CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-73819 Ebyte NA111-M Weak Authentication 31.08.2026 9.3
CVE-2026-76133 Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm 31.08.2026 9.3
CVE-2026-66047 ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE 31.08.2026 9.2
CVE-2026-82970 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability 31.08.2026 10
CVE-2026-59111 Command Injection vulnerability in eObčanka-Identifikace 31.08.2026 9.3
CVE-2026-82694 Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication 31.08.2026 10
CVE-2026-82695 Tenda AC18 Telnet telnet missing authentication 31.08.2026 10
CVE-2026-82692 D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82693 Tenda AC1206 Web UI telnet TendaTelnet missing authentication 31.08.2026 10
CVE-2026-82691 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection 31.08.2026 9.4
CVE-2026-82690 D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82689 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82688 D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection 31.08.2026 9.4
CVE-2026-82876 Phison PS3111-S11 Controller Firmware Signature Verification Bypass 31.08.2026 9.3
CVE-2026-49003 Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product 31.08.2026 9.6
CVE-2026-82854 Nodemailer before 8.0.3 SMTP Command Injection via envelope.size 31.08.2026 9.3
CVE-2026-82855 @hulumi/policies before 1.3.2 Evidence Validation Bypass 31.08.2026 9.3
CVE-2026-82856 @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass 31.08.2026 9.3
CVE-2026-82857 hulumi before v1.3.2 Privilege Escalation via IAM Policy 31.08.2026 9.3
CVE-2026-82858 @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance 31.08.2026 9.3
CVE-2026-82859 hulumi before v1.3.2 SCP Template Tag-on-Create Bypass 31.08.2026 9.3
CVE-2026-82860 @hulumi/policies before 1.3.2 Admin Policy Bypass 31.08.2026 9.3
CVE-2026-19410 Google Cloud Build Comment Control Bypass via Webhook Suppression 31.08.2026 9.4
CVE-2026-82628 Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management 31.08.2026 9.3
CVE-2026-58574 31.08.2026 9.8
CVE-2026-82616 TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow 31.08.2026 9.4
CVE-2026-82593 D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow 30.08.2026 9.4
CVE-2026-82592 D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow 30.08.2026 9.4
CVE-2026-82645 AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token 30.08.2026 9.2
CVE-2026-82653 SiYuan before v3.8.1 Stored XSS via confirmDialog 30.08.2026 9.3
CVE-2026-82654 SiYuan before v3.8.1 Stored XSS via block name 30.08.2026 9.3
CVE-2026-82542 Tenda HG10 Boa Web Server formIPv6Routing buffer overflow 30.08.2026 10
CVE-2026-82539 TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption 30.08.2026 9.4
CVE-2026-15980 MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token 30.08.2026 9.8
CVE-2026-15369 Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout 29.08.2026 9.8
CVE-2026-82460 Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown 29.08.2026 9.3
CVE-2026-82466 Rodauth before 2.46.0 Authentication Bypass via webauthn_login 29.08.2026 9.4
CVE-2026-82452 rust-iot-platform Authentication Bypass via Missing Request Guards 29.08.2026 9.3
CVE-2026-82454 Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in 29.08.2026 9.3
CVE-2026-82456 argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP 29.08.2026 10
CVE-2026-82448 Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key 29.08.2026 9.3
CVE-2026-14494 Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field 29.08.2026 9.8
CVE-2026-18527 IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ]. 28.08.2026 9.9
CVE-2026-19286 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement 28.08.2026 9.8
CVE-2026-19295 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement 31.08.2026 9.9
CVE-2026-3627 Multiple Vulnerabilities in IBM Concert Software 28.08.2026 9.1
CVE-2026-54745 Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true 28.08.2026 10
