CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding 14.08.2026 9.3
CVE-2026-72810 SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket 14.08.2026 9.2
CVE-2026-72811 SiYuan before v3.7.4 SQL Injection via backlink search 14.08.2026 9.9
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa 14.08.2026 9.3
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController 14.08.2026 9.3
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey 14.08.2026 9.3
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController 14.08.2026 9.3
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass 14.08.2026 9.3
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass 14.08.2026 9.2
CVE-2026-12949 Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter 14.08.2026 9.8
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup 13.08.2026 9.3
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 13.08.2026 9.4
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass 13.08.2026 9.4
CVE-2026-72850 Budibase before 3.40.0 Arbitrary File Write via Path Traversal 13.08.2026 9.4
CVE-2026-72851 Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook 13.08.2026 9
CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified 13.08.2026 9
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 14.08.2026 9.1
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 13.08.2026 9.1
CVE-2026-73842 OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation 13.08.2026 9
CVE-2026-73843 OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs 13.08.2026 9.6
CVE-2026-73665 FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection 13.08.2026 9.3
CVE-2026-19750 Tenda CH/CP/TX3 SSH hard-coded password 13.08.2026 9.2
CVE-2026-72776 AgenticSeek Unauthenticated RCE via /query API Endpoint 14.08.2026 9.3
CVE-2026-73663 FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover 13.08.2026 9.3
CVE-2026-17482 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 13.08.2026 9.8
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint 13.08.2026 9.1
CVE-2026-8715 Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath 14.08.2026 9.6
CVE-2026-19747 Tenda CH7 ATE Module Kylin HandleCmd command injection 14.08.2026 9.3
CVE-2026-73656 Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state 13.08.2026 9.9
CVE-2026-14525 IBM WebSphere Application Server Liberty is affected by an authenication bypass 13.08.2026 9.4
CVE-2026-73653 Vitest: Browser Mode provider commands bypass the file-access permission gate 13.08.2026 9.4
CVE-2026-73644 OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant 13.08.2026 9.6
CVE-2026-73649 Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) 13.08.2026 9.8
CVE-2026-73567 sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock 13.08.2026 9.1
CVE-2026-67614 CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal 14.08.2026 9.3
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build 13.08.2026 9.3
CVE-2026-73533 Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build 13.08.2026 9.3
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths 14.08.2026 9.2
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header 14.08.2026 9.1
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode 14.08.2026 9.1
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure 14.08.2026 9.1
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink 14.08.2026 9.2
CVE-2026-27544 WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability 13.08.2026 10
CVE-2026-28001 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28008 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28142 WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28148 WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability 13.08.2026 9.8
CVE-2026-28149 WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability 13.08.2026 9.8
CVE-2026-28185 WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-61962 WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability 13.08.2026 10
CVE-2026-61966 WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61967 WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-61969 WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-66436 WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66446 WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability 13.08.2026 9.8
CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66478 WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66691 WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability 13.08.2026 9.8
CVE-2026-49827 WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) 13.08.2026 9.8
CVE-2026-73483 Flowise before 3.1.3 Sandbox Escape via Puppeteer 13.08.2026 9.4
CVE-2026-73485 Flowise before 3.1.3 Remote Code Execution via Airtable Agent 13.08.2026 9
CVE-2026-73486 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV 13.08.2026 9
CVE-2026-73487 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent 13.08.2026 9
CVE-2026-73601 Flowise before 3.1.3 Remote Code Execution via Custom MCP 13.08.2026 9
CVE-2026-73602 Flowise before 3.1.3 Sandbox Escape to RCE 13.08.2026 9
CVE-2026-73608 SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget 13.08.2026 9.2
CVE-2026-59503 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor 13.08.2026 9.1
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security 13.08.2026 9.1
CVE-2026-59506 Priority – CWE-306: Missing Authentication for Critical Function 13.08.2026 9.3
CVE-2026-59507 Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control 13.08.2026 9.3
CVE-2026-59500 Priority - CWE-287: Improper Authentication 13.08.2026 10
CVE-2026-15413 Link Factory - Backdoor 13.08.2026 10
CVE-2026-49819 UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd 13.08.2026 9.8
CVE-2026-49481 UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd 13.08.2026 9.6
CVE-2026-71193 13.08.2026 9.6
CVE-2026-71471 Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image 13.08.2026 9
CVE-2024-27253 IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request 13.08.2026 10
CVE-2026-73501 kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default 13.08.2026 9.1
CVE-2026-73519 WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret 13.08.2026 9.3
CVE-2026-19001 MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names 13.08.2026 9.5
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE 13.08.2026 9.9
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 13.08.2026 9.9
