| CVE-2026-15623 |
Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service |
17.08.2026 |
9.4 |
| CVE-2026-19977 |
EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication |
17.08.2026 |
10 |
| CVE-2026-19961 |
Edimax EW-7478APC formWlSiteSurvey buffer overflow |
16.08.2026 |
9.4 |
| CVE-2026-19959 |
Edimax EW-7478APC formWanTcpipSetup stack-based overflow |
16.08.2026 |
9.4 |
| CVE-2026-73056 |
SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token |
16.08.2026 |
9.3 |
| CVE-2026-73061 |
Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor |
16.08.2026 |
9.3 |
| CVE-2026-74790 |
Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache |
16.08.2026 |
9.3 |
| CVE-2026-74791 |
Scriban before 7.0.0 Authorization Bypass via Stale Include Cache |
16.08.2026 |
9.2 |
| CVE-2026-74251 |
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 |
17.08.2026 |
9.3 |
| CVE-2024-13784 |
Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection |
16.08.2026 |
9.8 |
| CVE-2026-18316 |
Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action |
16.08.2026 |
9.1 |
| CVE-2026-14524 |
ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters |
16.08.2026 |
9.1 |
| CVE-2026-16098 |
ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override |
16.08.2026 |
9.8 |
| CVE-2026-18432 |
Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter |
16.08.2026 |
9.8 |
| CVE-2026-19924 |
Tenda AC10 httpd R7WebsSecurityHandler improper authentication |
16.08.2026 |
9.3 |
| CVE-2026-73041 |
SiYuan before v3.7.4 Remote Code Execution via PDF Annotations |
15.08.2026 |
9.4 |
| CVE-2026-73042 |
SiYuan before v3.7.4 Remote Code Execution via Menu Metadata |
15.08.2026 |
9.4 |
| CVE-2026-73043 |
SiYuan before v3.7.4 Remote Code Execution via Template Calculation |
15.08.2026 |
9.4 |
| CVE-2026-73044 |
SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width |
15.08.2026 |
9.4 |
| CVE-2026-73046 |
SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth |
15.08.2026 |
9.3 |
| CVE-2026-73050 |
SiYuan before v3.7.4 Stored XSS via select option color |
15.08.2026 |
9.4 |
| CVE-2026-73052 |
SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names |
15.08.2026 |
9.4 |
| CVE-2026-73053 |
SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji |
15.08.2026 |
9.4 |
| CVE-2026-73055 |
Shescape before 2.1.15 Home Directory Disclosure via BusyBox |
15.08.2026 |
9.3 |
| CVE-2026-74764 |
Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora |
15.08.2026 |
10 |
| CVE-2026-18855 |
Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter |
15.08.2026 |
9.1 |
| CVE-2026-19598 |
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router |
15.08.2026 |
9.8 |
| CVE-2026-19901 |
LB-LINK X-PRO easycwmp hard-coded credentials |
15.08.2026 |
9.2 |
| CVE-2026-19900 |
LB-LINK X-PRO shadow hard-coded credentials |
15.08.2026 |
9.2 |
| CVE-2026-74473 |
vxlan: use pskb_network_may_pull() in route_shortcircuit() |
17.08.2026 |
9.8 |
| CVE-2026-74474 |
vxlan: use pskb_network_may_pull() for transmit path header pulls |
17.08.2026 |
9.8 |
| CVE-2026-74475 |
vxlan: use neigh_ha_snapshot() in route_shortcircuit() |
17.08.2026 |
10 |
| CVE-2026-74476 |
veth: convert frag_list skbs before running XDP |
17.08.2026 |
9.1 |
| CVE-2026-74478 |
um: vector: fix use-after-free in vector_mmsg_rx() |
17.08.2026 |
9.8 |
| CVE-2026-74480 |
net: bridge: stop fast-leave after deleting a port group |
