CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-17561 Unauthenticated RCE in Innotim Software's Logsign SIEM 31.07.2026 9.8
CVE-2025-67649 Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script 31.07.2026 9.3
CVE-2026-14483 Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command 31.07.2026 9.8
CVE-2026-18452 Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials 31.07.2026 10
CVE-2026-63221 CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions 31.07.2026 9.4
CVE-2026-63223 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules 31.07.2026 9.8
CVE-2026-66418 OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field 30.07.2026 9.3
CVE-2026-68502 LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE 31.07.2026 9.8
CVE-2026-68503 LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard 30.07.2026 9.8
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability 31.07.2026 10
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent 31.07.2026 9.9
CVE-2026-67208 Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console 31.07.2026 9.3
CVE-2026-67594 Spikster Missing Authentication via API Route Group 31.07.2026 9.3
CVE-2026-66066 Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing 30.07.2026 9.5
CVE-2026-12943 This Power Hardware Management Console update is being released to address 31.07.2026 9.8
CVE-2026-12118 IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data 30.07.2026 9.8
CVE-2026-13435 Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure 31.07.2026 9.9
CVE-2026-48499 Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache 30.07.2026 9.3
CVE-2026-12940 Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints 31.07.2026 9.8
CVE-2026-28323 SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability 31.07.2026 9.8
CVE-2026-4978 SQLi in UMAI Vision's Traffic Analysis System 30.07.2026 9.8
CVE-2026-11707 Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager 30.07.2026 9.3
CVE-2026-15435 IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability 31.07.2026 9.8
CVE-2026-53431 Boruta accepts expired JWT client assertions due to missing exp claim validation 31.07.2026 9.1
CVE-2026-47876 VMXNET3 out-of-bounds write vulnerability 30.07.2026 9.3
CVE-2026-54363 CentreStack < 17.5 Hardcoded Key Token Forgery RCE 30.07.2026 9.3
CVE-2026-59309 vCenter authentication-bypass vulnerability 30.07.2026 9.8
CVE-2026-59310 vCenter directory-traversal vulnerability 30.07.2026 9.8
CVE-2026-18363 Weak password recovery mechanism in osTicket by Enhancesoft LLC 30.07.2026 9.1
CVE-2026-44090 Missing authentication for MQTT Broker 30.07.2026 9.3
CVE-2026-44101 OCPP reconfiguration vulnerability 30.07.2026 9.3
CVE-2026-44104 ControllerAgent does not perform validation of firmware 30.07.2026 9.3
CVE-2026-44108 Firewall bypass during shutdown 30.07.2026 9.3
CVE-2026-7849 Command Injection in SCM (idledisconnect parameter) 30.07.2026 9.3
CVE-2026-58046 30.07.2026 9.9
CVE-2026-58066 31.07.2026 9.8
CVE-2026-16610 Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key 30.07.2026 9.8
CVE-2026-48449 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 30.07.2026 10
CVE-2026-67595 VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php 30.07.2026 9.2
CVE-2026-16326 consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 29.07.2026 10
CVE-2026-67426 Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration 29.07.2026 9.3
CVE-2026-67429 Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) 29.07.2026 10
CVE-2026-14529 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery 30.07.2026 9.4
CVE-2026-18236 Google-ADK Continuation Forgery 29.07.2026 9.3
CVE-2026-41939 Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly 30.07.2026 9.3
CVE-2026-54680 Logging operator has Fluentd configuration injection that allows remote code execution 30.07.2026 9.9
CVE-2026-8338 Authentication and Authorization Bypass in Coverity Connect 29.07.2026 9.2
CVE-2026-54735 prebid-server's request forgery vulnerability allows for possible host environment data extraction 29.07.2026 10
CVE-2026-60112 AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() 29.07.2026 9.3
CVE-2026-60113 AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes 30.07.2026 9.3
CVE-2026-67191 Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser 29.07.2026 9.3
CVE-2026-67192 Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher 29.07.2026 9.2
CVE-2026-65886 Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65887 Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 30.07.2026 10
CVE-2026-65888 Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 30.07.2026 10
CVE-2026-65889 Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65890 Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-9177 Server-Side Template Injection in SecureTransport's Apache Velocity mail templates 31.07.2026 9.4
