{"resultsPerPage":10,"startIndex":0,"totalResults":10,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-09T17:30:07.332","vulnerabilities":[{"cve":{"id":"CVE-2026-18651","sourceIdentifier":"secalert@redhat.com","published":"2026-08-03T16:16:29.073","lastModified":"2026-08-09T13:54:50.200","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Directory Server 11","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds-base","cpes":["cpe:/a:redhat:directory_server:11"]},{"vendor":"Red Hat","product":"Red Hat Directory Server 12","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds-base","cpes":["cpe:/a:redhat:directory_server:12"]},{"vendor":"Red Hat","product":"Red Hat Directory Server 13","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds-base","cpes":["cpe:/a:redhat:directory_server:13"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds-base","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds-base","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds-base","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds:1.4/389-ds-base","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"389-ds-base","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-03T16:58:38.923285Z","id":"CVE-2026-18651","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:directory_server:11.0:*:*:*:*:*:*:*","matchCriteriaId":"2A169F6D-88A5-4631-9D30-519350ACFE6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:directory_server:12.0:*:*:*:*:*:*:*","matchCriteriaId":"A3DAF61A-58A9-41A6-A4DC-64148055B0C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:directory_server:13.0:*:*:*:*:*:*:*","matchCriteriaId":"904002F4-762C-4CFF-88C4-8FC929774DF8"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:389_directory_server:-:*:*:*:*:*:*:*","matchCriteriaId":"A861110D-0BBC-4052-BBFD-F718F6CD72C5"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"142AD0DD-4CF3-4D74-9442-459CE3347E3A"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"F4CFF558-3C47-480D-A2F0-BABF26042943"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"7F6FB57C-2BC7-487C-96DD-132683AEB35D"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"D65C2163-CFC2-4ABB-8F4E-CB09CEBD006C"}]}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-18651","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510617","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-62870","sourceIdentifier":"secure@microsoft.com","published":"2026-08-04T00:17:37.813","lastModified":"2026-08-09T14:32:17.837","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft 365 Apps for Enterprise","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.1","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Excel 2016","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.0.0","lessThan":"16.0.5561.1001","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Office 2019","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"19.0.0","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Office LTSC 2021","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.1","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft Office LTSC 2024","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"16.0.0","lessThan":"https://aka.ms/OfficeSecurityReleases","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T00:00:00+00:00","id":"CVE-2026-62870","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*","matchCriteriaId":"3259EBFE-AE2D-48B8-BE9A-E22BBDB31378"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*","matchCriteriaId":"CD25F492-9272-4836-832C-8439EBE64CCF"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x64:*","matchCriteriaId":"CD88F667-6773-4DB7-B6C3-9C7B769C0808"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:x86:*","matchCriteriaId":"B342EF98-B414-44D0-BAFB-FCA24294EECE"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*","matchCriteriaId":"241CDE2B-ABD0-4EFF-8D73-1766E32FA20F"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*","matchCriteriaId":"14D63E3F-A431-4DD8-979F-811E8DAC423D"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*","matchCriteriaId":"1D518075-3362-4D15-93B1-0E6C61518D16"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*","matchCriteriaId":"1059BEC6-C30B-4F0F-A878-5267A21CBD85"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*","matchCriteriaId":"55A9AFDA-D77B-4CC7-ACE5-3A2ABDA257D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*","matchCriteriaId":"8887D177-26A3-4008-89B6-50A9E9830F13"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62870","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-11368","sourceIdentifier":"vulnerabilities@zephyrproject.org","published":"2026-08-04T15:16:24.843","lastModified":"2026-08-09T14:26:15.890","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the completion handling to the system workqueue (att_tx_destroy -> att_tx_destroy_work_handler -> att_on_sent_cb -> bt_att_sent), where bt_att_sent dereferences the channel and its ATT context (sys_slist_get(&att->reqs)).