A31-4EE5-A215-C860616A4AB7"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.6:*:*:*:*:*:*:*","matchCriteriaId":"554AA8CA-A930-4788-B052-497E09D48381"}]}]}],"references":[{"url":"https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly","source":"security@apache.org","tags":["Mailing List","Vendor Advisory"]},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-detection-script-rce-on-apache-tomcat","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-34486-mitigation-script-rce-on-apache-tomcat","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36788","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36789","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36790","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36876","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36877","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36878","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:36879","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:37136","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:37137","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:38505","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:39188","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:39189","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/security/cve/CVE-2026-34486","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457027","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34486.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Third Party Advisory"]},{"url":"https://socradar.io/blog/snowlight-government-chinese-campaign/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2026-9198","sourceIdentifier":"psirt@us.ibm.com","published":"2026-07-17T18:17:17.340","lastModified":"2026-08-05T05:17:15.823","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments"}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.10.0:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.10.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-17T00:00:00+00:00","id":"CVE-2026-9198","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-08-04","cisaActionDue":"2026-08-07","cisaRequiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","cisaVulnerabilityName":"IBM Langflow Code Injection Vulnerability","weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"1.10.1","matchCriteriaId":"A32785B1-3CF7-4BD0-B6F8-1AA77D4E565B"}]}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7278927","source":"psirt@us.ibm.com","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}},{"cve":{"id":"CVE-2026-39875","sourceIdentifier":"product-security@apple.com","published":"2026-07-27T21:16:51.533","lastModified":"2026-08-05T05:17:00.987","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges."}],"affected":[{"source":"product-security@apple.com","affectedData":[{"vendor":"Apple","product":"macOS","versions":[{"version":"0","lessThan":"14.8.8","versionType":"custom","status":"affected"},{"version":"0","lessThan":"15.7.8","versionType":"custom","status":"affected"},{"version":"0","lessThan":"26.6","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-27T00:00:00+00:00","id":"CVE-2026-39875","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0","versionEndExcluding":"14.8.8","matchCriteriaId":"9FFAC61B-E4F2-49AF-9897-96D35FAD611C"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionStartIncluding":"15.0","versionEndExcluding":"15.7.8","matchCriteriaId":"B3E01512-81BB-4C92-B0A5-C07F1C1A432E"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionStartIncluding":"26.0","versionEndExcluding":"26.6","matchCriteriaId":"8D3D83F1-07DF-47C2-9F3B-0BC5A1434606"}]}]}],"references":[{"url":"https://support.apple.com/en-us/128067","source":"product-security@apple.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://support.apple.com/en-us/128071","source":"product-security@apple.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://support.apple.com/en-us/128072","source":"product-security@apple.com","tags":["Release Notes","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-66402","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:16:57.487","lastModified":"2026-08-05T05:17:09.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. 'victim.example\\0.attacker.example' as 'victim.example'), (2) accepts a matching Common Name even when non-matching DNS SAN entries are present, and (3) accepts IP-literal targets via DNS/CN matching without comparing iPAddress SANs. Under a trusted or misissued certificate chain, an attacker positioned to present such a certificate can bypass server identity verification, weakening TLS server authentication."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"FreeRDP","product":"FreeRDP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.29.0","versionType":"semver","status":"affected"},{"version":"3.29.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-66402","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/commit/b9533f07f98c25ed01c5f543b4d0ce73e120f5fd","source":"disclosure@vulncheck.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-43hh-p3vw-hfx3","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-tls-certificate-identity-validation-bypass","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-67289","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:16:57.803","lastModified":"2026-08-05T05:17:09.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"FreeRDP","product":"FreeRDP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.29.0","versionType":"semver","status":"affected"},{"version":"3.29.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-67289","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-113"}]}],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f","source":"disclosure@vulncheck.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-http-proxy-request-injection-via-redirection","source":"disclosure@vulncheck.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-67293","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:16:58.380","lastModified":"2026-08-05T05:17:10.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"FreeRDP","product":"FreeRDP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.29.0","versionType":"semver","status":"affected"},{"version":"3.29.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-67293","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f","source":"disclosure@vulncheck.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5wr6-8m8j-3h7f","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-improper-certificate-hostname-validation","source":"disclosure@vulncheck.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5wr6-8m8j-3h7f","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-67305","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:17:00.113","lastModified":"2026-08-05T05:17:10.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"FreeRDP","product":"FreeRDP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.29.0","versionType":"semver","status":"affected"},{"version":"3.29.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-67305","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cj9v-h4hq-29jr","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/freerdp-windows-client-before-heap-buffer-overflow-via-cliprdr","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-67323","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:17:02.637","lastModified":"2026-08-05T05:17:11.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"gitpython-developers","product":"GitPython","defaultStatus":"unaffected","packageURL":"pkg:pypi/GitPython","versions":[{"version":"0","lessThan":"3.1.51","versionType":"semver","status":"affected"},{"version":"3.1.51","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-67323","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options","source":"disclosure@vulncheck.com"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-67324","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:17:02.770","lastModified":"2026-08-05T05:17:11.467","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"gitpython-developers","product":"GitPython","defaultStatus":"unaffected","packageURL":"pkg:pypi/GitPython","versions":[{"version":"3.1.50","lessThan":"3.1.51","versionType":"semver","status":"affected"},{"version":"3.1.51","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-67324","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v396-v7q4-x2qj","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gitpython-authentication-bypass-via-joined-short-options","source":"disclosure@vulncheck.com"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v396-v7q4-x2qj","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-67325","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:17:02.923","lastModified":"2026-08-05T05:17:11.977","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"gitpython-developers","product":"GitPython","defaultStatus":"unaffected","packageURL":"pkg:pypi/GitPython","versions":[{"version":"0","lessThan":"3.1.51","versionType":"semver","status":"affected"},{"version":"3.1.51","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-67325","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-67326","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-01T13:17:03.063","lastModified":"2026-08-05T05:17:12.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"gitpython-developers","product":"GitPython","defaultStatus":"unaffected","packageURL":"pkg:pypi/gitpython","versions":[{"version":"0","lessThan":"3.1.50","versionType":"semver","status":"affected"},{"version":"3.1.50","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-67326","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-newline-injection-via-config-writer-section","source":"disclosure@vulncheck.com"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-18556","sourceIdentifier":"a5532a13-c4dd-4202-bef1-e0b8f2f8d12b","published":"2026-08-01T20:16:37.157","lastModified":"2026-08-05T05:16:46.967","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.\n\nThis issue affects N-central: through 2026.1."}],"affected":[{"source":"a5532a13-c4dd-4202-bef1-e0b8f2f8d12b","affectedData":[{"vendor":"N-able","product":"N-central","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2026.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"a5532a13-c4dd-4202-bef1-e0b8f2f8d12b","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-18556","options":[{"exploitation":"active"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-08-04","cisaActionDue":"2026-08-07","cisaRequiredAction":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","cisaVulnerabilityName":"N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability","weaknesses":[{"source":"a5532a13-c4dd-4202-bef1-e0b8f2f8d12b","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*","versionEndIncluding":"2026.1","matchCriteriaId":"4BC10DA8-8B50-4BCA-A302-810F4E3CD4CB"}]}]}],"references":[{"url":"https://uptime.n-able.com/","source":"a5532a13-c4dd-4202-bef1-e0b8f2f8d12b","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]},{"url":"https://www.n-able.com/blog/n-central-security-update-august-2-2026","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-68580","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-02T13:16:53.950","lastModified":"2026-08-05T05:17:12.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"FreeRDP","product":"FreeRDP","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.29.0","versionType":"semver","status":"affected"},{"version":"3.29.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-68580","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-integer-overflow-via-audio-input-channel","source":"disclosure@vulncheck.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-20464","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:40.357","lastModified":"2026-08-05T05:16:49.613","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6761","status":"affected"},{"version":"MT8766","status":"affected"},{"version":"MT8768","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20464","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20465","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:41.313","lastModified":"2026-08-05T05:16:50.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00489200; Issue ID: MSV-7834."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6890","status":"affected"},{"version":"MT7915","status":"affected"},{"version":"MT7916","status":"affected"},{"version":"MT7981","status":"affected"},{"version":"MT7986","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20465","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20467","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:41.547","lastModified":"2026-08-05T05:16:50.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT8195","status":"affected"},{"version":"MT8196","status":"affected"},{"version":"MT8366","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20467","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-749"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20468","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:41.683","lastModified":"2026-08-05T05:16:51.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT8196","status":"affected"},{"version":"MT8366","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20468","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20469","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:41.823","lastModified":"2026-08-05T05:16:51.590","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT8186","status":"affected"},{"version":"MT8188","status":"affected"},{"version":"MT8195","status":"affected"},{"version":"MT8365","status":"affected"},{"version":"MT8370","status":"affected"},{"version":"MT8371","status":"affected"},{"version":"MT8390","status":"affected"},{"version":"MT8391","status":"affected"},{"version":"MT8395","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20469","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-123"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20473","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:42.290","lastModified":"2026-08-05T05:16:52.