CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-5388 justhtml before 1.15.0 Multiple Security Issues 23.08.2026 9.3
CVE-2026-7808 justhtml before 1.16.0 Multiple Security Issues via Sanitization 23.08.2026 9.3
CVE-2026-8445 justhtml before 1.12.0 Sanitizer Bypass via Markdown 23.08.2026 9.3
CVE-2026-78155 Untrusted Search Path in StackGres 23.08.2026 9.9
CVE-2026-78050 Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow 22.08.2026 9.4
CVE-2026-4703 WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission 22.08.2026 9.8
CVE-2026-63310 NLTK before 3.9.3 Missing Post-Download Integrity Verification 22.08.2026 9.3
CVE-2026-76571 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 23.08.2026 9.3
CVE-2026-76602 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 23.08.2026 9.3
CVE-2026-76604 Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 23.08.2026 10
CVE-2026-76605 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2 23.08.2026 10
CVE-2026-76606 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2 23.08.2026 10
CVE-2026-76607 Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2 23.08.2026 10
CVE-2026-77992 Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 22.08.2026 9.5
CVE-2026-77946 TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow 22.08.2026 10
CVE-2026-78003 Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys 22.08.2026 9.8
CVE-2026-12710 Missing Authorization in Application Integration QueryEngineTask 22.08.2026 9.3
CVE-2026-49849 xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution 21.08.2026 9.1
CVE-2026-77415 JSONata: Arbitrary Code Execution via crafted JSONata expressions 21.08.2026 9.3
CVE-2026-77413 JSONata: Arbitrary Code Execution via crafted JSONata expressions 21.08.2026 9.3
CVE-2026-77414 JSONata: Arbitrary Code Execution via crafted JSONata expressions 21.08.2026 9.3
CVE-2026-61539 Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing 21.08.2026 10
CVE-2026-59989 Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) 21.08.2026 9.2
CVE-2026-62283 Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check 21.08.2026 9.9
CVE-2026-76904 GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers 21.08.2026 9.8
CVE-2026-77810 Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector 21.08.2026 9.4
CVE-2026-62674 Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE 21.08.2026 9
CVE-2026-77234 Improper input validation in FreeRTOS-Kernel timer command handling 21.08.2026 9.3
CVE-2026-39909 llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler 21.08.2026 9.2
CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability 21.08.2026 10
CVE-2026-75932 Jet Admin tenant isolation failure 21.08.2026 9.2
CVE-2026-63343 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 21.08.2026 9.9
CVE-2026-77087 Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding 21.08.2026 9.4
CVE-2026-48755 Incus has an argument injection in backup compression algorithm leading to AFW and ACE 21.08.2026 9.9
CVE-2026-48769 Incus has an arbitrary file write on its client due to trusted image hash 21.08.2026 9.9
CVE-2026-62867 Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution 21.08.2026 9.9
CVE-2026-62940 Incus has a project restriction bypass via instance migration config override 21.08.2026 9.9
CVE-2026-62941 Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 21.08.2026 9.9
CVE-2026-63125 Incus vulnerable to root RCE via image backup.yaml symlink 21.08.2026 9.9
CVE-2026-48751 Incus has a restricted project bypass leading to arbitrary command execution 21.08.2026 9.9
CVE-2026-48752 Incus has arbitrary file read+write on host via templates/ symlink in malicious image 21.08.2026 9.9
CVE-2026-48753 Incus has an arbitrary file write via path traversal in S3 multipart upload 21.08.2026 9.9
CVE-2026-48749 Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image 21.08.2026 9.9
CVE-2026-48750 Incus has an arbitrary file write on host via `exec-output` symlink in crafted image 21.08.2026 9.9
CVE-2026-77812 Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE 21.08.2026 9.4
CVE-2026-77806 21.08.2026 9.8
CVE-2026-77776 Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity 21.08.2026 9.3
CVE-2026-77086 SiYuan before v3.7.4 Path Traversal via packageName 21.08.2026 9.4
