CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-76590 TRENDnet TEW-755AP ssi wan.cgi stack-based overflow 19.08.2026 9.4
CVE-2026-76850 LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector 19.08.2026 9.3
CVE-2026-76310 Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise 19.08.2026 9.4
CVE-2026-76311 Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise 19.08.2026 9.4
CVE-2026-76312 Improper Access Control through Embedded Reports in Splunk Enterprise 19.08.2026 9.4
CVE-2026-76404 Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app 19.08.2026 9.1
CVE-2026-76589 TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow 19.08.2026 9.4
CVE-2026-75595 Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext 19.08.2026 9.1
CVE-2026-76584 TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow 19.08.2026 9.4
CVE-2026-53545 Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection 19.08.2026 9.8
CVE-2026-53546 Termix: Missing authorization in SSH host credential resolution exposes stored credentials 19.08.2026 9.6
CVE-2026-53548 Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users 19.08.2026 9.6
CVE-2026-16894 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16903 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.6
CVE-2026-16913 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16917 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16919 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16882 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16885 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16834 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16839 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.4
CVE-2026-16840 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16845 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16862 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16864 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16872 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-55085 Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite 19.08.2026 9.6
CVE-2026-55089 Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint 19.08.2026 9.9
CVE-2026-16822 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.3
CVE-2026-22306 Critical flaw impacting OZOLS ERP's automatic update channel 19.08.2026 10
CVE-2026-16687 Power System Buffer Overflow 19.08.2026 9.6
CVE-2026-16835 Power System Improper Certificate Validation 19.08.2026 9.6
CVE-2026-18315 TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter 19.08.2026 9.8
CVE-2026-70496 Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork 19.08.2026 9.9
CVE-2025-14600 Admin Account Takeover via Path Traversal in vsDesk 19.08.2026 9.3
CVE-2026-62682 Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) 19.08.2026 9.3
CVE-2026-72717 Orval: Import-time RCE via schema default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-62681 Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) 19.08.2026 9.3
CVE-2026-66794 Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route 19.08.2026 9.3
CVE-2026-71864 Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client 19.08.2026 9.3
CVE-2026-71865 Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli 19.08.2026 9.3
CVE-2026-71866 Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client 19.08.2026 9.3
CVE-2026-71867 Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator 19.08.2026 9.3
CVE-2026-71868 Orval: Import-time RCE via enum-typed default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-71869 Orval: Import-time RCE via array-items default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-71871 Orval: Import-time RCE via header-parameter default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-72716 Orval: Import-time RCE via query-parameter default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-32475 WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability 19.08.2026 9
CVE-2026-71470 Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa 19.08.2026 9.1
CVE-2026-72529 20.08.2026 9.3
CVE-2026-72530 20.08.2026 9.5
CVE-2026-75143 FFmpeg Heap Buffer Overflow via RIST Protocol Reader 19.08.2026 9.3
CVE-2026-20030 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20231 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities 20.08.2026 9.9
CVE-2026-20315 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities 20.08.2026 10
CVE-2026-20317 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities 19.08.2026 10
CVE-2026-20318 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation Vulnerabilities 19.08.2026 9.6
CVE-2026-20357 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20358 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20359 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 9.9
CVE-2026-48024 Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager 19.08.2026 9.1
CVE-2026-48162 Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager 19.08.2026 9.1
CVE-2026-49441 Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager 19.08.2026 9.1
CVE-2026-62668 Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols 19.08.2026 9.4
CVE-2026-16656 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16816 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-52889 Formie: Server-Side Template Injection in Formie Hidden field defaults 19.08.2026 9.8
CVE-2026-45272 MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File 19.08.2026 9.4
CVE-2026-47187 SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write 20.08.2026 9.3
CVE-2026-53451 Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution 19.08.2026 9.8
CVE-2026-75949 Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 19.08.2026 10
CVE-2026-75954 Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 19.08.2026 9.3
CVE-2026-15065 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.1
CVE-2026-15068 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-71960 Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT 19.08.2026 9.3
CVE-2024-58376 Renovate 37.158.0 before 37.199.0 Command Injection via helmv3 19.08.2026 9.3
CVE-2026-16019 SQL Injection in Faydam Innovation's FAYDAM Datalogger 19.08.2026 9.8
CVE-2026-75916 SiYuan XSS-to-RCE via unescaped block metadata in hint popup 19.08.2026 9.3
CVE-2026-75917 SiYuan before v3.7.4 XSS-to-RCE via pathName.ts 19.08.2026 9.3
CVE-2026-76213 phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle 19.08.2026 9.1
CVE-2026-76214 phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge 19.08.2026 9.1
CVE-2026-76242 stigmem Federation Peer Registration Authentication Bypass 19.08.2026 9.1
CVE-2026-76243 stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth 19.08.2026 9.2
CVE-2026-76244 stigmem-node Insecure Federation Transport Configuration 19.08.2026 9.1
CVE-2026-74803 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 19.08.2026 10
CVE-2026-74804 Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 19.08.2026 9.3
CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 20.08.2026 9.3
CVE-2026-67364 Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 19.08.2026 10
CVE-2026-66613 WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability 19.08.2026 9.8
CVE-2026-73183 WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73185 WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73347 WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability 19.08.2026 9.8
CVE-2026-73364 WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability 19.08.2026 9.8
CVE-2026-73388 WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73389 WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability 19.08.2026 9.8
CVE-2026-73390 WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability 19.08.2026 9.8
CVE-2026-73391 WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-76008 Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow 19.08.2026 10
CVE-2026-76003 UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow 19.08.2026 9.4
CVE-2026-76004 UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow 19.08.2026 9.4
CVE-2026-11751 19.08.2026 9.1
CVE-2026-75976 TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow 18.08.2026 9.4
CVE-2026-70905 18.08.2026 9.8
CVE-2026-70920 18.08.2026 9.9
CVE-2026-70921 18.08.2026 10
CVE-2026-70926 18.08.2026 9.8
CVE-2026-70953 18.08.2026 9.8
CVE-2026-70954 18.08.2026 9.8
CVE-2026-70958 18.08.2026 9.6
CVE-2026-70970 18.08.2026 9.8
CVE-2026-70976 18.08.2026 9.1
CVE-2026-70977 18.08.2026 9.1
CVE-2026-70978 18.08.2026 9.1
CVE-2026-70979 18.08.2026 9.1
CVE-2026-70980 19.08.2026 9
CVE-2026-70981 19.08.2026 9.1
CVE-2026-70984 19.08.2026 9.1
CVE-2026-70994 18.08.2026 9.1
CVE-2026-70995 18.08.2026 9.8
CVE-2026-70997 18.08.2026 9.1
CVE-2026-70998 18.08.2026 9.3
CVE-2026-71014 18.08.2026 9.1
CVE-2026-71015 18.08.2026 9.1
CVE-2026-71026 19.08.2026 9.1
CVE-2026-71036 18.08.2026 9.1
CVE-2026-71037 19.08.2026 9.3
CVE-2026-71040 19.08.2026 9.8
CVE-2026-71059 19.08.2026 9.9
CVE-2026-71063 19.08.2026 9.6
CVE-2026-71064 18.08.2026 9.6
CVE-2026-71065 18.08.2026 9.3
CVE-2026-71074 19.08.2026 9.8
CVE-2026-71102 19.08.2026 9.1
CVE-2026-71152 18.08.2026 9.8
CVE-2026-71164 19.08.2026 9.8
CVE-2026-71166 20.08.2026 9.4
CVE-2026-71167 20.08.2026 9.4
CVE-2026-73865 19.08.2026 9.1
CVE-2026-73866 19.08.2026 9.1
CVE-2026-73905 19.08.2026 9.8
CVE-2026-73912 19.08.2026 9.8
CVE-2026-73916 19.08.2026 9.1
CVE-2026-73917 19.08.2026 9.1
CVE-2026-73920 20.08.2026 9.4
CVE-2026-73921 19.08.2026 9.8
CVE-2026-73922 19.08.2026 9.1
CVE-2026-73924 19.08.2026 9.1
CVE-2026-73930 19.08.2026 9.9
CVE-2026-60591 18.08.2026 9.1
CVE-2026-60672 18.08.2026 9.8
CVE-2026-60696 19.08.2026 9.8
CVE-2026-60698 19.08.2026 9.8
CVE-2026-60702 19.08.2026 9.9
CVE-2026-60720 18.08.2026 9.9
CVE-2026-60721 18.08.2026 9.8
CVE-2026-60727 19.08.2026 9.8
CVE-2026-60728 19.08.2026 9.1
CVE-2026-60730 19.08.2026 9.9
CVE-2026-60737 18.08.2026 9.1
CVE-2026-60754 18.08.2026 9.1
CVE-2026-60782 18.08.2026 9.8
CVE-2026-60821 18.08.2026 9.8
CVE-2026-60858 18.08.2026 9.8
CVE-2026-60861 18.08.2026 9.6
CVE-2026-60905 20.08.2026 9.6
CVE-2026-60916 19.08.2026 9.9
CVE-2026-60921 18.08.2026 9.8
CVE-2026-60946 18.08.2026 9.8
CVE-2026-60947 18.08.2026 9.8
CVE-2026-60958 18.08.2026 9.8
CVE-2026-60970 18.08.2026 9.8
CVE-2026-60971 18.08.2026 9.8
CVE-2026-60977 18.08.2026 9.8
CVE-2026-60990 18.08.2026 9.9
CVE-2026-60995 18.08.2026 9.9
CVE-2026-61001 18.08.2026 9.6
CVE-2026-61003 18.08.2026 9.9
CVE-2026-61008 18.08.2026 9.1
CVE-2026-61018 18.08.2026 9.8
CVE-2026-61021 18.08.2026 9.9
CVE-2026-61029 18.08.2026 9
CVE-2026-61034 18.08.2026 9.1
CVE-2026-61066 18.08.2026 9.9
CVE-2026-61206 18.08.2026 9.9
CVE-2026-61241 18.08.2026 10
CVE-2026-61248 18.08.2026 9.9
CVE-2026-61258 18.08.2026 9.8
CVE-2026-61272 18.08.2026 9.8
CVE-2026-61317 20.08.2026 9.9
CVE-2026-61318 20.08.2026 9.8
CVE-2026-62452 19.08.2026 9.9
CVE-2026-62457 18.08.2026 9.8
CVE-2026-62463 18.08.2026 9.6
CVE-2026-62512 18.08.2026 9.9
CVE-2026-62539 18.08.2026 9.8
CVE-2026-62541 18.08.2026 9.8
CVE-2026-62543 18.08.2026 9.8
CVE-2026-62544 18.08.2026 9.8
CVE-2026-62582 18.08.2026 9.6
CVE-2026-62585 18.08.2026 9.8
CVE-2026-62588 20.08.2026 9.9
CVE-2026-62592 20.08.2026 9.8
CVE-2026-62608 18.08.2026 9.9
CVE-2026-62609 18.08.2026 9.8
CVE-2026-62610 18.08.2026 9.1
CVE-2026-62611 18.08.2026 9.8
CVE-2026-62613 18.08.2026 9.3
CVE-2026-62614 18.08.2026 9.8