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6991","status":"affected"},{"version":"MT6993","status":"affected"},{"version":"MT8126","status":"affected"},{"version":"MT8171","status":"affected"},{"version":"MT8188","status":"affected"},{"version":"MT8189","status":"affected"},{"version":"MT8367","status":"affected"},{"version":"MT8668","status":"affected"},{"version":"MT8676","status":"affected"},{"version":"MT8678","status":"affected"},{"version":"MT8766","status":"affected"},{"version":"MT8768","status":"affected"},{"version":"MT8781","status":"affected"},{"version":"MT8786","status":"affected"},{"version":"MT8791T","status":"affected"},{"version":"MT8799","status":"affected"},{"version":"MT8910","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20473","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20474","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:42.407","lastModified":"2026-08-05T05:16:52.553","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6991","status":"affected"},{"version":"MT6993","status":"affected"},{"version":"MT8126","status":"affected"},{"version":"MT8171","status":"affected"},{"version":"MT8188","status":"affected"},{"version":"MT8189","status":"affected"},{"version":"MT8367","status":"affected"},{"version":"MT8668","status":"affected"},{"version":"MT8676","status":"affected"},{"version":"MT8678","status":"affected"},{"version":"MT8766","status":"affected"},{"version":"MT8768","status":"affected"},{"version":"MT8781","status":"affected"},{"version":"MT8786","status":"affected"},{"version":"MT8791T","status":"affected"},{"version":"MT8799","status":"affected"},{"version":"MT8910","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20474","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20475","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:42.523","lastModified":"2026-08-05T05:16:53.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6991","status":"affected"},{"version":"MT6993","status":"affected"},{"version":"MT8126","status":"affected"},{"version":"MT8171","status":"affected"},{"version":"MT8188","status":"affected"},{"version":"MT8189","status":"affected"},{"version":"MT8367","status":"affected"},{"version":"MT8668","status":"affected"},{"version":"MT8676","status":"affected"},{"version":"MT8678","status":"affected"},{"version":"MT8766","status":"affected"},{"version":"MT8768","status":"affected"},{"version":"MT8781","status":"affected"},{"version":"MT8786","status":"affected"},{"version":"MT8791T","status":"affected"},{"version":"MT8799","status":"affected"},{"version":"MT8910","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20475","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20477","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:42.750","lastModified":"2026-08-05T05:16:53.513","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6991","status":"affected"},{"version":"MT6993","status":"affected"},{"version":"MT8188","status":"affected"},{"version":"MT8189","status":"affected"},{"version":"MT8668","status":"affected"},{"version":"MT8676","status":"affected"},{"version":"MT8678","status":"affected"},{"version":"MT8781","status":"affected"},{"version":"MT8799","status":"affected"},{"version":"MT8910","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20477","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20481","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:43.200","lastModified":"2026-08-05T05:16:54.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6989","status":"affected"},{"version":"MT8755","status":"affected"},{"version":"MT8768","status":"affected"},{"version":"MT8771","status":"affected"},{"version":"MT8775","status":"affected"},{"version":"MT8781","status":"affected"},{"version":"MT8791T","status":"affected"},{"version":"MT8792","status":"affected"},{"version":"MT8793","status":"affected"},{"version":"MT8796","status":"affected"},{"version":"MT8797","status":"affected"},{"version":"MT8798","status":"affected"},{"version":"MT8799","status":"affected"},{"version":"MT8910","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20481","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20483","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:43.430","lastModified":"2026-08-05T05:16:54.593","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6739","status":"affected"},{"version":"MT6761","status":"affected"},{"version":"MT6765","status":"affected"},{"version":"MT6768","status":"affected"},{"version":"MT6781","status":"affected"},{"version":"MT6789","status":"affected"},{"version":"MT6833","status":"affected"},{"version":"MT6835","status":"affected"},{"version":"MT6853","status":"affected"},{"version":"MT6855","status":"affected"},{"version":"MT6877","status":"affected"},{"version":"MT6878","status":"affected"},{"version":"MT6879","status":"affected"},{"version":"MT6883","status":"affected"},{"version":"MT6885","status":"affected"},{"version":"MT6886","status":"affected"},{"version":"MT6889","status":"affected"},{"version":"MT6893","status":"affected"},{"version":"MT6895","status":"affected"},{"version":"MT6897","status":"affected"},{"version":"MT6983","status":"affected"},{"version":"MT6985","status":"affected"},{"version":"MT6989","status":"affected"},{"version":"MT6991","status":"affected"},{"version":"MT6993","status":"affected"},{"version":"MT8766","status":"affected"},{"version":"MT8766R","status":"affected"},{"version":"MT8768","status":"affected"},{"version":"MT8775","status":"affected"},{"version":"MT8781","status":"affected"},{"version":"MT8792","status":"affected"},{"version":"MT8796","status":"affected"},{"version":"MT8873","status":"affected"},{"version":"MT8883","status":"affected"},{"version":"MT8893","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20483","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20485","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:43.653","lastModified":"2026-08-05T05:16:55.070","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6993","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20485","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20486","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:43.767","lastModified":"2026-08-05T05:16:55.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT2718","status":"affected"},{"version":"MT6878","status":"affected"},{"version":"MT6895","status":"affected"},{"version":"MT6991","status":"affected"},{"version":"MT6993","status":"affected"},{"version":"MT8370","status":"affected"},{"version":"MT8390","status":"affected"},{"version":"MT8395","status":"affected"},{"version":"MT8678","status":"affected"},{"version":"MT8799","status":"affected"},{"version":"MT8910","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20486","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-754"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20495","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:44.663","lastModified":"2026-08-05T05:16:56.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT7902","status":"affected"},{"version":"MT7920","status":"affected"},{"version":"MT7921","status":"affected"},{"version":"MT7922","status":"affected"},{"version":"MT7925","status":"affected"},{"version":"MT7927","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20495","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20497","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:44.890","lastModified":"2026-08-05T05:16:56.523","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6989","status":"affected"},{"version":"MT8755","status":"affected"},{"version":"MT8768","status":"affected"},{"version":"MT8771","status":"affected"},{"version":"MT8775","status":"affected"},{"version":"MT8781","status":"affected"},{"version":"MT8791T","status":"affected"},{"version":"MT8792","status":"affected"},{"version":"MT8796","status":"affected"},{"version":"MT8797","status":"affected"},{"version":"MT8798","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20497","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-20498","sourceIdentifier":"security@mediatek.com","published":"2026-08-03T03:16:45.000","lastModified":"2026-08-05T05:16:57.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MediaTek chipset","defaultStatus":"unaffected","versions":[{"version":"MT6991","status":"affected"},{"version":"MT8768","status":"affected"},{"version":"MT8791T","status":"affected"},{"version":"MT8792","status":"affected"},{"version":"MT8796","status":"affected"},{"version":"MT8799","status":"affected"},{"version":"MT8873","status":"affected"},{"version":"MT8883","status":"affected"},{"version":"MT8893","status":"affected"},{"version":"MT8910","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-20498","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1287"}]}],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/August-2026","source":"security@mediatek.com"}]}},{"cve":{"id":"CVE-2026-18574","sourceIdentifier":"cve@checkpoint.com","published":"2026-08-03T13:17:13.000","lastModified":"2026-08-05T05:16:47.433","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation."}],"affected":[{"source":"cve@checkpoint.com","affectedData":[{"vendor":"checkpoint","product":"Security Management Server","versions":[{"version":"R82.10 with Jumbo Hotfix Accumulator Take 39 or below","status":"affected"},{"version":"R82 with Jumbo Hotfix Accumulator Take 121 or below","status":"affected"},{"version":"R81.20 with Jumbo Hotfix Accumulator Take 160 or below","status":"affected"},{"version":"R81.10","status":"affected"},{"version":"R81","status":"affected"},{"version":"R80.40","status":"affected"},{"version":"R80.30","status":"affected"},{"version":"R80.20","status":"affected"},{"version":"R80.10","status":"affected"},{"version":"R80","status":"affected"}]},{"vendor":"checkpoint","product":"Multi-Domain Security Management Server","versions":[{"version":"R82.10 with Jumbo Hotfix Accumulator Take 39 or below","status":"affected"},{"version":"R82 with Jumbo Hotfix Accumulator Take 121 or below","status":"affected"},{"version":"R81.20 with Jumbo Hotfix Accumulator Take 160 or below","status":"affected"},{"version":"R81.10","status":"affected"},{"version":"R81","status":"affected"},{"version":"R80.40","status":"affected"},{"version":"R80.30","status":"affected"},{"version":"R80.20","status":"affected"},{"version":"R80.10","status":"affected"},{"version":"R80","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cve@checkpoint.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-18574","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@checkpoint.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"references":[{"url":"https://support.checkpoint.com/results/sk/sk185222","source":"cve@checkpoint.com"}]}},{"cve":{"id":"CVE-2026-69096","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-03T14:16:30.500","lastModified":"2026-08-05T05:17:13.900","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler builds a shell command from the request-controlled id, cmd, and uid fields and passes it to system() without quoting or argv-style execution in the rpcd root context. An authenticated attacker holding only the luci-app-dockerman read ACL can inject shell metacharacters (e.g., in id) to execute arbitrary commands as root via an HTTP POST to /ubus. openwrt-24.10 and openwrt-23.05 do not contain this backend and are not affected; no patched version was known as of the advisory."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"openwrt","product":"luci","defaultStatus":"unaffected","versions":[{"version":"26.162.29621~507ab5e","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-69096","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/openwrt/luci/commit/44618b5b53d9bdad5cd489e82e29688b4d0862c1","source":"disclosure@vulncheck.com"},{"url":"https://github.com/openwrt/luci/commit/f4d0a44950e42bcbb8eacf715a3493b276a4f3ac","source":"disclosure@vulncheck.com"},{"url":"https://github.com/openwrt/luci/security/advisories/GHSA-cq4h-h8jr-3xqv","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openwrt-luci-app-dockerman-read-acl-remote-code-execution","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-69097","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-03T14:16:30.677","lastModified":"2026-08-05T05:17:14.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"gitpython-developers","product":"GitPython","defaultStatus":"unaffected","packageURL":"pkg:pypi/gitpython","versions":[{"version":"0","lessThan":"3.1.53","versionType":"semver","status":"affected"},{"version":"3.1.53","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-69097","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-74"}]}],"references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-config-injection-via-submodule-names","source":"disclosure@vulncheck.com"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2025-9291","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-08-03T18:16:34.047","lastModified":"2026-08-05T05:16:44.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A\ncertification validation weakness exists in communication between affected\nOmada devices and cloud controllers. Certificate identity verification does not\nadequately validate that a presented certificate corresponds to the expected\ncloud controller hostname, which may allow certificate validation protections\nto be bypassed under specific conditions.\n\n\n\n\n\nSuccessful\nexploitation may allow interception or modification of communication between\naffected devices and cloud controllers."