17.08.2026 |
9.8 |
| CVE-2026-74493 |
net/smc: fix socket use-after-free during link group termination |
17.08.2026 |
9.8 |
| CVE-2026-74495 |
igbvf: Fix leak in TX DMA error cleanup |
17.08.2026 |
9.8 |
| CVE-2026-74517 |
KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs |
17.08.2026 |
9.3 |
| CVE-2026-74521 |
ksmbd: use memcmp() to compare ClientGUIDs |
17.08.2026 |
9.1 |
| CVE-2026-74545 |
rtase: fix double free of multi-frag skb on DMA map failure |
17.08.2026 |
9.8 |
| CVE-2026-74556 |
scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer |
17.08.2026 |
9.8 |
| CVE-2026-74568 |
KVM: arm64: vgic: Fix race between LPI release and re-registration |
17.08.2026 |
9.3 |
| CVE-2026-74569 |
netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() |
17.08.2026 |
9.8 |
| CVE-2026-74570 |
ntfs: harden runlist realloc size calculations |
17.08.2026 |
9.8 |
| CVE-2026-74573 |
iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE |
17.08.2026 |
9.3 |
| CVE-2026-16142 |
TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter |
15.08.2026 |
9.8 |
| CVE-2026-15826 |
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter |
15.08.2026 |
9.8 |
| CVE-2026-72496 |
RDMA/bnxt_re: Proper rollback if the ioremap fails |
17.08.2026 |
9.2 |
| CVE-2026-74255 |
tipc: fix UAF in tipc_l2_send_msg() |
17.08.2026 |
9.8 |
| CVE-2026-74267 |
net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen |
17.08.2026 |
9.8 |
| CVE-2026-74268 |
tcp: clear sock_ops cb flags before force-closing a child socket |
17.08.2026 |
9.8 |
| CVE-2026-74269 |
bnxt: fix head underflow on XDP head-grow |
17.08.2026 |
9.8 |
| CVE-2026-74279 |
crypto: cavium/cpt - fix DMA cleanup using wrong loop index |
17.08.2026 |
10 |
| CVE-2026-74280 |
crypto: marvell/octeontx - fix DMA cleanup using wrong loop index |
17.08.2026 |
10 |
| CVE-2026-74287 |
sctp: validate embedded address parameter length |
17.08.2026 |
9.1 |
| CVE-2026-74309 |
vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler |
17.08.2026 |
10 |
| CVE-2026-74310 |
vhost/net: complete zerocopy ubufs only once |
17.08.2026 |
9.3 |
| CVE-2026-74315 |
lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() |
17.08.2026 |
9.8 |
| CVE-2026-74345 |
RDMA/siw: Fix endpoint/socket association handling |
17.08.2026 |
9.8 |
| CVE-2026-74350 |
ocfs2: validate fast symlink target during inode read |
17.08.2026 |
9.8 |
| CVE-2026-74361 |
nvme: fix FDP fdpcidx bounds check |
17.08.2026 |
9.8 |
| CVE-2026-74376 |
md/raid10: reset read_slot when reusing r10bio for discard |
17.08.2026 |
9.8 |
| CVE-2026-74384 |
nvme-multipath: fix flex array size in struct nvme_ns_head |
17.08.2026 |
9.8 |
| CVE-2026-74394 |
RDMA/srpt: fix integer overflow in immediate data length check |
17.08.2026 |
9.8 |
| CVE-2026-74398 |
ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD |
17.08.2026 |
9.8 |
| CVE-2026-74401 |
dlm: fix add msg handle in send_queue ordered |
17.08.2026 |
9.8 |
| CVE-2026-74406 |
vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). |
17.08.2026 |
9.8 |
| CVE-2026-74427 |
afs: Fix netns teardown to cancel the preallocation charger |
17.08.2026 |
9.8 |
| CVE-2026-74428 |
rxrpc: Fix double unlock in rxrpc_recvmsg() |
17.08.2026 |
9.8 |
| CVE-2026-74433 |
rxrpc: Fix UAF in rxgk_issue_challenge() |
17.08.2026 |
9.8 |
| CVE-2026-74434 |
rxrpc: Don't move a peeked OOB message onto the pending queue |
17.08.2026 |
9.8 |
| CVE-2026-74436 |
