CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-65321 PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS 02.08.2026 9.3
CVE-2025-71401 better-auth before 1.4.1 basePath Modification DoS 02.08.2026 9.3
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token 02.08.2026 9.3
CVE-2026-8457 WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT 01.08.2026 9.8
CVE-2026-66402 FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass 01.08.2026 9.3
CVE-2026-67289 FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection 01.08.2026 9.3
CVE-2026-67292 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure 01.08.2026 9.3
CVE-2026-67293 FreeRDP before 3.29.0 Improper Certificate Hostname Validation 01.08.2026 9.3
CVE-2026-67294 FreeRDP before 3.29.0 TLS Certificate EKU Bypass 01.08.2026 9.3
CVE-2026-67305 FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr 01.08.2026 9.4
CVE-2026-67308 Wazuh GitHub Actions Shell Injection via Fork Pull Request 02.08.2026 9.3
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options 01.08.2026 9.3
CVE-2026-67330 better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision 01.08.2026 9.4
CVE-2026-67336 better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider 01.08.2026 9.4
CVE-2026-67340 ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts 01.08.2026 9.3
CVE-2026-67341 ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION 01.08.2026 9.3
CVE-2026-67342 ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers 01.08.2026 9.3
CVE-2026-15964 Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change 01.08.2026 9.8
CVE-2026-3141 FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter 01.08.2026 9.1
CVE-2026-68771 ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization 31.07.2026 9.3
CVE-2026-68770 sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False 31.07.2026 9.3
CVE-2026-54725 vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API 31.07.2026 9.6
CVE-2026-52855 Wings exposes node configuration secrets through egg configuration-file templating 31.07.2026 9.9
CVE-2026-58048 01.08.2026 9.4
CVE-2026-17349 pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner 01.08.2026 9.3
CVE-2026-17351 pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) 01.08.2026 9.4
CVE-2026-17566 pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) 01.08.2026 9.4
CVE-2026-17561 Unauthenticated RCE in Innotim Software's Logsign SIEM 31.07.2026 9.8
CVE-2025-67649 Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script 31.07.2026 9.3
CVE-2026-14483 Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command 31.07.2026 9.8
CVE-2026-18452 Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials 31.07.2026 10
CVE-2026-63221 CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions 31.07.2026 9.4
CVE-2026-63223 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules 31.07.2026 9.8
CVE-2026-66418 OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field 31.07.2026 9.3
CVE-2026-68502 LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE 31.07.2026 9.8
CVE-2026-68503 LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard 31.07.2026 9.8
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability 31.07.2026 10
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent 31.07.2026 9.9
CVE-2026-67208 Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console 31.07.2026 9.3
CVE-2026-67594 Spikster Missing Authentication via API Route Group 31.07.2026 9.3
CVE-2026-66066 Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing 01.08.2026 9.5
CVE-2026-12943 This Power Hardware Management Console update is being released to address 31.07.2026 9.8
CVE-2026-12118 IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data 30.07.2026 9.8
CVE-2026-13435 Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure 31.07.2026 9.9
CVE-2026-48499 Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache 30.07.2026 9.3
CVE-2026-12940 Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints 31.07.2026 9.8
CVE-2026-28323 SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability 31.07.2026 9.8
CVE-2026-4978 SQLi in UMAI Vision's Traffic Analysis System 30.07.2026 9.8
CVE-2026-11707 Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager 30.07.2026 9.3
CVE-2026-15435 IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability 31.07.2026 9.8
CVE-2026-53431 Boruta accepts expired JWT client assertions due to missing exp claim validation 31.07.2026 9.1
CVE-2026-47876 VMXNET3 out-of-bounds write vulnerability 30.07.2026 9.3
CVE-2026-54363 CentreStack < 17.5 Hardcoded Key Token Forgery RCE 30.07.2026 9.3
CVE-2026-59309 vCenter authentication-bypass vulnerability 30.07.2026 9.8
CVE-2026-59310 vCenter directory-traversal vulnerability 30.07.2026 9.8
CVE-2026-18363 Weak password recovery mechanism in osTicket by Enhancesoft LLC 30.07.2026 9.1
CVE-2026-44090 Missing authentication for MQTT Broker 30.07.2026 9.3
CVE-2026-44101 OCPP reconfiguration vulnerability 31.07.2026 9.3
CVE-2026-44104 ControllerAgent does not perform validation of firmware 30.07.2026 9.3
CVE-2026-44108 Firewall bypass during shutdown 30.07.2026 9.3
CVE-2026-7849 Command Injection in SCM (idledisconnect parameter) 30.07.2026 9.3
CVE-2026-58046 30.07.2026 9.9
CVE-2026-58066 31.07.2026 9.8
CVE-2026-16610 Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key 30.07.2026 9.8