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"Omada Gateways","defaultStatus":"unknown","versions":[{"version":"0","versionType":"custom","status":"affected"}]},{"vendor":"TP-Link Systems Inc.","product":"Omada Switches","defaultStatus":"unaffected","versions":[{"version":"0","versionType":"custom","status":"affected"}]},{"vendor":"TP-Link Systems Inc.","product":"Omada Access Points","defaultStatus":"unaffected","versions":[{"version":"0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2025-9291","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"references":[{"url":"https://support.omadanetworks.com/en/download/firmware/","source":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://support.omadanetworks.com/us/download/firmware/","source":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5216/","source":"f23511db-6c3e-4e32-a477-6aa17d310630"}]}},{"cve":{"id":"CVE-2026-40717","sourceIdentifier":"security_alert@emc.com","published":"2026-08-03T18:16:38.907","lastModified":"2026-08-05T05:17:01.510","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges."}],"affected":[{"source":"security_alert@emc.com","affectedData":[{"vendor":"Dell","product":"Monitor driver","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.0.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security_alert@emc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.3,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-40717","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security_alert@emc.com","type":"Secondary","description":[{"lang":"en","value":"CWE-59"}]}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000481265/dsa-2026-295","source":"security_alert@emc.com"}]}},{"cve":{"id":"CVE-2026-59912","sourceIdentifier":"security_alert@emc.com","published":"2026-08-03T19:16:48.050","lastModified":"2026-08-05T05:17:03.753","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution."}],"affected":[{"source":"security_alert@emc.com","affectedData":[{"vendor":"Dell","product":"Display and Peripheral Manager (DDPM Mac)","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.3.0.1005","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security_alert@emc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-59912","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security_alert@emc.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000490035/dsa-2026-319","source":"security_alert@emc.com"}]}},{"cve":{"id":"CVE-2026-59913","sourceIdentifier":"security_alert@emc.com","published":"2026-08-03T19:16:48.193","lastModified":"2026-08-05T05:17:04.277","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges."}],"affected":[{"source":"security_alert@emc.com","affectedData":[{"vendor":"Dell","product":"Display and Peripheral Manager (DDPM Mac)","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.3.0.1005","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security_alert@emc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-59913","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security_alert@emc.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000490035/dsa-2026-319","source":"security_alert@emc.com"}]}},{"cve":{"id":"CVE-2026-62354","sourceIdentifier":"security@apache.org","published":"2026-08-03T20:17:25.530","lastModified":"2026-08-05T05:17:04.743","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined component validation methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying Parameter Context configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, requiring write access to submit Parameter Context validation requests."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache NiFi","defaultStatus":"unaffected","packageName":"org.apache.nifi:nifi-web-api","versions":[{"version":"1.10.0","lessThanOrEqual":"2.10.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:L/U:Amber","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"PRESENT","Automatable":"YES","Recovery":"IRRECOVERABLE","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"LOW","providerUrgency":"AMBER"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-62354","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://lists.apache.org/thread/l17xcnnf1rm7qljmypyjxmh62cx4o4wj","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/03/11","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68979","sourceIdentifier":"security@apache.org","published":"2026-08-03T20:17:28.977","lastModified":"2026-08-05T05:17:13.377","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but framework authorization was limited to read and write privileges on the Parameter Context itself. As a result of the missing authorization, an authenticated user authorized to modify a Parameter Context, but not authorized on referencing components, could alter Parameter values affecting those components. In deployments where a Parameter value contains executable scripting content, updating a Parameter can result in code execution during automatic component validation, without starting the referencing component. The impact was limited to stopped components by existing verification checks, and the issue applies only to deployments that use component-level authorization policies. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which aligns the Parameter Context update method authorization with other methods, adding authorization checking on affected components."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache NiFi","defaultStatus":"unaffected","packageName":"org.apache.nifi:nifi-web-api","versions":[{"version":"1.10.0","lessThanOrEqual":"2.10.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@apache.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Clear","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NEGLIGIBLE","Automatable":"YES","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"LOW","providerUrgency":"CLEAR"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-68979","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://lists.apache.org/thread/xwz8wsss2ovx07tns96rkc3n7cm4xfrq","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/03/10","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-18667","sourceIdentifier":"vulnreport@tenable.com","published":"2026-08-03T23:16:45.590","lastModified":"2026-08-05T05:16:48.337","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host."}],"affected":[{"source":"vulnreport@tenable.com","affectedData":[{"vendor":"Tenable, Inc.","product":"Sensor Proxy","defaultStatus":"affected","platforms":["Linux"],"versions":[{"version":"0","lessThan":"1.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vulnreport@tenable.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"vulnreport@tenable.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-18667","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vulnreport@tenable.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.tenable.com/security/tns-2026-21","source":"vulnreport@tenable.com"}]}},{"cve":{"id":"CVE-2026-62870","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:37.813","lastModified":"2026-08-05T05:17:05.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft 365 Apps for Enterprise","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.1","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Excel 2016","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.0.0","lessThan":"16.0.5561.1001","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Office 2019","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"19.0.0","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Office LTSC 2021","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.1","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Office LTSC 2024","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.0","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-62870","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62870","source":"secure@microsoft.com"}]}},{"cve":{"id":"CVE-2026-66310","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:38.240","lastModified":"2026-08-05T05:17:06.550","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft Edge for Android","versions":[{"version":"1.0.0","lessThan":"151.0.4129.59","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-66310","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-73"}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66310","source":"secure@microsoft.com"}]}},{"cve":{"id":"CVE-2026-66312","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:38.510","lastModified":"2026-08-05T05:17:06.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft Edge (Chromium-based)","versions":[{"version":"1.0.0.0","lessThan":"151.0.4129.59","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-66312","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-126"}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66312","source":"secure@microsoft.com"}]}},{"cve":{"id":"CVE-2026-66315","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:38.927","lastModified":"2026-08-05T05:17:07.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft Edge (Chromium-based)","versions":[{"version":"1.0.0.0","lessThan":"151.0.4129.59","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-66315","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66315","source":"secure@microsoft.com"}]}},{"cve":{"id":"CVE-2026-66318","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:39.317","lastModified":"2026-08-05T05:17:07.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft Edge (Chromium-based)","versions":[{"version":"1.0.0.0","lessThan":"151.0.4129.59","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-66318","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66318","source":"secure@microsoft.com"}]}},{"cve":{"id":"CVE-2026-66321","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:39.440","lastModified":"2026-08-05T05:17:08.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft Edge (Chromium-based)","versions":[{"version":"1.0.0.0","lessThan":"151.0.4129.59","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-66321","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-843"}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66321","source":"secure@microsoft.com"}]}},{"cve":{"id":"CVE-2026-66326","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:39.847","lastModified":"2026-08-05T05:17:08.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft Edge (Chromium-based)","versions":[{"version":"1.0.0.0","lessThan":"151.0.4129.59","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-66326","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66326","source":"secure@microsoft.com"}]}},{"cve":{"id":"CVE-2026-6837","sourceIdentifier":"security@zyxel.com.tw","published":"2026-08-04T03:16:25.890","lastModified":"2026-08-05T05:17:14.873","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A post-authentication command injection vulnerability in the \"export-cgi\" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device."}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"WAX650S firmware","defaultStatus":"unaffected","versions":[{"version":"<= 7.10(ABRM.4)C0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-6837","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026","source":"security@zyxel.com.tw"}]}},{"cve":{"id":"CVE-2026-18739","sourceIdentifier":"secalert@redhat.com","published":"2026-08-04T06:16:30.330","lastModified":"2026-08-05T05:16:48.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"popt","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"popt","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"popt","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"popt","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"popt","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"popt","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcos","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":2.5,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.0,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-18739","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-18739","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510737","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-10709","sourceIdentifier":"psirt@autodesk.com","published":"2026-08-04T13:17:32.377","lastModified":"2026-08-05T05:16:45.593","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."}],"affected":[{"source":"psirt@autodesk.com","affectedData":[{"vendor":"Autodesk","product":"FBX SDK","defaultStatus":"unaffected","cpes":["cpe:2.3:a:autodesk:fbx_sdk:2020.3.9:*:*:*:*:*:*:*"],"versions":[{"version":"2020.3.9","lessThan":"2020.3.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@autodesk.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-10709","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@autodesk.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://www.autodesk.com/products/autodesk-access/overview","source":"psirt@autodesk.com"},{"url":"https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010","source":"psirt@autodesk.com"}]}},{"cve":{"id":"CVE-2026-10710","sourceIdentifier":"psirt@autodesk.com","published":"2026-08-04T13:17:32.507","lastModified":"2026-08-05T05:16:46.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process."}],"affected":[{"source":"psirt@autodesk.com","affectedData":[{"vendor":"Autodesk","product":"FBX SDK","defaultStatus":"unaffected","cpes":["cpe:2.3:a:autodesk:fbx_sdk:2020.3.9:*:*:*:*:*:*:*"],"versions":[{"version":"2020.3.9","lessThan":"2020.3.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@autodesk.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-10710","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@autodesk.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://www.autodesk.com/products/autodesk-access/overview","source":"psirt@autodesk.com"},{"url":"https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010","source":"psirt@autodesk.com"}]}},{"cve":{"id":"CVE-2026-21366","sourceIdentifier":"product-security@qualcomm.com","published":"2026-08-04T16:16:22.780","lastModified":"2026-08-05T05:16:57.477","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Memory corruption while processing a packet with a size close to the maximum allowed value."