CVE-2026-19584
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup,
CVSS
7.7
Alto
EPSS
0.2%
p9
KEV
—
Exploit Today
3
0-100
Publicado: 10 sept 2026 · Última mod.: 11 sept 2026 · CWE-94 · CWE-1336
Sin historial EPSS suficiente todavía.
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-91604.3 MED—
———Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection.
This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.3hCVE-2026-1456010.0 CRÍ—
——0The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.4hCVE-2026-819408.8 ALT—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.6hCVE-2026-812049.8 CRÍ—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.6hCVE-2026-797428.8 ALT—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.6hCVE-2026-785718.8 ALT—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.3h