📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 6m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH 6m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h Global phishing Cross-sector HIGH 6m Global data_breach Energy CRITICAL 1h Global phishing Government/Multi-sector HIGH 2h Global apt Education CRITICAL 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 5h Global vulnerability IT Infrastructure CRITICAL 6h Global vulnerability Technology and Software Development HIGH 7h Global vulnerability Enterprise IT and Government CRITICAL 7h Global ransomware Multiple Sectors / Enterprise CRITICAL 8h Global general Technology and Legal MEDIUM 8h
📅 Daily Security Digest — Sunday, May 17, 2026

🇸🇦 Saudi Cyber Daily Digest

All security vulnerabilities, threats, and news aggregated today from trusted sources — continuously updated

Sunday, May 17, 2026 Today
161 CVEs
4 Threats
0 News
🛡 Security Vulnerabilities (CVE)
161 vulnerabilities
CVE-2026-8719
AI Engine WordPress Plugin MCP OAuth Privilege Escalation (CVE-2026-8719)
19:18 KSA
HIGH CVSS 8.8 CWE-269
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes …
CVE-2018-25322
Allok Fast AVI MPEG Splitter 1.2 Stack Buffer Overflow in License Name
19:18 KSA
HIGH CVSS 8.4 CWE-121
Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk data followed by structured shellcode and…
CVE-2018-25323
Allok AVI DivX MPEG to DVD Converter SEH Buffer Overflow RCE
19:18 KSA
HIGH CVSS 8.4 CWE-120
Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing s…
CVE-2018-25328
VX Search 10.6.18 Local Buffer Overflow in Directory Field
19:18 KSA
HIGH CVSS 8.4 CWE-120
VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return a…
CVE-2018-25330
Joomla EkRishta 2.10 Persistent XSS and SQL Injection Vulnerabilities
19:18 KSA
HIGH CVSS 8.2 CWE-89
Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address tha…
CVE-2018-25333
SQL Injection in Nordex N149 Wind Turbine Web Server 4.0 Login Parameter
19:18 KSA
HIGH CVSS 8.2 CWE-89
Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the login parameter in login.php. Attackers can submit crafted POST requests with SQL…
CVE-2018-25338
Zechat 1.5 SQL Injection in Hashtag Parameter
19:18 KSA
HIGH CVSS 8.2 CWE-89
Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit the hashtag parameter with union-based payloads to retrieve table and column names.
CVE-2018-25339
Zechat 1.5 Unauthenticated SQL Injection via v Parameter
23:20 KSA
HIGH CVSS 8.2 CWE-89
Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the v parameter with sleep-based blind injection to confirm vulnerability and extrac…
CVE-2026-34333
Windows Win32K Graphics Use-After-Free Privilege Escalation
06:32 KSA
HIGH CVSS 7.8 CWE-190
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-34334
Windows TCP/IP Race Condition Privilege Escalation Vulnerability
06:32 KSA
HIGH CVSS 7.8 CWE-362
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-34336
Windows DWM Core Library Buffer Over-Read Information Disclosure
06:32 KSA
HIGH CVSS 7.8 CWE-126
Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-34337
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
12:54 KSA
HIGH CVSS 7.8 CWE-362
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-34338
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
12:54 KSA
HIGH CVSS 7.8 CWE-416
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-34343
Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate pr
12:54 KSA
HIGH CVSS 7.8 CWE-122
Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
CVE-2026-34344
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an
12:54 KSA
HIGH CVSS 7.8 CWE-843
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-34351
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an
12:54 KSA
HIGH CVSS 7.8 CWE-362
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-34636
Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result
12:54 KSA
HIGH CVSS 7.8 CWE-787
Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file…
CVE-2026-34637
Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result
12:54 KSA
HIGH CVSS 7.8 CWE-787
Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file…
CVE-2026-34638
Premiere Pro Use After Free Vulnerability Allows Arbitrary Code Execution
19:32 KSA
HIGH CVSS 7.8 CWE-416
Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-34639
Adobe Media Encoder Out-of-Bounds Write RCE Vulnerability
19:32 KSA
HIGH CVSS 7.8 CWE-787
Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fil…
CVE-2026-34640
Adobe Media Encoder Integer Overflow RCE Vulnerability
19:32 KSA
HIGH CVSS 7.8 CWE-190
Media Encoder versions 26.0.2, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma…
CVE-2026-34642
Adobe After Effects Heap Buffer Overflow RCE Vulnerability
19:32 KSA
HIGH CVSS 7.8 CWE-122
After Effects versions 26.0, 25.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
CVE-2026-34643
Adobe After Effects Out-of-Bounds Write RCE Vulnerability
19:32 KSA
HIGH CVSS 7.8 CWE-787
After Effects versions 26.0, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-34644
Adobe After Effects Integer Overflow Vulnerability (CVE-2026-34644)
19:32 KSA
HIGH CVSS 7.8 CWE-190
After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali…