CVE-2026-77683 Comfast CF-N1-S mbox-config system command injection 21.08.2026 9.4
CVE-2026-77264 Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure 21.08.2026 9.8
CVE-2026-76158 Datiphy Data Management Center - External Control of File Name or Path 21.08.2026 9.3
CVE-2026-76155 Datiphy Data Management Center - Use of Default Credentials 21.08.2026 9.3
CVE-2026-76156 Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command 21.08.2026 9.4
CVE-2026-77649 21.08.2026 9.8
CVE-2026-77650 21.08.2026 9.8
CVE-2026-77651 21.08.2026 9.8
CVE-2026-77647 21.08.2026 9.8
CVE-2026-18835 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.9
CVE-2026-77645 Critical Remote Code Execution (RCE) vulnerability reported in Windchill 22.08.2026 9.2
CVE-2026-17122 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17136 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17141 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17142 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17145 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-17152 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17157 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-17160 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-17422 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.3
CVE-2026-72843 EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover 21.08.2026 9.3
CVE-2026-77644 Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition 22.08.2026 9.3
CVE-2026-17040 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17118 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-55769 CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path` 21.08.2026 9.4
CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability 22.08.2026 9.3
CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability 22.08.2026 10
CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability 22.08.2026 10
CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability 22.08.2026 10
CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability 22.08.2026 9.1
CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability 22.08.2026 9.6
CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability 22.08.2026 10
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability 22.08.2026 10
CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-71485 Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends 20.08.2026 9.1
CVE-2026-67567 Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction 21.08.2026 9.9
CVE-2026-19586 Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways 21.08.2026 9.3
CVE-2026-66785 Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowedips / ipsec enables traffic hijack 20.08.2026 9.9
CVE-2026-66788 Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace 20.08.2026 9.9
CVE-2026-77148 Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow 20.08.2026 9.4
CVE-2026-2334 ) Missing Server-Side File Extension Validation in vsDesk 21.08.2026 9.4
CVE-2026-63385 Libevent: HTTP header handling bugs create risk of access control bypass. 21.08.2026 9.2
CVE-2026-63382 libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling 20.08.2026 9.2
CVE-2026-53424 Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions 21.08.2026 9.1
CVE-2026-73251 Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification 20.08.2026 9.3
CVE-2026-73253 Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching 20.08.2026 9.1
CVE-2026-73256 Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE 21.08.2026 9.1
CVE-2026-73257 Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling 20.08.2026 9.1
CVE-2026-55642 dbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured) 20.08.2026 9.8
CVE-2026-71428 unstructured: Server-Side Request Forgery in the URL-based partitioning 20.08.2026 9.3
CVE-2026-77022 Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow 21.08.2026 9.4
CVE-2026-18265 OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability 20.08.2026 9.8
CVE-2026-16926 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.1
CVE-2026-15706 Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS 20.08.2026 9.8
CVE-2026-28164 WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability 20.08.2026 9.6
