| CVE-2026-18258 |
Authorization Bypass Through User-Controlled Key in eScriptorium |
06.08.2026 |
8.8 |
| CVE-2026-18275 |
Authorization Bypass Through User-Controlled Key in eScriptorium |
06.08.2026 |
6.5 |
| CVE-2026-18276 |
Missing Authorization in eScriptorium |
06.08.2026 |
4.3 |
| CVE-2026-18277 |
Missing Authorization in eScriptorium |
06.08.2026 |
7.1 |
| CVE-2026-18359 |
Server-Side Request Forgery (SSRF) in eScriptorium |
06.08.2026 |
8.5 |
| CVE-2026-18427 |
@fastify/static vulnerable to route guard bypass via non-canonical path segments |
06.08.2026 |
7.5 |
| CVE-2026-19046 |
NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversal |
06.08.2026 |
|
| CVE-2026-19047 |
NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection |
06.08.2026 |
|
| CVE-2026-3430 |
Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi |
06.08.2026 |
8.6 |
| CVE-2026-43622 |
llama.cpp b1886–b7445 Double Free via llama-android.cpp |
06.08.2026 |
|
| CVE-2026-53977 |
OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown |
06.08.2026 |
|
| CVE-2026-53985 |
Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO |
06.08.2026 |
|
| CVE-2026-5423 |
Subscription Authentication Bypass via Unverified connectionParams.jwt |
06.08.2026 |
|
| CVE-2026-66370 |
html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking |
06.08.2026 |
|
| CVE-2026-66829 |
html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection |
06.08.2026 |
|
| CVE-2026-66843 |
html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding |
06.08.2026 |
|
| CVE-2026-68747 |
CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input |
06.08.2026 |
|
| CVE-2026-68749 |
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service |
06.08.2026 |
|
| CVE-2026-68750 |
Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service |
06.08.2026 |
|
| CVE-2025-49506 |
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack |
06.08.2026 |
|
| CVE-2026-15246 |
RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass |
06.08.2026 |
4.3 |
| CVE-2026-19044 |
LeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injection |
06.08.2026 |
|
| CVE-2026-19045 |
NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.showSecretDialog command injection |
06.08.2026 |
|
| CVE-2026-25403 |
WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access Control vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-28005 |
WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-28082 |
WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-28111 |
WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability |
06.08.2026 |
8.8 |
| CVE-2026-28139 |
WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-28140 |
WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability |
06.08.2026 |
7.5 |
| CVE-2026-28141 |
WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-28143 |
WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-28146 |
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-28169 |
WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data Exposure vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-28172 |
WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-28177 |
WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-28178 |
WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-28179 |
WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
5.9 |
| CVE-2026-28180 |
WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-28183 |
WordPress PublishPress Capabilities plugin <= 2.45.0 - Privilege Escalation vulnerability |
06.08.2026 |
7.2 |
| CVE-2026-32327 |
Apache Portable Runtime Utility: apr-util XML stack recursion crash |
06.08.2026 |
|
| CVE-2026-32469 |
WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-32548 |
WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-34191 |
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle |
06.08.2026 |
|
| CVE-2026-34501 |
Apache Portable Runtime Utility: Heap buffer overflow in APR redis client |
06.08.2026 |
|
| CVE-2026-34502 |
Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client |
06.08.2026 |
|
| CVE-2026-53975 |
OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec |
06.08.2026 |
|
| CVE-2026-53976 |
OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter |
06.08.2026 |
|
| CVE-2026-54489 |
|
06.08.2026 |
9.1 |
| CVE-2026-61959 |
WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-61961 |
WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-61963 |
WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-61964 |
WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-61982 |
WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65502 |
WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-65504 |
WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vulnerability |
06.08.2026 |
7.5 |
| CVE-2026-65507 |
WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65508 |
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-65509 |
WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65513 |
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65515 |
WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65517 |
WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65520 |
WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-65523 |
WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0.1 - Insecure Direct Object References (IDOR) vulnerability |
06.08.2026 |
7.5 |
| CVE-2026-65541 |
WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability |
06.08.2026 |
7.3 |
| CVE-2026-65542 |
WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerability |
06.08.2026 |
8.8 |
| CVE-2026-65543 |
WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability |
06.08.2026 |
7.5 |
| CVE-2026-65544 |
WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65545 |
WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65546 |
WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-65547 |
WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability |
06.08.2026 |
8.5 |
| CVE-2026-65548 |
WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability |
06.08.2026 |
9.9 |
| CVE-2026-65549 |
WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerability |
06.08.2026 |
7.2 |
| CVE-2026-65552 |
WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65553 |
WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability |
06.08.2026 |
10 |
| CVE-2026-65554 |
WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65556 |
WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65559 |
WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability |
06.08.2026 |
7.2 |
| CVE-2026-65560 |
WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65565 |
WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-65569 |
WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability |
06.08.2026 |
8.5 |
| CVE-2026-65570 |
WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerability |
06.08.2026 |
8.1 |
| CVE-2026-65571 |
WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65572 |
WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65573 |
WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65574 |
WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65575 |
WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65576 |
WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65577 |
WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65578 |
WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65579 |
WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65581 |
WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-66425 |
WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-66439 |
WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66440 |
WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66447 |
WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-66451 |
WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-66452 |
WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Broken Access Control vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-66457 |
WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66470 |
WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66662 |
WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-66663 |
WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66664 |
WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66665 |
WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability |
06.08.2026 |
10 |
| CVE-2026-66678 |
WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken Access Control vulnerability |
06.08.2026 |
4.3 |
| CVE-2026-66681 |
WordPress theme My Login plugin <= 7.1.14 - Cross Site Request Forgery (CSRF) vulnerability |
06.08.2026 |
4.3 |
| CVE-2026-66683 |
WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposure vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-66684 |
WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-66685 |
WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-66686 |
WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-66688 |
WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-66690 |
WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66692 |
WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability |
06.08.2026 |
4.3 |
| CVE-2026-66694 |
WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66695 |
WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-66696 |
WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability |
06.08.2026 |
4.3 |
| CVE-2026-66699 |
WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-66701 |
WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability |
06.08.2026 |
5.3 |
| CVE-2026-66702 |
WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66703 |
WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
6.5 |
| CVE-2026-66705 |
WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66706 |
WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
5.9 |
| CVE-2026-66707 |
WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66708 |
WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability |
06.08.2026 |
8.2 |
| CVE-2026-66709 |
WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability |
06.08.2026 |
9.1 |
| CVE-2026-66710 |
WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability |
06.08.2026 |
8.1 |
| CVE-2026-66711 |
WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Site Scripting (XSS) vulnerability |
06.08.2026 |
7.1 |
| CVE-2026-66712 |
WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability |
06.08.2026 |
7.5 |
| CVE-2026-67261 |
|
06.08.2026 |
9.8 |
| CVE-2026-70637 |
LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c |
06.08.2026 |
|
| CVE-2026-70646 |
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler |
06.08.2026 |
7.5 |
| CVE-2026-12605 |
|
06.08.2026 |
9.6 |
| CVE-2026-16315 |
Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard |
06.08.2026 |
|
| CVE-2026-16316 |
Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard |
06.08.2026 |
|
| CVE-2026-16731 |
Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout |
06.08.2026 |
|
| CVE-2026-18501 |
UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution |
06.08.2026 |
6.4 |
| CVE-2026-19040 |
MissionSquad mcp-api dcrClients.ts server-side request forgery |
06.08.2026 |
|
| CVE-2026-19041 |
MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection |
06.08.2026 |
|
| CVE-2026-5134 |
SQLi in Loca Software's CMS |
06.08.2026 |
9.8 |
| CVE-2026-64993 |
|
06.08.2026 |
6.8 |
| CVE-2026-15599 |
Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner |
06.08.2026 |
3.3 |
| CVE-2026-19037 |
WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow |
06.08.2026 |
|
| CVE-2026-19038 |
MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversal |
06.08.2026 |
|
| CVE-2026-19039 |
Kino-Kafkaesque ssh-mcp-server SSH index.ts ssh_exec command injection |
06.08.2026 |
|
| CVE-2026-65551 |
WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability |
06.08.2026 |
7.5 |
| CVE-2026-66732 |
Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager |
06.08.2026 |
|
| CVE-2026-66733 |
Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache |
06.08.2026 |
|
| CVE-2026-0673 |
Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection |
06.08.2026 |
5.3 |
| CVE-2026-19036 |
Shibby Tomato wanoptions sub_40F88C os command injection |
06.08.2026 |
|
| CVE-2026-70556 |
Hubzilla 11.2.1 CSRF via OAuth2 /authorize Endpoint App Registration |
06.08.2026 |
|
| CVE-2025-15028 |
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting |
06.08.2026 |
7.2 |
| CVE-2025-9266 |
Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation |
06.08.2026 |
4.3 |
| CVE-2026-11983 |
Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax |
06.08.2026 |
5.3 |
| CVE-2026-19035 |
Shibby Tomato qoslimit new_qoslimit_start os command injection |
06.08.2026 |
|
| CVE-2026-57818 |
Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider |
06.08.2026 |
|
| CVE-2026-5158 |
PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block |
06.08.2026 |
6.4 |
| CVE-2026-5391 |
LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
06.08.2026 |
6.4 |
| CVE-2026-61466 |
Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation |
06.08.2026 |
|
| CVE-2026-63687 |
Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters |
06.08.2026 |
|
| CVE-2026-65583 |
Apache CXF: Self-issued ID token claims validation skipped |
06.08.2026 |
|
| CVE-2026-68079 |
Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay |
06.08.2026 |
|
| CVE-2026-68481 |
Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider |
06.08.2026 |
|
| CVE-2026-8166 |
Stored XSS in Logo Software's e-Logo Purchasing Portal |
