CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-73056 SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token 16.08.2026 9.3
CVE-2026-73061 Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor 16.08.2026 9.3
CVE-2026-74790 Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache 16.08.2026 9.3
CVE-2026-74791 Scriban before 7.0.0 Authorization Bypass via Stale Include Cache 16.08.2026 9.2
CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 16.08.2026 9.3
CVE-2024-13784 Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection 16.08.2026 9.8
CVE-2026-18316 Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action 16.08.2026 9.1
CVE-2026-14524 ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters 16.08.2026 9.1
CVE-2026-16098 ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override 16.08.2026 9.8
CVE-2026-18432 Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter 16.08.2026 9.8
CVE-2026-19924 Tenda AC10 httpd R7WebsSecurityHandler improper authentication 16.08.2026 9.3
CVE-2026-73041 SiYuan before v3.7.4 Remote Code Execution via PDF Annotations 15.08.2026 9.4
CVE-2026-73042 SiYuan before v3.7.4 Remote Code Execution via Menu Metadata 15.08.2026 9.4
CVE-2026-73043 SiYuan before v3.7.4 Remote Code Execution via Template Calculation 15.08.2026 9.4
CVE-2026-73044 SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width 15.08.2026 9.4
CVE-2026-73046 SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth 15.08.2026 9.3
CVE-2026-73050 SiYuan before v3.7.4 Stored XSS via select option color 15.08.2026 9.4
CVE-2026-73052 SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names 15.08.2026 9.4
CVE-2026-73053 SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji 15.08.2026 9.4
CVE-2026-73055 Shescape before 2.1.15 Home Directory Disclosure via BusyBox 15.08.2026 9.3
CVE-2026-74764 Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora 15.08.2026 10
CVE-2026-18855 Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter 15.08.2026 9.1
CVE-2026-19598 Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router 15.08.2026 9.8
CVE-2026-19901 LB-LINK X-PRO easycwmp hard-coded credentials 15.08.2026 9.2
CVE-2026-19900 LB-LINK X-PRO shadow hard-coded credentials 15.08.2026 9.2
CVE-2026-16142 TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter 15.08.2026 9.8
CVE-2026-15826 User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter 15.08.2026 9.8
CVE-2026-14484 RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters 15.08.2026 9.1
CVE-2026-15303 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter 15.08.2026 9.8
CVE-2026-15341 User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters 15.08.2026 9.8
CVE-2026-73683 Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay 14.08.2026 9.2
CVE-2026-67365 Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 14.08.2026 9.2
CVE-2026-17181 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.3
CVE-2026-17182 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.8
CVE-2026-17184 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.8
CVE-2026-17186 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.9
CVE-2026-50027 mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete 14.08.2026 9.8
CVE-2026-73678 MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec() 14.08.2026 10
CVE-2026-19188 Haiwell IoT Cloud HMI Gateway OS Command Injection 14.08.2026 10
CVE-2026-49457 QUIC has Broken TLS verification 14.08.2026 9.1
CVE-2026-19681 Command Injection 15.08.2026 9.4
CVE-2026-19682 Command Injection 15.08.2026 9.4
CVE-2026-48528 Metacat has an unauthenticated SQL injection vulnerability 14.08.2026 9.8
CVE-2026-73849 emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. 14.08.2026 9.8
CVE-2026-19626 Remote Code Execution 15.08.2026 9.4
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding 14.08.2026 9.3
CVE-2026-72810 SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket 14.08.2026 9.2
CVE-2026-72811 SiYuan before v3.7.4 SQL Injection via backlink search 14.08.2026 9.9
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa 14.08.2026 9.3
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController 14.08.2026 9.3
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey 14.08.2026 9.3
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController 14.08.2026 9.3
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass 14.08.2026 9.3
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass 14.08.2026 9.2
CVE-2026-12949 Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter 14.08.2026 9.8
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup 14.08.2026 9.3
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 14.08.2026 9.4
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass 14.08.2026 9.4
CVE-2026-72850 Budibase before 3.40.0 Arbitrary File Write via Path Traversal 14.08.2026 9.4