rxrpc: serialize kernel accept preallocation with socket teardown |
17.08.2026 |
9.8 |
| CVE-2026-74439 |
iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry |
17.08.2026 |
9.3 |
| CVE-2026-68457 |
ksmbd: use opener credentials for FSCTL mutations |
17.08.2026 |
9.1 |
| CVE-2026-68476 |
ipvs: reload ip header after head reallocation |
17.08.2026 |
9.8 |
| CVE-2026-68477 |
ipvs: fix more places with wrong ipv6 transport offsets |
17.08.2026 |
9.8 |
| CVE-2026-72014 |
drbd: reject data replies with an out-of-range payload size |
17.08.2026 |
9.8 |
| CVE-2026-72020 |
ipvs: reset full ip_vs_seq structs in ip_vs_conn_new |
17.08.2026 |
9.8 |
| CVE-2026-72033 |
orangefs: keep the readdir entry size 64-bit in fill_from_part() |
17.08.2026 |
9.8 |
| CVE-2026-72041 |
espintcp: use sk_msg_free_partial to fix partial send |
17.08.2026 |
9.8 |
| CVE-2026-72046 |
gve: fix header buffer corruption with header-split and HW-GRO |
17.08.2026 |
9.8 |
| CVE-2026-72064 |
net: mana: Sync page pool RX frags for CPU |
17.08.2026 |
9.8 |
| CVE-2026-72065 |
net: mana: Validate the packet length reported by the NIC |
17.08.2026 |
9.8 |
| CVE-2026-72069 |
locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() |
17.08.2026 |
9.8 |
| CVE-2026-72083 |
scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE |
17.08.2026 |
9.8 |
| CVE-2026-72084 |
scsi: target: Bound PR-OUT TransportID parsing to the received buffer |
17.08.2026 |
9.8 |
| CVE-2026-72085 |
scsi: xen: scsiback: Free unsubmitted command instead of double-putting it |
17.08.2026 |
9.3 |
| CVE-2026-72098 |
dm-verity: fix buffer overflow in FEC calculation |
17.08.2026 |
9.8 |
| CVE-2026-72129 |
nvmet-rdma: handle inline data with a nonzero offset |
17.08.2026 |
9.8 |
| CVE-2026-72130 |
nvmet-auth: reject short AUTH_RECEIVE buffers |
17.08.2026 |
9.8 |
| CVE-2026-72137 |
xfrm: nat_keepalive: avoid double free on send error |
17.08.2026 |
9.8 |
| CVE-2026-72139 |
tcp: defer md5sig_info kfree past RCU grace period in tcp_connect |
17.08.2026 |
9.8 |
| CVE-2026-72185 |
ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() |
17.08.2026 |
9.8 |
| CVE-2026-72186 |
ntfs: make system files immutable to prevent corruption |
17.08.2026 |
9.1 |
| CVE-2026-72188 |
ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name() |
17.08.2026 |
9.1 |
| CVE-2026-72191 |
ntfs3: validate split-point offset in indx_insert_into_buffer |
17.08.2026 |
9.8 |
| CVE-2026-72192 |
ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head |
17.08.2026 |
9.8 |
| CVE-2026-72194 |
fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow |
17.08.2026 |
9.8 |
| CVE-2026-72199 |
ntfs: validate resident index root values on lookup |
17.08.2026 |
9.8 |
| CVE-2026-72200 |
ntfs: detect mapping-pairs LCN accumulator overflow |
17.08.2026 |
9.8 |
| CVE-2026-72201 |
ntfs: validate index entries on reading |
17.08.2026 |
9.8 |
| CVE-2026-72206 |
ntfs: validate index block header more strictly |
17.08.2026 |
9.8 |
| CVE-2026-72207 |
ntfs: not change 0-byte $DATA attribute to non-resident |
17.08.2026 |
9.8 |
| CVE-2026-72208 |
ntfs: add bounds check before accessing EA entries |
17.08.2026 |
9.8 |
| CVE-2026-72209 |
ntfs: validate attribute values on lookup |
17.08.2026 |
9.8 |
| CVE-2026-72210 |
ntfs: fix off-by-one in mapping pairs decoding bounds checks |
17.08.2026 |
9.8 |
| CVE-2026-72211 |
ntfs: grow index root value before reparent header update |
