| CVE-2026-66012 |
SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP |
25.07.2026 |
10 |
| CVE-2026-66013 |
OpenRemote before 1.26.2 Authentication Bypass via Console Registration |
25.07.2026 |
9.3 |
| CVE-2026-61884 |
Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel |
24.07.2026 |
9.3 |
| CVE-2026-62835 |
Azure Portal Information Disclosure Vulnerability |
25.07.2026 |
9.3 |
| CVE-2026-48021 |
epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau |
25.07.2026 |
9.1 |
| CVE-2026-56163 |
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
25.07.2026 |
10 |
| CVE-2026-57106 |
Data Quality Elevation of Privilege Vulnerability |
24.07.2026 |
10 |
| CVE-2026-58630 |
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability |
25.07.2026 |
10 |
| CVE-2026-12503 |
Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter |
24.07.2026 |
9.2 |
| CVE-2026-24727 |
SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type |
24.07.2026 |
9.3 |
| CVE-2026-15704 |
CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components |
24.07.2026 |
9.8 |
| CVE-2026-50517 |
Microsoft M365 Copilot Remote Code Execution Vulnerability |
25.07.2026 |
9.9 |
| CVE-2026-54120 |
Microsoft Surface Remote Code Execution Vulnerability |
25.07.2026 |
9.9 |
| CVE-2026-56160 |
Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability |
25.07.2026 |
9.1 |
| CVE-2026-56165 |
Microsoft Account Remote Code Execution Vulnerability |
25.07.2026 |
9.8 |
| CVE-2026-56191 |
Microsoft Exchange Online Tampering Vulnerability |
25.07.2026 |
10 |
| CVE-2026-58275 |
Azure DNS Elevation of Privilege Vulnerability |
25.07.2026 |
10 |
| CVE-2026-62825 |
Azure Key Vault Elevation of Privilege Vulnerability |
25.07.2026 |
10 |
| CVE-2026-28698 |
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs |
24.07.2026 |
9.2 |
| CVE-2026-42933 |
Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs |
24.07.2026 |
10 |
| CVE-2024-58353 |
Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
24.07.2026 |
9.3 |
| CVE-2024-58355 |
Cal.com through 4.7.15 Cross-Site Scripting via booking questions |
24.07.2026 |
9.3 |
| CVE-2025-71389 |
Cal.com before 5.9.9 Remote Code Execution via RSC |
24.07.2026 |
10 |
| CVE-2026-63732 |
9router before 0.4.60 Remote Code Execution via default password |
23.07.2026 |
9.4 |
| CVE-2026-49035 |
Stack-based Buffer Overflow in MZ Automation libIEC61850 |
24.07.2026 |
9.2 |
| CVE-2026-15981 |
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter |
24.07.2026 |
9.8 |
| CVE-2026-47724 |
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation |
23.07.2026 |
9.9 |
| CVE-2026-47669 |
DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE |
24.07.2026 |
9.3 |
| CVE-2026-47670 |
DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection |
24.07.2026 |
9.4 |
| CVE-2026-63359 |
Appriss Insights VINE SQLI |
