CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths 13.08.2026 9.2
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header 13.08.2026 9.1
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode 13.08.2026 9.1
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure 13.08.2026 9.1
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink 13.08.2026 9.2
CVE-2026-27544 WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability 13.08.2026 10
CVE-2026-28001 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28008 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28142 WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28148 WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability 13.08.2026 9.8
CVE-2026-28149 WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability 13.08.2026 9.8
CVE-2026-28185 WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-61962 WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability 13.08.2026 10
CVE-2026-61966 WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61967 WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-61969 WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-66436 WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66446 WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability 13.08.2026 9.8
CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66478 WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66691 WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability 13.08.2026 9.8
CVE-2026-49827 WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) 13.08.2026 9.8
CVE-2026-73483 Flowise before 3.1.3 Sandbox Escape via Puppeteer 13.08.2026 9.4
CVE-2026-73485 Flowise before 3.1.3 Remote Code Execution via Airtable Agent 13.08.2026 9
CVE-2026-73486 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV 13.08.2026 9
CVE-2026-73487 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent 13.08.2026 9
CVE-2026-73601 Flowise before 3.1.3 Remote Code Execution via Custom MCP 13.08.2026 9
CVE-2026-73602 Flowise before 3.1.3 Sandbox Escape to RCE 13.08.2026 9
CVE-2026-73608 SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget 13.08.2026 9.2
CVE-2026-59503 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor 13.08.2026 9.1
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security 13.08.2026 9.1
CVE-2026-59506 Priority – CWE-306: Missing Authentication for Critical Function 13.08.2026 9.3
CVE-2026-59507 Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control 13.08.2026 9.3
CVE-2026-59500 Priority - CWE-287: Improper Authentication 13.08.2026 10
CVE-2026-15413 Link Factory - Backdoor 13.08.2026 10
CVE-2026-49819 UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd 13.08.2026 9.8
CVE-2026-49481 UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd 12.08.2026 9.6
CVE-2026-71193 13.08.2026 9.6
CVE-2026-71471 Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image 13.08.2026 9
CVE-2024-27253 IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request 12.08.2026 10
CVE-2026-73501 kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default 13.08.2026 9.1
CVE-2026-73519 WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret 13.08.2026 9.3
CVE-2026-19001 MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names 13.08.2026 9.5
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE 13.08.2026 9.9
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 13.08.2026 9.9
CVE-2026-63294 Root RCE via image backup.yaml symlink 13.08.2026 9.9
CVE-2026-17083 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 13.08.2026 9.8
CVE-2026-63296 Project restriction bypass via instance migration config override 13.08.2026 9.9
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 13.08.2026 9.9
CVE-2026-72508 Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) 13.08.2026 9.9
CVE-2026-73414 Shescape: Shell injection via unescaped parentheses on Windows with CMD 12.08.2026 9.2
CVE-2026-19656 ScadaLTS Authenticated Remote Code Execution 12.08.2026 9.9
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag 12.08.2026 9.9
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution 13.08.2026 9.9
CVE-2026-72789 SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks 12.08.2026 9.2
CVE-2026-72793 SiYuan before v3.7.4 Information Disclosure via /api/system/getConf 12.08.2026 9.2
CVE-2026-72794 siyuan before v3.7.4 Session Cookie Key Disclosure via getConf 12.08.2026 9.2
CVE-2026-72795 SiYuan before v3.7.4 Information Disclosure via Embed Block 12.08.2026 9.2
CVE-2026-72798 SiYuan before v3.7.4 Information Disclosure via renderAttributeView 12.08.2026 9.2
CVE-2026-72804 SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints 12.08.2026 9.2
CVE-2026-73268 Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection 12.08.2026 9.9
CVE-2026-73269 Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa 12.08.2026 9.9
CVE-2026-73329 CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint 12.08.2026 9.2
CVE-2026-73332 CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field 12.08.2026 9.2
CVE-2026-73407 Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) 12.08.2026 9
CVE-2026-73300 Budibase: SQL Injection via `multipleStatements: true` 12.08.2026 9.6
CVE-2026-16860 IBM i is Affected By Remote Code Execution Vulnerability [] 12.08.2026 9.9
CVE-2026-16956 IBM Db2 Mirror for i is vulnerable to OS command injection [] 12.08.2026 9.8
CVE-2026-17218 IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] 12.08.2026 9.8
CVE-2026-73299 Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer 12.08.2026 10
CVE-2026-17276 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 9.6
CVE-2026-73296 Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure 13.08.2026 9.4
CVE-2026-73294 Semaphore U: OS Command Injection 12.08.2026 9.9
CVE-2026-64639 12.08.2026 9.3
CVE-2026-73263 Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path 12.08.2026 9.9
CVE-2026-50561 Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse 12.08.2026 9.4
CVE-2026-67285 Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 13.08.2026 9.2
CVE-2026-57858 Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID 12.08.2026 9.3
CVE-2026-67282 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 12.08.2026 10
CVE-2025-41769 Unauthenticated Buffer Overflow in PROFINET Service 13.08.2026 9.3
CVE-2026-66659 WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability 12.08.2026 9.3
CVE-2026-70398 Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace 12.08.2026 9.6
CVE-2026-72526 Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation 12.08.2026 9.9
CVE-2026-5917 libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend 12.08.2026 9.4
CVE-2026-67568 Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials 12.08.2026 9.3
CVE-2026-68067 Mira Hormone Monitor, Mira Android App Weak Authentication 12.08.2026 9.3
CVE-2026-48765 TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding 12.08.2026 9.9
CVE-2026-16230 Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field 11.08.2026 9.8
CVE-2026-45618 LiquidJS is Vulnerable to Remote Code Execution 13.08.2026 10
CVE-2026-73034 DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header 13.08.2026 9.3
CVE-2026-73032 PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() 11.08.2026 9.4
CVE-2026-18691 Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure 11.08.2026 9
CVE-2026-72742 DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing 12.08.2026 9.2
CVE-2026-69102 MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust 12.08.2026 9.3
CVE-2026-27302 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-48381 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 11.08.2026 9
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) 12.08.2026 9.1
CVE-2026-71398 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-47705 TypeBot vulnerable to CSV injection in result export 13.08.2026 9.6
