CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-46412 Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm 20.07.2026 10
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport 20.07.2026 9
CVE-2026-57309 Blind SQL Injection in Windu CMS 20.07.2026 9.3
CVE-2026-63756 SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition 20.07.2026 9.2
CVE-2026-64620 FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common 20.07.2026 9.3
CVE-2026-64621 FreeRDP before 3.28.0 Double-Free via selectedmonitors 20.07.2026 9.3
CVE-2026-64622 Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox 20.07.2026 9.3
CVE-2026-16242 Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates 20.07.2026 9.4
CVE-2026-44359 Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow 19.07.2026 10
CVE-2026-64035 igc: set tx buffer type for SMD frames 20.07.2026 9.8
CVE-2026-64037 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled 20.07.2026 9.8
CVE-2026-64046 net: tls: prevent chain-after-chain in plain text SG 20.07.2026 9.8
CVE-2026-64047 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring 20.07.2026 9.8
CVE-2026-64055 net: ethernet: cortina: Carry over frag counter 20.07.2026 9.8
CVE-2026-64056 net: ethernet: cortina: Make RX SKB per-port 20.07.2026 9.8
CVE-2026-64061 netfs: Fix early put of sink folio in netfs_read_gaps() 20.07.2026 9.8
CVE-2026-64066 netfs: Fix netfs_read_to_pagecache() to pause on subreq failure 20.07.2026 9.8
CVE-2026-64067 netfs: Fix missing barriers when accessing stream->subrequests locklessly 20.07.2026 9.8
CVE-2026-64068 netfs: Fix missing locking around retry adding new subreqs 20.07.2026 9.8
CVE-2026-64069 netfs: Fix cancellation of a DIO and single read subrequests 20.07.2026 9.8
CVE-2026-64080 firmware: arm_ffa: Snapshot notifier callbacks under lock 20.07.2026 9.3
CVE-2026-64089 batman-adv: tt: fix negative last_changeset_len 20.07.2026 9.8
CVE-2026-64091 batman-adv: tt: fix TOCTOU race for reported vlans 20.07.2026 9.8
CVE-2026-64102 RDMA/siw: Reject MPA FPDU length underflow before signed receive math 20.07.2026 9.8
CVE-2026-64106 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits 20.07.2026 9
CVE-2026-64113 ixgbevf: fix use-after-free in VEPA multicast source pruning 20.07.2026 9.8
CVE-2026-64122 net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover 20.07.2026 9.8
CVE-2026-64125 net: bcmgenet: keep RBUF EEE/PM disabled 20.07.2026 9.8
CVE-2026-64132 ipv6: ioam: refresh hdr pointer before ioam6_event() 20.07.2026 9.8
CVE-2026-64136 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() 20.07.2026 9.8
CVE-2026-64142 ksmbd: close durable scavenger races against m_fp_list lookups 20.07.2026 9.8
CVE-2026-64150 netfilter: nft_inner: release local_lock before re-enabling softirqs 20.07.2026 9.8
CVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_point 20.07.2026 9.8
CVE-2026-64162 idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() 20.07.2026 9.8
CVE-2026-64016 ksmbd: fix durable reconnect error path file lifetime 20.07.2026 9.8
CVE-2026-64018 net: mana: validate rx_req_idx to prevent out-of-bounds array access 20.07.2026 9.3
CVE-2026-64024 tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction 20.07.2026 9.4
CVE-2026-64025 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx 20.07.2026 9.8
CVE-2026-64033 RDMA/rtrs: Fix use-after-free in path file creation cleanup 20.07.2026 9.8
CVE-2026-64034 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer 20.07.2026 9.3
CVE-2026-63886 scsi: target: iscsi: Validate CHAP_R length before base64 decode 20.07.2026 9.8
CVE-2026-63887 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf 20.07.2026 9.8
CVE-2026-63888 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() 20.07.2026 9.8
CVE-2026-63912 xfrm: esp: restore combined single-frag length gate 20.07.2026 9.8
CVE-2026-63922 ipv6: exthdrs: refresh nh after handling HAO option 20.07.2026 9.8
CVE-2026-63924 ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() 20.07.2026 9.8
CVE-2026-63938 KVM: SEV: Check PSC request indices against the actual size of the buffer 20.07.2026 9.3
CVE-2026-63939 KVM: SEV: Compute the correct max length of the in-GHCB scratch area 20.07.2026 9.3
CVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0' 20.07.2026 9.3
CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit 20.07.2026 9.8
CVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doit 20.07.2026 9.8