CVE-2026-34661
Adobe Illustrator Out-of-Bounds Write RCE Vulnerability
19:32 KSA
HIGH CVSS 7.8 CWE-787
Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-34675
Substance3D Painter Out-of-Bounds Write RCE Vulnerability
19:32 KSA
HIGH CVSS 7.8 CWE-787
Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fil…
CVE-2026-34676
Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result
19:32 KSA
HIGH CVSS 7.8 CWE-787
Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious fil…
CVE-2026-34687
Adobe Illustrator Heap Buffer Overflow Remote Code Execution
19:32 KSA
HIGH CVSS 7.8 CWE-122
Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious f…
CVE-2026-35415
Windows Storage Spaces Controller Integer Overflow Privilege Escalation
19:32 KSA
HIGH CVSS 7.8 CWE-190
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CVE-2018-25325
WooCommerce CSV Importer 3.3.6 Path Traversal Arbitrary File Deletion
19:18 KSA
HIGH CVSS 7.5 CWE-22
Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in t…
CVE-2018-25326
Google Drive for WordPress 2.2 Path Traversal Vulnerability
19:18 KSA
HIGH CVSS 7.5 CWE-22
Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype para…
CVE-2018-25329
WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers
19:18 KSA
HIGH CVSS 7.5 CWE-98
WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attackers can send GET requests to wp.spritz.content.filter.php with malicious url valu…
CVE-2026-8725
CoreWorxLab CAAL Server-Side Request Forgery in Webhooks Component
19:18 KSA
HIGH CVSS 7.3 CWE-918
A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. T…
CVE-2026-8734
SQL Injection in Oinone Pamirs queryListByWrapper Interface
19:18 KSA
HIGH CVSS 7.3 CWE-74
A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Interface. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has bee…
CVE-2026-8755
Path Traversal in fishaudio Bert-VITS2 Model Handler Component
23:20 KSA
HIGH CVSS 7.3 CWE-22
A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of the file hiyoriUI.py of the component Model Handler. This manipulation causes path traversal. The attack can be initiated remotely…
CVE-2026-8756
Path Traversal in fishaudio Bert-VITS2 Gradio Interface
23:20 KSA
HIGH CVSS 7.3 CWE-22
A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_config of the file webui_preprocess.py of the component Gradio Interface. Such manipulation of the argument data_dir leads to path …
CVE-2026-8758
Metasoft MetaCRM Unrestricted File Upload in upload3.jsp
23:20 KSA
HIGH CVSS 7.3 CWE-284
A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has be…
CVE-2026-8759
A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic
23:20 KSA
HIGH CVSS 7.3 CWE-20
A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutral…
CVE-2026-8768
A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the fil
01:34 KSA
HIGH CVSS 7.3 CWE-918
A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launc…
CVE-2026-8764
H3C Magic B3 Buffer Overflow in UpdateWanParams Function
23:20 KSA
HIGH CVSS 7.2 CWE-119
A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack may be performed from remote. The exploit has been disclos…
CVE-2018-25319
Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulat
19:18 KSA
HIGH CVSS 7.1 CWE-89
Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Attackers can send GET requests to the event_add.php page with malicious myevents_id…
CVE-2026-34340
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
12:54 KSA
HIGH CVSS 7.0 CWE-416
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-34341
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
12:54 KSA
HIGH CVSS 7.0 CWE-415
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
CVE-2026-34342
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Com
12:54 KSA
HIGH CVSS 7.0 CWE-362
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVE-2026-34345
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
12:54 KSA
HIGH CVSS 7.0 CWE-362
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-34347
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
12:54 KSA
HIGH CVSS 7.0 CWE-416
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVE-2026-35416
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
19:32 KSA
HIGH CVSS 7.0 CWE-416
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-8738
A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderControlle
15:36 KSA
MEDIUM CVSS 6.5 CWE-840
A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.j…
CVE-2020-37240
Queue Management System 4.0.0 Stored XSS in User Creation Fields
01:16 KSA
MEDIUM CVSS 6.4 CWE-79
Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during use…
CVE-2021-47957
Cookie Law Bar 1.2.1 Stored XSS in Bar Message Field
01:16 KSA
MEDIUM CVSS 6.4 CWE-79
Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute i…
CVE-2025-14810
IBM InfoSphere Information Server Insufficient Session Expiration After Privilege Modification
11:08 KSA
MEDIUM CVSS 6.3 CWE-613
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE: CWE-613: Insufficient…
CVE-2025-66483
IBM Aspera Shares Session Invalidation Failure After Password Reset
15:21 KSA
MEDIUM CVSS 6.3 CWE-613
IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.