CVE-2026-73090 PeerTube: Cross-origin remote video takeover via Update activity 13.08.2026 9.3
CVE-2026-73211 PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() 11.08.2026 9.8
CVE-2026-12571 Authentication Bypass Leading to Account Takeover 12.08.2026 9.8
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 12.08.2026 9.4
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability 12.08.2026 9.8
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability 12.08.2026 9.3
CVE-2026-48362 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 12.08.2026 10
CVE-2026-71384 ColdFusion | Incorrect Authorization (CWE-863) 12.08.2026 9.6
CVE-2026-73080 SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle 13.08.2026 9.3
CVE-2025-31114 Fooocus webui vulnerable to Remote Code Execution 13.08.2026 9.3
CVE-2026-73069 Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution 11.08.2026 9.1
CVE-2026-17061 Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 11.08.2026 10
CVE-2026-47702 TypeBot API tokens stored in plaintext 11.08.2026 9.1
CVE-2026-72920 SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control 11.08.2026 9.8
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection 13.08.2026 9.8
CVE-2026-48056 Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler 11.08.2026 10
CVE-2026-48046 Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler 13.08.2026 9.3
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability 11.08.2026 9.6
CVE-2026-58115 12.08.2026 10
CVE-2026-72785 Craft CMS before 5.10.6 Authorization Bypass via structures/move-element 11.08.2026 9.3
CVE-2026-13737 Command Restriction Bypass 11.08.2026 9.2
CVE-2026-13738 Improper Authorization Validation 11.08.2026 9.2
CVE-2026-72550 Friendica Friendica - SQL Injection 11.08.2026 9.8
CVE-2026-72599 e107 e107 - SQL Injection 11.08.2026 9.8
CVE-2026-72603 wg-easy wg-easy - OS Command Injection 11.08.2026 9.9
CVE-2026-58231 Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) 12.08.2026 10
CVE-2026-10579 Picketlink-federation: auth bypass in picketlink saml unsolicited-response 11.08.2026 9.8
CVE-2026-13716 Path Traversal: '.../...//' in Crafty Controller 11.08.2026 9.1
CVE-2026-19516 CVE-2026-19516 CVE Record 12.08.2026 9.1
CVE-2026-19425 Win Men Intermational|Travel Agency Management System - SQL Injection 12.08.2026 9.3
CVE-2026-34265 Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform 12.08.2026 9.8
CVE-2026-44758 Code Injection vulnerability in Manufacturing Integration and Intelligence 11.08.2026 9.1
CVE-2026-48161 react18-use was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-48160 react-tracked was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation 13.08.2026 9.9
CVE-2026-14450 Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication 11.08.2026 9.9
CVE-2026-18948 Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server 11.08.2026 9.9
CVE-2026-72904 Firecrawl: Arbitrary file read via JSON Schema $ref expansion 11.08.2026 9.3
CVE-2026-72901 Dokploy: Remote Code Execution via volume-backup 10.08.2026 9.9
CVE-2026-72902 Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById 12.08.2026 9.9
CVE-2025-13293 Backdoor / default root credentials 12.08.2026 9.3
CVE-2025-13294 Unauthenticated SQL Injection 12.08.2026 9.3
CVE-2025-15681 Insufficient Webserver Authentication 12.08.2026 9.2
CVE-2026-72880 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` 11.08.2026 9.9
CVE-2026-72882 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers 10.08.2026 9.9
CVE-2026-72886 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) 10.08.2026 9.9
CVE-2026-72876 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* 10.08.2026 9.9
CVE-2026-72877 Dokploy: Command Injection via dockerImage in buildRemoteDocker 13.08.2026 9.6
CVE-2026-72878 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments 12.08.2026 9.6
CVE-2026-72879 Dokploy: Command Injection via Registry Credentials in Swarm Upload 11.08.2026 9.4
CVE-2026-72864 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) 11.08.2026 9.9
CVE-2026-72865 Dokploy: OS Command Injection via compose `composePath` 11.08.2026 9.9
CVE-2026-72867 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) 10.08.2026 9.9
CVE-2026-72868 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection 12.08.2026 9.9
CVE-2026-72869 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE 11.08.2026 9.9
CVE-2026-72872 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` 10.08.2026 9.9
CVE-2026-72863 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host 10.08.2026 9.9
CVE-2026-16626 JasperReports Server: XXE Injection Vulnerability (Unauthenticated) 11.08.2026 9.3
CVE-2026-48159 use-reducer-async was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72740 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` 10.08.2026 9.9
CVE-2026-72862 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE 10.08.2026 9.9
CVE-2026-72898 Metabase SQL injection via password reset endpoint 12.08.2026 10
CVE-2026-72899 Metabase SQL injection via public card or dashboard 11.08.2026 10
CVE-2026-72735 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution 10.08.2026 9.9
CVE-2026-72736 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE 10.08.2026 9.9
CVE-2026-72737 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups 10.08.2026 9.6
CVE-2026-72738 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter 10.08.2026 9.9
CVE-2026-72733 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore 10.08.2026 9.9
CVE-2026-48158 use-context-selector was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-47754 unauthenticated path traversal in Metacat 2.x 10.08.2026 9.3
CVE-2026-63106 ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php 10.08.2026 9.3
CVE-2026-13206 Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection 10.08.2026 9.8
CVE-2026-72564 fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication 10.08.2026 9.6
CVE-2026-72565 Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass 10.08.2026 9.8
CVE-2026-72567 deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete 10.08.2026 9.8
CVE-2026-72569 cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion 10.08.2026 9.1
CVE-2026-72575 daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects 10.08.2026 9.1
CVE-2026-72577 NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection 10.08.2026 9.8
CVE-2026-72580 duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints 10.08.2026 9.8
CVE-2026-72589 alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field 10.08.2026 9.8
CVE-2026-72590 alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter 10.08.2026 9.8
CVE-2026-72592 dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload 10.08.2026 9.8
CVE-2026-72593 dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access 10.08.2026 9.8
CVE-2026-66915 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.9 12.08.2026 10
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 10.08.2026 9.3
CVE-2026-71992 MSI Radix AXE6600 v781521 Command Injection via macfilter 10.08.2026 9.3
CVE-2026-71993 MSI Radix AXE6600 v781521 Command Injection via openvpn function 11.08.2026 9.3
CVE-2026-71991 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 08.08.2026 9.3
CVE-2026-71986 MSI Radix AXE6600 v781521 Command Injection via dmz Function 08.08.2026 9.3
CVE-2026-71987 MSI Radix AXE6600 v781521 Command Injection via alg function 10.08.2026 9.3
CVE-2026-71988 MSI Radix AXE6600 v781521 Command Injection via portFw function 11.08.2026 9.3
CVE-2026-71989 MSI Radix AXE6600 v781521 Command Injection via porTrigger function 10.08.2026 9.3
CVE-2026-71990 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 11.08.2026 9.3
CVE-2026-71984 MSI Radix AXE6600 v781521 Command Injection via urlfilter 10.08.2026 9.3
CVE-2026-71985 MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function 11.08.2026 9.3
CVE-2026-71983 MSI Radix AXE6600 v781521 Command Injection via wps.cgi 11.08.2026 9.3