}],"affected":[{"source":"product-security@qualcomm.com","affectedData":[{"vendor":"Qualcomm, Inc.","product":"Snapdragon","defaultStatus":"unaffected","platforms":["Snapdragon Auto"],"versions":[{"version":"LeMans_AU_LGIT","status":"affected"},{"version":"LeMansAU","status":"affected"},{"version":"QAM8255P","status":"affected"},{"version":"QAM8295P","status":"affected"},{"version":"QAM8620P","status":"affected"},{"version":"QAMSRV1H","status":"affected"},{"version":"QAMSRV1M","status":"affected"},{"version":"QCA6574AU","status":"affected"},{"version":"QCA6595","status":"affected"},{"version":"QCA6595AU","status":"affected"},{"version":"QCA6688AQ","status":"affected"},{"version":"QCA6696","status":"affected"},{"version":"QCA6698AQ","status":"affected"},{"version":"QCA6797AQ","status":"affected"},{"version":"QCA8695AU","status":"affected"},{"version":"SA6145P","status":"affected"},{"version":"SA6150P","status":"affected"},{"version":"SA6155P","status":"affected"},{"version":"SA7255P","status":"affected"},{"version":"SA7775P","status":"affected"},{"version":"SA8145P","status":"affected"},{"version":"SA8150P","status":"affected"},{"version":"SA8155P","status":"affected"},{"version":"SA8195P","status":"affected"},{"version":"SA8255P","status":"affected"},{"version":"SA8295P","status":"affected"},{"version":"SA8540P","status":"affected"},{"version":"SA8620P","status":"affected"},{"version":"SA8770P","status":"affected"},{"version":"SA9000P","status":"affected"},{"version":"SRV1H","status":"affected"},{"version":"SRV1L","status":"affected"},{"version":"SRV1M","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@qualcomm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-21366","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@qualcomm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","source":"product-security@qualcomm.com"}]}},{"cve":{"id":"CVE-2026-24076","sourceIdentifier":"product-security@qualcomm.com","published":"2026-08-04T16:16:22.920","lastModified":"2026-08-05T05:16:57.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Memory Corruption when processing registry values with incorrect types using a direct query method."}],"affected":[{"source":"product-security@qualcomm.com","affectedData":[{"vendor":"Qualcomm, Inc.","product":"Snapdragon","defaultStatus":"unaffected","platforms":["Snapdragon Compute","Snapdragon Consumer Electronics Connectivity","Snapdragon Industrial IOT"],"versions":[{"version":"AQT1000","status":"affected"},{"version":"Cologne","status":"affected"},{"version":"FastConnect 6200","status":"affected"},{"version":"FastConnect 6700","status":"affected"},{"version":"FastConnect 6800","status":"affected"},{"version":"FastConnect 6900","status":"affected"},{"version":"FastConnect 7800","status":"affected"},{"version":"QCA0000","status":"affected"},{"version":"QCA2062","status":"affected"},{"version":"QCA2064","status":"affected"},{"version":"QCA2065","status":"affected"},{"version":"QCA2066","status":"affected"},{"version":"QCA6391","status":"affected"},{"version":"QCA6420","status":"affected"},{"version":"QCA6430","status":"affected"},{"version":"QCM5430","status":"affected"},{"version":"QCM6490","status":"affected"},{"version":"Qualcomm Video Collaboration VC3 Platform","status":"affected"},{"version":"SC8380XP","status":"affected"},{"version":"SM6250","status":"affected"},{"version":"Snapdragon 7c Compute Platform","status":"affected"},{"version":"Snapdragon 7c Gen 2 Compute Platform \"Rennell Pro\"","status":"affected"},{"version":"Snapdragon 7c+ Gen 3 Compute","status":"affected"},{"version":"Snapdragon 8c Compute Platform \"Poipu Lite\"","status":"affected"},{"version":"Snapdragon 8c Compute Platform (SC8180XP-AD) \"Poipu Lite\"","status":"affected"},{"version":"Snapdragon 8cx Compute Platform","status":"affected"},{"version":"Snapdragon 8cx Compute Platform \"Poipu Pro\"","status":"affected"},{"version":"Snapdragon 8cx Gen 2 5G Compute Platform","status":"affected"},{"version":"Snapdragon 8cx Gen 2 5G Compute Platform \"Poipu Pro\"","status":"affected"},{"version":"Snapdragon 8cx Gen 3 Compute Platform","status":"affected"},{"version":"WCD9340","status":"affected"},{"version":"WCD9341","status":"affected"},{"version":"WCD9370","status":"affected"},{"version":"WCD9375","status":"affected"},{"version":"WCD9378C","status":"affected"},{"version":"WCD9380","status":"affected"},{"version":"WCD9385","status":"affected"},{"version":"WSA8810","status":"affected"},{"version":"WSA8815","status":"affected"},{"version":"WSA8830","status":"affected"},{"version":"WSA8835","status":"affected"},{"version":"WSA8840","status":"affected"},{"version":"WSA8845","status":"affected"},{"version":"WSA8845H","status":"affected"},{"version":"X2000077","status":"affected"},{"version":"X2000086","status":"affected"},{"version":"X2000090","status":"affected"},{"version":"X2000092","status":"affected"},{"version":"X2000094","status":"affected"},{"version":"XG101002","status":"affected"},{"version":"XG101032","status":"affected"},{"version":"XG101039","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@qualcomm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-24076","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@qualcomm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","source":"product-security@qualcomm.com"}]}},{"cve":{"id":"CVE-2026-24079","sourceIdentifier":"product-security@qualcomm.com","published":"2026-08-04T16:16:23.453","lastModified":"2026-08-05T05:16:58.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cryptographic Issue while processing registration requests with malformed or missing authentication parameters."}],"affected":[{"source":"product-security@qualcomm.com","affectedData":[{"vendor":"Qualcomm, Inc.","product":"Snapdragon","defaultStatus":"unaffected","platforms":["Snapdragon Auto","Snapdragon Compute","Snapdragon Consumer IOT","Snapdragon Industrial IOT","Snapdragon Mobile","Snapdragon Small Cell","Snapdragon WBC","Snapdragon Wearables"],"versions":[{"version":"AR8035","status":"affected"},{"version":"CSRA6620","status":"affected"},{"version":"CSRA6640","status":"affected"},{"version":"FastConnect 6200","status":"affected"},{"version":"FastConnect 6700","status":"affected"},{"version":"FastConnect 6800","status":"affected"},{"version":"FastConnect 6900","status":"affected"},{"version":"FastConnect 7800","status":"affected"},{"version":"FSM200 Platform","status":"affected"},{"version":"FSM20055","status":"affected"},{"version":"FWA Gen 3 Ultra Platform","status":"affected"},{"version":"G1 Gen 1","status":"affected"},{"version":"Milos","status":"affected"},{"version":"Netrani","status":"affected"},{"version":"Orne","status":"affected"},{"version":"Palawan25","status":"affected"},{"version":"QCA6174A","status":"affected"},{"version":"QCA6391","status":"affected"},{"version":"QCA6574AU","status":"affected"},{"version":"QCA6584AU","status":"affected"},{"version":"QCA6595AU","status":"affected"},{"version":"QCA6678AQ","status":"affected"},{"version":"QCA6688AQ","status":"affected"},{"version":"QCA6696","status":"affected"},{"version":"QCA6698AQ","status":"affected"},{"version":"QCA6698AU","status":"affected"},{"version":"QCA6797AQ","status":"affected"},{"version":"QCA8081","status":"affected"},{"version":"QCA8337","status":"affected"},{"version":"QCC710","status":"affected"},{"version":"QCM2290","status":"affected"},{"version":"QCM4325","status":"affected"},{"version":"QCM4490","status":"affected"},{"version":"QCM5430","status":"affected"},{"version":"QCM6490","status":"affected"},{"version":"QCN6024","status":"affected"},{"version":"QCN6224","status":"affected"},{"version":"QCN6274","status":"affected"},{"version":"QCN9011","status":"affected"},{"version":"QCN9012","status":"affected"},{"version":"QCN9024","status":"affected"},{"version":"QCS2290","status":"affected"},{"version":"QCS4290","status":"affected"},{"version":"QCS4490","status":"affected"},{"version":"QCS8550","status":"affected"},{"version":"QEP8111","status":"affected"},{"version":"QFW7114","status":"affected"},{"version":"QFW7124","status":"affected"},{"version":"QMP1000","status":"affected"},{"version":"Qualcomm Video Collaboration VC3 Platform","status":"affected"},{"version":"Robotics RB2 Platform","status":"affected"},{"version":"SD 8 Gen1 5G","status":"affected"},{"version":"SD662","status":"affected"},{"version":"SDX61","status":"affected"},{"version":"SM6225P","status":"affected"},{"version":"SM6650P","status":"affected"},{"version":"SM7325P","status":"affected"},{"version":"SM7435","status":"affected"},{"version":"SM7550","status":"affected"},{"version":"SM7550P","status":"affected"},{"version":"SM7635P","status":"affected"},{"version":"SM7675","status":"affected"},{"version":"SM7675P","status":"affected"},{"version":"SM8475P","status":"affected"},{"version":"SM8550P","status":"affected"},{"version":"SM8635","status":"affected"},{"version":"SM8635P","status":"affected"},{"version":"SM8650Q","status":"affected"},{"version":"SM8750P","status":"affected"},{"version":"Snapdragon 4 Gen 1 Mobile Platform","status":"affected"},{"version":"Snapdragon 4 Gen 2 Mobile Platform","status":"affected"},{"version":"Snapdragon 460 Mobile Platform","status":"affected"},{"version":"Snapdragon 480 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 480+ 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 6 Gen 1 Mobile Platform","status":"affected"},{"version":"Snapdragon 6 Gen 3 Mobile Platform","status":"affected"},{"version":"Snapdragon 6 Gen 4 Mobile Platform","status":"affected"},{"version":"Snapdragon 662 Mobile Platform","status":"affected"},{"version":"Snapdragon 680 4G Mobile Platform","status":"affected"},{"version":"Snapdragon 685 4G Mobile Platform","status":"affected"},{"version":"Snapdragon 690 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 695 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 7 Gen 1 Mobile Platform","status":"affected"},{"version":"Snapdragon 7+ Gen 2 Mobile Platform","status":"affected"},{"version":"Snapdragon 778G 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 778G+ 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 782G Mobile Platform","status":"affected"},{"version":"Snapdragon 7c+ Gen 3 Compute","status":"affected"},{"version":"Snapdragon 7s Gen 3 Mobile Platform","status":"affected"},{"version":"Snapdragon 8 Elite","status":"affected"},{"version":"Snapdragon 8 Gen 1 Mobile Platform","status":"affected"},{"version":"Snapdragon 8 Gen 2 Mobile Platform","status":"affected"},{"version":"Snapdragon 8 Gen 3 Mobile Platform","status":"affected"},{"version":"Snapdragon 8+ Gen 1 Mobile Platform","status":"affected"},{"version":"Snapdragon 8+ Gen 2 Mobile Platform","status":"affected"},{"version":"Snapdragon 865 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 865+ 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 870 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 888 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 888+ 5G Mobile Platform","status":"affected"},{"version":"Snapdragon Auto 5G Modem-RF","status":"affected"},{"version":"Snapdragon Auto 5G Modem-RF Gen 2","status":"affected"},{"version":"Snapdragon W5+ Gen 1 Wearable Platform","status":"affected"},{"version":"Snapdragon X32 5G Modem-RF System","status":"affected"},{"version":"Snapdragon X35 5G Modem-RF System","status":"affected"},{"version":"Snapdragon X53 5G Modem-RF System","status":"affected"},{"version":"Snapdragon X55 5G Modem-RF System","status":"affected"},{"version":"Snapdragon X65 5G Modem-RF System","status":"affected"},{"version":"Snapdragon X72 5G Modem-RF System","status":"affected"},{"version":"Snapdragon X75 5G Modem-RF System","status":"affected"},{"version":"SW5100","status":"affected"},{"version":"SW5100P","status":"affected"},{"version":"SW6100","status":"affected"},{"version":"SW6100P","status":"affected"},{"version":"Themisto","status":"affected"},{"version":"WCD9335","status":"affected"},{"version":"WCD9340","status":"affected"},{"version":"WCD9370","status":"affected"},{"version":"WCD9371","status":"affected"},{"version":"WCD9375","status":"affected"},{"version":"WCD9378","status":"affected"},{"version":"WCD9380","status":"affected"},{"version":"WCD9385","status":"affected"},{"version":"WCD9390","status":"affected"},{"version":"WCD9395","status":"affected"},{"version":"WCN3910","status":"affected"},{"version":"WCN3950","status":"affected"},{"version":"WCN3980","status":"affected"},{"version":"WCN3988","status":"affected"},{"version":"WCN6650","status":"affected"},{"version":"WCN6755","status":"affected"},{"version":"WCN7860","status":"affected"},{"version":"WCN7861","status":"affected"},{"version":"WCN7880","status":"affected"},{"version":"WCN7881","status":"affected"},{"version":"WSA8810","status":"affected"},{"version":"WSA8815","status":"affected"},{"version":"WSA8830","status":"affected"},{"version":"WSA8832","status":"affected"},{"version":"WSA8835","status":"affected"},{"version":"WSA8840","status":"affected"},{"version":"WSA8845","status":"affected"},{"version":"WSA8845H","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@qualcomm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-24079","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@qualcomm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","source":"product-security@qualcomm.com"}]}},{"cve":{"id":"CVE-2026-24080","sourceIdentifier":"product-security@qualcomm.com","published":"2026-08-04T16:16:23.770","lastModified":"2026-08-05T05:16:58.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Memory Corruption when handling malformed request parameters in the fingerprint TA."