CVE-2026-62617 18.08.2026 9.8
CVE-2026-62618 18.08.2026 9.3
CVE-2026-62621 18.08.2026 9.8
CVE-2026-62622 18.08.2026 9.8
CVE-2026-62624 18.08.2026 9.8
CVE-2026-62626 18.08.2026 9.8
CVE-2026-62629 18.08.2026 9.4
CVE-2026-62630 18.08.2026 9.8
CVE-2026-62632 18.08.2026 9.8
CVE-2026-62633 18.08.2026 9.8
CVE-2026-62634 18.08.2026 9.8
CVE-2026-62635 18.08.2026 9.8
CVE-2026-62637 18.08.2026 9.3
CVE-2026-62638 18.08.2026 9.1
CVE-2026-62639 18.08.2026 9.8
CVE-2026-62640 18.08.2026 9.8
CVE-2026-70668 18.08.2026 9.1
CVE-2026-70669 18.08.2026 9.8
CVE-2026-70670 18.08.2026 9.6
CVE-2026-70673 18.08.2026 9.3
CVE-2026-70689 18.08.2026 9.8
CVE-2026-70730 18.08.2026 9.1
CVE-2026-70739 18.08.2026 9.8
CVE-2026-70740 18.08.2026 9.8
CVE-2026-70741 18.08.2026 9.1
CVE-2026-70745 18.08.2026 9.8
CVE-2026-70817 18.08.2026 9.8
CVE-2026-70846 18.08.2026 9.6
CVE-2026-70854 18.08.2026 9.1
CVE-2026-70855 18.08.2026 9.3
CVE-2026-70862 18.08.2026 9.1
CVE-2026-70871 18.08.2026 9.8
CVE-2026-70872 18.08.2026 9.1
CVE-2026-70873 18.08.2026 9.8
CVE-2026-70876 18.08.2026 9.1
CVE-2026-70880 18.08.2026 10
CVE-2026-70883 18.08.2026 9.1
CVE-2026-70884 18.08.2026 9.1
CVE-2026-62988 Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints 18.08.2026 9
CVE-2026-67443 FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) 18.08.2026 9.2
CVE-2026-75877 TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow 19.08.2026 9.4
CVE-2026-52735 ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser 18.08.2026 9.3
CVE-2026-55166 Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR 18.08.2026 9.9
CVE-2026-47627 20.08.2026 9.8
CVE-2026-50161 libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow 19.08.2026 9.3
CVE-2026-75625 Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass 18.08.2026 9.1
CVE-2026-71878 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.2
CVE-2026-71879 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.1
CVE-2026-66780 Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace 18.08.2026 9.9
CVE-2026-18963 Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass 20.08.2026 9.1
CVE-2026-57580 authentik: Account Takeover via SAML NameID Comment Truncation 18.08.2026 9.4
CVE-2026-52723 ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust 18.08.2026 9.1
CVE-2026-67271 19.08.2026 9.8
CVE-2026-45118 MyBB: Contact page reflected XSS 18.08.2026 9.3
CVE-2026-12564 Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf 18.08.2026 9.6
CVE-2026-45117 MyBB: Installer database configuration RCE 18.08.2026 9.8
CVE-2026-75926 Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant 20.08.2026 9.3
CVE-2026-75856 CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU 18.08.2026 9.2
CVE-2026-59940 Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization 18.08.2026 9.8
CVE-2026-32470 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-32474 WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-66627 WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-73187 WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73339 WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73341 WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73343 WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability 18.08.2026 10
CVE-2026-73355 WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73365 WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73366 WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73376 WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73380 WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73381 WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability 18.08.2026 9.1
CVE-2026-73392 WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73397 WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability 18.08.2026 9.8
CVE-2026-73996 WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability 18.08.2026 9.8
CVE-2026-74015 WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-75784 TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow 18.08.2026 10
CVE-2026-28192 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability 18.08.2026 9.6
CVE-2026-32444 WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability 18.08.2026 9.9
CVE-2026-32463 WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-75783 TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow 18.08.2026 9.4
CVE-2026-74902 SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload 18.08.2026 9.3
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log 19.08.2026 9.3
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass 18.08.2026 9.3
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass 19.08.2026 9.3
CVE-2026-75835 Grav API Plugin before 1.0.14 Missing Authorization 18.08.2026 9.3
CVE-2026-75837 Grav before 2.0.14 Privilege Escalation via Group Access Field 19.08.2026 9.3
CVE-2026-75843 ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction 18.08.2026 9.4
CVE-2026-75851 ArcadeDB before 26.8.1 Authentication Bypass via Async Command 18.08.2026 9.4
CVE-2026-75852 ArcadeDB MongoDB wire protocol authentication bypass cross-database 18.08.2026 9.3
CVE-2026-75854 ArcadeDB Redis Wire-Protocol Plugin Missing Authentication 18.08.2026 9.3
CVE-2026-75626 SpiderFoot Stored Cross-Site Scripting via Correlation Titles 19.08.2026 9.3
CVE-2026-75627 Bastillion Authentication Bypass via Path-Prefix Routing Mismatch 18.08.2026 9.3
CVE-2026-15748 Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration 18.08.2026 9.8
CVE-2026-75094 COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection 18.08.2026 9.4
CVE-2026-71424 Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers 18.08.2026 9.6
CVE-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) 20.08.2026 9.3
CVE-2026-47686 vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE 19.08.2026 9.9
CVE-2026-47698 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators 19.08.2026 9.8
CVE-2026-65974 ERPNext: Server-Side Template Injection leading to Remote Code Execution 18.08.2026 9.9
CVE-2026-66795 Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does not validate certificate subject, signername, or requester identity 18.08.2026 9.1
CVE-2026-75106 OpnForm Editable Submission Secret Derivation via Empty Hashids Salt 18.08.2026 9.3
CVE-2026-75110 MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET 18.08.2026 9.3
CVE-2026-19478 Improper Control of Generation of Code ('Code Injection') in GitLab 17.08.2026 9.4
CVE-2026-71472 Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem 17.08.2026 9.1
CVE-2026-66792 Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clusters 19.08.2026 9.9
CVE-2026-74253 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 17.08.2026 10
CVE-2026-74254 Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 18.08.2026 9.3
CVE-2026-71479 New API: Integer overflow in quota billing yields negative charges (self-crediting) 17.08.2026 9.1
CVE-2026-75045 18.08.2026 9.1
CVE-2026-64859 New API: User List API Leaks Root User Access Token Leading to Privilege Escalation 17.08.2026 9.1
CVE-2026-55674 Discourse: Cache poisoning/XSS via color scheme cookies 18.08.2026 9.3
CVE-2026-71566 KubeVirt backend is not authenticated 17.08.2026 9.3
CVE-2026-14564 Sensitive Data Exposure in Innotim Software's Logsign SIEM 17.08.2026 9
CVE-2026-74843 Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow 17.08.2026 10
CVE-2026-74798 SiYuan kernel Path Traversal via database_clean MCP tool 18.08.2026 9.3
CVE-2026-74799 SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure 17.08.2026 9.2
CVE-2026-74800 SiYuan before v3.7.4 Stored XSS via assets endpoint 17.08.2026 9.4
CVE-2026-74872 openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool 18.08.2026 9.3
CVE-2026-74875 openssl_encrypt before 1.4.0 Schema Validation Bypass 17.08.2026 9.3
CVE-2026-74876 openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption 17.08.2026 9.3
CVE-2026-74878 openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass 17.08.2026 9.3
CVE-2026-74880 openssl_encrypt before 1.4.0 Token Leakage via Query Parameters 17.08.2026 9.3
CVE-2026-74885 openssl_encrypt before 1.4.0 Logging Bug and Race Condition 17.08.2026 9.3
CVE-2026-74886 openssl_encrypt before 1.4.0 Plugin Import Guard Bypass 17.08.2026 9.3
CVE-2026-74887 openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module 18.08.2026 9.3
CVE-2026-74889 openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF 17.08.2026 9.3
CVE-2026-74890 openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable 17.08.2026 9.3
CVE-2026-74894 openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token 17.08.2026 9.3
CVE-2026-74895 openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation 17.08.2026 9.3
CVE-2026-74896 openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal 17.08.2026 9.3
CVE-2026-74899 openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy 18.08.2026 9.3
CVE-2026-74900 openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode 17.08.2026 9.3
CVE-2026-74901 openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback 17.08.2026 9.3
CVE-2026-15623 Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service 17.08.2026 9.4
CVE-2026-19977 EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication 18.08.2026 10
CVE-2026-19961 Edimax EW-7478APC formWlSiteSurvey buffer overflow 17.08.2026 9.4
CVE-2026-19959 Edimax EW-7478APC formWanTcpipSetup stack-based overflow 18.08.2026 9.4
CVE-2026-73056 SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token 17.08.2026 9.3
CVE-2026-73061 Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor 17.08.2026 9.3
CVE-2026-74790 Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache 17.08.2026 9.3
CVE-2026-74791 Scriban before 7.0.0 Authorization Bypass via Stale Include Cache 17.08.2026 9.2
CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 18.08.2026 9.3
CVE-2024-13784 Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection 17.08.2026 9.8
CVE-2026-18316 Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action 17.08.2026 9.1
CVE-2026-14524 ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters 17.08.2026 9.1
CVE-2026-16098 ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override 18.08.2026 9.8
CVE-2026-18432 Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter 18.08.2026 9.8
CVE-2026-19924 Tenda AC10 httpd R7WebsSecurityHandler improper authentication 19.08.2026 9.3
CVE-2026-73041 SiYuan before v3.7.4 Remote Code Execution via PDF Annotations 17.08.2026 9.4
CVE-2026-73042 SiYuan before v3.7.4 Remote Code Execution via Menu Metadata 17.08.2026 9.4
CVE-2026-73043 SiYuan before v3.7.4 Remote Code Execution via Template Calculation 17.08.2026 9.4
CVE-2026-73044 SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width 17.08.2026 9.4
CVE-2026-73046 SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth 17.08.2026 9.3
CVE-2026-73050 SiYuan before v3.7.4 Stored XSS via select option color 17.08.2026 9.4
CVE-2026-73052 SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names 17.08.2026 9.4
CVE-2026-73053 SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji 18.08.2026 9.4
CVE-2026-73055 Shescape before 2.1.15 Home Directory Disclosure via BusyBox 17.08.2026 9.3
CVE-2026-74764 Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora 17.08.2026 10
CVE-2026-18855 Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter 17.08.2026 9.1