CVE-2026-63294 Root RCE via image backup.yaml symlink 13.08.2026 9.9
CVE-2026-17083 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 13.08.2026 9.8
CVE-2026-63296 Project restriction bypass via instance migration config override 13.08.2026 9.9
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 13.08.2026 9.9
CVE-2026-72508 Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) 13.08.2026 9.9
CVE-2026-73414 Shescape: Shell injection via unescaped parentheses on Windows with CMD 12.08.2026 9.2
CVE-2026-19656 ScadaLTS Authenticated Remote Code Execution 12.08.2026 9.9
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag 12.08.2026 9.9
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution 13.08.2026 9.9
CVE-2026-72789 SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks 12.08.2026 9.2
CVE-2026-72793 SiYuan before v3.7.4 Information Disclosure via /api/system/getConf 12.08.2026 9.2
CVE-2026-72794 siyuan before v3.7.4 Session Cookie Key Disclosure via getConf 12.08.2026 9.2
CVE-2026-72795 SiYuan before v3.7.4 Information Disclosure via Embed Block 12.08.2026 9.2
CVE-2026-72798 SiYuan before v3.7.4 Information Disclosure via renderAttributeView 12.08.2026 9.2
CVE-2026-72804 SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints 12.08.2026 9.2
CVE-2026-73268 Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection 12.08.2026 9.9
CVE-2026-73269 Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa 12.08.2026 9.9
CVE-2026-73329 CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint 12.08.2026 9.2
CVE-2026-73332 CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field 12.08.2026 9.2
CVE-2026-73407 Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) 12.08.2026 9
CVE-2026-73300 Budibase: SQL Injection via `multipleStatements: true` 12.08.2026 9.6
CVE-2026-16860 IBM i is Affected By Remote Code Execution Vulnerability [] 12.08.2026 9.9
CVE-2026-16956 IBM Db2 Mirror for i is vulnerable to OS command injection [] 12.08.2026 9.8
CVE-2026-17218 IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] 12.08.2026 9.8
CVE-2026-73299 Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer 12.08.2026 10
CVE-2026-17276 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 9.6
CVE-2026-73296 Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure 13.08.2026 9.4
CVE-2026-73294 Semaphore U: OS Command Injection 12.08.2026 9.9
CVE-2026-64639 12.08.2026 9.3
CVE-2026-73263 Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path 12.08.2026 9.9
CVE-2026-50561 Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse 13.08.2026 9.4
CVE-2026-67285 Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 13.08.2026 9.2
CVE-2026-57858 Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID 13.08.2026 9.3
CVE-2026-67282 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 12.08.2026 10
CVE-2025-41769 Unauthenticated Buffer Overflow in PROFINET Service 13.08.2026 9.3
CVE-2026-66659 WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability 12.08.2026 9.3
CVE-2026-70398 Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace 12.08.2026 9.6
CVE-2026-72526 Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation 12.08.2026 9.9
CVE-2026-68431 ksmbd: validate minimum PDU size for transform requests 13.08.2026 9.1
CVE-2026-5917 libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend 12.08.2026 9.4
CVE-2026-67568 Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials 12.08.2026 9.3
CVE-2026-68067 Mira Hormone Monitor, Mira Android App Weak Authentication 12.08.2026 9.3
CVE-2026-48765 TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding 12.08.2026 9.9
CVE-2026-16230 Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field 11.08.2026 9.8
CVE-2026-45618 LiquidJS is Vulnerable to Remote Code Execution 13.08.2026 10
CVE-2026-73034 DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header 13.08.2026 9.3
CVE-2026-73032 PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() 11.08.2026 9.4
CVE-2026-18691 Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure 11.08.2026 9
CVE-2026-72742 DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing 12.08.2026 9.2
CVE-2026-69102 MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust 12.08.2026 9.3
CVE-2026-27302 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-48381 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 11.08.2026 9
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) 12.08.2026 9.1
CVE-2026-71398 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-47705 TypeBot vulnerable to CSV injection in result export 13.08.2026 9.6
CVE-2026-73090 PeerTube: Cross-origin remote video takeover via Update activity 13.08.2026 9.3
CVE-2026-73211 PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() 11.08.2026 9.8
CVE-2026-12571 Authentication Bypass Leading to Account Takeover 12.08.2026 9.8
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 13.08.2026 9.4
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 13.08.2026 9.8
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability 13.08.2026 9.8
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability 13.08.2026 9.8
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability 13.08.2026 9.8
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability 13.08.2026 9.8
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability 13.08.2026 9.3
CVE-2026-48362 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 12.08.2026 10
CVE-2026-71384 ColdFusion | Incorrect Authorization (CWE-863) 12.08.2026 9.6
CVE-2026-73080 SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle 13.08.2026 9.3
CVE-2025-31114 Fooocus webui vulnerable to Remote Code Execution 13.08.2026 9.3
CVE-2026-73069 Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution 11.08.2026 9.1
CVE-2026-17061 Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 11.08.2026 10
CVE-2026-47702 TypeBot API tokens stored in plaintext 11.08.2026 9.1
CVE-2026-72920 SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control 11.08.2026 9.8
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection 13.08.2026 9.8
CVE-2026-48056 Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler 11.08.2026 10
CVE-2026-48046 Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler 13.08.2026 9.3
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability 11.08.2026 9.6
CVE-2026-58115 12.08.2026 10
CVE-2026-72785 Craft CMS before 5.10.6 Authorization Bypass via structures/move-element 11.08.2026 9.3