}],"affected":[{"source":"product-security@qualcomm.com","affectedData":[{"vendor":"Qualcomm, Inc.","product":"Snapdragon","defaultStatus":"unaffected","platforms":["Snapdragon Auto","Snapdragon Compute","Snapdragon Industrial IOT","Snapdragon Wearables"],"versions":[{"version":"Cologne","status":"affected"},{"version":"FastConnect 6700","status":"affected"},{"version":"FastConnect 6900","status":"affected"},{"version":"FastConnect 7800","status":"affected"},{"version":"QAM8255P","status":"affected"},{"version":"QAM8295P","status":"affected"},{"version":"QCA6574AU","status":"affected"},{"version":"QCA6595AU","status":"affected"},{"version":"QCA6678AQ","status":"affected"},{"version":"QCA6696","status":"affected"},{"version":"SA6145P","status":"affected"},{"version":"SA6150P","status":"affected"},{"version":"SA6155P","status":"affected"},{"version":"SA8145P","status":"affected"},{"version":"SA8150P","status":"affected"},{"version":"SA8155P","status":"affected"},{"version":"SA8195P","status":"affected"},{"version":"SA8255P","status":"affected"},{"version":"SA8295P","status":"affected"},{"version":"SA8540P","status":"affected"},{"version":"SA9000P","status":"affected"},{"version":"SW6100","status":"affected"},{"version":"SW6100P","status":"affected"},{"version":"Themisto","status":"affected"},{"version":"WCD9378C","status":"affected"},{"version":"WSA8840","status":"affected"},{"version":"WSA8845","status":"affected"},{"version":"WSA8845H","status":"affected"},{"version":"X2000077","status":"affected"},{"version":"X2000086","status":"affected"},{"version":"X2000090","status":"affected"},{"version":"X2000092","status":"affected"},{"version":"X2000094","status":"affected"},{"version":"XG101002","status":"affected"},{"version":"XG101032","status":"affected"},{"version":"XG101039","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@qualcomm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-24080","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@qualcomm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","source":"product-security@qualcomm.com"}]}},{"cve":{"id":"CVE-2026-24083","sourceIdentifier":"product-security@qualcomm.com","published":"2026-08-04T16:16:24.123","lastModified":"2026-08-05T05:16:59.323","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Memory Corruption while processing IOCTL device driver requests with invalid arguments."}],"affected":[{"source":"product-security@qualcomm.com","affectedData":[{"vendor":"Qualcomm, Inc.","product":"Snapdragon","defaultStatus":"unaffected","platforms":["Snapdragon Auto"],"versions":[{"version":"QAM8295P","status":"affected"},{"version":"QCA6696","status":"affected"},{"version":"SA8295P","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@qualcomm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-24083","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@qualcomm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-822"}]}],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","source":"product-security@qualcomm.com"}]}},{"cve":{"id":"CVE-2026-25289","sourceIdentifier":"product-security@qualcomm.com","published":"2026-08-04T16:16:24.890","lastModified":"2026-08-05T05:16:59.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values."}],"affected":[{"source":"product-security@qualcomm.com","affectedData":[{"vendor":"Qualcomm, Inc.","product":"Snapdragon","defaultStatus":"unaffected","platforms":["Snapdragon Auto","Snapdragon CCW","Snapdragon Compute","Snapdragon Connectivity","Snapdragon Consumer Electronics Connectivity","Snapdragon Consumer IOT","Snapdragon Industrial IOT","Snapdragon MC","Snapdragon Mobile","Snapdragon Technology","Snapdragon WBC","Snapdragon Wearables","Snapdragon Wired Infrastructure and Networking"],"versions":[{"version":"AR8035","status":"affected"},{"version":"Cologne","status":"affected"},{"version":"CQ7790","status":"affected"},{"version":"CQ8725S","status":"affected"},{"version":"CQ8750M","status":"affected"},{"version":"FastConnect 6200","status":"affected"},{"version":"FastConnect 6700","status":"affected"},{"version":"FastConnect 6800","status":"affected"},{"version":"FastConnect 6900","status":"affected"},{"version":"FastConnect 7800","status":"affected"},{"version":"FWA Gen 3 Ultra Platform","status":"affected"},{"version":"FWA Gen 5 Elite Platform","status":"affected"},{"version":"G2 Gen 1","status":"affected"},{"version":"Immersive Home 3210 Platform","status":"affected"},{"version":"Immersive Home 326 Platform","status":"affected"},{"version":"IPQ5300","status":"affected"},{"version":"IPQ5302","status":"affected"},{"version":"IPQ5312","status":"affected"},{"version":"IPQ5332","status":"affected"},{"version":"IPQ9554","status":"affected"},{"version":"IPQ9570","status":"affected"},{"version":"IPQ9574","status":"affected"},{"version":"IQ10 Series","status":"affected"},{"version":"IQX5121","status":"affected"},{"version":"IQX7181","status":"affected"},{"version":"Kobuk","status":"affected"},{"version":"LeMans_AU_LGIT","status":"affected"},{"version":"LeMansAU","status":"affected"},{"version":"Milos","status":"affected"},{"version":"Milos_IOT","status":"affected"},{"version":"Networking Pro 1210 Platform","status":"affected"},{"version":"Networking Pro 1610 Platform","status":"affected"},{"version":"Networking Pro 610 Platform","status":"affected"},{"version":"Networking Pro 810 Platform","status":"affected"},{"version":"Orne","status":"affected"},{"version":"Palawan25","status":"affected"},{"version":"Pandeiro","status":"affected"},{"version":"QAM8255P","status":"affected"},{"version":"QAM8397P","status":"affected"},{"version":"QAM8797P","status":"affected"},{"version":"QAMSRV1H","status":"affected"},{"version":"QAMSRV1M","status":"affected"},{"version":"QCA0000","status":"affected"},{"version":"QCA6391","status":"affected"},{"version":"QCA6426","status":"affected"},{"version":"QCA6436","status":"affected"},{"version":"QCA6554A","status":"affected"},{"version":"QCA6564AU","status":"affected"},{"version":"QCA6574","status":"affected"},{"version":"QCA6574A","status":"affected"},{"version":"QCA6574AU","status":"affected"},{"version":"QCA6584AU","status":"affected"},{"version":"QCA6595","status":"affected"},{"version":"QCA6595AU","status":"affected"},{"version":"QCA6678AQ","status":"affected"},{"version":"QCA6688AQ","status":"affected"},{"version":"QCA6696","status":"affected"},{"version":"QCA6698AQ","status":"affected"},{"version":"QCA6698AU","status":"affected"},{"version":"QCA6777AQ","status":"affected"},{"version":"QCA6787AQ","status":"affected"},{"version":"QCA6797AQ","status":"affected"},{"version":"QCA8075","status":"affected"},{"version":"QCA8081","status":"affected"},{"version":"QCA8337","status":"affected"},{"version":"QCA8386","status":"affected"},{"version":"QCA8695AU","status":"affected"},{"version":"QCC2073","status":"affected"},{"version":"QCC2076","status":"affected"},{"version":"QCC710","status":"affected"},{"version":"QCF8000","status":"affected"},{"version":"QCF8001","status":"affected"},{"version":"QCM8550","status":"affected"},{"version":"QCM8838","status":"affected"},{"version":"QCN5124","status":"affected"},{"version":"QCN6224","status":"affected"},{"version":"QCN6274","status":"affected"},{"version":"QCN6402","status":"affected"},{"version":"QCN6412","status":"affected"},{"version":"QCN6422","status":"affected"},{"version":"QCN6432","status":"affected"},{"version":"QCN9011","status":"affected"},{"version":"QCN9012","status":"affected"},{"version":"QCN9274","status":"affected"},{"version":"QCS6690","status":"affected"},{"version":"QCS8550","status":"affected"},{"version":"QFW7114","status":"affected"},{"version":"QFW7124","status":"affected"},{"version":"QLN1083BD","status":"affected"},{"version":"QLN1086BD","status":"affected"},{"version":"QMB715","status":"affected"},{"version":"QMP1000","status":"affected"},{"version":"QPA1083BD","status":"affected"},{"version":"QPA1086BD","status":"affected"},{"version":"QXM1083","status":"affected"},{"version":"QXM1086","status":"affected"},{"version":"QXM1093","status":"affected"},{"version":"QXM1094","status":"affected"},{"version":"QXM1095","status":"affected"},{"version":"QXM1096","status":"affected"},{"version":"SA7255P","status":"affected"},{"version":"SA7775P","status":"affected"},{"version":"SA8255P","status":"affected"},{"version":"SA8620P","status":"affected"},{"version":"SA8770P","status":"affected"},{"version":"SA9000P","status":"affected"},{"version":"SAR1165P","status":"affected"},{"version":"SAR2130P","status":"affected"},{"version":"SC8380XP","status":"affected"},{"version":"SD 8 Gen1 5G","status":"affected"},{"version":"SD865 5G","status":"affected"},{"version":"SDR753","status":"affected"},{"version":"SDX81","status":"affected"},{"version":"SM6650P","status":"affected"},{"version":"SM7635P","status":"affected"},{"version":"SM7675","status":"affected"},{"version":"SM7675P","status":"affected"},{"version":"SM8550P","status":"affected"},{"version":"SM8635","status":"affected"},{"version":"SM8635P","status":"affected"},{"version":"SM8650Q","status":"affected"},{"version":"SM8750P","status":"affected"},{"version":"Snapdragon 6 Gen 4 Mobile Platform","status":"affected"},{"version":"Snapdragon 7 Gen 4 Mobile Platform","status":"affected"},{"version":"Snapdragon 7s Gen 3 Mobile Platform","status":"affected"},{"version":"Snapdragon 8 Elite","status":"affected"},{"version":"Snapdragon 8 Elite Gen 5","status":"affected"},{"version":"Snapdragon 8 Gen 1 Mobile Platform","status":"affected"},{"version":"Snapdragon 8 Gen 2 Mobile Platform","status":"affected"},{"version":"Snapdragon 8 Gen 3 Mobile Platform","status":"affected"},{"version":"Snapdragon 8+ Gen 2 Mobile Platform","status":"affected"},{"version":"Snapdragon 865 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 865+ 5G Mobile Platform","status":"affected"},{"version":"Snapdragon 870 5G Mobile Platform","status":"affected"},{"version":"Snapdragon AR1 Gen 1 Platform","status":"affected"},{"version":"Snapdragon AR1+ Gen 1 Platform","status":"affected"},{"version":"Snapdragon Auto 5G Modem-RF Gen 2","status":"affected"},{"version":"Snapdragon X72 5G Modem-RF System","status":"affected"},{"version":"Snapdragon X75 5G Modem-RF System","status":"affected"},{"version":"Snapdragon XR2 5G Platform","status":"affected"},{"version":"Snapdragon Wear Elite platform","status":"affected"},{"version":"SRV1H","status":"affected"},{"version":"SRV1M","status":"affected"},{"version":"SSG2115P","status":"affected"},{"version":"SSG2125P","status":"affected"},{"version":"SXR1230P","status":"affected"},{"version":"SXR2230P","status":"affected"},{"version":"SXR2250P","status":"affected"},{"version":"SXR2330P","status":"affected"},{"version":"SXR2350P","status":"affected"},{"version":"Themisto","status":"affected"},{"version":"WCD9340","status":"affected"},{"version":"WCD9370","status":"affected"},{"version":"WCD9375","status":"affected"},{"version":"WCD9378","status":"affected"},{"version":"WCD9378C","status":"affected"},{"version":"WCD9380","status":"affected"},{"version":"WCD9385","status":"affected"},{"version":"WCD9390","status":"affected"},{"version":"WCD9395","status":"affected"},{"version":"WCN3988","status":"affected"},{"version":"WCN6450","status":"affected"},{"version":"WCN6650","status":"affected"},{"version":"WCN6740","status":"affected"},{"version":"WCN6755","status":"affected"},{"version":"WCN7860","status":"affected"},{"version":"WCN7861","status":"affected"},{"version":"WCN7880","status":"affected"},{"version":"WCN7881","status":"affected"},{"version":"WSA8810","status":"affected"},{"version":"WSA8815","status":"affected"},{"version":"WSA8830","status":"affected"},{"version":"WSA8832","status":"affected"},{"version":"WSA8835","status":"affected"},{"version":"WSA8840","status":"affected"},{"version":"WSA8845","status":"affected"},{"version":"WSA8845H","status":"affected"},{"version":"X1E80100","status":"affected"},{"version":"X2000077","status":"affected"},{"version":"X2000086","status":"affected"},{"version":"X2000090","status":"affected"},{"version":"X2000092","status":"affected"},{"version":"X2000094","status":"affected"},{"version":"XG101002","status":"affected"},{"version":"XG101032","status":"affected"},{"version":"XG101039","status":"affected"},{"version":"XRV7209","status":"affected"},{"version":"XRV9209","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"product-security@qualcomm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-25289","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"product-security@qualcomm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html","source":"product-security@qualcomm.com"}]}},{"cve":{"id":"CVE-2026-15307","sourceIdentifier":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","published":"2026-08-04T17:16:46.127","lastModified":"2026-08-05T05:16:46.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.\nGeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a `GeometryField` or `RasterField` reaches this constructor, including untrusted input, for example a spatial-field filter submitted through the Django admin changelist query string by a staff user with view permission. A `dict`, or a `str` holding its JSON representation, is opened in write mode regardless of the constructor's `write=False` default, allowing a file with an attacker-chosen name and contents to be written through a file-backed GDAL driver. Any other `str` is treated as a datasource, allowing an outbound network request through a GDAL virtual filesystem handler. Writing a file to a location later imported by the application can result in remote code execution.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Bence Nagy, localhost-detect, and kimchunbok_ for reporting this issue."