CVE-2026-1879
Harvard IQSS Dataverse Unrestricted File Upload in Theme Customization
09:57 KSA
MEDIUM CVSS 6.3 CWE-284
A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote explo…
CVE-2026-2930
A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the
11:14 KSA
MEDIUM CVSS 6.3 CWE-119
A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of the argument boundary leads to stack-based buffer overflow. The attack can be exec…
CVE-2026-2945
A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the fil
11:14 KSA
MEDIUM CVSS 6.3 CWE-918
A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack may be launched remotely. Th…
CVE-2026-2954
A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/im
11:14 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is possib…
CVE-2026-2956
A security flaw has been discovered in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the fi
11:14 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the file /home/restore. The manipulation of the argument Name results in command injection. The attack can be launched remotely. The exploit has been released to the …
CVE-2026-3262
A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is
05:22 KSA
MEDIUM CVSS 6.3 CWE-698
A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The ex…
CVE-2026-3263
Improper Authorization in go2ismail Asp.Net-Core-Inventory-Order-Management-System
05:22 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization…
CVE-2026-3286
A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save
04:30 KSA
MEDIUM CVSS 6.3 CWE-918
A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save of the file paicoding-web/src/main/java/com/github/paicoding/forum/web/common/image/rest/ImageRestController.java of the component Image Save Endpoint. Such man…
CVE-2026-3287
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the
04:30 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/main/java/com/youlai/mall/pms/controller/app/SpuController.java of the component App-side Product Pagination Endpoint. Performing a …
CVE-2026-3289
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file Templ
04:30 KSA
MEDIUM CVSS 6.3 CWE-22
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The…
CVE-2026-3292
A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frph
04:30 KSA
MEDIUM CVSS 6.3 CWE-74
A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipulation of the argument data leads to sql injection. The attack is possible to be carried out remotel…
CVE-2026-32921
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b
09:57 KSA
MEDIUM CVSS 6.3 CWE-367
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute dif…
CVE-2026-32977
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u
09:57 KSA
MEDIUM CVSS 6.3 CWE-367
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths i…
CVE-2026-34323
Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authenticat
21:40 KSA
MEDIUM CVSS 6.3
Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authentication). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via H…
CVE-2026-34626
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo
00:48 KSA
MEDIUM CVSS 6.3 CWE-1321
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current us…
CVE-2026-34664
Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted
19:59 KSA
MEDIUM CVSS 6.3 CWE-22
Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files…
CVE-2026-34861
Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may
02:16 KSA
MEDIUM CVSS 6.3 CWE-362
Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34862
Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnera
02:16 KSA
MEDIUM CVSS 6.3 CWE-362
Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-40133
Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthoriz
20:16 KSA
MEDIUM CVSS 6.3 CWE-862
Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact on the confidentiality and integrity of the data. Additionally, this vulnerability…
CVE-2026-4485
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio
05:45 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/search_student.php. The manipulation of the argument Search leads to sql injection. The attack is possible to be carried out remotely. The …
CVE-2026-4500
Code Injection in bagofwords1 generate_df Function (CVE-2026-4500)
05:45 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.py. Such manipulation leads to injection. The attack may be launched remotely. The exploit is publicly available …
CVE-2026-4505
DB-GPT Unrestricted Plugin Upload Vulnerability (CVE-2026-4505)
05:45 KSA
MEDIUM CVSS 6.3 CWE-284
A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component FastAPI Endpoint. Such manipulation leads to unrestricted upl…
CVE-2026-4506
MindSQL Code Injection Vulnerability in ask_db Function (CVE-2026-4506)
05:45 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core/mindsql_core.py. Performing a manipulation results in code injection. The attack can be initiated remotely. The exploit has been made public and could be used.…
