CVE-2026-24079
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVSS
8.1
High
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Published: Aug 4, 2026 · Last modified: Aug 6, 2026 · CWE-306
0.1%EPSS · 30 days0.2%
2026-08-052026-08-31
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-751337.5 HIG—
——0Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable dump filename based on the database name, a limited random range, and the current Unix timestamp to download the generated backup from the publicly accessible uploads directory.1dCVE-2026-660478.1 HIG—
——0ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin installation and activation, achieving PHP code execution as the web-server user.1dCVE-2026-8269510.0 CRI—
——0A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.1dCVE-2026-8269410.0 CRI—
——0A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.1dCVE-2026-8269310.0 CRI—
——0A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.1dCVE-2026-585749.8 CRI26.3%
——8Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.1d