{"sector":{"id":"ics","name":"Industrial Control Systems / OT","sector":"industrial","description":"Operational technology, ICS/SCADA, manufacturing, energy and utilities.\nHeavy weight on PLC/HMI vendors and protocol-level vulnerabilities.","visibility":"public"},"top_24h":[{"id":"f6966d75-71ff-4ab8-af5f-1d0829d58a5f","threat_type":"cve","title":"WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to up","summary":"WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T13:19:10.050000Z","last_modified_at":"2026-08-13T13:29:56.940763Z","external_id":"CVE-2026-49827","description":"WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818.","affected_products":[],"references":["https://github.com/SMEWebify/WebErpMesv2/commit/5c54862fa044b363fd2be03d586750e81afd6818","https://github.com/SMEWebify/WebErpMesv2/security/advisories/GHSA-chhq-7p67-2ff9"],"sources":["nvd"],"score":80.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":true,"matched":["manufacturing"],"points":25},"cwe_match":{"hit":true,"matched":["CWE-306"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":9.8,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":80,"final_score":80.0},"calculated_at":"2026-08-13T13:29:59.699419Z"},{"id":"70227679-453f-404d-bd31-a14fdb63de34","threat_type":"cve","title":"GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git","summary":"GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T12:17:27.753000Z","last_modified_at":"2026-08-13T12:26:34.402949Z","external_id":"CVE-2026-73625","description":"GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.","affected_products":[],"references":["https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3","https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-kwarg-value-smuggling"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":8.8,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T12:26:35.106731Z"},{"id":"2b169071-6a86-4567-add2-962e9ea21db7","threat_type":"cve","title":"UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerIn","summary":"UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers &gt; 0` count check — a condition that is false on every fresh install — allowing an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution at `backend/networking/wake.go:43` (`exec.CommandContext(ctx, \"/bin/sh\", \"-c\", wake_cmd)`). Version 5.4.0 fixes the issue.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T00:17:32.747000Z","last_modified_at":"2026-08-13T13:29:54.774108Z","external_id":"CVE-2026-49819","description":"UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers &gt; 0` count check — a condition that is false on every fresh install — allowing an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution at `backend/networking/wake.go:43` (`exec.CommandContext(ctx, \"/bin/sh\", \"-c\", wake_cmd)`). Version 5.4.0 fixes the issue.","affected_products":[],"references":["https://github.com/seriousm4x/UpSnap/releases/tag/5.4.0","https://github.com/seriousm4x/UpSnap/security/advisories/GHSA-w4jr-728f-5jhq"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-306","CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":9.8,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T13:29:59.107732Z"},{"id":"105efa27-a05c-41f7-92e1-1f9a45a253ec","threat_type":"cve","title":"UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality du","summary":"UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be inserted into the wake_cmd and shutdown_cmd templates and executed via /bin/sh -c (Linux) or cmd /C (Windows) without sanitization, resulting in an authenticated Remote Code Execution (RCE). A low-privileged user with permission to create or edit devices can execute arbitrary operating system commands on the UpSnap hosted server. Version 5.4.0 patches the issue.","severity":"critical","cvss_score":9.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-12T23:17:21.363000Z","last_modified_at":"2026-08-13T00:14:34.258508Z","external_id":"CVE-2026-49481","description":"UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be inserted into the wake_cmd and shutdown_cmd templates and executed via /bin/sh -c (Linux) or cmd /C (Windows) without sanitization, resulting in an authenticated Remote Code Execution (RCE). A low-privileged user with permission to create or edit devices can execute arbitrary operating system commands on the UpSnap hosted server. Version 5.4.0 patches the issue.","affected_products":[],"references":["https://github.com/seriousm4x/UpSnap/releases/tag/5.4.0","https://github.com/seriousm4x/UpSnap/security/advisories/GHSA-6mc7-6948-w5h4"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":9.6,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T02:01:16.824376Z"},{"id":"d6c04544-ae4d-4c6b-82f7-291f16ef1dce","threat_type":"cve","title":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafte","summary":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-12T18:18:15.480000Z","last_modified_at":"2026-08-12T19:09:39.017649Z","external_id":"CVE-2026-73327","description":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.","affected_products":[],"references":["https://github.com/joomla/joomla-cms","https://github.com/joomla/joomla-cms/commit/9678a171d37e1e10ca75c9124bdafe20fe14fa5b","https://github.com/joomla/joomla-cms/pull/48057","https://www.vulncheck.com/advisories/joomla-zip-slip-path-traversal-via-com-joomlaupdate-extract-php"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-22"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":7.6,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T02:01:14.894161Z"},{"id":"115c36aa-57ff-4be3-a19c-a23edcd67b1e","threat_type":"cve","title":"Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro","summary":"Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable position, authenticated UI users can run arbitrary commands as the nagios user. Exploitation requires a non-default configuration in which a notification command references these macros in a shell-executed command line.