CVE-2025-15688 WordPress Capella theme <= 2.5.5 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2025-15689 WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-66583 WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-66592 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66593 WordPress Security & Malware scan by CleanTalk plugin <= 2.184 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66600 WordPress Media LIbrary Assistant plugin <= 3.39 - Arbitrary File Upload vulnerability 20.08.2026 9.1
CVE-2026-66609 WordPress TheGem (Elementor) theme <= 5.12.3 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66649 WordPress Directory Pro plugin <= 2.5.8 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66672 WordPress Flatastic theme <= 2.0 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-66680 WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66682 WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-68566 WordPress BookingPress Appointment Booking Pro plugin <= 6.0.2 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-73992 WordPress Query Wrangler plugin <= 1.5.57 - Remote Code Execution (RCE) vulnerability 20.08.2026 9.9
CVE-2026-73993 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-74001 WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability 20.08.2026 9.8
CVE-2026-74014 WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-74016 WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-74018 WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-11861 Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships 20.08.2026 9.6
CVE-2026-13097 Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore 21.08.2026 9.1
CVE-2026-14950 Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic 20.08.2026 9.2
CVE-2026-76590 TRENDnet TEW-755AP ssi wan.cgi stack-based overflow 21.08.2026 9.4
CVE-2026-76850 LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector 21.08.2026 9.3
CVE-2026-76310 Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise 21.08.2026 9.4
CVE-2026-76311 Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise 21.08.2026 9.4
CVE-2026-76312 Improper Access Control through Embedded Reports in Splunk Enterprise 21.08.2026 9.4
CVE-2026-76404 Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app 20.08.2026 9.1
CVE-2026-76589 TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow 19.08.2026 9.4
CVE-2026-75595 Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext 20.08.2026 9.1
CVE-2026-76584 TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow 20.08.2026 9.4
CVE-2026-53545 Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection 21.08.2026 9.8
CVE-2026-53546 Termix: Missing authorization in SSH host credential resolution exposes stored credentials 20.08.2026 9.6
CVE-2026-53548 Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users 21.08.2026 9.6
CVE-2026-16894 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16903 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.6
CVE-2026-16913 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16917 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16919 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16882 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16885 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16834 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16839 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.4
CVE-2026-16840 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16845 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16862 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16864 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16872 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-55085 Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite 21.08.2026 9.6
CVE-2026-55089 Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint 19.08.2026 9.9
CVE-2026-16822 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.3
CVE-2026-22306 Critical flaw impacting OZOLS ERP's automatic update channel 19.08.2026 10
CVE-2026-16687 Power System Buffer Overflow 22.08.2026 9.6
CVE-2026-16835 Power System Improper Certificate Validation 22.08.2026 9.6
CVE-2026-18315 TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter 21.08.2026 9.8
CVE-2026-70496 Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork 19.08.2026 9.9