CVE-2026-4507
MindSQL SQL Injection in ask_db Function (CVE-2026-4507)
05:45 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the file mindsql/core/mindsql_core.py. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclo…
CVE-2026-4511
Code Injection in vanna-ai vanna Legacy Module exec Function
23:36 KSA
MEDIUM CVSS 6.3 CWE-74
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor wa…
CVE-2026-4513
SQL Injection in vanna-ai vanna ask Function (CVE-2026-4513)
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public a…
CVE-2026-4514
PbootCMS Improper Access Control in UserController Backend Component
09:54 KSA
MEDIUM CVSS 6.3 CWE-266
A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The atta…
CVE-2026-4515
Code Injection in Foundation Agents MetaGPT code_generate Function
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/scripts/operator.py. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been discl…
CVE-2026-4516
MetaGPT DataInterpreter Code Injection Vulnerability (CVE-2026-4516)
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of the component DataInterpreter. The manipulation results in injection. It is possible to launch the attack remotely.…
CVE-2026-4533
SQL Injection in Simple Food Ordering System 1.0 Status Parameter
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Status results in sql injection. It is possible to launch the attack remotely. The exp…
CVE-2026-4543
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin/firewall.cgi of the component POST Request Handler. Performing a manipulation of the argument dmz_flag/del_flag results in command injection. It is possible to…
CVE-2026-4548
A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function
09:54 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launch…
CVE-2026-4554
Tenda F453 Command Injection in FormWriteFacMac Function
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been r…
CVE-2026-4568
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /update_supplier.php of the component HTTP GET Request Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remot…
CVE-2026-4569
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manipulation of the argument searchtxt causes sql injection. Remote exploitation of th…
CVE-2026-4570
A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql injection. The attack can be execu…
CVE-2026-4571
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results …
CVE-2026-4572
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /view_product.php of the component HTTP POST Request Handler. Executing a manipulation of the argument searchtxt can lead to sql injec…
CVE-2026-4573
A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET Parameter Handler. The manipulation of the argument post_id leads to sql injection…
CVE-2026-4574
A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of
09:54 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument firstName results in sql injection. It is possible to launch the attack remotely. Th…
CVE-2026-4586
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-serve
09:54 KSA
MEDIUM CVSS 6.3 CWE-284
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web/api/controller/driver/JdbcDriverController.java of the component JDBC Driver Upl…
CVE-2026-4589
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file
09:54 KSA
MEDIUM CVSS 6.3 CWE-918
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side r…
CVE-2026-4825
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /up
11:08 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /update_sales.php of the component HTTP GET Parameter Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. …
CVE-2026-4836
A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the
11:08 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id results in sql injection. It is possible to initiate the attack remotely. The expl…
CVE-2026-4876
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown fun
11:08 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulation of the argument ID leads to sql injection. The attack may be performed from rem…
CVE-2026-4907
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted
02:36 KSA
MEDIUM CVSS 6.3 CWE-918
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component Endpoint. The manipulation of the argument url leads to server-side request forgery…
CVE-2026-4970
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the
02:36 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploi…
CVE-2026-6587
SSRF Vulnerability in vibrantlabsai RAGAS Collections Module (CVE-2026-6587)
06:54 KSA
MEDIUM CVSS 6.3 CWE-918
A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manip…
CVE-2026-6599
Langflow MCP API X-Forwarded-For Header Injection Vulnerability
11:48 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v1/mcp_projects.py of the component Model Context Protocol Configuration API. Performing a manipulatio…