23.07.2026 |
9.3 |
| CVE-2026-47668 |
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner |
24.07.2026 |
10 |
| CVE-2026-6516 |
Remote Code Execution |
24.07.2026 |
10 |
| CVE-2026-47752 |
Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution |
23.07.2026 |
9.9 |
| CVE-2026-65700 |
h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API |
23.07.2026 |
9.3 |
| CVE-2026-65701 |
SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route |
23.07.2026 |
9.3 |
| CVE-2026-65760 |
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 |
24.07.2026 |
9.2 |
| CVE-2026-65761 |
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 |
24.07.2026 |
9.3 |
| CVE-2026-65687 |
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing |
24.07.2026 |
9.3 |
| CVE-2026-65688 |
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing |
24.07.2026 |
9.3 |
| CVE-2026-65689 |
Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download |
24.07.2026 |
9.3 |
| CVE-2026-65907 |
|
24.07.2026 |
9.1 |
| CVE-2026-64812 |
|
24.07.2026 |
10 |
| CVE-2026-64813 |
|
24.07.2026 |
10 |
| CVE-2026-65605 |
SiYuan before v3.7.2 Stored XSS to RCE via Attribute View |
24.07.2026 |
9.4 |
| CVE-2026-65606 |
SiYuan before v3.7.2 Cross-Site Scripting to RCE |
24.07.2026 |
9.4 |
| CVE-2026-27064 |
WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability |
23.07.2026 |
9.1 |
| CVE-2026-57784 |
WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
9.6 |
| CVE-2026-59514 |
WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-59525 |
WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-59526 |
WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-59540 |
WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability |
23.07.2026 |
9.8 |
| CVE-2026-59543 |
WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability |
23.07.2026 |
9.9 |
| CVE-2026-59544 |
WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability |
23.07.2026 |
9.8 |
| CVE-2026-59555 |
WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability |
23.07.2026 |
10 |
| CVE-2026-61948 |
WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-61949 |
WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-61950 |
WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-61951 |
WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability |
23.07.2026 |
9.8 |
| CVE-2026-65455 |
WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability |
23.07.2026 |
9.1 |
| CVE-2026-65461 |
WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability |
23.07.2026 |
9.1 |
| CVE-2026-65471 |
WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
9.6 |
| CVE-2026-15015 |
MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint |
23.07.2026 |
9.8 |
| CVE-2026-14282 |
GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field |
23.07.2026 |
9.8 |
| CVE-2026-15011 |
Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter |
23.07.2026 |
9.8 |
| CVE-2026-16723 |
Remote Code Execution in fastjson 1.2.68–1.2.83 |
23.07.2026 |
9 |
| CVE-2026-60366 |
|
23.07.2026 |
10 |
| CVE-2026-60367 |
|
23.07.2026 |
9.8 |
| CVE-2026-60369 |
|
23.07.2026 |
9.9 |
| CVE-2026-60372 |
|
23.07.2026 |
9.8 |
| CVE-2026-13072 |
MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption |
24.07.2026 |
9.2 |
| CVE-2026-64829 |
Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow |
24.07.2026 |
9.1 |
| CVE-2026-40712 |
|
24.07.2026 |
9.1 |
| CVE-2026-46738 |
|
24.07.2026 |
9.1 |
| CVE-2026-16606 |
Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris |
22.07.2026 |
9.3 |
| CVE-2026-2395 |
SQLi in Xpoda Türkiye Informatics Technology's No Code Platform |
22.07.2026 |
9.8 |
| CVE-2026-63048 |
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 |
23.07.2026 |
9.4 |
| CVE-2026-47731 |
NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker) |
22.07.2026 |
9.1 |
| CVE-2026-60328 |
|
23.07.2026 |
9.8 |
| CVE-2026-60329 |
|
23.07.2026 |
9.8 |
| CVE-2026-60333 |
|
24.07.2026 |
9.9 |
| CVE-2026-60355 |
|
24.07.2026 |
9.8 |
| CVE-2026-60358 |
|
24.07.2026 |
10 |
| CVE-2026-60360 |
|
24.07.2026 |
10 |
| CVE-2026-60361 |
|
24.07.2026 |
9.9 |
| CVE-2026-60362 |
|
24.07.2026 |
9.8 |
| CVE-2026-60363 |
|
24.07.2026 |
9.8 |
| CVE-2026-60364 |
|
24.07.2026 |
9.8 |
| CVE-2026-60365 |
|
24.07.2026 |
10 |
| CVE-2026-60374 |
|
24.07.2026 |
9.8 |
| CVE-2026-60375 |
|
24.07.2026 |
9.8 |
| CVE-2026-60376 |
|
24.07.2026 |
9.8 |
| CVE-2026-60377 |
|
24.07.2026 |
9.9 |
| CVE-2026-60378 |
|
24.07.2026 |
9.8 |
| CVE-2026-60379 |
|
24.07.2026 |
10 |
| CVE-2026-60380 |
|
24.07.2026 |
9.8 |
| CVE-2026-60381 |
|
24.07.2026 |
9.9 |
| CVE-2026-60384 |
|
24.07.2026 |
9.8 |
| CVE-2026-60385 |
|
24.07.2026 |
9.8 |
| CVE-2026-60386 |
|
24.07.2026 |
9.8 |
| CVE-2026-60387 |
|
24.07.2026 |
9.8 |
| CVE-2026-60388 |
|
24.07.2026 |
9.8 |
| CVE-2026-60389 |
|
24.07.2026 |
10 |
| CVE-2026-60402 |
|
24.07.2026 |
9.9 |
| CVE-2026-60422 |
|
24.07.2026 |
9.9 |
| CVE-2026-60424 |
|
24.07.2026 |
9 |
| CVE-2026-60429 |
|
24.07.2026 |
9.9 |
| CVE-2026-60435 |
|
24.07.2026 |
9.8 |
| CVE-2026-60438 |
|
24.07.2026 |
9.1 |
| CVE-2026-60441 |
|
24.07.2026 |
9.8 |
| CVE-2026-60442 |
|
24.07.2026 |
9.8 |
| CVE-2026-60445 |
|
24.07.2026 |
9.9 |
| CVE-2026-60446 |
|
24.07.2026 |
9.8 |
| CVE-2026-60447 |
|
24.07.2026 |
9.9 |
| CVE-2026-60456 |
|
24.07.2026 |
9.9 |
| CVE-2026-60457 |
|
24.07.2026 |
9.9 |
| CVE-2026-60458 |
|
24.07.2026 |
9.9 |
| CVE-2026-60459 |
|
24.07.2026 |
9.9 |
| CVE-2026-60460 |
|
24.07.2026 |
9.8 |
| CVE-2026-60461 |
|
24.07.2026 |
9.9 |
| CVE-2026-60463 |
|
24.07.2026 |
9.8 |
| CVE-2026-60524 |
|
24.07.2026 |
9.9 |
| CVE-2026-60531 |
|
24.07.2026 |
9.9 |
| CVE-2026-60532 |
|
24.07.2026 |
9.8 |
| CVE-2026-60535 |