CVE-2026-54754 Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) 28.08.2026 9.6
CVE-2026-54755 Klever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) 28.08.2026 9.6
CVE-2026-55068 free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints 28.08.2026 9.3
CVE-2026-55220 Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column 28.08.2026 9.3
CVE-2026-55247 plone.app.event: Denial of service via iCalendar import 28.08.2026 9.1
CVE-2026-55248 plone.app.portlets: Denial of service via RSS feed portlet 28.08.2026 9.1
CVE-2026-55378 JS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context values 28.08.2026 9.3
CVE-2026-55511 Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` 28.08.2026 9.1
CVE-2026-55559 Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) 28.08.2026 9.8
CVE-2026-55565 Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) 28.08.2026 9.9
CVE-2026-55634 Pimcore: Remote Code Execution via DataObject Class-Definition Field Name 28.08.2026 9.9
CVE-2026-82021 Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference 29.08.2026 9
CVE-2026-82266 Redpanda Admin API Unauthenticated Superuser Access via Default Configuration 28.08.2026 9.3
CVE-2026-82277 Argo Rollouts Dashboard Unauthenticated Mutating Operations 28.08.2026 9.3
CVE-2026-82281 Kotaemon Missing Ownership Check in Conversation Functions 28.08.2026 9.1
CVE-2026-82329 Potential authentication bypass leading to administrative access in Artifactory 28.08.2026 9.8
CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector 31.08.2026 9.4
CVE-2026-18918 OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default 31.08.2026 9.1
CVE-2026-42007 28.08.2026 9.1
CVE-2026-82222 WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability 28.08.2026 10
CVE-2026-82244 Budibase before 3.41.3 Remote Code Execution via Plugin eval() 28.08.2026 9.4
CVE-2026-40541 28.08.2026 9
CVE-2026-76581 WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion 28.08.2026 9.8
CVE-2026-78032 28.08.2026 9.3
CVE-2026-80600 batman-adv: dat: acquire ARP hw source only after skb realloc 29.08.2026 9.8
CVE-2026-80603 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read 29.08.2026 9.1
CVE-2026-80609 qede: fix out-of-bounds check for cqe->len_list[] 29.08.2026 9.8
CVE-2026-80612 net: lwtunnel: Drop skb metadata before LWT encapsulation 29.08.2026 9.8
CVE-2026-80617 net: airoha: fix foe_check_time allocation size 29.08.2026 9.8
CVE-2026-80630 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 29.08.2026 9.8
CVE-2026-80634 netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag 29.08.2026 9.8
CVE-2026-80668 netfilter: nf_conntrack_expect: use conntrack GC to reap expectations 29.08.2026 9.8
CVE-2026-80670 perf tools: Use perf_env__get_cpu_topology() in machine__resolve() 29.08.2026 9.1
CVE-2026-80671 perf sched: Fix register_pid() overflow, strcpy, and BUG_ON 29.08.2026 9.3
CVE-2026-80673 ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() 29.08.2026 9.8
CVE-2026-80674 ntfs: validate resident attribute lists and harden the validator 29.08.2026 9.8
CVE-2026-80681 vxlan: re-fetch eth header after route_shortcircuit() 29.08.2026 9.8
CVE-2026-80684 KVM: s390: pci: Fix NULL dereference on AIBV allocation failure 29.08.2026 9.3
CVE-2026-80693 idpf: bound interrupt-vector register fill to the allocated array 29.08.2026 9.3
CVE-2026-80694 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller 29.08.2026 9.8
CVE-2026-80714 ipvs: do not propagate one-packet flag to synced conns 29.08.2026 9.8
CVE-2026-82082 Green-Computing|NUMail - OS Command Injection 31.08.2026 9.3
CVE-2026-82090 28.08.2026 9.2
CVE-2026-13086 Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint 29.08.2026 9.3
CVE-2026-19313 Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution 29.08.2026 9.3
CVE-2026-19315 Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution 29.08.2026 9.3
CVE-2026-19318 Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution 29.08.2026 9.3
