CVE-2026-78032
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server priv
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 28 ago 2026 · Última mod.: 28 ago 2026 · CWE-502
Sin historial EPSS suficiente todavía.
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-78614——
——0WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.17hCVE-2026-78612——
——0WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.17hCVE-2026-100368.8 ALT—
——0SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file within the configured checkpoint path to trigger code execution during candidate discovery, even if the malicious checkpoint is never selected for recovery.23hCVE-2026-782929.8 CRÍ42.3%
——13Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.1dCVE-2026-782869.8 CRÍ42.3%
——13Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.1dCVE-2026-782767.2 ALT40.9%
——12Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.1d