CVE-2026-13737 Command Restriction Bypass 11.08.2026 9.2
CVE-2026-13738 Improper Authorization Validation 11.08.2026 9.2
CVE-2026-72550 Friendica Friendica - SQL Injection 11.08.2026 9.8
CVE-2026-72599 e107 e107 - SQL Injection 11.08.2026 9.8
CVE-2026-72603 wg-easy wg-easy - OS Command Injection 11.08.2026 9.9
CVE-2026-58231 Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) 12.08.2026 10
CVE-2026-10579 Picketlink-federation: auth bypass in picketlink saml unsolicited-response 11.08.2026 9.8
CVE-2026-13716 Path Traversal: '.../...//' in Crafty Controller 11.08.2026 9.1
CVE-2026-19516 CVE-2026-19516 CVE Record 12.08.2026 9.1
CVE-2026-19425 Win Men Intermational|Travel Agency Management System - SQL Injection 12.08.2026 9.3
CVE-2026-34265 Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform 12.08.2026 9.8
CVE-2026-44758 Code Injection vulnerability in Manufacturing Integration and Intelligence 11.08.2026 9.1
CVE-2026-48161 react18-use was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-48160 react-tracked was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation 13.08.2026 9.9
CVE-2026-14450 Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication 11.08.2026 9.9
CVE-2026-18948 Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server 11.08.2026 9.9
CVE-2026-72904 Firecrawl: Arbitrary file read via JSON Schema $ref expansion 11.08.2026 9.3
CVE-2026-72901 Dokploy: Remote Code Execution via volume-backup 13.08.2026 9.9
CVE-2026-72902 Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById 12.08.2026 9.9
CVE-2025-13293 Backdoor / default root credentials 12.08.2026 9.3
CVE-2025-13294 Unauthenticated SQL Injection 12.08.2026 9.3
CVE-2025-15681 Insufficient Webserver Authentication 12.08.2026 9.2
CVE-2026-72880 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` 11.08.2026 9.9
CVE-2026-72882 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers 13.08.2026 9.9
CVE-2026-72886 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) 10.08.2026 9.9
CVE-2026-72876 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* 10.08.2026 9.9
CVE-2026-72877 Dokploy: Command Injection via dockerImage in buildRemoteDocker 13.08.2026 9.6
CVE-2026-72878 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments 12.08.2026 9.6
CVE-2026-72879 Dokploy: Command Injection via Registry Credentials in Swarm Upload 11.08.2026 9.4
CVE-2026-72864 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) 11.08.2026 9.9
CVE-2026-72865 Dokploy: OS Command Injection via compose `composePath` 11.08.2026 9.9
CVE-2026-72867 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) 13.08.2026 9.9
CVE-2026-72868 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection 12.08.2026 9.9
CVE-2026-72869 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE 11.08.2026 9.9
CVE-2026-72872 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` 13.08.2026 9.9
CVE-2026-72863 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host 10.08.2026 9.9
CVE-2026-16626 JasperReports Server: XXE Injection Vulnerability (Unauthenticated) 11.08.2026 9.3
CVE-2026-48159 use-reducer-async was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72740 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` 10.08.2026 9.9
CVE-2026-72862 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE 13.08.2026 9.9
CVE-2026-72898 Metabase SQL injection via password reset endpoint 12.08.2026 10
CVE-2026-72899 Metabase SQL injection via public card or dashboard 11.08.2026 10
CVE-2026-72735 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution 10.08.2026 9.9
CVE-2026-72736 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE 10.08.2026 9.9
CVE-2026-72737 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups 13.08.2026 9.6
CVE-2026-72738 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter 10.08.2026 9.9
CVE-2026-72733 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore 10.08.2026 9.9
CVE-2026-48158 use-context-selector was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-47754 unauthenticated path traversal in Metacat 2.x 10.08.2026 9.3
CVE-2026-63106 ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php 10.08.2026 9.3
CVE-2026-13206 Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection 10.08.2026 9.8
CVE-2026-68117 tipc: clear sock->sk on the failed-insert path in tipc_sk_create() 13.08.2026 9.8
CVE-2026-68123 openvswitch: fix GSO userspace truncation underflow 13.08.2026 9.8
CVE-2026-68124 mctp: serial: handle zero-length frames to prevent rx buffer overflow 13.08.2026 9.6
CVE-2026-68127 ila: reload IPv6 header after pskb_may_pull in checksum adjust 13.08.2026 9.8
CVE-2026-68136 net: gro: fix double aggregation of flush-marked skbs 13.08.2026 9.8
CVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh() 13.08.2026 9.8
CVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb() 13.08.2026 9.8
CVE-2026-68154 libceph: reject zero bucket types in crush_decode 13.08.2026 9.8
CVE-2026-68156 libceph: refresh auth->authorizer_buf{,_len} after authorizer update 13.08.2026 9.8
CVE-2026-68158 libceph: Fix multiplication overflow in decode_new_up_state_weight() 13.08.2026 9.8
CVE-2026-68159 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE 13.08.2026 9.8
CVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() 13.08.2026 9.8
CVE-2026-68161 sctp: close UDP tunnel sockets during netns teardown 13.08.2026 9.8
CVE-2026-68170 mptcp: fix stale skb->sk reference on subflow close 13.08.2026 9.8
CVE-2026-68300 sctp: auth: verify auth requirement when auth_chunk is NULL 13.08.2026 9.8
CVE-2026-68302 amt: re-read skb header pointers after every pull 13.08.2026 9.8
CVE-2026-68343 smb: client: validate DFS referral PathConsumed 13.08.2026 9.1
CVE-2026-68381 ksmbd: pin conn during async oplock break notification 13.08.2026 9.8
CVE-2026-68385 s390/checksum: Fix csum_partial() without vector facility 13.08.2026 9.8
CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate 13.08.2026 9.8
CVE-2026-68426 xfrm: fix stale skb->prev after async crypto steals a GSO segment 13.08.2026 9.8
CVE-2026-68083 ksmbd: fix path resolution in ksmbd_vfs_kern_path_create 13.08.2026 9.1
CVE-2026-72564 fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication 10.08.2026 9.6
CVE-2026-72565 Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass 10.08.2026 9.8
CVE-2026-72567 deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete 10.08.2026 9.8
CVE-2026-72569 cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion 10.08.2026 9.1