CVE-2026-6612
SuperAGI Authorization Bypass via agent_execution_id Manipulation
14:00 KSA
MEDIUM CVSS 6.3 CWE-285
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_execution/update_agent_execution of the file superagi/controllers/agent_execution.py of the component Agent Execution Endpoint. Executing a manipulation of the argument…
CVE-2026-6613
SuperAGI Authorization Bypass in Agent Management Functions (CVE-2026-6613)
14:00 KSA
MEDIUM CVSS 6.3 CWE-285
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_schedule/get_schedule_data of the file superagi/controllers/agent.py. The manipulation of the argument agent_id leads to authorization bypass. The attack is poss…
CVE-2026-6614
TransformerOptimus SuperAGI Authorization Bypass in Project Management
14:00 KSA
MEDIUM CVSS 6.3 CWE-285
A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the function get_project/update_project/get_projects_organisation of the file superagi/controllers/project.py. The manipulation results in authorization bypass. The …
CVE-2026-6616
TransformerOptimus SuperAGI SSRF in WebScraperTool Webpage Extraction
16:16 KSA
MEDIUM CVSS 6.3 CWE-918
A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extract_with_bs4/extract_with_3k/extract_with_lxml of the file superagi/helper/webpage_extractor.py of the component WebScraperTool. Such manipulation leads to server…
CVE-2026-6617
Dify SSRF Vulnerability in ApiToolManageService URL Handling
16:16 KSA
MEDIUM CVSS 6.3 CWE-918
A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Performing a manipulation of the argument url…
CVE-2026-6618
Dify SSRF Vulnerability in ApiBasedToolSchemaParser URL Handling
16:16 KSA
MEDIUM CVSS 6.3 CWE-918
A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-sid…
CVE-2026-6620
Path Traversal in SonicCloudOrg sonic-server File Upload Endpoint
16:16 KSA
MEDIUM CVSS 6.3 CWE-22
A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path traversal. The attack may be launched remotely. …
CVE-2026-6829
Path Traversal in nesquena hermes-webui Workspace Management
21:40 KSA
MEDIUM CVSS 6.3 CWE-22
nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an arbitrary existing directory on disk by manipulating workspace path parameters in endpoints such as /api/session/new, /api/session/…
CVE-2026-6989
Tenda F453 Telnet Service Command Injection Vulnerability (CVE-2026-6989)
01:36 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed …
CVE-2026-6991
SQL Injection in Zod CUID Data Type Handler (CVE-2026-6991)
01:36 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Executing a manipulation can lead to sql injection. The attack can be launched remote…
CVE-2026-7091
Improper Authorization in code-projects Invoice System Laravel 1.0
13:32 KSA
MEDIUM CVSS 6.3 CWE-266
A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Management Handler. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been …
CVE-2026-7092
Improper Authorization in code-projects Invoice System Laravel 1.0 Profile Handler
13:32 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The ex…
CVE-2026-7093
Improper Authorization in code-projects Invoice System Laravel 1.0
13:32 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack…
CVE-2026-7102
Tenda F456 Remote Command Injection via WriteFacMac Parameter
15:48 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in command injection. The attack can be executed remotely. The exploit has been made pub…
CVE-2026-7107
Unrestricted File Upload in code-projects Invoice System Laravel 1.0
15:48 KSA
MEDIUM CVSS 6.3 CWE-284
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has b…
CVE-2026-7114
SQL Injection in code-projects Employee Management System 1.0 edit.php
18:00 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed a…
CVE-2026-7115
SQL Injection in code-projects Employee Management System 1.0 delete.php
18:00 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly ava…
CVE-2026-7118
SQL Injection in code-projects Employee Management System 1.0 cancel.php
20:16 KSA
MEDIUM CVSS 6.3 CWE-74
A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation of the argument id/token leads to sql injection. The attack is possible to be carried out re…
CVE-2026-7142
Wooey API Improper Authorization Vulnerability (CVE-2026-7142)
00:32 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of the component API Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotel…
CVE-2026-7143
SQL Injection in 1000 Projects Portfolio Management System MCA block_status.php
00:32 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicl…
CVE-2026-7148
CodeAstro Online Classroom 1.0 SQL Injection in Faculty Addition
03:48 KSA
MEDIUM CVSS 6.3 CWE-74
A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
CVE-2026-7150
dh1011 auto-favicon SSRF Vulnerability in Favicon Generation
03:48 KSA
MEDIUM CVSS 6.3 CWE-918
A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in serve…
CVE-2026-7392
SQL Injection in SourceCodester Pharmacy System delete_supplier Function