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-12T17:17:27.840000Z","last_modified_at":"2026-08-12T19:09:36.891839Z","external_id":"CVE-2026-48554","description":"Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or $NOTIFICATIONAUTHOR$ in a shell-reachable position, authenticated UI users can run arbitrary commands as the nagios user. Exploitation requires a non-default configuration in which a notification command references these macros in a shell-executed command line.","affected_products":[],"references":["https://github.com/NagiosEnterprises/nagioscore/blob/master/Changelog","https://www.nagios.com/security-disclosures/nagios-core/","https://www.vulncheck.com/advisories/nagios-core-xi-authenticated-rce-via-unfiltered-notification-family-macro-substitution"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T02:01:14.376410Z"},{"id":"74b17f4c-d9df-4088-8956-8547745b1f29","threat_type":"cve","title":"Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection thro","summary":"Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an authenticated attacker with NRDP access can inject OS commands through the macro value. Exploitation requires a non-default configuration in which a custom variable is defined and referenced in a shell-executed command.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-12T17:17:27.697000Z","last_modified_at":"2026-08-12T21:12:12.825986Z","external_id":"CVE-2026-48553","description":"Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a shell-executed command line, an authenticated attacker with NRDP access can inject OS commands through the macro value. Exploitation requires a non-default configuration in which a custom variable is defined and referenced in a shell-executed command.","affected_products":[],"references":["https://github.com/NagiosEnterprises/nagioscore/blob/master/Changelog","https://www.nagios.com/security-disclosures/nagios-core/","https://www.vulncheck.com/advisories/nagios-core-xi-authenticated-rce-via-custom-variable-macro-injection"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":7.5,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T02:01:14.412878Z"},{"id":"503e5859-4db9-412c-bba0-8b0232f88ba6","threat_type":"cve","title":"OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.","summary":"OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renameObject.SrcName, supplied as src_name, before concatenating it with the authorized path and passing the result to fs.Rename. A user with rename permission can use traversal segments in src_name to make path normalization select a file outside the authorized directory and configured base path, resulting in cross-user file integrity loss, limited availability impact, and file-existence disclosure through success or error responses. This issue is fixed in version 4.2.4.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T15:20:17.623000Z","last_modified_at":"2026-08-13T15:31:54.005303Z","external_id":"CVE-2026-73509","description":"OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renameObject.SrcName, supplied as src_name, before concatenating it with the authorized path and passing the result to fs.Rename. A user with rename permission can use traversal segments in src_name to make path normalization select a file outside the authorized directory and configured base path, resulting in cross-user file integrity loss, limited availability impact, and file-existence disclosure through success or error responses. This issue is fixed in version 4.2.4.","affected_products":[],"references":["https://github.com/OpenListTeam/OpenList/commit/651da18da4c647d96648d4bb64462baac1c37e04","https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4","https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-95cv-r8x4-vh75"],"sources":["nvd"],"score":35.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-22"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":7.6,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":35,"final_score":35.0},"calculated_at":"2026-08-13T15:31:57.383575Z"},{"id":"4e353ef8-b660-435b-9a80-396ea35d4585","threat_type":"cve","title":"rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controll","summary":"rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.","severity":"high","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T15:20:00.117000Z","last_modified_at":"2026-08-13T15:31:53.420147Z","external_id":"CVE-2026-70461","description":"rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.","affected_products":[],"references":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-jhxm-j4mq-3fj4","https://www.vulncheck.com/advisories/rsync-heap-out-of-bounds-write-via-files-from-entry"],"sources":["nvd"],"score":35.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-787"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":8.2,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":35,"final_score":35.0},"calculated_at":"2026-08-13T15:31:55.648288Z"},{"id":"bd56bf86-618a-496b-bf1e-e99b18fbc090","threat_type":"cve","title":"rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks withi","summary":"rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T15:19:59.957000Z","last_modified_at":"2026-08-13T15:31:53.342252Z","external_id":"CVE-2026-70460","description":"rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.","affected_products":[],"references":["https://github.com/RsyncProject/rsync/releases/tag/v3.5.0","https://github.com/RsyncProject/rsync/security/advisories/GHSA-w3xf-j2r2-gv4x","https://www.vulncheck.com/advisories/rsync-path-traversal-via-partial-dir-backup-dir-symlink"],"sources":["nvd"],"score":35.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-22"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":8.1,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":35,"final_score":35.0},"calculated_at":"2026-08-13T15:31:55.710196Z"}],"top_7d":[{"id":"f6966d75-71ff-4ab8-af5f-1d0829d58a5f","threat_type":"cve","title":"WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to up","summary":"WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T13:19:10.050000Z","last_modified_at":"2026-08-13T13:29:56.940763Z","external_id":"CVE-2026-49827","description":"WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818.","affected_products":[],"references":["https://github.com/SMEWebify/WebErpMesv2/commit/5c54862fa044b363fd2be03d586750e81afd6818","https://github.com/SMEWebify/WebErpMesv2/security/advisories/GHSA-chhq-7p67-2ff9"],"sources":["nvd"],"score":80.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":true,"matched":["manufacturing"],"points":25},"cwe_match":{"hit":true,"matched":["CWE-306"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":9.8,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":80,"final_score":80.0},"calculated_at":"2026-08-13T13:29:59.699419Z"},{"id":"cace28d3-fd4d-4310-9b02-2892e366e5c9","threat_type":"cve","title":"A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions &lt; V4.3.4.1 running Industrial OS with Node-RED i","summary":"A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions &lt; V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server.