CVE-2026-72575 daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects 10.08.2026 9.1
CVE-2026-72577 NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection 10.08.2026 9.8
CVE-2026-72580 duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints 10.08.2026 9.8
CVE-2026-72589 alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field 10.08.2026 9.8
CVE-2026-72590 alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter 10.08.2026 9.8
CVE-2026-72592 dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload 10.08.2026 9.8
CVE-2026-72593 dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access 10.08.2026 9.8
CVE-2026-66915 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.9 12.08.2026 10
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 10.08.2026 9.3
CVE-2026-71992 MSI Radix AXE6600 v781521 Command Injection via macfilter 10.08.2026 9.3
CVE-2026-71993 MSI Radix AXE6600 v781521 Command Injection via openvpn function 11.08.2026 9.3
CVE-2026-71991 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 08.08.2026 9.3
CVE-2026-71986 MSI Radix AXE6600 v781521 Command Injection via dmz Function 08.08.2026 9.3
CVE-2026-71987 MSI Radix AXE6600 v781521 Command Injection via alg function 10.08.2026 9.3
CVE-2026-71988 MSI Radix AXE6600 v781521 Command Injection via portFw function 11.08.2026 9.3
CVE-2026-71989 MSI Radix AXE6600 v781521 Command Injection via porTrigger function 10.08.2026 9.3
CVE-2026-71990 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 11.08.2026 9.3
CVE-2026-71984 MSI Radix AXE6600 v781521 Command Injection via urlfilter 10.08.2026 9.3
CVE-2026-71985 MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function 11.08.2026 9.3
CVE-2026-71983 MSI Radix AXE6600 v781521 Command Injection via wps.cgi 11.08.2026 9.3
CVE-2026-71956 D-Link DWR-M961 Command Injection via app.cgi 11.08.2026 9.3
CVE-2026-71957 D-Link DWR-M961 Buffer Overflow via app.cgi 08.08.2026 9.3
CVE-2026-71958 D-Link DWR-M961 Buffer Overflow via quicksetup.cgi 10.08.2026 9.3
CVE-2026-71944 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel 11.08.2026 9.3
CVE-2026-71945 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom 10.08.2026 9.3
CVE-2026-71946 D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun 11.08.2026 9.3
CVE-2026-71947 D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun 08.08.2026 9.3
CVE-2026-71948 D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun 10.08.2026 9.3
CVE-2026-71949 D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup 11.08.2026 9.3
CVE-2026-71950 D-Link DWR-M961 Command Injection via /boafrm/formSmsManage 10.08.2026 9.3
CVE-2026-71951 D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup 11.08.2026 9.3
CVE-2026-71952 D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup 08.08.2026 9.3
CVE-2026-71953 D-Link DWR-M961 Command Injection via /boafrm/formNtp 10.08.2026 9.3
CVE-2026-71954 D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup 11.08.2026 9.3
CVE-2026-71955 D-Link DWR-M961 Command Injection via /boafrm/formWsc 10.08.2026 9.3
CVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers() 13.08.2026 9.8
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route 11.08.2026 9.8
CVE-2026-46409 OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution 11.08.2026 9.6
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs 10.08.2026 9.2
CVE-2026-48170 scimPatch vulnerable to prototype pollution via unfiltered keys in patch 10.08.2026 9.1
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading 12.08.2026 9.6
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration 10.08.2026 9.8
CVE-2026-48039 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 07.08.2026 9.1
CVE-2026-71851 crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain 08.08.2026 9
CVE-2026-64637 07.08.2026 9.9

Latest Updates

CVE Title Updated Score
CVE-2026-19837 Webkul Bagisto Customer Search search information disclosure 14.08.2026
CVE-2026-63700 14.08.2026 7.8
CVE-2026-66271 14.08.2026 7.2
CVE-2026-16772 CVE-2026-16772 14.08.2026
CVE-2026-19836 Webkul Bagisto Backend Customer Detail Feature view authorization 14.08.2026
CVE-2026-19884 14.08.2026
CVE-2026-53970 ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb 14.08.2026
CVE-2026-63701 14.08.2026 6.3
CVE-2026-63702 14.08.2026 6.3
CVE-2026-66270 14.08.2026 7.2
CVE-2026-66272 14.08.2026 5.3
CVE-2026-13002 Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing 14.08.2026
CVE-2026-13196 Out-of-bounds Write in KUNBUS piControl 14.08.2026
CVE-2026-13197 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl 14.08.2026
CVE-2026-13198 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl 14.08.2026
CVE-2026-19834 Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization 14.08.2026
CVE-2026-19835 Webkul Bagisto Customer Item Deletion Endpoint access control 14.08.2026
CVE-2026-57469 Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory 14.08.2026
CVE-2026-57471 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad 14.08.2026
CVE-2026-57472 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad 14.08.2026
CVE-2026-19879 Io.undertow/undertow: undertow: http response header integrity issue due to character truncation 14.08.2026
CVE-2026-58224 Samba: ctdb fails to do integrity checking of received packets 14.08.2026
CVE-2026-19880 Incomplete protection against CVE-2025-11226 14.08.2026
CVE-2026-69101 Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint 14.08.2026
CVE-2026-19768 14.08.2026
CVE-2026-19829 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal 14.08.2026
CVE-2026-19830 TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources 14.08.2026
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding 14.08.2026
CVE-2026-1621 Register Bypass in Universal Sotware's E-Municipality 14.08.2026 5.3
CVE-2026-53472 Migration-planner: credentialurl validator accepts javascript: urls 14.08.2026
CVE-2026-73633 Apache Struts: Unbounded read of a JSON request body 14.08.2026
CVE-2026-19827 alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal 14.08.2026
CVE-2026-19828 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal 14.08.2026
CVE-2026-19825 SourceCodester Simple Client Management System Master.php save_service sql injection 14.08.2026
CVE-2026-19826 alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization 14.08.2026
CVE-2026-19824 Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow 14.08.2026
CVE-2026-19823 Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow 14.08.2026
