CVE ID :CVE-2026-66013 Published : July 25, 2026, 11:17 a.m. | 13 hours, 20 minutes ago Description :OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers…
CVE-2026-66012 – SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP
CVE ID :CVE-2026-66012 Published : July 25, 2026, 11:17 a.m. | 13 hours, 20 minutes ago Description :SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated…
CVE-2026-10818 – WPForms Pro <= 1.10.1.1 – Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
CVE ID :CVE-2026-10818 Published : July 25, 2026, 7:17 a.m. | 17 hours, 20 minutes ago Description :The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to,…
CVE-2026-66374 – Knot Resolver Heap-Based Buffer Overflow Remote Code Execution
CVE ID :CVE-2026-66374 Published : July 25, 2026, 1:16 a.m. | 23 hours, 21 minutes ago Description :Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC)…
CVE-2026-61892 – Weintek cMT3092X Incorrect Permission Assignment for Critical Resource
CVE ID :CVE-2026-61892 Published : July 24, 2026, 11:16 p.m. | 1 hour, 20 minutes ago Description :Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. Severity: 8.8 | HIGH…
CVE-2026-60134 – Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision
CVE ID :CVE-2026-60134 Published : July 24, 2026, 11:16 p.m. | 1 hour, 20 minutes ago Description :Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. Severity: 8.8 |…
CVE-2026-61884 – Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel
CVE ID :CVE-2026-61884 Published : July 24, 2026, 10:16 p.m. | 2 hours, 20 minutes ago Description :The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login…
CVE-2025-71408 – NLTK < 3.9.2 Eval Injection via collocations.py Command-Line Arguments
CVE ID :CVE-2025-71408 Published : July 24, 2026, 10:16 p.m. | 2 hours, 20 minutes ago Description :NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that…
CVE-2026-66041 – FFmpeg 7.0 – 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter
CVE ID :CVE-2026-66041 Published : July 24, 2026, 8:18 p.m. | 4 hours, 18 minutes ago Description :FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc…
CVE-2026-58275 – Azure DNS Elevation of Privilege Vulnerability
CVE ID :CVE-2026-58275 Published : July 24, 2026, 12:01 a.m. | 35 minutes ago Description :None Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline,…