CVE-2026-61800 Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893) 28.08.2026 9.1
CVE-2026-78174 WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs 28.08.2026 9.3
CVE-2026-18717 Improper Certificate Validation in ASE 2000 28.08.2026 9.1
CVE-2026-50152 Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users 28.08.2026 9.1
CVE-2026-68929 FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization 28.08.2026 9.3
CVE-2026-69658 Ebyte NA111-M Cleartext Transmission of Sensitive Information 31.08.2026 9.3
CVE-2026-71187 Ebyte NA111-M Use of Client-Side Authentication 31.08.2026 9.3
CVE-2026-73125 Ebyte NA111-M Missing Authentication for Critical Function 31.08.2026 9.3
CVE-2026-76179 Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings 31.08.2026 9.3
CVE-2026-76943 Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel 28.08.2026 9.3
CVE-2026-78239 Xiiaozet LK100W Missing Authentication for Critical Function 28.08.2026 9.3
CVE-2026-18885 Unauthenticated Remote Code Execution in GraphQL Composite Data API 29.08.2026 10
CVE-2026-18886 Unauthenticated Privilege Escalation via System Configuration Image Upload Processor 29.08.2026 10
CVE-2026-19092 Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing 28.08.2026 9.8
CVE-2026-48996 Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client 29.08.2026 9.3
CVE-2026-53578 Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml 27.08.2026 9.3
CVE-2026-53579 Trilium: Note Import to RCE via Book Note 28.08.2026 9.3
CVE-2026-74820 Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause 29.08.2026 10
CVE-2026-81934 Redis TLS pending-data list use-after-free 28.08.2026 9.2
CVE-2026-16279 Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x 27.08.2026 9.3
CVE-2026-57499 Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) 27.08.2026 9.1
CVE-2026-81094 mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring Authentication 29.08.2026 9.3
CVE-2026-81096 ToolUniverse through 1.2.6 Unauthenticated Remote Code Execution via python_code_executor Sandbox Escape 29.08.2026 9.3
CVE-2026-81098 Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport 29.08.2026 9.3
CVE-2026-81680 openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal 27.08.2026 9.3
CVE-2026-81681 openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage 27.08.2026 9.3
CVE-2026-81685 openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata 27.08.2026 9.3
CVE-2026-81694 verify-usb before 1.4.9 Output Injection via Unsanitized Filenames 28.08.2026 9.3
CVE-2026-81695 openssl_encrypt before 1.4.9 Terminal Injection via key_id 27.08.2026 9.3
CVE-2026-81696 openssl_encrypt before 1.4.9 Terminal Injection via info Command 27.08.2026 9.3
CVE-2026-81698 openssl_encrypt before 1.4.9 Shell Injection via info command 27.08.2026 9.3
CVE-2026-81700 openssl_encrypt before 1.4.9 GPG Signature Verification Bypass 27.08.2026 9.3
CVE-2026-81701 openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin 27.08.2026 9.3
CVE-2026-81702 openssl_encrypt before 1.4.9 Key Substitution via Identity Load 27.08.2026 9.3
CVE-2026-81706 openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing 27.08.2026 9.3
CVE-2026-81707 openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email 27.08.2026 9.3
CVE-2026-81714 openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass 27.08.2026 9.3
CVE-2026-81717 openssl_encrypt before 1.4.9 Integrity Bypass via Added Files 27.08.2026 9.3
CVE-2026-81719 openssl_encrypt before 1.4.9 Remote Code Execution via Plugin 27.08.2026 9.3
CVE-2026-81735 UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution 29.08.2026 10
CVE-2026-81826 Flowintel Fails to Invalidate Active Sessions After Password Change 27.08.2026 9.1
CVE-2026-74232 Zbtlink MQWrt yunmgrd Cloud C2 Implant 27.08.2026 9.3
CVE-2026-74233 Zbtlink MQWrt infosrvd Command Injection 27.08.2026 9.3
CVE-2026-81672 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81673 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81674 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81675 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-32479 WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulnerability 28.08.2026 9.3
