CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-66659 WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability 12.08.2026 9.3
CVE-2026-70398 Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace 12.08.2026 9.6
CVE-2026-72526 Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation 12.08.2026 9.9
CVE-2026-5917 libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend 11.08.2026 9.4
CVE-2026-67568 Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials 11.08.2026 9.3
CVE-2026-68067 Mira Hormone Monitor, Mira Android App Weak Authentication 11.08.2026 9.3
CVE-2026-48765 TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding 11.08.2026 9.9
CVE-2026-16230 Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field 11.08.2026 9.8
CVE-2026-45618 LiquidJS is Vulnerable to Remote Code Execution 11.08.2026 10
CVE-2026-73034 DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header 11.08.2026 9.3
CVE-2026-73032 PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() 11.08.2026 9.4
CVE-2026-18691 Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure 11.08.2026 9
CVE-2026-72742 DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing 11.08.2026 9.2
CVE-2026-69102 MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust 11.08.2026 9.3
CVE-2026-27302 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 11.08.2026 10
CVE-2026-48381 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 11.08.2026 9
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) 12.08.2026 9.1
CVE-2026-71398 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 11.08.2026 10
CVE-2026-47705 TypeBot vulnerable to CSV injection in result export 11.08.2026 9.6
CVE-2026-73090 PeerTube: Cross-origin remote video takeover via Update activity 11.08.2026 9.3
CVE-2026-73211 PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() 11.08.2026 9.8
CVE-2026-12571 Authentication Bypass Leading to Account Takeover 12.08.2026 9.8
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 12.08.2026 9.4
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability 12.08.2026 9.3
CVE-2026-48362 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 12.08.2026 10
CVE-2026-71384 ColdFusion | Incorrect Authorization (CWE-863) 11.08.2026 9.6
CVE-2026-73080 SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle 11.08.2026 9.3
CVE-2025-31114 Fooocus webui vulnerable to Remote Code Execution 11.08.2026 9.3
CVE-2026-73069 Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution 11.08.2026 9.1
CVE-2026-17061 Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 11.08.2026 10
CVE-2026-47702 TypeBot API tokens stored in plaintext 11.08.2026 9.1
CVE-2026-72920 SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control 11.08.2026 9.8
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection 11.08.2026 9.8
CVE-2026-48056 Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler 11.08.2026 10
CVE-2026-48046 Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler 11.08.2026 9.3
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability 11.08.2026 9.6
CVE-2026-58115 11.08.2026 10
CVE-2026-72785 Craft CMS before 5.10.6 Authorization Bypass via structures/move-element 11.08.2026 9.3
CVE-2026-13737 Command Restriction Bypass 11.08.2026 9.2
CVE-2026-13738 Improper Authorization Validation 11.08.2026 9.2
CVE-2026-72550 Friendica Friendica - SQL Injection 11.08.2026 9.8
CVE-2026-72599 e107 e107 - SQL Injection 11.08.2026 9.8
CVE-2026-72603 wg-easy wg-easy - OS Command Injection 11.08.2026 9.9
CVE-2026-58231 Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) 12.08.2026 10
CVE-2026-10579 Picketlink-federation: auth bypass in picketlink saml unsolicited-response 11.08.2026 9.8
CVE-2026-13716 Path Traversal: '.../...//' in Crafty Controller 11.08.2026 9.1
CVE-2026-19516 CVE-2026-19516 CVE Record 11.08.2026 9.1
CVE-2026-19425 Win Men Intermational|Travel Agency Management System - SQL Injection 11.08.2026 9.3
CVE-2026-34265 Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform 12.08.2026 9.8
CVE-2026-44758 Code Injection vulnerability in Manufacturing Integration and Intelligence 11.08.2026 9.1
CVE-2026-48161 react18-use was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-48160 react-tracked was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation 10.08.2026 9.9
CVE-2026-14450 Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication 11.08.2026 9.9
CVE-2026-18948 Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server 11.08.2026 9.9
CVE-2026-72904 Firecrawl: Arbitrary file read via JSON Schema $ref expansion 11.08.2026 9.3
CVE-2026-72901 Dokploy: Remote Code Execution via volume-backup 10.08.2026 9.9
CVE-2026-72902 Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById 10.08.2026 9.9
CVE-2025-13293 Backdoor / default root credentials 10.08.2026 9.3
CVE-2025-13294 Unauthenticated SQL Injection 10.08.2026 9.3
CVE-2025-15681 Insufficient Webserver Authentication 10.08.2026 9.2
CVE-2026-72880 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` 11.08.2026 9.9
CVE-2026-72882 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers 10.08.2026 9.9
CVE-2026-72886 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) 10.08.2026 9.9
CVE-2026-72876 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* 10.08.2026 9.9
CVE-2026-72877 Dokploy: Command Injection via dockerImage in buildRemoteDocker 10.08.2026 9.6
CVE-2026-72878 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments 10.08.2026 9.6
CVE-2026-72879 Dokploy: Command Injection via Registry Credentials in Swarm Upload 11.08.2026 9.4
CVE-2026-72864 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) 11.08.2026 9.9
CVE-2026-72865 Dokploy: OS Command Injection via compose `composePath` 11.08.2026 9.9
CVE-2026-72867 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) 10.08.2026 9.9
CVE-2026-72868 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection 10.08.2026 9.9
CVE-2026-72869 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE 11.08.2026 9.9
CVE-2026-72872 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` 10.08.2026 9.9
CVE-2026-72863 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host 10.08.2026 9.9
CVE-2026-16626 JasperReports Server: XXE Injection Vulnerability (Unauthenticated) 11.08.2026 9.3
CVE-2026-48159 use-reducer-async was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72740 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` 10.08.2026 9.9
CVE-2026-72862 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE 10.08.2026 9.9
CVE-2026-72898 Metabase SQL injection via password reset endpoint 12.08.2026 10
CVE-2026-72899 Metabase SQL injection via public card or dashboard 11.08.2026 10
CVE-2026-72735 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution 10.08.2026 9.9
CVE-2026-72736 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE 10.08.2026 9.9
CVE-2026-72737 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups 10.08.2026 9.6
CVE-2026-72738 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter 10.08.2026 9.9
CVE-2026-72733 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore 10.08.2026 9.9
CVE-2026-48158 use-context-selector was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-47754 unauthenticated path traversal in Metacat 2.x 10.08.2026 9.3
CVE-2026-63106 ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php 10.08.2026 9.3
CVE-2026-13206 Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection 10.08.2026 9.8
CVE-2026-19429 Jenkins - FilePath.untarFrom() Symlink Target Validation Bypass and Blank-Name Check Bypass (Arbitrary File Read) 11.08.2026 9.4
CVE-2026-72564 fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication 10.08.2026 9.6
CVE-2026-72565 Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass 10.08.2026 9.8
CVE-2026-72567 deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete 10.08.2026 9.8
CVE-2026-72569 cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion 10.08.2026 9.1
CVE-2026-72575 daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects 10.08.2026 9.1
CVE-2026-72577 NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection 10.08.2026 9.8
CVE-2026-72580 duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints 10.08.2026 9.8
CVE-2026-72589 alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field 10.08.2026 9.8
CVE-2026-72590 alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter 10.08.2026 9.8
CVE-2026-72592 dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload 10.08.2026 9.8
CVE-2026-72593 dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access 10.08.2026 9.8
CVE-2026-66915 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.7 10.08.2026 10
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 10.08.2026 9.3
CVE-2026-71992 MSI Radix AXE6600 v781521 Command Injection via macfilter 10.08.2026 9.3
CVE-2026-71993 MSI Radix AXE6600 v781521 Command Injection via openvpn function 11.08.2026 9.3
CVE-2026-71991 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 08.08.2026 9.3
CVE-2026-71986 MSI Radix AXE6600 v781521 Command Injection via dmz Function 08.08.2026 9.3
CVE-2026-71987 MSI Radix AXE6600 v781521 Command Injection via alg function 10.08.2026 9.3
CVE-2026-71988 MSI Radix AXE6600 v781521 Command Injection via portFw function 11.08.2026 9.3
CVE-2026-71989 MSI Radix AXE6600 v781521 Command Injection via porTrigger function 10.08.2026 9.3
CVE-2026-71990 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 11.08.2026 9.3
CVE-2026-71984 MSI Radix AXE6600 v781521 Command Injection via urlfilter 10.08.2026 9.3
CVE-2026-71985 MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function 11.08.2026 9.3
CVE-2026-71983 MSI Radix AXE6600 v781521 Command Injection via wps.cgi 11.08.2026 9.3
CVE-2026-71956 D-Link DWR-M961 Command Injection via app.cgi 11.08.2026 9.3
CVE-2026-71957 D-Link DWR-M961 Buffer Overflow via app.cgi 08.08.2026 9.3
CVE-2026-71958 D-Link DWR-M961 Buffer Overflow via quicksetup.cgi 10.08.2026 9.3
CVE-2026-71944 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel 11.08.2026 9.3
CVE-2026-71945 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom 10.08.2026 9.3
CVE-2026-71946 D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun 11.08.2026 9.3
CVE-2026-71947 D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun 08.08.2026 9.3
CVE-2026-71948 D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun 10.08.2026 9.3
CVE-2026-71949 D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup 11.08.2026 9.3
