CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-66402 FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass 01.08.2026 9.3
CVE-2026-67289 FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection 01.08.2026 9.3
CVE-2026-67292 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure 01.08.2026 9.3
CVE-2026-67293 FreeRDP before 3.29.0 Improper Certificate Hostname Validation 01.08.2026 9.3
CVE-2026-67294 FreeRDP before 3.29.0 TLS Certificate EKU Bypass 01.08.2026 9.3
CVE-2026-67305 FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr 01.08.2026 9.4
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options 01.08.2026 9.3
CVE-2026-67330 better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision 01.08.2026 9.4
CVE-2026-67336 better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider 01.08.2026 9.4
CVE-2026-67340 ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts 01.08.2026 9.3
CVE-2026-67341 ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION 01.08.2026 9.3
CVE-2026-67342 ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers 01.08.2026 9.3
CVE-2026-15964 Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change 01.08.2026 9.8
CVE-2026-3141 FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter 01.08.2026 9.1
CVE-2026-68771 ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization 31.07.2026 9.3
CVE-2026-68770 sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False 31.07.2026 9.3
CVE-2026-54725 vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API 31.07.2026 9.6
CVE-2026-52855 Wings exposes node configuration secrets through egg configuration-file templating 31.07.2026 9.9
CVE-2026-58048 01.08.2026 9.4
CVE-2026-17349 pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner 01.08.2026 9.3
CVE-2026-17351 pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) 01.08.2026 9.4
CVE-2026-17566 pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) 01.08.2026 9.4
CVE-2026-17561 Unauthenticated RCE in Innotim Software's Logsign SIEM 31.07.2026 9.8
CVE-2025-67649 Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script 31.07.2026 9.3
CVE-2026-14483 Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command 31.07.2026 9.8
CVE-2026-18452 Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials 31.07.2026 10
CVE-2026-63221 CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions 31.07.2026 9.4
CVE-2026-63223 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules 31.07.2026 9.8
CVE-2026-66418 OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field 31.07.2026 9.3
CVE-2026-68502 LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE 31.07.2026 9.8
CVE-2026-68503 LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard 31.07.2026 9.8
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability 31.07.2026 10
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent 31.07.2026 9.9
CVE-2026-67208 Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console 31.07.2026 9.3
CVE-2026-67594 Spikster Missing Authentication via API Route Group 31.07.2026 9.3
CVE-2026-66066 Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing 01.08.2026 9.5
CVE-2026-12943 This Power Hardware Management Console update is being released to address 31.07.2026 9.8
CVE-2026-12118 IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data 30.07.2026 9.8
CVE-2026-13435 Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure 31.07.2026 9.9
CVE-2026-48499 Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache 30.07.2026 9.3
CVE-2026-12940 Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints 31.07.2026 9.8
CVE-2026-28323 SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability 31.07.2026 9.8
CVE-2026-4978 SQLi in UMAI Vision's Traffic Analysis System 30.07.2026 9.8
CVE-2026-11707 Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager 30.07.2026 9.3
CVE-2026-15435 IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability 31.07.2026 9.8
CVE-2026-53431 Boruta accepts expired JWT client assertions due to missing exp claim validation 31.07.2026 9.1
CVE-2026-47876 VMXNET3 out-of-bounds write vulnerability 30.07.2026 9.3
CVE-2026-54363 CentreStack < 17.5 Hardcoded Key Token Forgery RCE 30.07.2026 9.3
CVE-2026-59309 vCenter authentication-bypass vulnerability 30.07.2026 9.8
CVE-2026-59310 vCenter directory-traversal vulnerability 30.07.2026 9.8
CVE-2026-18363 Weak password recovery mechanism in osTicket by Enhancesoft LLC 30.07.2026 9.1
CVE-2026-44090 Missing authentication for MQTT Broker 30.07.2026 9.3
CVE-2026-44101 OCPP reconfiguration vulnerability 31.07.2026 9.3
CVE-2026-44104 ControllerAgent does not perform validation of firmware 30.07.2026 9.3
CVE-2026-44108 Firewall bypass during shutdown 30.07.2026 9.3
CVE-2026-7849 Command Injection in SCM (idledisconnect parameter) 30.07.2026 9.3
CVE-2026-58046 30.07.2026 9.9
CVE-2026-58066 31.07.2026 9.8
CVE-2026-16610 Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key 30.07.2026 9.8
CVE-2026-48449 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 30.07.2026 10
CVE-2026-67595 VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php 30.07.2026 9.2
CVE-2026-16326 consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 29.07.2026 10
CVE-2026-67426 Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration 29.07.2026 9.3