CVE-2026-63984 ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() 20.07.2026 9.8
CVE-2026-63992 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() 20.07.2026 9.1
CVE-2026-63993 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() 20.07.2026 9.8
CVE-2026-63994 tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() 20.07.2026 9.8
CVE-2026-64000 net: hsr: fix potential OOB access in supervision frame handling 20.07.2026 9.8
CVE-2026-64007 netfilter: synproxy: refresh tcphdr after skb_ensure_writable 20.07.2026 9.8
CVE-2026-63857 net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() 20.07.2026 9.8
CVE-2026-53384 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails 20.07.2026 9.8
CVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanup 20.07.2026 9.8
CVE-2026-53399 nfsd: release layout stid on setlease failure 20.07.2026 9.8
CVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error path 20.07.2026 10
CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout() 20.07.2026 9.8
CVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry() 20.07.2026 9.8
CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes 20.07.2026 9.8
CVE-2026-63830 net: skmsg: preserve sg.copy across SG transforms 20.07.2026 9.4
CVE-2026-9323 Insecure PRNG and Information Exposure in urwid Web Display Backend 18.07.2026 9.2
CVE-2024-58366 SurrealDB before 1.1.1 Format String via Scripting Functions 20.07.2026 9
CVE-2025-71392 SurrealDB before 2.2.2 SurrealQL Injection via export 18.07.2026 9.4
CVE-2026-16117 @fastify/http-proxy vulnerable to prefix escape via URL-encoded characters 20.07.2026 10
CVE-2026-47865 VMware Avi Load Balancer Authentication Bypass Vulnerability 18.07.2026 9.8
CVE-2026-13446 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints 17.07.2026 9.8
CVE-2026-48062 CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule 20.07.2026 9.8
CVE-2026-54159 ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE 20.07.2026 10
CVE-2026-54466 websocket-driver: Message corruption via abuse of protocol length headers 17.07.2026 9.2
CVE-2026-55518 Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation 17.07.2026 9.6
CVE-2026-15091 Multiple Vulnerabilities in IBM Engineering AI hub. 20.07.2026 9.3
CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution 18.07.2026 9.8
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability 20.07.2026 9.9
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint 17.07.2026 9.9
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution 17.07.2026 9.8
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component 17.07.2026 9.9
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header 20.07.2026 9.9
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint 20.07.2026 9.8
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation 17.07.2026 9.9
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation 18.07.2026 9.8
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution 18.07.2026 9.8
CVE-2026-12693 IDOR in Vimesoft's Enterprise Video Platform 17.07.2026 9.4
CVE-2026-12694 Missing Authorization in Vimesoft's Enterprise Video Platform 17.07.2026 9.1
CVE-2026-54496 Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness 17.07.2026 9.3
CVE-2026-12692 Improper Authentication in Vimesoft's Enterprise Video Platform 17.07.2026 9.8
CVE-2026-8297 SQLi in GIS Informatics' GisLab Laboratory Management System 17.07.2026 9.8
CVE-2026-9586 Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB 17.07.2026 9.3
CVE-2024-23564 17.07.2026 9.1
CVE-2026-15982 Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function' 17.07.2026 9.8
CVE-2026-14956 Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter 17.07.2026 9.8
CVE-2026-62232 Grav < 2.0.4 2FA Bypass via Secret Regeneration 17.07.2026 9.1
CVE-2026-62241 clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery 17.07.2026 9.3
CVE-2026-44181 Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution 17.07.2026 10
CVE-2026-44182 Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering 17.07.2026 10
CVE-2026-44180 Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed 17.07.2026 9.8
CVE-2026-53412 Zoom Workplace VDI Plugin for Windows - Improper Input Validation 17.07.2026 9.8
CVE-2026-15422 SCTP needs to better-check INIT ACK chunk parameters 17.07.2026 9.1
CVE-2026-63089 WireGuard Easy Weak Token Generation Information Disclosure via OTL Route 18.07.2026 9