\n\nWhen a peer disconnects while an ATT PDU (a server notification/indication or any response) is still in flight in the controller TX path, L2CAP tears the channel down in l2cap_chan_del(): it runs the disconnected callback and then the released callback (bt_att_released), which frees the channel slab slot. Because the in-flight buffer is held by the connection TX path rather than the channel's own queue, its deferred destroy work can run after the channel has been freed. The att_on_sent_cb guard intended to drop the stale callback itself dereferences meta->att_chan, which is now a dangling pointer into a freed (and possibly reused) slab slot.\n\nA remote peer with an ATT connection can drive this by disconnecting during routine ATT traffic; no pairing or user interaction is required to reach the ATT bearer. The result is a use-after-free read/write of freed channel memory, reliably crashing the Bluetooth host (denial of service) and, because the channel slab slot may be reused, potentially corrupting live memory.\n\nThe fix makes bt_att_released() NULL the att_chan field of every tx_meta_data_storage[] entry still referencing the channel before freeing it, so the deferred guard observes a NULL pointer and drops the callback. Teardown and the destroy work both run on the cooperative system workqueue, so the array update is serialized and needs no lock."}],"affected":[{"source":"vulnerabilities@zephyrproject.org","affectedData":[{"vendor":"zephyrproject","product":"zephyr","defaultStatus":"unaffected","collectionURL":"https://github.com/zephyrproject-rtos/zephyr","packageName":"zephyr","programFiles":["subsys/bluetooth/host/att.c"],"versions":[{"version":"4.4.0","lessThan":"4.5.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"vulnerabilities@zephyrproject.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-04T17:56:36.608577Z","id":"CVE-2026-11368","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vulnerabilities@zephyrproject.org","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*","versionStartIncluding":"4.4.0","versionEndExcluding":"4.5.0","matchCriteriaId":"FB84D027-409D-4419-BE61-FF6982D53EFB"}]}]}],"references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/dfdea9bad8d9b5b31c125e97fcffb549f2217caa","source":"vulnerabilities@zephyrproject.org","tags":["Patch"]},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-85vg-gwc4-77g7","source":"vulnerabilities@zephyrproject.org","tags":["Exploit","Patch","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-10302","sourceIdentifier":"ed10eef1-636d-4fbe-9993-6890dfa878f8","published":"2026-08-06T08:16:26.920","lastModified":"2026-08-09T14:25:39.260","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes.\n\nAllowing unvalidated input into user claims can lead to various security risks. Malicious or malformed data injected during signup could be processed by other parts of the application, potentially enabling attacks such as content manipulation, redirection, user interface inconsistencies, unauthorized actions, and data exposure. The actual impact depends on how the compromised data is consumed and the privileges associated with the affected users."}],"affected":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","affectedData":[{"vendor":"WSO2","product":"WSO2 API Control Plane","defaultStatus":"unaffected","versions":[{"version":"4.5.0","lessThan":"4.5.0.10","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Traffic Manager","defaultStatus":"unaffected","versions":[{"version":"4.5.0","lessThan":"4.5.0.9","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Universal Gateway","defaultStatus":"unaffected","versions":[{"version":"4.5.0","lessThan":"4.5.0.9","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 API Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.1.0","versionType":"custom","status":"unknown"},{"version":"3.1.0","lessThan":"3.1.0.331","versionType":"custom","status":"affected"},{"version":"3.2.0","lessThan":"3.2.0.427","versionType":"custom","status":"affected"},{"version":"3.2.1","lessThan":"3.2.1.39","versionType":"custom","status":"affected"},{"version":"4.0.0","lessThan":"4.0.0.318","versionType":"custom","status":"affected"},{"version":"4.1.0","lessThan":"4.1.0.200","versionType":"custom","status":"affected"},{"version":"4.2.0","lessThan":"4.2.0.138","versionType":"custom","status":"affected"},{"version":"4.3.0","lessThan":"4.3.0.51","versionType":"custom","status":"affected"},{"version":"4.5.0","lessThan":"4.5.0.9","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Open Banking IAM","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.0","versionType":"custom","status":"unknown"},{"version":"2.0.0","lessThan":"2.0.0.400","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Identity Server as