CVE-2026-48449 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 30.07.2026 10
CVE-2026-67595 VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php 30.07.2026 9.2
CVE-2026-16326 consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 29.07.2026 10
CVE-2026-67426 Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration 29.07.2026 9.3
CVE-2026-67429 Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) 29.07.2026 10
CVE-2026-14529 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery 30.07.2026 9.4
CVE-2026-18236 Google-ADK Continuation Forgery 29.07.2026 9.3
CVE-2026-41939 Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly 30.07.2026 9.3
CVE-2026-54680 Logging operator has Fluentd configuration injection that allows remote code execution 30.07.2026 9.9
CVE-2026-8338 Authentication and Authorization Bypass in Coverity Connect 29.07.2026 9.2
CVE-2026-54735 prebid-server's request forgery vulnerability allows for possible host environment data extraction 29.07.2026 10
CVE-2026-60112 AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() 29.07.2026 9.3
CVE-2026-60113 AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes 30.07.2026 9.3
CVE-2026-67191 Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser 29.07.2026 9.3
CVE-2026-67192 Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher 29.07.2026 9.2
CVE-2026-65886 Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65887 Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 01.08.2026 10
CVE-2026-65888 Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 01.08.2026 10
CVE-2026-65889 Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65890 Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-9177 Server-Side Template Injection in SecureTransport's Apache Velocity mail templates 31.07.2026 9.4
CVE-2026-0667 29.07.2026 9.3
CVE-2026-65884 Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 30.07.2026 10
CVE-2026-65885 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 30.07.2026 9.4
CVE-2026-14488 Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter 29.07.2026 9.1
CVE-2026-14900 Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter 29.07.2026 9.8
CVE-2026-65883 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 29.07.2026 10
CVE-2025-10656 Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation 29.07.2026 9.8
CVE-2026-58161 Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server 29.07.2026 9.2
CVE-2026-58179 Apache Traffic Server: regex_remap plugin overflows the stack from attacker input 30.07.2026 9.2
CVE-2026-58154 Apache Traffic Server: Memory-safety errors in MIME and header parsing 29.07.2026 9.2
CVE-2026-58155 Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling 29.07.2026 9.2
CVE-2026-18191 Vacron|IP Camera - Hidden Functionality 29.07.2026 9.3
CVE-2026-63227 Unrestricted SCORM file upload vulnerability 29.07.2026 9.9
CVE-2026-63229 Pre-authentication blind SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63230 Pre-authentication error-based SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63232 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63233 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63234 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-18072 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter 29.07.2026 9.8
CVE-2026-54658 @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution 29.07.2026 9.8
CVE-2026-62325 goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) 29.07.2026 9.1
CVE-2026-64863 goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite 29.07.2026 9.1
CVE-2026-14446 IBM WebSphere Application Server is affected by a privilege escalation 30.07.2026 9.8
CVE-2026-14512 IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information 30.07.2026 9.8
CVE-2026-14958 OS command injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14959 OS Command Injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14973 Path Traversal in IBM Desktop App 31.07.2026 9.3
CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance 29.07.2026 9.4
CVE-2026-16498 terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 28.07.2026 10
CVE-2026-50736 28.07.2026 9
CVE-2026-50737 28.07.2026 9
CVE-2026-67174 DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick 28.07.2026 9.2
CVE-2026-65880 Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 28.07.2026 10
CVE-2026-11841 CVE-2026-11841 28.07.2026 9.4
CVE-2026-16462 SQL injection via unauthenticated GetGridData endpoint 28.07.2026 9.3
CVE-2026-11756 Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x 28.07.2026 10
CVE-2026-15014 SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter 28.07.2026 9.8
CVE-2026-64541 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket 30.07.2026 9.8
CVE-2026-64551 sctp: validate STALE_COOKIE cause length before reading staleness 30.07.2026 9.1
CVE-2026-66824 Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding 28.07.2026 9.2
CVE-2026-48030 Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78) 27.07.2026 9.9
CVE-2026-55579 Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise 27.07.2026 9.8
CVE-2026-63077 28.07.2026 9.8
CVE-2026-16812 VeloCloud Orchestrator OS Command Injection 28.07.2026 10
CVE-2026-66394 SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass 28.07.2026 9.3
CVE-2026-66395 SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol 28.07.2026 9.4
CVE-2026-66396 SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL 28.07.2026 9.3
