CVE-2026-14904 - RES Auth.GetUserPrivateKey Arbitrary File Read
CVE ID :CVE-2026-14904
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users' SSH private keys and application configuration secrets. It's recommended to upgrade to RES version 2026.06.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14904
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users' SSH private keys and application configuration secrets. It's recommended to upgrade to RES version 2026.06.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-23697 - Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
CVE ID :CVE-2026-23697
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-23697
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-23698 - Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
CVE ID :CVE-2026-23698
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-23698
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become directly accessible via HTTP, bypassing Vtiger's authentication and authorization layer entirely since Apache resolves the path and invokes the PHP interpreter before the application routing layer is involved, resulting in a persistent web shell independent of the originating session.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-57851 - MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
CVE ID :CVE-2026-57851
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-57851
Published : July 7, 2026, 5:16 p.m. | 2 hours, 50 minutes ago
Description :MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44877 - Unauthenticated Remote Disclosure of Cryptographic Secrets
CVE ID :CVE-2026-44877
Published : July 7, 2026, 7:03 p.m. | 1 hour, 3 minutes ago
Description :An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-44877
Published : July 7, 2026, 7:03 p.m. | 1 hour, 3 minutes ago
Description :An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48947 - Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints
CVE ID :CVE-2026-48947
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows privileged users to overwrite media files without editing permissions.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48947
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows privileged users to overwrite media files without editing permissions.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48948 - Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
CVE ID :CVE-2026-48948
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48948
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48949 - Joomla! Core - [20260703] - XSS in MFA method management
CVE ID :CVE-2026-48949
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of validation leads to an XSS vulnerability in the MFA management views.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48949
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of validation leads to an XSS vulnerability in the MFA management views.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48950 - Joomla! Core - [20260704] - XSS in com_templates
CVE ID :CVE-2026-48950
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48950
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48951 - Joomla! Core - [20260705] - XSS in various modalreturn layouts
CVE ID :CVE-2026-48951
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48951
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48952 - Joomla! Core - [20260706] - XSS in com_installer
CVE ID :CVE-2026-48952
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48952
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48953 - Joomla! Core - [20260707] - XSS in the generic image output layout
CVE ID :CVE-2026-48953
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48953
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48954 - Joomla! Core - [20260708] - XSS through language overrides
CVE ID :CVE-2026-48954
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Improper validation leads to a generic XSS vector in the language override feature.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48954
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Improper validation leads to a generic XSS vector in the language override feature.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48955 - Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
CVE ID :CVE-2026-48955
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows unauthorized users to access workflow stage and transition information.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48955
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows unauthorized users to access workflow stage and transition information.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48956 - Joomla! Core - [20260710] - Incorrect Access Control in com_modules
CVE ID :CVE-2026-48956
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows users to display a list of modules in the frontend.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48956
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows users to display a list of modules in the frontend.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48957 - Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
CVE ID :CVE-2026-48957
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows unauthorized users to access com_privacy datasets.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48957
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows unauthorized users to access com_privacy datasets.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48958 - Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
CVE ID :CVE-2026-48958
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-48958
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55435 - Suspended Coder users retain access to AI Bridge LLM proxy endpoints
CVE ID :CVE-2026-55435
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-55435
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59708 - Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint
CVE ID :CVE-2026-59708
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59708
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59800 - 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
CVE ID :CVE-2026-59800
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), the sudoPassword value is interpreted by sh as a shell command, allowing a remote unauthenticated attacker to execute arbitrary OS commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-07-04 (UTC).
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59800
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), the sudoPassword value is interpreted by sh as a shell command, allowing a remote unauthenticated attacker to execute arbitrary OS commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-07-04 (UTC).
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-7017 - HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
CVE ID :CVE-2026-7017
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that "Authorization headers will not be included in a redirected request" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-7017
Published : July 7, 2026, 7:16 p.m. | 50 minutes ago
Description :HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire. The HTTP::Tiny POD note that "Authorization headers will not be included in a redirected request" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...