CVE-2026-72851 Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook 14.08.2026 9
CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified 14.08.2026 9
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 14.08.2026 9.1
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 13.08.2026 9.1
CVE-2026-73842 OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation 13.08.2026 9
CVE-2026-73843 OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs 14.08.2026 9.6
CVE-2026-73665 FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection 13.08.2026 9.3
CVE-2026-19750 Tenda CH/CP/TX3 SSH hard-coded password 14.08.2026 9.2
CVE-2026-72776 AgenticSeek Unauthenticated RCE via /query API Endpoint 14.08.2026 9.3
CVE-2026-73663 FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover 14.08.2026 9.3
CVE-2026-17482 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 13.08.2026 9.8
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint 15.08.2026 9.1
CVE-2026-8715 Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath 14.08.2026 9.6
CVE-2026-19747 Tenda CH7 ATE Module Kylin HandleCmd command injection 14.08.2026 9.3
CVE-2026-73656 Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state 14.08.2026 9.9
CVE-2026-14525 IBM WebSphere Application Server Liberty is affected by an authenication bypass 15.08.2026 9.4
CVE-2026-73653 Vitest: Browser Mode provider commands bypass the file-access permission gate 13.08.2026 9.4
CVE-2026-73644 OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant 13.08.2026 9.6
CVE-2026-73649 Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) 14.08.2026 9.8
CVE-2026-73567 sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock 14.08.2026 9.1
CVE-2026-67614 CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal 14.08.2026 9.3
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build 14.08.2026 9.3
CVE-2026-73533 Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build 14.08.2026 9.3
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths 14.08.2026 9.2
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header 14.08.2026 9.1
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode 14.08.2026 9.1
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure 14.08.2026 9.1
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink 14.08.2026 9.2
CVE-2026-27544 WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability 13.08.2026 10
CVE-2026-28001 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28008 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28142 WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28148 WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability 13.08.2026 9.8
CVE-2026-28149 WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability 13.08.2026 9.8
CVE-2026-28185 WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-61962 WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability 13.08.2026 10
CVE-2026-61966 WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61967 WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-61969 WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-66436 WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66446 WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability 13.08.2026 9.8
CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66478 WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66691 WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability 13.08.2026 9.8
CVE-2026-49827 WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) 13.08.2026 9.8
CVE-2026-73483 Flowise before 3.1.3 Sandbox Escape via Puppeteer 14.08.2026 9.4
CVE-2026-73485 Flowise before 3.1.3 Remote Code Execution via Airtable Agent 14.08.2026 9
CVE-2026-73486 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV 13.08.2026 9
CVE-2026-73487 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent 14.08.2026 9
CVE-2026-73601 Flowise before 3.1.3 Remote Code Execution via Custom MCP 14.08.2026 9
CVE-2026-73602 Flowise before 3.1.3 Sandbox Escape to RCE 13.08.2026 9
CVE-2026-73608 SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget 14.08.2026 9.2
CVE-2026-59503 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor 13.08.2026 9.1
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security 13.08.2026 9.1
CVE-2026-59506 Priority – CWE-306: Missing Authentication for Critical Function 13.08.2026 9.3
CVE-2026-59507 Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control 13.08.2026 9.3
CVE-2026-59500 Priority - CWE-287: Improper Authentication 13.08.2026 10
CVE-2026-15413 Link Factory - Backdoor 13.08.2026 10
CVE-2026-49819 UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd 13.08.2026 9.8
CVE-2026-49481 UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd 13.08.2026 9.6
CVE-2026-71193 13.08.2026 9.6
CVE-2026-71471 Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image 13.08.2026 9
CVE-2024-27253 IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request 13.08.2026 10