CVE-2026-71956 D-Link DWR-M961 Command Injection via app.cgi 11.08.2026 9.3
CVE-2026-71957 D-Link DWR-M961 Buffer Overflow via app.cgi 08.08.2026 9.3
CVE-2026-71958 D-Link DWR-M961 Buffer Overflow via quicksetup.cgi 10.08.2026 9.3
CVE-2026-71944 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel 11.08.2026 9.3
CVE-2026-71945 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom 10.08.2026 9.3
CVE-2026-71946 D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun 11.08.2026 9.3
CVE-2026-71947 D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun 08.08.2026 9.3
CVE-2026-71948 D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun 10.08.2026 9.3
CVE-2026-71949 D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup 11.08.2026 9.3
CVE-2026-71950 D-Link DWR-M961 Command Injection via /boafrm/formSmsManage 10.08.2026 9.3
CVE-2026-71951 D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup 11.08.2026 9.3
CVE-2026-71952 D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup 08.08.2026 9.3
CVE-2026-71953 D-Link DWR-M961 Command Injection via /boafrm/formNtp 10.08.2026 9.3
CVE-2026-71954 D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup 11.08.2026 9.3
CVE-2026-71955 D-Link DWR-M961 Command Injection via /boafrm/formWsc 10.08.2026 9.3
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route 11.08.2026 9.8
CVE-2026-46409 OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution 11.08.2026 9.6
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs 10.08.2026 9.2
CVE-2026-48170 scimPatch vulnerable to prototype pollution via unfiltered keys in patch 10.08.2026 9.1
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading 12.08.2026 9.6
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration 10.08.2026 9.8
CVE-2026-48039 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 07.08.2026 9.1
CVE-2026-71851 crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain 08.08.2026 9
CVE-2026-64637 07.08.2026 9.9
CVE-2022-4995 Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp 07.08.2026 9.3
CVE-2026-19264 Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover 07.08.2026 9.3
CVE-2026-66914 Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 10.08.2026 9.2
CVE-2026-54203 TeamDavid: Memory Leak leaking sensitive information 10.08.2026 9.2
CVE-2026-54210 TeamDavid: Buffer Overflow in file names of file upload functionalities 07.08.2026 9.5
CVE-2026-54211 TeamDavid: Buffer Overflow in multiple form data parameters 07.08.2026 9.5
CVE-2026-54212 TeamDavid: Buffer Overflow in JSON-parsing 07.08.2026 9.5
CVE-2026-54213 TeamDavid: Denial of Service via endpoint 'internalRestart' 07.08.2026 9.2
CVE-2026-14364 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' 07.08.2026 9.8
CVE-2026-14365 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' 07.08.2026 9.8
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability 12.08.2026 9.9
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability 12.08.2026 9.9
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability 12.08.2026 9.6
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability 12.08.2026 10
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability 12.08.2026 9.9
CVE-2026-59118 Copilot Cowork Elevation of Privilege Vulnerability 12.08.2026 9.3
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability 12.08.2026 9.9
CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability 12.08.2026 9.8
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability 12.08.2026 9.6
CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability 12.08.2026 10
CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability 12.08.2026 10
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability 12.08.2026 9.1
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability 12.08.2026 9.6
CVE-2025-14561 Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations 07.08.2026 9
CVE-2026-17032 Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server 07.08.2026 9.8
CVE-2026-18367 07.08.2026 9.3
CVE-2026-3418 Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution 07.08.2026 9.1
CVE-2026-48085 OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap 07.08.2026 9.8
CVE-2026-48086 OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN 07.08.2026 9.9
CVE-2026-48087 OpenReception: WebAuthn passkey injection allows account takeover 07.08.2026 9.8
CVE-2026-48088 OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory 08.08.2026 9.4
CVE-2026-5857 Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments 08.08.2026 9.2
CVE-2026-70558 Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token 08.08.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-19487 Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass 13.08.2026
CVE-2026-19744 Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes 13.08.2026
CVE-2026-73514 PostGIS address_standardizer Out-of-Bounds Write via standardize_address() 13.08.2026
CVE-2026-73515 PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer 13.08.2026
CVE-2026-73670 CMS Admin SQL Injection via db_data.php table_name Parameter 13.08.2026
CVE-2026-19710 SourceCodester Simple Student Information System view_department.php sql injection 13.08.2026
CVE-2026-73559 vLLM: Completion prompt lists fan out into unbounded engine requests 13.08.2026 6.5
CVE-2026-73570 13.08.2026 8.9
CVE-2026-73571 13.08.2026 3.1
CVE-2026-73572 13.08.2026 6.1
CVE-2026-73573 13.08.2026 3.1
CVE-2026-73574 13.08.2026 3.1
CVE-2026-73575 13.08.2026 3.1
CVE-2026-73576 13.08.2026 6.3
CVE-2026-12036 13.08.2026
CVE-2026-14256 13.08.2026
CVE-2026-15994 13.08.2026
CVE-2026-19293 SMP security request 13.08.2026 8.8
CVE-2026-28154 WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-49820 Probo has an open redirect bypass via path normalization 13.08.2026 4.7
CVE-2026-49856 @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization 13.08.2026 4.3
CVE-2026-49857 auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback 13.08.2026 7.4
CVE-2026-53783 rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync 13.08.2026
CVE-2026-53784 rsync < 3.5.0 Path Traversal via Symlink Module Root 13.08.2026
CVE-2026-53785 rsync < 3.5.0 Path Traversal Write Escape via --relative Mode 13.08.2026
CVE-2026-53786 rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive 13.08.2026
CVE-2026-53788 rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping 13.08.2026
CVE-2026-53789 rsync < 3.5.0 Arbitrary File Deletion via Malicious File List 13.08.2026
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths 13.08.2026
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header 13.08.2026
CVE-2026-53792 rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block 13.08.2026
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode 13.08.2026
CVE-2026-53794 rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error 13.08.2026
CVE-2026-53795 rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest 13.08.2026
CVE-2026-53796 rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling 13.08.2026
CVE-2026-53797 rsync < 3.5.0 Symlink Race Condition Information Disclosure 13.08.2026
CVE-2026-53798 rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping 13.08.2026
CVE-2026-53799 rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application 13.08.2026
CVE-2026-53800 rsync < 3.5.0 Symlink Race Condition via --remove-source-files 13.08.2026
CVE-2026-53801 rsync < 3.5.0 Symlink Race Condition Directory Traversal 13.08.2026
CVE-2026-53802 rsync < 3.5.0 Arbitrary File Read via Symlink Following 13.08.2026
CVE-2026-53803 rsync < 3.5.0 Symlink Following Arbitrary File Overwrite 13.08.2026
CVE-2026-63423 13.08.2026
CVE-2026-63424 13.08.2026
CVE-2026-63425 13.08.2026
CVE-2026-63426 13.08.2026
CVE-2026-65932 BT122 stops advertising 13.08.2026
CVE-2026-65933 BT122 malformed packet with increased length field causes memory leak 13.08.2026
CVE-2026-65934 BT122 plaintext pause encryption request causes DOS 13.08.2026