CVE-2026-32566 WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability 27.08.2026 9.8
CVE-2026-59354 Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata 28.08.2026 9.6
CVE-2026-78260 WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability 28.08.2026 9.3
CVE-2026-78274 WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability 27.08.2026 9.1
CVE-2026-78286 WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability 28.08.2026 9.8
CVE-2026-78288 WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability 27.08.2026 9.3
CVE-2026-78292 WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability 27.08.2026 9.8
CVE-2026-59270 Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces 28.08.2026 9.4
CVE-2026-77991 Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 28.08.2026 9.4
CVE-2026-65956 KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF 29.08.2026 10
CVE-2026-65641 27.08.2026 9.3
CVE-2026-60004 26.08.2026 9.8
CVE-2026-19485 Bucket Squatting in Vertex AI Search for Commerce 26.08.2026 9.3
CVE-2026-70419 26.08.2026 9.1
CVE-2026-54569 SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core 26.08.2026 9.8
CVE-2026-80428 ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint 29.08.2026 9.3
CVE-2026-81032 NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration 26.08.2026 9.3
CVE-2026-75062 Eval Injection in google/langfun via default lf.query protocol 27.08.2026 9.2
CVE-2026-74737 net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG 27.08.2026 9.8
CVE-2026-74743 macvlan: inherit needed_headroom and needed_tailroom from lowerdev 27.08.2026 9.8
CVE-2026-74744 ipvlan: inherit needed_headroom and needed_tailroom from phy_dev 27.08.2026 9.8
CVE-2026-74746 netfilter: flowtable: publish GC-visible tuple last 27.08.2026 9.8
CVE-2026-74751 riscv: lib: Fix ZBB strnlen reading past count boundary 27.08.2026 9.4
CVE-2026-74752 sctp: validate cookie AUTH state before use 27.08.2026 9.8
CVE-2026-80519 ovpn: finish crypto callback cleanup before peer release 27.08.2026 9.8
CVE-2026-80528 ceph: avoid fs reclaim while using current->journal_info 27.08.2026 9.8
CVE-2026-80551 s390/vfio_ccw: Ensure first IDAW remains constant 27.08.2026 9.3
CVE-2026-80554 s390/vfio_ccw: Limit the number of channel program segments 27.08.2026 9.3
CVE-2026-80557 libceph: fix OOB read in decode_watchers() via missing bounds check 27.08.2026 9.8
CVE-2026-80558 libceph: Avoid using invalid osd indices from primary_temp 27.08.2026 9.8
CVE-2026-80561 libceph: fix multiple unsafe decodes in decode_locker() 27.08.2026 9.8
CVE-2026-80585 mptcp: fastopen: only mark MPTFO subflows with SYN data 27.08.2026 9.4
CVE-2026-80586 mptcp: options: reset DSS fields in case of unexpected size 27.08.2026 9.8
CVE-2026-80587 mptcp: avoid combining some incoming suboptions 27.08.2026 9.8
CVE-2026-80589 block: stop the timeout timer when releasing a never added disk 27.08.2026 9.8
CVE-2026-54523 Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system 26.08.2026 9.6
CVE-2026-75896 Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk 26.08.2026 9.1
CVE-2026-12717 Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection 26.08.2026 9.4
CVE-2026-18080 ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment 26.08.2026 9.8
CVE-2026-77532 26.08.2026 9.6
CVE-2026-77554 26.08.2026 10
CVE-2026-77557 26.08.2026 9.8
CVE-2026-77549 27.08.2026 9
CVE-2026-77550 27.08.2026 10
CVE-2026-77551 26.08.2026 9
CVE-2026-77552 26.08.2026 9.8
CVE-2026-77553 26.08.2026 9.9
CVE-2026-77546 26.08.2026 9.9
CVE-2026-77547 26.08.2026 9.9
CVE-2026-77548 26.08.2026 9.9
CVE-2026-80203 Grav before 1.0.18 Authentication Bypass via Scoped API Key 28.08.2026 9.3
CVE-2026-80204 Grav before 1.0.18 Authentication Bypass via Scoped API Key 26.08.2026 9.3
CVE-2026-77542 26.08.2026 9.1
CVE-2026-77543 26.08.2026 9.9
CVE-2026-77545 27.08.2026 9