CVE-2026-71950 D-Link DWR-M961 Command Injection via /boafrm/formSmsManage 10.08.2026 9.3
CVE-2026-71951 D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup 11.08.2026 9.3
CVE-2026-71952 D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup 08.08.2026 9.3
CVE-2026-71953 D-Link DWR-M961 Command Injection via /boafrm/formNtp 10.08.2026 9.3
CVE-2026-71954 D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup 11.08.2026 9.3
CVE-2026-71955 D-Link DWR-M961 Command Injection via /boafrm/formWsc 10.08.2026 9.3
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route 11.08.2026 9.8
CVE-2026-46409 OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution 11.08.2026 9.6
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs 10.08.2026 9.2
CVE-2026-48170 scimPatch vulnerable to prototype pollution via unfiltered keys in patch 10.08.2026 9.1
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading 07.08.2026 9.6
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration 10.08.2026 9.8
CVE-2026-48039 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 07.08.2026 9.1
CVE-2026-71851 crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain 08.08.2026 9
CVE-2026-64637 07.08.2026 9.9
CVE-2022-4995 Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp 07.08.2026 9.3
CVE-2026-19264 Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover 07.08.2026 9.3
CVE-2026-66914 Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 10.08.2026 9.2
CVE-2026-54203 TeamDavid: Memory Leak leaking sensitive information 10.08.2026 9.2
CVE-2026-54210 TeamDavid: Buffer Overflow in file names of file upload functionalities 07.08.2026 9.5
CVE-2026-54211 TeamDavid: Buffer Overflow in multiple form data parameters 07.08.2026 9.5
CVE-2026-54212 TeamDavid: Buffer Overflow in JSON-parsing 07.08.2026 9.5
CVE-2026-54213 TeamDavid: Denial of Service via endpoint 'internalRestart' 07.08.2026 9.2
CVE-2026-14364 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' 07.08.2026 9.8
CVE-2026-14365 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' 07.08.2026 9.8
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability 11.08.2026 9.9
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability 11.08.2026 9.9
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability 12.08.2026 9.6
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability 12.08.2026 10
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability 11.08.2026 9.9
CVE-2026-59118 Copilot Cowork Elevation of Privilege Vulnerability 12.08.2026 9.3
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability 12.08.2026 9.9
CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability 11.08.2026 9.8
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability 11.08.2026 9.6
CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability 11.08.2026 10
CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability 12.08.2026 10
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability 12.08.2026 9.1
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability 12.08.2026 9.6
CVE-2025-14561 Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations 07.08.2026 9
CVE-2026-11976 MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise 07.08.2026 10
CVE-2026-14812 Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) 07.08.2026 10
CVE-2026-17032 Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server 07.08.2026 9.8
CVE-2026-18367 07.08.2026 9.3
CVE-2026-3418 Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution 07.08.2026 9.1
CVE-2026-43629 llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore 07.08.2026 9.2
CVE-2026-43631 llama.cpp b7492–b9060 Use-After-Free RCE via llama-server 07.08.2026 9.2
CVE-2026-43632 llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints 08.08.2026 9.2
CVE-2026-48085 OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap 07.08.2026 9.8
CVE-2026-48086 OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN 07.08.2026 9.9
CVE-2026-48087 OpenReception: WebAuthn passkey injection allows account takeover 07.08.2026 9.8
CVE-2026-48088 OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory 08.08.2026 9.4
CVE-2026-53983 Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL 07.08.2026 9.2
CVE-2026-5857 Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments 08.08.2026 9.2
CVE-2026-70558 Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token 08.08.2026 9.3
CVE-2026-28005 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-28139 WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-53975 OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec 06.08.2026 9.3
CVE-2026-53976 OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter 06.08.2026 9.3
CVE-2026-54489 06.08.2026 9.1
CVE-2026-65507 WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-65508 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65520 WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65546 WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65548 WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.9
CVE-2026-65552 WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65553 WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability 06.08.2026 10
CVE-2026-65556 WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65571 WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65572 WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65573 WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65574 WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65575 WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65576 WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65577 WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65578 WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65579 WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65581 WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-66447 WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-66665 WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability 06.08.2026 10
CVE-2026-66709 WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.1
CVE-2026-67261 06.08.2026 9.8
CVE-2026-12605 06.08.2026 9.6
CVE-2026-5134 SQLi in Loca Software's CMS 06.08.2026 9.8
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products 06.08.2026 9.4
CVE-2026-1728 Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover 06.08.2026 9.8
CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover 06.08.2026 10
CVE-2026-64597 smb: client: fix double-free in SMB2_close() replay 08.08.2026 9.8
CVE-2026-67531 FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool 06.08.2026 9.3
CVE-2026-71319 Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution 07.08.2026 9.6
CVE-2026-48168 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name 05.08.2026 10
CVE-2026-20267 Cisco IOS XE Software Security Hardening Release 06.08.2026 9
CVE-2026-20272 Cisco IOS XE Software Security Hardening Release 06.08.2026 9.8
CVE-2026-20303 Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities 06.08.2026 9.9
CVE-2026-20304 Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities 06.08.2026 9.9
CVE-2026-20310 Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access 06.08.2026 9.1
CVE-2026-7329 Privilege escalation in Progress MarkLogic Server REST query interfaces 07.08.2026 9.9
CVE-2026-7557 SAML authentication bypass in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-8709 Privilege escalation in Progress MarkLogic Server REST document patch operation 07.08.2026 9.9
CVE-2026-9190 HTTP request smuggling in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-9192 Authentication bypass in Progress MarkLogic Server ODBC App Server 07.08.2026 9.8
CVE-2026-9193 Privilege escalation in Progress MarkLogic Server Hadoop integration 07.08.2026 9.9
CVE-2026-9195 Cross-site scripting in Progress MarkLogic Server Query Console 05.08.2026 9.3
CVE-2026-15587 Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header 05.08.2026 9.4
CVE-2026-39923 Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset 05.08.2026 9.2
CVE-2026-71262 IoTSharp BlobStorageController Missing Authentication and Path Traversal 10.08.2026 9.8
CVE-2026-71263 FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() 10.08.2026 9.1
CVE-2026-71267 microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() 10.08.2026 9.8
CVE-2026-71268 OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write 10.08.2026 9.9
CVE-2026-71277 rust-iot-platform Authentication Bypass via Non-Validated Authorization Header 10.08.2026 9.1
CVE-2026-71278 rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation 10.08.2026 9.8
CVE-2026-71289 NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API 10.08.2026 9.8
CVE-2026-71254 nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() 10.08.2026 9.8
CVE-2026-71256 nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id 10.08.2026 9.8
CVE-2026-66747 ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant 05.08.2026 9.3
CVE-2026-71231 IOTSmartHome - Unauthenticated SQL Injection via lastLogin Cookie 10.08.2026 9.8
CVE-2026-71237 Miantang IoT-PHP - Unauthenticated SQL Injection in /userlogin 10.08.2026 9.8
CVE-2026-71238 DjangoCRM - Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery 10.08.2026 9.1
CVE-2026-71248 Inventory-Management-System-PHP - Unauthenticated SQL Injection in Login and Product Deletion 10.08.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-19426 FitSoft|POS Sytstem - Missing Authentication 12.08.2026 8.2
CVE-2026-12976 LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant 12.08.2026
CVE-2026-13168 Eventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API 12.08.2026
CVE-2026-13171 Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint 12.08.2026
CVE-2026-13177 Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR 12.08.2026
CVE-2026-13612 KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR 12.08.2026
CVE-2026-13613 KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint 12.08.2026
CVE-2026-14857 WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR 12.08.2026
CVE-2026-14858 WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR 12.08.2026
CVE-2026-14859 WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization 12.08.2026
CVE-2026-14925 Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download 12.08.2026
CVE-2026-15039 Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload 12.08.2026