CVE-2026-67429 Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) 29.07.2026 10
CVE-2026-14529 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery 30.07.2026 9.4
CVE-2026-18236 Google-ADK Continuation Forgery 29.07.2026 9.3
CVE-2026-41939 Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly 30.07.2026 9.3
CVE-2026-54680 Logging operator has Fluentd configuration injection that allows remote code execution 30.07.2026 9.9
CVE-2026-8338 Authentication and Authorization Bypass in Coverity Connect 29.07.2026 9.2
CVE-2026-54735 prebid-server's request forgery vulnerability allows for possible host environment data extraction 29.07.2026 10
CVE-2026-60112 AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() 29.07.2026 9.3
CVE-2026-60113 AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes 30.07.2026 9.3
CVE-2026-67191 Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser 29.07.2026 9.3
CVE-2026-67192 Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher 29.07.2026 9.2
CVE-2026-65886 Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65887 Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 01.08.2026 10
CVE-2026-65888 Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 01.08.2026 10
CVE-2026-65889 Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65890 Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-9177 Server-Side Template Injection in SecureTransport's Apache Velocity mail templates 31.07.2026 9.4
CVE-2026-0667 29.07.2026 9.3
CVE-2026-65884 Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 30.07.2026 10
CVE-2026-65885 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 30.07.2026 9.4
CVE-2026-14488 Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter 29.07.2026 9.1
CVE-2026-14900 Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter 29.07.2026 9.8
CVE-2026-65883 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 29.07.2026 10
CVE-2025-10656 Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation 29.07.2026 9.8
CVE-2026-58161 Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server 29.07.2026 9.2
CVE-2026-58179 Apache Traffic Server: regex_remap plugin overflows the stack from attacker input 30.07.2026 9.2
CVE-2026-58154 Apache Traffic Server: Memory-safety errors in MIME and header parsing 29.07.2026 9.2
CVE-2026-58155 Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling 29.07.2026 9.2
CVE-2026-18191 Vacron|IP Camera - Hidden Functionality 29.07.2026 9.3
CVE-2026-63227 Unrestricted SCORM file upload vulnerability 29.07.2026 9.9
CVE-2026-63229 Pre-authentication blind SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63230 Pre-authentication error-based SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63232 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63233 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63234 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-18072 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter 29.07.2026 9.8
CVE-2026-54658 @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution 29.07.2026 9.8
CVE-2026-62325 goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) 29.07.2026 9.1
CVE-2026-64863 goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite 29.07.2026 9.1
CVE-2026-14446 IBM WebSphere Application Server is affected by a privilege escalation 30.07.2026 9.8
CVE-2026-14512 IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information 30.07.2026 9.8
CVE-2026-14958 OS command injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14959 OS Command Injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14973 Path Traversal in IBM Desktop App 31.07.2026 9.3
CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance 29.07.2026 9.4
CVE-2026-16498 terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 28.07.2026 10
CVE-2026-50736 28.07.2026 9
CVE-2026-50737 28.07.2026 9
CVE-2026-67174 DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick 28.07.2026 9.2
CVE-2026-65880 Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 28.07.2026 10
CVE-2026-11841 CVE-2026-11841 28.07.2026 9.4
CVE-2026-16462 SQL injection via unauthenticated GetGridData endpoint 28.07.2026 9.3
CVE-2026-11756 Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x 28.07.2026 10
CVE-2026-15014 SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter 28.07.2026 9.8
CVE-2026-64541 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket 30.07.2026 9.8
CVE-2026-64551 sctp: validate STALE_COOKIE cause length before reading staleness 30.07.2026 9.1
CVE-2026-66824 Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding 28.07.2026 9.2
CVE-2026-48030 Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78) 27.07.2026 9.9
CVE-2026-55579 Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise 27.07.2026 9.8
CVE-2026-63077 28.07.2026 9.8
CVE-2026-16812 VeloCloud Orchestrator OS Command Injection 28.07.2026 10
CVE-2026-66394 SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass 28.07.2026 9.3
CVE-2026-66395 SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol 28.07.2026 9.4
CVE-2026-66396 SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL 28.07.2026 9.3
CVE-2026-66398 phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API 28.07.2026 9.4