06.08.2026 |
5.4 |
| CVE-2026-19034 |
Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection |
06.08.2026 |
|
| CVE-2026-54225 |
Apache CXF: Denial of Service attack via large attachments |
06.08.2026 |
|
| CVE-2026-57817 |
Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow |
06.08.2026 |
|
| CVE-2026-57819 |
Apache CXF: No default restriction on the amount of form parameters per message |
06.08.2026 |
|
| CVE-2026-64958 |
Apache CXF: Denial of service via message header attachments |
06.08.2026 |
|
| CVE-2026-65432 |
Apache CXF: XXE via WSDL/XSD import parsing |
06.08.2026 |
|
| CVE-2026-66909 |
Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage |
06.08.2026 |
|
| CVE-2026-55978 |
Improper access control vulnerability in CatchPulse |
06.08.2026 |
8.4 |
| CVE-2026-55979 |
Improper access control check in CatchPulse's named pipe communication interface |
06.08.2026 |
5.2 |
| CVE-2026-55980 |
Denial-of-service vulnerability in CatchPulse |
06.08.2026 |
5.5 |
| CVE-2026-19022 |
OpenHands send_pull_request.py initialize_repo command injection |
06.08.2026 |
|
| CVE-2026-64640 |
Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation |
06.08.2026 |
|
| CVE-2024-10302 |
Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure |
06.08.2026 |
4 |
| CVE-2024-6832 |
Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks |
06.08.2026 |
5.9 |
| CVE-2024-8995 |
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access |
06.08.2026 |
4.9 |
| CVE-2025-11850 |
Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use] |
06.08.2026 |
4.3 |
| CVE-2025-12627 |
Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions |
06.08.2026 |
2.4 |
| CVE-2025-13394 |
Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions |
06.08.2026 |
5.4 |
| CVE-2025-13736 |
Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery |
06.08.2026 |
3.7 |
| CVE-2025-13909 |
Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure |
06.08.2026 |
4.3 |
| CVE-2025-14779 |
Improper Access Control via Secret Type Management API in WSO2 Identity Server |
06.08.2026 |
3.8 |
| CVE-2025-15039 |
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products |
06.08.2026 |
9.4 |
| CVE-2026-0637 |
Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products |
06.08.2026 |
4.4 |
| CVE-2026-18597 |
Blind SSRF on Foxit PDF Services API |
06.08.2026 |
8.5 |
| CVE-2026-18915 |
Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock |
06.08.2026 |
5 |
| CVE-2026-19019 |
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup |
06.08.2026 |
|
| CVE-2026-19020 |
itsourcecode Hospital Management System servicetype.php sql injection |
06.08.2026 |
|
| CVE-2026-19021 |
SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection |
06.08.2026 |
|
| CVE-2026-1728 |
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover |
06.08.2026 |
9.8 |
| CVE-2026-5430 |
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover |
06.08.2026 |
10 |
| CVE-2023-7353 |
|
06.08.2026 |
|
| CVE-2023-7354 |
|
06.08.2026 |
|
| CVE-2023-7355 |
|
06.08.2026 |
|
| CVE-2026-18649 |
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders |
06.08.2026 |
|
| CVE-2026-19008 |
mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following |
06.08.2026 |
|
| CVE-2026-19009 |
TinyAGI Message API Endpoint response.ts collectFiles file inclusion |
06.08.2026 |
|
| CVE-2026-19010 |
TinyAGI Message API Endpoint index.ts processMessage authorization |
06.08.2026 |
|
| CVE-2026-19011 |
TinyAGI agents.ts buildSystemPrompt file inclusion |
06.08.2026 |
|
| CVE-2026-64583 |
usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown |
06.08.2026 |
|
| CVE-2026-64584 |
usb: gadget: f_midi: cancel pending IN work before freeing the midi object |
06.08.2026 |
|
| CVE-2026-64585 |
can: esd_usb: kill anchored URBs before freeing netdevs |
06.08.2026 |
|
| CVE-2026-64586 |
wifi: brcmfmac: drain bus_reset work on device removal |
06.08.2026 |
|
| CVE-2026-64587 |
net: ethernet: arc: emac: quiesce interrupts before requesting IRQ |
06.08.2026 |
|
| CVE-2026-64588 |
fuse-uring: fix data races on ring->ready |
06.08.2026 |
|
| CVE-2026-64589 |
i2c: core: fix NULL-deref on adapter registration failure |
06.08.2026 |
|
| CVE-2026-64590 |
dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning |
06.08.2026 |
|
| CVE-2026-64591 |
iommu/vt-d: Avoid WARNING in sva unbind path |
06.08.2026 |
|
| CVE-2026-64592 |
riscv: mm: Unconditionally sfence.vma for spurious fault |
06.08.2026 |
|
| CVE-2026-64593 |
btrfs: do not trim a device which is not writeable |