CVE-2026-65935 Bypassing passkey entry in legacy pairing 13.08.2026
CVE-2026-65936 RS9116W/SiWx917 malformed packet with increased length field causes memory leak 13.08.2026
CVE-2026-6387 13.08.2026
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure 13.08.2026
CVE-2026-70453 rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() 13.08.2026
CVE-2026-70454 rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode 13.08.2026
CVE-2026-70455 rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion 13.08.2026
CVE-2026-70456 rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() 13.08.2026
CVE-2026-70457 rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() 13.08.2026
CVE-2026-70458 rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling 13.08.2026
CVE-2026-70459 rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry 13.08.2026
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink 13.08.2026
CVE-2026-70461 rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry 13.08.2026
CVE-2026-70462 rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT 13.08.2026
CVE-2026-70463 rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing 13.08.2026
CVE-2026-70464 rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall 13.08.2026
CVE-2026-73505 Oh My Posh: Arbitrary command execution via template injection in the path segment 13.08.2026 7.8
CVE-2026-73506 Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data 13.08.2026 6.1
CVE-2026-73507 Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion 13.08.2026 7.5
CVE-2026-73508 Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names 13.08.2026 5.3
CVE-2026-73509 OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal 13.08.2026 7.6
CVE-2026-73555 vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages 13.08.2026 5.3
CVE-2026-73556 vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574 13.08.2026 5.3
CVE-2026-73557 vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts 13.08.2026
CVE-2026-73558 vLLM: Cross-User Data Leak Vulnerability 13.08.2026 5.3
CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue 13.08.2026
CVE-2026-16101 forced re-pairing with already bonded device 13.08.2026 8.8
CVE-2026-19291 Bluetooth re-pairing can use a lower security level than previous 13.08.2026 8.8
CVE-2026-19292 Bluetooth re-pairing with legitimate device can use lower security level 13.08.2026 8.8
CVE-2026-19734 IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking 13.08.2026
CVE-2026-66256 Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API) 13.08.2026
CVE-2026-68451 s390/zcrypt: Validate length for CCA ECC private key requests 13.08.2026
CVE-2026-68452 s390/zcrypt: Validate length for CCA AES cipher key requests 13.08.2026
CVE-2026-68453 s390/zcrypt: Fix buffer over-read in cca_cipher2protkey 13.08.2026
CVE-2026-68454 KVM: s390: pci: Fix handling of AIF enable without AISB 13.08.2026
CVE-2025-62314 HCL AION is affected by multiple security vulnerabilities. 13.08.2026 5.6
CVE-2025-62315 HCL AION is affected by multiple security vulnerabilities. 13.08.2026 3.4
CVE-2025-62318 HCL AION is affected by multiple security vulnerabilities. 13.08.2026 3.7
CVE-2026-19716 Stored Cross-site Scripting in Pentestify user account deletion via unescaped username 13.08.2026
CVE-2026-21832 HCL AION is affected by multiple security vulnerabilities. 13.08.2026 4.3
CVE-2026-27345 WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Access Control vulnerability 13.08.2026 7.5
CVE-2026-27380 WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerability 13.08.2026 7.2
CVE-2026-27535 WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability 13.08.2026 7.1
CVE-2026-27536 WordPress MailChimp Subscribe Forms plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-27537 WordPress Popup by Supsystic plugin <= 1.11.2 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-27538 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 7.5
CVE-2026-27539 WordPress Welcart e-Commerce plugin <= 2.11.31 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-27543 WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability 13.08.2026 8.1
CVE-2026-27544 WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability 13.08.2026 10
CVE-2026-27999 WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-28001 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28002 WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability 13.08.2026 8.5
CVE-2026-28003 WordPress Maspik – Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-28004 WordPress Business Directory plugin <= 6.4.25 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-28008 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28142 WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28148 WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability 13.08.2026 9.8
CVE-2026-28149 WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability 13.08.2026 9.8
CVE-2026-28155 WordPress Do Lasso plugin <= 358 - Insecure Direct Object References (IDOR) vulnerability 13.08.2026 6.5
CVE-2026-28156 WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability 13.08.2026 8.5
CVE-2026-28157 WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability 13.08.2026 7.5
CVE-2026-28158 WordPress Do Lasso plugin <= 358 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-28159 WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-28161 WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability 13.08.2026 8.8
CVE-2026-28168 WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability 13.08.2026 8.5
CVE-2026-28170 WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-28173 WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vulnerability 13.08.2026 7.1
CVE-2026-28174 WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability 13.08.2026 6.5
CVE-2026-28175 WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-28176 WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability 13.08.2026 8.8
CVE-2026-28181 WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-28182 WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-28184 WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability 13.08.2026 8.5
CVE-2026-28185 WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28186 WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability 13.08.2026 8.1
CVE-2026-28187 WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 17.211.0 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-28188 WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability 13.08.2026 7.3
CVE-2026-28189 WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion vulnerability 13.08.2026 7.4
CVE-2026-48702 Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic 13.08.2026 7.5
CVE-2026-61960 WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-61962 WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability 13.08.2026 10
CVE-2026-61965 WordPress GeekyBot plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-61966 WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61967 WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-61969 WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61974 WordPress Mang Board WP plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-61978 WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-61979 WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability 13.08.2026 8.1
CVE-2026-61980 WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability 13.08.2026 7.5
CVE-2026-61984 WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability 13.08.2026 7.5
CVE-2026-65580 WordPress Agrion theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-65582 WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability 13.08.2026 7.7
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-66426 WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66429 WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66430 WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Injection vulnerability 13.08.2026 8.5
