Skip to content

Menu
  • Home
Menu

CVE-2026-8457 – WooCommerce – Social Login <= 2.8.7 – Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT

Posted on August 2, 2026

CVE ID :CVE-2026-8457 Published : Aug. 2, 2026, 12:16 a.m. | 1 hour, 25 minutes ago Description :The WooCommerce – Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up…

CVE-2026-18556 – Unauthenticated administrative account takeover

Posted on August 2, 2026

CVE ID :CVE-2026-18556 Published : Aug. 1, 2026, 8:16 p.m. | 3 hours, 25 minutes ago Description :Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue…

CVE-2026-55735 – Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation

Posted on August 2, 2026

CVE ID :CVE-2026-55735 Published : Aug. 1, 2026, 7:16 p.m. | 4 hours, 25 minutes ago Description :Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim’s session…

CVE-2026-67343 – ArcadeDB before 26.7.2 Cluster Token Disclosure via GET /api/v1/server

Posted on August 2, 2026

CVE ID :CVE-2026-67343 Published : Aug. 1, 2026, 1:17 p.m. | 10 hours, 25 minutes ago Description :ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing…

CVE-2026-67342 – ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers

Posted on August 2, 2026

CVE ID :CVE-2026-67342 Published : Aug. 1, 2026, 1:17 p.m. | 10 hours, 25 minutes ago Description :ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus,…

CVE-2026-67341 – ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION

Posted on August 2, 2026

CVE ID :CVE-2026-67341 Published : Aug. 1, 2026, 1:17 p.m. | 10 hours, 25 minutes ago Description :ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with…

CVE-2026-9044 – Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75

Posted on August 1, 2026

CVE ID :CVE-2026-9044 Published : July 31, 2026, 11:17 p.m. | 24 minutes ago Description :An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows…

CVE-2026-68771 – ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization

Posted on August 1, 2026

CVE ID :CVE-2026-68771 Published : July 31, 2026, 10:17 p.m. | 1 hour, 25 minutes ago Description :ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to…

CVE-2026-68770 – sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False

Posted on August 1, 2026

CVE ID :CVE-2026-68770 Published : July 31, 2026, 9:17 p.m. | 2 hours, 24 minutes ago Description :sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting…

CVE-2026-62959 – Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)

Posted on August 1, 2026

CVE ID :CVE-2026-62959 Published : July 31, 2026, 8:16 p.m. | 3 hours, 25 minutes ago Description :Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when…

Posts pagination

1 2 … 120 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme