| CVE-2026-18931 |
Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software |
01.09.2026 |
9.1 |
| CVE-2026-78012 |
Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack |
01.09.2026 |
9.3 |
| CVE-2026-18210 |
SQL Injection in TRtek Technological Products's Store |
01.09.2026 |
9.8 |
| CVE-2026-9621 |
RSLinx Classic® - Multiple Vulnerabilities |
01.09.2026 |
9.2 |
| CVE-2026-18808 |
Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO |
01.09.2026 |
9.8 |
| CVE-2026-18765 |
SQL Injection in Teracity Sotware's Teracity E-OSB Platform |
01.09.2026 |
9.8 |
| CVE-2026-84149 |
Information Disclosure Vulnerability in Manacle Technologies ERP System |
01.09.2026 |
9.2 |
| CVE-2026-84147 |
Remote Code Execution Vulnerability in Manacle Technologies ERP System |
01.09.2026 |
10 |
| CVE-2026-84148 |
Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System |
01.09.2026 |
9.2 |
| CVE-2023-54356 |
Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites |
01.09.2026 |
9.3 |
| CVE-2026-84189 |
LibreNMS before 26.7.0 Stored XSS via Oxidized API |
01.09.2026 |
9.2 |
| CVE-2026-84200 |
Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions |
01.09.2026 |
9.4 |
| CVE-2026-18550 |
Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter |
01.09.2026 |
9.8 |
| CVE-2026-4813 |
Code injection in the Lutece Core |
01.09.2026 |
9.4 |
| CVE-2026-78319 |
TOCTOU Vulnerability in file exchange |
01.09.2026 |
9.3 |
| CVE-2026-83772 |
Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection |
01.09.2026 |
9.4 |
| CVE-2026-67394 |
|
01.09.2026 |
9 |
| CVE-2026-75865 |
WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint |
01.09.2026 |
9.8 |
| CVE-2026-83524 |
RedPort Optimizer wXa-223 System Clock datetime.php exec command injection |
31.08.2026 |
9.4 |
| CVE-2026-82971 |
QVidium Opera11 CGI Script net_tr.cgi command injection |
31.08.2026 |
10 |
| CVE-2026-82954 |
Dokploy Settings application.ts writeTraefikConfigInPath path traversal |
31.08.2026 |
9.4 |
| CVE-2026-81779 |
WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability |
01.09.2026 |
10 |
| CVE-2026-81293 |
WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability |
01.09.2026 |
9.3 |
| CVE-2026-81756 |
WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL Injection vulnerability |
31.08.2026 |
9.3 |
| CVE-2026-81763 |
WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability |
31.08.2026 |
9.3 |
| CVE-2026-81780 |
WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability |
31.08.2026 |
10 |
| CVE-2026-82226 |
WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability |
01.09.2026 |
9.8 |
| CVE-2026-82908 |
MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow |
01.09.2026 |
9.3 |
| CVE-2026-53552 |
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers |
01.09.2026 |
9.6 |
| CVE-2026-79748 |
MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args) |
31.08.2026 |
9.9 |
| CVE-2026-82807 |
ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management |
31.08.2026 |
9.3 |
| CVE-2026-73819 |
Ebyte NA111-M Weak Authentication |
31.08.2026 |
9.3 |
| CVE-2026-76133 |
Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm |
31.08.2026 |
9.3 |
| CVE-2026-66047 |
ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE |
31.08.2026 |
9.2 |
| CVE-2026-82970 |
WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability |
31.08.2026 |
10 |
| CVE-2026-59111 |
Command Injection vulnerability in eObčanka-Identifikace |
31.08.2026 |
9.3 |
| CVE-2026-82694 |
Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication |
31.08.2026 |
10 |
| CVE-2026-82695 |
Tenda AC18 Telnet telnet missing authentication |
31.08.2026 |
10 |
| CVE-2026-82692 |
D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82693 |
Tenda AC1206 Web UI telnet TendaTelnet missing authentication |
31.08.2026 |
10 |
| CVE-2026-82691 |
D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82690 |
D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82689 |
D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82688 |
D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82876 |
Phison PS3111-S11 Controller Firmware Signature Verification Bypass |
31.08.2026 |
9.3 |
| CVE-2026-49003 |
Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product |
31.08.2026 |
9.6 |
| CVE-2026-82854 |
Nodemailer before 8.0.3 SMTP Command Injection via envelope.size |
31.08.2026 |
9.3 |
| CVE-2026-82855 |
@hulumi/policies before 1.3.2 Evidence Validation Bypass |
31.08.2026 |
9.3 |
| CVE-2026-82856 |
@hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
31.08.2026 |
9.3 |
| CVE-2026-82857 |
hulumi before v1.3.2 Privilege Escalation via IAM Policy |
01.09.2026 |
9.3 |
| CVE-2026-82858 |
@hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
31.08.2026 |
9.3 |
| CVE-2026-82859 |
hulumi before v1.3.2 SCP Template Tag-on-Create Bypass |
31.08.2026 |
9.3 |
| CVE-2026-82860 |
@hulumi/policies before 1.3.2 Admin Policy Bypass |
31.08.2026 |
9.3 |
| CVE-2026-19410 |
Google Cloud Build Comment Control Bypass via Webhook Suppression |
31.08.2026 |
9.4 |
| CVE-2026-82628 |
Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management |
31.08.2026 |
9.3 |
| CVE-2026-58574 |
|
31.08.2026 |
9.8 |
| CVE-2026-82616 |
TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow |
31.08.2026 |
9.4 |
| CVE-2026-82593 |
D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow |
01.09.2026 |
9.4 |
| CVE-2026-82592 |
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow |
31.08.2026 |
9.4 |
| CVE-2026-82645 |
AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token |
31.08.2026 |
9.2 |
| CVE-2026-82653 |
SiYuan before v3.8.1 Stored XSS via confirmDialog |
30.08.2026 |
9.3 |
| CVE-2026-82654 |
SiYuan before v3.8.1 Stored XSS via block name |
01.09.2026 |
9.3 |
| CVE-2026-82542 |
Tenda HG10 Boa Web Server formIPv6Routing buffer overflow |
01.09.2026 |
10 |
| CVE-2026-82539 |
TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption |
30.08.2026 |
9.4 |
| CVE-2026-15980 |
MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token |
31.08.2026 |
9.8 |
| CVE-2026-15369 |
Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout |
01.09.2026 |
9.8 |
| CVE-2026-82460 |
Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown |
31.08.2026 |
9.3 |
| CVE-2026-82466 |
Rodauth before 2.46.0 Authentication Bypass via webauthn_login |
31.08.2026 |
9.4 |
| CVE-2026-82452 |
rust-iot-platform Authentication Bypass via Missing Request Guards |
01.09.2026 |
9.3 |
| CVE-2026-82454 |
Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in |
31.08.2026 |
9.3 |
| CVE-2026-82456 |
argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP |
29.08.2026 |
10 |
| CVE-2026-82448 |
Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key |
31.08.2026 |
9.3 |
| CVE-2026-14494 |
Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field |
31.08.2026 |
9.8 |
| CVE-2026-18527 |
IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ]. |
31.08.2026 |
9.9 |
| CVE-2026-19286 |
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement |
01.09.2026 |
9.8 |
| CVE-2026-19295 |
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement |
01.09.2026 |
9.9 |
| CVE-2026-3627 |
Multiple Vulnerabilities in IBM Concert Software |
01.09.2026 |
9.1 |
| CVE-2026-54745 |
Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true |
31.08.2026 |
10 |
| CVE-2026-54754 |
Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) |
31.08.2026 |
9.6 |
| CVE-2026-54755 |
Klever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) |
31.08.2026 |
9.6 |
| CVE-2026-55068 |
free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints |
31.08.2026 |
9.3 |
| CVE-2026-55220 |
Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column |
31.08.2026 |
9.3 |
| CVE-2026-55247 |
plone.app.event: Denial of service via iCalendar import |
31.08.2026 |
9.1 |
| CVE-2026-55248 |
plone.app.portlets: Denial of service via RSS feed portlet |
28.08.2026 |
9.1 |
| CVE-2026-55378 |
JS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context values |
01.09.2026 |
9.3 |
| CVE-2026-55511 |
Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` |
01.09.2026 |
9.1 |
| CVE-2026-55559 |
Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) |
28.08.2026 |
9.8 |
| CVE-2026-55565 |
Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) |
31.08.2026 |
9.9 |
| CVE-2026-55634 |
Pimcore: Remote Code Execution via DataObject Class-Definition Field Name |
28.08.2026 |
9.9 |
| CVE-2026-82021 |
Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference |
31.08.2026 |
9 |
| CVE-2026-82266 |
Redpanda Admin API Unauthenticated Superuser Access via Default Configuration |
01.09.2026 |
9.3 |
| CVE-2026-82277 |
Argo Rollouts Dashboard Unauthenticated Mutating Operations |
31.08.2026 |
9.3 |
| CVE-2026-82281 |
Kotaemon Missing Ownership Check in Conversation Functions |
31.08.2026 |
9.1 |
| CVE-2026-82329 |
Potential authentication bypass leading to administrative access in Artifactory |
31.08.2026 |
9.8 |
| CVE-2026-82078 |
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector |
01.09.2026 |
9.4 |
| CVE-2026-18918 |
OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default |
31.08.2026 |
9.1 |
| CVE-2026-42007 |
|
28.08.2026 |
9.1 |
| CVE-2026-82222 |
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability |
28.08.2026 |
10 |
| CVE-2026-82244 |
Budibase before 3.41.3 Remote Code Execution via Plugin eval() |
28.08.2026 |
9.4 |
| CVE-2026-40541 |
|
28.08.2026 |
9 |
| CVE-2026-76581 |
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion |
28.08.2026 |
9.8 |
| CVE-2026-78032 |
|
28.08.2026 |
9.3 |
| CVE-2026-80600 |
batman-adv: dat: acquire ARP hw source only after skb realloc |
29.08.2026 |
9.8 |
| CVE-2026-80603 |
netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
29.08.2026 |
9.1 |
| CVE-2026-80609 |
qede: fix out-of-bounds check for cqe->len_list[] |
29.08.2026 |
9.8 |
| CVE-2026-80612 |
net: lwtunnel: Drop skb metadata before LWT encapsulation |
29.08.2026 |
9.8 |
| CVE-2026-80617 |
net: airoha: fix foe_check_time allocation size |
29.08.2026 |
9.8 |
| CVE-2026-80630 |
net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen |
29.08.2026 |
9.8 |
| CVE-2026-80634 |
netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
29.08.2026 |
9.8 |
| CVE-2026-80668 |
netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
29.08.2026 |
9.8 |
| CVE-2026-80670 |
perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
29.08.2026 |
9.1 |
| CVE-2026-80671 |
perf sched: Fix register_pid() overflow, strcpy, and BUG_ON |
29.08.2026 |
9.3 |
| CVE-2026-80673 |
ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() |
29.08.2026 |
9.8 |
| CVE-2026-80674 |
ntfs: validate resident attribute lists and harden the validator |
29.08.2026 |
9.8 |
| CVE-2026-80681 |
vxlan: re-fetch eth header after route_shortcircuit() |
29.08.2026 |
9.8 |
| CVE-2026-80684 |
KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
29.08.2026 |
9.3 |
| CVE-2026-80693 |
idpf: bound interrupt-vector register fill to the allocated array |
29.08.2026 |
9.3 |
| CVE-2026-80694 |
net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
29.08.2026 |
9.8 |
| CVE-2026-80714 |
ipvs: do not propagate one-packet flag to synced conns |
29.08.2026 |
9.8 |
| CVE-2026-82082 |
Green-Computing|NUMail - OS Command Injection |
31.08.2026 |
9.3 |
| CVE-2026-82090 |
|
28.08.2026 |
9.2 |
| CVE-2026-13086 |
Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint |
29.08.2026 |
9.3 |
| CVE-2026-19313 |
Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution |
29.08.2026 |
9.3 |
| CVE-2026-19315 |
Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution |
01.09.2026 |
9.3 |
| CVE-2026-19318 |
Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution |
29.08.2026 |
9.3 |
| CVE-2026-61800 |
Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893) |
28.08.2026 |
9.1 |
| CVE-2026-78174 |
WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs |
28.08.2026 |
9.3 |
| CVE-2026-18717 |
Improper Certificate Validation in ASE 2000 |
28.08.2026 |
9.1 |
| CVE-2026-50152 |
Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users |
01.09.2026 |
9.1 |
| CVE-2026-68929 |
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization |
28.08.2026 |
9.3 |
| CVE-2026-69658 |
Ebyte NA111-M Cleartext Transmission of Sensitive Information |
31.08.2026 |
9.3 |
| CVE-2026-71187 |
Ebyte NA111-M Use of Client-Side Authentication |
31.08.2026 |
9.3 |
| CVE-2026-73125 |
Ebyte NA111-M Missing Authentication for Critical Function |
31.08.2026 |
9.3 |
| CVE-2026-76179 |
Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings |
31.08.2026 |
9.3 |
| CVE-2026-76943 |
Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel |
28.08.2026 |
9.3 |
| CVE-2026-78239 |
Xiiaozet LK100W Missing Authentication for Critical Function |
28.08.2026 |
9.3 |
| CVE-2026-18885 |
Unauthenticated Remote Code Execution in GraphQL Composite Data API |
29.08.2026 |
10 |
| CVE-2026-18886 |
Unauthenticated Privilege Escalation via System Configuration Image Upload Processor |
29.08.2026 |
10 |
| CVE-2026-19092 |
Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing |
28.08.2026 |
9.8 |
| CVE-2026-48996 |
Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client |
29.08.2026 |
9.3 |
| CVE-2026-53578 |
Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml |
31.08.2026 |
9.3 |
| CVE-2026-53579 |
Trilium: Note Import to RCE via Book Note |
28.08.2026 |
9.3 |
| CVE-2026-74820 |
Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause |
29.08.2026 |
10 |
| CVE-2026-16279 |
Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x |
27.08.2026 |
9.3 |
| CVE-2026-57499 |
Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) |
27.08.2026 |
9.1 |
| CVE-2026-81094 |
mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring Authentication |
29.08.2026 |
9.3 |
| CVE-2026-81096 |
ToolUniverse through 1.2.6 Unauthenticated Remote Code Execution via python_code_executor Sandbox Escape |
29.08.2026 |
9.3 |
| CVE-2026-81098 |
Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport |
29.08.2026 |
9.3 |
| CVE-2026-81680 |
openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal |
27.08.2026 |
9.3 |
| CVE-2026-81681 |
openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage |
27.08.2026 |
9.3 |
| CVE-2026-81685 |
openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata |
27.08.2026 |
9.3 |
| CVE-2026-81694 |
verify-usb before 1.4.9 Output Injection via Unsanitized Filenames |
28.08.2026 |
9.3 |
| CVE-2026-81695 |
openssl_encrypt before 1.4.9 Terminal Injection via key_id |
27.08.2026 |
9.3 |
| CVE-2026-81696 |
openssl_encrypt before 1.4.9 Terminal Injection via info Command |
27.08.2026 |
9.3 |
| CVE-2026-81698 |
openssl_encrypt before 1.4.9 Shell Injection via info command |
27.08.2026 |
9.3 |
| CVE-2026-81700 |
openssl_encrypt before 1.4.9 GPG Signature Verification Bypass |
27.08.2026 |
9.3 |
| CVE-2026-81701 |
openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin |
27.08.2026 |
9.3 |
| CVE-2026-81702 |
openssl_encrypt before 1.4.9 Key Substitution via Identity Load |
01.09.2026 |
9.3 |
| CVE-2026-81706 |
openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing |
27.08.2026 |
9.3 |
| CVE-2026-81707 |
openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email |
31.08.2026 |
9.3 |
| CVE-2026-81714 |
openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass |
27.08.2026 |
9.3 |
| CVE-2026-81717 |
openssl_encrypt before 1.4.9 Integrity Bypass via Added Files |
27.08.2026 |
9.3 |
| CVE-2026-81719 |
openssl_encrypt before 1.4.9 Remote Code Execution via Plugin |
27.08.2026 |
9.3 |
| CVE-2026-81735 |
UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution |
31.08.2026 |
10 |
| CVE-2026-81826 |
Flowintel Fails to Invalidate Active Sessions After Password Change |
27.08.2026 |
9.1 |
| CVE-2026-74232 |
Zbtlink MQWrt yunmgrd Cloud C2 Implant |
27.08.2026 |
9.3 |
| CVE-2026-74233 |
Zbtlink MQWrt infosrvd Command Injection |
27.08.2026 |
9.3 |
| CVE-2026-81672 |
Multiple Vulnerabilities in TOOOLS' iSquad |
27.08.2026 |
9.3 |
| CVE-2026-81673 |
Multiple Vulnerabilities in TOOOLS' iSquad |
27.08.2026 |
9.3 |
| CVE-2026-81674 |
Multiple Vulnerabilities in TOOOLS' iSquad |
27.08.2026 |
9.3 |
| CVE-2026-81675 |
Multiple Vulnerabilities in TOOOLS' iSquad |
27.08.2026 |
9.3 |
| CVE-2026-32479 |
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulnerability |
28.08.2026 |
9.3 |
| CVE-2026-32566 |
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability |
27.08.2026 |
9.8 |
| CVE-2026-59354 |
Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata |
28.08.2026 |
9.6 |
| CVE-2026-78260 |
WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability |
28.08.2026 |
9.3 |
| CVE-2026-78274 |
WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability |
27.08.2026 |
9.1 |
| CVE-2026-78286 |
WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability |
28.08.2026 |
9.8 |
| CVE-2026-78288 |
WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability |
27.08.2026 |
9.3 |
| CVE-2026-78292 |
WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability |
27.08.2026 |
9.8 |
| CVE-2026-59270 |
Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces |
28.08.2026 |
9.4 |
| CVE-2026-77991 |
Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 |
28.08.2026 |
9.4 |
| CVE-2026-65956 |
KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF |
29.08.2026 |
10 |
| CVE-2026-65641 |
|
27.08.2026 |
9.3 |
| CVE-2026-60004 |
|
26.08.2026 |
9.8 |
| CVE-2026-19485 |
Bucket Squatting in Vertex AI Search for Commerce |
26.08.2026 |
9.3 |
| CVE-2026-70419 |
|
26.08.2026 |
9.1 |
| CVE-2026-54569 |
SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core |
26.08.2026 |
9.8 |
| CVE-2026-80428 |
ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint |
29.08.2026 |
9.3 |
| CVE-2026-81032 |
NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration |
26.08.2026 |
9.3 |
| CVE-2026-75062 |
Eval Injection in google/langfun via default lf.query protocol |
27.08.2026 |
9.2 |
| CVE-2026-74737 |