CVE-2025-14600 Admin Account Takeover via Path Traversal in vsDesk 19.08.2026 9.3
CVE-2026-62682 Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) 19.08.2026 9.3
CVE-2026-72717 Orval: Import-time RCE via schema default -> zod module-level template literal 21.08.2026 9.3
CVE-2026-62681 Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) 21.08.2026 9.3
CVE-2026-66794 Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route 21.08.2026 9.3
CVE-2026-71864 Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client 19.08.2026 9.3
CVE-2026-71865 Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli 21.08.2026 9.3
CVE-2026-71866 Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client 19.08.2026 9.3
CVE-2026-71867 Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator 19.08.2026 9.3
CVE-2026-71868 Orval: Import-time RCE via enum-typed default -> zod module-level template literal 21.08.2026 9.3
CVE-2026-71869 Orval: Import-time RCE via array-items default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-71871 Orval: Import-time RCE via header-parameter default -> zod module-level template literal 21.08.2026 9.3
CVE-2026-72716 Orval: Import-time RCE via query-parameter default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-32475 WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability 20.08.2026 9
CVE-2026-71470 Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa 20.08.2026 9.1
CVE-2026-72529 21.08.2026 9.3
CVE-2026-72530 21.08.2026 9.5
CVE-2026-75143 FFmpeg Heap Buffer Overflow via RIST Protocol Reader 21.08.2026 9.3
CVE-2026-20030 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20231 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities 20.08.2026 9.9
CVE-2026-20315 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities 20.08.2026 10
CVE-2026-20317 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities 20.08.2026 10
CVE-2026-20318 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation Vulnerabilities 20.08.2026 9.6
CVE-2026-20357 Cisco Crosswork Security Hardening Release: August 2026 21.08.2026 10
CVE-2026-20358 Cisco Crosswork Security Hardening Release: August 2026 21.08.2026 10
CVE-2026-20359 Cisco Crosswork Security Hardening Release: August 2026 20.08.2026 9.9
CVE-2026-48024 Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager 21.08.2026 9.1
CVE-2026-48162 Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager 19.08.2026 9.1
CVE-2026-49441 Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager 19.08.2026 9.1
CVE-2026-62668 Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols 19.08.2026 9.4
CVE-2026-16656 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16816 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-52889 Formie: Server-Side Template Injection in Formie Hidden field defaults 19.08.2026 9.8
CVE-2026-45272 MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File 19.08.2026 9.4
CVE-2026-47187 SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write 20.08.2026 9.3
CVE-2026-53451 Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution 21.08.2026 9.8
CVE-2026-75949 Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 21.08.2026 10
CVE-2026-75954 Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 21.08.2026 9.3
CVE-2026-15065 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.1
CVE-2026-15068 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-71960 Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT 21.08.2026 9.3
CVE-2024-58376 Renovate 37.158.0 before 37.199.0 Command Injection via helmv3 20.08.2026 9.3
CVE-2026-16019 SQL Injection in Faydam Innovation's FAYDAM Datalogger 20.08.2026 9.8
CVE-2026-75916 SiYuan XSS-to-RCE via unescaped block metadata in hint popup 21.08.2026 9.3
CVE-2026-75917 SiYuan before v3.7.4 XSS-to-RCE via pathName.ts 20.08.2026 9.3
CVE-2026-76213 phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle 19.08.2026 9.1
CVE-2026-76214 phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge 21.08.2026 9.1
CVE-2026-76242 stigmem Federation Peer Registration Authentication Bypass 20.08.2026 9.1
CVE-2026-76243 stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth 19.08.2026 9.2
CVE-2026-76244 stigmem-node Insecure Federation Transport Configuration 19.08.2026 9.1
CVE-2026-74803 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 21.08.2026 10