17.08.2026 |
9.8 |
| CVE-2026-72217 |
SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing |
17.08.2026 |
9.8 |
| CVE-2026-72220 |
sunrpc: harden rq_procinfo lifecycle to prevent double-free |
17.08.2026 |
9.8 |
| CVE-2026-72221 |
sunrpc: wait for in-flight TLS handshake callback when cancel loses race |
17.08.2026 |
9.8 |
| CVE-2026-72222 |
sunrpc: pin svc_xprt across the asynchronous TLS handshake callback |
17.08.2026 |
9.8 |
| CVE-2026-72226 |
batman-adv: tt: prevent TVLV OOB check overflow |
17.08.2026 |
9.8 |
| CVE-2026-72234 |
batman-adv: access unicast_ttvn skb->data only after skb realloc |
17.08.2026 |
9.8 |
| CVE-2026-72239 |
x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" |
17.08.2026 |
9.3 |
| CVE-2026-72248 |
netfilter: flowtable: support IPIP tunnel with direct xmit |
17.08.2026 |
9.8 |
| CVE-2026-72249 |
netfilter: flowtable: use dst in this direction when pushing IPIP header |
17.08.2026 |
9.8 |
| CVE-2026-72251 |
netfilter: nf_nat_sip: reload possible stale data pointer |
17.08.2026 |
9.8 |
| CVE-2026-72277 |
KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory |
17.08.2026 |
9.3 |
| CVE-2026-72278 |
KVM: arm64: nv: Re-translate VNCR before injecting abort |
17.08.2026 |
9.3 |
| CVE-2026-72279 |
KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR |
17.08.2026 |
9 |
| CVE-2026-72288 |
KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling |
17.08.2026 |
9.3 |
| CVE-2026-72289 |
KVM: arm64: vgic: Check the interrupt is still ours before migrating it |
17.08.2026 |
9.3 |
| CVE-2026-72291 |
KVM: s390: Fix unlikely race in try_get_locked_pte() |
17.08.2026 |
9.3 |
| CVE-2026-72296 |
net: ife: require ETH_HLEN to be pullable in ife_decode() |
17.08.2026 |
9.1 |
| CVE-2026-72299 |
tipc: restrict socket queue dumps in enqueue tracepoints |
17.08.2026 |
9.8 |
| CVE-2026-72317 |
SUNRPC: pin upper rpc_clnt across the TLS connect_worker |
17.08.2026 |
9.8 |
| CVE-2026-72318 |
cifs: validate DFS referral string offsets |
17.08.2026 |
9.4 |
| CVE-2026-72319 |
ipvs: ensure inner headers in ICMP errors are in headroom |
17.08.2026 |
9.8 |
| CVE-2026-72320 |
netfilter: nft_lookup: fix catchall element handling with inverted lookups |
17.08.2026 |
9.1 |
| CVE-2026-72322 |
ipv6: mcast: Fix potential UAF in MLD delayed work |
17.08.2026 |
9.8 |
| CVE-2026-72323 |
ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() |
17.08.2026 |
9.8 |
| CVE-2026-72329 |
net/liquidio: drop cached VF pci_dev LUT |
17.08.2026 |
9.3 |
| CVE-2026-72339 |
qede: fix off-by-one in BD ring consumption on build_skb failure |
17.08.2026 |
9.8 |
| CVE-2026-72348 |
netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop |
17.08.2026 |
9.1 |
| CVE-2026-72351 |
gue: validate REMCSUM private option length |
17.08.2026 |
9.8 |
| CVE-2026-72355 |
netfs: Fix barriering when walking subrequest list |
17.08.2026 |
9.8 |
| CVE-2026-72366 |
netfs: Fix netfs_create_write_req() to handle async cache object creation |
17.08.2026 |
9.8 |
| CVE-2026-72381 |
ksmbd: fix use-after-free of fp->owner.name in durable handle owner check |
17.08.2026 |
9.8 |
| CVE-2026-72393 |
eth: fbnic: don't cache shinfo across skb realloc |
17.08.2026 |
9.8 |
| CVE-2026-72398 |
sctp: add INIT verification after cookie unpacking |
17.08.2026 |
9.8 |
| CVE-2026-72399 |
net: enetc: check the number of BDs needed for xdp_frame |
17.08.2026 |
9.8 |
| CVE-2026-72407 |