CVE-2026-19870 IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation 14.08.2026
CVE-2026-73673 Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication 14.08.2026
CVE-2025-71405 go-chi chi before v5.2.2 Open Redirect via RedirectSlashes 14.08.2026
CVE-2026-19822 Tenda W20E QoS Edit editQos lstAdd stack-based overflow 14.08.2026
CVE-2026-72810 SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket 14.08.2026
CVE-2026-72811 SiYuan before v3.7.4 SQL Injection via backlink search 14.08.2026
CVE-2026-72812 SiYuan before v3.7.4 Missing Authorization via refreshBacklink 14.08.2026
CVE-2026-72813 actix-files before 0.6.10 Denial of Service via empty Range header 14.08.2026
CVE-2026-72814 actix-web before 0.6.10 Information Disclosure via Files 14.08.2026
CVE-2026-72815 go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header 14.08.2026
CVE-2026-72816 go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware 14.08.2026
CVE-2026-72817 go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For 14.08.2026
CVE-2026-72819 Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload 14.08.2026
CVE-2026-72820 Grav 2.0.11 Path Traversal via Backup Profile Configuration 14.08.2026
CVE-2026-72821 Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle 14.08.2026
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa 14.08.2026
CVE-2026-72823 Grav before 1.0.13 API-key scope cap bypass via DemoController 14.08.2026
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController 14.08.2026
CVE-2026-72825 Grav before 1.0.13 API-key scope cap bypass via ReportsController 14.08.2026
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey 14.08.2026
CVE-2026-72827 Grav CMS before 2.0.13 Remote Code Execution via Twig 14.08.2026
CVE-2026-72828 Grav before 1.0.13 API Key Scope Bypass via InvitationsController 14.08.2026
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController 14.08.2026
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass 14.08.2026
CVE-2026-72831 Grav through 2.0.11 Authentication Bypass via Flex Objects 14.08.2026
CVE-2026-72832 Grav before 2.0.12 Stored XSS via quoted-attribute bypass 14.08.2026
CVE-2026-72833 Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys 14.08.2026
CVE-2026-72834 filebrowser before 2.63.19 Permission Bypass via checksum 14.08.2026
CVE-2026-72835 filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization 14.08.2026
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass 14.08.2026
CVE-2026-72837 File Browser before 2.63.20 Privilege Escalation via Proxy Authentication 14.08.2026
CVE-2026-72838 FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload 14.08.2026
CVE-2026-72859 Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL 14.08.2026
CVE-2026-73048 SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID 14.08.2026
CVE-2026-73049 SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks 14.08.2026
CVE-2026-73051 actix-http before 3.12.1 HTTP Request Smuggling via CL.TE 14.08.2026
CVE-2026-73630 SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess 14.08.2026
CVE-2026-19821 Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow 14.08.2026
CVE-2026-19814 TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow 14.08.2026
CVE-2026-19815 TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow 14.08.2026
CVE-2026-19813 TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow 14.08.2026
CVE-2026-19794 WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting 14.08.2026 7.2
CVE-2026-19812 TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow 14.08.2026
CVE-2026-19811 TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow 14.08.2026
CVE-2026-14290 Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute 14.08.2026
CVE-2026-15205 Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup 14.08.2026
CVE-2026-16739 Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery 14.08.2026
CVE-2026-18039 Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment 14.08.2026
CVE-2026-19617 Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser 14.08.2026
CVE-2026-12743 affiliate-toolkit <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter 14.08.2026 4.9
CVE-2026-12949 Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter 14.08.2026 9.8
CVE-2026-16810 Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Parameter 14.08.2026 6.5
CVE-2025-10308 Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset 14.08.2026 4.3
CVE-2026-19791 Tenda G0 httpd web management interface module addStaticRoute stack-based overflow 14.08.2026
CVE-2026-19792 Tenda G0 httpd web management interface module setPortMapping buffer overflow 14.08.2026
CVE-2026-19788 Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow 14.08.2026
CVE-2026-19789 Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow 14.08.2026
CVE-2026-19790 Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow 14.08.2026
CVE-2026-18109 W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name 14.08.2026 7.2
CVE-2026-19784 francoisjacquet RosarioSIS Referrals.php DBUpdate authorization 14.08.2026
CVE-2026-19785 francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection 14.08.2026
CVE-2026-19786 francoisjacquet RosarioSIS Modules.php cross-site request forgery 14.08.2026
CVE-2026-19787 SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection 14.08.2026
CVE-2026-19767 itsourcecode Hospital Management System viewdoctortimings.php sql injection 14.08.2026
CVE-2026-19770 feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgery 14.08.2026
CVE-2026-19771 Baicells EG3661M LuCI Web luci os command injection 14.08.2026
CVE-2026-19764 Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection 14.08.2026
CVE-2026-19765 eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource server-side request forgery 14.08.2026
CVE-2026-19762 DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal 14.08.2026
CVE-2026-19763 DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal 14.08.2026
CVE-2026-19761 DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal 14.08.2026
CVE-2026-19758 dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal 13.08.2026
CVE-2026-19757 Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal 14.08.2026
CVE-2026-19756 Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal 13.08.2026
CVE-2026-18532 13.08.2026
CVE-2026-19753 Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery 14.08.2026
CVE-2026-3883 13.08.2026