CVE-2026-19598 Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router 17.08.2026 9.8
CVE-2026-19901 LB-LINK X-PRO easycwmp hard-coded credentials 18.08.2026 9.2
CVE-2026-19900 LB-LINK X-PRO shadow hard-coded credentials 17.08.2026 9.2
CVE-2026-74473 vxlan: use pskb_network_may_pull() in route_shortcircuit() 19.08.2026 9.8
CVE-2026-74474 vxlan: use pskb_network_may_pull() for transmit path header pulls 17.08.2026 9.8
CVE-2026-74475 vxlan: use neigh_ha_snapshot() in route_shortcircuit() 19.08.2026 10
CVE-2026-74476 veth: convert frag_list skbs before running XDP 17.08.2026 9.1
CVE-2026-74478 um: vector: fix use-after-free in vector_mmsg_rx() 19.08.2026 9.8
CVE-2026-74480 net: bridge: stop fast-leave after deleting a port group 19.08.2026 9.8
CVE-2026-74493 net/smc: fix socket use-after-free during link group termination 19.08.2026 9.8
CVE-2026-74495 igbvf: Fix leak in TX DMA error cleanup 19.08.2026 9.8
CVE-2026-74517 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs 17.08.2026 9.3
CVE-2026-74521 ksmbd: use memcmp() to compare ClientGUIDs 17.08.2026 9.1
CVE-2026-74545 rtase: fix double free of multi-frag skb on DMA map failure 17.08.2026 9.8
CVE-2026-74556 scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer 19.08.2026 9.8
CVE-2026-74568 KVM: arm64: vgic: Fix race between LPI release and re-registration 17.08.2026 9.3
CVE-2026-74569 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() 19.08.2026 9.8
CVE-2026-74570 ntfs: harden runlist realloc size calculations 17.08.2026 9.8
CVE-2026-74573 iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE 17.08.2026 9.3
CVE-2026-16142 TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter 17.08.2026 9.8
CVE-2026-15826 User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter 17.08.2026 9.8
CVE-2026-72496 RDMA/bnxt_re: Proper rollback if the ioremap fails 17.08.2026 9.2
CVE-2026-74255 tipc: fix UAF in tipc_l2_send_msg() 17.08.2026 9.8
CVE-2026-74267 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 17.08.2026 9.8
CVE-2026-74268 tcp: clear sock_ops cb flags before force-closing a child socket 17.08.2026 9.8
CVE-2026-74269 bnxt: fix head underflow on XDP head-grow 17.08.2026 9.8
CVE-2026-74279 crypto: cavium/cpt - fix DMA cleanup using wrong loop index 17.08.2026 10
CVE-2026-74280 crypto: marvell/octeontx - fix DMA cleanup using wrong loop index 17.08.2026 10
CVE-2026-74287 sctp: validate embedded address parameter length 17.08.2026 9.1
CVE-2026-74309 vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler 17.08.2026 10
CVE-2026-74310 vhost/net: complete zerocopy ubufs only once 17.08.2026 9.3
CVE-2026-74315 lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() 17.08.2026 9.8
CVE-2026-74345 RDMA/siw: Fix endpoint/socket association handling 17.08.2026 9.8
CVE-2026-74350 ocfs2: validate fast symlink target during inode read 17.08.2026 9.8
CVE-2026-74361 nvme: fix FDP fdpcidx bounds check 17.08.2026 9.8
CVE-2026-74376 md/raid10: reset read_slot when reusing r10bio for discard 17.08.2026 9.8
CVE-2026-74384 nvme-multipath: fix flex array size in struct nvme_ns_head 17.08.2026 9.8
CVE-2026-74394 RDMA/srpt: fix integer overflow in immediate data length check 17.08.2026 9.8
CVE-2026-74398 ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD 17.08.2026 9.8
CVE-2026-74401 dlm: fix add msg handle in send_queue ordered 17.08.2026 9.8
CVE-2026-74406 vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). 17.08.2026 9.8
CVE-2026-74427 afs: Fix netns teardown to cancel the preallocation charger 17.08.2026 9.8
CVE-2026-74428 rxrpc: Fix double unlock in rxrpc_recvmsg() 17.08.2026 9.8
CVE-2026-74433 rxrpc: Fix UAF in rxgk_issue_challenge() 17.08.2026 9.8
CVE-2026-74434 rxrpc: Don't move a peeked OOB message onto the pending queue 17.08.2026 9.8
CVE-2026-74436 rxrpc: serialize kernel accept preallocation with socket teardown 17.08.2026 9.8
CVE-2026-74439 iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry 17.08.2026 9.3
CVE-2026-68457 ksmbd: use opener credentials for FSCTL mutations 18.08.2026 9.1
CVE-2026-68476 ipvs: reload ip header after head reallocation 17.08.2026 9.8
CVE-2026-68477 ipvs: fix more places with wrong ipv6 transport offsets 17.08.2026 9.8
CVE-2026-72014 drbd: reject data replies with an out-of-range payload size 17.08.2026 9.8
CVE-2026-72020 ipvs: reset full ip_vs_seq structs in ip_vs_conn_new 17.08.2026 9.8
CVE-2026-72033 orangefs: keep the readdir entry size 64-bit in fill_from_part() 17.08.2026 9.8
CVE-2026-72041 espintcp: use sk_msg_free_partial to fix partial send 17.08.2026 9.8
CVE-2026-72046 gve: fix header buffer corruption with header-split and HW-GRO 17.08.2026 9.8
CVE-2026-72064 net: mana: Sync page pool RX frags for CPU 17.08.2026 9.8
CVE-2026-72065 net: mana: Validate the packet length reported by the NIC 17.08.2026 9.8
CVE-2026-72069 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() 17.08.2026 9.8
CVE-2026-72083 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE 17.08.2026 9.8
CVE-2026-72084 scsi: target: Bound PR-OUT TransportID parsing to the received buffer 17.08.2026 9.8
CVE-2026-72085 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it 17.08.2026 9.3
CVE-2026-72098 dm-verity: fix buffer overflow in FEC calculation 17.08.2026 9.8
CVE-2026-72129 nvmet-rdma: handle inline data with a nonzero offset 17.08.2026 9.8
CVE-2026-72130 nvmet-auth: reject short AUTH_RECEIVE buffers 17.08.2026 9.8
CVE-2026-72137 xfrm: nat_keepalive: avoid double free on send error 17.08.2026 9.8
CVE-2026-72139 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect 17.08.2026 9.8
CVE-2026-72185 ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() 17.08.2026 9.8
CVE-2026-72186 ntfs: make system files immutable to prevent corruption 17.08.2026 9.1
CVE-2026-72188 ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name() 17.08.2026 9.1
CVE-2026-72191 ntfs3: validate split-point offset in indx_insert_into_buffer 17.08.2026 9.8
CVE-2026-72192 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head 17.08.2026 9.8
CVE-2026-72194 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow 17.08.2026 9.8
CVE-2026-72199 ntfs: validate resident index root values on lookup 18.08.2026 9.8
CVE-2026-72200 ntfs: detect mapping-pairs LCN accumulator overflow 19.08.2026 9.8
CVE-2026-72201 ntfs: validate index entries on reading 18.08.2026 9.8
CVE-2026-72206 ntfs: validate index block header more strictly 18.08.2026 9.8
CVE-2026-72207 ntfs: not change 0-byte $DATA attribute to non-resident 18.08.2026 9.8
CVE-2026-72208 ntfs: add bounds check before accessing EA entries 18.08.2026 9.8
CVE-2026-72209 ntfs: validate attribute values on lookup 17.08.2026 9.8
CVE-2026-72210 ntfs: fix off-by-one in mapping pairs decoding bounds checks 19.08.2026 9.8
CVE-2026-72211 ntfs: grow index root value before reparent header update 18.08.2026 9.8
CVE-2026-72217 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing 17.08.2026 9.8
CVE-2026-72220 sunrpc: harden rq_procinfo lifecycle to prevent double-free 17.08.2026 9.8
CVE-2026-72221 sunrpc: wait for in-flight TLS handshake callback when cancel loses race 17.08.2026 9.8
CVE-2026-72222 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback 17.08.2026 9.8
CVE-2026-72226 batman-adv: tt: prevent TVLV OOB check overflow 17.08.2026 9.8
CVE-2026-72234 batman-adv: access unicast_ttvn skb->data only after skb realloc 17.08.2026 9.8
CVE-2026-72239 x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" 17.08.2026 9.3
CVE-2026-72248 netfilter: flowtable: support IPIP tunnel with direct xmit 17.08.2026 9.8
CVE-2026-72249 netfilter: flowtable: use dst in this direction when pushing IPIP header 17.08.2026 9.8
CVE-2026-72251 netfilter: nf_nat_sip: reload possible stale data pointer 17.08.2026 9.8
CVE-2026-72277 KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory 17.08.2026 9.3
CVE-2026-72278 KVM: arm64: nv: Re-translate VNCR before injecting abort 17.08.2026 9.3
CVE-2026-72279 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR 17.08.2026 9
CVE-2026-72288 KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling 17.08.2026 9.3
CVE-2026-72289 KVM: arm64: vgic: Check the interrupt is still ours before migrating it 17.08.2026 9.3
CVE-2026-72291 KVM: s390: Fix unlikely race in try_get_locked_pte() 17.08.2026 9.3
CVE-2026-72296 net: ife: require ETH_HLEN to be pullable in ife_decode() 17.08.2026 9.1
CVE-2026-72299 tipc: restrict socket queue dumps in enqueue tracepoints 17.08.2026 9.8
CVE-2026-72317 SUNRPC: pin upper rpc_clnt across the TLS connect_worker 17.08.2026 9.8
CVE-2026-72318 cifs: validate DFS referral string offsets 17.08.2026 9.4
CVE-2026-72319 ipvs: ensure inner headers in ICMP errors are in headroom 17.08.2026 9.8
CVE-2026-72320 netfilter: nft_lookup: fix catchall element handling with inverted lookups 17.08.2026 9.1
CVE-2026-72322 ipv6: mcast: Fix potential UAF in MLD delayed work 17.08.2026 9.8
CVE-2026-72323 ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() 17.08.2026 9.8
CVE-2026-72329 net/liquidio: drop cached VF pci_dev LUT 17.08.2026 9.3
CVE-2026-72339 qede: fix off-by-one in BD ring consumption on build_skb failure 17.08.2026 9.8
CVE-2026-72348 netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop 17.08.2026 9.1
CVE-2026-72351 gue: validate REMCSUM private option length 17.08.2026 9.8
CVE-2026-72355 netfs: Fix barriering when walking subrequest list 17.08.2026 9.8
CVE-2026-72366 netfs: Fix netfs_create_write_req() to handle async cache object creation 17.08.2026 9.8
CVE-2026-72381 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check 17.08.2026 9.8
CVE-2026-72393 eth: fbnic: don't cache shinfo across skb realloc 17.08.2026 9.8
CVE-2026-72398 sctp: add INIT verification after cookie unpacking 17.08.2026 9.8
CVE-2026-72399 net: enetc: check the number of BDs needed for xdp_frame 17.08.2026 9.8
CVE-2026-72407 geneve: validate inner network offset in geneve_gro_complete() 17.08.2026 10
CVE-2026-72408 geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint 17.08.2026 10
CVE-2026-72412 s390/mm: Fix handling of _PAGE_UNUSED pte bit 17.08.2026 9.3
CVE-2026-72417 netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() 17.08.2026 9.8
CVE-2026-72421 ipv4: fib: Don't ignore error route in local/main tables. 17.08.2026 10
CVE-2026-72422 ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE 17.08.2026 9.8
CVE-2026-72429 ipv6: ioam: fix type confusion of dst_entry 17.08.2026 9.8
CVE-2026-72436 netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types 17.08.2026 9.8
CVE-2026-72442 netfilter: flowtable: fix and simplify IP6IP6 tunnel handling 17.08.2026 9.8
CVE-2026-72451 xfrm: Fix xfrm state cache insertion race 17.08.2026 9.8
CVE-2026-72463 xfrm: Fix dev use-after-free in xfrm async resumption 17.08.2026 9.8
CVE-2026-72466 xprtrdma: Fix bcall rep leak and unbounded peek 17.08.2026 9.8
CVE-2026-72472 nfs: use nfsi->rwsem to protect traversal of the file lock list 17.08.2026 9.8
CVE-2026-72473 xprtrdma: Decouple req recycling from RPC completion 17.08.2026 9.8
CVE-2026-72477 fs/ntfs3: call _ntfs_bad_inode() when failing to rename 17.08.2026 9.8
CVE-2026-72491 net/9p: fix race condition on rdma->state in trans_rdma.c 17.08.2026 9.8
CVE-2026-72493 net: serialize netif_running() check in enqueue_to_backlog() 17.08.2026 9.9
CVE-2026-72494 RDMA/irdma: Replace waitqueue and flag with completion 17.08.2026 9.8