CVE-2026-15249 Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link 12.08.2026
CVE-2026-15388 Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure 12.08.2026
CVE-2026-16051 WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action 12.08.2026
CVE-2026-16066 Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name 12.08.2026
CVE-2026-16253 Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848) 12.08.2026
CVE-2026-16294 Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL 12.08.2026
CVE-2026-16538 TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up 12.08.2026
CVE-2026-16737 WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart 12.08.2026
CVE-2026-16977 Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name 12.08.2026
CVE-2026-17013 WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart 12.08.2026
CVE-2026-18035 User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API 12.08.2026
CVE-2026-18046 Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update 12.08.2026
CVE-2026-18048 WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal 12.08.2026
CVE-2026-18049 WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo 12.08.2026
CVE-2026-18057 Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection 12.08.2026
CVE-2026-18230 WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter 12.08.2026
CVE-2026-18366 Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator 12.08.2026
CVE-2026-18391 WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection 12.08.2026
CVE-2026-18474 WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category 12.08.2026
CVE-2026-18789 Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes 12.08.2026
CVE-2026-18943 WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure 12.08.2026
CVE-2026-18962 WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization 12.08.2026
CVE-2026-19050 ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate 12.08.2026
CVE-2026-19052 ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls 12.08.2026
CVE-2026-19073 Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure 12.08.2026
CVE-2026-19217 Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget 12.08.2026
CVE-2026-66659 WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability 12.08.2026 9.3
CVE-2026-19594 Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation 12.08.2026 8.1
CVE-2026-12234 TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write 12.08.2026 7.8
CVE-2026-12235 Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) 12.08.2026 6.3
CVE-2026-64954 Velociraptor collect_client() Permissions Bypass 12.08.2026 8.2
CVE-2026-12232 Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties 12.08.2026 6.1
CVE-2026-12233 Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention 12.08.2026 5.9
CVE-2025-15687 Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service 12.08.2026
CVE-2025-15684 Open5GS CER init.c diam_log_func assertion 12.08.2026
CVE-2025-15685 Open5GS freeDiameter memory corruption 12.08.2026
CVE-2025-15686 Open5GS HSS Service fd_msg_sess_get denial of service 12.08.2026
CVE-2026-18961 Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback 12.08.2026 8.1
CVE-2026-19587 12.08.2026 6.5
CVE-2026-19588 12.08.2026 6.5
CVE-2026-9318 tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title 12.08.2026
CVE-2026-64927 Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and configmap mutation via spec.secretref.namespace confused deputy 12.08.2026
CVE-2026-66878 Multicloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltration 12.08.2026
CVE-2026-70398 Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace 12.08.2026
CVE-2026-72526 Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation 12.08.2026
CVE-2026-73122 Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespaces 12.08.2026
CVE-2024-14044 Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow 12.08.2026
CVE-2026-68447 drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size 12.08.2026
CVE-2026-68448 ovl: check access to copy_file_range source with src mounter creds 12.08.2026
CVE-2026-68449 ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning 12.08.2026
CVE-2026-68450 btrfs: free mapping node on duplicate reloc root insert 12.08.2026
CVE-2026-6484 Lack of verified boot to certain FV may cause arbitrary code execution 12.08.2026 8.2
CVE-2026-68429 drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() 12.08.2026
CVE-2026-68430 drm/amdgpu/gfx8: drop unecessary BUG_ON() 12.08.2026
CVE-2026-68431 ksmbd: validate minimum PDU size for transform requests 12.08.2026
CVE-2026-68432 vxlan: require CAP_NET_ADMIN in the device netns for changelink 12.08.2026
CVE-2026-68433 libceph: bound get_version reply decode to front len 12.08.2026
CVE-2026-68434 serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms 12.08.2026
CVE-2026-68435 LoongArch: Fix address space mismatch in kexec command line lookup 12.08.2026
CVE-2026-68436 drm/amd/display: use kvzalloc to allocate struct dc 12.08.2026
CVE-2026-68437 drm/imagination: Fit paired fragment job in the correct CCCB 12.08.2026
CVE-2026-68438 smp: Make CSD lock acquisition atomic for debug mode 12.08.2026
CVE-2026-68439 wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() 12.08.2026
CVE-2026-68440 net: txgbe: fix heap overflow when reading module EEPROM 12.08.2026
CVE-2026-68441 net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains 12.08.2026
CVE-2026-68442 btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps 12.08.2026
CVE-2026-68443 hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop 12.08.2026
CVE-2026-68444 firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() 12.08.2026
CVE-2026-68445 drm/vc4: Prevent shader BO mappings from becoming writable 12.08.2026
CVE-2026-68446 drm/vmwgfx: Validate vmw_surface_metadata::array_size 12.08.2026
CVE-2024-14043 Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow 11.08.2026
CVE-2026-73250 Notepad++: Install-time PowerShell command injection through installation path 11.08.2026
CVE-2026-18710 Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization 11.08.2026
CVE-2026-73246 Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials 11.08.2026 7.5
CVE-2026-73247 Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata 11.08.2026 8.6
CVE-2026-73248 calibre: Bypass of Python template restrictions via nested `template()` leading to RCE 11.08.2026
CVE-2026-73249 calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification 11.08.2026 7.5
CVE-2026-29036 cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding 11.08.2026
CVE-2026-5917 libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend 11.08.2026
CVE-2026-66098 Mira Hormone Monitor, Mira Android App Missing authentication for critical function 11.08.2026
CVE-2026-66875 Mira Hormone Monitor, Mira Android App Missing authentication for critical function 11.08.2026
CVE-2026-67558 Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing 11.08.2026
CVE-2026-67568 Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials 11.08.2026
CVE-2026-73245 Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth 11.08.2026 6.5
CVE-2026-19556 11.08.2026
CVE-2026-19557 11.08.2026
CVE-2026-19558 11.08.2026
CVE-2026-19559 11.08.2026
CVE-2026-19560 11.08.2026
CVE-2026-64934 Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision 11.08.2026
CVE-2026-66340 Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts 11.08.2026
CVE-2026-68067 Mira Hormone Monitor, Mira Android App Weak Authentication 11.08.2026
CVE-2026-19550 Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes 11.08.2026
CVE-2026-48763 TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath 11.08.2026 8.2
CVE-2026-66832 Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings 11.08.2026
CVE-2026-14863 FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection 11.08.2026
CVE-2026-15606 Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token 11.08.2026 8.8
CVE-2026-48762 TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler 11.08.2026 5.4
CVE-2026-48765 TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding 11.08.2026 9.9
CVE-2026-63133 Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS) 11.08.2026 6.5
CVE-2026-63134 Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation 11.08.2026 5.4
CVE-2026-63177 Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC 11.08.2026 7.1
CVE-2026-71290 Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM) 11.08.2026
CVE-2026-18634 12.08.2026
CVE-2026-19579 Snipe-IT Checkout Request Cancellation IDOR 11.08.2026
CVE-2026-29035 CivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompression 11.08.2026
CVE-2026-55676 Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component 11.08.2026 8.8
CVE-2026-66147 12.08.2026
CVE-2026-66148 11.08.2026
CVE-2026-66149 12.08.2026
CVE-2026-66150 12.08.2026
CVE-2026-66154 12.08.2026
CVE-2026-18844 Pulsetto Vagus Nerve Stimulator Hidden Functionality 11.08.2026
CVE-2026-66145 12.08.2026
CVE-2026-66146 11.08.2026
CVE-2026-73243 kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass 11.08.2026 5.8
CVE-2026-73244 kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing 11.08.2026 5.3
CVE-2026-13457 InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure 11.08.2026 7.5
CVE-2026-16230 Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field 11.08.2026 9.8
CVE-2026-19091 GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision 11.08.2026 8.1
CVE-2026-45618 LiquidJS is Vulnerable to Remote Code Execution 11.08.2026 10
CVE-2026-65655 Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy 11.08.2026
CVE-2026-73034 DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header 11.08.2026
CVE-2026-73036 Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml 11.08.2026
CVE-2026-73231 Faker: helpers.fake exploitable into arbritary code execution 11.08.2026 7.8
CVE-2026-73232 ffuf denial of service (OOM) via HTTP response decompression bomb 11.08.2026 7.5
CVE-2026-73233 FreeCAD: FEM formula incomplete escape 11.08.2026
CVE-2026-73234 FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore() 11.08.2026 7.8
CVE-2026-73235 FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser 11.08.2026 6.1
CVE-2026-73241 FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`) 11.08.2026
CVE-2026-73242 FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage` 11.08.2026