CVE-2026-73501 kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default 13.08.2026 9.1
CVE-2026-73519 WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret 13.08.2026 9.3
CVE-2026-19001 MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names 13.08.2026 9.5
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE 13.08.2026 9.9
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 13.08.2026 9.9
CVE-2026-63294 Root RCE via image backup.yaml symlink 13.08.2026 9.9
CVE-2026-17083 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 13.08.2026 9.8
CVE-2026-63296 Project restriction bypass via instance migration config override 13.08.2026 9.9
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 13.08.2026 9.9
CVE-2026-72508 Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) 13.08.2026 9.9
CVE-2026-73414 Shescape: Shell injection via unescaped parentheses on Windows with CMD 14.08.2026 9.2
CVE-2026-19656 ScadaLTS Authenticated Remote Code Execution 12.08.2026 9.9
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag 12.08.2026 9.9
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution 13.08.2026 9.9
CVE-2026-72789 SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks 14.08.2026 9.2
CVE-2026-72793 SiYuan before v3.7.4 Information Disclosure via /api/system/getConf 14.08.2026 9.2
CVE-2026-72794 siyuan before v3.7.4 Session Cookie Key Disclosure via getConf 14.08.2026 9.2
CVE-2026-72795 SiYuan before v3.7.4 Information Disclosure via Embed Block 14.08.2026 9.2
CVE-2026-72798 SiYuan before v3.7.4 Information Disclosure via renderAttributeView 14.08.2026 9.2
CVE-2026-72804 SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints 14.08.2026 9.2
CVE-2026-73268 Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection 12.08.2026 9.9
CVE-2026-73269 Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa 12.08.2026 9.9
CVE-2026-73329 CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint 14.08.2026 9.2
CVE-2026-73332 CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field 14.08.2026 9.2
CVE-2026-73407 Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) 12.08.2026 9
CVE-2026-73300 Budibase: SQL Injection via `multipleStatements: true` 12.08.2026 9.6
CVE-2026-16860 IBM i is Affected By Remote Code Execution Vulnerability [] 12.08.2026 9.9
CVE-2026-16956 IBM Db2 Mirror for i is vulnerable to OS command injection [] 12.08.2026 9.8
CVE-2026-17218 IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] 12.08.2026 9.8
CVE-2026-73299 Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer 12.08.2026 10
CVE-2026-17276 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 9.6
CVE-2026-73296 Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure 13.08.2026 9.4
CVE-2026-73294 Semaphore U: OS Command Injection 12.08.2026 9.9
CVE-2026-64639 14.08.2026 9.3
CVE-2026-73263 Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path 12.08.2026 9.9
CVE-2026-50561 Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse 13.08.2026 9.4
CVE-2026-67285 Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 14.08.2026 9.2
CVE-2026-57858 Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID 13.08.2026 9.3
CVE-2026-67282 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 12.08.2026 10
CVE-2025-41769 Unauthenticated Buffer Overflow in PROFINET Service 13.08.2026 9.3
CVE-2026-66659 WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability 12.08.2026 9.3
CVE-2026-70398 Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace 12.08.2026 9.6
CVE-2026-72526 Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation 12.08.2026 9.9
CVE-2026-68431 ksmbd: validate minimum PDU size for transform requests 13.08.2026 9.1
CVE-2026-5917 libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend 14.08.2026 9.4
CVE-2026-67568 Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials 12.08.2026 9.3
CVE-2026-68067 Mira Hormone Monitor, Mira Android App Weak Authentication 12.08.2026 9.3
CVE-2026-48765 TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding 12.08.2026 9.9
CVE-2026-16230 Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field 11.08.2026 9.8
CVE-2026-45618 LiquidJS is Vulnerable to Remote Code Execution 13.08.2026 10
CVE-2026-73034 DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header 14.08.2026 9.3
CVE-2026-73032 PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() 11.08.2026 9.4
CVE-2026-18691 Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure 11.08.2026 9
CVE-2026-72742 DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing 12.08.2026 9.2
CVE-2026-69102 MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust 14.08.2026 9.3
CVE-2026-27302 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-48381 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 11.08.2026 9
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) 12.08.2026 9.1
