{"source":"cve","note":"Free 5-item preview. The full feed is $0.05/call at GET /v1/cve/changes.","question":"Which new CVE vulnerabilities were published since T, and how severe (CVSS) are they?","sample":[{"source":"cve","entityId":"cve:CVE-2026-11411","type":"cve_published","title":"CVE-2026-11411 (CVSS 1.9 LOW)","summary":"A security flaw has been discovered in iAI Lab PDF AI App 4.21.0 on Android. Impacted is the function getExternalCacheDir of the component chatpdf.pro. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.","significance":2,"detectedAt":"2026-07-20T00:31:08.811Z","effectiveDate":"2026-06-06T11:16:49.110","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-11411","detail":{"cvss":1.9,"severity":"LOW","status":"Deferred","published":"2026-06-06T11:16:49.110"}},{"source":"cve","entityId":"cve:CVE-2026-11408","type":"cve_published","title":"CVE-2026-11408 (CVSS 2.1 LOW)","summary":"A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of the component Log Viewer Endpoint. Such manipulation of the argument req.query leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The name of the patch is 805d82e7100d49b79b3beb1b9420e8e458987198. It is best practice to apply a patch to resolve this issue.","significance":2,"detectedAt":"2026-07-20T00:31:08.811Z","effectiveDate":"2026-06-06T11:16:48.347","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-11408","detail":{"cvss":2.1,"severity":"LOW","status":"Deferred","published":"2026-06-06T11:16:48.347"}},{"source":"cve","entityId":"cve:CVE-2026-11406","type":"cve_published","title":"CVE-2026-11406 (CVSS 2.1 LOW)","summary":"A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.9.0_beta3-1012-0513-1778656146 is able to resolve this issue. You should upgrade the affected component. The vendor confirms: \"This issue has been addressed by implementing malicious checks on OpenVPN configuration files to prevent command injecti…","significance":2,"detectedAt":"2026-07-20T00:31:08.811Z","effectiveDate":"2026-06-06T10:16:27.017","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-11406","detail":{"cvss":2.1,"severity":"LOW","status":"Deferred","published":"2026-06-06T10:16:27.017"}},{"source":"cve","entityId":"cve:CVE-2026-10725","type":"cve_published","title":"CVE-2026-10725 (CVSS 7.5 HIGH)","summary":"Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large server memory (the \"HTTP/2 bomb\"). The headers_decode method materialises a full key+value copy per indexed reference with no running size check, and the stream_header_block_add method appends (since version 1.12) every CONTINUATION frame to the per-stream buffer unbounded. MAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never consulted on decode. It is absent from the decoder and fr…","significance":8,"detectedAt":"2026-07-20T00:31:08.811Z","effectiveDate":"2026-06-06T10:16:25.790","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-10725","detail":{"cvss":7.5,"severity":"HIGH","status":"Analyzed","published":"2026-06-06T10:16:25.790"}},{"source":"cve","entityId":"cve:CVE-2026-9851","type":"cve_published","title":"CVE-2026-9851 (CVSS 7.2 HIGH)","summary":"The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a nonce and the dispatcher invokes Schedule::updateUser() with the $administrator argument hard-coded to 1, bypassing the only owner-restriction check inside that function and allowing the target user to be determined solely by attacker-supplied input passed directly to wp_update_user(). This makes it possible fo…","significance":7,"detectedAt":"2026-07-20T00:31:08.811Z","effectiveDate":"2026-06-06T05:16:30.047","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9851","detail":{"cvss":7.2,"severity":"HIGH","status":"Deferred","published":"2026-06-06T05:16:30.047"}}]}