\nThis could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.","severity":"critical","cvss_score":10.0,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-11T13:19:00.190000Z","last_modified_at":"2026-08-12T21:12:01.312607Z","external_id":"CVE-2026-58115","description":"A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions &lt; V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server.\nThis could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.","affected_products":[],"references":["https://cert-portal.siemens.com/productcert/html/ssa-834709.html"],"sources":["nvd"],"score":60.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":true,"matched":["industrial"],"points":25},"cwe_match":{"hit":true,"matched":["CWE-306"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":10.0,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":60,"final_score":60.0},"calculated_at":"2026-08-13T02:00:50.378632Z"},{"id":"abaa3a5b-ec04-440c-9162-0d70b237c000","threat_type":"cve","title":"SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using sp","summary":"SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-11T01:17:20.930000Z","last_modified_at":"2026-08-11T15:37:46.691114Z","external_id":"CVE-2026-44763","description":"SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory and affect other components, resulting in a high impact on confidentiality, integrity, and availability.","affected_products":[],"references":["https://me.sap.com/notes/3759854","https://url.sap/sapsecuritypatchday"],"sources":["nvd"],"score":60.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":true,"matched":["manufacturing"],"points":25},"cwe_match":{"hit":true,"matched":["CWE-22"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":7.6,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":60,"final_score":60.0},"calculated_at":"2026-08-13T02:01:00.039465Z"},{"id":"2250aec3-7dcb-41a5-8d33-5efc6fb7f20e","threat_type":"cve","title":"A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Th","summary":"A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp;\n\nThis vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.","severity":"critical","cvss_score":8.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","cvss_version":"3.1","tags":["nvd","kev","actively-exploited"],"published_at":"2026-08-11T00:00:00Z","last_modified_at":"2026-08-13T13:22:30.492392Z","external_id":"CVE-2026-20349","description":"A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp;\n\nThis vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.","affected_products":["cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.1.28:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.7:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.11:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.13:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.14:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.14:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.15:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.19:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.23:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.9:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.14:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.19:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.27:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.38:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.39:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.42:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.48:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.55:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.57:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.61:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.62:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.67:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.70:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.71:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.76:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.82:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.84:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.85:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.89:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.92:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.1.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.2.5:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.2.7:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.2.8:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.3.39:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.3.46:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.3.53:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.3.55:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.3.56:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.5:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.8:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.22:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.24:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.29:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.34:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.40:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.47:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.50:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.52:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.53:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.57:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.66:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.67:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.68:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.71:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.76:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.82:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.90:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.18.4.135:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.5:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.9:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.12:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.18:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.22:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.24:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.27:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.28:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