CVE-2026-72495 RDMA/bnxt_re: Avoid repeated requests to allocate WC pages 17.08.2026 9.3
CVE-2026-14484 RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters 17.08.2026 9.1
CVE-2026-15303 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter 17.08.2026 9.8
CVE-2026-15341 User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters 17.08.2026 9.8
CVE-2026-73683 Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay 18.08.2026 9.2
CVE-2026-67365 Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 18.08.2026 9.2
CVE-2026-17181 IBM Db2 Mirror for i is affected by multiple vulnerabilities 18.08.2026 9.3
CVE-2026-17182 IBM Db2 Mirror for i is affected by multiple vulnerabilities 17.08.2026 9.8
CVE-2026-17184 IBM Db2 Mirror for i is affected by multiple vulnerabilities 18.08.2026 9.8
CVE-2026-17186 IBM Db2 Mirror for i is affected by multiple vulnerabilities 17.08.2026 9.9
CVE-2026-50027 mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete 17.08.2026 9.8
CVE-2026-73678 MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec() 17.08.2026 10
CVE-2026-19188 Haiwell IoT Cloud HMI Gateway OS Command Injection 14.08.2026 10
CVE-2026-49457 QUIC has Broken TLS verification 14.08.2026 9.1
CVE-2026-19681 Command Injection 15.08.2026 9.4
CVE-2026-19682 Command Injection 15.08.2026 9.4
CVE-2026-48528 Metacat has an unauthenticated SQL injection vulnerability 17.08.2026 9.8
CVE-2026-73849 emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. 18.08.2026 9.8
CVE-2026-19626 Remote Code Execution 15.08.2026 9.4
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding 14.08.2026 9.3
CVE-2026-72810 SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket 18.08.2026 9.2
CVE-2026-72811 SiYuan before v3.7.4 SQL Injection via backlink search 14.08.2026 9.9
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa 14.08.2026 9.3
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController 14.08.2026 9.3
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey 18.08.2026 9.3
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController 14.08.2026 9.3
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass 14.08.2026 9.3
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass 18.08.2026 9.2
CVE-2026-12949 Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter 14.08.2026 9.8
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup 14.08.2026 9.3
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 18.08.2026 9.4
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass 14.08.2026 9.4
CVE-2026-72850 Budibase before 3.40.0 Arbitrary File Write via Path Traversal 14.08.2026 9.4
CVE-2026-72851 Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook 14.08.2026 9
CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified 14.08.2026 9
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 14.08.2026 9.1
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 18.08.2026 9.1
CVE-2026-73842 OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation 18.08.2026 9
CVE-2026-73843 OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs 14.08.2026 9.6
CVE-2026-73665 FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection 18.08.2026 9.3
CVE-2026-19750 Tenda CH/CP/TX3 SSH hard-coded password 14.08.2026 9.2
CVE-2026-72776 AgenticSeek Unauthenticated RCE via /query API Endpoint 18.08.2026 9.3
CVE-2026-73663 FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover 14.08.2026 9.3
CVE-2026-17482 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 17.08.2026 9.8
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint 15.08.2026 9.1
CVE-2026-8715 Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath 14.08.2026 9.6
CVE-2026-19747 Tenda CH7 ATE Module Kylin HandleCmd command injection 14.08.2026 9.3
CVE-2026-73656 Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state 14.08.2026 9.9
CVE-2026-14525 IBM WebSphere Application Server Liberty is affected by an authenication bypass 15.08.2026 9.4
CVE-2026-73653 Vitest: Browser Mode provider commands bypass the file-access permission gate 13.08.2026 9.4
CVE-2026-73644 OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant 18.08.2026 9.6
CVE-2026-73649 Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) 14.08.2026 9.8
CVE-2026-73567 sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock 14.08.2026 9.1
CVE-2026-67614 CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal 14.08.2026 9.3
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build 14.08.2026 9.3
CVE-2026-73533 Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build 17.08.2026 9.3
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths 14.08.2026 9.2
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header 14.08.2026 9.1
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode 14.08.2026 9.1
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure 14.08.2026 9.1
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink 14.08.2026 9.2
CVE-2026-27544 WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability 13.08.2026 10
CVE-2026-28001 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28008 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28142 WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28148 WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability 13.08.2026 9.8
CVE-2026-28149 WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability 13.08.2026 9.8
CVE-2026-28185 WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-61962 WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability 13.08.2026 10
CVE-2026-61966 WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61967 WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-61969 WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-66436 WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66446 WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability 13.08.2026 9.8
CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66478 WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66691 WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability 13.08.2026 9.8
CVE-2026-49827 WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) 13.08.2026 9.8
CVE-2026-73483 Flowise before 3.1.3 Sandbox Escape via Puppeteer 14.08.2026 9.4
CVE-2026-73485 Flowise before 3.1.3 Remote Code Execution via Airtable Agent 14.08.2026 9
CVE-2026-73486 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV 13.08.2026 9
CVE-2026-73487 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent 14.08.2026 9
CVE-2026-73601 Flowise before 3.1.3 Remote Code Execution via Custom MCP 14.08.2026 9
CVE-2026-73602 Flowise before 3.1.3 Sandbox Escape to RCE 13.08.2026 9
CVE-2026-73608 SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget 14.08.2026 9.2

Latest Updates

CVE Title Updated Score
CVE-2026-75948 Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 20.08.2026
CVE-2026-76564 Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 20.08.2026
CVE-2025-14601 vsDesk Task Scheduler OS Command Injection 20.08.2026
CVE-2026-76565 Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 20.08.2026
CVE-2026-76569 Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 20.08.2026
CVE-2025-14602 Weak File Name Generation in vsDesk 20.08.2026
CVE-2026-14163 20.08.2026
CVE-2026-71368 20.08.2026
CVE-2026-13405 Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder 20.08.2026
CVE-2026-15049 Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import 20.08.2026
CVE-2026-19615 Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC 20.08.2026
CVE-2026-19697 GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload 20.08.2026
CVE-2026-19699 GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure 20.08.2026
CVE-2026-74992 Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload 20.08.2026
CVE-2026-75860 JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update 20.08.2026
CVE-2026-17153 AI Agent by SiteGround <= 1.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Upload via /generate-content REST Endpoint 20.08.2026 5.3
CVE-2026-75963 Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_page_template' Event Property 20.08.2026 7.5
CVE-2026-73542 20.08.2026 3.7
CVE-2026-19582 Binutils: stack buffer overflow in gnu binutils in rsrc_print_name from an untrusted pe file 20.08.2026
CVE-2026-76956 20.08.2026 7.5
CVE-2026-76957 20.08.2026 4.9
CVE-2026-76800 DeDeCMS select_media_post.php unrestricted upload 20.08.2026
CVE-2026-76799 code-projects Login Registration System SQL Database Backup login_registration_system.sql file access 20.08.2026
CVE-2026-76795 AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery 20.08.2026
CVE-2026-75628 Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter 20.08.2026
CVE-2026-76785 amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection 20.08.2026
CVE-2026-76783 DeDeCMS advancedsearch.php sql injection 20.08.2026
CVE-2026-76764 code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection 20.08.2026
CVE-2022-4996 mruby bigint.c udiv floating point comparison with incorrect operator 19.08.2026
CVE-2026-76762 code-projects Assessment Management welcome.php sql injection 19.08.2026
CVE-2026-8619 Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600 19.08.2026
CVE-2026-76761 chenhg5 cc-connect Management API engine.go shellExecCommand os command injection 19.08.2026
CVE-2026-76926 Reachable Assertion in Wireshark 19.08.2026 3.1
CVE-2026-76927 NULL Pointer Dereference in Wireshark 19.08.2026 4.7
CVE-2026-76928 NULL Pointer Dereference in Wireshark 19.08.2026 7.5
CVE-2026-76929 Out-of-bounds Read in Wireshark 19.08.2026 4.7
CVE-2026-76760 chenhg5 cc-connect webhook.go authenticate code injection 19.08.2026
CVE-2026-76879 Stack-based Buffer Overflow in Wireshark 19.08.2026 7.5
CVE-2026-76880 Out-of-bounds Write in Wireshark 19.08.2026 7.5
CVE-2026-76885 Buffer Over-read in Wireshark 19.08.2026 3.1
CVE-2026-76890 Expired Pointer Dereference in Wireshark 19.08.2026 3.1
CVE-2026-76891 Expired Pointer Dereference in Wireshark 19.08.2026 3.1
CVE-2026-76917 Heap-based Buffer Overflow in Wireshark 19.08.2026 5.5
CVE-2026-76918 Heap-based Buffer Overflow in Wireshark 19.08.2026 5.5
CVE-2026-76919 Use of Uninitialized Variable in Wireshark 19.08.2026 5.3
CVE-2026-76920 Out-of-bounds Write in Wireshark 19.08.2026 4.7
CVE-2026-76921 Use After Free in Wireshark 19.08.2026 5.5
CVE-2026-76922 NULL Pointer Dereference in Wireshark 19.08.2026 5.5
CVE-2026-76923 Out-of-bounds Read in Wireshark 19.08.2026 5.5
CVE-2026-76924 Out-of-bounds Read in Wireshark 19.08.2026 5.5
CVE-2026-76881 NULL Pointer Dereference in Wireshark 19.08.2026 4.7
CVE-2026-76882 Out-of-bounds Read in Wireshark 19.08.2026 4.7
CVE-2026-76883 Heap-based Buffer Overflow in Wireshark 19.08.2026 4.7
CVE-2026-76884 Buffer Over-read in Wireshark 19.08.2026 3.1
CVE-2026-76886 Heap-based Buffer Overflow in Wireshark 19.08.2026 8.1
CVE-2026-76887 Heap-based Buffer Overflow in Wireshark 19.08.2026 3.1
CVE-2026-76888 Heap-based Buffer Overflow in Wireshark 19.08.2026 3.1
CVE-2026-76889 Heap-based Buffer Overflow in Wireshark 19.08.2026 4.7
CVE-2026-18502 19.08.2026
CVE-2026-18862 19.08.2026
CVE-2026-19561 19.08.2026
CVE-2026-19562 19.08.2026
CVE-2026-19563 19.08.2026
CVE-2026-76591 TRENDnet TEW-755AP ssi email.cgi log_email_server command injection 19.08.2026
CVE-2026-76832 Agno PythonTools Path Traversal via joinpath file_name argument 19.08.2026