Key Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.10.0","versionType":"custom","status":"unknown"},{"version":"5.10.0","lessThan":"5.10.0.351","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Identity Server","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.10.0","versionType":"custom","status":"unknown"},{"version":"5.10.0","lessThan":"5.10.0.358","versionType":"custom","status":"affected"},{"version":"5.11.0","lessThan":"5.11.0.379","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Carbon Identity Recovery Management","defaultStatus":"unknown","packageName":"org.wso2.carbon.identity.governance:org.wso2.carbon.identity.recovery","versions":[{"version":"1.4.1","lessThan":"1.4.1.72","versionType":"custom","status":"affected"},{"version":"1.4.72","lessThan":"1.4.72.68","versionType":"custom","status":"affected"},{"version":"1.4.100","lessThan":"1.4.100.8","versionType":"custom","status":"affected"},{"version":"1.4.102","lessThan":"1.4.102.2","versionType":"custom","status":"affected"},{"version":"1.7.2","lessThan":"1.7.2.4","versionType":"custom","status":"affected"},{"version":"1.8.107","lessThan":"1.8.107.2","versionType":"custom","status":"affected"},{"version":"1.8.108","lessThan":"1.8.108.4","versionType":"custom","status":"affected"},{"version":"1.6.380","lessThanOrEqual":"1.6.*","versionType":"custom","status":"unaffected"},{"version":"1.8.109","lessThanOrEqual":"*","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-06T12:34:51.949840Z","id":"CVE-2024-10302","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_control_plane:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"E492668B-C015-43BE-B395-3D826B45DF12"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"1344FB79-0796-445C-A8F3-C03E995925D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*","matchCriteriaId":"E31E32CD-497E-4EF5-B3FC-8718EE06EDAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"B58251E8-606B-47C8-8E50-9F9FC8C179BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.0.0:*:*:*:*:*:*:*","matchCriteriaId":"E21D7ABF-C328-425D-B914-618C7628220B"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.1.0:*:*:*:*:*:*:*","matchCriteriaId":"1C1165F9-F8C5-4053-B012-E161D0F47424"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.2.0:*:*:*:*:*:*:*","matchCriteriaId":"ABAA8BD3-9F46-42C5-AA2A-F47B2932D0CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.3.0:*:*:*:*:*:*:*","matchCriteriaId":"5B668BAF-313C-44B0-9F7D-C69743A3136E"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"865443F0-6F44-485C-AAE3-5AFDA5E9C49C"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*","matchCriteriaId":"F4F126CA-A2F9-44F4-968B-DF71765869E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*","matchCriteriaId":"2153AECE-020A-4C01-B2A6-F9F5D98E7EBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*","matchCriteriaId":"6BB34405-A2F1-461A-B51B-E103BB3680A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"D7C241A3-8EA0-41E4-ABF3-21B9D8E7A5BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:traffic_manager:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"C7413107-D7B2-49AE-AC46-52E7BFCD6ED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:universal_gateway:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"61636553-C25E-44DF-93D7-EB3E1056D1DC"}]}]}],"references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3740/","source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-6832","sourceIdentifier":"ed10eef1-636d-4fbe-9993-6890dfa878f8","published":"2026-08-06T08:16:27.533","lastModified":"2026-08-09T14:14:01.077","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores.\n\nWhen the account locking mechanism is bypassed due to the inaccessibility of secondary user stores, users in accessible user stores are left vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations against a user account without the expected account lockout consequence."}],"affected":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","affectedData":[{"vendor":"WSO2","product":"WSO2 Enterprise Integrator","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.6.0","versionType":"custom","status":"unknown"},{"version":"6.6.0","lessThan":"6.6.0.229","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 API Control Plane","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.5.0","versionType":"custom","status":"unknown"},{"version":"4.5.0","lessThan":"4.5.0.40","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.4","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.5","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Traffic Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.5.0","versionType":"custom","status":"unknown"},{"version":"4.5.0","lessThan":"4.5.0.38","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.4","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.5","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Universal