CVE-2026-74804 Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 21.08.2026 9.3
CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 20.08.2026 9.3
CVE-2026-67364 Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 21.08.2026 10
CVE-2026-66613 WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability 20.08.2026 9.8
CVE-2026-73183 WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73185 WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-73347 WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-73364 WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability 19.08.2026 9.8
CVE-2026-73388 WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73389 WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-73390 WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-73391 WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-76008 Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow 19.08.2026 10
CVE-2026-76003 UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow 21.08.2026 9.4
CVE-2026-76004 UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow 19.08.2026 9.4
CVE-2026-11751 20.08.2026 9.1
CVE-2026-75976 TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow 18.08.2026 9.4
CVE-2026-70905 22.08.2026 9.8
CVE-2026-70920 22.08.2026 9.9
CVE-2026-70921 22.08.2026 10
CVE-2026-70926 22.08.2026 9.8
CVE-2026-70953 22.08.2026 9.8
CVE-2026-70954 22.08.2026 9.8
CVE-2026-70958 22.08.2026 9.6
CVE-2026-70970 20.08.2026 9.8
CVE-2026-70976 22.08.2026 9.1
CVE-2026-70977 22.08.2026 9.1
CVE-2026-70978 22.08.2026 9.1
CVE-2026-70979 22.08.2026 9.1
CVE-2026-70980 19.08.2026 9
CVE-2026-70981 19.08.2026 9.1
CVE-2026-70984 19.08.2026 9.1
CVE-2026-70994 20.08.2026 9.1
CVE-2026-70995 20.08.2026 9.8
CVE-2026-70997 20.08.2026 9.1
CVE-2026-70998 20.08.2026 9.3
CVE-2026-71014 22.08.2026 9.1
CVE-2026-71015 22.08.2026 9.1
CVE-2026-71026 19.08.2026 9.1
CVE-2026-71036 21.08.2026 9.1
CVE-2026-71037 19.08.2026 9.3
CVE-2026-71040 19.08.2026 9.8
CVE-2026-71059 19.08.2026 9.9
CVE-2026-71063 19.08.2026 9.6
CVE-2026-71064 22.08.2026 9.6
CVE-2026-71065 22.08.2026 9.3
CVE-2026-71074 19.08.2026 9.8
CVE-2026-71102 19.08.2026 9.1
CVE-2026-71152 21.08.2026 9.8
CVE-2026-71164 19.08.2026 9.8
CVE-2026-71166 20.08.2026 9.4
CVE-2026-71167 20.08.2026 9.4
CVE-2026-73865 19.08.2026 9.1
CVE-2026-73866 19.08.2026 9.1
CVE-2026-73905 19.08.2026 9.8
CVE-2026-73912 19.08.2026 9.8
CVE-2026-73916 19.08.2026 9.1
CVE-2026-73917 19.08.2026 9.1
CVE-2026-73920 20.08.2026 9.4
CVE-2026-73921 19.08.2026 9.8
CVE-2026-73922 19.08.2026 9.1
CVE-2026-73924 19.08.2026 9.1
CVE-2026-73930 19.08.2026 9.9
CVE-2026-60591 20.08.2026 9.1
CVE-2026-60672 20.08.2026 9.8
CVE-2026-60696 19.08.2026 9.8
CVE-2026-60698 19.08.2026 9.8
CVE-2026-60702 19.08.2026 9.9
CVE-2026-60720 21.08.2026 9.9
CVE-2026-60721 20.08.2026 9.8
CVE-2026-60727 19.08.2026 9.8
CVE-2026-60728 19.08.2026 9.1
CVE-2026-60730 19.08.2026 9.9
CVE-2026-60737 20.08.2026 9.1
CVE-2026-60754 20.08.2026 9.1
CVE-2026-60782 20.08.2026 9.8
CVE-2026-60821 21.08.2026 9.8
CVE-2026-60858 20.08.2026 9.8
CVE-2026-60861 20.08.2026 9.6
CVE-2026-60905 20.08.2026 9.6
CVE-2026-60916 19.08.2026 9.9
CVE-2026-60921 21.08.2026 9.8
CVE-2026-60946 21.08.2026 9.8
CVE-2026-60947 21.08.2026 9.8
CVE-2026-60958 21.08.2026 9.8
CVE-2026-60970 21.08.2026 9.8
CVE-2026-60971 21.08.2026 9.8
CVE-2026-60977 21.08.2026 9.8
CVE-2026-60990 21.08.2026 9.9
CVE-2026-60995 21.08.2026 9.9
CVE-2026-61001 21.08.2026 9.6
CVE-2026-61003 21.08.2026 9.9
CVE-2026-61008 20.08.2026 9.1
CVE-2026-61018 21.08.2026 9.8
CVE-2026-61021 20.08.2026 9.9
CVE-2026-61029 20.08.2026 9
CVE-2026-61034 20.08.2026 9.1
CVE-2026-61066 21.08.2026 9.9
CVE-2026-61206 21.08.2026 9.9
CVE-2026-61241 21.08.2026 10
CVE-2026-61248 21.08.2026 9.9
CVE-2026-61258 21.08.2026 9.8
CVE-2026-61272 21.08.2026 9.8
CVE-2026-61317 20.08.2026 9.9
CVE-2026-61318 20.08.2026 9.8
CVE-2026-62452 19.08.2026 9.9
CVE-2026-62457 18.08.2026 9.8
CVE-2026-62463 18.08.2026 9.6
CVE-2026-62512 21.08.2026 9.9
CVE-2026-62539 18.08.2026 9.8
CVE-2026-62541 18.08.2026 9.8
CVE-2026-62543 18.08.2026 9.8
CVE-2026-62544 18.08.2026 9.8
CVE-2026-62582 18.08.2026 9.6
CVE-2026-62585 21.08.2026 9.8
CVE-2026-62588 20.08.2026 9.9
CVE-2026-62592 20.08.2026 9.8
CVE-2026-62608 18.08.2026 9.9
CVE-2026-62609 18.08.2026 9.8