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication 28.07.2026 9.1
CVE-2026-59527 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59533 WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59538 WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59549 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59550 WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-61511 vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php 29.07.2026 9.3
CVE-2026-65766 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 28.07.2026 9.2
CVE-2026-65876 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 28.07.2026 9.2
CVE-2026-48144 Apache Thrift: c_glib TLS Client Missing Hostname Verification 28.07.2026 9.1
CVE-2026-55971 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() 28.07.2026 9.3
CVE-2026-64534 nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path 30.07.2026 9.8
CVE-2026-64535 nvmet-tcp: Fix potential UAF when ddgst mismatch 30.07.2026 9.8
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle 27.07.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2025-71402 better-auth before 1.4.0 Session Revocation via Forged Cookie 01.08.2026
CVE-2025-71403 better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass 01.08.2026
CVE-2025-71404 better-auth before 1.1.16 Reflected XSS via error parameter 01.08.2026
CVE-2026-10773 Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) 01.08.2026 5.4
CVE-2026-66401 FreeRDP before 3.29.0 Out-of-Bounds Read via UVC H.264 01.08.2026
CVE-2026-66402 FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass 01.08.2026
CVE-2026-67288 FreeRDP before 3.29.0 Denial of Service via smartcard cache 01.08.2026
CVE-2026-67289 FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection 01.08.2026
CVE-2026-67290 FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF 01.08.2026
CVE-2026-67291 FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD 01.08.2026
CVE-2026-67292 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure 01.08.2026
CVE-2026-67293 FreeRDP before 3.29.0 Improper Certificate Hostname Validation 01.08.2026
CVE-2026-67294 FreeRDP before 3.29.0 TLS Certificate EKU Bypass 01.08.2026
CVE-2026-67295 FreeRDP before 3.29.0 Path Traversal via drive redirection 01.08.2026
CVE-2026-67296 FreeRDP before 3.29.0 Denial of Service via RDPEI PDU 01.08.2026
CVE-2026-67297 FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response 01.08.2026
CVE-2026-67298 FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow 01.08.2026
CVE-2026-67299 FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message 01.08.2026
CVE-2026-67300 FreeRDP before 3.29.0 Use-After-Free via async message proxy 01.08.2026
CVE-2026-67301 FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy 01.08.2026
CVE-2026-67302 FreeRDP rdpecam StartStreamsRequest divide-by-zero denial of service 01.08.2026
CVE-2026-67303 FreeRDP before 3.29.0 Denial of Service via serial DeviceControl 01.08.2026
CVE-2026-67304 FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup 01.08.2026
CVE-2026-67305 FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr 01.08.2026
CVE-2026-67306 FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE 01.08.2026
CVE-2026-67307 Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync 01.08.2026
CVE-2026-67308 Wazuh GitHub Actions Shell Injection via Fork Pull Request 01.08.2026
CVE-2026-67309 Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass 01.08.2026
CVE-2026-67310 openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks 01.08.2026
CVE-2026-67311 Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect 01.08.2026
CVE-2026-67312 axios 0.28.0 before 0.33.0 Denial of Service via formToJSON 01.08.2026
CVE-2026-67313 axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON 01.08.2026
CVE-2026-67314 axios before 1.18.0 Prototype Pollution via auth subfields 01.08.2026
CVE-2026-67315 axios 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 01.08.2026
CVE-2026-67316 axios before 1.18.0 Prototype Pollution via bodyless methods 01.08.2026
CVE-2026-67317 axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream 01.08.2026
CVE-2026-67318 axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2 01.08.2026
CVE-2026-67319 axios before 0.33.0 Prototype Pollution via nested option objects 01.08.2026
CVE-2026-67320 axios before 0.33.0 Prototype Pollution via Node HTTP adapter 01.08.2026
CVE-2026-67321 axios before 0.33.0 Denial of Service via maxDepth bypass 01.08.2026
CVE-2026-67322 GitPython before 3.1.52 Environment Variable Exfiltration via clone_from 01.08.2026
CVE-2026-67323 GitPython before 3.1.51 Command Injection via unguarded Git options 01.08.2026
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options 01.08.2026
CVE-2026-67325 GitPython before 3.1.51 Command Injection via option prefix abbreviation 01.08.2026
CVE-2026-67326 GitPython before 3.1.50 Newline Injection via config_writer section 01.08.2026
CVE-2026-67327 better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP 01.08.2026
CVE-2026-67328 @better-auth/sso before 1.6.21 Account Takeover via SSO 01.08.2026
CVE-2026-67329 @better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription 01.08.2026
CVE-2026-67330 better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision 01.08.2026