Gateway","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.5.0","versionType":"custom","status":"unknown"},{"version":"4.5.0","lessThan":"4.5.0.38","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.4","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.5","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 API Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.1.0","versionType":"custom","status":"unknown"},{"version":"3.1.0","lessThan":"3.1.0.296","versionType":"custom","status":"affected"},{"version":"3.2.0","lessThan":"3.2.0.386","versionType":"custom","status":"affected"},{"version":"3.2.0","lessThan":"3.2.0.455","versionType":"custom","status":"affected"},{"version":"3.2.1","lessThan":"3.2.1.74","versionType":"custom","status":"affected"},{"version":"4.1.0","lessThan":"4.1.0.238","versionType":"custom","status":"affected"},{"version":"4.2.0","lessThan":"4.2.0.179","versionType":"custom","status":"affected"},{"version":"4.3.0","lessThan":"4.3.0.91","versionType":"custom","status":"affected"},{"version":"4.4.0","lessThan":"4.4.0.55","versionType":"custom","status":"affected"},{"version":"4.5.0","lessThan":"4.5.0.39","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.4","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Identity Server","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.10.0","versionType":"custom","status":"unknown"},{"version":"5.10.0","lessThan":"5.10.0.320","versionType":"custom","status":"affected"},{"version":"5.11.0","lessThan":"5.11.0.427","versionType":"custom","status":"affected"},{"version":"6.0.0","lessThan":"6.0.0.254","versionType":"custom","status":"affected"},{"version":"6.1.0","lessThan":"6.1.0.195","versionType":"custom","status":"affected"},{"version":"7.0.0","lessThan":"7.0.0.82","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Identity Server as Key Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.10.0","versionType":"custom","status":"unknown"},{"version":"5.10.0","lessThan":"5.10.0.314","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Open Banking IAM","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.0","versionType":"custom","status":"unknown"},{"version":"2.0.0","lessThan":"2.0.0.366","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Open Banking AM","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.0","versionType":"custom","status":"unknown"},{"version":"2.0.0","lessThan":"2.0.0.345","versionType":"custom","status":"affected"}]},{"vendor":"WSO2","product":"WSO2 Carbon User Manager Kernel","defaultStatus":"unknown","packageName":"org.wso2.carbon:org.wso2.carbon.user.core","versions":[{"version":"4.5.0","lessThan":"4.5.0.7","versionType":"custom","status":"affected"},{"version":"4.5.3","lessThan":"4.5.3.53","versionType":"custom","status":"affected"},{"version":"4.6.0","lessThan":"4.6.0.196","versionType":"custom","status":"affected"},{"version":"4.6.1","lessThan":"4.6.1.163","versionType":"custom","status":"affected"},{"version":"4.6.1","lessThan":"4.6.1.164","versionType":"custom","status":"affected"},{"version":"4.6.3","lessThan":"4.6.3.44","versionType":"custom","status":"affected"},{"version":"4.6.4","lessThan":"4.6.4.25","versionType":"custom","status":"affected"},{"version":"4.7.1","lessThan":"4.7.1.77","versionType":"custom","status":"affected"},{"version":"4.7.1","lessThan":"4.7.1.78","versionType":"custom","status":"affected"},{"version":"4.8.1","lessThan":"4.8.1.46","versionType":"custom","status":"affected"},{"version":"4.9.26","lessThan":"4.9.26.33","versionType":"custom","status":"affected"},{"version":"4.9.27","lessThan":"4.9.27.19","versionType":"custom","status":"affected"},{"version":"4.9.28","lessThan":"4.9.28.21","versionType":"custom","status":"affected"},{"version":"4.9.33","lessThan":"4.9.33.4","versionType":"custom","status":"affected"},{"version":"4.10.9","lessThan":"4.10.9.49","versionType":"custom","status":"affected"},{"version":"x","lessThanOrEqual":"*","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-06T12:34:22.435766Z","id":"CVE-2024-6832","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","type":"Secondary","description":[{"lang":"en","value":"CWE-693"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_control_plane:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"E492668B-C015-43BE-B395-3D826B45DF12"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_control_plane:4.6.0:*:*:*:*:*:*:*","matchCriteriaId":"F17BA3C7-B741-44CF-BA24-2FCBB39CCCF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"1344FB79-0796-445C-A8F3-C03E995925D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.2.0:*:*:*:*:*:*:*","matchCriteriaId":"E31E32CD-497E-4EF5-B3FC-8718EE06EDAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"B58251E8-606B-47C8-8E50-9F9FC8C179BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.1.0:*:*:*:*:*:*:*","matchCriteriaId":"1C1165F9-F8C5-4053-B012-E161D0F47424"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