| CVE-2026-10032 |
Arbitrary JavaScript Execution via openUrl in @a2ui/web_core |
04.08.2026 |
|
| CVE-2026-18773 |
NousResearch hermes-agent Quick run.py _check_slash_access authorization |
04.08.2026 |
|
| CVE-2026-18801 |
Stored Clickhouse SQL Injection Through Customer Usage Attribution |
04.08.2026 |
|
| CVE-2026-21366 |
Integer Overflow or Wraparound in Data Network Stack & Connectivity |
04.08.2026 |
7.8 |
| CVE-2026-24076 |
Buffer Copy Without Checking Size of Input in Bluetooth HOST |
04.08.2026 |
6.7 |
| CVE-2026-24077 |
Integer Underflow (Wrap or Wraparound) in WLAN Host |
04.08.2026 |
6.5 |
| CVE-2026-24078 |
Exposure of Private Personal Information to an Unauthorized Actor in Data Modem |
04.08.2026 |
6.5 |
| CVE-2026-24079 |
Missing Authentication for Critical Function in Data Modem |
04.08.2026 |
8.1 |
| CVE-2026-24080 |
Buffer Copy Without Checking Size of Input in Biometrics |
04.08.2026 |
7.8 |
| CVE-2026-24083 |
Untrusted Pointer Dereference in Automotive Security |
04.08.2026 |
7.8 |
| CVE-2026-24084 |
Insecure Security Identifier Mechanism in Multi-Mode Call Processor |
04.08.2026 |
7.5 |
| CVE-2026-25288 |
Buffer Over-read in WLAN Firmware |
04.08.2026 |
7.4 |
| CVE-2026-25289 |
Stack-based Buffer Overflow in WLAN Firmware |
04.08.2026 |
9.6 |
| CVE-2026-25292 |
Improper Validation of Syntactic Correctness of Input in Automotive Linux OS |
04.08.2026 |
7.6 |
| CVE-2026-69098 |
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization |
04.08.2026 |
|
| CVE-2026-69100 |
LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution |
04.08.2026 |
|
| CVE-2026-69110 |
OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music |
04.08.2026 |
|
| CVE-2026-69252 |
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization |
04.08.2026 |
|
| CVE-2026-69253 |
Flowise Sandbox Escape to RCE |
04.08.2026 |
|
| CVE-2026-69254 |
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override |
04.08.2026 |
|
| CVE-2026-11368 |
Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer |
04.08.2026 |
7.1 |
| CVE-2026-18401 |
jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of service |
04.08.2026 |
|
| CVE-2026-18650 |
Missing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYS |
04.08.2026 |
8.8 |
| CVE-2026-18766 |
chetans9 core-php-admin-panel customers.php sql injection |
04.08.2026 |
|
| CVE-2026-18770 |
vibesurf-ai VibeSurf Python Validation code code injection |
04.08.2026 |
|
| CVE-2026-61514 |
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 |
04.08.2026 |
|
| CVE-2026-61515 |
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell |
04.08.2026 |
|
| CVE-2026-67195 |
Perspective 5.0.0 RCE via eval() Expression Injection |
04.08.2026 |
|
| CVE-2026-67196 |
Perspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation |
04.08.2026 |
|
| CVE-2026-67198 |
Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher |
04.08.2026 |
|
| CVE-2026-67199 |
Perspective 5.0.0 DoS via Loop Expression Evaluation |
04.08.2026 |
|
| CVE-2026-67200 |
Perspective 5.0.0 Path Traversal via cwd_static_file_handler |
04.08.2026 |
|
| CVE-2026-67618 |
marimo < 0.23.15 API Key Exfiltration via Malicious Notebook PEP-723 Metadata |
04.08.2026 |
|
| CVE-2026-68494 |
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq) |
04.08.2026 |
|
| CVE-2026-69250 |
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration |
04.08.2026 |
|
| CVE-2026-69251 |
Flowise RCE via TypeORM DataSource |
04.08.2026 |
|
| CVE-2026-14337 |
Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role. |
04.08.2026 |
|
| CVE-2026-17070 |
Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS |
04.08.2026 |
8.8 |
| CVE-2026-70367 |
Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loopback-only services |
04.08.2026 |
|
| CVE-2026-70368 |
Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message |
04.08.2026 |
|
| CVE-2026-10709 |
FBX BinaryReadSectionHeader Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK |
04.08.2026 |
7.8 |
| CVE-2026-10710 |
FBX ExtractDrive Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK |
04.08.2026 |
7.8 |
| CVE-2026-18806 |
Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardus-image-writer |
04.08.2026 |
7.1 |
| CVE-2026-18809 |
Information disclosure in Firefox for Android and Firefox Focus for Android |
04.08.2026 |
|
| CVE-2026-70369 |
Koha: SQL Injection in reports/acquisitions_stats.pl |