CVE-2026-66431 WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability 13.08.2026 7.5
CVE-2026-66432 WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability 13.08.2026 7.5
CVE-2026-66436 WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66441 WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability 13.08.2026 7.5
CVE-2026-66443 WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability 13.08.2026 7.5
CVE-2026-66444 WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability 13.08.2026 6.5
CVE-2026-66446 WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66449 WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66450 WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability 13.08.2026 8.1
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-66454 WordPress WP Social Avatar plugin <= 1.5 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-66455 WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability 13.08.2026 6
CVE-2026-66456 WordPress Profile Extra Fields by BestWebSoft plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66459 WordPress AI for SEO plugin <= 2.4.2 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-66460 WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-66461 WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypass vulnerability 13.08.2026 7.5
CVE-2026-66462 WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure vulnerability 13.08.2026 7.5
CVE-2026-66463 WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability 13.08.2026 7.5
CVE-2026-66464 WordPress Internal Link Optimiser plugin <= 5.2.7 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability 13.08.2026 9.8
CVE-2026-66466 WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability 13.08.2026 7.5
CVE-2026-66467 WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-66468 WordPress Local Delivery Drivers for WooCommerce plugin <= 3.0.0 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66469 WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnerability 13.08.2026 7.5
CVE-2026-66471 WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66478 WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66653 WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability 13.08.2026 8.1
CVE-2026-66654 WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerability 13.08.2026 6
CVE-2026-66655 WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66656 WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability 13.08.2026 8.1
CVE-2026-66657 WordPress Biagiotti Core plugin <= 2.1.1 - Local File Inclusion vulnerability 13.08.2026 8.1
CVE-2026-66658 WordPress Reviewer plugin <= 3.14.2 - SQL Injection vulnerability 13.08.2026 8.5
CVE-2026-66660 WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-66661 WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability 13.08.2026 7.7
CVE-2026-66687 WordPress WpBookingly plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-66689 WordPress Anti Spam and list cleaner – AcyChecker plugin <= 2.0.0 - Broken Access Control vulnerability 13.08.2026 6.3
CVE-2026-66691 WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability 13.08.2026 9.8
CVE-2026-66693 WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability 13.08.2026 6.5
CVE-2026-66697 WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66698 WordPress SureDash plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66700 WordPress Smart Online Order for Clover plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability 13.08.2026 7.1
CVE-2026-66704 WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerability 13.08.2026 7.2
CVE-2026-67986 13.08.2026
CVE-2026-67990 13.08.2026
CVE-2026-67991 13.08.2026
CVE-2026-73188 WordPress KiviCare plugin <= 4.5.1 - Sensitive Data Exposure vulnerability 13.08.2026 7.5
CVE-2026-73340 WordPress Featured Image from URL plugin <= 5.3.3 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-73344 WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability 13.08.2026 5.9
CVE-2026-73346 WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability 13.08.2026 7.6
CVE-2026-73349 WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability 13.08.2026 5.3
CVE-2026-73353 WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Control vulnerability 13.08.2026 5.3
CVE-2026-73357 WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability 13.08.2026 6.5
CVE-2026-73401 WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability 13.08.2026 5.3
CVE-2026-73403 WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability 13.08.2026 5.3
CVE-2025-52640 HCL AION is affected by multiple security vulnerabilities. 13.08.2026 4.7
CVE-2026-14662 PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound 13.08.2026 8.8
CVE-2026-14663 PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext 13.08.2026 6.5
CVE-2026-14664 PostgreSQL regexp heap buffer overflow executes arbitrary code 13.08.2026 8.8
CVE-2026-14666 PostgreSQL row security caching disregards role modifications 13.08.2026 4.2
CVE-2026-14668 PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read 13.08.2026 8.1
CVE-2026-14669 PostgreSQL to_char heap buffer overflow executes arbitrary code 13.08.2026 8.8
CVE-2026-14670 PostgreSQL plperl tied object heap buffer overflow executes arbitrary code 13.08.2026 8.8
CVE-2026-14671 PostgreSQL refint plan cache type confusion executes arbitrary code 13.08.2026 8.8
CVE-2026-14672 PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle 13.08.2026 5.3
CVE-2026-14673 PostgreSQL amcheck does not clear untrusted search path 13.08.2026 3.8
CVE-2026-14676 PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code 13.08.2026 8.8
CVE-2026-14677 PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound 13.08.2026 8.8
CVE-2026-14678 PostgreSQL pg_trgm picksplit reads past end of buffer 13.08.2026 4.3
CVE-2026-14679 PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory 13.08.2026 8.2
CVE-2026-14680 PostgreSQL type confusion via "internal" arguments 13.08.2026 8.8
CVE-2026-14681 PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL 13.08.2026 4.2
CVE-2026-15741 PostgreSQL expression deparse allows SQL injection via EXTRACT argument 13.08.2026 8.8
CVE-2026-15742 PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound 13.08.2026 8.8
CVE-2026-16238 PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code 13.08.2026 8.8
CVE-2026-16239 PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code 13.08.2026 8.8
CVE-2026-16241 PostgreSQL ECPG integer underflow can crash the client 13.08.2026 3.8
CVE-2026-18024 PostgreSQL ascii() function reads past end of buffer 13.08.2026 4.3
CVE-2026-18408 PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client 13.08.2026 8.8
CVE-2026-19385 PostgreSQL pg_dump heap buffer overflow executes arbitrary code 13.08.2026 8.8
CVE-2026-49478 Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage 13.08.2026 8.7
CVE-2026-49827 WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) 13.08.2026 9.8
CVE-2026-6464 PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands 13.08.2026 8.1
CVE-2026-6469 PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership 13.08.2026 3.8
CVE-2026-6470 PostgreSQL fails to check type USAGE privilege 13.08.2026 4.3
CVE-2026-6471 PostgreSQL logical decoding can dlopen arbitrary file 13.08.2026 7.2
CVE-2026-73583 Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr 13.08.2026
CVE-2026-73584 Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling 13.08.2026
CVE-2026-73585 Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack 13.08.2026
CVE-2026-73483 Flowise before 3.1.3 Sandbox Escape via Puppeteer 13.08.2026
CVE-2026-73484 Flowise before 3.1.3 Sandbox Escape via Pandas Methods 13.08.2026
CVE-2026-73485 Flowise before 3.1.3 Remote Code Execution via Airtable Agent 13.08.2026
CVE-2026-73486 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV 13.08.2026