CVE-2026-19752 EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery 14.08.2026
CVE-2026-33818 Enforce maximum recursion depth in encoding/asn1 14.08.2026
CVE-2026-56853 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http 14.08.2026
CVE-2026-56858 Fix Javascript regexp context tracking in html/template 14.08.2026
CVE-2026-56859 Add recursion depth guard during decode in encoding/xml 14.08.2026
CVE-2026-56860 Avoid quadratic complexity in resolvePath in net/url 13.08.2026
CVE-2026-56862 Limit handshake messages we are willing to accept post-handshake in crypto/tls 14.08.2026
CVE-2026-56864 Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb 13.08.2026
CVE-2026-56865 Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog 14.08.2026
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup 13.08.2026
CVE-2026-72840 OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write 13.08.2026
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 13.08.2026
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass 13.08.2026
CVE-2026-72849 Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF 13.08.2026
CVE-2026-72850 Budibase before 3.40.0 Arbitrary File Write via Path Traversal 13.08.2026
CVE-2026-72851 Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook 13.08.2026
CVE-2026-72853 Budibase before 3.40.0 SQL Injection via Oracle connector 13.08.2026
CVE-2026-72855 Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST 13.08.2026
CVE-2026-72856 Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email 13.08.2026
CVE-2026-72857 Budibase before 3.40.0 Credential Exposure via STRING Fields 13.08.2026
CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified 13.08.2026
CVE-2026-73304 Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users 14.08.2026 4.9
CVE-2026-73305 Budibase: Privilege escalation via public role assignment API missing app-level authorization 13.08.2026 8.8
CVE-2026-73408 Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector 13.08.2026 7.6
CVE-2026-73416 jupyterlab: PyPI extension blocklist package-name canonicalization bypass 13.08.2026
CVE-2026-73417 JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) 13.08.2026
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 14.08.2026
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 13.08.2026
CVE-2026-73428 Trix: Stored XSS via HTMLParser attribute injection on paste 13.08.2026 4.6
CVE-2026-73489 Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records 13.08.2026 4.3
CVE-2026-73840 OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) 13.08.2026 5.3
CVE-2026-73841 OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints 13.08.2026 8.8
CVE-2026-73842 OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation 13.08.2026 9
CVE-2026-73843 OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs 13.08.2026 9.6
CVE-2026-19751 EnzoVezzaro mcp-dominican-layer parse-csv tool index.ts axios.get server-side request forgery 13.08.2026
CVE-2026-73039 streama Insecure Direct Object Reference via ViewingStatusController 14.08.2026
CVE-2026-73664 FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module 13.08.2026
CVE-2026-73665 FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection 13.08.2026
CVE-2026-73666 OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete 13.08.2026 8.2
CVE-2026-73667 OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods 13.08.2026 8.8
CVE-2026-19750 Tenda CH/CP/TX3 SSH hard-coded password 13.08.2026
CVE-2026-72776 AgenticSeek Unauthenticated RCE via /query API Endpoint 14.08.2026
CVE-2026-73479 dua-cli Terminal Escape Sequence Injection via Marked Paths 13.08.2026
CVE-2026-73657 Trigger.dev: Cross-tenant payload poisoning via packet write + replay 13.08.2026 4.2
CVE-2026-73658 Trigger.dev: Cross-tenant object store read and write via URL path traversal 13.08.2026 8.2
CVE-2026-73659 Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API 13.08.2026 8.1
CVE-2026-73660 FreePBX: Authenticated TTS AGI Command Injection Through TTS Name 13.08.2026
CVE-2026-73661 FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup 13.08.2026
CVE-2026-73662 Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files 13.08.2026
CVE-2026-73663 FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover 13.08.2026
CVE-2026-73480 gdu Terminal Injection via Unstripped Escape Sequences 14.08.2026
CVE-2026-17075 IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager 13.08.2026 6.5
CVE-2026-17438 IBM i is Affected By An Improper Privilege Management Vulnerability in LDAP [] 13.08.2026 4.4
CVE-2026-17468 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 14.08.2026 5.3
CVE-2026-17473 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 13.08.2026 7.5
CVE-2026-17476 IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime 13.08.2026 4.8
CVE-2026-17481 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 13.08.2026 8.8
CVE-2026-17482 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 13.08.2026 9.8
CVE-2026-17502 IBM i is Affected By Multiple Vulnerabilities in NetServer 14.08.2026 8.6
CVE-2026-17649 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 5.3
CVE-2026-18020 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 5.3
CVE-2026-18068 IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension 13.08.2026 4.3
CVE-2026-18077 IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol 13.08.2026 7.5
CVE-2026-18086 IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension 14.08.2026 4.5
CVE-2026-18101 IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty 13.08.2026 8.8
CVE-2026-18193 IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime 13.08.2026 8.9
CVE-2026-18249 IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime 14.08.2026 8.4
CVE-2026-18509 IBM i is Affected By A Prvilege Escalation Vulnerability [] 14.08.2026 8.2
CVE-2026-18511 IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension 14.08.2026 7.3
CVE-2026-18671 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 6.5
CVE-2026-18715 IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty 14.08.2026 6.5
CVE-2026-18741 Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields 13.08.2026 4.8
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint 13.08.2026 9.1
CVE-2026-19483 The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher 14.08.2026 7.1
CVE-2026-19749 Tenda CH7 RTSP/ONVIF missing authentication 13.08.2026
CVE-2026-17071 IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager 13.08.2026 2.7