CVE-2026-80349 TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter 26.08.2026 9.3
CVE-2026-77539 27.08.2026 9.1
CVE-2026-77540 27.08.2026 9.1
CVE-2026-77541 26.08.2026 9.1
CVE-2026-59683 OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings 26.08.2026 9.3
CVE-2026-77535 26.08.2026 9.1
CVE-2026-77536 27.08.2026 9.9
CVE-2026-77537 26.08.2026 10
CVE-2026-77534 27.08.2026 9.9
CVE-2026-77533 26.08.2026 9.9
CVE-2026-80235 Thinking Software Technology|EFence - Arbitrary File Upload 26.08.2026 9.3
CVE-2026-18431 Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write 27.08.2026 9.8
CVE-2026-15203 Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software 26.08.2026 9.3
CVE-2026-19632 TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure 26.08.2026 9.8
CVE-2026-80202 Kimai before 2.56.0 Authorization Bypass via TimesheetVoter 26.08.2026 9.3
CVE-2026-79911 TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow 27.08.2026 10
CVE-2026-80138 ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter 26.08.2026 9.2
CVE-2026-62862 TypeBot: Account takeover via brute-forceable 6-digit magic-link code 26.08.2026 9.1
CVE-2026-65083 26.08.2026 9.9
CVE-2026-65093 26.08.2026 9.9
CVE-2026-80104 DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename 29.08.2026 9.3
CVE-2026-45018 Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution 25.08.2026 9.8
CVE-2026-78379 Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools 25.08.2026 9.2
CVE-2026-79787 Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature 25.08.2026 9.3
CVE-2026-76193 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 29.08.2026 10
CVE-2026-76195 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 29.08.2026 10
CVE-2026-76197 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 29.08.2026 10
CVE-2026-55640 Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) 25.08.2026 9.1
CVE-2022-51000 Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxslt 28.08.2026 9.3
CVE-2024-58378 Nokogiri before 1.16.2 Use-After-Free via xmlTextReader 28.08.2026 9.3
CVE-2025-71407 Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free 25.08.2026 9.3
CVE-2026-55536 Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) 28.08.2026 9.1
CVE-2026-55546 QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input 25.08.2026 9.8
CVE-2026-79675 NLTK before 3.10.3 JVM Argument Injection via Per-Call Options 27.08.2026 9.3
CVE-2026-79774 Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy 26.08.2026 9.3
CVE-2026-79782 rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect 28.08.2026 9.3
CVE-2026-16286 File Upload in TRTEK Software's Software Repository Management 25.08.2026 9.8
CVE-2026-77998 Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 26.08.2026 10
CVE-2026-57909 WatchGuard Agent path traversal allows unauthenticated remote code execution 26.08.2026 9.4
CVE-2026-57910 WatchGuard Agent improper authentication allows unauthenticated remote code execution 25.08.2026 9.3
CVE-2026-79657 NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization 25.08.2026 9.3
CVE-2026-79664 Ech0 before 4.7.3 Access Token Revocation Bypass 25.08.2026 9.1
CVE-2026-78570 Total Donations <= 2.0.5 - Unauthenticated Privilege Escalation 27.08.2026 9.8
CVE-2026-63586 Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface 25.08.2026 9.3
CVE-2026-77136 Server-Side Template Injection in extension "powermail" (powermail) 25.08.2026 9.5
CVE-2026-77138 Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail) 25.08.2026 9.3
CVE-2026-78568 Total Donations <= 2.0.5 - Unauthenticated SQL Injection 25.08.2026 9.8
CVE-2026-78477 Jawn <= 1.4.2 - Unauthenticated Privilege Escalation 25.08.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-51711 31.08.2026
CVE-2026-51712 31.08.2026
CVE-2026-51713 31.08.2026
CVE-2026-51714 31.08.2026
CVE-2026-51715 31.08.2026
CVE-2026-51716 31.08.2026
CVE-2026-83492 WordPress Kubio AI Website Builder - Denial Of Service 31.08.2026