CVE-2026-46512 Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping 18.07.2026 9.9
CVE-2026-46515 Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution 16.07.2026 9.3
CVE-2026-45336 HireFlow: Use of Hard-coded Credentials 17.07.2026 10
CVE-2026-45568 zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths 17.07.2026 9.9
CVE-2026-44632 Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` 16.07.2026 9.1
CVE-2026-46562 Yamcs: Remote Code Execution via Mission Database algorithm override 16.07.2026 9.8
CVE-2026-46621 Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection 16.07.2026 9.1
CVE-2026-63087 Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint 17.07.2026 9.3
CVE-2026-45695 Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used 16.07.2026 9.8
CVE-2026-54733 moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint 16.07.2026 9.3
CVE-2026-59864 Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions 17.07.2026 9.3
CVE-2026-59865 Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` 17.07.2026 9.3
CVE-2026-59866 Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName 17.07.2026 9.3
CVE-2026-11386 ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution 16.07.2026 9
CVE-2026-63304 AVideo through 29.0 OS Command Injection via listFFmpegProcesses 16.07.2026 9.2
CVE-2026-63305 AVideo through 29.0 OS Command Injection via ffmpeg.json.php 17.07.2026 9.2
CVE-2026-63306 stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints 16.07.2026 9.2
CVE-2023-49899 Origin Validation Error in X-Rite MA-T6 18.07.2026 9.8
CVE-2023-49900 Origin Validation Error in X-Rite MA-T6 16.07.2026 9.8
CVE-2026-22752 Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata 16.07.2026 9.6
CVE-2026-15925 Improper TLS Hostname Verification in Snowflake Connector for Python 16.07.2026 9.2
CVE-2026-15013 SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion 16.07.2026 9.8
CVE-2026-54458 AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin 16.07.2026 9.6
CVE-2026-55445 Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication 18.07.2026 9.3
CVE-2026-52891 Wekan: Shell Injection via Avatar Upload 17.07.2026 9.9
CVE-2026-52893 Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook 18.07.2026 9.2
CVE-2026-55652 Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin) 17.07.2026 9.8
CVE-2026-46339 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes 16.07.2026 10
CVE-2026-49352 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass 16.07.2026 9.8
CVE-2026-54052 n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments 18.07.2026 9.9
CVE-2026-52887 NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE 20.07.2026 10
CVE-2026-45534 DataEase: RCE Vulnerability 16.07.2026 9
CVE-2026-46684 DataEase: Unauthorized Command Execution Vulnerability 17.07.2026 9.5
CVE-2026-49445 Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access 16.07.2026 9.2
CVE-2026-46421 Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) 15.07.2026 9.3
CVE-2026-62948 OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI 15.07.2026 9.6
CVE-2026-50562 FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows 15.07.2026 9.3
CVE-2026-53512 Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins 18.07.2026 9.1
CVE-2026-53513 Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration 15.07.2026 9.6
CVE-2026-62378 RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover 16.07.2026 9
CVE-2026-52842 Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass 15.07.2026 9.3
CVE-2026-52843 Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode 15.07.2026 9.3
CVE-2026-44986 Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile 15.07.2026 9.9
CVE-2026-50148 Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write 20.07.2026 10
CVE-2026-42533 NGINX Map directive and Regex matching vulnerability 16.07.2026 9.2
CVE-2026-61736 LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests 15.07.2026 9.3
CVE-2026-61740 LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection 15.07.2026 9.3
CVE-2026-56400 open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation 15.07.2026 9
CVE-2026-56699 Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index 15.07.2026 10
CVE-2026-61451 Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url 15.07.2026 9.4
CVE-2026-13385 16.07.2026 9.5
CVE-2026-45363 `jwt` (Ruby gem) - empty-key HMAC bypass 15.07.2026 9.1
CVE-2026-48334 Illustrator | Improper Input Validation (CWE-20) 15.07.2026 9.3