06.08.2026 |
|
| CVE-2026-64594 |
usb: gadget: f_fs: initialize reset_work at allocation time |
06.08.2026 |
|
| CVE-2026-64595 |
HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove() |
06.08.2026 |
|
| CVE-2026-64596 |
libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo() |
06.08.2026 |
|
| CVE-2026-64597 |
smb: client: fix double-free in SMB2_close() replay |
06.08.2026 |
|
| CVE-2026-64598 |
smb/client: Fix error code in smb2_aead_req_alloc() |
06.08.2026 |
|
| CVE-2026-64599 |
crypto: amlogic - avoid double cleanup in meson_crypto_probe() |
06.08.2026 |
|
| CVE-2026-64601 |
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission |
06.08.2026 |
|
| CVE-2026-64602 |
iio: adc: spear: Initialize completion before requesting IRQ |
06.08.2026 |
|
| CVE-2026-64603 |
platform/x86: intel-hid: Protect ACPI notify handler against recursion |
06.08.2026 |
|
| CVE-2026-64604 |
KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode |
06.08.2026 |
|
| CVE-2025-15678 |
Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload |
06.08.2026 |
|
| CVE-2026-11588 |
EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation |
06.08.2026 |
|
| CVE-2026-12713 |
WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number |
06.08.2026 |
|
| CVE-2026-13153 |
Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint |
06.08.2026 |
|
| CVE-2026-13154 |
Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint |
06.08.2026 |
|
| CVE-2026-13703 |
SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure |
06.08.2026 |
|
| CVE-2026-14204 |
Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF |
06.08.2026 |
|
| CVE-2026-14240 |
Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export |
06.08.2026 |
|
| CVE-2026-14313 |
PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering via IDOR |
06.08.2026 |
|
| CVE-2026-14314 |
PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR |
06.08.2026 |
|
| CVE-2026-14547 |
Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form |
06.08.2026 |
|
| CVE-2026-14829 |
Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret |
06.08.2026 |
|
| CVE-2026-16054 |
Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle |
06.08.2026 |
|
| CVE-2026-16065 |
Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import |
06.08.2026 |
|
| CVE-2026-16268 |
Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler |
06.08.2026 |
|
| CVE-2026-16290 |
ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group |
06.08.2026 |
|
| CVE-2026-16537 |
Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode |
06.08.2026 |
|
| CVE-2026-16734 |
Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation |
06.08.2026 |
|
| CVE-2026-16954 |
AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens |
06.08.2026 |
|
| CVE-2026-18050 |
Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads |
06.08.2026 |
|
| CVE-2026-18395 |
Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes |
06.08.2026 |
|
| CVE-2026-18400 |
Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting |
06.08.2026 |
6.4 |
| CVE-2026-18510 |
TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
06.08.2026 |
7.2 |
| CVE-2026-18967 |
Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow |
06.08.2026 |
|
| CVE-2026-19005 |
nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges management |
06.08.2026 |
|
| CVE-2026-19006 |
mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization |
06.08.2026 |
|
| CVE-2026-19007 |
mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management |
06.08.2026 |
|
| CVE-2026-15459 |
WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint |
06.08.2026 |
8.1 |
| CVE-2026-18997 |
cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization |
06.08.2026 |
|
| CVE-2026-18998 |
cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization |
06.08.2026 |
|
| CVE-2026-19000 |
JeecgBoot Anonymous Chat Attachment send server-side request forgery |
06.08.2026 |
|
| CVE-2026-15991 |
File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter |
06.08.2026 |
8.8 |
| CVE-2026-16636 |
FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs |
06.08.2026 |
7.2 |
| CVE-2026-18325 |
Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field |
06.08.2026 |
7.2 |
| CVE-2026-18909 |
|
06.08.2026 |
|
| CVE-2026-18992 |
zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization |
06.08.2026 |
|
| CVE-2026-18993 |
NousResearch hermes-agent Memory Toolset model_tools.py access control |
06.08.2026 |
|
| CVE-2026-18995 |
netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure |
06.08.2026 |
|
| CVE-2026-18996 |
cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment |
06.08.2026 |
|
| CVE-2026-18990 |
letta-ai LettaBot API Status Route server.ts missing authentication |
06.08.2026 |
|
| CVE-2026-18991 |
nanocoai NanoClaw send_file core.ts path traversal |
06.08.2026 |
|
| CVE-2026-18976 |
NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment |
06.08.2026 |
|
| CVE-2026-18980 |
nearai ironclaw shell.rs classify_command_risk command injection |
06.08.2026 |
|
| CVE-2026-18973 |
heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery |
06.08.2026 |
|
| CVE-2026-18974 |
heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure |
06.08.2026 |
|
| CVE-2023-54375 |
|
05.08.2026 |
|
| CVE-2023-54376 |
|
05.08.2026 |
|
| CVE-2023-54377 |
|
05.08.2026 |
|
| CVE-2023-54378 |
|
05.08.2026 |
|
| CVE-2023-54379 |
|
05.08.2026 |
|
| CVE-2023-54380 |
|
05.08.2026 |
|
| CVE-2023-54381 |
|
05.08.2026 |
|
| CVE-2023-54382 |
|
05.08.2026 |
|
| CVE-2023-54383 |
|
05.08.2026 |
|
| CVE-2023-54384 |
|
05.08.2026 |
|
| CVE-2023-54385 |
|
05.08.2026 |
|
| CVE-2023-54386 |
|
05.08.2026 |
|
| CVE-2023-54387 |
|
05.08.2026 |
|
| CVE-2023-54388 |
|
05.08.2026 |
|
| CVE-2023-54389 |
|
06.08.2026 |
|
| CVE-2026-18970 |
Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection |
06.08.2026 |
|
| CVE-2026-18969 |
Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload |
06.08.2026 |
|
| CVE-2026-52466 |
|
06.08.2026 |
|
| CVE-2026-18968 |
ttttonyhe OBlog tags.php cross site scripting |
06.08.2026 |
|
| CVE-2026-19027 |
HDF5 out-of-bounds heap read in N-Bit filter decompression |
06.08.2026 |
|
| CVE-2026-19028 |
HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read |
06.08.2026 |
|
| CVE-2026-67531 |
FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool |
05.08.2026 |
|
| CVE-2026-67869 |
|
06.08.2026 |
7.5 |
| CVE-2026-67870 |
|
05.08.2026 |
|
| CVE-2026-67871 |
|
06.08.2026 |
|
| CVE-2026-67872 |
|
06.08.2026 |
|
| CVE-2026-67873 |
|
06.08.2026 |
|
| CVE-2026-19025 |
HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open |
06.08.2026 |
|
| CVE-2026-19026 |
Nbit filter NULL/short parameter-array dereference |
06.08.2026 |
|
| CVE-2026-19023 |
HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets |
06.08.2026 |
|
| CVE-2026-19024 |
HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message |
06.08.2026 |
|
| CVE-2026-67863 |
|
06.08.2026 |
7.5 |
| CVE-2026-67866 |
|
06.08.2026 |
|
| CVE-2026-67867 |
|
06.08.2026 |
|
| CVE-2025-63822 |
|
06.08.2026 |
|
| CVE-2025-63823 |
|
06.08.2026 |
|
| CVE-2026-67864 |
|
06.08.2026 |
|
| CVE-2026-67865 |
|
06.08.2026 |
|
| CVE-2026-71321 |
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation |
06.08.2026 |
7.5 |
| CVE-2026-71316 |
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients |
05.08.2026 |
7.5 |
| CVE-2026-71318 |
Nuxt: Unauthorized Component Instantiation via Server Island Props |
06.08.2026 |
4.8 |
| CVE-2026-71319 |
Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution |
06.08.2026 |
9.6 |
| CVE-2026-71320 |
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props |
06.08.2026 |
8.1 |
| CVE-2026-18839 |
Popt-devel: popt-static: size_t underflow in singleoptionhelp |
06.08.2026 |
|
| CVE-2026-71313 |
rclone: Local Encoding Path Traversal |
06.08.2026 |
6.9 |
| CVE-2026-71314 |
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering |
06.08.2026 |
7.5 |
| CVE-2026-71315 |
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) |
06.08.2026 |
8.2 |
| CVE-2026-15996 |
Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters |
06.08.2026 |
|
| CVE-2026-17583 |
Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check |
06.08.2026 |
8.4 |
| CVE-2026-18411 |
Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100 |
06.08.2026 |
|
| CVE-2026-18959 |
yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal |
05.08.2026 |
|
| CVE-2026-34966 |
Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass |
06.08.2026 |
|
| CVE-2026-71309 |
rclone: Incomplete path validation allows backend root escape in serve restic |
06.08.2026 |
|
| CVE-2026-71310 |
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory |
06.08.2026 |
5.9 |
| CVE-2026-71311 |
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines |
05.08.2026 |
6.4 |
| CVE-2026-71312 |
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution |
06.08.2026 |
8 |
| CVE-2026-21766 |
HCL Digital Experience and Digital Experience Compose insufficiently protects credentials |
06.08.2026 |
5.4 |