CVE-2026-21827 HCL Connections is vulnerable to an information disclosure vulnerability 31.08.2026 3.1
CVE-2026-82805 Typora Mermaid Rendering cross site scripting 31.08.2026
CVE-2026-77966 Ebyte NA111-M Missing Authorization 31.08.2026 8.8
CVE-2026-51152 31.08.2026
CVE-2026-51153 31.08.2026
CVE-2026-51702 31.08.2026
CVE-2026-51703 31.08.2026
CVE-2026-51704 31.08.2026
CVE-2026-51705 31.08.2026
CVE-2026-51706 31.08.2026
CVE-2026-51708 31.08.2026
CVE-2026-51709 31.08.2026
CVE-2026-51710 31.08.2026
CVE-2026-73819 Ebyte NA111-M Weak Authentication 31.08.2026 9.8
CVE-2026-75133 Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_process 31.08.2026
CVE-2026-76133 Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm 31.08.2026 9.8
CVE-2026-77975 Ebyte NA111-M Cleartext Storage of Sensitive Information 31.08.2026 6.5
CVE-2026-82803 armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null pointer dereference 31.08.2026
CVE-2026-51698 31.08.2026
CVE-2026-51699 31.08.2026
CVE-2026-51700 31.08.2026
CVE-2026-51701 31.08.2026
CVE-2026-75132 WAPT Server SQL Injection via /api/v3/hosts Endpoint 31.08.2026
CVE-2026-82802 NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery 31.08.2026
CVE-2026-82823 31.08.2026
CVE-2026-51692 31.08.2026
CVE-2026-51693 31.08.2026
CVE-2026-51694 31.08.2026
CVE-2026-51695 31.08.2026
CVE-2026-51696 31.08.2026
CVE-2026-51697 31.08.2026
CVE-2026-82801 NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery 31.08.2026
CVE-2026-51691 31.08.2026
CVE-2026-63083 31.08.2026
CVE-2026-66047 ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE 31.08.2026
CVE-2026-82703 Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection 31.08.2026
CVE-2026-82970 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability 31.08.2026 10
CVE-2026-59111 Command Injection vulnerability in eObčanka-Identifikace 31.08.2026 9.3
CVE-2026-82702 Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection 31.08.2026
CVE-2026-51683 31.08.2026
CVE-2026-51684 31.08.2026
CVE-2026-51686 31.08.2026
CVE-2026-51687 31.08.2026
CVE-2026-51688 31.08.2026
CVE-2026-51689 31.08.2026
CVE-2026-51690 31.08.2026
CVE-2026-78422 zbus_polkit: polkit authorization bypass via PID reuse due to incorrect D-Bus type for the subject UID 31.08.2026
CVE-2026-82701 code-projects Online Shopping System Search Functionality action.php sql injection 31.08.2026
CVE-2026-19702 OS Command Injection in TÜBİTAK BİLGEM's Pardus Boot Repair 31.08.2026 7.8
CVE-2026-51678 31.08.2026
CVE-2026-51679 31.08.2026
CVE-2026-51680 31.08.2026
CVE-2026-51681 31.08.2026
CVE-2026-78075 Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 31.08.2026
CVE-2026-78076 Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 31.08.2026
CVE-2026-78078 Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 31.08.2026
CVE-2026-82700 code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scripting 31.08.2026
CVE-2026-51675 31.08.2026
CVE-2026-51676 31.08.2026
CVE-2026-51677 31.08.2026
CVE-2026-76763 Io.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of service via large exponent float literals 31.08.2026
CVE-2026-78074 Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions 31.08.2026
CVE-2026-78077 Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 31.08.2026
CVE-2026-78079 Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 31.08.2026
CVE-2026-19616 Information Disclosure in TBC Technology's KitLogistic 31.08.2026 7.5
CVE-2026-51671 31.08.2026
CVE-2026-51672 31.08.2026
CVE-2026-51673 31.08.2026
CVE-2026-51674 31.08.2026
CVE-2026-82699 sambitraj Student Management System Password aca.sql cleartext storage 31.08.2026
CVE-2026-51668 31.08.2026
CVE-2026-51669 31.08.2026
CVE-2026-51670 31.08.2026
CVE-2026-82217 31.08.2026 8.8
CVE-2026-76986 Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue 31.08.2026
CVE-2026-82698 sambitraj Student-Management-System aca.sql default password 31.08.2026
CVE-2026-76985 Apache Wicket: XSS in Palette via getAdditionalAttributes 31.08.2026
CVE-2026-82697 sambitraj Student-Management-System session_start cookie httponly flag 31.08.2026