CVE-2024-14042 Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow 11.08.2026
CVE-2026-48804 python-socketio: Binary attachment accumulation can cause denial of service 11.08.2026 7.5
CVE-2026-48813 Flawfinder output manipulation via untrusted filenames and source text 11.08.2026
CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 12.08.2026 5.4
CVE-2026-71467 Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofing 11.08.2026
CVE-2026-71468 Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache 11.08.2026
CVE-2026-71474 Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response 11.08.2026
CVE-2026-71475 Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path 11.08.2026
CVE-2026-71845 Insights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault() 11.08.2026
CVE-2026-73031 telegram-search Stored XSS via v-html in MessageList.vue 11.08.2026
CVE-2026-73032 PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() 11.08.2026
CVE-2026-73229 Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests 11.08.2026 4.3
CVE-2026-73230 Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets 11.08.2026
CVE-2026-73281 11.08.2026 3.5
CVE-2026-73282 11.08.2026 4.8
CVE-2026-73283 11.08.2026 2.5
CVE-2026-18688 Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure 11.08.2026
CVE-2026-18690 Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections 11.08.2026
CVE-2026-18691 Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure 11.08.2026
CVE-2026-18692 Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution 11.08.2026
CVE-2026-18693 Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure 11.08.2026
CVE-2026-18694 Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure 11.08.2026
CVE-2026-18696 Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections 11.08.2026
CVE-2026-18697 Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos 11.08.2026
CVE-2026-18698 Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command 11.08.2026
CVE-2026-18699 Improper Input Validation in MongoDB Query Planner Leads to Denial of Service 11.08.2026
CVE-2026-18700 Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service 11.08.2026
CVE-2026-18701 Type Confusion in MongoDB Query Subsystem Leads to Denial of Service 11.08.2026
CVE-2026-18702 Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings 11.08.2026
CVE-2026-18704 Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write Operations 11.08.2026
CVE-2026-18705 Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data 11.08.2026
CVE-2026-18708 Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes 11.08.2026
CVE-2026-18709 Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency 11.08.2026
CVE-2026-18711 Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure 11.08.2026
CVE-2026-18712 Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections 11.08.2026
CVE-2026-69119 Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id} 11.08.2026
CVE-2026-72742 DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing 11.08.2026
CVE-2026-73223 electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename 11.08.2026 8.1
CVE-2026-73224 Electerm check folder size function may get attacked by unsafe folder name 11.08.2026 8.8
CVE-2026-73225 electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename 11.08.2026 8.1
CVE-2026-73226 Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist 11.08.2026 8.8
CVE-2026-73227 electerm's RDP clipboard file download may parse unsafe file name 11.08.2026 8.1
CVE-2026-73228 Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data` 11.08.2026 5.3
CVE-2026-15426 AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update 11.08.2026 8.8
CVE-2026-18687 Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index Corruption 11.08.2026
CVE-2026-18695 Improper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of Service 11.08.2026
CVE-2026-18703 Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication Method 11.08.2026
CVE-2026-18706 Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code Execution 11.08.2026
CVE-2026-18707 Improper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of Service 11.08.2026
CVE-2026-48802 python-engineio has unbound thread allocation that can cause denial of service 11.08.2026 7.5
CVE-2026-48809 python-engineio has possible denial of service due to maximum payload size sometimes not being enforced 11.08.2026 7.5
CVE-2026-69115 OpenIM Server v3.8.3 Missing Authorization on User and Group Enumeration Endpoints 11.08.2026
CVE-2026-69117 NetBox 4.5.8 ORM Injection via WritableNestedSerializer 11.08.2026
CVE-2026-73221 CVAT: Flawed authorization logic in endpoints related to lambda requests 11.08.2026
CVE-2026-73222 Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) 11.08.2026 8.8
CVE-2026-69102 MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust 11.08.2026
CVE-2026-69113 Cap v0.3.1 Broken Access Control via video comment endpoint 11.08.2026
CVE-2026-20712 11.08.2026
CVE-2026-20917 11.08.2026
CVE-2026-27302 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 11.08.2026 10
CVE-2026-47940 Lightroom Classic | Integer Overflow or Wraparound (CWE-190) 12.08.2026 7.8
CVE-2026-48381 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 11.08.2026 9
CVE-2026-48397 Lightroom Classic | Deserialization of Untrusted Data (CWE-502) 12.08.2026 8.6
CVE-2026-48404 Lightroom Classic | Out-of-bounds Write (CWE-787) 12.08.2026 7.8
CVE-2026-48405 Lightroom Classic | Out-of-bounds Write (CWE-787) 12.08.2026 7.8
CVE-2026-48406 Lightroom Classic | Out-of-bounds Write (CWE-787) 12.08.2026 7.8
CVE-2026-48407 Lightroom Classic | Out-of-bounds Write (CWE-787) 12.08.2026 7.8
CVE-2026-48408 Lightroom Classic | Out-of-bounds Write (CWE-787) 12.08.2026 7.8
CVE-2026-48409 Lightroom Classic | Out-of-bounds Write (CWE-787) 12.08.2026 7.8
CVE-2026-48410 Lightroom Classic | Out-of-bounds Write (CWE-787) 12.08.2026 7.8
CVE-2026-48411 Adobe Commerce | Incorrect Authorization (CWE-863) 11.08.2026 6.5
CVE-2026-48412 Adobe Commerce | Incorrect Authorization (CWE-863) 12.08.2026 2.7
CVE-2026-48413 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 11.08.2026 8.7
CVE-2026-48414 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 11.08.2026 7.7
CVE-2026-48415 Adobe Commerce | Incorrect Authorization (CWE-863) 11.08.2026 7.6
CVE-2026-48416 Adobe Commerce | Incorrect Authorization (CWE-863) 11.08.2026 7.5
CVE-2026-48441 Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 12.08.2026 8.6
CVE-2026-48447 Lightroom Classic | Incorrect Authorization (CWE-863) 12.08.2026 7.7
CVE-2026-65680 Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) 12.08.2026 9.1
CVE-2026-71398 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 11.08.2026 10
CVE-2026-72712 Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet 11.08.2026
CVE-2026-72713 XAgent Path Traversal Arbitrary File Read via /workspace/file 11.08.2026
CVE-2026-73213 Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF) 11.08.2026
CVE-2026-73214 coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS 11.08.2026
CVE-2026-73215 The coturn server can end in a state where it does not accept more requests with "even-port" enabled. 11.08.2026
CVE-2026-73216 coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity 11.08.2026 6.5
CVE-2026-73217 Cursor: Sandbox escape via tampered Python virtual environments 11.08.2026
CVE-2026-73218 Cursor: Sandbox escape via launching privileged containers 11.08.2026
CVE-2026-73219 CVAT: Denial of service with regards to automatic annotation 11.08.2026
CVE-2016-20097 Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad 11.08.2026
CVE-2022-50997 Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp 11.08.2026
CVE-2025-0046 11.08.2026
CVE-2025-54512 11.08.2026
CVE-2026-0465 11.08.2026
CVE-2026-20901 12.08.2026
CVE-2026-47705 TypeBot vulnerable to CSV injection in result export 11.08.2026 9.6
CVE-2026-48494 TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session ids 11.08.2026
CVE-2026-48767 Google Sheets OAuth access token disclosure to guest members via getAccessToken 11.08.2026 7.6
CVE-2026-48771 ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database Configuration 11.08.2026 8.2
CVE-2026-48790 turso-cli persists Turso platform JWT with world-readable (0o644) file permissions 11.08.2026 5.5
CVE-2026-73090 PeerTube: Cross-origin remote video takeover via Update activity 11.08.2026 9.3
CVE-2026-73211 PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() 11.08.2026 9.8
CVE-2026-73212 coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE 11.08.2026
CVE-2025-0041 11.08.2026
CVE-2025-48505 11.08.2026
CVE-2025-48506 11.08.2026
CVE-2025-61970 11.08.2026
CVE-2025-8087 11.08.2026
CVE-2026-12571 Authentication Bypass Leading to Account Takeover 12.08.2026 9.8
CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability 12.08.2026 8.6
CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-43606 11.08.2026
CVE-2026-47285 Visual Studio Code Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability 11.08.2026 7.2
CVE-2026-47922 CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) 11.08.2026 4.7
CVE-2026-48387 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) 11.08.2026 6.2
CVE-2026-48434 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) 11.08.2026 6.2
CVE-2026-48435 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) 11.08.2026 6.2
CVE-2026-48436 CAI Content Credentials | Improper Input Validation (CWE-20) 11.08.2026 6.5
CVE-2026-48437 CAI Content Credentials | Improper Certificate Validation (CWE-295) 11.08.2026 5.5
CVE-2026-48438 CAI Content Credentials | NULL Pointer Dereference (CWE-476) 11.08.2026 7.5
CVE-2026-48439 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) 11.08.2026 7.5
CVE-2026-48442 CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 11.08.2026 7.1
CVE-2026-48443 CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) 11.08.2026 6.2
CVE-2026-48444 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) 11.08.2026 6.2
CVE-2026-48445 CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) 11.08.2026 6.2
CVE-2026-48446 CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 11.08.2026 5.5
CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 12.08.2026 9.4
CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability 11.08.2026 7.5
CVE-2026-54123 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability 12.08.2026 7.8
CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability 11.08.2026 7.8
CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-56179 Windows Network Address Translation (NAT) Spoofing Vulnerability 12.08.2026 8.3
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability 11.08.2026 8.8
CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability 12.08.2026 8
CVE-2026-58612 PowerShell Information Disclosure Vulnerability 11.08.2026 7.4
CVE-2026-58639 Microsoft SharePoint Server Spoofing Vulnerability 12.08.2026 6.5
CVE-2026-58641 .NET Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability 11.08.2026 7.8
CVE-2026-58651 Microsoft Word Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability 12.08.2026 7.3
CVE-2026-59122 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-59125 Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability 11.08.2026 7
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-59128 Windows Encrypting File System (EFS) Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-59130 AMD Zen Information Disclosure Vulnerability 11.08.2026 5.6
CVE-2026-59131 AMD Zen Information Disclosure Vulnerability 11.08.2026 5.6
CVE-2026-59132 Windows TCP/IP Denial of Service Vulnerability 11.08.2026 7.5
CVE-2026-59133 Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability 12.08.2026 8.8
CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability 12.08.2026 7.5
CVE-2026-59135 Microsoft Windows Search Component Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-59136 Microsoft COM for Windows Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-59137 Windows Event Logging Service Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-59138 Microsoft Remote Registry Service Denial of Service Vulnerability 11.08.2026 6.5
CVE-2026-61345 Microsoft Remote Registry Service Denial of Service Vulnerability 11.08.2026 6.5
CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability 11.08.2026 7
CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-61348 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-61349 Windows Work Folder Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61350 Windows NTFS Information Disclosure Vulnerability 11.08.2026 4.6
CVE-2026-61352 Remote Desktop Client Remote Code Execution Vulnerability 11.08.2026 7.5
CVE-2026-61353 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61355 Windows Sensor Data Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61356 Windows Remote Desktop Services Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61357 Application Information Services Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-61358 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61360 Windows GDI Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-61361 Windows DHCP Client Remote Code Execution Vulnerability 12.08.2026 7
CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability 12.08.2026 7.5
CVE-2026-61364 Windows Remote Desktop Services Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61365 Windows Remote Desktop Services Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61366 Windows Network Connection Broker Elevation of Privilege Vulnerability 11.08.2026 7
CVE-2026-61367 Windows Remote Desktop Services Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61368 Windows Hyper-V Information Disclosure Vulnerability 11.08.2026 5
CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 6.6
CVE-2026-61921 Windows Remote Desktop Client Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-61924 Windows Remote Desktop Client Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-61925 Windows Installer Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61926 Windows USB Driver Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61927 Windows Bind Filter Driver Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-61928 Windows Hello Tampering Vulnerability 11.08.2026 5.5
CVE-2026-61929 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-61930 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61932 Windows DWM Core Library Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61933 Windows DWM Core Library Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-61934 Windows Bind Filter Driver Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability 11.08.2026 5.5
CVE-2026-61937 Windows HTTP.sys Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-61938 Windows Installer Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-61939 Winlogon Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability 12.08.2026 7.8
CVE-2026-62690 Windows Push Notifications Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62692 Windows Remote Desktop Services Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability 12.08.2026 7
CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62698 Microsoft Digest Authentication Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability 11.08.2026 6.8
CVE-2026-62700 Windows NTFS Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62701 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62702 Windows Graphics Kernel Denial of Service Vulnerability 11.08.2026 6.8
CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-62705 Windows Bind Filter Driver Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62707 Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-62708 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 6.4
CVE-2026-62709 Windows GDI+ Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62710 Windows Device Association Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62711 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62712 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62713 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62714 Windows DHCP Server Information Disclosure Vulnerability 12.08.2026 6.5
CVE-2026-62715 Windows DHCP Server Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-62716 Windows DHCP Server Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-62717 Windows Message Queuing Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62718 Windows DHCP Server Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-62719 Windows Message Queuing Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-62720 Windows DHCP Server Information Disclosure Vulnerability 12.08.2026 6.5
CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62722 Windows Bind Filter Driver Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62723 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62724 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62725 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62726 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62729 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62730 Windows Wired AutoConfig Service Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62732 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62733 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62734 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62735 Windows HTTP.sys Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62736 Windows DHCP Client Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62737 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62738 Windows Management Instrumentation Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62739 Windows HTTP.sys Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62740 Windows Imaging Component Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-62741 Windows HTTP.sys Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62742 Windows DHCP Server Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-62743 Win32k Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62745 Windows DHCP Server Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-62746 Win32k Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62748 Windows Telephony Service Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62749 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62750 Windows HTTP Protocol Stack Tampering Vulnerability 11.08.2026 6.5
CVE-2026-62751 Windows Projected File System Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62752 Windows Kerberos Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62753 Windows HTTP.sys Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62757 Windows Schannel Security Feature Bypass Vulnerability 12.08.2026 5.3
CVE-2026-62758 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62761 Windows DHCP Server Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62766 Windows Kerberos Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62769 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-62770 Windows Shell Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62771 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-62773 Windows Kerberos Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62774 Windows Graphics Kernel Elevation of Privilege Vulnerability 11.08.2026 7
CVE-2026-62775 Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62776 Windows DHCP Server Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-62778 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 8.1
CVE-2026-62779 Windows Schannel Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62780 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62781 RPC Runtime Library Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-62782 Windows SMB Client Information Disclosure Vulnerability 12.08.2026 6.5
CVE-2026-62783 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62784 Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62785 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62786 Win32k Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62787 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 7.5
CVE-2026-62788 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62790 Windows SMBv3 Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62792 Windows TCP/IP Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-62793 Windows NTFS Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62795 Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62796 Windows NTFS Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-62797 Windows NTFS Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62798 Win32k Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-62799 Windows SMB Client Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62800 Windows SMBv3 Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62803 Windows DHCP Server Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62807 Windows DHCP Server Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62811 Windows HTTP.sys Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62812 Windows DHCP Server Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62814 Windows DHCP Server Information Disclosure Vulnerability 12.08.2026 6.5