CVE-2026-0667 29.07.2026 9.3
CVE-2026-65884 Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 30.07.2026 10
CVE-2026-65885 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 30.07.2026 9.4
CVE-2026-14488 Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter 29.07.2026 9.1
CVE-2026-14900 Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter 29.07.2026 9.8
CVE-2026-65883 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 29.07.2026 10
CVE-2025-10656 Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation 29.07.2026 9.8
CVE-2026-58161 Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server 29.07.2026 9.2
CVE-2026-58179 Apache Traffic Server: regex_remap plugin overflows the stack from attacker input 30.07.2026 9.2
CVE-2026-58154 Apache Traffic Server: Memory-safety errors in MIME and header parsing 29.07.2026 9.2
CVE-2026-58155 Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling 29.07.2026 9.2
CVE-2026-18191 Vacron|IP Camera - Hidden Functionality 29.07.2026 9.3
CVE-2026-63227 Unrestricted SCORM file upload vulnerability 29.07.2026 9.9
CVE-2026-63229 Pre-authentication blind SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63230 Pre-authentication error-based SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63232 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63233 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63234 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-18072 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter 29.07.2026 9.8
CVE-2026-54658 @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution 29.07.2026 9.8
CVE-2026-62325 goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) 29.07.2026 9.1
CVE-2026-64863 goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite 29.07.2026 9.1
CVE-2026-14446 IBM WebSphere Application Server is affected by a privilege escalation 30.07.2026 9.8
CVE-2026-14512 IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information 30.07.2026 9.8
CVE-2026-14958 OS command injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14959 OS Command Injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14973 Path Traversal in IBM Desktop App 31.07.2026 9.3
CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance 29.07.2026 9.4
CVE-2026-16498 terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 28.07.2026 10
CVE-2026-50736 28.07.2026 9
CVE-2026-50737 28.07.2026 9
CVE-2026-67174 DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick 28.07.2026 9.2
CVE-2026-65880 Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 28.07.2026 10
CVE-2026-11841 CVE-2026-11841 28.07.2026 9.4
CVE-2026-16462 SQL injection via unauthenticated GetGridData endpoint 28.07.2026 9.3
CVE-2026-11756 Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x 28.07.2026 10
CVE-2026-15014 SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter 28.07.2026 9.8
CVE-2026-64541 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket 30.07.2026 9.8
CVE-2026-64551 sctp: validate STALE_COOKIE cause length before reading staleness 30.07.2026 9.1
CVE-2026-66824 Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding 28.07.2026 9.2
CVE-2026-48030 Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78) 27.07.2026 9.9
CVE-2026-55579 Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise 27.07.2026 9.8
CVE-2026-63077 28.07.2026 9.8
CVE-2026-16812 VeloCloud Orchestrator OS Command Injection 28.07.2026 10
CVE-2026-66394 SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass 28.07.2026 9.3
CVE-2026-66395 SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol 28.07.2026 9.4
CVE-2026-66396 SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL 28.07.2026 9.3
CVE-2026-66398 phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API 28.07.2026 9.4
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication 28.07.2026 9.1
CVE-2026-59527 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59533 WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59538 WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59549 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59550 WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-61511 vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php 29.07.2026 9.3
CVE-2026-65766 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 28.07.2026 9.2
CVE-2026-65876 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 28.07.2026 9.2
CVE-2026-48144 Apache Thrift: c_glib TLS Client Missing Hostname Verification 28.07.2026 9.1
CVE-2026-55971 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() 28.07.2026 9.3
CVE-2026-64534 nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path 30.07.2026 9.8
CVE-2026-64535 nvmet-tcp: Fix potential UAF when ddgst mismatch 30.07.2026 9.8