CVE-2026-71398 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-47705 TypeBot vulnerable to CSV injection in result export 13.08.2026 9.6
CVE-2026-73090 PeerTube: Cross-origin remote video takeover via Update activity 13.08.2026 9.3
CVE-2026-73211 PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() 11.08.2026 9.8
CVE-2026-12571 Authentication Bypass Leading to Account Takeover 12.08.2026 9.8
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 14.08.2026 9.4
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability 14.08.2026 9.3
CVE-2026-48362 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 12.08.2026 10
CVE-2026-71384 ColdFusion | Incorrect Authorization (CWE-863) 12.08.2026 9.6
CVE-2026-73080 SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle 13.08.2026 9.3
CVE-2025-31114 Fooocus webui vulnerable to Remote Code Execution 13.08.2026 9.3
CVE-2026-73069 Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution 11.08.2026 9.1
CVE-2026-17061 Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 11.08.2026 10
CVE-2026-47702 TypeBot API tokens stored in plaintext 11.08.2026 9.1
CVE-2026-72920 SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control 11.08.2026 9.8
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection 13.08.2026 9.8
CVE-2026-48056 Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler 11.08.2026 10
CVE-2026-48046 Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler 13.08.2026 9.3
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability 11.08.2026 9.6
CVE-2026-58115 12.08.2026 10
CVE-2026-72785 Craft CMS before 5.10.6 Authorization Bypass via structures/move-element 11.08.2026 9.3
CVE-2026-13737 Command Restriction Bypass 11.08.2026 9.2
CVE-2026-13738 Improper Authorization Validation 11.08.2026 9.2
CVE-2026-72550 Friendica Friendica - SQL Injection 11.08.2026 9.8
CVE-2026-72599 e107 e107 - SQL Injection 11.08.2026 9.8
CVE-2026-72603 wg-easy wg-easy - OS Command Injection 11.08.2026 9.9
CVE-2026-58231 Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) 12.08.2026 10
CVE-2026-10579 Picketlink-federation: auth bypass in picketlink saml unsolicited-response 11.08.2026 9.8
CVE-2026-13716 Path Traversal: '.../...//' in Crafty Controller 11.08.2026 9.1
CVE-2026-19516 CVE-2026-19516 CVE Record 12.08.2026 9.1
CVE-2026-19425 Win Men Intermational|Travel Agency Management System - SQL Injection 12.08.2026 9.3
CVE-2026-34265 Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform 12.08.2026 9.8
CVE-2026-44758 Code Injection vulnerability in Manufacturing Integration and Intelligence 11.08.2026 9.1
CVE-2026-48161 react18-use was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-48160 react-tracked was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation 13.08.2026 9.9
CVE-2026-14450 Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication 11.08.2026 9.9
CVE-2026-18948 Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server 11.08.2026 9.9
CVE-2026-72904 Firecrawl: Arbitrary file read via JSON Schema $ref expansion 11.08.2026 9.3
CVE-2026-72901 Dokploy: Remote Code Execution via volume-backup 13.08.2026 9.9
CVE-2026-72902 Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById 12.08.2026 9.9
CVE-2025-13293 Backdoor / default root credentials 12.08.2026 9.3
CVE-2025-13294 Unauthenticated SQL Injection 12.08.2026 9.3
CVE-2025-15681 Insufficient Webserver Authentication 12.08.2026 9.2
CVE-2026-72880 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` 11.08.2026 9.9
CVE-2026-72882 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers 13.08.2026 9.9
CVE-2026-72886 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) 10.08.2026 9.9
CVE-2026-72876 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* 10.08.2026 9.9
CVE-2026-72877 Dokploy: Command Injection via dockerImage in buildRemoteDocker 13.08.2026 9.6
CVE-2026-72878 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments 12.08.2026 9.6
CVE-2026-72879 Dokploy: Command Injection via Registry Credentials in Swarm Upload 11.08.2026 9.4
CVE-2026-72864 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) 11.08.2026 9.9
CVE-2026-72865 Dokploy: OS Command Injection via compose `composePath` 11.08.2026 9.9
CVE-2026-72867 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) 13.08.2026 9.9
CVE-2026-72868 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection 12.08.2026 9.9
CVE-2026-72869 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE 11.08.2026 9.9
CVE-2026-72872 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` 13.08.2026 9.9
CVE-2026-72863 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host 10.08.2026 9.9
CVE-2026-16626 JasperReports Server: XXE Injection Vulnerability (Unauthenticated) 11.08.2026 9.3
CVE-2026-48159 use-reducer-async was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72740 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` 10.08.2026 9.9