CVE-2026-82696 itsourcecode Sales and Inventory System inv_searchfrm.php sql injection 31.08.2026
CVE-2026-51666 31.08.2026
CVE-2026-51667 31.08.2026
CVE-2026-5956 SQLi in Ankara Hosting's Site Management Panel 31.08.2026 8.8
CVE-2026-82694 Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication 31.08.2026
CVE-2026-82695 Tenda AC18 Telnet telnet missing authentication 31.08.2026
CVE-2026-12894 Quarkus-qute: io.quarkus.qute.reflectionvalueresolver: quarkus:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine 31.08.2026
CVE-2026-74010 WordPress bbPress plugin <= 2.6.14 - Broken Access Control vulnerability 31.08.2026 5.3
CVE-2026-82692 D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection 31.08.2026
CVE-2026-82693 Tenda AC1206 Web UI telnet TendaTelnet missing authentication 31.08.2026
CVE-2026-76983 Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel 31.08.2026
CVE-2026-76984 Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute 31.08.2026
CVE-2026-75802 Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel 31.08.2026
CVE-2026-76982 Apache Wicket: XSS in Button via its model object 31.08.2026
CVE-2026-70449 Apache Wicket: Path traversal in resource style/variation/locale 31.08.2026
CVE-2026-71257 Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed 31.08.2026
CVE-2026-71378 Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener 31.08.2026
CVE-2026-82691 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection 31.08.2026
CVE-2026-82690 D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection 31.08.2026
CVE-2026-82797 31.08.2026 5.5
CVE-2026-82689 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection 31.08.2026
CVE-2026-82688 D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection 31.08.2026
CVE-2026-82876 Phison PS3111-S11 Controller Firmware Signature Verification Bypass 31.08.2026
CVE-2026-82877 ILIAS before 9.22 Arbitrary File Read via SOAP addFile 31.08.2026
CVE-2026-82878 DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Chart Endpoints 31.08.2026
CVE-2026-82879 DataEase before 2.10.26 Access Control Bypass via Share Tickets 31.08.2026
CVE-2026-82880 YaCy Search Server through 1.941 XML External Entity Injection via Parsers 31.08.2026
CVE-2026-82881 Aix-DB through 1.2.4 Stored Cross-Site Scripting via Markdown 31.08.2026
CVE-2026-82680 D-Link DSM-G600 Multipart load_file.cgi out-of-bounds write 31.08.2026
CVE-2026-82679 diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload 31.08.2026
CVE-2026-82678 diem-project diem Administrative Console actions.class.php executeCommand os command injection 31.08.2026
CVE-2026-19873 HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements 31.08.2026
CVE-2026-82677 valkey-io valkey Module Timer module.c moduleTimerHandler double free 31.08.2026
CVE-2026-49003 Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product 31.08.2026 9.6
CVE-2026-82671 IObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess privileges management 31.08.2026
CVE-2026-82669 klaussilveira GitList XML Parsing CommandLine.php SimpleXMLElement denial of service 31.08.2026
CVE-2026-82670 IObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges management 31.08.2026
CVE-2026-82668 klaussilveira GitList Git Command Line CommandLine.php getDefaultBranch os command injection 31.08.2026
CVE-2024-58379 nodemailer before 6.9.9 ReDoS via attachDataUrls parameter 31.08.2026
CVE-2026-81624 Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite 31.08.2026
CVE-2026-82659 nodemailer before 9.0.1 File Read and SSRF via raw option 31.08.2026
CVE-2026-82660 Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess 31.08.2026
CVE-2026-82661 Nodemailer CRLF Injection via List-* Header Comments 31.08.2026
CVE-2026-82662 Nodemailer before 8.0.8 TLS Certificate Validation Bypass 31.08.2026
CVE-2026-82667 yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forgery 31.08.2026
CVE-2026-82853 Nodemailer before 8.0.5 SMTP Command Injection via CRLF 31.08.2026