CVE-2026-48284 ColdFusion | Improper Input Validation (CWE-20) 15.07.2026 9.6
CVE-2026-48318 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 15.07.2026 9.9
CVE-2026-48319 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 15.07.2026 9.1
CVE-2026-48321 ColdFusion | Incorrect Authorization (CWE-863) 16.07.2026 9.3
CVE-2026-48322 ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) 15.07.2026 9.6
CVE-2026-48324 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 15.07.2026 9.1
CVE-2026-48325 ColdFusion | Missing Authentication for Critical Function (CWE-306) 15.07.2026 9.3
CVE-2026-48327 ColdFusion | Incorrect Authorization (CWE-863) 15.07.2026 9
CVE-2026-15643 AWS HealthLake MCP Server SSRF via Pagination URL 15.07.2026 9.2
CVE-2026-53486 decompress: Archive extraction can create files and links outside the target directory 15.07.2026 9.1
CVE-2026-13001 Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter 14.07.2026 9.8
CVE-2026-47428 Vitest browser mode serves unsanitized otelCarrier query parameter as inline script 15.07.2026 9.6
CVE-2026-48356 Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434) 15.07.2026 9.6
CVE-2026-48358 Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) 15.07.2026 9.1
CVE-2026-53633 Vitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE 16.07.2026 9.8
CVE-2026-47429 Vitest: Arbitrary file can be read and executed when Vitest UI server is listening 14.07.2026 9.8
CVE-2026-48259 Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918) 15.07.2026 9.6
CVE-2026-48359 Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) 15.07.2026 9.6
CVE-2026-45063 Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator 14.07.2026 9.1
CVE-2026-50380 Windows GDI+ Remote Code Execution Vulnerability 17.07.2026 9.6
CVE-2026-50447 Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-50518 Windows DHCP Server Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-55010 Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability 17.07.2026 9.1
CVE-2026-55944 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-56190 Remote Desktop Protocol Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-57092 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability 17.07.2026 9.9
CVE-2026-42990 SQL Server ODBC driver Elevation of Privilege Vulnerability 17.07.2026 9.8
CVE-2026-48561 Microsoft Copilot Remote Code Execution Vulnerability 17.07.2026 9.6
CVE-2026-49172 Windows FTP Service Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability 17.07.2026 9.3
CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-54990 Remote Desktop Client Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-55008 Microsoft Exchange Server Spoofing Vulnerability 17.07.2026 9.6
CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability 17.07.2026 9.8
CVE-2026-59891 Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry 14.07.2026 9.6
CVE-2026-15701 Totolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow 15.07.2026 9.3
CVE-2025-11698 CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow 14.07.2026 9.2
CVE-2026-55954 Missing ID token claim validation in ueberauth_apple allows account takeover 15.07.2026 9.1
CVE-2025-12011 CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow 14.07.2026 9.2
CVE-2025-12012 CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow 14.07.2026 9.2
CVE-2026-15265 Tenable Agent Path Traversal Leading to Remote Code Execution 14.07.2026 9.3
CVE-2026-58479 Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection 14.07.2026 9.2
CVE-2026-10577 Rockwell Automation 1715 Redundant IO – Access Control Vulnerability 14.07.2026 10
CVE-2026-62422 15.07.2026 10
CVE-2026-56451 14.07.2026 10
CVE-2026-15183 Input Validation Vulnerabilities in Snowflake Spark Connector 14.07.2026 9.2
CVE-2026-57898 14.07.2026 9
CVE-2026-27690 HTTP Request Smuggling in SAP Approuter 14.07.2026 9.1
CVE-2026-44747 Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP 15.07.2026 9.9
CVE-2026-44761 Insecure Sample Credentials in SAP Commerce Cloud 15.07.2026 9.1
CVE-2026-59801 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers 14.07.2026 9.3
CVE-2026-62327 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats 14.07.2026 9.3
CVE-2026-58409 ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload 14.07.2026 9.1

Latest Updates

CVE Title Updated Score
CVE-2026-13724 Business Logic Bypass in Gobito's Corporate Training Management System 20.07.2026 4.3