CVE-2026-72862 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE 13.08.2026 9.9
CVE-2026-72898 Metabase SQL injection via password reset endpoint 12.08.2026 10
CVE-2026-72899 Metabase SQL injection via public card or dashboard 11.08.2026 10
CVE-2026-72735 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution 10.08.2026 9.9
CVE-2026-72736 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE 10.08.2026 9.9
CVE-2026-72737 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups 13.08.2026 9.6
CVE-2026-72738 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter 10.08.2026 9.9
CVE-2026-72733 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore 10.08.2026 9.9
CVE-2026-48158 use-context-selector was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-47754 unauthenticated path traversal in Metacat 2.x 10.08.2026 9.3
CVE-2026-63106 ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php 10.08.2026 9.3
CVE-2026-13206 Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection 10.08.2026 9.8
CVE-2026-68117 tipc: clear sock->sk on the failed-insert path in tipc_sk_create() 13.08.2026 9.8
CVE-2026-68123 openvswitch: fix GSO userspace truncation underflow 13.08.2026 9.8
CVE-2026-68124 mctp: serial: handle zero-length frames to prevent rx buffer overflow 13.08.2026 9.6
CVE-2026-68127 ila: reload IPv6 header after pskb_may_pull in checksum adjust 13.08.2026 9.8
CVE-2026-68136 net: gro: fix double aggregation of flush-marked skbs 13.08.2026 9.8
CVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh() 13.08.2026 9.8
CVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb() 13.08.2026 9.8
CVE-2026-68154 libceph: reject zero bucket types in crush_decode 13.08.2026 9.8
CVE-2026-68156 libceph: refresh auth->authorizer_buf{,_len} after authorizer update 13.08.2026 9.8
CVE-2026-68158 libceph: Fix multiplication overflow in decode_new_up_state_weight() 13.08.2026 9.8
CVE-2026-68159 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE 13.08.2026 9.8
CVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() 13.08.2026 9.8
CVE-2026-68161 sctp: close UDP tunnel sockets during netns teardown 13.08.2026 9.8
CVE-2026-68170 mptcp: fix stale skb->sk reference on subflow close 13.08.2026 9.8
CVE-2026-68300 sctp: auth: verify auth requirement when auth_chunk is NULL 13.08.2026 9.8
CVE-2026-68302 amt: re-read skb header pointers after every pull 13.08.2026 9.8
CVE-2026-68343 smb: client: validate DFS referral PathConsumed 13.08.2026 9.1
CVE-2026-68381 ksmbd: pin conn during async oplock break notification 13.08.2026 9.8
CVE-2026-68385 s390/checksum: Fix csum_partial() without vector facility 13.08.2026 9.8
CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate 13.08.2026 9.8
CVE-2026-68426 xfrm: fix stale skb->prev after async crypto steals a GSO segment 13.08.2026 9.8
CVE-2026-68083 ksmbd: fix path resolution in ksmbd_vfs_kern_path_create 13.08.2026 9.1
CVE-2026-72564 fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication 10.08.2026 9.6
CVE-2026-72565 Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass 10.08.2026 9.8
CVE-2026-72567 deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete 10.08.2026 9.8
CVE-2026-72569 cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion 10.08.2026 9.1
CVE-2026-72575 daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects 10.08.2026 9.1
CVE-2026-72577 NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection 10.08.2026 9.8
CVE-2026-72580 duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints 10.08.2026 9.8
CVE-2026-72589 alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field 10.08.2026 9.8
CVE-2026-72590 alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter 10.08.2026 9.8
CVE-2026-72592 dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload 10.08.2026 9.8
CVE-2026-72593 dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access 10.08.2026 9.8
CVE-2026-66915 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.9 12.08.2026 10

Latest Updates

CVE Title Updated Score
CVE-2026-72887 Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token 16.08.2026
CVE-2026-72888 Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require 16.08.2026
CVE-2026-19349 Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends 16.08.2026
CVE-2024-58375 OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation 16.08.2026
CVE-2026-73056 SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token 16.08.2026
CVE-2026-73057 stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service 16.08.2026
CVE-2026-73058 stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass 16.08.2026
CVE-2026-73059 stoatchat before 0.15.0 Permission Bypass via message_fetch 16.08.2026
CVE-2026-73060 Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply 16.08.2026
CVE-2026-73061 Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor 16.08.2026
CVE-2026-73062 Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication 16.08.2026