CVE-2026-82854 Nodemailer before 8.0.3 SMTP Command Injection via envelope.size 31.08.2026
CVE-2026-82855 @hulumi/policies before 1.3.2 Evidence Validation Bypass 31.08.2026
CVE-2026-82856 @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass 31.08.2026
CVE-2026-82857 hulumi before v1.3.2 Privilege Escalation via IAM Policy 31.08.2026
CVE-2026-82858 @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance 31.08.2026
CVE-2026-82859 hulumi before v1.3.2 SCP Template Tag-on-Create Bypass 31.08.2026
CVE-2026-82860 @hulumi/policies before 1.3.2 Admin Policy Bypass 31.08.2026
CVE-2026-82861 @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass 31.08.2026
CVE-2026-82862 Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files 31.08.2026
CVE-2026-82863 @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection 31.08.2026
CVE-2026-82864 pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb 31.08.2026
CVE-2026-82865 pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Label 31.08.2026
CVE-2026-82866 @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch 31.08.2026
CVE-2026-82867 @pdfme/schemas before 5.5.9 Cross-Site Scripting via Select 31.08.2026
CVE-2026-82868 @pdfme/schemas before 5.5.9 Cross-Site Scripting via SVG 31.08.2026
CVE-2026-82869 ToolJet Database before v3.16.44 Privilege Escalation via join_tables 31.08.2026
CVE-2026-82870 ToolJet before v3.16.208 Cross-Tenant Database Manipulation 31.08.2026
CVE-2026-82871 ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes 31.08.2026
CVE-2026-82872 ToolJet before v3.16.208 Cross-Workspace Authorization Bypass 31.08.2026
CVE-2026-82873 ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export 31.08.2026
CVE-2026-82874 ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db 31.08.2026
CVE-2026-82875 ToolJet before v3.16.208 Authorization Bypass via organizationId 31.08.2026
CVE-2026-82666 yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection 31.08.2026
CVE-2026-19410 Google Cloud Build Comment Control Bypass via Webhook Suppression 31.08.2026
CVE-2026-82664 yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting 31.08.2026
CVE-2026-82665 yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal 31.08.2026
CVE-2026-82631 valkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free 31.08.2026
CVE-2026-58301 Apache Shiro: Server-side POST request may be steered to an alternate host 31.08.2026
CVE-2026-82630 PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery 31.08.2026
CVE-2026-82838 Default webserver configuration with incorrect CSP 31.08.2026
CVE-2026-82629 jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload 31.08.2026
CVE-2026-82625 code-projects Simple Inventory System User Registration register.php cross site scripting 31.08.2026
CVE-2026-82628 Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management 31.08.2026
CVE-2026-40463 An Insufficient Role-based Access Control Vulnerability in WaveSuite 31.08.2026
CVE-2026-40464 A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP 31.08.2026
CVE-2026-40465 An Open Re-direct Vulnerability in Nokia NSP 31.08.2026
CVE-2026-53620 31.08.2026
CVE-2026-58574 31.08.2026 9.8
CVE-2026-68951 31.08.2026
CVE-2026-77013 Icollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted Method Dispatch 31.08.2026
CVE-2026-82622 code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting 31.08.2026
CVE-2026-82623 open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after free 31.08.2026
CVE-2026-82624 code-projects Simple Inventory System Database Backup File inventorymanagement.sql information disclosure 31.08.2026
CVE-2026-82621 Soarkey StudentManagement/学生信息管理系统 Administrative Servlet AdminDao.java AdminDao.doGet authorization 31.08.2026
CVE-2026-82620 Soarkey StudentManagement/学生信息管理系统 CourseDao.java CourseDao.course_ranking sql injection 31.08.2026
CVE-2026-82619 Systerel S2OPC subscription_mgr.c use after free 31.08.2026
CVE-2026-82618 Systerel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-bounds 31.08.2026