CVE-2026-73487 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent 13.08.2026
CVE-2026-73488 Flowise before 3.1.3 IDOR via customer-default-source endpoint 13.08.2026
CVE-2026-73601 Flowise before 3.1.3 Remote Code Execution via Custom MCP 13.08.2026
CVE-2026-73602 Flowise before 3.1.3 Sandbox Escape to RCE 13.08.2026
CVE-2026-73603 Flowise before 3.1.4 Credential Abuse via Text-to-Speech 13.08.2026
CVE-2026-73604 Flowise before 3.1.3 Credential Exposure via API 13.08.2026
CVE-2026-73605 SiYuan before v3.7.4 Path Traversal via getUniqueFilename 13.08.2026
CVE-2026-73606 SiYuan before v3.7.4 Information Disclosure via getRefIDs 13.08.2026
CVE-2026-73607 SiYuan before v3.7.4 Information Disclosure via getOutlineStorage 13.08.2026
CVE-2026-73608 SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget 13.08.2026
CVE-2026-73609 SiYuan before v3.7.4 Information Disclosure via getBookmarkLabels 13.08.2026
CVE-2026-73610 SiYuan before v3.7.4 Information Disclosure via Local Storage 13.08.2026
CVE-2026-73611 File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass 13.08.2026
CVE-2026-73612 File Browser before v2.63.22 Authorization Bypass via Recursive Operations 13.08.2026
CVE-2026-73613 filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink 13.08.2026
CVE-2026-73614 Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation 13.08.2026
CVE-2026-73615 Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch 13.08.2026
CVE-2026-73616 OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference 13.08.2026
CVE-2026-73617 Budibase before 3.40.0 NoSQL Injection via MongoDB datasource 13.08.2026
CVE-2026-73618 Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter 13.08.2026
CVE-2026-73619 GitPython before 3.1.57 Arbitrary File Read via Repo.archive() 13.08.2026
CVE-2026-73620 GitPython before 3.1.57 Arbitrary File Overwrite and Read 13.08.2026
CVE-2026-73621 GitPython before 3.1.56 Arbitrary File Truncation via Commit.count 13.08.2026
CVE-2026-73622 GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() 13.08.2026
CVE-2026-73623 GitPython before 3.1.54 Remote Code Execution via --template 13.08.2026
CVE-2026-73624 GitPython before 3.1.54 Arbitrary File Overwrite via diff 13.08.2026
CVE-2026-73625 GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling 13.08.2026
CVE-2026-73626 JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager 13.08.2026
CVE-2026-73627 JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass 13.08.2026
CVE-2026-73628 Serendipity 2.3.5 Reflected XSS via search clean-URL route 13.08.2026
CVE-2026-73629 Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses 13.08.2026
CVE-2026-45819 13.08.2026
CVE-2026-16455 Local privilege escalation via improper input sanitization in execl() call 13.08.2026
CVE-2026-18368 Heap buffer overflow in Modbusgwd 13.08.2026
CVE-2026-12263 Authentication Bypass 13.08.2026 8.8
CVE-2026-11970 13.08.2026
CVE-2026-59501 Priority – CWE-284: Improper Access Control 13.08.2026 8.2
CVE-2026-59502 Priority - CWE-203: Observable Discrepancy 13.08.2026 5.3
CVE-2026-59503 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor 13.08.2026 9.1
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security 13.08.2026 9.1
CVE-2026-59505 Priority - CWE-284: Improper Access Control 13.08.2026 8.6
CVE-2026-59506 Priority – CWE-306: Missing Authentication for Critical Function 13.08.2026 9.3
CVE-2026-59507 Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control 13.08.2026 9.3
CVE-2026-19484 @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary 13.08.2026 7.5
CVE-2026-59499 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor 13.08.2026 8.6
CVE-2026-59500 Priority - CWE-287: Improper Authentication 13.08.2026 10
CVE-2026-16458 Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto 13.08.2026
CVE-2026-16459 Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto 13.08.2026
CVE-2026-19481 @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header 13.08.2026 7.5
CVE-2026-14298 Denial of service via resource exhaustion in Mattermost 13.08.2026 6.5
CVE-2026-14332 Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action 13.08.2026 5.4
CVE-2026-15413 Link Factory - Backdoor 13.08.2026 10
CVE-2026-19694 Heap-based Buffer Overflow in Wireshark 13.08.2026 4.7
CVE-2026-19695 Stack-based Buffer Overflow in Wireshark 13.08.2026 4.7
CVE-2026-19696 Out-of-bounds Write in Wireshark 13.08.2026 6.6
CVE-2026-11840 SQL Injection 13.08.2026 8.8
CVE-2026-3639 PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 13.08.2026 6.4
CVE-2026-18622 Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid 13.08.2026 4.7
CVE-2026-18146 Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values 13.08.2026 7.2
CVE-2026-13328 TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification 13.08.2026
CVE-2026-13610 KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration 13.08.2026
CVE-2026-14182 Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass 13.08.2026
CVE-2026-14213 Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR 13.08.2026
CVE-2026-18945 WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation 13.08.2026
CVE-2026-19088 ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication 13.08.2026
CVE-2026-3835 Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access 13.08.2026 5.3
CVE-2026-19135 OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes 13.08.2026 5.4
CVE-2026-19182 OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only 13.08.2026 4.3
CVE-2026-72506 13.08.2026
CVE-2026-18728 Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing 13.08.2026
CVE-2026-0289 Prisma Browser: Inappropriate Implementation in Account Protection 13.08.2026
CVE-2026-0290 Prisma Browser: Sensitive Information Disclosure Vulnerability 13.08.2026
CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux 13.08.2026
CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows 13.08.2026
CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows 13.08.2026
CVE-2026-0294 Prisma Access Agent: Local Privilege Escalation 13.08.2026
CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS 13.08.2026
CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability 13.08.2026
CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake 13.08.2026
CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) 13.08.2026
CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities 13.08.2026
CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering 13.08.2026
CVE-2026-46382 Meeting Room Booking System has server-side request forgery in import functionality 12.08.2026
CVE-2026-46688 Meeting Room Booking System has an unauthenticated open redirect 13.08.2026
CVE-2026-48791 Sigstore Java has a vulnerability with bundle verification of integratedTime 13.08.2026 2
CVE-2026-16770 PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document 13.08.2026
CVE-2026-17431 PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for 13.08.2026
CVE-2026-49473 @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation 13.08.2026 8.8
CVE-2026-49819 UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd 13.08.2026 9.8
CVE-2026-50544 NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions 12.08.2026 6.3
CVE-2026-49481 UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd 12.08.2026 9.6
CVE-2026-15141 Referer Validation Bypass in TL-WR820N Web Management Interface 13.08.2026
CVE-2026-15424 12.08.2026
CVE-2026-47717 FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations 13.08.2026 7.5
CVE-2026-47718 FUXA provides guest and invalid-token access to protected read APIs in secure mode 12.08.2026
CVE-2026-71193 13.08.2026 9.6
CVE-2026-71194 13.08.2026 6.8
CVE-2026-71469 Acm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticated memory-exhaustion dos 12.08.2026
CVE-2026-71471 Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image 13.08.2026
CVE-2026-71473 Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spoke 13.08.2026