CVE-2026-66398 phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API 28.07.2026 9.4
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication 28.07.2026 9.1
CVE-2026-59527 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59533 WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59538 WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59549 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59550 WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-61511 vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php 29.07.2026 9.3
CVE-2026-65766 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 28.07.2026 9.2
CVE-2026-65876 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 28.07.2026 9.2
CVE-2026-48144 Apache Thrift: c_glib TLS Client Missing Hostname Verification 28.07.2026 9.1
CVE-2026-55971 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() 28.07.2026 9.3
CVE-2026-64534 nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path 30.07.2026 9.8
CVE-2026-64535 nvmet-tcp: Fix potential UAF when ddgst mismatch 30.07.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-9856 Path Traversal in huggingface/transformers 02.08.2026
CVE-2026-65321 PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS 02.08.2026
CVE-2026-10774 PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS 02.08.2026 2.4
CVE-2025-71399 Better Auth before 1.4.4 Path Normalization Bypass via rou3 02.08.2026
CVE-2025-71400 better-auth passkey before 1.4.0 IDOR via delete-passkey 02.08.2026
CVE-2025-71401 better-auth before 1.4.1 basePath Modification DoS 02.08.2026
CVE-2026-67356 ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger 02.08.2026
CVE-2026-67357 ArcadeDB before 26.7.3 Information Disclosure via get_server_settings 02.08.2026
CVE-2026-68578 ArcadeDB before 26.7.3 Authentication Bypass via MCP Transport 02.08.2026
CVE-2026-68579 FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read 02.08.2026
CVE-2026-68580 FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel 02.08.2026
CVE-2026-68581 Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision 02.08.2026
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token 02.08.2026
CVE-2026-68583 luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name 02.08.2026
CVE-2026-12231 Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' 02.08.2026 6.4
CVE-2025-15675 Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text 02.08.2026
CVE-2026-11872 Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item 02.08.2026
CVE-2026-12586 Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset 02.08.2026
CVE-2026-13389 WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes 02.08.2026
CVE-2026-14817 Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes 02.08.2026
CVE-2026-14841 King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget 02.08.2026
CVE-2026-14864 JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode 02.08.2026
CVE-2026-14920 AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter 02.08.2026
CVE-2026-14938 FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR 02.08.2026
CVE-2026-15151 Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications 02.08.2026
CVE-2026-15206 SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile 02.08.2026
CVE-2026-15236 Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure 02.08.2026
CVE-2026-15241 ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response 02.08.2026
CVE-2026-15248 Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR 02.08.2026
CVE-2026-15385 RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS 02.08.2026
CVE-2026-15939 Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API 02.08.2026
CVE-2026-16042 LWS Optimize < 3.4 - Subscriber+ Cache Deletion 02.08.2026
CVE-2026-16062 Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content 02.08.2026
CVE-2026-16063 Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content 02.08.2026
CVE-2026-16064 Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event 02.08.2026
CVE-2026-16256 Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation 02.08.2026
CVE-2026-16261 Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover 02.08.2026
CVE-2026-16273 Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta 02.08.2026
CVE-2026-16285 WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download 02.08.2026
CVE-2026-16291 ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR 02.08.2026
CVE-2026-16292 Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF 02.08.2026
CVE-2026-16540 Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint 02.08.2026
CVE-2026-18570 Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed 02.08.2026
CVE-2026-18571 Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation 02.08.2026
CVE-2026-18572 Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes 02.08.2026
CVE-2026-18573 Keycloak-services: keycloak-services: client access-type policy condition bypass during client update 02.08.2026
CVE-2026-9335 Improper Handling of HDF5 ExternalLinks in keras-team/keras 02.08.2026
CVE-2026-13339 CubeWP Framework <= 1.1.30 - Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter 01.08.2026 7.5
CVE-2026-18352 User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter 01.08.2026 7.5
CVE-2026-8457 WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT 01.08.2026 9.8
CVE-2026-17002 01.08.2026