|
24.07.2026 |
9.8 |
| CVE-2026-60537 |
|
24.07.2026 |
9.9 |
| CVE-2026-60538 |
|
24.07.2026 |
9.8 |
| CVE-2026-60540 |
|
21.07.2026 |
9.6 |
| CVE-2026-60541 |
|
21.07.2026 |
9.8 |
| CVE-2026-60542 |
|
21.07.2026 |
9.9 |
| CVE-2026-60547 |
|
21.07.2026 |
9.9 |
| CVE-2026-60551 |
|
21.07.2026 |
9.8 |
| CVE-2026-60552 |
|
21.07.2026 |
9.9 |
| CVE-2026-60555 |
|
21.07.2026 |
9.8 |
| CVE-2026-60561 |
|
21.07.2026 |
9.9 |
| CVE-2026-60562 |
|
21.07.2026 |
9.9 |
| CVE-2026-60564 |
|
21.07.2026 |
9.6 |
| CVE-2026-60565 |
|
21.07.2026 |
9.9 |
| CVE-2026-60566 |
|
21.07.2026 |
9.8 |
| CVE-2026-60567 |
|
21.07.2026 |
9.1 |
| CVE-2026-60568 |
|
21.07.2026 |
9.9 |
| CVE-2026-60606 |
|
21.07.2026 |
9.1 |
| CVE-2026-60627 |
|
25.07.2026 |
9.9 |
| CVE-2026-60631 |
|
21.07.2026 |
9.3 |
| CVE-2026-60632 |
|
21.07.2026 |
9.3 |
| CVE-2026-60644 |
|
21.07.2026 |
10 |
| CVE-2026-60649 |
|
21.07.2026 |
9.1 |
| CVE-2026-60663 |
|
24.07.2026 |
9.9 |
| CVE-2026-60711 |
|
25.07.2026 |
9.9 |
| CVE-2026-60719 |
|
24.07.2026 |
9.9 |
| CVE-2026-60773 |
|
24.07.2026 |
9.6 |
| CVE-2026-60880 |
|
24.07.2026 |
9.8 |
| CVE-2026-60999 |
|
24.07.2026 |
9.8 |
| CVE-2026-61041 |
|
24.07.2026 |
9.9 |
| CVE-2026-61059 |
|
24.07.2026 |
9.1 |
| CVE-2026-61065 |
|
24.07.2026 |
9.8 |
| CVE-2026-61072 |
|
24.07.2026 |
9.9 |
| CVE-2026-61076 |
|
24.07.2026 |
9.9 |
| CVE-2026-61097 |
|
23.07.2026 |
9.6 |
| CVE-2026-61100 |
|
23.07.2026 |
9.8 |
| CVE-2026-61129 |
|
23.07.2026 |
9.8 |
| CVE-2026-61130 |
|
23.07.2026 |
9.1 |
| CVE-2026-61131 |
|
23.07.2026 |
9.8 |
| CVE-2026-61140 |
|
23.07.2026 |
9.8 |
| CVE-2026-61145 |
|
23.07.2026 |
9.8 |
| CVE-2026-61146 |
|
23.07.2026 |
9.9 |
| CVE-2026-61153 |
|
23.07.2026 |
9.1 |
| CVE-2026-61154 |
|
23.07.2026 |
9.8 |
| CVE-2026-61155 |
|
23.07.2026 |
9.1 |
| CVE-2026-61156 |
|
23.07.2026 |
9.1 |
| CVE-2026-61161 |
|
23.07.2026 |
9.8 |
| CVE-2026-61167 |
|
23.07.2026 |
9.8 |
| CVE-2026-61171 |
|
23.07.2026 |
9.1 |
| CVE-2026-61174 |
|
23.07.2026 |
9 |
| CVE-2026-61175 |
|
23.07.2026 |
9.3 |
| CVE-2026-61178 |
|
23.07.2026 |
9.8 |
| CVE-2026-61183 |
|
23.07.2026 |
9.8 |
| CVE-2026-61184 |
|
23.07.2026 |
9.1 |
| CVE-2026-61186 |
|
23.07.2026 |
9.4 |
| CVE-2026-61196 |
|
22.07.2026 |
9.8 |
| CVE-2026-61197 |
|
22.07.2026 |
9.1 |
| CVE-2026-61201 |
|
22.07.2026 |
9 |
| CVE-2026-61203 |
|
22.07.2026 |
9.4 |
| CVE-2026-61204 |
|
22.07.2026 |
9 |
| CVE-2026-61207 |
|
22.07.2026 |
9.3 |
| CVE-2026-61209 |
|
22.07.2026 |
9.9 |
| CVE-2026-61211 |
|
22.07.2026 |
9.9 |
| CVE-2026-61223 |
|
22.07.2026 |
9 |
| CVE-2026-61233 |
|
22.07.2026 |
9.8 |
| CVE-2026-61235 |
|
22.07.2026 |
9.1 |
| CVE-2026-61237 |
|
22.07.2026 |
9.9 |
| CVE-2026-61238 |
|
22.07.2026 |
9.1 |
| CVE-2026-61239 |
|
22.07.2026 |
9.9 |
| CVE-2026-61242 |
|
22.07.2026 |
9.9 |
| CVE-2026-61244 |
|
22.07.2026 |
9.1 |
| CVE-2026-61245 |
|