CVE-2026-71846 Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilege 12.08.2026
CVE-2024-27253 IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request 12.08.2026 10
CVE-2026-10534 IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser 13.08.2026 8.4
CVE-2026-17485 IBM i is Affected By Denial of Service Vulnerability [] 12.08.2026 8.2
CVE-2026-73499 etcd: Watch API authorization bypass via open-ended range requests 12.08.2026
CVE-2026-73500 etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline 12.08.2026
CVE-2026-73501 kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default 13.08.2026 9.1
CVE-2026-18726 Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing 13.08.2026
CVE-2026-18727 Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing 13.08.2026
CVE-2026-18744 CVE-2026-18744 13.08.2026
CVE-2026-18749 CVE-2026-18749 13.08.2026
CVE-2026-18750 CVE-2026-18750 13.08.2026
CVE-2026-19003 MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings 13.08.2026
CVE-2026-73492 Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons 12.08.2026
CVE-2026-73493 http4s-blaze-server: Unbounded WebSocket message aggregation 12.08.2026 7.5
CVE-2026-73495 blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) 13.08.2026 7.4
CVE-2026-73498 MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment 13.08.2026 7.7
CVE-2026-73519 WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret 13.08.2026
CVE-2026-7366 IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall 13.08.2026 4.2
CVE-2026-10543 IBM® Db2® is vulnerable to privilege escalation with a specially crafted query 13.08.2026 8.2
CVE-2026-13094 IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities 12.08.2026 7.8
CVE-2026-13105 IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities 13.08.2026 8.8
CVE-2026-13367 IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility 12.08.2026 7.8
CVE-2026-13433 IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities 13.08.2026 8.3
CVE-2026-13476 IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution 12.08.2026 7.3
CVE-2026-13622 Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host 12.08.2026
CVE-2026-16480 IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data. 13.08.2026 4.3
CVE-2026-16695 IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities 12.08.2026 7.8
CVE-2026-18096 IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak 13.08.2026 3.3
CVE-2026-18097 IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. 12.08.2026 5.5
CVE-2026-19130 Provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedfrom labels bypasses authorization 12.08.2026
CVE-2026-19654 Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd 13.08.2026
CVE-2026-64826 rConfig < 8.2.13 Path Traversal File Read via FileDownloadController 12.08.2026
CVE-2026-73425 @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped 13.08.2026 3.7
CVE-2026-73427 Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController) 13.08.2026
CVE-2026-73429 Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) 12.08.2026 5.3
CVE-2026-73430 Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) 12.08.2026 5.3
CVE-2026-73490 Loofah: SVG `href` attribute bypasses local-reference restriction 13.08.2026 4.7
CVE-2026-73491 Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references 13.08.2026
CVE-2026-18888 MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data 13.08.2026
CVE-2026-19001 MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names 13.08.2026
CVE-2026-19002 Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver 13.08.2026
CVE-2026-19004 MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters 13.08.2026
CVE-2026-65370 13.08.2026
CVE-2026-73419 NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them 13.08.2026 6.8
CVE-2026-73422 Astro: Reflected XSS via unescaped View Transition animation properties 12.08.2026
CVE-2026-73423 Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered 12.08.2026
CVE-2026-11932 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 12.08.2026 5.3
CVE-2026-14866 IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities 13.08.2026 7.7
CVE-2026-16033 Arbitrary file read+write on host via templates/ symlink in malicious image 13.08.2026 8.5
CVE-2026-17616 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 12.08.2026 6.8
CVE-2026-19502 Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI 13.08.2026
CVE-2026-19503 Insufficient OIDC endpoint validation could invoke unintended local protocol handlers 13.08.2026
CVE-2026-62421 12.08.2026
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE 13.08.2026 9.9
CVE-2026-73418 NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers 13.08.2026 7.5
CVE-2026-11923 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 13.08.2026 7.4
CVE-2026-11937 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 12.08.2026 3.1
CVE-2026-12004 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 13.08.2026 8.7
CVE-2026-12005 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 13.08.2026 7.2
CVE-2026-12359 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 13.08.2026 8.1
CVE-2026-12618 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 13.08.2026 7.2
CVE-2026-13267 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 13.08.2026 8.1
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 13.08.2026 9.9
CVE-2026-63294 Root RCE via image backup.yaml symlink 13.08.2026 9.9
CVE-2026-67579 Filter expression injection via forged keyset pagination cursor in Ash 13.08.2026
CVE-2026-73415 jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab 12.08.2026
CVE-2026-13361 IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution 13.08.2026 8.8
CVE-2026-17082 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 13.08.2026 8.8
CVE-2026-17083 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 13.08.2026 9.8
CVE-2026-17111 IBM i is Affected By Multiple Vulnerabilities in SQL 12.08.2026 7.6
CVE-2026-17417 IBM i is Affected By Remote Code Execution Vulnerabilities [, ] 13.08.2026 8.8
CVE-2026-17445 IBM i is Affected By Improper Validation Vulnerability in Line Printer Daemon [] 12.08.2026 8.2
CVE-2026-17642 IBM i is Affected By Remote Code Execution Vulnerabilities [, ] 13.08.2026 8.8
CVE-2026-18099 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 8.9
CVE-2026-18148 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 13.08.2026 4.3
CVE-2026-18150 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 4.3
CVE-2026-19642 Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp 13.08.2026 5.9
CVE-2026-19643 Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms 13.08.2026 5.3
CVE-2026-46731 13.08.2026 7.8
CVE-2026-49466 Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes 13.08.2026 6.5
CVE-2026-59914 13.08.2026 7.8
CVE-2026-59917 13.08.2026 7.8
CVE-2026-63295 Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated` 13.08.2026 4.3
CVE-2026-63296 Project restriction bypass via instance migration config override 13.08.2026 9.9
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 13.08.2026 9.9
CVE-2026-63298 LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration 13.08.2026 8.7
CVE-2026-72508 Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) 13.08.2026
CVE-2026-73409 Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile 12.08.2026
CVE-2026-73411 Shescape: Home-directory disclosure in assignment context on Unix with Dash 12.08.2026
CVE-2026-73412 Shescape: Path disclosure on Unix with Zsh 13.08.2026
CVE-2026-73413 Shescape: Quadratic-time denial of service in flag-protection 13.08.2026
CVE-2026-73414 Shescape: Shell injection via unescaped parentheses on Windows with CMD 12.08.2026
CVE-2025-9486 Incorrect Privilege Assignment in GitLab 13.08.2026 3.3
CVE-2026-15216 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab 13.08.2026 8.7
CVE-2026-15217 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab 13.08.2026 8.7