net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG |
27.08.2026 |
9.8 |
| CVE-2026-74743 |
macvlan: inherit needed_headroom and needed_tailroom from lowerdev |
27.08.2026 |
9.8 |
| CVE-2026-74744 |
ipvlan: inherit needed_headroom and needed_tailroom from phy_dev |
27.08.2026 |
9.8 |
| CVE-2026-74746 |
netfilter: flowtable: publish GC-visible tuple last |
27.08.2026 |
9.8 |
| CVE-2026-74751 |
riscv: lib: Fix ZBB strnlen reading past count boundary |
27.08.2026 |
9.4 |
| CVE-2026-74752 |
sctp: validate cookie AUTH state before use |
27.08.2026 |
9.8 |
| CVE-2026-80519 |
ovpn: finish crypto callback cleanup before peer release |
27.08.2026 |
9.8 |
| CVE-2026-80528 |
ceph: avoid fs reclaim while using current->journal_info |
27.08.2026 |
9.8 |
| CVE-2026-80551 |
s390/vfio_ccw: Ensure first IDAW remains constant |
27.08.2026 |
9.3 |
| CVE-2026-80554 |
s390/vfio_ccw: Limit the number of channel program segments |
27.08.2026 |
9.3 |
| CVE-2026-80557 |
libceph: fix OOB read in decode_watchers() via missing bounds check |
27.08.2026 |
9.8 |
| CVE-2026-80558 |
libceph: Avoid using invalid osd indices from primary_temp |
27.08.2026 |
9.8 |
| CVE-2026-80561 |
libceph: fix multiple unsafe decodes in decode_locker() |
27.08.2026 |
9.8 |
| CVE-2026-80585 |
mptcp: fastopen: only mark MPTFO subflows with SYN data |
27.08.2026 |
9.4 |
| CVE-2026-80586 |
mptcp: options: reset DSS fields in case of unexpected size |
27.08.2026 |
9.8 |
| CVE-2026-80587 |
mptcp: avoid combining some incoming suboptions |
27.08.2026 |
9.8 |
| CVE-2026-80589 |
block: stop the timeout timer when releasing a never added disk |
27.08.2026 |
9.8 |
| CVE-2026-54523 |
Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system |
26.08.2026 |
9.6 |
| CVE-2026-75896 |
Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk |
26.08.2026 |
9.1 |
| CVE-2026-12717 |
Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection |
26.08.2026 |
9.4 |
| CVE-2026-18080 |
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment |
26.08.2026 |
9.8 |
| CVE-2026-77532 |
|
26.08.2026 |
9.6 |
| CVE-2026-77554 |
|
26.08.2026 |
10 |
| CVE-2026-77557 |
|
26.08.2026 |
9.8 |
| CVE-2026-77549 |
|
27.08.2026 |
9 |
| CVE-2026-77550 |
|
27.08.2026 |
10 |
| CVE-2026-77551 |
|
26.08.2026 |
9 |
| CVE-2026-77552 |
|
26.08.2026 |
9.8 |
| CVE-2026-77553 |
|
26.08.2026 |
9.9 |
| CVE-2026-77546 |
|
26.08.2026 |
9.9 |
| CVE-2026-77547 |
|
26.08.2026 |
9.9 |
| CVE-2026-77548 |
|
26.08.2026 |
9.9 |
| CVE-2026-80203 |
Grav before 1.0.18 Authentication Bypass via Scoped API Key |
28.08.2026 |
9.3 |
| CVE-2026-80204 |
Grav before 1.0.18 Authentication Bypass via Scoped API Key |
26.08.2026 |
9.3 |
| CVE-2026-77542 |
|
26.08.2026 |
9.1 |
| CVE-2026-77543 |
|
26.08.2026 |
9.9 |
| CVE-2026-77545 |
|
27.08.2026 |
9 |
| CVE-2026-80349 |
TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter |
26.08.2026 |
9.3 |
| CVE-2026-77539 |
|
27.08.2026 |
9.1 |
| CVE-2026-77540 |
|
27.08.2026 |
9.1 |
| CVE-2026-77541 |
|
26.08.2026 |
9.1 |
| CVE-2026-59683 |
OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings |
26.08.2026 |
9.3 |
| CVE-2026-77535 |
|
26.08.2026 |
9.1 |
| CVE-2026-77536 |
|
27.08.2026 |
9.9 |
| CVE-2026-77537 |
|
26.08.2026 |
10 |
| CVE-2026-77534 |
|
27.08.2026 |
9.9 |
| CVE-2026-77533 |
|
26.08.2026 |
9.9 |
| CVE-2026-80235 |
Thinking Software Technology|EFence - Arbitrary File Upload |
26.08.2026 |
9.3 |
| CVE-2026-18431 |
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write |
27.08.2026 |
9.8 |
| CVE-2026-15203 |
Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software |
26.08.2026 |
9.3 |