22.07.2026 |
9.8 |
| CVE-2026-62546 |
|
22.07.2026 |
9.1 |
| CVE-2026-62549 |
|
22.07.2026 |
9.6 |
| CVE-2026-65318 |
Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader |
22.07.2026 |
9.2 |
| CVE-2026-35290 |
|
23.07.2026 |
9.8 |
| CVE-2026-46876 |
|
23.07.2026 |
9.8 |
| CVE-2026-46924 |
|
23.07.2026 |
9.8 |
| CVE-2026-46982 |
|
23.07.2026 |
9.8 |
| CVE-2026-46983 |
|
23.07.2026 |
9.8 |
| CVE-2026-46989 |
|
23.07.2026 |
9.1 |
| CVE-2026-46994 |
|
23.07.2026 |
9.8 |
| CVE-2026-47036 |
|
25.07.2026 |
9.8 |
| CVE-2026-47040 |
|
23.07.2026 |
9.1 |
| CVE-2026-47056 |
|
23.07.2026 |
10 |
| CVE-2026-60168 |
|
23.07.2026 |
9.1 |
| CVE-2026-60173 |
|
23.07.2026 |
9.8 |
| CVE-2026-60197 |
|
23.07.2026 |
9.8 |
| CVE-2026-60198 |
|
23.07.2026 |
9.8 |
| CVE-2026-60199 |
|
23.07.2026 |
9.8 |
| CVE-2026-60200 |
|
23.07.2026 |
9.8 |
| CVE-2026-60202 |
|
25.07.2026 |
9.8 |
| CVE-2026-60204 |
|
25.07.2026 |
9.8 |
| CVE-2026-60205 |
|
25.07.2026 |
9.8 |
| CVE-2026-60206 |
|
25.07.2026 |
9.9 |
| CVE-2026-60208 |
|
25.07.2026 |
9.1 |
| CVE-2026-60209 |
|
23.07.2026 |
9.8 |
| CVE-2026-60210 |
|
23.07.2026 |
9.8 |
| CVE-2026-60212 |
|
23.07.2026 |
9.8 |
| CVE-2026-60215 |
|
23.07.2026 |
9.8 |
| CVE-2026-60216 |
|
23.07.2026 |
9.8 |
| CVE-2026-60217 |
|
23.07.2026 |
10 |
| CVE-2026-60219 |
|
23.07.2026 |
9.8 |
| CVE-2026-60220 |
|
23.07.2026 |
9.3 |
| CVE-2026-60221 |
|
23.07.2026 |
9.8 |
| CVE-2026-60224 |
|
23.07.2026 |
9.8 |
| CVE-2026-60225 |
|
23.07.2026 |
9.8 |
| CVE-2026-60226 |
|
23.07.2026 |
9.8 |
| CVE-2026-60227 |
|
23.07.2026 |
9.8 |
| CVE-2026-60228 |
|
23.07.2026 |
9.8 |
| CVE-2026-60229 |
|
23.07.2026 |
9.8 |
| CVE-2026-60230 |
|
23.07.2026 |
9.8 |
| CVE-2026-60232 |
|
23.07.2026 |
9.8 |
| CVE-2026-60234 |
|
23.07.2026 |
9.8 |
| CVE-2026-60236 |
|
23.07.2026 |
9.8 |
| CVE-2026-60239 |
|
23.07.2026 |
9.6 |
| CVE-2026-60240 |
|
23.07.2026 |
9.8 |
| CVE-2026-60241 |
|
23.07.2026 |
9.8 |
| CVE-2026-60242 |
|
23.07.2026 |
9.8 |
| CVE-2026-60244 |
|
23.07.2026 |
9.8 |
| CVE-2026-60246 |
|
23.07.2026 |
9.8 |
| CVE-2026-60247 |
|
23.07.2026 |
9.8 |
| CVE-2026-60248 |
|
23.07.2026 |
9.3 |
| CVE-2026-60249 |
|
23.07.2026 |
9 |
| CVE-2026-60250 |
|
23.07.2026 |
9.8 |
| CVE-2026-60251 |
|
23.07.2026 |
9.8 |
| CVE-2026-60253 |
|
23.07.2026 |
9.8 |
| CVE-2026-60254 |
|
23.07.2026 |
9.8 |
| CVE-2026-60256 |
|
23.07.2026 |
9.8 |
| CVE-2026-60257 |
|
23.07.2026 |
9.8 |
| CVE-2026-60258 |
|
23.07.2026 |
9.8 |
| CVE-2026-60259 |
|
23.07.2026 |
9.8 |
| CVE-2026-60262 |
|
23.07.2026 |
9.8 |
| CVE-2026-60264 |
|
23.07.2026 |
9.8 |
| CVE-2026-60267 |
|
23.07.2026 |
9.1 |
| CVE-2026-60269 |
|
24.07.2026 |
9.8 |
| CVE-2026-60272 |
|
23.07.2026 |
9.8 |
| CVE-2026-60274 |
|
23.07.2026 |
9.8 |
| CVE-2026-60275 |
|
23.07.2026 |
9.8 |
| CVE-2026-60276 |
|
24.07.2026 |
9.8 |
| CVE-2026-60278 |
|
23.07.2026 |
9.8 |