CVE-2026-76878 19.08.2026
CVE-2026-63123 Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root 19.08.2026 6.5
CVE-2026-76590 TRENDnet TEW-755AP ssi wan.cgi stack-based overflow 19.08.2026
CVE-2026-76850 LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector 19.08.2026
CVE-2026-59992 Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) 19.08.2026 5.4
CVE-2026-76251 Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud 19.08.2026 7.1
CVE-2026-76252 Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk Enterprise 19.08.2026 6.8
CVE-2026-76253 Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76254 SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise 19.08.2026 7.5
CVE-2026-76255 Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise 19.08.2026 6.4
CVE-2026-76256 Information Exposure through REST API Endpoints in Splunk Secure Gateway 19.08.2026 4.3
CVE-2026-76257 Missing Authorization through REST API Endpoints in Splunk Secure Gateway 19.08.2026 6.5
CVE-2026-76258 Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway 19.08.2026 6.5
CVE-2026-76259 Improper Privilege Management on the Management Port in Splunk Enterprise for Windows 19.08.2026 8.8
CVE-2026-76260 Incorrect Permission Assignment for Critical Resource through the REST API in Splunk Enterprise 19.08.2026 6.5
CVE-2026-76261 Insecure Default Access Control List through the REST API in Splunk Secure Gateway 19.08.2026 5.3
CVE-2026-76262 Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise 19.08.2026 7.5
CVE-2026-76263 Improper Access Control through the REST API in Splunk Enterprise 19.08.2026 5.4
CVE-2026-76309 Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise 19.08.2026 4.3
CVE-2026-76310 Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise 19.08.2026 9.4
CVE-2026-76311 Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise 19.08.2026 9.4
CVE-2026-76312 Improper Access Control through Embedded Reports in Splunk Enterprise 19.08.2026 9.4
CVE-2026-76313 Remote Code Execution (RCE) through the REST API in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76314 Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76315 Code Injection through Splunk Web Manager Configuration in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76316 Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76317 Path Traversal through the Lookup Configuration REST API in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76318 Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise 19.08.2026 5.7
CVE-2026-76319 Remote Code Execution (RCE) through Federated Search in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76320 SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Builder in Splunk Web for Splunk Enterprise 19.08.2026 5.9
CVE-2026-76321 SPL Injection through Nearby Event Searches in Splunk Enterprise 19.08.2026 7.3
CVE-2026-76322 SPL Injection through Dashboard Studio Search Query Options in Splunk Enterprise 19.08.2026 6.7
CVE-2026-76323 SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splunk Enterprise 19.08.2026 6.4
CVE-2026-76324 Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise 19.08.2026 5.7
CVE-2026-76325 Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise 19.08.2026 7.3
CVE-2026-76326 Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Splunk Enterprise 19.08.2026 5.7
CVE-2026-76327 SPL Injection through Splunk Web in Splunk Secure Gateway 19.08.2026 6.4
CVE-2026-76328 SPL Injection through Splunk Web in Splunk Enterprise 19.08.2026 6.7
CVE-2026-76329 SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise 19.08.2026 6.4
CVE-2026-76330 SPL Injection through Monitoring Console Forwarder Filters in Splunk Enterprise 19.08.2026 7.1
CVE-2026-76331 SPL Injection through the REST API in Splunk Enterprise 19.08.2026 8.1
CVE-2026-76332 SPL Injection through Splunk Web in Splunk Enterprise 19.08.2026 7.1
CVE-2026-76333 Stored Cross-Site Scripting (XSS) through Dashboard Studio Workflow Actions in Splunk Enterprise 19.08.2026 7.1
CVE-2026-76334 SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise 19.08.2026 6.4
CVE-2026-76335 Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76336 Improper Access Control through the REST API in Splunk Enterprise 19.08.2026 7.1
CVE-2026-76337 Path Traversal through Splunk Web Static File Serving in Splunk Enterprise 19.08.2026 5.3
CVE-2026-76338 Improper Authentication through REST API Distributed Search Token Requests in Splunk Enterprise 19.08.2026 8.1
CVE-2026-76339 SPL Injection through the geostats Command in Splunk Enterprise 19.08.2026 5.4
CVE-2026-76340 Missing Authorization for Reloading Token-Signing Keys through the REST API in Splunk Enterprise 19.08.2026 5.3
CVE-2026-76341 Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in Splunk Enterprise 19.08.2026 5.4
CVE-2026-76342 Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise 19.08.2026 5.4
CVE-2026-76343 Structured Query Language (SQL) Injection through the REST API in Splunk Enterprise 19.08.2026 6.5
CVE-2026-76344 Path Traversal through the Search Dispatch REST API in Splunk Enterprise 19.08.2026 7.7
CVE-2026-76345 Remote Code Execution (RCE) through the REST API in Splunk Enterprise 19.08.2026 6
CVE-2026-76346 Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Format Options in Splunk Enterprise 19.08.2026 5.4
CVE-2026-76347 Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway 19.08.2026 5.4
CVE-2026-76348 Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise 19.08.2026 3.8
CVE-2026-76349 SPL Injection through Splunk Web Form Tokens in Splunk Enterprise 19.08.2026 6.4
CVE-2026-76350 Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76351 Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway 19.08.2026 8.8
CVE-2026-76352 Improper Authorization through the REST API in Splunk Enterprise 19.08.2026 8.8
CVE-2026-76353 Path Traversal through Knowledge Bundle Replication in Splunk Enterprise 19.08.2026 5.4
CVE-2026-76354 Path Traversal through Search Head Clustering in Splunk Enterprise 19.08.2026 8.1
CVE-2026-76355 Unauthenticated Information Disclosure through an Edge Processor Service Endpoint in Splunk Enterprise 19.08.2026 7.5
CVE-2026-76356 Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR 19.08.2026 8.1
CVE-2026-76357 Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR 19.08.2026 7.6
CVE-2026-76358 Path Traversal through App Installation Tar Extraction in Splunk SOAR 19.08.2026 6.5
CVE-2026-76359 Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR 19.08.2026 6.5
CVE-2026-76360 Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR 19.08.2026 4.3
CVE-2026-76361 Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR 19.08.2026 2.7
CVE-2026-76362 Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR 19.08.2026 7.4
CVE-2026-76363 Structured Query Language Injection through the REST API in Splunk SOAR 19.08.2026 6.5
CVE-2026-76364 Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR 19.08.2026 6.5
CVE-2026-76365 Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR 19.08.2026 6.5
CVE-2026-76366 Information Disclosure through the REST API in Splunk SOAR 19.08.2026 6.5
CVE-2026-76367 Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR 19.08.2026 4
CVE-2026-76368 Missing Authorization through Playbooks in Splunk SOAR 19.08.2026 2.7
CVE-2026-76369 Path Traversal through Automation Broker in Splunk SOAR 19.08.2026 2.7
CVE-2026-76370 Information Disclosure through the REST API in Splunk SOAR 19.08.2026 4.3
CVE-2026-76371 Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR 19.08.2026 2.7
CVE-2026-76372 Incorrect Permission Assignment through Safe Mode in Nmap Scanner for Splunk SOAR 19.08.2026 6.6
CVE-2026-76373 Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR 19.08.2026 5.4
CVE-2026-76374 Information Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76375 Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR 19.08.2026 5
CVE-2026-76376 Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76377 Information Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76378 Information Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76379 Information Disclosure through Action Parameters in Cisco Webex app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76380 Information Disclosure through Action Parameters in CrowdStrike OAuth API app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76381 Information Disclosure through Action Parameters in MS Graph for Active Directory app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76382 Information Disclosure through Action Parameters in Phantom app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76383 Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76384 Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for Splunk SOAR 19.08.2026 4.3
CVE-2026-76385 Information Disclosure through Action Parameters in Venafi app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76386 Information Disclosure through Action Parameters in Zoom app for Splunk SOAR 19.08.2026 4.3
CVE-2026-76387 SPL Injection through the REST API in Splunk Enterprise Security 19.08.2026 8.1
CVE-2026-76388 Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security 19.08.2026 8.1
CVE-2026-76389 Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security Cloud 19.08.2026 8.8
CVE-2026-76390 Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security Cloud 19.08.2026 5.3
CVE-2026-76391 Improper Privilege Management through Agent Run History in Splunk AI Toolkit 19.08.2026 8.3
CVE-2026-76392 Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit 19.08.2026 5.4
CVE-2026-76393 Race Condition during Model Upload through the REST API in Splunk AI Toolkit 19.08.2026 5.9
CVE-2026-76394 Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit 19.08.2026 8.3
CVE-2026-76395 Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit 19.08.2026 8.8
CVE-2026-76396 Improper Access Control through Scheduled Searches in Splunk AI Toolkit 19.08.2026 7.5
CVE-2026-76397 Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit 19.08.2026 8.1
CVE-2026-76398 Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit 19.08.2026 4.3
CVE-2026-76399 Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit 19.08.2026 8.1
CVE-2026-76400 Denial of Service (DoS) through the REST API in Splunk Connect for Kafka 19.08.2026 5.9
CVE-2026-76401 Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for Kafka 19.08.2026 5.9
CVE-2026-76402 Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka 19.08.2026 8.2
CVE-2026-76403 Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka 19.08.2026 7.4
CVE-2026-76404 Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app 19.08.2026 9.1
CVE-2026-76405 Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app 19.08.2026 4.3
CVE-2026-76589 TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow 19.08.2026
CVE-2025-36254 DS8900F and DS8A00 Authentication Bypass 19.08.2026 7.4
CVE-2025-36255 DS8900F and DS8A00 Privilege Escalation 19.08.2026 7.5
CVE-2025-36398 DS8900F and DS8A00 Information Disclosure 19.08.2026 5.4
CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability 19.08.2026 6.5
CVE-2026-11617 Tanium addressed a compression bomb vulnerability in Findings. 19.08.2026 3.1
CVE-2026-14514 Reliable Scalable Cluster Technology Denial-of-Service 19.08.2026 6.5