.2.0:*:*:*:*:*:*:*","matchCriteriaId":"ABAA8BD3-9F46-42C5-AA2A-F47B2932D0CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.3.0:*:*:*:*:*:*:*","matchCriteriaId":"5B668BAF-313C-44B0-9F7D-C69743A3136E"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.4.0:*:*:*:*:*:*:*","matchCriteriaId":"52215FF0-CB2F-4A05-AED7-1B218A82F7D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"865443F0-6F44-485C-AAE3-5AFDA5E9C49C"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:api_manager:4.6.0:*:*:*:*:*:*:*","matchCriteriaId":"2E5EE2A0-2E46-46CA-96A9-F025D34390FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.10.0:*:*:*:*:*:*:*","matchCriteriaId":"F4F126CA-A2F9-44F4-968B-DF71765869E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:5.11.0:*:*:*:*:*:*:*","matchCriteriaId":"2153AECE-020A-4C01-B2A6-F9F5D98E7EBE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"7B81C488-69D0-4A5C-AEED-31869C1BF5CA"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:6.1.0:*:*:*:*:*:*:*","matchCriteriaId":"65CD2558-C60C-4296-8E96-D4D804C598F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server:7.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B8DF49C6-F2F6-4229-982E-0C0559265203"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:identity_server_as_key_manager:5.10.0:*:*:*:*:*:*:*","matchCriteriaId":"6BB34405-A2F1-461A-B51B-E103BB3680A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_am:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"94347800-04D2-48C4-ACF0-078A5ACBB063"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:open_banking_iam:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"D7C241A3-8EA0-41E4-ABF3-21B9D8E7A5BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:traffic_manager:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"C7413107-D7B2-49AE-AC46-52E7BFCD6ED8"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:traffic_manager:4.6.0:*:*:*:*:*:*:*","matchCriteriaId":"933BA5C3-F145-498F-AF06-75CB9EE88046"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:universal_gateway:4.5.0:*:*:*:*:*:*:*","matchCriteriaId":"61636553-C25E-44DF-93D7-EB3E1056D1DC"},{"vulnerable":true,"criteria":"cpe:2.3:a:wso2:universal_gateway:4.6.0:*:*:*:*:*:*:*","matchCriteriaId":"E189CD5B-E7D2-48B8-AFAD-9D9CDE6F8BBA"}]}]}],"references":[{"url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3352/","source":"ed10eef1-636d-4fbe-9993-6890dfa878f8","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-19352","sourceIdentifier":"cna@vuldb.com","published":"2026-08-09T13:16:50.927","lastModified":"2026-08-09T13:16:50.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: \"I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug.\" The CVSS vector reflects the high level of pre-requisites."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"mifi","product":"lossless-cut","cpes":["cpe:2.3:a:mifi:lossless-cut:*:*:*:*:*:*:*:*"],"modules":["Built-in HTTP API Service"],"versions":[{"version":"3.0","status":"affected"},{"version":"3.1","status":"affected"},{"version":"3.2","status":"affected"},{"version":"3.3","status":"affected"},{"version":"3.4","status":"affected"},{"version":"3.5","status":"affected"},{"version":"3.6","status":"affected"},{"version":"3.7","status":"affected"},{"version":"3.8","status":"affected"},{"version":"3.9","status":"affected"},{"version":"3.10","status":"affected"},{"version":"3.11","status":"affected"},{"version":"3.12","status":"affected"},{"version":"3.13","status":"affected"},{"version":"3.14","status":"affected"},{"version":"3.15","status":"affected"},{"version":"3.16","status":"affected"},{"version":"3.17","status":"affected"},{"version":"3.18","status":"affected"},{"version":"3.19","status":"affected"},{"version":"3.20","status":"affected"},{"version":"3.21","status":"affected"},{"version":"3.22","status":"affected"},{"version":"3.23","status":"affected"},{"version":"3.24","status":"affected"},{"version":"3.25","status":"affected"},{"version":"3.26","status":"affected"},{"version":"3.27","status":"affected"},{"version":"3.28","status":"affected"},{"version":"3.29","status":"affected"},{"version":"3.30","status":"affected"},{"version":"3.31","status":"affected"},{"version":"3.32","status":"affected"},{"version":"3.33","status":"affected"},{"version":"3.34","status":"affected"},{"version":"3.35","status":"affected"},{"version":"3.36","status":"affected"},{"version":"3.37","status":"affected"},{"version":"3.38","status":"affected"},{"version":"3.39","status":"affected"},{"version":"3.40","status":"affected"},{"version":"3.41","status":"affected"},{"version":"3.42","status":"affected"},{"version":"3.43","status":"affected"},{"version":"3.44","status":"affected"},{"version":"3.45","status":"affected"},{"version":"3.46","status":"affected"},{"version":"3.47","status":"affected"},{"version":"3.48","status":"affected"},{"version":"3.49","status":"affected"},{"version":"3.50","