CVE-2026-62610 18.08.2026 9.1
CVE-2026-62611 18.08.2026 9.8
CVE-2026-62613 18.08.2026 9.3
CVE-2026-62614 18.08.2026 9.8
CVE-2026-62617 18.08.2026 9.8
CVE-2026-62618 18.08.2026 9.3
CVE-2026-62621 18.08.2026 9.8
CVE-2026-62622 18.08.2026 9.8
CVE-2026-62624 18.08.2026 9.8
CVE-2026-62626 18.08.2026 9.8
CVE-2026-62629 18.08.2026 9.4
CVE-2026-62630 18.08.2026 9.8
CVE-2026-62632 18.08.2026 9.8
CVE-2026-62633 18.08.2026 9.8
CVE-2026-62634 18.08.2026 9.8
CVE-2026-62635 18.08.2026 9.8
CVE-2026-62637 18.08.2026 9.3
CVE-2026-62638 18.08.2026 9.1
CVE-2026-62639 18.08.2026 9.8
CVE-2026-62640 18.08.2026 9.8
CVE-2026-70668 18.08.2026 9.1
CVE-2026-70669 18.08.2026 9.8
CVE-2026-70670 18.08.2026 9.6
CVE-2026-70673 18.08.2026 9.3
CVE-2026-70689 18.08.2026 9.8
CVE-2026-70730 18.08.2026 9.1
CVE-2026-70739 18.08.2026 9.8
CVE-2026-70740 18.08.2026 9.8
CVE-2026-70741 18.08.2026 9.1
CVE-2026-70745 18.08.2026 9.8
CVE-2026-70817 18.08.2026 9.8
CVE-2026-70846 18.08.2026 9.6
CVE-2026-70854 18.08.2026 9.1
CVE-2026-70855 18.08.2026 9.3
CVE-2026-70862 18.08.2026 9.1
CVE-2026-70871 18.08.2026 9.8
CVE-2026-70872 18.08.2026 9.1
CVE-2026-70873 18.08.2026 9.8
CVE-2026-70876 18.08.2026 9.1
CVE-2026-70880 18.08.2026 10
CVE-2026-70883 18.08.2026 9.1
CVE-2026-70884 18.08.2026 9.1
CVE-2026-62988 Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints 21.08.2026 9
CVE-2026-67443 FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) 21.08.2026 9.2
CVE-2026-75877 TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow 19.08.2026 9.4
CVE-2026-52735 ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser 18.08.2026 9.3
CVE-2026-55166 Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR 18.08.2026 9.9
CVE-2026-47627 20.08.2026 9.8
CVE-2026-50161 libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow 19.08.2026 9.3
CVE-2026-75625 Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass 18.08.2026 9.1
CVE-2026-71878 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.2
CVE-2026-71879 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.1
CVE-2026-66780 Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace 18.08.2026 9.9
CVE-2026-18963 Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass 20.08.2026 9.1
CVE-2026-57580 authentik: Account Takeover via SAML NameID Comment Truncation 18.08.2026 9.4
CVE-2026-52723 ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust 18.08.2026 9.1
CVE-2026-67271 19.08.2026 9.8
CVE-2026-45118 MyBB: Contact page reflected XSS 18.08.2026 9.3
CVE-2026-12564 Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf 18.08.2026 9.6
CVE-2026-45117 MyBB: Installer database configuration RCE 18.08.2026 9.8
CVE-2026-75926 Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant 20.08.2026 9.3
CVE-2026-75856 CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU 18.08.2026 9.2
CVE-2026-59940 Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization 18.08.2026 9.8
CVE-2026-32470 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-32474 WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-66627 WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-73187 WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73339 WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73341 WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73343 WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability 18.08.2026 10
CVE-2026-73355 WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73365 WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73366 WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73376 WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73380 WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73381 WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability 18.08.2026 9.1
CVE-2026-73392 WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73397 WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability 18.08.2026 9.8
CVE-2026-73996 WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability 18.08.2026 9.8
CVE-2026-74015 WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-75784 TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow 20.08.2026 10
CVE-2026-28192 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability 18.08.2026 9.6
CVE-2026-32444 WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability 18.08.2026 9.9