CVE-2026-14978 Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions 19.08.2026 5.5
CVE-2026-75476 Tanium addressed a compression bomb vulnerability in Threat Response. 19.08.2026 3.1
CVE-2026-75595 Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext 19.08.2026
CVE-2026-61556 LiquidJS: An infinite loop vulnerability in `strip_html` filter 19.08.2026
CVE-2026-62727 Windows Telephony Service Elevation of Privilege Vulnerability 19.08.2026 7
CVE-2026-69222 LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process 19.08.2026 7.5
CVE-2026-75596 Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing 19.08.2026
CVE-2026-76584 TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow 19.08.2026
CVE-2026-76827 Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering) 19.08.2026
CVE-2026-12522 Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fields 19.08.2026 8.8
CVE-2026-12633 Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router Advertisement 19.08.2026 8.1
CVE-2026-12634 Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read length 19.08.2026 5.3
CVE-2026-54491 Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths 19.08.2026 7.1
CVE-2026-54492 Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation 19.08.2026 4.3
CVE-2026-54493 Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations 19.08.2026 7.7
CVE-2026-54494 Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4 19.08.2026
CVE-2026-68552 Coturn: uint16_t truncation overflow in STUN message length causes TCP stream framing bypass 19.08.2026 5.3
CVE-2026-68553 Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command 19.08.2026 7.1
CVE-2026-68554 Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests 19.08.2026
CVE-2026-68555 coturn: Chained mobility resumes allow authenticated remote memory exhaustion 19.08.2026 6.5
CVE-2026-75569 Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mutable stolostron/release@master 19.08.2026
CVE-2026-75616 Command Injection in Router Web Management Interface 19.08.2026
CVE-2026-76139 Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials 19.08.2026
CVE-2026-76583 TRENDnet TV-IP751WIC alphapd set_time.cgi command injection 19.08.2026
CVE-2026-17015 IBM i Denial of Service 19.08.2026 5.4
CVE-2026-18102 IBM i Buffer Overflow 19.08.2026 3.5
CVE-2026-18544 Portieris is vulnerable to Image Policy Bypass via Unvalidated ownerReference 19.08.2026 8.1
CVE-2026-53542 Termix: Tar option injection in file-manager archive creation allows command execution on managed SSH hosts 19.08.2026 8.8
CVE-2026-53545 Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection 19.08.2026 9.8
CVE-2026-53546 Termix: Missing authorization in SSH host credential resolution exposes stored credentials 19.08.2026 9.6
CVE-2026-53547 Termix: Account Takeover via Global Settings Disclosure 19.08.2026 8.8
CVE-2026-53548 Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users 19.08.2026 9.6
CVE-2026-53549 Termix: Server-Side Request Forgery via Proxy Connectivity Test 19.08.2026 7.7
CVE-2026-54738 Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo 19.08.2026 6.5
CVE-2026-76582 TRENDnet TEW-821DAP ssi ping.cgi system command injection 19.08.2026
CVE-2026-18849 IBM OpenBMC Code Execution 19.08.2026 6.8
CVE-2026-4936 Power System Insufficient Entropy 19.08.2026 5.1
CVE-2026-4937 Power System Insufficient Entropy 19.08.2026 5.3
CVE-2026-54739 Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential 19.08.2026
CVE-2026-54740 Lemmy: Lower-ranked federated moderator can remove higher-ranked moderators 19.08.2026 6.5
CVE-2026-54741 Lemmy: Blocked users can edit private messages sent before the block 19.08.2026
CVE-2026-54743 Lemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embed 19.08.2026
CVE-2026-76576 yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal 19.08.2026
CVE-2026-16707 Power System Out-of-bounds Read 19.08.2026 8.2
CVE-2026-54742 Lemmy: `CollectionAdd::Featured` does not check the post is in the community 19.08.2026
CVE-2026-61711 BuildKit: Custom frontend could bypass Seccomp/AppArmor 19.08.2026
CVE-2026-61712 BuildKit: Possible runtime DoS via unbounded group parsing 19.08.2026
CVE-2026-75593 BuildKit: Malicious client can bypass destination directory validation on local sources upload 19.08.2026
CVE-2026-16886 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 4.3
CVE-2026-16890 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 3.6
CVE-2026-16891 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 3.3
CVE-2026-16894 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16897 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 4.4
CVE-2026-16901 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16903 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.6
CVE-2026-16909 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16911 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16913 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16914 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 6.7
CVE-2026-16917 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16919 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-76574 code-projects Hospital Information System User Login UsersController.php login sql injection 19.08.2026
CVE-2026-16873 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.8
CVE-2026-16874 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.8
CVE-2026-16875 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.8
CVE-2026-16877 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16882 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16883 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 5.5
CVE-2026-16885 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16888 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 3.7
CVE-2026-17028 Power System Out-of-bounds Read 19.08.2026 6.5
CVE-2026-17091 Power System Integer Overflow 19.08.2026 8.4
CVE-2026-17097 Power System Improper Validation 19.08.2026 7.3
CVE-2026-18821 Power System Out-of-bounds Write 19.08.2026 7.5
CVE-2026-63187 Logto: OS command injection vulnerability exists in the Commitlint workflow 19.08.2026 6.3
CVE-2026-63188 logto-tunnel serves files outside --experience-path via path traversal 19.08.2026
CVE-2026-16661 Power System Integer Overflow 19.08.2026 8.2
CVE-2026-16724 Power System Integer Overflow 19.08.2026 4.5
CVE-2026-16834 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16836 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16837 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16838 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7
CVE-2026-16839 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.4
CVE-2026-16840 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16841 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16842 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16844 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16845 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16846 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 6.5
CVE-2026-16847 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16848 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16849 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 4.3
CVE-2026-16850 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16851 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.4
CVE-2026-16852 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16855 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 5.5
CVE-2026-16857 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.2
CVE-2026-16862 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16864 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-16865 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.8
CVE-2026-16866 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 4.8
CVE-2026-16869 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.8
CVE-2026-16872 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.8
CVE-2026-17414 Power System Improper Input Validation 19.08.2026 8.1
CVE-2026-18871 Power System Buffer Overflow 19.08.2026 7.3
CVE-2026-55085 Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite 19.08.2026 9.6
CVE-2026-55086 Etherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite 19.08.2026 4.2
CVE-2026-55088 Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token 19.08.2026 6.8
CVE-2026-55089 Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint 19.08.2026 9.9
CVE-2026-55090 Etherpad: Stored XSS in HTML export via unescaped attribute-pool values 19.08.2026
CVE-2026-62317 Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing) 19.08.2026 7.5
CVE-2026-76572 pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference 19.08.2026
CVE-2026-16822 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 9.3
CVE-2026-16824 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16825 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 4.2
CVE-2026-16827 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 5.9
CVE-2026-16829 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 5.3
CVE-2026-16831 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16833 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 5.3
CVE-2026-19505 RDK-B WebUI improper cryptographic signature verification vulnerability 19.08.2026
CVE-2026-19506 RDK-B WebUI race condition vulnerability 19.08.2026
CVE-2026-19507 RDK WebUI uncontrolled resource consumption 19.08.2026
CVE-2026-19508 RDK WebUI heap-based buffer overflow vulnerability 19.08.2026
CVE-2026-19509 RDK WebUI DOS vulnerability 19.08.2026
CVE-2026-22306 Critical flaw impacting OZOLS ERP's automatic update channel 19.08.2026
CVE-2026-55087 Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect) 19.08.2026 6.1
CVE-2026-67189 pfSense Plus/CE Stored XSS via Traffic Graphs PTR Record 19.08.2026
CVE-2026-68558 Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446) 19.08.2026 8.5
CVE-2026-68559 Wekan: Broken access control in the Excel-export route (`/api/boards/:boardId/exportExcel`) 19.08.2026 6.5
CVE-2026-68560 Wekan:hell Injection in External Antivirus Scanner Path via asyncExec 19.08.2026
CVE-2026-68561 Wekan: a low-privilege board member escalates to board admin and takes over a private board via the `sort` collection-allow rule 19.08.2026 8.8
CVE-2026-68899 Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback 19.08.2026 8.7
CVE-2026-68900 Wekan: Stored XSS in HTML board exports through a card-title second parse 19.08.2026 7.6
CVE-2026-68901 WeKan Board Export REST Endpoints: NULL Pointer Dereference on Invalid authToken Leads to Uncaught Exception / Remote Denial of Service 19.08.2026 6.5
CVE-2026-74226 19.08.2026
CVE-2026-74227 19.08.2026
CVE-2026-74228 19.08.2026
CVE-2026-76647 Leantime JSON-RPC API contains a missing authorization vulnerability 19.08.2026
CVE-2026-16933 Power System Integer Overflow 19.08.2026 8.2
CVE-2026-17042 Power System Out-of-bounds Read 19.08.2026 7.3
CVE-2026-17063 Power System Incorrect Authorization 19.08.2026 7.9
CVE-2026-17590 19.08.2026
CVE-2026-63722 ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php 19.08.2026
CVE-2026-75112 OTTO® Fleet Manager – Weak Password Hashing Configuration 19.08.2026
CVE-2026-16687 Power System Buffer Overflow 19.08.2026 9.6
CVE-2026-19198 Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch 19.08.2026
CVE-2026-16828 Power System Out-of-bounds Read 19.08.2026 7.6