04.08.2026 |
|
| CVE-2026-70370 |
Koha: SQL Injection in reports/catalogue_stats.pl |
04.08.2026 |
|
| CVE-2026-70371 |
Koha: SQL Injection in reports/issues_avg_stats.pl |
04.08.2026 |
|
| CVE-2026-70372 |
Koha: SQL Injection in reports/bor_issues_top.pl |
04.08.2026 |
|
| CVE-2026-70373 |
Koha: SQL Injection in reports/issues_stats.pl |
04.08.2026 |
|
| CVE-2026-58080 |
|
04.08.2026 |
|
| CVE-2026-60007 |
|
04.08.2026 |
|
| CVE-2026-61387 |
|
04.08.2026 |
|
| CVE-2026-62927 |
|
04.08.2026 |
|
| CVE-2026-63248 |
|
04.08.2026 |
|
| CVE-2026-63252 |
|
04.08.2026 |
|
| CVE-2026-66883 |
Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup |
04.08.2026 |
|
| CVE-2026-66884 |
Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session or no state parameter, defeating CSRF protection |
04.08.2026 |
|
| CVE-2026-10050 |
Digest authentication lossy encoding |
04.08.2026 |
|
| CVE-2026-14175 |
Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
9.8 |
| CVE-2026-14192 |
Stored XSS in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
5.4 |
| CVE-2026-14194 |
Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
6.5 |
| CVE-2026-14202 |
Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
5.3 |
| CVE-2026-14219 |
URL Redirection in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
5.4 |
| CVE-2026-14465 |
Session Fixation in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
6.5 |
| CVE-2026-14804 |
Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
9.1 |
| CVE-2026-14838 |
Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
7.4 |
| CVE-2026-15721 |
Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
9.8 |
| CVE-2026-18772 |
|
04.08.2026 |
5.5 |
| CVE-2026-18753 |
Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) |
04.08.2026 |
9.1 |
| CVE-2026-18754 |
Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) |
04.08.2026 |
9.1 |
| CVE-2026-18755 |
GV-ASManager DLL hijacking vulnerability |
04.08.2026 |
7.3 |
| CVE-2026-18759 |
An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync. |
04.08.2026 |
|
| CVE-2026-67243 |
|
04.08.2026 |
|
| CVE-2026-10526 |
EmbedPress < 4.6.1 - Unauthenticated Blind SSRF |
04.08.2026 |
|
| CVE-2026-11366 |
MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass |
04.08.2026 |
|
| CVE-2026-12698 |
wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment |
04.08.2026 |
|
| CVE-2026-14816 |
The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam |
04.08.2026 |
|
| CVE-2026-14824 |
Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question |
04.08.2026 |
|
| CVE-2026-14848 |
Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process_checkout |
04.08.2026 |
|
| CVE-2026-14872 |
Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter |
04.08.2026 |
|
| CVE-2026-14939 |
Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery via JSON Import |
04.08.2026 |
|
| CVE-2026-15233 |
Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title |
04.08.2026 |
|
| CVE-2026-15958 |
Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX |
04.08.2026 |
|
| CVE-2026-16035 |
miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send |
04.08.2026 |
|
| CVE-2026-16056 |
Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts |
04.08.2026 |
|
| CVE-2026-16068 |
Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset |
04.08.2026 |
|
| CVE-2026-16069 |
Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point |
04.08.2026 |
|
| CVE-2026-16070 |
Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR |
04.08.2026 |
|
| CVE-2026-16293 |
Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL |
04.08.2026 |
|
| CVE-2026-16295 |
Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher |
04.08.2026 |
|
| CVE-2026-16296 |
Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler |
04.08.2026 |
|
| CVE-2026-16536 |
Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id |
04.08.2026 |
|
| CVE-2026-16546 |
Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp |
04.08.2026 |
|
| CVE-2026-16547 |
REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint |
04.08.2026 |
|
| CVE-2026-16548 |
Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint |
04.08.2026 |
|
| CVE-2026-16618 |
ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution |
04.08.2026 |
|
| CVE-2026-16623 |
Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite) |
04.08.2026 |