CVE-2026-32463 WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-75783 TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow 18.08.2026 9.4
CVE-2026-74902 SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload 18.08.2026 9.3
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log 19.08.2026 9.3
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass 18.08.2026 9.3
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass 19.08.2026 9.3
CVE-2026-75835 Grav API Plugin before 1.0.14 Missing Authorization 18.08.2026 9.3
CVE-2026-75837 Grav before 2.0.14 Privilege Escalation via Group Access Field 19.08.2026 9.3
CVE-2026-75843 ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction 18.08.2026 9.4
CVE-2026-75851 ArcadeDB before 26.8.1 Authentication Bypass via Async Command 18.08.2026 9.4
CVE-2026-75852 ArcadeDB MongoDB wire protocol authentication bypass cross-database 18.08.2026 9.3
CVE-2026-75854 ArcadeDB Redis Wire-Protocol Plugin Missing Authentication 18.08.2026 9.3
CVE-2026-75626 SpiderFoot Stored Cross-Site Scripting via Correlation Titles 19.08.2026 9.3
CVE-2026-75627 Bastillion Authentication Bypass via Path-Prefix Routing Mismatch 18.08.2026 9.3
CVE-2026-15748 Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration 18.08.2026 9.8
CVE-2026-75094 COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection 18.08.2026 9.4
CVE-2026-71424 Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers 18.08.2026 9.6
CVE-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) 20.08.2026 9.3
CVE-2026-47686 vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE 19.08.2026 9.9
CVE-2026-47698 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators 19.08.2026 9.8
CVE-2026-65974 ERPNext: Server-Side Template Injection leading to Remote Code Execution 18.08.2026 9.9
CVE-2026-66795 Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does not validate certificate subject, signername, or requester identity 18.08.2026 9.1
CVE-2026-75106 OpnForm Editable Submission Secret Derivation via Empty Hashids Salt 21.08.2026 9.3
CVE-2026-75110 MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET 18.08.2026 9.3
CVE-2026-19478 Improper Control of Generation of Code ('Code Injection') in GitLab 17.08.2026 9.4
CVE-2026-71472 Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem 20.08.2026 9.1
CVE-2026-66792 Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clusters 20.08.2026 9.9
CVE-2026-74253 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 17.08.2026 10
CVE-2026-74254 Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 18.08.2026 9.3
CVE-2026-71479 New API: Integer overflow in quota billing yields negative charges (self-crediting) 17.08.2026 9.1
CVE-2026-75045 18.08.2026 9.1
CVE-2026-64859 New API: User List API Leaks Root User Access Token Leading to Privilege Escalation 17.08.2026 9.1
CVE-2026-55674 Discourse: Cache poisoning/XSS via color scheme cookies 18.08.2026 9.3
CVE-2026-71566 KubeVirt backend is not authenticated 17.08.2026 9.3
CVE-2026-14564 Sensitive Data Exposure in Innotim Software's Logsign SIEM 17.08.2026 9
CVE-2026-74843 Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow 17.08.2026 10
CVE-2026-74798 SiYuan kernel Path Traversal via database_clean MCP tool 18.08.2026 9.3
CVE-2026-74799 SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure 17.08.2026 9.2
CVE-2026-74800 SiYuan before v3.7.4 Stored XSS via assets endpoint 17.08.2026 9.4
CVE-2026-74872 openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool 18.08.2026 9.3
CVE-2026-74875 openssl_encrypt before 1.4.0 Schema Validation Bypass 17.08.2026 9.3
CVE-2026-74876 openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption 17.08.2026 9.3
CVE-2026-74878 openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass 17.08.2026 9.3
CVE-2026-74880 openssl_encrypt before 1.4.0 Token Leakage via Query Parameters 17.08.2026 9.3
CVE-2026-74885 openssl_encrypt before 1.4.0 Logging Bug and Race Condition 17.08.2026 9.3
CVE-2026-74886 openssl_encrypt before 1.4.0 Plugin Import Guard Bypass 17.08.2026 9.3
CVE-2026-74887 openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module 18.08.2026 9.3
CVE-2026-74889 openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF 17.08.2026 9.3
