| CVE-2026-65321 |
PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS |
02.08.2026 |
9.3 |
| CVE-2025-71401 |
better-auth before 1.4.1 basePath Modification DoS |
02.08.2026 |
9.3 |
| CVE-2026-68582 |
Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token |
02.08.2026 |
9.3 |
| CVE-2026-8457 |
WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT |
01.08.2026 |
9.8 |
| CVE-2026-66402 |
FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass |
01.08.2026 |
9.3 |
| CVE-2026-67289 |
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection |
01.08.2026 |
9.3 |
| CVE-2026-67292 |
FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure |
01.08.2026 |
9.3 |
| CVE-2026-67293 |
FreeRDP before 3.29.0 Improper Certificate Hostname Validation |
01.08.2026 |
9.3 |
| CVE-2026-67294 |
FreeRDP before 3.29.0 TLS Certificate EKU Bypass |
01.08.2026 |
9.3 |
| CVE-2026-67305 |
FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr |
01.08.2026 |
9.4 |
| CVE-2026-67308 |
Wazuh GitHub Actions Shell Injection via Fork Pull Request |
02.08.2026 |
9.3 |
| CVE-2026-67324 |
GitPython 3.1.50 Authentication Bypass via Joined Short Options |
01.08.2026 |
9.3 |
| CVE-2026-67330 |
better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision |
01.08.2026 |
9.4 |
| CVE-2026-67336 |
better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider |
01.08.2026 |
9.4 |
| CVE-2026-67340 |
ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts |
01.08.2026 |
9.3 |
| CVE-2026-67341 |
ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION |
01.08.2026 |
9.3 |
| CVE-2026-67342 |
ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers |
01.08.2026 |
9.3 |
| CVE-2026-15964 |
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change |
01.08.2026 |
9.8 |
| CVE-2026-3141 |
FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter |
01.08.2026 |
9.1 |
| CVE-2026-68771 |
ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization |
31.07.2026 |
9.3 |
| CVE-2026-68770 |
sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False |
31.07.2026 |
9.3 |
| CVE-2026-54725 |
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API |
31.07.2026 |
9.6 |
| CVE-2026-52855 |
Wings exposes node configuration secrets through egg configuration-file templating |
31.07.2026 |
9.9 |
| CVE-2026-58048 |
|
01.08.2026 |
9.4 |
| CVE-2026-17349 |
pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner |
01.08.2026 |
9.3 |
| CVE-2026-17351 |
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) |
01.08.2026 |
9.4 |
| CVE-2026-17566 |
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) |
01.08.2026 |
9.4 |
| CVE-2026-17561 |
Unauthenticated RCE in Innotim Software's Logsign SIEM |
31.07.2026 |
9.8 |
| CVE-2025-67649 |
Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script |
31.07.2026 |
9.3 |
| CVE-2026-14483 |
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command |
31.07.2026 |
9.8 |
| CVE-2026-18452 |
Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials |
31.07.2026 |
10 |
| CVE-2026-63221 |
CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions |
31.07.2026 |
9.4 |
| CVE-2026-63223 |
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules |
31.07.2026 |
9.8 |
| CVE-2026-66418 |
OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field |
31.07.2026 |
9.3 |
| CVE-2026-68502 |
LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE |
31.07.2026 |
9.8 |
| CVE-2026-68503 |
LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard |
31.07.2026 |
9.8 |
| CVE-2026-66803 |
Azure Cosmos DB Remote Code Execution Vulnerability |
31.07.2026 |
10 |
| CVE-2026-12946 |
Remote Code Execution in CUGA Component CodeAgent |
31.07.2026 |
9.9 |
| CVE-2026-67208 |
Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console |
31.07.2026 |
9.3 |
| CVE-2026-67594 |
Spikster Missing Authentication via API Route Group |
31.07.2026 |
9.3 |
| CVE-2026-66066 |
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing |
01.08.2026 |
9.5 |
| CVE-2026-12943 |
This Power Hardware Management Console update is being released to address |
31.07.2026 |
9.8 |
| CVE-2026-12118 |
IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data |
30.07.2026 |
9.8 |
| CVE-2026-13435 |
Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure |
31.07.2026 |
9.9 |
| CVE-2026-48499 |
Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache |
30.07.2026 |
9.3 |
| CVE-2026-12940 |
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints |
31.07.2026 |
9.8 |
| CVE-2026-28323 |
SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability |
31.07.2026 |
9.8 |
| CVE-2026-4978 |
SQLi in UMAI Vision's Traffic Analysis System |
30.07.2026 |
9.8 |
| CVE-2026-11707 |
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager |
30.07.2026 |
9.3 |
| CVE-2026-15435 |
IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability |
31.07.2026 |
9.8 |
| CVE-2026-53431 |
Boruta accepts expired JWT client assertions due to missing exp claim validation |
31.07.2026 |
9.1 |
| CVE-2026-47876 |
VMXNET3 out-of-bounds write vulnerability |
30.07.2026 |
9.3 |
| CVE-2026-54363 |
CentreStack < 17.5 Hardcoded Key Token Forgery RCE |
30.07.2026 |
9.3 |
| CVE-2026-59309 |
vCenter authentication-bypass vulnerability |
30.07.2026 |
9.8 |
| CVE-2026-59310 |
vCenter directory-traversal vulnerability |
30.07.2026 |
9.8 |
| CVE-2026-18363 |
Weak password recovery mechanism in osTicket by Enhancesoft LLC |
30.07.2026 |
9.1 |
| CVE-2026-44090 |
Missing authentication for MQTT Broker |
30.07.2026 |
9.3 |
| CVE-2026-44101 |
OCPP reconfiguration vulnerability |
31.07.2026 |
9.3 |
| CVE-2026-44104 |
ControllerAgent does not perform validation of firmware |
30.07.2026 |
9.3 |
| CVE-2026-44108 |
Firewall bypass during shutdown |
30.07.2026 |
9.3 |
| CVE-2026-7849 |
Command Injection in SCM (idledisconnect parameter) |
30.07.2026 |
9.3 |
| CVE-2026-58046 |
|
30.07.2026 |
9.9 |
| CVE-2026-58066 |
|
31.07.2026 |
9.8 |
| CVE-2026-16610 |
Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key |
30.07.2026 |
9.8 |
| CVE-2026-48449 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
30.07.2026 |
10 |
| CVE-2026-67595 |
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php |
30.07.2026 |
9.2 |
| CVE-2026-16326 |
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode |
29.07.2026 |
10 |
| CVE-2026-67426 |
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration |
29.07.2026 |
9.3 |
| CVE-2026-67429 |
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) |
29.07.2026 |
10 |
| CVE-2026-14529 |
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery |
30.07.2026 |
9.4 |
| CVE-2026-18236 |
Google-ADK Continuation Forgery |
29.07.2026 |
9.3 |
| CVE-2026-41939 |
Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly |
30.07.2026 |
9.3 |
| CVE-2026-54680 |
Logging operator has Fluentd configuration injection that allows remote code execution |
30.07.2026 |
9.9 |
| CVE-2026-8338 |
Authentication and Authorization Bypass in Coverity Connect |
29.07.2026 |
9.2 |
| CVE-2026-54735 |
prebid-server's request forgery vulnerability allows for possible host environment data extraction |
29.07.2026 |
10 |
| CVE-2026-60112 |
AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() |
29.07.2026 |
9.3 |
| CVE-2026-60113 |
AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes |
30.07.2026 |
9.3 |
| CVE-2026-67191 |
Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser |
29.07.2026 |
9.3 |
| CVE-2026-67192 |
Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher |
29.07.2026 |
9.2 |
| CVE-2026-65886 |
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 |
29.07.2026 |
9.2 |
| CVE-2026-65887 |
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 |
01.08.2026 |
10 |
| CVE-2026-65888 |
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 |
01.08.2026 |
10 |
| CVE-2026-65889 |
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2 |
29.07.2026 |
9.2 |
| CVE-2026-65890 |
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 |
29.07.2026 |
9.2 |
| CVE-2026-9177 |
Server-Side Template Injection in SecureTransport's Apache Velocity mail templates |
31.07.2026 |
9.4 |
| CVE-2026-0667 |
|
29.07.2026 |
9.3 |
| CVE-2026-65884 |
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 |
30.07.2026 |
10 |
| CVE-2026-65885 |
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 |
30.07.2026 |
9.4 |
| CVE-2026-14488 |
Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter |
29.07.2026 |
9.1 |
| CVE-2026-14900 |
Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter |
29.07.2026 |
9.8 |
| CVE-2026-65883 |
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 |
29.07.2026 |
10 |
| CVE-2025-10656 |
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation |
29.07.2026 |
9.8 |
| CVE-2026-58161 |
Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server |
29.07.2026 |
9.2 |
| CVE-2026-58179 |
Apache Traffic Server: regex_remap plugin overflows the stack from attacker input |
30.07.2026 |
9.2 |
| CVE-2026-58154 |
Apache Traffic Server: Memory-safety errors in MIME and header parsing |
29.07.2026 |