CVE-2026-17074 IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM 13.08.2026 3.1
CVE-2026-17076 IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM 13.08.2026 5.3
CVE-2026-17077 IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM 13.08.2026 5.3
CVE-2026-17078 IBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM [] 13.08.2026 5.3
CVE-2026-17088 IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager 13.08.2026 4.3
CVE-2026-17099 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 13.08.2026 7.3
CVE-2026-17101 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 14.08.2026 8.3
CVE-2026-17212 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 5.3
CVE-2026-17216 IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM 13.08.2026 5.3
CVE-2026-17226 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 5.4
CVE-2026-17272 IBM i is Affected By a Denial of Service in HTTP Server [] 13.08.2026 8.2
CVE-2026-8715 Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath 14.08.2026 9.6
CVE-2026-19748 Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy 13.08.2026
CVE-2026-16853 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 6.5
CVE-2026-16859 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 5.3
CVE-2026-16861 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 5.3
CVE-2026-16867 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 8.1
CVE-2026-16868 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 8.1
CVE-2026-16871 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 4.3
CVE-2026-16878 IBM i is Affected By Multiple Vulnerabilities in NetServer 13.08.2026 5.4
CVE-2026-16887 IBM i is Affected By A Denial of Service Vulnerability DST/SST [] 13.08.2026 7.5
CVE-2026-16896 IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service 13.08.2026 7.1
CVE-2026-16898 IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service 13.08.2026 7.8
CVE-2026-16908 IBM i is Affected By Multiple SQL Vulnerabilities [, ] 13.08.2026 8.5
CVE-2026-16961 IBM i is Affected By SQL Injection Vulnerability in Db2 Mirror [] 13.08.2026 7.6
CVE-2026-16967 IBM i is Affected By Multiple SQL Vulnerabilities [, ] 14.08.2026 8.5
CVE-2026-16975 IBM i is Affected By A Remote Code Execution Vulnerability [] 14.08.2026 8.8
CVE-2026-16987 IBM i is Affected By An Improper Validation Vulnerability in PASE [] 14.08.2026 8.8
CVE-2026-17029 IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension 14.08.2026 8.8
CVE-2026-17043 IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager 13.08.2026 3.8
CVE-2026-17045 IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager 13.08.2026 8.1
CVE-2026-17069 IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager 14.08.2026 8.1
CVE-2026-19747 Tenda CH7 ATE Module Kylin HandleCmd command injection 14.08.2026
CVE-2026-73655 Trigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Google Login 13.08.2026 7.4
CVE-2026-73656 Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state 13.08.2026 9.9
CVE-2026-10571 IBM WebSphere Application Server Liberty is affected by a denial of service 13.08.2026 5.7
CVE-2026-13365 IBM Planning Analytics Local is affected by security vulnerabilities 13.08.2026 7.1
CVE-2026-13460 The following vulnerabilities that can affect IBM Storage Scale and the Management GUI are now fixed in 5.2.3.9 or higher and 6.0.1.1 or higher 13.08.2026 7.5
CVE-2026-14525 IBM WebSphere Application Server Liberty is affected by an authenication bypass 13.08.2026 9.4
CVE-2026-14875 IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities 13.08.2026 7.3
CVE-2026-16674 IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server Liberty 13.08.2026 8.8
CVE-2026-16692 IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol 13.08.2026 6.5
CVE-2026-16713 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 13.08.2026 4.3
CVE-2026-16722 IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL [] 13.08.2026 8.8
CVE-2026-16815 IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol 13.08.2026 8.6
CVE-2026-45725 compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal 13.08.2026
CVE-2026-45774 compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal 13.08.2026
CVE-2026-73654 Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS 13.08.2026 8.5
CVE-2026-16929 IBM i is Affected By Multiple Vulnerabilities in Host Servers 13.08.2026 5.3
CVE-2026-16982 IBM i is Affected By Multiple Vulnerabilities in Host Servers 13.08.2026 7.5
CVE-2026-17004 IBM i is Affected By Multiple Vulnerabilities in Host Servers 13.08.2026 7.5
CVE-2026-17199 IBM i is Affected By Multiple Vulnerabilities in Host Servers 13.08.2026 7.5
CVE-2026-17206 IBM i is Affected By Multiple Vulnerabilities in Host Servers 14.08.2026 8.1
CVE-2026-17223 IBM i is Affected By Multiple Vulnerabilities in Host Servers 14.08.2026 8.8
CVE-2026-17229 IBM i is Affected By Multiple Vulnerabilities in Host Servers 13.08.2026 7.5
CVE-2026-18164 Flow Neuroscience FL-100 Use of Hard-coded Credentials 13.08.2026
CVE-2026-18846 IBM i is Affected By Multiple Vulnerabilities in Host Servers 13.08.2026 7.5
CVE-2026-19745 Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service 13.08.2026
CVE-2026-19746 Calix GigaSpire traceroute.cmd denial of service 13.08.2026
CVE-2026-48099 WsgiDAV encoded dot segments can escape filesystem share roots 13.08.2026 7.1
CVE-2026-49089 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-49096 Uncaught Exception in Kibana Cases Leading to Denial of Service 13.08.2026 4.3
CVE-2026-49864 wetty vulnerable to DOM XSS via file-download filename 13.08.2026
CVE-2026-59714 Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) 13.08.2026 7.1
CVE-2026-72629 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models 13.08.2026 7.1
CVE-2026-72630 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation 14.08.2026 7.1
CVE-2026-72631 Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys 14.08.2026 6.5
CVE-2026-72632 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys 13.08.2026 7.1
CVE-2026-72636 Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72638 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72639 Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72640 Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret Disclosure 13.08.2026 6.5
CVE-2026-72642 Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process 14.08.2026 8.8
CVE-2026-72643 Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents 13.08.2026 7.1