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle 27.07.2026 9.8
CVE-2026-66012 SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP 28.07.2026 10
CVE-2026-66013 OpenRemote before 1.26.2 Authentication Bypass via Console Registration 29.07.2026 9.3
CVE-2026-64523 net/handshake: Take a long-lived file reference at submit 27.07.2026 9.8
CVE-2026-64257 smb: client: reject overlapping data areas in SMB2 responses 27.07.2026 9.1
CVE-2026-64268 RDMA/siw: bound Read Response placement to the RREAD length 27.07.2026 9.8
CVE-2026-64269 RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg 27.07.2026 9.1
CVE-2026-64303 spi: fsl-lpspi: terminate the RX channel on TX prepare failure path 27.07.2026 9.8
CVE-2026-64319 nvmet-auth: validate reply message payload bounds against transfer length 27.07.2026 9.1
CVE-2026-64320 nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page 27.07.2026 9.1
CVE-2026-64355 bpf: Reject fragmented frames in devmap 27.07.2026 9.8
CVE-2026-64383 smb: client: fix double-free in SMB2_flush() replay 27.07.2026 9.8
CVE-2026-64384 smb: client: fix change notify replay double-free 27.07.2026 9.8
CVE-2026-64385 smb: client: fix double-free in SMB2_ioctl() replay 27.07.2026 9.8
CVE-2026-64386 smb: client: fix query_info() replay double-free 27.07.2026 9.8
CVE-2026-64387 smb: client: fix query directory replay double-free 27.07.2026 9.8
CVE-2026-64391 ksmbd: use opener credentials for ADS I/O 27.07.2026 9.8
CVE-2026-64392 ksmbd: use opener credentials for delete-on-close 27.07.2026 9.1
CVE-2026-64393 ksmbd: run set info with opener credentials 27.07.2026 9.1
CVE-2026-64397 ksmbd: serialize QUERY_DIRECTORY requests per file 27.07.2026 9.8
CVE-2026-64399 ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE 27.07.2026 9.8
CVE-2026-64410 netfilter: flowtable: IPIP tunnel hardware offload is not yet support 27.07.2026 9.8
CVE-2026-64439 crypto: krb5 - filter out async aead implementations at alloc 27.07.2026 9.8
CVE-2026-64450 tipc: fix out-of-bounds read in broadcast Gap ACK blocks 27.07.2026 9.1
CVE-2026-64459 tcp: restore RCU grace period in tcp_ao_destroy_sock 27.07.2026 9.8
CVE-2026-61884 Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel 27.07.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2025-62347 31.07.2026 4.3
CVE-2026-16503 VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities 31.07.2026
CVE-2026-16504 VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities 31.07.2026
CVE-2026-56567 HCL iControl is affected by multiple security vulnerabilities. 31.07.2026 5.1
CVE-2026-56568 HCL iControl is affected by multiple security vulnerabilities. 31.07.2026 3.7
CVE-2026-56569 HCL iControl is affected by multiple security vulnerabilities. 31.07.2026 4
CVE-2026-56570 HCL iControl is affected by multiple security vulnerabilities. 31.07.2026 3.7
CVE-2026-56571 HCL iControl is affected by multiple security vulnerabilities. 31.07.2026 3.7
CVE-2026-59231 Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs 31.07.2026
CVE-2026-10685 Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler 31.07.2026 7.6
CVE-2026-18446 fast-uri vulnerable to host confusion via backslash authority introducer 31.07.2026 7.5
CVE-2026-51229 31.07.2026
CVE-2026-51230 31.07.2026
CVE-2026-51231 31.07.2026
CVE-2026-51232 31.07.2026
CVE-2026-51233 31.07.2026
CVE-2026-51234 31.07.2026
CVE-2026-51236 31.07.2026
CVE-2026-51237 31.07.2026
CVE-2026-51238 31.07.2026
CVE-2026-51239 31.07.2026
CVE-2026-51240 31.07.2026
CVE-2026-51241 31.07.2026
CVE-2026-51242 31.07.2026
CVE-2026-51243 31.07.2026
CVE-2026-51245 31.07.2026
CVE-2026-51246 31.07.2026
CVE-2026-51247 31.07.2026
CVE-2026-51248 31.07.2026
CVE-2026-51249 31.07.2026
CVE-2026-51250 31.07.2026
CVE-2026-51253 31.07.2026
CVE-2026-51255 31.07.2026
CVE-2026-51256 31.07.2026
CVE-2026-51257 31.07.2026
CVE-2026-51258 31.07.2026
CVE-2026-51262 31.07.2026
CVE-2026-51264 31.07.2026
CVE-2026-51265 31.07.2026
CVE-2026-51276 31.07.2026
CVE-2026-51277 31.07.2026
CVE-2026-51278 31.07.2026
CVE-2026-51279 31.07.2026
CVE-2026-51280 31.07.2026
CVE-2026-51281 31.07.2026
CVE-2026-51282 31.07.2026
CVE-2026-51283 31.07.2026
CVE-2026-51284 31.07.2026
CVE-2026-51285 31.07.2026
CVE-2026-51286 31.07.2026
CVE-2026-51287 31.07.2026
CVE-2026-51288 31.07.2026
CVE-2026-51289 31.07.2026
CVE-2026-51299 31.07.2026
CVE-2026-51301 31.07.2026
CVE-2026-67350 Serendipity < 2.6.1 Open Redirect via exit.php 31.07.2026
CVE-2026-28144 WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability 31.07.2026 4.3
CVE-2026-28145 WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability 31.07.2026 5.3
CVE-2026-65636 YAML injection via unescaped newlines in ymlr document comments 31.07.2026
CVE-2026-17561 Unauthenticated RCE in Innotim Software's Logsign SIEM 31.07.2026 9.8
CVE-2026-17592 31.07.2026