CVE-2026-16832 Power System Buffer Overflow 19.08.2026 8.4
CVE-2026-16835 Power System Improper Certificate Validation 19.08.2026 9.6
CVE-2026-16930 Power System Missing Authorization 19.08.2026 8.2
CVE-2026-16938 Power System Missing Authorization 19.08.2026 6.9
CVE-2026-17429 Power System Incorrect Authorization 19.08.2026 8.1
CVE-2026-17494 Power System Buffer Overflow 19.08.2026 8.2
CVE-2026-18681 This Power System Buffer Overflow 19.08.2026 6.8
CVE-2026-18848 Power System Cross-Site Request Forgery (CSRF) 19.08.2026 8.3
CVE-2026-17093 Power System Buffer Overflow 19.08.2026 8.2
CVE-2026-17100 Power System Out-of-bounds Write 19.08.2026 8.2
CVE-2026-18315 TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter 19.08.2026 9.8
CVE-2026-19321 Power System Integer Overflow 19.08.2026 6.7
CVE-2026-55643 Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode 19.08.2026
CVE-2026-55694 Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover 19.08.2026
CVE-2026-55703 Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET 19.08.2026 4.3
CVE-2026-61807 Snipe-IT: Stored DOM XSS via table selected-count IDs 19.08.2026
CVE-2026-75618 RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 19.08.2026
CVE-2026-75619 RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 19.08.2026
CVE-2026-49870 Snipe-IT: TOTP Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor` 19.08.2026 5.9
CVE-2026-49976 Snipe-IT: User Account Escalation via CSV Import 19.08.2026 6.5
CVE-2026-50550 Snipe-IT: 2FA reset privilege bypass 19.08.2026 5.8
CVE-2026-55482 Snipe-IT: Multi-Tenancy Bypass via Bulk Asset Update 19.08.2026 6.3
CVE-2026-55483 Snipe-IT: Privilege Escalation via Missing admin Permission Check in User Creation 19.08.2026
CVE-2026-55519 Snipe-IT: Improper Authorization in File Deletion (IDOR) 19.08.2026 5.4
CVE-2026-70496 Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork 19.08.2026
CVE-2026-19234 Power System Buffer Overflow 19.08.2026 8.2
CVE-2026-63633 FreeRDP: Heap buffer overflow in Opus audio decode (`freerdp_dsp_decode_opus` resizes the wrong stream) — server→client 19.08.2026
CVE-2026-69159 FreeRDP: Out-of-Bounds Read in Planar RLE Decoder (planar_decompress_plane_rle / planar_decompress_plane_rle_only) 19.08.2026 5.4
CVE-2026-18874 Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscription 19.08.2026
CVE-2026-55192 FreeRDP: Out-of-bounds read in H.264 YUV-to-RGB conversion due to decoder/surface dimension mismatch 19.08.2026
CVE-2026-55194 FreeRDPHeap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly due to alloc_hint capacity mismatch 19.08.2026
CVE-2026-63117 FreeRDP: Denial of service through ADPCM frame size calculation 19.08.2026 6.5
CVE-2026-63652 FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Client Audio Formats PDU 19.08.2026
CVE-2025-14600 Admin Account Takeover via Path Traversal in vsDesk 19.08.2026
CVE-2026-19653 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 6.5
CVE-2026-55191 FreeRDP: Heap-buffer-overflow write in AVC444 YUV buffer allocation 19.08.2026
CVE-2026-55193 FreeRDP: Heap-buffer-overflow write in TS Gateway RPC fragment receive due to uncapped bind_ack max_xmit_frag 19.08.2026
CVE-2026-55564 FreeRDP: Out-of-bounds read in glyph_cache_get via crafted glyph fragments 19.08.2026 5.4
CVE-2026-55648 FreeRDP: Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds Check 19.08.2026
CVE-2026-61518 ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter 19.08.2026
CVE-2026-62680 Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref 19.08.2026 7.1
CVE-2026-62682 Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) 19.08.2026
CVE-2026-72717 Orval: Import-time RCE via schema default -> zod module-level template literal 19.08.2026
CVE-2026-75149 marimo < 0.23.15 Code Injection via MCP Server Configuration 19.08.2026
CVE-2026-17183 CVE-2026-17183 CVE Record 19.08.2026 7.1
CVE-2026-19875 Unauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in Langflow 19.08.2026 7.5
CVE-2026-62681 Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) 19.08.2026
CVE-2026-66794 Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route 19.08.2026
CVE-2026-71864 Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client 19.08.2026
CVE-2026-71865 Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli 19.08.2026
CVE-2026-71866 Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client 19.08.2026
CVE-2026-71867 Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator 19.08.2026
CVE-2026-71868 Orval: Import-time RCE via enum-typed default -> zod module-level template literal 19.08.2026
CVE-2026-71869 Orval: Import-time RCE via array-items default -> zod module-level template literal 19.08.2026
CVE-2026-71871 Orval: Import-time RCE via header-parameter default -> zod module-level template literal 19.08.2026
CVE-2026-72716 Orval: Import-time RCE via query-parameter default -> zod module-level template literal 19.08.2026
CVE-2025-14603 Use of user input in raw SQL queries in vsDesk leading to blind SQL injection 19.08.2026
CVE-2026-32475 WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability 19.08.2026 9
CVE-2026-67581 On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay 19.08.2026
CVE-2026-73136 Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay 19.08.2026
CVE-2026-73541 Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain 19.08.2026
CVE-2026-73829 Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race 19.08.2026
CVE-2026-50173 Flow-Like: Azure invoke presign grants app content write SAS to ExecuteEvents-only users 19.08.2026
CVE-2026-71470 Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa 19.08.2026
CVE-2026-72529 20.08.2026 9.8
CVE-2026-72530 20.08.2026 9
CVE-2024-13942 Rockchip RK3588s Secure BootROM TOCTOU (time-of-check to time-of-use) vulnerability leading to arbitrary code execution with highest privileges 19.08.2026 7.6
CVE-2026-20320 19.08.2026 7.5
CVE-2026-20327 Cisco Unified Intelligence Center SQL Injection Vulnerability 19.08.2026 6.5
CVE-2026-49392 Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd 19.08.2026 5.3
CVE-2026-75141 FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing 19.08.2026
CVE-2026-75142 FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c 19.08.2026
CVE-2026-75143 FFmpeg Heap Buffer Overflow via RIST Protocol Reader 19.08.2026
CVE-2026-75144 FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer 19.08.2026
CVE-2026-75145 FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer 19.08.2026
CVE-2026-75146 FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c 19.08.2026
CVE-2026-75147 FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c 19.08.2026
CVE-2026-75583 keeper.sh Calendar version prior to 2.18.14 SSRF Guard Bypass via DNS Rebinding 19.08.2026
CVE-2026-20030 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20177 Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability 19.08.2026 5.3
CVE-2026-20231 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities 20.08.2026 9.9
CVE-2026-20232 Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability 19.08.2026 5.4
CVE-2026-20302 Cisco RoomOS Stack Overflow Vulnerability 19.08.2026 6.1
CVE-2026-20314 Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability 19.08.2026 5
CVE-2026-20315 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities 20.08.2026 10
CVE-2026-20317 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities 19.08.2026 10
CVE-2026-20318 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation Vulnerabilities 19.08.2026 9.6
CVE-2026-20319 Cisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management Vulnerabilities 19.08.2026 7.5
CVE-2026-20357 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20358 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20359 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 9.9
CVE-2026-41424 Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint 19.08.2026 8.2
CVE-2026-44255 Wazuh: Username Enumeration via Timing Side-Channel 19.08.2026 5.3
CVE-2026-44256 Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username 19.08.2026 5.3
CVE-2026-44901 Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability 19.08.2026 8.4
CVE-2026-45798 Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field 19.08.2026 7.5
CVE-2026-48024 Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager 19.08.2026 9.1
CVE-2026-48162 Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager 19.08.2026 9.1
CVE-2026-49441 Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager 19.08.2026 9.1
CVE-2026-44252 Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation 19.08.2026
CVE-2026-44253 Wazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulation 19.08.2026 4.9
CVE-2026-44254 Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path 19.08.2026 5.3
CVE-2026-46343 Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file() 19.08.2026
CVE-2026-64852 Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account 19.08.2026
CVE-2026-18430 HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason 19.08.2026
CVE-2026-62671 CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on task=login.regenerate2FASecret) 19.08.2026 5.4
CVE-2026-62673 Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems 19.08.2026
CVE-2026-63407 Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses 19.08.2026 8.2
CVE-2026-63408 Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter 19.08.2026 7.5
CVE-2026-64850 Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() 19.08.2026
CVE-2026-64851 Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers 19.08.2026
CVE-2026-62666 Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super 19.08.2026 8.8
CVE-2026-62667 Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL 19.08.2026 8.1
CVE-2026-62669 Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge 19.08.2026 7.4
CVE-2026-62672 Grav: Authenticated ReDoS via regex_replace in Twig Sandbox 19.08.2026
CVE-2026-19672 tarfile extraction filter bypass allows creation of directories outside the destination 19.08.2026
CVE-2026-61607 Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer 19.08.2026 4.6
CVE-2026-61690 Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits 19.08.2026 6.5
CVE-2026-61842 Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass) 19.08.2026 6.5
CVE-2026-62668 Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols 19.08.2026
CVE-2026-62670 Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny) 19.08.2026 6.3
CVE-2026-16819 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.7
CVE-2026-53654 Grav: Unauthenticated open redirect via login twofa_cancel _redirect 19.08.2026
CVE-2026-14970 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16656 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16686 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.2
CVE-2026-16690 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16703 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 7.8
CVE-2026-16706 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16814 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 8.8
CVE-2026-16816 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-16817 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-16818 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 7.5
CVE-2026-40509 OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter 19.08.2026