CVE-2026-74783 Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service 16.08.2026
CVE-2026-74784 Scriban before 7.2.0 Denial of Service via array.insert_at 16.08.2026
CVE-2026-74785 Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption 16.08.2026
CVE-2026-74786 Scriban before 7.0.0 Denial of Service via Unbounded Template Output 16.08.2026
CVE-2026-74787 Scriban before 7.0.0 Uncontrolled Recursion via object.to_json 16.08.2026
CVE-2026-74788 Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right 16.08.2026
CVE-2026-74789 Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations 16.08.2026
CVE-2026-74790 Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache 16.08.2026
CVE-2026-74791 Scriban before 7.0.0 Authorization Bypass via Stale Include Cache 16.08.2026
CVE-2026-74792 Scriban before 7.0.0 Stack Overflow via nested array initializers 16.08.2026
CVE-2026-74794 Scriban before 6.6.0 Denial of Service via Infinite Recursion 16.08.2026
CVE-2026-74795 Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion 16.08.2026
CVE-2026-74796 OpenTofu before 1.11.7 Symlink Following Path Traversal 16.08.2026
CVE-2026-74797 OpenTofu before 1.11.4 Denial of Service via malicious zip 16.08.2026
CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 16.08.2026
CVE-2024-13784 Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection 16.08.2026 9.8
CVE-2026-74578 crypto: algif_skcipher - force synchronous processing on trees without ctx->state 16.08.2026
CVE-2026-10734 Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint 16.08.2026 7.2
CVE-2026-12998 Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter 16.08.2026 5.3
CVE-2026-13424 Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action 16.08.2026 7.2
CVE-2026-17087 WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter 16.08.2026 7.5
CVE-2026-17604 Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter 16.08.2026 4.9
CVE-2026-17608 WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion 16.08.2026 6.5
CVE-2026-18347 Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter 16.08.2026 4.3
CVE-2026-2357 Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting 16.08.2026 6.4
CVE-2026-2497 Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys 16.08.2026 7.2
CVE-2026-13712 Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL 16.08.2026
CVE-2026-15384 Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR 16.08.2026
CVE-2026-17533 All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import 16.08.2026
CVE-2026-18653 WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter 16.08.2026
CVE-2026-19613 ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source 16.08.2026
CVE-2026-19711 Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request 16.08.2026
CVE-2026-19712 Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description 16.08.2026
CVE-2026-19714 Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience Validation 16.08.2026
CVE-2026-19717 CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API 16.08.2026
CVE-2026-19725 WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connect 16.08.2026
CVE-2026-19726 Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure 16.08.2026
CVE-2026-19728 Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileupload 16.08.2026
CVE-2026-10035 Turnkey bbPress by WeaverTheme <= 1.7.1 - Authenticated (Administrator+) PHP Object Injection 16.08.2026 6.6
CVE-2026-15056 StoreEngine <= 2.1.1 - Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL 16.08.2026 6.5
CVE-2026-15345 ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated (Subscriber+) Third-Party Plugin Option Modification via 'causer' Parameter 16.08.2026 4.3
CVE-2026-15351 WC Vendors <= 2.7.0 - Authenticated (Shop Manager+) SQL Injection via 'status' Parameter 16.08.2026 4.9
CVE-2026-15604 Toocheke Companion <= 2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'series_bg_color' Post Meta 16.08.2026 6.4
CVE-2026-15790 Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode 16.08.2026 6.4
CVE-2026-16758 Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 16.08.2026 6.4
CVE-2026-16775 Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute 16.08.2026 6.4
CVE-2026-17581 WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine 16.08.2026 7.2
CVE-2026-17582 Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate) 16.08.2026 4.9
CVE-2026-18316 Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action 16.08.2026 9.1
CVE-2026-18402 SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute 16.08.2026 6.4
CVE-2026-2283 User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection via 'blog_id' Parameter 16.08.2026 4.9
CVE-2026-9767 The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameter 16.08.2026 6.5
CVE-2026-19934 itsourcecode Hospital Management System vieworder.php sql injection 16.08.2026