}],"affected":[{"source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","affectedData":[{"vendor":"djangoproject","product":"Django","defaultStatus":"unaffected","collectionURL":"https://pypi.org/project/Django/","packageName":"django","repo":"https://github.com/django/django/","versions":[{"version":"6.0","lessThan":"6.0.8","versionType":"python","status":"affected"},{"version":"6.0.8","versionType":"python","status":"unaffected"},{"version":"5.2","lessThan":"5.2.17","versionType":"python","status":"affected"},{"version":"5.2.17","versionType":"python","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-15307","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92","type":"Secondary","description":[{"lang":"en","value":"CWE-73"},{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/115ffd0463a765ab1cc93de18e94b5459b8a300e","source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/208f80cb682868b584ed0a78f23e4ba6304212aa","source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/39b3e2d0c743a338def6c473086ebc06865e86b6","source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/f1949c1f9758947ade984c895ff16bef46f56520","source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://groups.google.com/g/django-announce","source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://www.djangoproject.com/weblog/2026/aug/04/security-releases/","source":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"}]}},{"cve":{"id":"CVE-2026-58072","sourceIdentifier":"support@hackerone.com","published":"2026-08-04T17:16:56.633","lastModified":"2026-08-05T05:17:01.967","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"Veeam","product":"Service Provider Console","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"9.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"support@hackerone.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-58072","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.veeam.com/kb4893","source":"support@hackerone.com"}]}},{"cve":{"id":"CVE-2026-58073","sourceIdentifier":"support@hackerone.com","published":"2026-08-04T17:16:56.930","lastModified":"2026-08-05T05:17:02.413","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"Veeam","product":"Service Provider Console","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"9.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"support@hackerone.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.5,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-58073","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]}],"references":[{"url":"https://www.veeam.com/kb4893","source":"support@hackerone.com"}]}},{"cve":{"id":"CVE-2026-58074","sourceIdentifier":"support@hackerone.com","published":"2026-08-04T17:16:57.067","lastModified":"2026-08-05T05:17:02.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability allowing a high-privileged user to execute arbitrary code on the server."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"Veeam","product":"ONE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"13.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"support@hackerone.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-58074","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.veeam.com/kb4892","source":"support@hackerone.com"}]}},{"cve":{"id":"CVE-2026-58075","sourceIdentifier":"support@hackerone.com","published":"2026-08-04T17:16:57.190","lastModified":"2026-08-05T05:17:03.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"Veeam","product":"ONE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"13.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"support@hackerone.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-58075","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://www.veeam.com/kb4892","source":"support@hackerone.com"}]}},{"cve":{"id":"CVE-2026-64633","sourceIdentifier":"support@hackerone.com","published":"2026-08-04T17:16:58.227","lastModified":"2026-08-05T05:17:05.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability allowing remote unauthenticated code execution on the agent host."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"Veeam","product":"ONE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"13.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"support@hackerone.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-64633","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.veeam.com/kb4892","source":"support@hackerone.com"}]}},{"cve":{"id":"CVE-2026-64634","sourceIdentifier":"support@hackerone.com","published":"2026-08-04T17:16:58.347","lastModified":"2026-08-05T05:17:06.107","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability allowing local privilege escalation to the Reporter service context."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"Veeam","product":"ONE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"13.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"support@hackerone.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-64634","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://www.veeam.com/kb4892","source":"support@hackerone.com"}]}},{"cve":{"id":"CVE-2026-0163","sourceIdentifier":"dsap-vuln-management@google.com","published":"2026-08-04T19:16:39.213","lastModified":"2026-08-05T05:16:45.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."}],"affected":[{"source":"dsap-vuln-management@google.com","affectedData":[{"vendor":"Google","product":"Android","defaultStatus":"unaffected","versions":[{"version":"Android kernel","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-0163","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-08-01","source":"dsap-vuln-management@google.com"}]}},{"cve":{"id":"CVE-2026-18657","sourceIdentifier":"ff89ba41-3aa1-4d27-914a-91399e9639e5","published":"2026-08-04T20:16:50.570","lastModified":"2026-08-05T05:16:47.880","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in the directory.\n\n\n\nTo remediate this issue, users should upgrade to version 2.10.0 or higher."}],"affected":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","affectedData":[{"vendor":"Amazon","product":"Kiro CLI","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.10.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-18657","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","description":[{"lang":"en","value":"CWE-427"}]}],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-074-aws/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://kiro.dev/changelog/cli/2-10/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}]}},{"cve":{"id":"CVE-2026-18900","sourceIdentifier":"cna@vuldb.com","published":"2026-08-05T05:16:49.243","lastModified":"2026-08-05T05:16:49.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"H3C","product":"NX15","cpes":["cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:*"],"modules":["Backend RPC"],"versions":[{"version":"V100R017","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:M/C:C/I:C/A:C","baseScore":8.3,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"MULTIPLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.4,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-77"},{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/file_exec_root_rce/poc/postauth_file_exec_rce.py","source":"cna@vuldb.com"},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/file_exec_root_rce/report/postauth_file_exec_rce_report.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-18900","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/857814","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385934","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385934/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-18901","sourceIdentifier":"cna@vuldb.com","published":"2026-08-05T05:16:49.433","lastModified":"2026-08-05T05:16:49.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"H3C","product":"NX15","cpes":["cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:*"],"modules":["Web API"],"versions":[{"version":"V100R017","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:M/C:C/I:C/A:C","baseScore":8.3,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"MULTIPLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.4,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-749"}]}],"references":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/service_add_root_rce_chain/poc/postauth_service_add_rce.py","source":"cna@vuldb.com"},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce_chain/report","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-18901","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/857817","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385935","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385935/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-11421","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:36.387","lastModified":"2026-08-05T06:16:36.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wedevs","product":"ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.17.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/includes/functions-people.php#L203","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/includes/functions-people.php#L228","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/CRM.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/includes/AjaxHandler.php#L180","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/erp/tags/1.17.4/modules/crm/includes/functions-customer.php#L2376","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3577284%40erp%2Ftrunk%2Fmodules%2Fcrm%2Fincludes%2Ffunctions-customer.php&old=3479082%40erp%2Ftrunk%2Fmodules%2Fcrm%2Fincludes%2Ffunctions-customer.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c8f3c96b-9a78-47cb-9266-ff87d9409160?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15918","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:36.587","lastModified":"2026-08-05T06:16:36.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. No authentication or special privileges are required"}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"e4jvikwp","product":"VikAppointments Services Booking Calendar","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.2.19","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/lib.vikappointments.php#L5907","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/helpers/lib.vikappointments.php#L6011","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/views/employeesearch/view.html.php#L74","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/vikappointments/tags/1.2.19/site/views/servicesearch/view.html.php#L80","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3d1e49cf-86ac-4368-800a-4e46f72c975d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15941","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:36.740","lastModified":"2026-08-05T06:16:36.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"Relevanssi","product":"Relevanssi Premium – A Better Search","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.30.2","versionType":"semver","status":"affected"}]},{"vendor":"comesio","product":"Relevanssi – A Better Search","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.27.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/admin-ajax.php#L195","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search-tax-query.php#L411","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search.php#L969","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4f96b87a-1405-4cf6-b903-ad0c7c8e2826?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16143","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:36.880","lastModified":"2026-08-05T06:16:36.880","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"e4jvikwp","product":"VikRentItems Flexible Rental Management System","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/admin/views/editorder/tmpl/default.php#L499","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/site/controller.php#L389","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3617300/vikrentitems/trunk/admin/views/editorder/tmpl/default.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/197760d1-395d-4dfb-aaa7-5fc5fc0a1ecb?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18322","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:37.330","lastModified":"2026-08-05T06:16:37.330","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"supsysticcom","product":"Smart Popup by Supsystic","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.12.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/classes/frame.php#L180","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/popup/models/popup.php#L316","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L292","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L358","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L440","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3629986%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&old=3628131%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/835579b0-8a96-40fa-a6a3-30571a0a1d0a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18902","sourceIdentifier":"cna@vuldb.com","published":"2026-08-05T06:16:37.490","lastModified":"2026-08-05T06:16:37.490","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"H3C","product":"NX15","cpes":["cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:*"],"versions":[{"version":"V100R017","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:M/C:C/I:C/A:C","baseScore":8.3,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"MULTIPLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.4,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py","source":"cna@vuldb.com"},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-18902","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/857833","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385936","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385936/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-18903","sourceIdentifier":"cna@vuldb.com","published":"2026-08-05T06:16:37.710","lastModified":"2026-08-05T06:16:37.