| CVE-2026-60279 |
|
24.07.2026 |
9.8 |
| CVE-2026-60280 |
|
23.07.2026 |
9.8 |
| CVE-2026-60285 |
|
23.07.2026 |
9.8 |
| CVE-2026-60286 |
|
23.07.2026 |
9.8 |
| CVE-2026-60287 |
|
23.07.2026 |
9.8 |
| CVE-2026-60288 |
|
23.07.2026 |
9.8 |
| CVE-2026-60289 |
|
23.07.2026 |
9.8 |
| CVE-2026-60290 |
|
23.07.2026 |
9.8 |
| CVE-2026-60291 |
|
25.07.2026 |
9.8 |
| CVE-2026-60292 |
|
25.07.2026 |
9.8 |
| CVE-2026-60294 |
|
25.07.2026 |
9.8 |
| CVE-2026-60296 |
|
21.07.2026 |
9.8 |
| CVE-2026-60297 |
|
23.07.2026 |
9.8 |
| CVE-2026-60298 |
|
23.07.2026 |
9.8 |
| CVE-2026-60299 |
|
23.07.2026 |
9.8 |
| CVE-2026-60300 |
|
23.07.2026 |
9.8 |
| CVE-2026-60302 |
|
23.07.2026 |
9.8 |
| CVE-2026-60306 |
|
23.07.2026 |
9.8 |
| CVE-2026-60308 |
|
23.07.2026 |
9.8 |
| CVE-2026-60326 |
|
23.07.2026 |
9.1 |
| CVE-2026-65317 |
Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass |
23.07.2026 |
9.2 |
| CVE-2026-8984 |
Unauthenticated RCE |
22.07.2026 |
10 |
| CVE-2026-8985 |
Unauthenticated Command Injection |
22.07.2026 |
10 |
| CVE-2026-8986 |
Command Injection via Malicious OCPP Server |
22.07.2026 |
9.5 |
| CVE-2026-8987 |
Authenticated Heap Overflow |
22.07.2026 |
9.4 |
| CVE-2026-47708 |
MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper |
22.07.2026 |
9.3 |
| CVE-2026-65057 |
Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck |
22.07.2026 |
9.2 |
| CVE-2026-8982 |
Hard-coded / Backdoor Accounts |
22.07.2026 |
10 |
| CVE-2026-8983 |
Backdoor Authentication Token |
22.07.2026 |
10 |
| CVE-2026-64878 |
Command Injection |
24.07.2026 |
9.4 |
| CVE-2026-64879 |
Command Injection |
24.07.2026 |
9.4 |
| CVE-2016-20096 |
Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp |
22.07.2026 |
9.3 |
| CVE-2026-64877 |
|
24.07.2026 |
9.4 |
| CVE-2026-47413 |
praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members |
22.07.2026 |
9.6 |
| CVE-2026-47416 |
praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id} |
22.07.2026 |
9.6 |
| CVE-2026-47407 |
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation |
22.07.2026 |
9.4 |
| CVE-2026-47410 |
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset |
22.07.2026 |
9.8 |
| CVE-2026-47391 |
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution |
23.07.2026 |
9.8 |
| CVE-2026-47392 |
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) |
21.07.2026 |
9.9 |
| CVE-2026-47393 |
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
22.07.2026 |
9.8 |
| CVE-2026-47396 |
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset |
22.07.2026 |
9.8 |
| CVE-2026-64824 |
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore |
21.07.2026 |
9.3 |
| CVE-2026-64825 |
Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload |
21.07.2026 |
9 |
| CVE-2026-65048 |
Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index |
22.07.2026 |
9.3 |
| CVE-2026-65008 |