CVE-2026-19933 DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflow 16.08.2026
CVE-2025-10005 Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update 16.08.2026 4.3
CVE-2026-11780 Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter 16.08.2026 6.4
CVE-2026-12477 Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter 16.08.2026 4.4
CVE-2026-12905 Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter 16.08.2026 4.3
CVE-2026-13167 Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints 16.08.2026 4.3
CVE-2026-13358 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure 16.08.2026 6.5
CVE-2026-14498 Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter 16.08.2026 8.8
CVE-2026-14524 ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters 16.08.2026 9.1
CVE-2026-15002 Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter 16.08.2026 7.2
CVE-2026-15009 Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter 16.08.2026 6.1
CVE-2026-15066 Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments 16.08.2026 6.4
CVE-2026-15441 Product Table & List Builder For WooCommerce <= 5.6.0 - Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter 16.08.2026 5.3
CVE-2026-15602 NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Parameter 16.08.2026 4.9
CVE-2026-15726 Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute 16.08.2026 6.4
CVE-2026-15963 Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option 16.08.2026 6.5
CVE-2026-16079 Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection via 'href' Attribute in Post Content 16.08.2026 6.5
CVE-2026-16098 ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override 16.08.2026 9.8
CVE-2026-16099 Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter 16.08.2026 8.8
CVE-2026-16779 Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action 16.08.2026 4.3
CVE-2026-17123 Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting 16.08.2026 8.8
CVE-2026-18385 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field 16.08.2026 5.4
CVE-2026-18432 Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter 16.08.2026 9.8
CVE-2026-19932 DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection 16.08.2026
CVE-2026-19930 Dolibarr User Cloning card.php ldap injection 16.08.2026
CVE-2026-2487 Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form' Setting 16.08.2026 4.4
CVE-2026-19929 OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine 16.08.2026
CVE-2026-19928 OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management 16.08.2026
CVE-2026-19927 OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery 16.08.2026
CVE-2026-19925 SourceCodester Stock Management System Master.php delete_supplier sql injection 16.08.2026
CVE-2026-19926 Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection 16.08.2026
CVE-2026-19924 Tenda AC10 httpd R7WebsSecurityHandler improper authentication 16.08.2026
CVE-2026-19923 code-projects Online Shopping System checkout_process.php sql injection 16.08.2026
CVE-2026-19922 code-projects Online Shopping System checkout.php cross site scripting 16.08.2026
CVE-2026-19921 code-projects Online Shopping System homeaction.php sql injection 16.08.2026
CVE-2026-19920 code-projects Online Shopping System action.php sql injection 15.08.2026
CVE-2026-19919 code-projects Online Shopping System Login login.php sql injection 15.08.2026
CVE-2026-19918 SpaceX Starlink Router Gen 3 gRPC Management get_status access control 15.08.2026
CVE-2026-19917 code-projects Online Food Order System delete_food_items1.php sql injection 15.08.2026
CVE-2026-19916 code-projects Online Food Order System edit_food_items.php cross site scripting 15.08.2026
CVE-2026-74767 Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bomb 15.08.2026
CVE-2026-73041 SiYuan before v3.7.4 Remote Code Execution via PDF Annotations 15.08.2026
CVE-2026-73042 SiYuan before v3.7.4 Remote Code Execution via Menu Metadata 15.08.2026
CVE-2026-73043 SiYuan before v3.7.4 Remote Code Execution via Template Calculation 15.08.2026
CVE-2026-73044 SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width 15.08.2026
CVE-2026-73045 SiYuan before 3.7.4 Brute-Force via authFilePublishAccess 15.08.2026
CVE-2026-73046 SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth 15.08.2026
CVE-2026-73047 siyuan before v3.7.4 Server-Side Template Injection via attribute-view 15.08.2026
CVE-2026-73050 SiYuan before v3.7.4 Stored XSS via select option color 15.08.2026
CVE-2026-73052 SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names 15.08.2026
CVE-2026-73053 SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji 15.08.2026
CVE-2026-73054 SiYuan before v3.7.4 Authentication Bypass via WebSocket 15.08.2026
CVE-2026-73055 Shescape before 2.1.15 Home Directory Disclosure via BusyBox 15.08.2026
CVE-2026-74764 Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora 15.08.2026