CVE-2026-15227 Missing Authorization Allows Editing of Foreign Reports 31.07.2026
CVE-2026-18358 Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service 31.07.2026
CVE-2026-68574 31.07.2026
CVE-2026-68575 31.07.2026
CVE-2026-68576 31.07.2026
CVE-2026-68577 31.07.2026
CVE-2026-9611 31.07.2026
CVE-2025-67649 Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script 31.07.2026
CVE-2025-67650 Authenticated SQL Injection in PHP Jabbers scripts 31.07.2026
CVE-2025-67651 CSRF in PHP Jabbers scripts 31.07.2026
CVE-2026-46593 Authenticated SQL Injection in PHP Poll Script 31.07.2026
CVE-2026-46594 Reflected XSS in PHP Poll Script 31.07.2026
CVE-2026-44615 Path traversal in NotebookRepo note and folder path composition 31.07.2026
CVE-2026-16843 31.07.2026 7.2
CVE-2026-17567 Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter 31.07.2026 5.3
CVE-2026-62391 Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases 31.07.2026
CVE-2026-64607 Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS 31.07.2026
CVE-2026-10079 Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection 31.07.2026
CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check 31.07.2026
CVE-2026-15722 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing 31.07.2026
CVE-2026-18436 MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint 31.07.2026 5.3
CVE-2026-18437 MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates 31.07.2026 5.3
CVE-2026-65310 Missing authentication and permissive CORS policy 31.07.2026 7.5
CVE-2026-65311 Missing authentication for logging-configuration endpoint 31.07.2026 5.3
CVE-2026-65313 Use of hard-coded VNC credentials in the engineering-workstation provisioning 31.07.2026 8.1
CVE-2026-16105 Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints 31.07.2026
CVE-2026-18203 Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes 31.07.2026
CVE-2026-18206 Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass 31.07.2026
CVE-2026-18208 Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim 31.07.2026
CVE-2026-18209 Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check 31.07.2026
CVE-2026-18211 Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains 31.07.2026
CVE-2026-18214 Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction 31.07.2026
CVE-2026-18215 Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant 31.07.2026
CVE-2026-18217 Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution 31.07.2026
CVE-2026-18218 Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero 31.07.2026
CVE-2026-65309 Storage of passwords in a reversible format 31.07.2026 7.5
CVE-2026-12251 Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Selection Field 31.07.2026
CVE-2026-12376 Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint 31.07.2026
CVE-2026-12695 miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret 31.07.2026
CVE-2026-12697 wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR 31.07.2026
CVE-2026-12720 Kirki < 6.0.13 - Unauthenticated PHP Object Injection 31.07.2026
CVE-2026-12721 Kirki < 6.0.13 - Unauthenticated SQL Injection 31.07.2026
CVE-2026-13392 ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) 31.07.2026
CVE-2026-13393 ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite) 31.07.2026
CVE-2026-13609 Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field 31.07.2026
CVE-2026-14317 GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass 31.07.2026
CVE-2026-14319 GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure 31.07.2026
CVE-2026-14333 Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory 31.07.2026
CVE-2026-14483 Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command 31.07.2026 9.8
CVE-2026-14554 Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters 31.07.2026
CVE-2026-14830 FlxWoo < 3.1.1 - Unauthenticated Payment Bypass 31.07.2026
CVE-2026-14833 Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute 31.07.2026
CVE-2026-14834 Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX 31.07.2026
CVE-2026-14843 Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR 31.07.2026
CVE-2026-14845 NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget 31.07.2026
CVE-2026-14847 Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR 31.07.2026
CVE-2026-14849 Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exposure via Residual Export Files 31.07.2026
CVE-2026-14862 Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing Authorization 31.07.2026
CVE-2026-14919 ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute 31.07.2026
CVE-2026-14921 Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode 31.07.2026
CVE-2026-14922 WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment 31.07.2026
CVE-2026-14927 FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes 31.07.2026