CVE-2026-72645 Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72647 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72648 Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure 13.08.2026 6.5
CVE-2026-72650 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure 13.08.2026 4.3
CVE-2026-72651 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72653 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72655 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification 13.08.2026 4.3
CVE-2026-72656 Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72657 Authorization Bypass Through User-Controlled Key in Fleet Server Leading to Information Disclosure 13.08.2026 6.5
CVE-2026-72658 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation 14.08.2026 7.3
CVE-2026-72659 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72660 Uncaught Exception in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72661 Missing Authorization in Kibana Leading to Information Disclosure 13.08.2026 6.5
CVE-2026-72663 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72664 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions 13.08.2026 6.5
CVE-2026-72665 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions 13.08.2026 8.1
CVE-2026-72666 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts 13.08.2026 6.8
CVE-2026-72667 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72669 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering 13.08.2026 7.6
CVE-2026-72670 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials 13.08.2026 7.7
CVE-2026-72671 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments 13.08.2026 4.3
CVE-2026-72672 Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data 13.08.2026 7.7
CVE-2026-72673 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations 13.08.2026 5.4
CVE-2026-72674 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72675 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification 13.08.2026 7.1
CVE-2026-72676 Improper Control of Generation of Code in Fleet Server Leading to Code Injection 13.08.2026 6.5
CVE-2026-72677 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources 13.08.2026 7.3
CVE-2026-72678 Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72679 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72680 Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification 13.08.2026 6.5
CVE-2026-72681 Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure 14.08.2026 6.5
CVE-2026-72683 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72684 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72685 Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service 13.08.2026 4.3
CVE-2026-72686 Uncontrolled Recursion in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-72687 Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service 13.08.2026 6.5
CVE-2026-73530 Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() 14.08.2026
CVE-2026-73531 django-helpdesk < 2.3.3 Stored XSS via HTML Attachments 13.08.2026
CVE-2026-73669 Philips Hue Bridge Pro MQTT broker missing authentication 13.08.2026 6.3
CVE-2026-17197 IBM i is Affected By Multiple Vulnerabilities in Host Servers 14.08.2026 8.1
CVE-2026-17220 IBM i is Affected By Multiple Vulnerabilities in Host Servers 13.08.2026 8.2
CVE-2026-18071 IBM i is Affected By An Improper Management Vulnerability in HTTP Server [] 14.08.2026 7.8
CVE-2026-73038 NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name 14.08.2026
CVE-2026-73481 phpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules 14.08.2026
CVE-2026-73482 phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php 14.08.2026
CVE-2026-72777 Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url 14.08.2026
CVE-2026-73037 Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter 14.08.2026
CVE-2026-73650 SVGO: removeScripts plugin leaves some executable scripts intact 13.08.2026 8.2
CVE-2026-73651 TypeORM: migration:generate template-literal code injection 13.08.2026 5.7
CVE-2026-73652 vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review 13.08.2026
CVE-2026-73653 Vitest: Browser Mode provider commands bypass the file-access permission gate 13.08.2026 9.4
CVE-2026-12908 13.08.2026
CVE-2026-19730 Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives 13.08.2026
CVE-2026-72741 Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access 14.08.2026
CVE-2026-73569 fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits 13.08.2026
CVE-2026-73643 js-yaml: Exponential parsing time in the flow collections leads to denial of service 13.08.2026 7.5
CVE-2026-73644 OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant 13.08.2026 9.6
CVE-2026-73645 OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds. 13.08.2026
CVE-2026-73647 Quasar Framework: Prototype pollution in Quasar extend() utility 13.08.2026 5.6
CVE-2026-73648 rails-html-sanitizer: Possible XSS vulnerability with certain configurations 13.08.2026
CVE-2026-73649 Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) 13.08.2026 9.8
CVE-2019-25765 ASP-CMS SQL Injection via commentList.asp id Parameter 14.08.2026
CVE-2026-18428 SQL Query Validation Bypass in OpenSearch Direct Query 13.08.2026
CVE-2026-73561 Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion 13.08.2026 7.5
CVE-2026-73562 Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter) 13.08.2026 6.5
CVE-2026-73563 Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend` 13.08.2026 4.7
CVE-2026-73564 frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow 13.08.2026
CVE-2026-73565 @hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake 13.08.2026 5.3
CVE-2026-73566 node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection 13.08.2026 7.5
CVE-2026-73567 sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock 13.08.2026 9.1
CVE-2026-73568 py-libp2p: yamux connection DoS via oversized data frame 13.08.2026 7.5
CVE-2024-58374 Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree 13.08.2026
CVE-2026-12236 Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length 13.08.2026 6.5
CVE-2026-67613 CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport 14.08.2026
CVE-2026-67614 CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal 14.08.2026
CVE-2026-24059 Gitea runner registration-token GET endpoint performs a write under a read-only token scope 13.08.2026
CVE-2026-24791 Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes 13.08.2026