.31:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.37:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.38:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.19.1.42:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.1.5:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.2.10:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.2.21:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.2.22:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3.4:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3.7:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3.9:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3.10:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3.13:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3.16:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.3.20:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.7:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.10:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.14:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.19:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.22:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.28:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.30:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.34:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.20.4.46:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.1.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.1.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.1.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.1.6:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.2.4:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.2.9:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.2.13:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.2.14:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.2.20:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.2.32:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.22.3.5:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.3:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.7:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.13:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.19:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.22:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.26:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.32:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.23.1.195:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.24.1:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.24.1.5:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.24.1.9:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.24.1.11:*:*:*:*:*:*:*","cpe:2.3:o:cisco:adaptive_security_appliance_software:9.24.1.155:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.1.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.6.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.6.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.6.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.4:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.5:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.5.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.5.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.6:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.7:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.8:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.8.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.9:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.10:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.10.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.11:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.12:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.1.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.1.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.1.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.2.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.2.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.2.4:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.4:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.7:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.4.8:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.6.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.6.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.6.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.6.4:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.7.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.7.10:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.7.10.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.7.11:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.7.13:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:10.0.2:*:*:*:*:*:*:*"],"references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20349"],"sources":["nvd","cisa_kev"],"score":60.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":8.6,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":true,"points":25},"actively_exploited":{"hit":true,"points":15},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":true,"source_count":2,"points":5},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":60,"final_score":60.0},"calculated_at":"2026-08-13T13:24:16.369214Z"},{"id":"13e37cc0-39fc-4c4e-bd19-f433e7878ff7","threat_type":"cve","title":"Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","summary":"Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","severity":"critical","cvss_score":7.0,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd","kev","actively-exploited"],"published_at":"2026-08-11T00:00:00Z","last_modified_at":"2026-08-13T13:22:30.557343Z","external_id":"CVE-2026-68820","description":"Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","affected_products":["cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*"],"references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-68820"],"sources":["nvd","cisa_kev"],"score":60.