9.2 |
| CVE-2026-58155 |
Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling |
29.07.2026 |
9.2 |
| CVE-2026-18191 |
Vacron|IP Camera - Hidden Functionality |
29.07.2026 |
9.3 |
| CVE-2026-63227 |
Unrestricted SCORM file upload vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-63229 |
Pre-authentication blind SQL injection vulnerability |
29.07.2026 |
9.1 |
| CVE-2026-63230 |
Pre-authentication error-based SQL injection vulnerability |
29.07.2026 |
9.1 |
| CVE-2026-63232 |
SQL injection and unsafe deserialisation vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-63233 |
SQL injection and unsafe deserialisation vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-63234 |
SQL injection and unsafe deserialisation vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-18072 |
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter |
29.07.2026 |
9.8 |
| CVE-2026-54658 |
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution |
29.07.2026 |
9.8 |
| CVE-2026-62325 |
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) |
29.07.2026 |
9.1 |
| CVE-2026-64863 |
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite |
29.07.2026 |
9.1 |
| CVE-2026-14446 |
IBM WebSphere Application Server is affected by a privilege escalation |
30.07.2026 |
9.8 |
| CVE-2026-14512 |
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information |
30.07.2026 |
9.8 |
| CVE-2026-14958 |
OS command injection in IBM Aspera Faspex |
30.07.2026 |
9.1 |
| CVE-2026-14959 |
OS Command Injection in IBM Aspera Faspex |
30.07.2026 |
9.1 |
| CVE-2026-14973 |
Path Traversal in IBM Desktop App |
31.07.2026 |
9.3 |
| CVE-2026-6881 |
Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance |
29.07.2026 |
9.4 |
| CVE-2026-16498 |
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode |
28.07.2026 |
10 |
| CVE-2026-50736 |
|
28.07.2026 |
9 |
| CVE-2026-50737 |
|
28.07.2026 |
9 |
| CVE-2026-67174 |
DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick |
28.07.2026 |
9.2 |
| CVE-2026-65880 |
Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 |
28.07.2026 |
10 |
| CVE-2026-11841 |
CVE-2026-11841 |
28.07.2026 |
9.4 |
| CVE-2026-16462 |
SQL injection via unauthenticated GetGridData endpoint |
28.07.2026 |
9.3 |
| CVE-2026-11756 |
Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x |
28.07.2026 |
10 |
| CVE-2026-15014 |
SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter |
28.07.2026 |
9.8 |
| CVE-2026-64541 |
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket |
30.07.2026 |
9.8 |
| CVE-2026-64551 |
sctp: validate STALE_COOKIE cause length before reading staleness |
30.07.2026 |
9.1 |
| CVE-2026-66824 |
Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding |
28.07.2026 |
9.2 |
| CVE-2026-48030 |
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78) |
27.07.2026 |
9.9 |
| CVE-2026-55579 |
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise |
27.07.2026 |
9.8 |
| CVE-2026-63077 |
|
28.07.2026 |
9.8 |
| CVE-2026-16812 |
VeloCloud Orchestrator OS Command Injection |
28.07.2026 |
10 |
| CVE-2026-66394 |
SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass |
28.07.2026 |
9.3 |
| CVE-2026-66395 |
SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol |
28.07.2026 |
9.4 |
| CVE-2026-66396 |
SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL |
28.07.2026 |
9.3 |
| CVE-2026-66398 |
phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API |
28.07.2026 |
9.4 |
| CVE-2026-55953 |
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication |
28.07.2026 |
9.1 |
| CVE-2026-59527 |
WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59533 |
WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59538 |
WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59549 |
WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59550 |
WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-61511 |
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php |
29.07.2026 |
9.3 |
| CVE-2026-65766 |
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 |
28.07.2026 |
9.2 |
| CVE-2026-65876 |
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 |
28.07.2026 |
9.2 |
| CVE-2026-48144 |
Apache Thrift: c_glib TLS Client Missing Hostname Verification |
28.07.2026 |
9.1 |
| CVE-2026-55971 |
Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() |
28.07.2026 |
9.3 |
| CVE-2026-64534 |
nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path |
30.07.2026 |
9.8 |
| CVE-2026-64535 |
nvmet-tcp: Fix potential UAF when ddgst mismatch |
30.07.2026 |
9.8 |