|
| CVE-2026-64561 |
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available |
04.08.2026 |
|
| CVE-2026-64562 |
KVM: nVMX: Hide shadow VMCS right after VMCLEAR |
04.08.2026 |
|
| CVE-2026-64563 |
rhashtable: clear stale iter->p on table restart |
04.08.2026 |
|
| CVE-2026-64564 |
sctp: don't free the ASCONF's own transport in DEL-IP processing |
04.08.2026 |
|
| CVE-2026-64565 |
Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() |
04.08.2026 |
|
| CVE-2026-16881 |
|
04.08.2026 |
|
| CVE-2026-18569 |
Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens |
04.08.2026 |
|
| CVE-2026-18739 |
Popt-devel: popt-static: off-by-one in poptstuffargs |
04.08.2026 |
|
| CVE-2026-68744 |
Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply |
04.08.2026 |
|
| CVE-2026-14818 |
|
04.08.2026 |
7.2 |
| CVE-2026-18721 |
kalcaddle kodbox SSO API Login apiLogin redirect |
04.08.2026 |
|
| CVE-2026-18722 |
diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization |
04.08.2026 |
|
| CVE-2026-18723 |
diaowen DWSurvey Survey Status up-survey-status.do improper authorization |
04.08.2026 |
|
| CVE-2026-42169 |
Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr width (file-png.c) |
04.08.2026 |
|
| CVE-2026-17614 |
Wildfly-core: path traversal on wildfly domain controller |
04.08.2026 |
|
| CVE-2026-18720 |
kalcaddle kodbox msgWarning Plugin action improper authorization |
04.08.2026 |
|
| CVE-2026-6837 |
|
04.08.2026 |
7.2 |
| CVE-2026-8508 |
|
04.08.2026 |
6.5 |
| CVE-2026-18719 |
cemtan sar2html Search sar2html.py sql injection |
04.08.2026 |
|
| CVE-2026-56845 |
|
04.08.2026 |
|
| CVE-2026-56846 |
|
04.08.2026 |
|
| CVE-2026-58041 |
|
04.08.2026 |
|
| CVE-2026-58042 |
|
04.08.2026 |
|
| CVE-2026-58044 |
|
04.08.2026 |
|
| CVE-2026-58045 |
|
04.08.2026 |
|
| CVE-2026-11835 |
Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Address (TOCTOU) |
04.08.2026 |
|
| CVE-2026-11836 |
Production Debug-Unlock Token Verification Missing Device Binding |
04.08.2026 |
|
| CVE-2026-18686 |
GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection |
04.08.2026 |
|
| CVE-2026-18685 |
GL.iNet GL-MT3000 modem.so glc set_upgrade command injection |
04.08.2026 |
|
| CVE-2026-62870 |
Microsoft Excel Remote Code Execution Vulnerability |
03.08.2026 |
8.8 |
| CVE-2026-65802 |
Microsoft Edge for Android Information Disclosure Vulnerability |
04.08.2026 |
7.4 |
| CVE-2026-65804 |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
03.08.2026 |
6.1 |
| CVE-2026-66310 |
Microsoft Edge for Android Information Disclosure Vulnerability |
04.08.2026 |
7.7 |
| CVE-2026-66311 |
Microsoft Edge (Chromium-based) Tampering Vulnerability |
04.08.2026 |
6.2 |
| CVE-2026-66312 |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
04.08.2026 |
6.5 |
| CVE-2026-66313 |
Microsoft Edge (Chromium-based) Tampering Vulnerability |
04.08.2026 |
6.8 |
| CVE-2026-66314 |
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
03.08.2026 |
6.5 |
| CVE-2026-66315 |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
04.08.2026 |
7.5 |
| CVE-2026-66316 |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
04.08.2026 |
5.4 |
| CVE-2026-66317 |
Microsoft Edge (Chromium-based) Tampering Vulnerability |
04.08.2026 |
5.4 |
| CVE-2026-66318 |
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
04.08.2026 |
8.1 |
| CVE-2026-66321 |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
04.08.2026 |
7.4 |
| CVE-2026-66322 |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
04.08.2026 |
7.1 |
| CVE-2026-66325 |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
04.08.2026 |
6.1 |
| CVE-2026-66326 |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
04.08.2026 |
6.5 |
| CVE-2026-18684 |
GL.iNet GL-MT3000 modem.so glc remove_profile command injection |
03.08.2026 |
|
| CVE-2026-48317 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) |
04.08.2026 |
9.6 |
| CVE-2026-48323 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) |
03.08.2026 |
10 |
| CVE-2026-48326 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
04.08.2026 |
9.9 |
| CVE-2026-48330 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
03.08.2026 |
10 |
| CVE-2026-48331 |
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
04.08.2026 |
10 |
| CVE-2026-48333 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
04.08.2026 |
9.8 |
| CVE-2026-48399 |
Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657) |
03.08.2026 |
7.5 |
| CVE-2026-18667 |
Sensor Proxy Version 1.4.2 Fixes One Vulnerability |
03.08.2026 |
9.6 |
| CVE-2026-67673 |
|
03.08.2026 |
|
| CVE-2026-67978 |
|
03.08.2026 |
|
| CVE-2026-46713 |
Misskey: JSON-LD signature validation + compaction may lead to improper activity handling |
03.08.2026 |
|
| CVE-2026-46714 |
Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation |
03.08.2026 |
|
| CVE-2026-47746 |
Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacks |
04.08.2026 |
|
| CVE-2026-67616 |
Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint |
03.08.2026 |
|
| CVE-2026-67617 |
Microweber CMS 2.0.20 Stored XSS via tag_names Parameter |
04.08.2026 |
|
| CVE-2026-67969 |
|
03.08.2026 |
|
| CVE-2026-67970 |
|
03.08.2026 |
|
| CVE-2026-67973 |
|
03.08.2026 |
|
| CVE-2026-67974 |
|
03.08.2026 |
|
| CVE-2026-67975 |
|
03.08.2026 |
|
| CVE-2026-67977 |
|
03.08.2026 |
|
| CVE-2026-10849 |
Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body |
03.08.2026 |
8.2 |
| CVE-2026-18682 |
OpenAkita File Upload API upload cross site scripting |
04.08.2026 |
|
| CVE-2026-46712 |
Misskey: Lack of proper permission checks in Direct Messaging feature |
03.08.2026 |
|
| CVE-2026-48115 |
Misskey: Improper Authorization in the Announcements API |
03.08.2026 |
|
| CVE-2026-69247 |
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing |
04.08.2026 |
|
| CVE-2026-69248 |
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees |
04.08.2026 |
|
| CVE-2026-69249 |
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building |
04.08.2026 |
|
| CVE-2026-18647 |
jina-ai reader Crawler/Puppeteer crawler.ts isValidTLD server-side request forgery |
04.08.2026 |
|
| CVE-2026-18648 |
Blix Email Blue Mail Calendar App react-native-receive-sharing-intent FileDirectory.getFileFromUri path traversal |
03.08.2026 |
|
| CVE-2026-18738 |
Shlink CSV Formula Injection via Visit Export CLI |
04.08.2026 |
|
| CVE-2026-41447 |
FirmaCheck < 1.3.16 DLL Hijacking via Unvalidated OpenSSL Configuration Path |
04.08.2026 |
|
| CVE-2026-48061 |
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header |
04.08.2026 |
5.9 |
| CVE-2026-48063 |
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload |
04.08.2026 |
|
| CVE-2026-48113 |
Chisel: ACL Bypass via Post-Handshake SSH Channel ExtraData Injection |
03.08.2026 |
|
| CVE-2026-51190 |
|
03.08.2026 |
|
| CVE-2026-51775 |
|
03.08.2026 |
|
| CVE-2026-52102 |
|
03.08.2026 |
|
| CVE-2026-52520 |
|
03.08.2026 |
|
| CVE-2026-52521 |
|
03.08.2026 |
|
| CVE-2026-67972 |
|
03.08.2026 |
|
| CVE-2026-67976 |
|
03.08.2026 |
|
| CVE-2026-69243 |
AIOHTTP: HTTP request smuggling via WebSocket upgrade |
03.08.2026 |
|
| CVE-2026-69244 |
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) |
04.08.2026 |
|
| CVE-2026-69245 |
Guzzle: Noncanonical cookie domain keeps subdomain scope |
04.08.2026 |
6.5 |
| CVE-2026-69246 |
Guzzle: Noncanonical host can bypass host-based checks |
04.08.2026 |
7.2 |
| CVE-2026-18645 |
danpros HTMLy Admin Content Endpoint admin.php add_content path traversal |
03.08.2026 |
|
| CVE-2026-18646 |
danpros HTMLy Author Name htmly.php path traversal |
04.08.2026 |
|
| CVE-2026-18733 |
Prompt injection bypasses shell tool consent gate in Strands Agents Tools |
03.08.2026 |
8.8 |
| CVE-2026-18736 |
Shlink Server-Side Request Forgery via Short URL Title Auto-Resolution |
04.08.2026 |
|
| CVE-2026-18737 |
Shlink Blind SQL Injection via tags/stats orderBy Parameter |
03.08.2026 |
|
| CVE-2026-49131 |
OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field |
04.08.2026 |
|
| CVE-2026-49132 |
OPNsense < 26.1.9 Stored XSS via Certificate Description Field |
03.08.2026 |
|
| CVE-2026-66065 |
Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211) |
03.08.2026 |
|
| CVE-2026-69240 |
Sequelize: SQL Injection (Oracle DB) |
04.08.2026 |
9.8 |
| CVE-2026-18644 |
danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal |
03.08.2026 |
|
| CVE-2026-47211 |
Ouroboros: Remote Code Execution via Untrusted Project-Directory .env |
03.08.2026 |
|
| CVE-2026-68980 |
Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion |
03.08.2026 |
|
| CVE-2026-68981 |
Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests |
03.08.2026 |
|
| CVE-2026-69198 |
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks |
03.08.2026 |
|