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62816 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62817 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-62820 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-62822 Windows GDI+ Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62824 Remote Desktop Client Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability 12.08.2026 8.8
CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability 11.08.2026 4.6
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-62839 Microsoft SharePoint Server Spoofing Vulnerability 12.08.2026 6.5
CVE-2026-62842 Microsoft Office Graphics Component Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62869 Azure Entra ID Spoofing Vulnerability 12.08.2026 8.8
CVE-2026-62871 .NET Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62872 .NET Framework Elevation of Privilege Vulnerability 12.08.2026 8.8
CVE-2026-62876 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62877 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62881 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-62882 Microsoft Outlook Spoofing Vulnerability 12.08.2026 4.3
CVE-2026-62883 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-62885 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62886 .NET Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62887 Windows NTFS Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-62888 Windows DWM Core Library Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62892 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62894 Windows DWM Core Library Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability 12.08.2026 7
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability 12.08.2026 7.5
CVE-2026-62899 .NET Security Feature Bypass Vulnerability 11.08.2026 5.9
CVE-2026-62900 .NET Information Disclosure Vulnerability 11.08.2026 5.9
CVE-2026-62901 .NET Denial of Service Vulnerability 11.08.2026 7.5
CVE-2026-62902 .NET Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-62908 Windows Backup Engine Elevation of Privilege Vulnerability 11.08.2026 7
CVE-2026-62909 .NET Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability 12.08.2026 7.2
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability 12.08.2026 8
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability 11.08.2026 6.5
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability 11.08.2026 7.3
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability 11.08.2026 6.5
CVE-2026-62917 Microsoft SharePoint Server Spoofing Vulnerability 12.08.2026 4.6
CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability 11.08.2026 6.5
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-63515 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability 11.08.2026 6.5
CVE-2026-63517 Microsoft Office Graphics Component Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-63521 Microsoft Office Word Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-63524 Microsoft Office Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-63525 Microsoft Office Word Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63526 Microsoft Office Graphics Component Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63527 Microsoft Office Word Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63528 Microsoft Office Word Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-63529 Microsoft Office Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-63530 Microsoft Office Word Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-63531 Microsoft Office Word Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-63532 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-63533 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64897 Microsoft SharePoint Server Spoofing Vulnerability 12.08.2026 4.6
CVE-2026-64898 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-64900 Microsoft SharePoint Server Spoofing Vulnerability 12.08.2026 7.3
CVE-2026-64901 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-64902 Microsoft SharePoint Server Spoofing Vulnerability 12.08.2026 4.6
CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64904 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64905 Microsoft Office Word Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64907 Microsoft Office Word Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64908 Microsoft Access Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64909 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64910 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64911 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64912 Microsoft Access Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64914 Microsoft Access Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64915 Microsoft Office Word Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64916 Microsoft SharePoint Server Spoofing Vulnerability 12.08.2026 4.6
CVE-2026-64917 Microsoft Office Word Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-64919 Microsoft Access Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64920 Microsoft Access Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-64921 Microsoft SharePoint Server Elevation of Privilege Vulnerability 12.08.2026 8.8
CVE-2026-64922 Microsoft SharePoint Server Spoofing Vulnerability 11.08.2026 4.6
CVE-2026-65656 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-65657 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-65658 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-65660 Microsoft SharePoint Server Spoofing Vulnerability 11.08.2026 6.5
CVE-2026-65661 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-65662 Windows GDI Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-65663 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-65664 Microsoft Office Graphics Component Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-65665 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-65672 Remote Access API Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-65673 Microsoft Entra Connect Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability 11.08.2026 7.1
CVE-2026-65678 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65679 Windows iSCSI Target Service Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-65681 Windows iSCSI Target Service Denial of Service Vulnerability 12.08.2026 7.5
CVE-2026-65767 Microsoft Teams for Android and iOS Spoofing Vulnerability 12.08.2026 8.8
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-65773 Windows Kernel Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65774 Windows Installer Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability 12.08.2026 5.3
CVE-2026-65778 Windows Autopilot Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65780 Windows Autopilot Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65781 Windows Autopilot Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65782 Windows Autopilot Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65783 Windows Autopilot Elevation of Privilege Vulnerability 11.08.2026 7
CVE-2026-65784 Windows NTFS Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-65785 Windows DHCP Client Denial of Service Vulnerability 11.08.2026 6.5
CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65788 Desktop Window Manager Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-65789 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-65790 Windows Message Queuing Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-65794 Windows SMB Client Information Disclosure Vulnerability 12.08.2026 6.5
CVE-2026-65795 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-65796 Windows iSCSI Target Service Denial of Service Vulnerability 12.08.2026 5.9
CVE-2026-65797 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-65798 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-65799 Windows DNS Elevation of Privilege Vulnerability 12.08.2026 6.7
CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-65807 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-65810 .NET Framework Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65811 Power BI Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability 12.08.2026 6.5
CVE-2026-65814 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-65815 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-66301 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-66799 Windows Key Guard Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-66805 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-66806 Microsoft Office Word Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-66808 Microsoft SharePoint Server Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-66809 Microsoft Office Graphics Component Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-66810 Microsoft Office Word Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-68792 Microsoft Office Elevation of Privilege Vulnerability 12.08.2026 7.8
CVE-2026-68793 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68794 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68795 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68796 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68797 Microsoft Excel Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-68798 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68799 Microsoft Excel Information Disclosure Vulnerability 12.08.2026 5.5
CVE-2026-68800 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68802 Microsoft Excel Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-68803 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68804 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68805 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68806 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68807 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68808 Microsoft Excel Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-68809 Powerpoint Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-68810 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68811 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68812 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68813 Microsoft Excel Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-68814 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68816 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-68819 Windows Network File System Denial of Service Vulnerability 11.08.2026 5.9
CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability 11.08.2026 7.3
CVE-2026-69223 Apache Allura: Server-side request forgery 11.08.2026
CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability 12.08.2026 7.8
CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability 11.08.2026 8.2
CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability 12.08.2026 8.4
CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability 11.08.2026 6.7
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability 12.08.2026 9.3
CVE-2026-70307 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 12.08.2026 7
CVE-2026-70310 Microsoft Word Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70311 Microsoft Office Word Remote Code Execution Vulnerability 11.08.2026 7.8
CVE-2026-70312 Powerpoint Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70313 Microsoft PowerPoint Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-70314 Microsoft Office Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70315 Microsoft Office Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70316 Powerpoint Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70317 Microsoft Office Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70318 Microsoft Excel Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70319 Microsoft Office Word Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70320 Powerpoint Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70321 Microsoft SharePoint Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-70322 Powerpoint Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70323 Microsoft Office Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70324 Microsoft SharePoint Elevation of Privilege Vulnerability 12.08.2026 8.8
CVE-2026-70325 Powerpoint Information Disclosure Vulnerability 11.08.2026 5.5
CVE-2026-70326 Microsoft SharePoint Server Elevation of Privilege Vulnerability 12.08.2026 8.8
CVE-2026-70327 Microsoft Excel Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-70328 Microsoft Excel Information Disclosure Vulnerability 11.08.2026 6.5
CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability 11.08.2026 6.7
CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability 11.08.2026 8.8
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability 12.08.2026 8.8
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability 12.08.2026 7.8
CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability 12.08.2026 8.1
CVE-2026-70344 Windows Installer Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-70345 Windows Installer Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-70346 Windows Installer Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-70347 Windows Installer Elevation of Privilege Vulnerability 11.08.2026 7.8
CVE-2026-70348 Windows Management Services Denial of Service Vulnerability 11.08.2026 5.5
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability 12.08.2026 7.8
CVE-2026-70355 Microsoft SharePoint Server Elevation of Privilege Vulnerability 12.08.2026 7.3
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability 12.08.2026 8.1
CVE-2026-71389 CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) 11.08.2026 6.2
CVE-2026-71390 CAI Content Credentials | Improper Input Validation (CWE-20) 11.08.2026 4
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability 11.08.2026 5.5
CVE-2026-73086 nanoid: Integer Overflow or Wraparound 11.08.2026 7.4
CVE-2026-73087 Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher 11.08.2026
CVE-2026-73088 Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) 11.08.2026 7.5
CVE-2026-73089 Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM 11.08.2026 7.5
CVE-2025-31356 11.08.2026
CVE-2025-31936 12.08.2026
CVE-2025-31938 11.08.2026
CVE-2025-35973 11.08.2026
CVE-2025-35987 11.08.2026
CVE-2026-20702 11.08.2026
CVE-2026-20705 11.08.2026
CVE-2026-20707 11.08.2026
CVE-2026-20708 11.08.2026
CVE-2026-20713 11.08.2026
CVE-2026-20715 11.08.2026
CVE-2026-20716 11.08.2026
CVE-2026-20727 11.08.2026
CVE-2026-20728 11.08.2026
CVE-2026-20731 11.08.2026
CVE-2026-20734 11.08.2026
CVE-2026-20737 11.08.2026
CVE-2026-20739 11.08.2026
CVE-2026-20741 11.08.2026
CVE-2026-20745 11.08.2026
CVE-2026-20747 11.08.2026
CVE-2026-20749 11.08.2026
CVE-2026-20752 11.08.2026
CVE-2026-20755 11.08.2026
CVE-2026-20760 11.08.2026
CVE-2026-20763 11.08.2026
CVE-2026-20765 11.08.2026
CVE-2026-20769 11.08.2026
CVE-2026-20770 11.08.2026
CVE-2026-20775 11.08.2026
CVE-2026-20776 11.08.2026
CVE-2026-20778 11.08.2026
CVE-2026-20780 11.08.2026
CVE-2026-20783 11.08.2026
CVE-2026-20786 11.08.2026
CVE-2026-20787 11.08.2026
CVE-2026-20789 11.08.2026
CVE-2026-20795 11.08.2026
CVE-2026-20799 11.08.2026
CVE-2026-20878 11.08.2026
CVE-2026-20885 11.08.2026
CVE-2026-20886 11.08.2026
CVE-2026-20890 11.08.2026
CVE-2026-20891 11.08.2026
CVE-2026-20898 12.08.2026
CVE-2026-20903 11.08.2026
CVE-2026-20906 11.08.2026
CVE-2026-20908 11.08.2026
CVE-2026-20913 11.08.2026
CVE-2026-21269 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) 11.08.2026 4.6
CVE-2026-21273 ColdFusion | Improper Input Validation (CWE-20) 11.08.2026 8.7
CVE-2026-21279 ColdFusion | Improper Input Validation (CWE-20) 11.08.2026 8.2
CVE-2026-21387 11.08.2026
CVE-2026-21399 11.08.2026
CVE-2026-21400 11.08.2026
CVE-2026-22887 11.08.2026
CVE-2026-24099 11.08.2026
CVE-2026-24693 11.08.2026
CVE-2026-24911 11.08.2026
CVE-2026-25194 11.08.2026
CVE-2026-25652 ColdFusion | Incorrect Authorization (CWE-863) 12.08.2026 7.8
CVE-2026-27765 11.08.2026
CVE-2026-28700 11.08.2026
CVE-2026-28707 11.08.2026
CVE-2026-28729 11.08.2026
CVE-2026-28757 11.08.2026
CVE-2026-32677 11.08.2026
CVE-2026-32788 11.08.2026
CVE-2026-32791 11.08.2026
CVE-2026-34175 11.08.2026
CVE-2026-34635 ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321) 11.08.2026 8.4
CVE-2026-35502 11.08.2026
CVE-2026-39452 11.08.2026
CVE-2026-48362 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 12.08.2026 10
CVE-2026-48375 ColdFusion | Incorrect Authorization (CWE-863) 11.08.2026 6.5
CVE-2026-48376 ColdFusion | Improper Encoding or Escaping of Output (CWE-116) 11.08.2026 5.4
CVE-2026-48384 ColdFusion | Improper Input Validation (CWE-20) 11.08.2026 4.9
CVE-2026-48385 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 11.08.2026 7.7
CVE-2026-48386 ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327) 11.08.2026 7.5
CVE-2026-48440 ColdFusion | Heap-based Buffer Overflow (CWE-122) 12.08.2026 8.1
CVE-2026-71383 ColdFusion | Incorrect Authorization (CWE-863) 11.08.2026 7.3
CVE-2026-71384 ColdFusion | Incorrect Authorization (CWE-863) 11.08.2026 9.6
CVE-2026-71386 ColdFusion | Cross-site Scripting (XSS) (CWE-79) 12.08.2026 8.8
CVE-2026-71387 ColdFusion | Incorrect Authorization (CWE-863) 12.08.2026 8.8
CVE-2026-73081 Activepieces: Remote Code Execution via Command Injection in Code Step Name 11.08.2026
CVE-2026-73082 Activepieces: Server-side request forgery in MCP tool validation endpoint 11.08.2026
CVE-2026-73083 Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading 11.08.2026
CVE-2026-73084 Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint 11.08.2026 6.1
CVE-2026-73085 Audiobookshelf: Refresh Token Accepted on Resource Endpoints 11.08.2026
CVE-2026-18247 DOM-Based Cross-Site Scripting in BlackBerry AtHoc Web Portals 11.08.2026
CVE-2026-47704 TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows unauthorized control of another bot's waiting session 11.08.2026
CVE-2026-48483 TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server 11.08.2026 5.4
CVE-2026-42142 TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential Access 11.08.2026 7.1
CVE-2026-48495 TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots 11.08.2026 7.1
CVE-2026-48766 TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrl 11.08.2026 7.6
CVE-2026-53413 Zoom Clients - Buffer Over-write 12.08.2026 8.3
CVE-2026-53414 Zoom Clients - Buffer Over-read 11.08.2026 6.5
CVE-2026-53415 Zoom Clients - Use After Free 11.08.2026 8.3
CVE-2026-53416 Zoom VDI - Path Traversal 11.08.2026 7.1
CVE-2026-56720 CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action 11.08.2026
CVE-2026-56721 CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController 11.08.2026
CVE-2026-67179 Genkit improper host header validation 11.08.2026 7.8
CVE-2026-67180 Google Turbinia arbitrary command execution 11.08.2026 8.4
CVE-2026-73077 Vim: Arbitrary Code Execution via Shell Keyword Lookup 11.08.2026
CVE-2026-73078 Vim: Arbitrary Code Execution via Netrw Menu Construction 11.08.2026
CVE-2026-73079 Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials 11.08.2026 8.5
CVE-2026-73080 SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle 11.08.2026 9.3
CVE-2025-31114 Fooocus webui vulnerable to Remote Code Execution 11.08.2026
CVE-2026-14180 Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap 11.08.2026
CVE-2026-19078 Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing via unvalidated parameter. 11.08.2026
CVE-2026-6726 An information leakage vulnerability in the TCG TPM 2.0 reference code. 11.08.2026
CVE-2026-6727 CVE-2026-6727 11.08.2026
CVE-2026-73069 Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution 11.08.2026 9.1
CVE-2026-73070 Vim: Stack Buffer Overflow in the Vim Socket Server 11.08.2026
CVE-2026-73071 Vim: Use-after-free in JSON Decoding 11.08.2026 3.3
CVE-2026-73072 Vim: Heap Buffer Overflow when Loading a Spell File 11.08.2026
CVE-2026-73074 Vim: Heap Buffer Overflow in Text Property Handling 11.08.2026
CVE-2026-73075 Vim: Out-of-bounds Access in Popup Opacity Handling 11.08.2026
CVE-2026-73076 Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` 11.08.2026
CVE-2026-11733 Buffer overflow vulnerability in some NETGEAR Nighthawk routers 12.08.2026
CVE-2026-11734 Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices. 12.08.2026
CVE-2026-11735 Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models 12.08.2026
CVE-2026-11736 Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers 12.08.2026
CVE-2026-11737 Some NETGEAR Nighthawk devices allow administrators to tamper with the device 12.08.2026
