CVE-2026-65082
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful
CVSS
7.0
Alto
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Publicado: 25 ago 2026 · Última mod.: 26 ago 2026 · CWE-94
Sin historial EPSS suficiente todavía.
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-600049.8 CRÍ—
KEV—50Gitea Code Injection Vulnerability12hCVE-2026-584748.8 ALT—
———whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant filenames from the Hub API siblings rfilename field, directly into Python source code without escaping, allowing the crafted filename to break out of the generated string literal and execute injected code on the user's machine before any model download occurs.1dCVE-2026-792496.5 MED8.2%
——2Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted file. (Chromium security severity: Medium)1dCVE-2026-524909.8 CRÍ33.3%
——10An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c2dCVE-2026-408778.7 ALT24.1%
——7Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.6hCVE-2026-39975—27.6%
——8Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3.3d