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":7.0,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":true,"points":25},"actively_exploited":{"hit":true,"points":15},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":true,"source_count":2,"points":5},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":60,"final_score":60.0},"calculated_at":"2026-08-13T13:24:17.652632Z"},{"id":"7e5ceddc-35de-4cf1-b91f-0d0b670b8c7d","threat_type":"cve","title":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t","summary":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.","severity":"critical","cvss_score":10.0,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd","kev","actively-exploited"],"published_at":"2026-08-10T18:18:53.300000Z","last_modified_at":"2026-08-13T13:22:30.617064Z","external_id":"CVE-2026-72898","description":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.","affected_products":["cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*","cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*"],"references":["https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-222-01.json","https://www.cve.org/CVERecord?id=CVE-2026-72898","https://www.metabase.com/blog/security-update","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72898"],"sources":["nvd","cisa_kev"],"score":60.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":false,"matched":[],"points":0},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":10.0,"points":15},"priority_boost":{"hit":false,"matched":[],"points":0},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":true,"points":25},"actively_exploited":{"hit":true,"points":15},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":true,"source_count":2,"points":5},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":60,"final_score":60.0},"calculated_at":"2026-08-13T13:24:21.044872Z"},{"id":"70227679-453f-404d-bd31-a14fdb63de34","threat_type":"cve","title":"GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git","summary":"GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T12:17:27.753000Z","last_modified_at":"2026-08-13T12:26:34.402949Z","external_id":"CVE-2026-73625","description":"GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.","affected_products":[],"references":["https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3","https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-kwarg-value-smuggling"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":8.8,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T12:26:35.106731Z"},{"id":"2b169071-6a86-4567-add2-962e9ea21db7","threat_type":"cve","title":"UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerIn","summary":"UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers &gt; 0` count check — a condition that is false on every fresh install — allowing an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution at `backend/networking/wake.go:43` (`exec.CommandContext(ctx, \"/bin/sh\", \"-c\", wake_cmd)`). Version 5.4.0 fixes the issue.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-13T00:17:32.747000Z","last_modified_at":"2026-08-13T13:29:54.774108Z","external_id":"CVE-2026-49819","description":"UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers &gt; 0` count check — a condition that is false on every fresh install — allowing an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution at `backend/networking/wake.go:43` (`exec.CommandContext(ctx, \"/bin/sh\", \"-c\", wake_cmd)`). Version 5.4.0 fixes the issue.","affected_products":[],"references":["https://github.com/seriousm4x/UpSnap/releases/tag/5.4.0","https://github.com/seriousm4x/UpSnap/security/advisories/GHSA-w4jr-728f-5jhq"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-306","CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":9.8,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T13:29:59.107732Z"},{"id":"105efa27-a05c-41f7-92e1-1f9a45a253ec","threat_type":"cve","title":"UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality du","summary":"UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be inserted into the wake_cmd and shutdown_cmd templates and executed via /bin/sh -c (Linux) or cmd /C (Windows) without sanitization, resulting in an authenticated Remote Code Execution (RCE). A low-privileged user with permission to create or edit devices can execute arbitrary operating system commands on the UpSnap hosted server. Version 5.4.0 patches the issue.","severity":"critical","cvss_score":9.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-12T23:17:21.363000Z","last_modified_at":"2026-08-13T00:14:34.258508Z","external_id":"CVE-2026-49481","description":"UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be inserted into the wake_cmd and shutdown_cmd templates and executed via /bin/sh -c (Linux) or cmd /C (Windows) without sanitization, resulting in an authenticated Remote Code Execution (RCE). A low-privileged user with permission to create or edit devices can execute arbitrary operating system commands on the UpSnap hosted server. Version 5.4.0 patches the issue.","affected_products":[],"references":["https://github.com/seriousm4x/UpSnap/releases/tag/5.4.0","https://github.com/seriousm4x/UpSnap/security/advisories/GHSA-6mc7-6948-w5h4"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-78"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":9.6,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T02:01:16.824376Z"},{"id":"d6c04544-ae4d-4c6b-82f7-291f16ef1dce","threat_type":"cve","title":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafte","summary":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","cvss_version":"3.1","tags":["nvd"],"published_at":"2026-08-12T18:18:15.480000Z","last_modified_at":"2026-08-12T19:09:39.017649Z","external_id":"CVE-2026-73327","description":"Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.","affected_products":[],"references":["https://github.com/joomla/joomla-cms","https://github.com/joomla/joomla-cms/commit/9678a171d37e1e10ca75c9124bdafe20fe14fa5b","https://github.com/joomla/joomla-cms/pull/48057","https://www.vulncheck.com/advisories/joomla-zip-slip-path-traversal-via-com-joomlaupdate-extract-php"],"sources":["nvd"],"score":55.0,"score_breakdown":{"technology_match":{"hit":false,"matched":[],"points":0},"keyword_match":{"hit":false,"matched":[],"points":0},"cwe_match":{"hit":true,"matched":["CWE-22"],"points":20},"cvss_threshold":{"hit":true,"threshold":6.0,"cvss_score":7.6,"points":15},"priority_boost":{"hit":true,"matched":["remote code execution"],"points":20},"excluded":{"hit":false,"matched":[],"points":0},"kev":{"hit":false,"points":0},"actively_exploited":{"hit":false,"points":0},"ransomware":{"hit":false,"points":0},"multi_source":{"hit":false,"source_count":1,"points":0},"package_match":{"hit":false,"matched":[],"points":0},"raw_total":55,"final_score":55.0},"calculated_at":"2026-08-13T02:01:14.894161Z"}],"stats":{"total_threats":103596,"critical_count":282,"high_count":62,"average_score":13.73,"sources_active":["cisa_kev","github_advisories","nvd"]}}