CVE-2026-16494 Missing Authorization in GitLab 13.08.2026 7.1
CVE-2026-18433 Incorrect Authorization in GitLab 13.08.2026 4.3
CVE-2026-18679 Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured 13.08.2026
CVE-2026-19228 Authorization Bypass Through User-Controlled Key in GitLab 13.08.2026 8.5
CVE-2026-19656 ScadaLTS Authenticated Remote Code Execution 12.08.2026 9.9
CVE-2026-19657 ScadaLTS Unauthenticated Reflected XSS 12.08.2026 6.1
CVE-2026-4879 Missing Authorization in GitLab 13.08.2026 4.3
CVE-2026-59916 13.08.2026 7.8
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag 12.08.2026 9.9
CVE-2026-63299 Storage volume cross-project move and snapshot restore bypass project disk limits 12.08.2026 8.5
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution 13.08.2026 9.9
CVE-2026-6821 Missing Authorization in GitLab 13.08.2026 4.3
CVE-2026-72786 Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset 13.08.2026
CVE-2026-72787 Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name 12.08.2026
CVE-2026-72788 SiYuan before v3.7.4 Information Disclosure via UILayout Filter 12.08.2026
CVE-2026-72789 SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks 12.08.2026
CVE-2026-72790 SiYuan before v3.7.4 Information Disclosure via getNotebookInfo 12.08.2026
CVE-2026-72791 SiYuan before v3.7.4 Information Disclosure via getAttributeViewFieldViews 12.08.2026
CVE-2026-72792 SiYuan before v3.7.4 Information Disclosure via Tag API 12.08.2026
CVE-2026-72793 SiYuan before v3.7.4 Information Disclosure via /api/system/getConf 12.08.2026
CVE-2026-72794 siyuan before v3.7.4 Session Cookie Key Disclosure via getConf 12.08.2026
CVE-2026-72795 SiYuan before v3.7.4 Information Disclosure via Embed Block 12.08.2026
CVE-2026-72796 SiYuan before v3.7.4 Access Control Bypass via Static Routes 12.08.2026
CVE-2026-72797 SiYuan before v3.7.4 Information Disclosure via getEncryptedNotebookStatus 12.08.2026
CVE-2026-72798 SiYuan before v3.7.4 Information Disclosure via renderAttributeView 12.08.2026
CVE-2026-72799 SiYuan before v3.7.4 Information Disclosure via Path Resolution 12.08.2026
CVE-2026-72800 SiYuan before v3.7.4 Information Disclosure via Unfiltered API 12.08.2026
CVE-2026-72801 SiYuan before v3.7.4 Information Disclosure via Encryption Key Material 12.08.2026
CVE-2026-72802 SiYuan before v3.7.4 Information Disclosure via resolveAssetPath 12.08.2026
CVE-2026-72803 SiYuan before v3.7.4 Information Disclosure via getBlockAttrs 12.08.2026
CVE-2026-72804 SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints 12.08.2026
CVE-2026-72805 SiYuan before v3.7.4 Information Disclosure via Block Endpoints 12.08.2026
CVE-2026-72806 SiYuan before v3.7.4 Authentication Bypass via Attribute View 12.08.2026
CVE-2026-72807 SiYuan before v3.7.4 SQL Injection via queryBlocks template 12.08.2026
CVE-2026-72808 SiYuan before v3.7.4 Information Disclosure via getFileAnnotation 12.08.2026
CVE-2026-72809 SiYuan before v3.7.4 Authentication Bypass via Localhost Trust 12.08.2026
CVE-2026-73268 Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection 12.08.2026
CVE-2026-73269 Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa 12.08.2026
CVE-2026-73303 Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session) 12.08.2026 8.2
CVE-2026-73306 Budibase: Account Enumeration via Login Lockout Response Differential 13.08.2026 5.3
CVE-2026-73307 Budibase: SSRF via bare fetch() in uploadUrl during AI table generation 12.08.2026
CVE-2026-73308 Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders 12.08.2026 5.7
CVE-2026-73326 CamaleonCMS Missing Authorization via Plugin Administration Endpoints 12.08.2026
CVE-2026-73329 CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint 12.08.2026
CVE-2026-73330 CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action 12.08.2026
CVE-2026-73331 CamaleonCMS 2.9.1 Authenticated SQL Injection via Post Slug Field 12.08.2026
CVE-2026-73332 CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field 12.08.2026
CVE-2026-73406 Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint 13.08.2026 7.5
CVE-2026-73407 Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) 12.08.2026
CVE-2026-73433 Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write 12.08.2026
CVE-2026-73434 Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing 13.08.2026
CVE-2026-18675 Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid 13.08.2026
CVE-2026-18676 Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin 13.08.2026
CVE-2026-18677 Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity 13.08.2026
CVE-2026-18678 Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured 13.08.2026
CVE-2026-18952 Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin 13.08.2026
CVE-2026-19311 Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin 13.08.2026
CVE-2026-18673 Kong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authentication 13.08.2026
CVE-2026-73301 Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings 12.08.2026 4.3
CVE-2026-15423 Incorrect Authorization in GitLab 13.08.2026 8.5
CVE-2026-16627 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab 13.08.2026 7.7
CVE-2026-18244 Missing Authorization in GitLab 13.08.2026 4.3
CVE-2026-73300 Budibase: SQL Injection via `multipleStatements: true` 12.08.2026 9.6
CVE-2026-73327 Joomla 6.1.1 Zip Slip Path Traversal via com_joomlaupdate extract.php 12.08.2026
CVE-2026-7427 Allocation of Resources Without Limits or Throttling in GitLab 13.08.2026 5.3
CVE-2026-8667 Incorrect Authorization in GitLab 13.08.2026 4.3
CVE-2026-16856 IBM i is Affected By Multiple Vulnerabilities in Domain Name System 12.08.2026 8.8
CVE-2026-16860 IBM i is Affected By Remote Code Execution Vulnerability [] 12.08.2026 9.9
CVE-2026-16863 IBM i is Affected By Out-of-Bounds Read Vulnerability [] 12.08.2026 7.7
CVE-2026-16906 IBM i is Affected By Multiple Vulnerabilities in Domain Name System 12.08.2026 8.8
CVE-2026-16907 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 12.08.2026 7.6
CVE-2026-16931 IBM i is Affected By A Denial of Service Vulnerability [] 12.08.2026 7.5
CVE-2026-16956 IBM Db2 Mirror for i is vulnerable to OS command injection [] 12.08.2026 9.8
CVE-2026-17109 IBM i is Affected By Multiple Vulnerabilities in SQL 12.08.2026 4.3
CVE-2026-17110 IBM i is Affected By Multiple Vulnerabilities in SQL 12.08.2026 8.8
CVE-2026-17218 IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] 12.08.2026 9.8
CVE-2026-17222 IBM i is Affected By Multiple Vulnerabilities in SQL 12.08.2026 4.3
CVE-2026-17248 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 12.08.2026 7.1
CVE-2026-17271 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 12.08.2026 7.5
CVE-2026-17420 IBM i is Affected By Multiple Vulnerabilities in SQL 12.08.2026 6.3
CVE-2026-18669 IBM i is Affected By A Privilege Escalation Vulnerability [] 12.08.2026 8.8
CVE-2026-42018 Anonymous user token generation exposure in JFrog Artifactory 13.08.2026 7.5
CVE-2026-69106 Potential cache poisoning in JFrog Artifactory 13.08.2026 8.8
CVE-2026-73298 Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/write/delete processes 12.08.2026
CVE-2026-73299 Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer 12.08.2026 10
CVE-2026-16904 IBM i is Affected By improper privilege management in Navigator for i 12.08.2026 8.1
CVE-2026-17266 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 6.5
CVE-2026-17268 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 6.8
CVE-2026-17276 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 9.6
CVE-2026-17418 IBM i is Affected By Multiple Vulnerabilities in SQL 12.08.2026 8.5
CVE-2026-17419 IBM i is Affected By Multiple Vulnerabilities in SQL 12.08.2026 6.5
CVE-2026-18235 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 8.3
CVE-2026-18250 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 6.3
CVE-2026-18713 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 8.8