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument path causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"yeqifu","product":"warehouse","cpes":["cpe:2.3:a:yeqifu:warehouse:*:*:*:*:*:*:*:*"],"versions":[{"version":"aaf29962ba407d22d991781de28796ee7b4670e4","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://fanatical-brain-9ba.notion.site/warehouse-381f1a573df48073ae69fd68e2c27b69","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-18903","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/859531","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385940","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/385940/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-55707","sourceIdentifier":"cve@mitre.org","published":"2026-08-05T06:16:37.903","lastModified":"2026-08-05T06:16:37.903","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"OpenStack","product":"Neutron","defaultStatus":"unaffected","repo":"https://opendev.org/openstack/neutron","versions":[{"version":"14.0.0","lessThan":"26.0.6","versionType":"semver","status":"affected"},{"version":"27.0.0","lessThan":"27.0.4","versionType":"semver","status":"affected"},{"version":"28.0.0","lessThan":"28.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://launchpad.net/bugs/2152113","source":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2026-032.html","source":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2026/07/29/5","source":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/29/5","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-5062","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:38.097","lastModified":"2026-08-05T06:16:38.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `search_links_table()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"supercleanse","product":"PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.6.20","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/pretty-link/tags/3.6.20/app/controllers/PrliLinksController.php#L1047","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pretty-link/tags/3.6.20/app/controllers/PrliLinksController.php#L1051","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3493031%40pretty-link%2Ftrunk&old=3444399%40pretty-link%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a2399535-c293-4b06-8ef4-1706bbe12bf7?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-66344","sourceIdentifier":"vultures@jpcert.or.jp","published":"2026-08-05T06:16:38.783","lastModified":"2026-08-05T06:16:38.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"Integrated Systems Technologies, Inc.","product":"NetKids iMark","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"V5.2.5.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV30":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Primary","description":[{"lang":"en","value":"CWE-427"}]}],"references":[{"url":"https://jvn.jp/en/jp/JVN28045338/","source":"vultures@jpcert.or.jp"},{"url":"https://www.istinc.co.jp/dl/jpc/%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9%E3%81%AE%E5%AE%9F%E8%A1%8C%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%83%91%E3%82%B9%E3%81%8C%E5%BC%95%E7%94%A8%E7%AC%A6%E3%81%A7%E5%9B%B2%E3%81%BE%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E3%82%88%E3%82%8B%E6%A8%A9%E9%99%90%E6%98%87%E6%A0%BC%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","source":"vultures@jpcert.or.jp"},{"url":"https://www.istinc.co.jp/dl/jpc/DLL%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%81%AE%E8%AA%AD%E3%81%BF%E8%BE%BC%E3%81%BF%E3%81%8A%E3%82%88%E3%81%B3%E3%82%A4%E3%83%B3%E3%82%B9%E3%83%88%E3%83%BC%E3%83%AB%E3%83%95%E3%82%A9%E3%83%AB%E3%83%80%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E6%A8%A9%E9%99%90%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","source":"vultures@jpcert.or.jp"}]}},{"cve":{"id":"CVE-2026-66839","sourceIdentifier":"vultures@jpcert.or.jp","published":"2026-08-05T06:16:38.980","lastModified":"2026-08-05T06:16:38.980","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"Integrated Systems Technologies, Inc.","product":"NetKids iMark","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"V5.2.5.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV30":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Primary","description":[{"lang":"en","value":"CWE-428"}]}],"references":[{"url":"https://jvn.jp/en/jp/JVN28045338/","source":"vultures@jpcert.or.jp"},{"url":"https://www.istinc.co.jp/dl/jpc/%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9%E3%81%AE%E5%AE%9F%E8%A1%8C%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%83%91%E3%82%B9%E3%81%8C%E5%BC%95%E7%94%A8%E7%AC%A6%E3%81%A7%E5%9B%B2%E3%81%BE%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E3%82%88%E3%82%8B%E6%A8%A9%E9%99%90%E6%98%87%E6%A0%BC%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","source":"vultures@jpcert.or.jp"},{"url":"https://www.istinc.co.jp/dl/jpc/DLL%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%81%AE%E8%AA%AD%E3%81%BF%E8%BE%BC%E3%81%BF%E3%81%8A%E3%82%88%E3%81%B3%E3%82%A4%E3%83%B3%E3%82%B9%E3%83%88%E3%83%BC%E3%83%AB%E3%83%95%E3%82%A9%E3%83%AB%E3%83%80%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E6%A8%A9%E9%99%90%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf","source":"vultures@jpcert.or.jp"}]}},{"cve":{"id":"CVE-2026-71190","sourceIdentifier":"cve@mitre.org","published":"2026-08-05T06:16:40.023","lastModified":"2026-08-05T06:16:40.023","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The \"qdtext\" pattern (?:[^\"]|\\\\.)* allows an unauthenticated remote attacker to send a crafted Accept header that causes exponential CPU consumption in the proxy worker. A payload of 32 backslash-character pairs exceeds 30 seconds of CPU time. No authentication is required. Repeated requests can exhaust all proxy worker threads, resulting in a complete denial of service."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"OpenStack","product":"Swift","defaultStatus":"unaffected","repo":"https://opendev.org/openstack/swift","versions":[{"version":"1.9.1","lessThan":"2.35.4","versionType":"semver","status":"affected"},{"version":"2.36.0","lessThan":"2.36.3","versionType":"semver","status":"affected"},{"version":"2.37.0","lessThan":"2.37.3","versionType":"semver","status":"affected"},{"version":"2.38.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-1333"}]}],"references":[{"url":"https://launchpad.net/bugs/2158771","source":"cve@mitre.org"},{"url":"https://openwall.com/lists/oss-security/2026/07/28/27","source":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2026-031.html","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-71191","sourceIdentifier":"cve@mitre.org","published":"2026-08-05T06:16:40.180","lastModified":"2026-08-05T06:16:40.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"OpenStack","product":"Swift","defaultStatus":"unaffected","repo":"https://opendev.org/openstack/swift","versions":[{"version":"2.18.0","lessThan":"2.35.4","versionType":"semver","status":"affected"},{"version":"2.36.0","lessThan":"2.36.3","versionType":"semver","status":"affected"},{"version":"2.37.0","lessThan":"2.37.3","versionType":"semver","status":"affected"},{"version":"2.38.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://launchpad.net/bugs/2158733","source":"cve@mitre.org"},{"url":"https://openwall.com/lists/oss-security/2026/07/28/26","source":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2026-030.html","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-71192","sourceIdentifier":"cve@mitre.org","published":"2026-08-05T06:16:40.333","lastModified":"2026-08-05T06:16:40.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An\nattacker can inject these headers into a signed PUT request targeting their own bucket, causing Swift to perform a server-side copy from another tenant's private object. The source object authorization is bypassed because the S3API middleware has already authorized the request against the destination. The attacker can read any object whose project_id, container name, and object name are known, regardless of the source object's ACLs or ownership. This requires the non-default s3_acl=true configuration."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"OpenStack","product":"Swift","defaultStatus":"unaffected","repo":"https://opendev.org/openstack/swift","versions":[{"version":"2.18.0","lessThan":"2.35.4","versionType":"semver","status":"affected"},{"version":"2.36.0","lessThan":"2.36.3","versionType":"semver","status":"affected"},{"version":"2.37.0","lessThan":"2.37.3","versionType":"semver","status":"affected"},{"version":"2.38.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://launchpad.net/bugs/2158733","source":"cve@mitre.org"},{"url":"https://openwall.com/lists/oss-security/2026/07/28/26","source":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2026-030.html","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-7753","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:40.500","lastModified":"2026-08-05T06:16:40.500","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX action (handler `CCBExportImport::export_calculators()`) in all versions up to, and including, 3.6.17. The handler only verifies a nonce, but the corresponding `ccb_export_nonce` is broadcast on every wp-admin page (including pages reachable to Subscribers, such as `/wp-admin/profile.php`) by the `ccb_add_admin_nonces` callback hooked to `admin_head`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export every calculator's full configuration — including stored Stripe secret keys, PayPal client secrets, Razorpay secret keys, webhook secret keys, and reCAPTCHA secret keys."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"stylemix","product":"Cost Calculator Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.6.17","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/classes/CCBExportImport.php#L308","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L129","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L24","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.17/includes/install.php#L77","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cost-calculator-builder/trunk/includes/classes/CCBExportImport.php#L308","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3531960%40cost-calculator-builder%2Ftrunk&old=3528688%40cost-calculator-builder%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/89de168e-1bce-4e11-a765-afc1d7dce8fe?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-8761","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:40.660","lastModified":"2026-08-05T06:16:40.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` capability check with a vendor-only check that inspects the **requesting** user's role and never validates the **target** user. This makes it possible for authenticated attackers with Vendor/Seller-level access and above to read, modify, or delete any WordPress user — including administrators — via `GET`/`PUT`/`DELETE` requests against `/wp-json/dokan/v1/customers/{id}`. Setting the `password` parameter on an administrator's record yields a full site takeover."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"dokaninc","product":"Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy","defaultStatus":"unaffected","versions":[{"version":"<=5.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L280","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L281","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L60","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/tags/5.0.1/includes/REST/CustomersController.php#L80","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L280","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L281","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L60","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/dokan-lite/trunk/includes/REST/CustomersController.php#L80","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3541712%40dokan-lite%2Ftags%2F5.0.3&old=3535602%40dokan-lite%2Ftags%2F5.0.2","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/24666f75-9179-4043-841b-4dd83be078e8?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-8790","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:40.810","lastModified":"2026-08-05T06:16:40.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext` is empty, or the user is unable to save), the raw POST value is echoed back into a `<textarea>` element using `printf('%s', ...)` with no HTML escaping. This makes it possible for unauthenticated attackers to execute arbitrary web scripts in the browser of an authenticated victim (Subscriber-level or higher) who is tricked into submitting a crafted POST request to a page that contains the Shoutbox widget."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"antoineh","product":"Football Pool","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.13.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L127","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L142","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-pool/tags/2.13.4/widgets/widget-football-pool-shoutbox.php#L84","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L127","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L142","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/football-pool/trunk/widgets/widget-football-pool-shoutbox.php#L84","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3538628/football-pool/trunk/widgets/widget-football-pool-shoutbox.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c5d17538-30ff-423c-bd61-d85a3f5aba74?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-9273","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T06:16:40.967","lastModified":"2026-08-05T06:16:40.967","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"stellarwp","product":"Membership Plugin – Kadence Memberships","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.8}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-640"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L207","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L243","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L306","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L243","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L306","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3549742%40restrict-content%2Ftags%2F4.0.1&old=3529319%40restrict-content%2Ftags%2F4.0.0","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca38c423-2df8-4f20-bd95-2ecd84167a7f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2025-15677","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:33.493","lastModified":"2026-08-05T07:16:33.