CVE-2026-67331 better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass 01.08.2026
CVE-2026-67332 @better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypass 01.08.2026
CVE-2026-67333 better-auth before 1.6.13 Stored XSS via javascript redirect_uri 01.08.2026
CVE-2026-67334 better-auth Stale Sessions Persist After User Deletion 01.08.2026
CVE-2026-67335 better-auth before 1.6.2 OAuth State Validation Bypass 01.08.2026
CVE-2026-67336 better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider 01.08.2026
CVE-2026-67337 better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieCache 01.08.2026
CVE-2026-67338 JupyterLab before 4.5.9 Stored XSS via Extension Manager 01.08.2026
CVE-2026-67339 guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure 01.08.2026
CVE-2026-67340 ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts 01.08.2026
CVE-2026-67341 ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION 01.08.2026
CVE-2026-67342 ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers 01.08.2026
CVE-2026-67343 ArcadeDB before 26.7.2 Cluster Token Disclosure via GET /api/v1/server 01.08.2026
CVE-2026-67344 ArcadeDB before 26.7.2 Authentication Bypass via ALTER TYPE 01.08.2026
CVE-2026-67352 luci-app-https-dns-proxy Stored XSS via resolver_url 01.08.2026
CVE-2026-67353 guzzlehttp/guzzle before 7.15.1 Unbounded Cookie Denial of Service 01.08.2026
CVE-2026-67354 guzzlehttp/guzzle before 7.15.1 URI Fragment Disclosure via Referer 01.08.2026
CVE-2026-67355 guzzlehttp/guzzle before 7.15.1 Host-only Cookie Scope 01.08.2026
CVE-2026-10772 01.08.2026
CVE-2026-2411 Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values 01.08.2026 6.5
CVE-2026-18536 Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP 01.08.2026
CVE-2025-14073 WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure 01.08.2026 5.3
CVE-2026-15644 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute 01.08.2026 6.4
CVE-2026-15964 Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change 01.08.2026 9.8
CVE-2026-16635 Pronamic Pay <= 10.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms 'Update user role' Field 01.08.2026 8.8
CVE-2026-17555 WPvivid <= 0.9.131 - Authenticated (Administrator+) SQL Injection via 'export_data' Parameter 01.08.2026 4.9
CVE-2026-17571 Fluent Forms <= 6.2.8 - Reflected Cross-Site Scripting via 'param' 01.08.2026 6.1
CVE-2026-18344 Responsive Thumbnail Slider < 1.1.53 - Reflected Cross-Site Scripting via 'id' Parameter 01.08.2026 6.1
CVE-2026-6453 CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'relation_id' Parameter 01.08.2026 6.5
CVE-2026-10782 RealHomes Memberships <= 3.0.9 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass via 'ims_add_paypal_recurring_membership' AJAX Action 01.08.2026 4.3
CVE-2026-11995 Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action() 01.08.2026 5.3
CVE-2026-13458 GenerateBlocks <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes 01.08.2026 6.4
CVE-2026-15018 Database Collation Fix <= 1.2.10 - Unauthenticated SQL Injection via 'force-collation-algorithm' Parameter 01.08.2026 5.3
CVE-2026-15052 MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder <= 4.3.3 - Unauthenticated Stored Cross-Site Scripting via Form Field Values 01.08.2026 7.2
CVE-2026-15450 NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter 01.08.2026 8.1
CVE-2026-15601 Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip) 01.08.2026 4.9
CVE-2026-15645 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nav' Shortcode Attribute 01.08.2026 6.4
CVE-2026-15649 Powerkit <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 01.08.2026 6.4
CVE-2026-15662 Advanced Woo Labels <= 2.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_color' Parameter 01.08.2026 6.4
CVE-2026-15950 Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute 01.08.2026 6.4
CVE-2026-15951 Icegram Mailer <= 1.0.12 - Authenticated (Administrator+) SQL Injection via 'fields' Parameter 01.08.2026 4.9
CVE-2026-16087 Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Injection via 'messages[][id]' Parameter 01.08.2026 6.5
CVE-2026-16090 GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via gamipress_achievement Shortcode 01.08.2026 6.4
CVE-2026-16091 GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gamipress_rank' Shortcode 01.08.2026 6.4
CVE-2026-16144 Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter 01.08.2026 8.1
CVE-2026-16614 GSheetConnector <= 5.2.1 - Authenticated (Administrator+) SQL Injection via 's' Parameter 01.08.2026 4.9
CVE-2026-16684 Easy Property Listings <= 3.5.24 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'facebook' User Contact Method 01.08.2026 6.4
CVE-2026-16685 Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute 01.08.2026 6.4
CVE-2026-17580 Advanced Views <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via 'view-refresh' and 'card-refresh' REST Endpoints 01.08.2026 6.5
CVE-2026-17605 Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field 01.08.2026 6.6
CVE-2026-18059 PixelYourSite <= 11.2.1 - Unauthenticated Sensitive Information Exposure via Order-Received Endpoint Missing Key Validation 01.08.2026 5.3
CVE-2026-18062 Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content 01.08.2026 6.4