CVE-2026-21824 A privilege escalation vulnerability affects HCL Commerce 20.07.2026 8.8
CVE-2026-25039 The application evaluate UNC path in workspace name 20.07.2026 8.8
CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c 20.07.2026
CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero 20.07.2026
CVE-2026-45709 Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer 20.07.2026 5.8
CVE-2026-45711 Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs 20.07.2026 5.9
CVE-2026-45712 Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write) 20.07.2026 5.9
CVE-2026-45713 Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes 20.07.2026 7.5
CVE-2026-46412 Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm 20.07.2026 10
CVE-2026-46415 Caddy Defender trusted proxy client IP bypass 20.07.2026 8.2
CVE-2026-48824 Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw) 20.07.2026 5.3
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport 20.07.2026
CVE-2026-16252 Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection 20.07.2026
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() 20.07.2026
CVE-2026-45139 CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations 20.07.2026 6.5
CVE-2026-45270 CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule 20.07.2026 8.7
CVE-2026-46410 FileBrowser Quantum: unauthenticated user share share info 20.07.2026
CVE-2026-46516 Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments) 20.07.2026
CVE-2026-51386 20.07.2026
CVE-2026-52349 20.07.2026
CVE-2026-53405 Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask 20.07.2026
CVE-2026-53421 Apache Syncope: Remote Code Execution via Scripted Connector 20.07.2026
CVE-2026-54685 FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel 20.07.2026 5.3
CVE-2026-54910 FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files 20.07.2026 7.7
CVE-2026-57308 Apache Syncope: SQL injection vulnerability in Audit Events search 20.07.2026
CVE-2026-59238 Stored XSS in Pentestify via unsanitized finding images and report client logo 20.07.2026
CVE-2026-62183 Apache Syncope: User self-service privilege escalation 20.07.2026
CVE-2026-62418 Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check 20.07.2026
CVE-2026-63071 Apache Syncope: RCE via Groovy Sandbox bypass 20.07.2026
CVE-2026-63090 ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly 20.07.2026
CVE-2026-63091 ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser 20.07.2026
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys 20.07.2026
CVE-2026-16244 itsourcecode Hospital Management System prescriptionorderreport.php sql injection 20.07.2026
CVE-2026-16248 Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow 20.07.2026
CVE-2026-57309 Blind SQL Injection in Windu CMS 20.07.2026
CVE-2026-57310 Weak password hashing in Windu CMS 20.07.2026
CVE-2026-57311 Unrestricted Upload of File with Dangerous Type in Windu CMS 20.07.2026
CVE-2026-14448 Authenticated RCE in system_certificates view 20.07.2026
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering 20.07.2026
CVE-2026-16246 Insecure permission assignment due to execution of LogPathConfig.exe during setup 20.07.2026 7.3
CVE-2026-16247 Insecure permission overwrite due to execution of LogPathConfig.exe while installing _connect.BRAIN 20.07.2026 7.3
CVE-2026-63733 SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause 20.07.2026
CVE-2026-63734 SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import 20.07.2026
CVE-2026-63735 SurrealDB before 3.2.0 Authentication Bypass via Custom API 20.07.2026
CVE-2026-63736 SurrealDB before 3.2.0 SSRF via JWKS URL hostname resolution 20.07.2026
CVE-2026-63737 SurrealDB before 3.1.5 Denial of Service via deep operator chains 20.07.2026
CVE-2026-63738 SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal 20.07.2026
CVE-2026-63739 SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER 20.07.2026
CVE-2026-63740 SurrealDB before 3.1.4 Array Element Permission Bypass 20.07.2026
CVE-2026-63741 SurrealDB before 3.1.0 Authentication Bypass via USE statement 20.07.2026
CVE-2026-63742 SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT 20.07.2026
CVE-2026-63743 SurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP Redirect 20.07.2026
CVE-2026-63744 SurrealDB before 3.1.5 SSRF via JWKS URL Redirect 20.07.2026
CVE-2026-63745 SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id 20.07.2026