CVE-2026-14928 JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject 31.07.2026
CVE-2026-14929 JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR 31.07.2026
CVE-2026-14930 JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload 31.07.2026
CVE-2026-14931 JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure 31.07.2026
CVE-2026-15048 GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat History 31.07.2026
CVE-2026-15209 JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR 31.07.2026
CVE-2026-15258 Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter 31.07.2026
CVE-2026-15381 WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter 31.07.2026
CVE-2026-16236 Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload 31.07.2026 8.8
CVE-2026-18452 Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials 31.07.2026
CVE-2026-8155 BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR 31.07.2026
CVE-2026-56670 ComfyUI: Stored XSS via SVG file upload on the /view endpoint 31.07.2026 8.2
CVE-2026-56671 ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read 31.07.2026 7.5
CVE-2026-56672 ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization 31.07.2026 8.2
CVE-2026-56673 ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration 31.07.2026 7.5
CVE-2026-63221 CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions 31.07.2026 9.4
CVE-2026-63222 CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames 31.07.2026 7.5
CVE-2026-63223 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules 31.07.2026 9.8
CVE-2026-43829 tbc 31.07.2026
CVE-2026-43830 tbc 31.07.2026
CVE-2026-43831 tbc 31.07.2026
CVE-2026-43832 tbc 31.07.2026
CVE-2026-43833 tbc 31.07.2026
CVE-2026-55495 Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account 31.07.2026 4.3
CVE-2026-55496 Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate 31.07.2026 4.3
CVE-2026-55497 Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS) 31.07.2026 6.5
CVE-2026-55499 Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipients 31.07.2026 4.3
CVE-2026-55502 Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials 31.07.2026 7.1
CVE-2026-62323 Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored 31.07.2026 6.3
CVE-2026-63220 CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() 31.07.2026 4.8
CVE-2026-14541 Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider 31.07.2026
CVE-2026-18157 Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection 31.07.2026
CVE-2026-6889 31.07.2026
CVE-2026-6890 31.07.2026
CVE-2026-14537 Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints 31.07.2026
CVE-2026-14538 BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox 31.07.2026
CVE-2026-14539 Denial of Service via Unrestricted Payload Buffering in MCP Toolbox 31.07.2026
CVE-2026-14540 Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox 31.07.2026
CVE-2026-58039 31.07.2026
CVE-2026-10031 SFTPGo 2.7.4 Permission Bypass via Symbolic Link Creation 31.07.2026
CVE-2026-61893 MZ Automation lib60870 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-63033 MZ Automation lib60870 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-63550 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-66369 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-66720 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-56758 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-65421 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-66349 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-66360 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 7.5
CVE-2026-66364 MZ Automation libiec61850 Out-of-bounds Read 30.07.2026 6.5
CVE-2026-66421 OpenClaw Dashboard Stored XSS via lastMessage Session Field 31.07.2026
CVE-2026-63035 o6 Automation open62541 Use After Free 30.07.2026 8.1
CVE-2026-63362 o6 Automation open62541 Integer Underflow 30.07.2026 5.9
CVE-2026-65423 o6 Automation open62541 Integer Overflow or Wraparound 30.07.2026 8.8
CVE-2026-66420 MeshCentral Cross-Site WebSocket Hijacking via Origin Validation Bypass on Self-Signed Certificate Deployments 31.07.2026
CVE-2026-12562 Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function 30.07.2026 8.8
CVE-2026-18064 NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference 30.07.2026 7.5
CVE-2026-63559 o6 Automation open62541 Integer Overflow or Wraparound 30.07.2026 7.5
CVE-2026-64816 RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath 31.07.2026
CVE-2026-5846 Hard-coded Cryptographic Key in Watchfire Signs Controllers 31.07.2026 5.7
CVE-2026-62845 Kamaji: SQL injection via unescaped datastore identifiers in PostgreSQL/MySQL drivers 31.07.2026 4.7
CVE-2026-68562 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering 31.07.2026
CVE-2026-68563 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions 30.07.2026