CVE-2026-74890 openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable 17.08.2026 9.3
CVE-2026-74894 openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token 17.08.2026 9.3
CVE-2026-74895 openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation 17.08.2026 9.3
CVE-2026-74896 openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal 17.08.2026 9.3
CVE-2026-74899 openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy 18.08.2026 9.3
CVE-2026-74900 openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode 17.08.2026 9.3
CVE-2026-74901 openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback 17.08.2026 9.3
CVE-2026-15623 Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service 17.08.2026 9.4
CVE-2026-19977 EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication 18.08.2026 10
CVE-2026-19961 Edimax EW-7478APC formWlSiteSurvey buffer overflow 17.08.2026 9.4
CVE-2026-19959 Edimax EW-7478APC formWanTcpipSetup stack-based overflow 18.08.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-4671 justhtml before 1.18.0 Denial of Service via CSS Selector 23.08.2026
CVE-2026-5388 justhtml before 1.15.0 Multiple Security Issues 23.08.2026
CVE-2026-5389 justhtml before 1.13.0 XSS via code fence breakout 23.08.2026
CVE-2026-5751 justhtml before 1.14.0 Mutation XSS via custom sanitization policies 23.08.2026
CVE-2026-6827 justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities 23.08.2026
CVE-2026-74793 justhtml before 3.11.0 XSS via selectedcontent projection 23.08.2026
CVE-2026-77088 justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span 23.08.2026
CVE-2026-7808 justhtml before 1.16.0 Multiple Security Issues via Sanitization 23.08.2026
CVE-2026-8445 justhtml before 1.12.0 Sanitizer Bypass via Markdown 23.08.2026
CVE-2026-8630 justhtml before 1.12.0 Mutation XSS via Raw Text Elements 23.08.2026
CVE-2026-9769 justhtml before 1.10.0 Denial of Service via deeply nested HTML 23.08.2026
CVE-2026-78115 SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization 23.08.2026
CVE-2026-10053 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab 23.08.2026 8.5
CVE-2026-78112 itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection 23.08.2026
CVE-2026-78155 Untrusted Search Path in StackGres 23.08.2026 9.9
CVE-2026-13598 RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator 23.08.2026
CVE-2026-14853 WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization 23.08.2026
CVE-2026-77003 Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_mask 23.08.2026
CVE-2026-77115 Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters 23.08.2026
CVE-2026-77116 Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview 23.08.2026
CVE-2026-78063 Tenda CH22 editFileName formeditFileName command injection 23.08.2026
CVE-2026-78062 vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials 23.08.2026
CVE-2026-78060 SourceCodester Stock Management System getOrderReport.php cross site scripting 23.08.2026
CVE-2026-78061 vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery 23.08.2026
CVE-2026-78059 SourceCodester Stock Management System printOrder.php cross site scripting 23.08.2026
CVE-2026-78057 sambitraj Student-Management-System Management Mutation sql injection 23.08.2026
CVE-2026-78056 sambitraj Student-Management-System Dashboard sql injection 23.08.2026
CVE-2026-78055 SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting 23.08.2026
CVE-2026-78136 23.08.2026 7.8
CVE-2026-78054 SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting 23.08.2026
CVE-2026-0551 PPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_roles 22.08.2026 8.8
CVE-2026-16149 Security Hardener <= 2.4.4 - Authenticated (Subscriber+) Privilege Escalation via REST API '/wp/v2/users' permission_callback Overwrite 22.08.2026 8.8
CVE-2026-18027 WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter 22.08.2026 6.5
CVE-2026-78051 alexta69 MeTube Cookie File cookies.txt file access 22.08.2026
CVE-2026-5723 22.08.2026
CVE-2026-78050 Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow 22.08.2026
CVE-2026-78122 docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems 22.08.2026
CVE-2026-19684 22.08.2026
CVE-2026-78049 Systerel S2OPC AddNodes Service sopc_node_mgt_helper_internal.c out-of-bounds 22.08.2026
CVE-2026-47895 23.08.2026 7.5