CVE-2026-63746 SurrealDB before 3.1.0 Permission Bypass via Graph Traversal 20.07.2026
CVE-2026-63747 SurrealDB before 3.1.0 Denial of Service via malformed RPC use 20.07.2026
CVE-2026-63748 SurrealDB before 3.1.0 Information Disclosure via Error Messages 20.07.2026
CVE-2026-63749 SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT 20.07.2026
CVE-2026-63750 SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket 20.07.2026
CVE-2026-63751 SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch 20.07.2026
CVE-2026-63752 SurrealDB before 3.1.0 RELATE Statement Record Overwrite 20.07.2026
CVE-2026-63753 SurrealDB before 3.1.0 Authentication Bypass via LIVE Query 20.07.2026
CVE-2026-63754 SurrealDB before 3.1.0 Denial of Service via LIVE Query 20.07.2026
CVE-2026-63755 SurrealDB before 3.1.0 Permission Bypass via WHERE Clause 20.07.2026
CVE-2026-63756 SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition 20.07.2026
CVE-2026-63757 SurrealDB before 3.1.0 Session Hijacking via /rpc sessions 20.07.2026
CVE-2026-63758 SurrealDB before 3.1.0 Authorization Bypass via KILL Statement 20.07.2026
CVE-2026-63759 SurrealDB before 3.1.0 Denial of Service nested type annotations 20.07.2026
CVE-2026-63760 SurrealDB before 3.1.0 Denial of Service via JSON Parser 20.07.2026
CVE-2026-63761 SurrealDB before 3.1.0 Algorithm Downgrade via ES512 20.07.2026
CVE-2026-63762 SurrealDB before v2.6.1 Denial of Service via scripting 20.07.2026
CVE-2026-63763 SurrealDB before 2.5.0 Privilege Escalation via Future Fields 20.07.2026
CVE-2026-64620 FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common 20.07.2026
CVE-2026-64621 FreeRDP before 3.28.0 Double-Free via selectedmonitors 20.07.2026
CVE-2026-64622 Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox 20.07.2026
CVE-2026-64623 Network-AI before 5.13.4 Cryptographic Signature Verification Bypass 20.07.2026
CVE-2026-15813 Kronosnet: kronosnet: memory corruption and out-of-bounds access via malformed network packet defragmentation 20.07.2026
CVE-2026-16254 Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk installed-database parser 20.07.2026
CVE-2026-13577 Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable 20.07.2026
CVE-2026-16242 Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates 20.07.2026
CVE-2026-2445 Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification 20.07.2026 6.1
CVE-2026-10081 Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget 20.07.2026
CVE-2026-10724 Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews 20.07.2026
CVE-2026-10755 All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration 20.07.2026
CVE-2026-11349 Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more 20.07.2026
CVE-2026-11868 WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation 20.07.2026
CVE-2026-12592 SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header 20.07.2026
CVE-2026-12723 Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library 20.07.2026
CVE-2026-12724 Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password 20.07.2026
CVE-2026-12898 All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal 20.07.2026
CVE-2026-12970 LearnPress < 4.4.1 - Reflected XSS via c_search 20.07.2026
CVE-2026-12972 PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering 20.07.2026
CVE-2026-12973 PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification 20.07.2026
CVE-2026-13142 Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force 20.07.2026
CVE-2026-13147 Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis 20.07.2026
CVE-2026-13156 MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF 20.07.2026
CVE-2026-13432 ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation 20.07.2026
CVE-2026-16235 Crypt::Password versions through 0.28 for Perl generate insecure random values for salts 20.07.2026
CVE-2026-6656 Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks 20.07.2026
CVE-2026-8825 Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API 20.07.2026
CVE-2026-9833 Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter 20.07.2026
CVE-2026-42566 Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure 19.07.2026 7.5
CVE-2026-45138 CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule 20.07.2026 5.4
CVE-2026-44359 Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow 19.07.2026 10
CVE-2026-12484 Unsafe Deserialization in keras.layers.TorchModuleWrapper.from_config 20.07.2026