CVE-2026-52834 jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platforms 19.08.2026 7.3
CVE-2026-52889 Formie: Server-Side Template Injection in Formie Hidden field defaults 19.08.2026 9.8
CVE-2026-53477 19.08.2026 7.8
CVE-2026-58562 19.08.2026 7.3
CVE-2026-58564 19.08.2026 7.8
CVE-2026-58565 19.08.2026 8.8
CVE-2026-67266 19.08.2026 5.5
CVE-2026-67267 19.08.2026 5.5
CVE-2026-67268 19.08.2026 6.5
CVE-2026-76614 OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore 19.08.2026
CVE-2026-18756 HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering 19.08.2026
CVE-2026-23501 20.08.2026 7.2
CVE-2026-40507 OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal 19.08.2026
CVE-2026-40508 OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler 19.08.2026
CVE-2026-45272 MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File 19.08.2026
CVE-2026-45273 MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint 19.08.2026
CVE-2026-45274 MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement 19.08.2026
CVE-2026-47187 SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write 20.08.2026 9.3
CVE-2026-48711 SSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 20.08.2026 7
CVE-2026-49283 SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass 19.08.2026 8.7
CVE-2026-49289 SimpleSAMLphp SAML2: Possible DoS via XPath Transform 19.08.2026 7.5
CVE-2026-49816 19.08.2026 7.8
CVE-2026-49817 19.08.2026 7.8
CVE-2026-52792 Algernon: Server-side script source disclosure on Windows via NTFS filename 19.08.2026
CVE-2026-53451 Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution 19.08.2026 9.8
CVE-2026-53452 Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath` 19.08.2026 5.3
CVE-2026-56796 19.08.2026 6.6
CVE-2026-56797 19.08.2026 7.3
CVE-2026-75949 Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-75950 Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-75951 Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-75952 Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-75953 Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-75954 Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-75955 Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-75956 Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 19.08.2026
CVE-2026-15061 Vulnerabilities in IBM AIX and PowerVM VIOS 19.08.2026 8.2
CVE-2026-15065 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.1
CVE-2026-15068 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-15078 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 8.1
CVE-2026-15961 Power System Information Disclosure 19.08.2026 5.2
CVE-2026-32802 19.08.2026 5.3
CVE-2026-44829 Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename 19.08.2026 8.8
CVE-2026-45741 Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes 19.08.2026 7.5
CVE-2026-45742 Gotenberg: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') 19.08.2026 7.5
CVE-2026-49253 electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling 19.08.2026 7.1
CVE-2026-49255 electerm: Command Injection in File System Operations (rmrf, mv, cp) 19.08.2026 8.8
CVE-2026-71960 Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT 19.08.2026
CVE-2026-71961 Cudy WR3000 2.0 OS Command Injection via Mesh MQTT Command Handler 19.08.2026
CVE-2026-76203 CSS sanitizer bypass in Pentestify report themes allows forced outbound requests 19.08.2026
CVE-2026-18526 HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation 19.08.2026
CVE-2026-50149 Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled 19.08.2026 6.5
CVE-2026-54793 19.08.2026 4.6
CVE-2026-71176 20.08.2026 8.8
CVE-2019-25766 Renovate before 19.38.7 Credential Exposure via Go Modules 19.08.2026
CVE-2020-37267 Renovate 19.180.0 before 23.25.1 Token Leakage via Logs 19.08.2026
CVE-2024-58376 Renovate 37.158.0 before 37.199.0 Command Injection via helmv3 19.08.2026
CVE-2026-16019 SQL Injection in Faydam Innovation's FAYDAM Datalogger 19.08.2026 9.8
CVE-2026-43961 Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution 19.08.2026
CVE-2026-54794 19.08.2026 7.2
CVE-2026-70422 19.08.2026 8.1
CVE-2026-70423 19.08.2026 6.5
CVE-2026-70424 19.08.2026 6.5
CVE-2026-71694 19.08.2026
CVE-2026-75916 SiYuan XSS-to-RCE via unescaped block metadata in hint popup 19.08.2026
CVE-2026-75917 SiYuan before v3.7.4 XSS-to-RCE via pathName.ts 19.08.2026
CVE-2026-75918 phpMyFAQ before 4.1.7 Authentication Bypass via Tracking File 19.08.2026
CVE-2026-75919 phpMyFAQ before 4.1.7 Authentication Bypass via Setup API 19.08.2026
CVE-2026-75920 phpMyFAQ before 4.1.6 Information Disclosure via Backup ZIP 19.08.2026
CVE-2026-76205 phpMyFAQ before 4.1.7 SQL Injection via Glossary 19.08.2026
CVE-2026-76206 phpMyFAQ before 4.1.7 Information Disclosure via PDF Export 19.08.2026
CVE-2026-76207 phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie 19.08.2026
CVE-2026-76208 phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP 19.08.2026
CVE-2026-76209 phpMyFAQ before v4.1.6 Registration Bypass via API 19.08.2026
CVE-2026-76210 phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export 19.08.2026
CVE-2026-76211 phpMyFAQ before 4.1.7 Information Disclosure via Admin API 19.08.2026
CVE-2026-76212 phpMyFAQ before 4.1.7 LIKE Wildcard Injection via PostgreSQL 19.08.2026
CVE-2026-76213 phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle 19.08.2026
CVE-2026-76214 phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge 19.08.2026
CVE-2026-76215 phpMyFAQ before 4.1.7 Missing Authorization via child resources 19.08.2026
CVE-2026-76216 Vikunja through 2.4.0 Principal-Type Confusion via LinkSharing 19.08.2026
CVE-2026-76217 GitPython before 3.1.58 Arbitrary File Read via pathspec-from-file 19.08.2026
CVE-2026-76218 GitPython before 3.1.58 Remote Code Execution via Repo.init 20.08.2026
CVE-2026-76219 GitPython before 3.1.58 Arbitrary File Overwrite via read-tree 19.08.2026
CVE-2026-76220 GitPython before 3.1.58 Command Execution via split_single_char_options 20.08.2026
CVE-2026-76221 GitPython before 3.1.58 Config Injection via option-name 20.08.2026
CVE-2026-76222 GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name 19.08.2026
CVE-2026-76223 ArcadeDB before 26.8.1 Permission Bypass via DEFINE FUNCTION 19.08.2026
CVE-2026-76224 ArcadeDB before 26.8.1 Remote Code Execution via Groovy Fallback 19.08.2026
CVE-2026-76225 ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV 19.08.2026
CVE-2026-76226 Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance 19.08.2026
CVE-2026-76227 Renovate 42.68.1 before 42.96.3 Environment Variable Exposure 19.08.2026
CVE-2026-76228 Renovate before 42.68.5 Remote Code Execution via Gradle Wrapper 19.08.2026
CVE-2026-76229 Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomize 19.08.2026
CVE-2026-76230 Renovate 35.63.0 before 40.33.0 Command Injection via npm 19.08.2026
CVE-2026-76231 Renovate 32.135.0 before 40.33.0 Command Injection via hermit 19.08.2026
CVE-2026-76232 Renovate 31.51.0 before 40.33.0 Command Injection via helmv3 19.08.2026
CVE-2026-76233 Renovate 39.53.0 before 40.33.0 Command Injection via gleam manager 19.08.2026
CVE-2026-76234 libcrux before 0.0.6 Cryptographic Implementation Bug Fixes 19.08.2026
CVE-2026-76236 stigmem before 0.9.0a12 Cross-Tenant BOLA via Tombstones 19.08.2026
CVE-2026-76237 stigmem before 0.9.0a12 Cross-Tenant BOLA via quarantine 19.08.2026
CVE-2026-76238 stigmem before 0.9.0a12 Cross-Tenant BOLA via decay sweep 19.08.2026
CVE-2026-76239 Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address 19.08.2026
CVE-2026-76240 stigmem Postgres SQL Injection via Schema Identifier 19.08.2026
CVE-2026-76241 stigmem Plugin Signature Enforcement Bypass via Configuration 19.08.2026
CVE-2026-76242 stigmem Federation Peer Registration Authentication Bypass 19.08.2026
CVE-2026-76243 stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth 19.08.2026
CVE-2026-76244 stigmem-node Insecure Federation Transport Configuration 19.08.2026
CVE-2026-76245 stigmem Federation Peer Token Timestamp Validation Bypass 19.08.2026
CVE-2026-50719 19.08.2026
CVE-2026-50720 19.08.2026
CVE-2026-51366 19.08.2026
CVE-2026-51367 19.08.2026
CVE-2026-54795 20.08.2026 8.8
CVE-2026-56088 19.08.2026 7.1
CVE-2026-70421 20.08.2026 7.2
CVE-2026-74803 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 19.08.2026
CVE-2026-74804 Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 19.08.2026
CVE-2026-75114 Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 19.08.2026
CVE-2026-75148 cgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds Check 19.08.2026
CVE-2026-54796 20.08.2026 7.2
CVE-2026-65609 Out-of-bounds write in nnn 19.08.2026
CVE-2026-65610 Numeric Truncation Error in nnn 19.08.2026
CVE-2026-65611 Shell Command Injection in nnn 19.08.2026
CVE-2026-65612 Shell Command Injection in nnn 19.08.2026
CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 20.08.2026
CVE-2026-67363 Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 19.08.2026
CVE-2026-67364 Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 19.08.2026
CVE-2026-19489 19.08.2026
CVE-2026-32552 WordPress YITH WooCommerce Membership Premium plugin <= 2.33.0 - SQL Injection vulnerability 19.08.2026 8.5
CVE-2026-61986 WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability 19.08.2026 7.1
CVE-2026-66596 WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability 19.08.2026 7.1
CVE-2026-66613 WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability 19.08.2026 9.8
CVE-2026-66668 WordPress Community by PeepSo plugin <= 9.0.5.2 - SQL Injection vulnerability 19.08.2026 8.5
CVE-2026-73182 WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability 19.08.2026 7.1
CVE-2026-73183 WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73184 WordPress Global Gallery plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability 19.08.2026 7.1
CVE-2026-73185 WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73347 WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability 19.08.2026 9.8
CVE-2026-73354 WordPress SimplyRETS Real Estate IDX plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability 19.08.2026 7.1
CVE-2026-73363 WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access Control vulnerability 19.08.2026 6.5
CVE-2026-73364 WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability 19.08.2026 9.8
CVE-2026-73384 WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure vulnerability 19.08.2026 7.5
CVE-2026-73385 WordPress Outranking plugin Options plugin <= 1.1.3 - Broken Access Control vulnerability 19.08.2026 7.5
CVE-2026-73386 WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability 19.08.2026 7.5
CVE-2026-73387 WordPress Resido theme <= 1.5 - Local File Inclusion vulnerability 19.08.2026 8.1
CVE-2026-73388 WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73389 WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability 19.08.2026 9.8
CVE-2026-73390 WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability 19.08.2026 9.8
CVE-2026-73391 WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73394 WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability 19.08.2026 7.5
CVE-2026-76235 Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html 19.08.2026
CVE-2026-18371 HTML injection in M-Files Web 19.08.2026
CVE-2026-18372 CSS injection in M-Files Web 19.08.2026