CVE-2026-11738 Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device. 12.08.2026
CVE-2026-11739 Command injection vulnerability in some NETGEAR Nighthawk devices 12.08.2026
CVE-2026-11814 Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers 11.08.2026
CVE-2026-18638 Velociraptor server crash via the SetPassword API 11.08.2026 6.5
CVE-2026-18639 Velociraptor OIDC Authenticator susceptible to email spoofing 11.08.2026 7.3
CVE-2026-18640 Velociraptor directory traversal via the NewNotebook API 11.08.2026 7.1
CVE-2026-19546 Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute 12.08.2026
CVE-2026-73068 ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tables 11.08.2026 5.9
CVE-2026-9214 Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device. 12.08.2026
CVE-2020-37257 11.08.2026
CVE-2020-37258 11.08.2026
CVE-2020-37259 11.08.2026
CVE-2020-37260 11.08.2026
CVE-2020-37261 11.08.2026
CVE-2020-37262 11.08.2026
CVE-2020-37263 11.08.2026
CVE-2020-37264 11.08.2026
CVE-2020-37265 11.08.2026
CVE-2021-47988 11.08.2026
CVE-2021-47989 11.08.2026
CVE-2021-47990 11.08.2026
CVE-2021-47991 11.08.2026
CVE-2021-47992 11.08.2026
CVE-2021-47993 11.08.2026
CVE-2021-47994 11.08.2026
CVE-2021-47995 11.08.2026
CVE-2022-50974 11.08.2026
CVE-2023-54367 11.08.2026
CVE-2023-54368 11.08.2026
CVE-2023-54369 11.08.2026
CVE-2023-54370 11.08.2026
CVE-2023-54371 11.08.2026
CVE-2023-54372 11.08.2026
CVE-2023-54373 11.08.2026
CVE-2023-54374 11.08.2026
CVE-2026-17535 Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes 11.08.2026 6.2
CVE-2026-18636 Velociraptor VFSGetBuffer API path deny list bypass 11.08.2026 6.8
CVE-2026-18860 Velociraptor incorrect Org deletion permissions check 11.08.2026 8.7
CVE-2026-72922 AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification 11.08.2026 8.2
CVE-2026-72925 SWC HTML minifier may allow script element breakout when minifying embedded JSON 11.08.2026 6.1
CVE-2026-73066 Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddata 11.08.2026
CVE-2026-73067 Tesseract: Heap OOB read in the DAWG loader 11.08.2026
CVE-2026-17061 Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 11.08.2026 10
CVE-2026-18125 11.08.2026 7.5
CVE-2026-18127 11.08.2026 7.7
CVE-2026-18129 12.08.2026 8.1
CVE-2026-18635 Velociraptor query plugin allows impersonation in other orgs 11.08.2026 7.2
CVE-2026-47702 TypeBot API tokens stored in plaintext 11.08.2026
CVE-2026-72920 SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control 11.08.2026 9.8
CVE-2026-72921 SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths 11.08.2026 8.1
CVE-2026-19434 Stored Cross-site Scripting in Pentestify finding severity field 11.08.2026
CVE-2026-19539 IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion 11.08.2026
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection 11.08.2026 9.8
CVE-2026-48056 Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler 11.08.2026 10
CVE-2026-51583 11.08.2026
CVE-2026-51584 11.08.2026
CVE-2026-73210 Server-Side Request Forgery via Favicon Retrieval in Lookyloo PlaywrightCapture 11.08.2026
CVE-2026-48046 Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler 11.08.2026
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability 11.08.2026 9.6
CVE-2026-50058 11.08.2026 7.8
CVE-2026-50059 11.08.2026 7.8
CVE-2026-50060 11.08.2026 7.8
CVE-2026-50061 11.08.2026 7.8
CVE-2026-50062 11.08.2026 7.8
CVE-2026-50063 11.08.2026 7.8
CVE-2026-50064 11.08.2026 7.8
CVE-2026-57262 11.08.2026 6.8
CVE-2026-57263 11.08.2026 6.8
CVE-2026-58115 11.08.2026 10
CVE-2026-59086 11.08.2026 7.8
CVE-2026-59693 11.08.2026 4.3
CVE-2026-59700 11.08.2026 7.8
CVE-2026-59701 11.08.2026 7.8
CVE-2026-64629 11.08.2026 7.8
CVE-2026-69108 11.08.2026 6
CVE-2026-69109 11.08.2026 7.5
CVE-2026-72779 Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject 11.08.2026
CVE-2026-72780 Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey 11.08.2026
CVE-2026-72781 Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape 11.08.2026
CVE-2026-72782 Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak 11.08.2026
CVE-2026-72783 Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained 11.08.2026
CVE-2026-72784 Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation 11.08.2026
CVE-2026-72785 Craft CMS before 5.10.6 Authorization Bypass via structures/move-element 11.08.2026
CVE-2026-72744 Nuxt before 4.5.1 Information Disclosure via Chrome DevTools 11.08.2026
CVE-2026-72745 FreeRDP before 3.30.0 Out-of-Bounds Read via Kerberos GSS Wrap-token EC 11.08.2026
CVE-2026-72746 FreeRDP before 3.30.0 RDSTLS Server Authentication Bypass via PDU-type Confusion 11.08.2026
CVE-2026-72747 AVideo Stored Cross-Site Scripting via Unauthenticated Registration 11.08.2026
CVE-2026-72748 AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php 11.08.2026
CVE-2026-72749 n8n before 1.123.67 Prototype Pollution via Edit Fields 11.08.2026
CVE-2026-72750 n8n before 1.123.67 SQL Injection via executeQuery Operation 11.08.2026
CVE-2026-72762 n8n before 1.123.67 Arbitrary File Write via Edit Image Node 11.08.2026
CVE-2026-72763 n8n before 1.123.67 Credential Exfiltration via Sub-Workflow 11.08.2026
CVE-2026-72764 n8n before 1.123.67 Module Cache Poisoning via Code Node 11.08.2026
CVE-2026-72765 n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape 11.08.2026
CVE-2026-72766 n8n before 1.123.67 Arbitrary File Read via Send Email Node 11.08.2026
CVE-2026-72767 n8n before 1.123.67 Remote Code Execution via Git node 11.08.2026
CVE-2026-72768 n8n before 2.32.1 SSRF Protection Bypass via MCP Client 11.08.2026
CVE-2026-72769 n8n before 1.123.67 Prototype Pollution via VM Expression Engine 11.08.2026
CVE-2026-72770 n8n before 1.123.67 Path Traversal via Git Node Operations 11.08.2026
CVE-2026-72771 n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes 11.08.2026
CVE-2026-72772 n8n before 2.32.1 Authentication Bypass via Token Exchange 11.08.2026
CVE-2026-72773 n8n before 2.32.1 Path Traversal via computer-use search_files 11.08.2026
CVE-2026-72774 n8n before 1.123.67 Authentication Bypass via HTTP Request Node 11.08.2026
CVE-2026-72775 n8n before 1.123.67 SQL Injection via PostgresTrigger Node 11.08.2026
CVE-2026-72778 Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config 11.08.2026
CVE-2026-50236 Openshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift console 11.08.2026
CVE-2026-50237 Openshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via projecthelmchartrepository in openshift console 11.08.2026
CVE-2026-72607 Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age 11.08.2026 7.1
CVE-2026-72608 Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name 11.08.2026 6.5
CVE-2026-72609 Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl 11.08.2026 7.1
CVE-2026-72610 Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation 11.08.2026 4.3
CVE-2026-13737 Command Restriction Bypass 11.08.2026
CVE-2026-13738 Improper Authorization Validation 11.08.2026
CVE-2026-13739 Server-Side Request Forgery (SSRF) 11.08.2026
CVE-2026-72533 Portainer Portainer CE - Authentication Bypass 11.08.2026 8.8
CVE-2026-72534 Authentik Security authentik - Privilege Escalation 11.08.2026 8.8
CVE-2026-72535 Chaskiq Chaskiq - Missing Authentication 11.08.2026 8.2
CVE-2026-72536 Chaskiq Chaskiq - Missing Authentication 11.08.2026 8.2
CVE-2026-72537 Authentik Security authentik - Privilege Escalation 11.08.2026 8.8
CVE-2026-72538 PrefectHQ Prefect - Argument Injection 11.08.2026 8.8
CVE-2026-72539 Windmill Labs Windmill - Information Disclosure 11.08.2026 6.5
CVE-2026-72540 PhotoPrism PhotoPrism - Insecure Direct Object Reference 11.08.2026 4.3
CVE-2026-72541 Windmill Labs Windmill - Missing Authorization 11.08.2026 6.5
CVE-2026-72542 Windmill Labs Windmill - Missing Authorization 11.08.2026 5.4
CVE-2026-72543 OpenSignLabs OpenSign - Insecure Direct Object Reference 11.08.2026 7.5
CVE-2026-72544 OpenSignLabs OpenSign - Insufficient Verification of Data Authenticity 11.08.2026 7.5
CVE-2026-72545 OpenSignLabs OpenSign - Insecure Direct Object Reference 11.08.2026 7.5
CVE-2026-72546 Attendize Attendize - Insecure Direct Object Reference 11.08.2026 7.1
CVE-2026-72547 Attendize Attendize - Insecure Direct Object Reference 11.08.2026 7.1
CVE-2026-72548 OpenSignLabs OpenSign - Information Disclosure 11.08.2026 7.5
CVE-2026-72549 OpenSignLabs OpenSign - Information Disclosure 11.08.2026 5.3
CVE-2026-72550 Friendica Friendica - SQL Injection 11.08.2026 9.8
CVE-2026-72551 Apioo Fusio - Remote Code Execution 11.08.2026 8.8
CVE-2026-72552 Dub Dub - Server-Side Request Forgery 11.08.2026 7.5
CVE-2026-72553 ElkArte Forum ElkArte - Cross-Site Scripting 11.08.2026 5.4
CVE-2026-72554 Ladybird Web Solution Faveo Helpdesk - Broken Access Control 11.08.2026 6.5
CVE-2026-72555 Peppermint Lab Peppermint - Broken Access Control 11.08.2026 8.1
CVE-2026-72556 ZoneMinder ZoneMinder - Remote Code Execution 11.08.2026 8.8
CVE-2026-72557 Cockpit CMS Cockpit CMS - Unrestricted File Upload 11.08.2026 8.8
CVE-2026-72558 CiviCRM CiviCRM - SQL Injection 11.08.2026 8.8
CVE-2026-72559 Daniel Brendel HortusFox - Cross-Site Scripting 11.08.2026 5.4
CVE-2026-72560 HumanSignal Label Studio - Server-Side Request Forgery 11.08.2026 6.5
CVE-2026-72561 Peppermint Lab Peppermint - Broken Access Control 11.08.2026 8.8
CVE-2026-72562 Pimcore pimcore admin-ui-classic-bundle - SQL Injection 11.08.2026 8.8
CVE-2026-72563 BadChoice Handesk - Broken Access Control 11.08.2026 8.1
CVE-2026-72595 BadChoice Handesk - Broken Access Control 11.08.2026 8.1
CVE-2026-72596 Ghost Foundation Ghost - Broken Access Control 11.08.2026 8.1
CVE-2026-72597 Friendica Friendica - Server-Side Request Forgery 11.08.2026 6.5
CVE-2026-72598 Apioo Fusio - Server-Side Request Forgery 11.08.2026 6.5
CVE-2026-72599 e107 e107 - SQL Injection 11.08.2026 9.8
CVE-2026-72600 Idurar IDURAR ERP CRM - Broken Access Control 11.08.2026 7.5
CVE-2026-72601 CSZ CMS CSZ CMS - Broken Access Control 11.08.2026 7.5
CVE-2026-72602 AsyncFuncAI deepwiki-open - Path Traversal 11.08.2026 7.5
CVE-2026-72603 wg-easy wg-easy - OS Command Injection 11.08.2026 9.9
CVE-2026-72604 Intelliants Subrion CMS - Path Traversal 11.08.2026 6.5
CVE-2026-72605 Swing Music Swing Music - Missing Authentication 11.08.2026 7.5
CVE-2026-72606 Pinry Pinry - Server-Side Request Forgery 11.08.2026 7.5
CVE-2026-58231 Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) 12.08.2026 10