13:36 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The …
CVE-2026-7410
SQL Injection in SourceCodester Pizzafy Ecommerce System 1.0 add_to_cart Function
20:09 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The exploit ha…
CVE-2026-7445
Path Traversal in ZachHandley ZMCPTools MCP Log Resource Handler
20:09 KSA
MEDIUM CVSS 6.3 CWE-22
A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP Log Resource Handler. The manipulation of the argument dirname leads to path trav…
CVE-2026-7508
Bootstrap CMS 0.9.0-alpha Code Injection in Page Creation Handler
07:32 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. Remote exploitation of the at…
CVE-2026-7510
OWASP DefectDojo Authorization Bypass in Benchmark/Engagement Components
07:32 KSA
MEDIUM CVSS 6.3 CWE-285
A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exp…
CVE-2026-7591
SQL Injection in astro-mcp-server MCP Tool Query Construction
03:54 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown function of the file src/index.ts of the component MCP Tool Query Construction. Performing a manipulation of the argument request.params.arguments results in sql inj…
CVE-2026-7595
Code Injection in nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator
03:54 KSA
MEDIUM CVSS 6.3 CWE-74
A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code…
CVE-2026-7597
mem0ai mem0 Pickle Deserialization RCE in FAISS Vector Store
06:54 KSA
MEDIUM CVSS 6.3 CWE-20
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been made public…
CVE-2026-7599
Path Traversal in hwpx-mcp 0.2.0 Document Export Functions
06:54 KSA
MEDIUM CVSS 6.3 CWE-22
A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_to_html of the file mcp-server/src/index.ts of the component MCP Interface. Performing a manipulation of the argument output_path results in path traversal. Remo…
CVE-2026-7600
OS Command Injection in ArtMin96 yii2-mcp-server MCP Interface
09:00 KSA
MEDIUM CVSS 6.3 CWE-77
A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exp…
CVE-2026-7715
Path Traversal in ravenwits mcp-server-arangodb arango_backup Function
09:18 KSA
MEDIUM CVSS 6.3 CWE-22
A vulnerability has been found in ravenwits mcp-server-arangodb up to 0.4.7. This affects the function arango_backup of the file src/tools.ts of the component MCP Interface. Such manipulation of the argument outputDir leads to path traversal. It is possible to launch the attack r…
CVE-2026-7783
Perfex CRM SQL Injection in Admin Kanban Endpoint (CVE-2026-7783)
08:16 KSA
MEDIUM CVSS 6.3 CWE-74
A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::applySortQuery of the file application/services/AbstractKanban.php of the component Admin Kanban Endpoint. This manipulation of the argument this causes sql injecti…
CVE-2026-8081
Server-Side Request Forgery in router-for-me CLIProxyAPI 6.9.29
01:37 KSA
MEDIUM CVSS 6.3 CWE-918
A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request for…
CVE-2026-8097
SQL Injection in CodeAstro Online Classroom 1.0 /askquery.php
04:18 KSA
MEDIUM CVSS 6.3 CWE-74
A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /askquery.php. The manipulation of the argument squeryx results in sql injection. The attack may be performed from remote. The exploit has been released to t…
CVE-2026-8112
8421bit MiniClaw OS Command Injection in executeCognitivePulse Function
04:18 KSA
MEDIUM CVSS 6.3 CWE-77
A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the file src/kernel.ts. Performing a manipulation results in os command injection. It is possible to initiate the attack remotely. The e…
CVE-2026-8114
JeecgBoot SQL Injection in /sys/dict/loadTreeData Endpoint
04:18 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON Object Handler. The manipulation of the argument condition leads to sql injection. The attack can be initiated re…
CVE-2026-8116
Path Traversal in xiaozhi-mcphub manifest.name Parameter
08:00 KSA
MEDIUM CVSS 6.3 CWE-22
A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of the file src/controllers/dxtController.ts. This manipulation of the argument manifest.name causes path traversal. The attack may be initiated remotely. The exp…
CVE-2026-8125
SQL Injection in Simple Chat System 1.0 sendMessage.php Parameter Validation
11:18 KSA
MEDIUM CVSS 6.3 CWE-74
A vulnerability was detected in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file sendMessage.php. The manipulation of the argument type/length/business parameter validity results in sql injection. The attack may be launched remotely. The e…
CVE-2026-8127
eladmin Users API Improper Access Control Vulnerability (CVE-2026-8127)
11:18 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserController.java of the component Users API Endpoint. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit has been discl…
CVE-2026-8188
Wavlink NU516U1 OS Command Injection in WiFi Configuration
22:36 KSA
MEDIUM CVSS 6.3 CWE-77