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GeoDirectory  WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup)."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"GeoDirectory","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.8.110","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/bb6daced-3ee3-4ec7-a221-9981cd85285a/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14553","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:34.787","lastModified":"2026-08-05T07:16:34.787","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"zportals","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.3.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/02c83708-8f2f-48f8-b73e-df37a42ab360/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15210","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:34.897","lastModified":"2026-08-05T07:16:34.897","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"OTP Login With Phone Number, OTP Verification","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.8.71","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/96101127-8b13-4770-9204-f540fb044040/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15230","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.010","lastModified":"2026-08-05T07:16:35.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The YayPricing  WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"YayPricing","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.5.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c2346f90-130c-45da-92ca-31acaa2f4605/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15360","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.123","lastModified":"2026-08-05T07:16:35.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Ajax Load More  WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Ajax Load More","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"8.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/0b5c1dd6-8bb9-45f7-8237-84a43ef53ec4/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15372","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.237","lastModified":"2026-08-05T07:16:35.237","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WP 2FA  WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"WP 2FA","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/a8d697c9-6de4-4a28-be9e-7d42abcb6c7e/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16036","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.350","lastModified":"2026-08-05T07:16:35.350","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The miniOrange 2FA  WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"miniOrange 2FA","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.2.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/cffa0566-7fcc-40f0-9e4c-f1c3abaa5eb0/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16055","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.463","lastModified":"2026-08-05T07:16:35.463","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Contest Gallery  WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery  WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Contest Gallery","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"30.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/fa83e5a0-ed6a-4043-8df3-8654bb354a99/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16561","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.570","lastModified":"2026-08-05T07:16:35.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Sunshine Photo Cart  WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Sunshine Photo Cart","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.6.12","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/25bbf054-3b3f-4d88-899e-03d48055cbcd/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16573","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.683","lastModified":"2026-08-05T07:16:35.683","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Bit Form  WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to upload a crafted SVG file containing JavaScript that executes when the file is viewed, leading to Stored Cross-Site Scripting."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Bit Form","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/a102e6ba-02f3-46cf-b496-f129ea3d9c8f/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16583","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.783","lastModified":"2026-08-05T07:16:35.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files when its SVG upload feature is enabled, allowing authenticated users with the upload capability (Author and above by default, without the unfiltered_html capability) to upload SVG files containing JavaScript that executes in the site context when the file is viewed, leading to Stored Cross-Site Scripting."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More","defaultStatus":"unaffected","versions":[{"version":"3.0.0","lessThan":"3.0.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/29b2b8af-2fd9-40f1-8843-d0f16cfb706b/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16602","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:35.893","lastModified":"2026-08-05T07:16:35.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Passster  WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Passster","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.3.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/fcca0d1c-1a5b-4515-8182-d68f0759b978/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16603","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.003","lastModified":"2026-08-05T07:16:36.003","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Passster  WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Passster","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.3.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/ec56a66e-e98a-4260-a0af-3ef6905ce839/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16604","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.107","lastModified":"2026-08-05T07:16:36.107","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Passster  WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Passster","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.3.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/6a3222e3-352f-4fe8-b17f-b2980c3528e4/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16605","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.217","lastModified":"2026-08-05T07:16:36.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MultiVendorX  WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MultiVendorX","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/e31c9bf0-7340-4bd7-ad6e-6ad01737654a/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16613","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.323","lastModified":"2026-08-05T07:16:36.323","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GDPR Cookie Compliance  WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"GDPR Cookie Compliance","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/d9511e8a-be67-4c39-b947-7931b5569ffb/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16736","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.433","lastModified":"2026-08-05T07:16:36.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The User Registration & Membership  WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"User Registration & Membership","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.2.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/dc0d63d6-bcd9-4f14-865a-49d254a831a2/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16746","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.540","lastModified":"2026-08-05T07:16:36.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MultiVendorX  WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MultiVendorX","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/721033a0-b0bb-4a64-a99a-12ac416b20fd/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16940","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.650","lastModified":"2026-08-05T07:16:36.650","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site takeover."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Custom Fields","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/a315a6ac-3ffb-4735-92ca-6e85338f8807/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16942","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.770","lastModified":"2026-08-05T07:16:36.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"WP Custom HTML Page","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"0.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/cda6b957-2013-4707-a5b5-5ddc04be2f6a/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16968","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.877","lastModified":"2026-08-05T07:16:36.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The GeoDirectory  WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"GeoDirectory","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.8.168","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/d7a4e3ee-507d-44fb-9386-27ad67158cdc/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16981","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:36.983","lastModified":"2026-08-05T07:16:36.983","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequential ids and download every stored shipping label, each containing the customer's full name, complete postal address, and order reference."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"DHL Shipping Germany for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/61b3228d-50a0-4928-977a-23448939dff9/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16993","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:37.097","lastModified":"2026-08-05T07:16:37.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"DHL Shipping Germany for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/efcf57b5-f35e-4943-8a49-350aa8bf1b8a/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-17515","sourceIdentifier":"contact@wpscan.com","published":"2026-08-05T07:16:37.207","lastModified":"2026-08-05T07:16:37.207","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.0.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/8c8da95c-df83-4788-bcb2-ca924a60f909/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-70374","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T07:16:39.567","lastModified":"2026-08-05T07:16:39.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in getMIMEType() (src/Common/utilities.js) truncates the extracted extension at the first '?' character, while Path.extname() does not, allowing a filename such as 'x.jpg?$(command)' to pass the image-type check while still injecting a shell command substitution into the exec() call. An authenticated user holding the media resource scope can achieve arbitrary OS command execution in the context of the Node.js process via POST /api/{project}/{environment}/media/new."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"HashBrownCMS","product":"hashbrown-cms","defaultStatus":"unknown","programFiles":["src/Server/Entity/Resource/Media.js","src/Common/utilities.js"],"repo":"https://github.com/HashBrownCMS/hashbrown-cms","versions":[{"version":"0","lessThanOrEqual":"1.4.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://cve.turansec.uz/advisories/TRN-11FC0D88","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"},{"url":"https://github.com/HashBrownCMS/hashbrown-cms","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-70375","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T07:16:39.697","lastModified":"2026-08-05T07:16:39.697","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), interpolating the configured branch value directly into a shell command with no escaping. GitDeployer.validate() only rejects a single-quote character in the repo, branch, username, and password fields; shell metacharacters such as ';', '&&', '|', backticks, and '$()' are not filtered. A user able to configure a project's Git deployer settings can set a malicious branch value (e.g. 'master;<command>#') that executes automatically on every subsequent deployer operation (media upload, content save, etc.), since pullRepo() is invoked unconditionally at the start of each such operation. This is related to CVE-2020-6948, which addressed single-quote escaping of the repo, username, and password fields in the same file's git clone invocation; the branch field used in the unquoted git checkout command was not covered by that fix and remains injectable."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"HashBrownCMS","product":"hashbrown-cms","defaultStatus":"unknown","programFiles":["src/Server/Entity/Deployer/GitDeployer.js"],"repo":"https://github.com/HashBrownCMS/hashbrown-cms","versions":[{"version":"0","lessThanOrEqual":"1.4.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://cve.turansec.uz/advisories/TRN-B571F773","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"},{"url":"https://github.com/HashBrownCMS/hashbrown-cms","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71201","sourceIdentifier":"cve@mitre.org","published":"2026-08-05T07:16:39.813","lastModified":"2026-08-05T07:16:39.813","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"OpenStack","product":"Ironic","defaultStatus":"unaffected","versions":[{"version":"1.0.0","lessThanOrEqual":"29.0.6","versionType":"semver","status":"affected"},{"version":"30.0.0","lessThanOrEqual":"32.0.1","versionType":"semver","status":"affected"},{"version":"33.0.0","lessThanOrEqual":"35.0.1","versionType":"semver","status":"affected"},{"version":"36.0.0","lessThanOrEqual":"38.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://bugs.launchpad.net/ironic/+bug/2162715","source":"cve@mitre.org"}]}}]}