CVE-2026-18435 Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute 01.08.2026 6.4
CVE-2025-14469 Theme Editor <= 3.1 - Cross-Site Request Forgery to CSS Modification 01.08.2026 4.3
CVE-2026-15988 AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match 01.08.2026 8.8
CVE-2026-2916 Jeg Kit for Elementor <= 3.1.1 - Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline Script 01.08.2026 4.3
CVE-2025-15669 Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label 01.08.2026
CVE-2026-10827 Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes 01.08.2026
CVE-2026-11882 Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes 01.08.2026
CVE-2026-12696 wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field 01.08.2026
CVE-2026-12966 Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions 01.08.2026
CVE-2026-13157 Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload 01.08.2026
CVE-2026-13158 Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload 01.08.2026
CVE-2026-13329 WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund 01.08.2026
CVE-2026-13596 Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search 01.08.2026
CVE-2026-13604 Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX 01.08.2026
CVE-2026-13725 Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax 01.08.2026
CVE-2026-13729 Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF 01.08.2026
CVE-2026-14195 Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info 01.08.2026
CVE-2026-14197 Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR 01.08.2026
CVE-2026-14214 Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment 01.08.2026
CVE-2026-14292 WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title 01.08.2026
CVE-2026-14309 Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass 01.08.2026
CVE-2026-14315 Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission 01.08.2026
CVE-2026-14561 Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure 01.08.2026
CVE-2026-14596 DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection 01.08.2026
CVE-2026-14822 Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation 01.08.2026
CVE-2026-14823 Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR 01.08.2026
CVE-2026-14836 Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass 01.08.2026
CVE-2026-14839 Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure 01.08.2026
CVE-2026-14840 YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing 01.08.2026
CVE-2026-15234 Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute 01.08.2026
CVE-2026-15244 HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view 01.08.2026
CVE-2026-15262 Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column 01.08.2026
CVE-2026-15368 Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration 01.08.2026
CVE-2026-15932 Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal 01.08.2026
CVE-2026-3141 FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter 01.08.2026 9.1
CVE-2026-13362 SendPulse Email Marketing Newsletter <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via _sp_form_code Post Meta 01.08.2026 6.4
CVE-2026-15006 Bit integrations <= 2.9.0 - Unauthenticated Arbitrary File Read via Optional CF7 File Field 01.08.2026 7.5
CVE-2026-15403 Pinpoint Booking System <= 2.9.9.6.9 - Authenticated (Administrator+) SQL Injection via 'field' Parameter 01.08.2026 4.9
CVE-2026-15414 Subscriptions for WooCommerce <= 2.0.0 - Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta 01.08.2026 8.8
CVE-2026-7623 SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute 01.08.2026 6.4
CVE-2026-34641 Premiere Pro | Out-of-bounds Write (CWE-787) 31.07.2026 7.8
CVE-2026-45377 Decidim: Private exports can be downloaded through reusable links 31.07.2026 6.5
CVE-2026-45376 Decidim: Admin user search allows SQL injection through similarity-based sorting 31.07.2026 5.5
CVE-2026-54768 WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design) 31.07.2026
CVE-2026-54785 gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode 31.07.2026 6.2
CVE-2026-45330 Decidim: Verification admins can access supplied IDs from other organisations 31.07.2026 4.9
CVE-2026-53573 core-geonetwork has an Open Redirect Bypass 31.07.2026
CVE-2026-54787 sigstore-go fails to check signature timestamps against a signing key's validity period 31.07.2026 3.1
CVE-2026-54909 Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute 31.07.2026 5.3
CVE-2026-9044 Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75 31.07.2026
CVE-2026-45086 Decidim: Forms admin question editor lacks authorization 31.07.2026 5.4
CVE-2026-51953 31.07.2026
CVE-2026-52134 31.07.2026
CVE-2026-52232 31.07.2026
CVE-2026-52371 31.07.2026
CVE-2026-68771 ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization 31.07.2026
CVE-2025-69946 31.07.2026
CVE-2025-69948 31.07.2026
CVE-2026-65981 Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover 31.07.2026 7.1
CVE-2026-68770 sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False 31.07.2026
CVE-2026-38708 31.07.2026
CVE-2026-38710 31.07.2026
CVE-2026-38713 31.07.2026
CVE-2026-50986 31.07.2026
CVE-2026-51785 31.07.2026
CVE-2026-53551 free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure 31.07.2026