A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/EncrypType leads to os command injection. It is possible to initiate the attack remotel…
CVE-2026-8189
Wavlink NU516U1 OS Command Injection in adm.cgi WLAN Parameters
02:37 KSA
MEDIUM CVSS 6.3 CWE-77
A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch th…
CVE-2026-8733
SlimPDFReader Stack-Based Buffer Overflow (CVE-2026-8733)
13:00 KSA
MEDIUM CVSS 6.3 CWE-119
A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has be…
CVE-2026-8735
Oinone Pamirs Deserialization Vulnerability in JsonUtils.parseMap
13:00 KSA
MEDIUM CVSS 6.3 CWE-20
A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit is…
CVE-2026-8740
A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccm
15:36 KSA
MEDIUM CVSS 6.3 CWE-791
A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument tem…
CVE-2026-8743
Open5GS AMF/MME Improper Authorization Vulnerability (CVE-2026-8743)
17:58 KSA
MEDIUM CVSS 6.3 CWE-266
A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The explo…
CVE-2026-8747
Z-BlogPHP 1.7.4.3430 Improper Authorization in Comment Approval Handler
17:58 KSA
MEDIUM CVSS 6.3 CWE-266
A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The e…
CVE-2026-8753
Kodbox fileThumb Plugin Command Injection via ffmpegBin Parameter
20:32 KSA
MEDIUM CVSS 6.3 CWE-74
A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin l…
CVE-2026-8754
AstrBot Path Traversal in File Upload Handler (CVE-2026-8754)
20:32 KSA
MEDIUM CVSS 6.3 CWE-22
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulation of the argument filename results in path traversal. It is possible to launch th…
CVE-2018-25324
Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticat
20:32 KSA
MEDIUM CVSS 6.2 CWE-98
Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspath parameter on PHP versions before 5.3.4. Attackers can supply malicious wp_abspa…
CVE-2018-25331
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to i
20:32 KSA
MEDIUM CVSS 6.1 CWE-79
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.p…
CVE-2018-25334
Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's informa
20:32 KSA
MEDIUM CVSS 5.4 CWE-352
Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but an attacker can use the hashtag parameter to inject an encoded payload and bypas…
CVE-2018-25327
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta
20:32 KSA
MEDIUM CVSS 5.3 CWE-352
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete jo…
CVE-2018-25336
Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify us
20:32 KSA
MEDIUM CVSS 5.3 CWE-352
Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML forms targeting endpoints , and to change user credentials, passwords, and aff…
CVE-2026-8737
Sanluan PublicCMS Authentication Bypass in Trade Address Query Handler
15:36 KSA
MEDIUM CVSS 5.3 CWE-287
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulat…
CVE-2026-8739
Hard-Coded Cryptographic Key in Sanluan PublicCMS SafeConfigComponent
15:36 KSA
MEDIUM CVSS 5.3 CWE-320
A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of…
CVE-2026-8750
H2O-3 ImportFile API Information Disclosure via PersistNFS Component
17:58 KSA
MEDIUM CVSS 5.3 CWE-200
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be exec…
CVE-2026-8752
H2O-3 Rapids setproperty Improper Access Control Vulnerability
20:32 KSA
MEDIUM CVSS 5.3 CWE-266
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to im…
CVE-2026-8767
Vercel AI OS Command Injection via PR Branch Name Interpolation
06:16 KSA
MEDIUM CVSS 5.0 CWE-77
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The …
⚠️ Threat Intelligence
4 threats
rss:The Hacker News
21:54 KSA
CRITICAL vulnerability
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE A critical heap buffer overflow vulnerability (CVE-2026-42945, CVSS 9.2) in NGINX Plus and NGINX Open is being actively exploited in the wild shortly after public disclosure. The…
rss:BleepingComputer
21:54 KSA
CRITICAL phishing
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing Tycoon2FA phishing kit has evolved to support device-code phishing attacks, exploiting Trustifi click-tracking URLs to compromise Microsoft 365 accounts. This attack method bypasses traditional au…
rss:The Hacker News
14:17 KSA
HIGH supply_chain
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt Grafana disclosed that an unauthorized party obtained a GitHub token granting access to the company's GitHub environment and codebase. The investigation confirmed no customer data or pers…
rss:BleepingComputer
03:32 KSA
CRITICAL vulnerability
Microsoft rejects critical Azure vulnerability report, no CVE issued A security researcher alleges Microsoft silently patched a critical Azure Backup for AKS vulnerability after rejecting the disclosure report without issuing a CVE identifier. Microsoft disputes…
📰 Cybersecurity News
0 articles
📰 No news aggregated today yet

This digest is updated automatically every day — Last updated: Sunday, May 17, 2026
CVE Archive · Threats · News

📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.