status":"affected"},{"version":"3.51","status":"affected"},{"version":"3.52","status":"affected"},{"version":"3.53","status":"affected"},{"version":"3.54","status":"affected"},{"version":"3.55","status":"affected"},{"version":"3.56","status":"affected"},{"version":"3.57","status":"affected"},{"version":"3.58","status":"affected"},{"version":"3.59","status":"affected"},{"version":"3.60","status":"affected"},{"version":"3.61","status":"affected"},{"version":"3.62","status":"affected"},{"version":"3.63","status":"affected"},{"version":"3.64","status":"affected"},{"version":"3.65","status":"affected"},{"version":"3.66","status":"affected"},{"version":"3.67","status":"affected"},{"version":"3.68","status":"affected"},{"version":"3.69.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":1.3,"baseSeverity":"LOW","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:H/Au:N/C:P/I:N/A:N","baseScore":1.8,"accessVector":"ADJACENT_NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.2,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/mifi/lossless-cut/","source":"cna@vuldb.com"},{"url":"https://github.com/mifi/lossless-cut/commit/260802348955231442c4bae6c2d9d8ede947af0a","source":"cna@vuldb.com"},{"url":"https://my.feishu.cn/file/Jq4Ib90xeod3oPxlk77cv7jPnFe","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-19352","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865910","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387191","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387191/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-19353","sourceIdentifier":"cna@vuldb.com","published":"2026-08-09T13:16:51.923","lastModified":"2026-08-09T13:16:51.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"n/a","product":"DedeCMS","cpes":["cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*"],"modules":["Installation Wizard"],"versions":[{"version":"5.7.118 UTF8SP2","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":1.3,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:P","baseScore":4.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-73"}]}],"references":[{"url":"https://github.com/I4m6da/CVE/issues/9","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-19353","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865977","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387207","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387207/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-19354","sourceIdentifier":"cna@vuldb.com","published":"2026-08-09T14:17:25.647","lastModified":"2026-08-09T14:17:25.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injection. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"lock-upme","product":"OPMS","cpes":["cpe:2.3:a:lock-upme:opms:*:*:*:*:*:*:*:*"],"modules":["IN Clause Handler"],"versions":[{"version":"831440f37a92c1568f2e071d5233bc873a9d8b09","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://vuldb.com/cve/CVE-2026-19354","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865991","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387208","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387208/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-19355","sourceIdentifier":"cna@vuldb.com","published":"2026-08-09T14:17:26.763","lastModified":"2026-08-09T14:17:26.763","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"MingSoft","product":"MCMS","cpes":["cpe:2.3:a:mingsoft:mcms:*:*:*:*:*:*:*:*"],"modules":["ms-mdiy"],"versions":[{"version":"3.0.0","status":"affected"},{"version":"3.0.1","status":"affected"},{"version":"3.0.2","status":"affected"},{"version":"3.0.3","status":"affected"},{"version":"3.0.4","status":"affected"},{"version":"3.0.5","status":"affected"},{"version":"3.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://vuldb.com/cve/CVE-2026-19355","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865994","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387209","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387209/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-19356","sourceIdentifier":"cna@vuldb.com","published":"2026-08-09T14:17:26.930","lastModified":"2026-08-09T14:17:26.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"MingSoft","product":"MCMS","cpes":["cpe:2.3:a:mingsoft:mcms:*:*:*:*:*:*:*:*"],"modules":["ms-mdiy"],"versions":[{"version":"3.0.0","status":"affected"},{"version":"3.0.1","status":"affected"},{"version":"3.0.2","status":"affected"},{"version":"3.0.3","status":"affected"},{"version":"3.0.4","status":"affected"},{"version":"3.0.5","status":"affected"},{"version":"3.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://vuldb.com/cve/CVE-2026-19356","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865995","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387210","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387210/cti","source":"cna@vuldb.com"}]}}]}