CVE-2026-72601 - CSZ CMS CSZ CMS - Broken Access Control
CVE ID :CVE-2026-72601
Published : Aug. 11, 2026, 11:14 a.m. | 16 minutes ago
Description :A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-72601
Published : Aug. 11, 2026, 11:14 a.m. | 16 minutes ago
Description :A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72602 - AsyncFuncAI deepwiki-open - Path Traversal
CVE ID :CVE-2026-72602
Published : Aug. 11, 2026, 11:14 a.m. | 16 minutes ago
Description :A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path parameter and returns a directory listing without authentication, as WIKI_AUTH_MODE defaults to false. An attacker can enumerate sensitive directory contents on the host system.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-72602
Published : Aug. 11, 2026, 11:14 a.m. | 16 minutes ago
Description :A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path parameter and returns a directory listing without authentication, as WIKI_AUTH_MODE defaults to false. An attacker can enumerate sensitive directory contents on the host system.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72603 - wg-easy wg-easy - OS Command Injection
CVE ID :CVE-2026-72603
Published : Aug. 11, 2026, 11:15 a.m. | 16 minutes ago
Description :An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-72603
Published : Aug. 11, 2026, 11:15 a.m. | 16 minutes ago
Description :An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72604 - Intelliants Subrion CMS - Path Traversal
CVE ID :CVE-2026-72604
Published : Aug. 11, 2026, 11:15 a.m. | 15 minutes ago
Description :A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to unlink() without sanitization or path canonicalization. An authenticated administrator can delete sensitive system files outside the web root, potentially causing server instability or facilitating further attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-72604
Published : Aug. 11, 2026, 11:15 a.m. | 15 minutes ago
Description :A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to unlink() without sanitization or path canonicalization. An authenticated administrator can delete sensitive system files outside the web root, potentially causing server instability or facilitating further attacks.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72605 - Swing Music Swing Music - Missing Authentication
CVE ID :CVE-2026-72605
Published : Aug. 11, 2026, 11:15 a.m. | 15 minutes ago
Description :A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-72605
Published : Aug. 11, 2026, 11:15 a.m. | 15 minutes ago
Description :A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-72606 - Pinry Pinry - Server-Side Request Forgery
CVE ID :CVE-2026-72606
Published : Aug. 11, 2026, 11:15 a.m. | 15 minutes ago
Description :A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-from-URL feature. The feature passes the user-supplied URL directly to requests.get() without host or IP validation, and ALLOW_NEW_REGISTRATIONS defaults to true enabling anonymous triggering. An attacker can reach internal services or cloud metadata endpoints from the server.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-72606
Published : Aug. 11, 2026, 11:15 a.m. | 15 minutes ago
Description :A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-from-URL feature. The feature passes the user-supplied URL directly to requests.get() without host or IP validation, and ALLOW_NEW_REGISTRATIONS defaults to true enabling anonymous triggering. An attacker can reach internal services or cloud metadata endpoints from the server.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58231 - Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
CVE ID :CVE-2026-58231
Published : Aug. 11, 2026, 11:17 a.m. | 14 minutes ago
Description :SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58231
Published : Aug. 11, 2026, 11:17 a.m. | 14 minutes ago
Description :SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2021-47995 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2021-47995
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2021-47995
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2022-50974 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2022-50974
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2022-50974
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54367 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54367
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54367
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54368 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54368
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54368
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54369 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54369
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54369
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54370 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54370
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54370
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54371 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54371
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54371
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54372 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54372
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54372
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54373 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54373
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54373
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-54374 - Rejected reason: This CVE ID has been rejected.
CVE ID :CVE-2023-54374
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2023-54374
Published : Aug. 11, 2026, 3:17 p.m. | 14 minutes ago
Description :Rejected reason: This CVE ID has been rejected.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17061 - Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026
CVE ID :CVE-2026-17061
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-17061
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17535 - Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes
CVE ID :CVE-2026-17535
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files. If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-17535
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files. If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18125 - Ivanti Endpoint Manager Agent Out-of-Bounds Read
CVE ID :CVE-2026-18125
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18125
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18127 - Ivanti Endpoint Manager Path Traversal Vulnerability
CVE ID :CVE-2026-18127
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18127
Published : Aug. 11, 2026, 3:17 p.m. | 13 minutes ago
Description :External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...