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData |
22.07.2026 |
9.3 |
| CVE-2026-1617 |
SQLi in Turkmesh's Turkhotspot 5651 Loglama |
21.07.2026 |
9.8 |
| CVE-2026-13439 |
Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint |
21.07.2026 |
9.8 |
| CVE-2026-64625 |
AVideo before 29.0 OS Command Injection via execAsync |
23.07.2026 |
9.3 |
| CVE-2026-13380 |
VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses |
21.07.2026 |
9 |
| CVE-2026-53595 |
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL |
21.07.2026 |
9.4 |
| CVE-2026-16337 |
|
21.07.2026 |
9.4 |
| CVE-2026-44231 |
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint |
21.07.2026 |
9.1 |
| CVE-2026-63766 |
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py |
21.07.2026 |
9.3 |
| CVE-2026-63767 |
ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ |
21.07.2026 |
9.3 |
| CVE-2026-61424 |
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 |
23.07.2026 |
10 |
| CVE-2026-61425 |
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 |
23.07.2026 |
9.4 |
| CVE-2026-61900 |
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 |
23.07.2026 |
10 |
| CVE-2026-60032 |
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 |
23.07.2026 |
9.4 |
| CVE-2026-60034 |
Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 |
23.07.2026 |
9.4 |
| CVE-2026-39878 |
Chamilo stored XSS via user registration leads to admin account takeover |
20.07.2026 |
9.3 |
| CVE-2026-35048 |
Piwigo RCE via PHP Code Injection into Config File in Installer |
20.07.2026 |
9.8 |
| CVE-2026-41252 |
xrdp: lib_palette_update Heap Buffer Overflow & RCE |
23.07.2026 |
9.8 |
| CVE-2026-54051 |
Network-AI has an an OS Command Injection issue |
21.07.2026 |
9.9 |
| CVE-2026-35198 |
HeyForm vulnerable to stored XSS via form field titles |
20.07.2026 |
9 |
| CVE-2026-46428 |
lettre has TLS hostname verification disabled when using Boring TLS backend |
21.07.2026 |
9.1 |
| CVE-2026-51027 |
|
20.07.2026 |
9.9 |
| CVE-2026-46412 |
Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm |
20.07.2026 |
10 |
| CVE-2026-12701 |
Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport |
22.07.2026 |
9 |
| CVE-2026-57309 |
Blind SQL Injection in Windu CMS |
20.07.2026 |
9.3 |
| CVE-2026-63756 |
SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition |
21.07.2026 |
9.2 |
| CVE-2026-64620 |
FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common |
21.07.2026 |
9.3 |
| CVE-2026-64621 |
FreeRDP before 3.28.0 Double-Free via selectedmonitors |
23.07.2026 |
9.3 |
| CVE-2026-64622 |
Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox |
21.07.2026 |
9.3 |
| CVE-2026-16242 |
Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates |
24.07.2026 |
9.4 |
| CVE-2026-44359 |
Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow |
24.07.2026 |
10 |