geneve: validate inner network offset in geneve_gro_complete() |
17.08.2026 |
10 |
| CVE-2026-72408 |
geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint |
17.08.2026 |
10 |
| CVE-2026-72412 |
s390/mm: Fix handling of _PAGE_UNUSED pte bit |
17.08.2026 |
9.3 |
| CVE-2026-72417 |
netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() |
17.08.2026 |
9.8 |
| CVE-2026-72421 |
ipv4: fib: Don't ignore error route in local/main tables. |
17.08.2026 |
10 |
| CVE-2026-72422 |
ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE |
17.08.2026 |
9.8 |
| CVE-2026-72429 |
ipv6: ioam: fix type confusion of dst_entry |
17.08.2026 |
9.8 |
| CVE-2026-72436 |
netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types |
17.08.2026 |
9.8 |
| CVE-2026-72442 |
netfilter: flowtable: fix and simplify IP6IP6 tunnel handling |
17.08.2026 |
9.8 |
| CVE-2026-72451 |
xfrm: Fix xfrm state cache insertion race |
17.08.2026 |
9.8 |
| CVE-2026-72463 |
xfrm: Fix dev use-after-free in xfrm async resumption |
17.08.2026 |
9.8 |
| CVE-2026-72466 |
xprtrdma: Fix bcall rep leak and unbounded peek |
17.08.2026 |
9.8 |
| CVE-2026-72472 |
nfs: use nfsi->rwsem to protect traversal of the file lock list |
17.08.2026 |
9.8 |
| CVE-2026-72473 |
xprtrdma: Decouple req recycling from RPC completion |
17.08.2026 |
9.8 |
| CVE-2026-72477 |
fs/ntfs3: call _ntfs_bad_inode() when failing to rename |
17.08.2026 |
9.8 |
| CVE-2026-72491 |
net/9p: fix race condition on rdma->state in trans_rdma.c |
17.08.2026 |
9.8 |
| CVE-2026-72493 |
net: serialize netif_running() check in enqueue_to_backlog() |
17.08.2026 |
9.9 |
| CVE-2026-72494 |
RDMA/irdma: Replace waitqueue and flag with completion |
17.08.2026 |
9.8 |
| CVE-2026-72495 |
RDMA/bnxt_re: Avoid repeated requests to allocate WC pages |
17.08.2026 |
9.3 |
| CVE-2026-14484 |
RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters |
15.08.2026 |
9.1 |
| CVE-2026-15303 |
6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter |
15.08.2026 |
9.8 |
| CVE-2026-15341 |
User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters |
15.08.2026 |
9.8 |
| CVE-2026-73683 |
Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay |
14.08.2026 |
9.2 |
| CVE-2026-67365 |
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 |
14.08.2026 |
9.2 |
| CVE-2026-17181 |
IBM Db2 Mirror for i is affected by multiple vulnerabilities |
14.08.2026 |
9.3 |
| CVE-2026-17182 |
IBM Db2 Mirror for i is affected by multiple vulnerabilities |
14.08.2026 |
9.8 |
| CVE-2026-17184 |
IBM Db2 Mirror for i is affected by multiple vulnerabilities |
14.08.2026 |
9.8 |
| CVE-2026-17186 |
IBM Db2 Mirror for i is affected by multiple vulnerabilities |
14.08.2026 |
9.9 |
| CVE-2026-50027 |
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete |
14.08.2026 |
9.8 |
| CVE-2026-73678 |
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec() |
14.08.2026 |
10 |
| CVE-2026-19188 |
Haiwell IoT Cloud HMI Gateway OS Command Injection |
14.08.2026 |
10 |
| CVE-2026-49457 |
QUIC has Broken TLS verification |
14.08.2026 |
9.1 |
| CVE-2026-19681 |
Command Injection |
15.08.2026 |
9.4 |
| CVE-2026-19682 |
Command Injection |
15.08.2026 |
9.4 |
| CVE-2026-48528 |
Metacat has an unauthenticated SQL injection vulnerability |
14.08.2026 |
9.8 |
| CVE-2026-73849 |
emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. |
14.08.2026 |
9.8 |
| CVE-2026-19626 |
Remote Code Execution |
15.08.2026 |
9.4 |
| CVE-2026-19871 |
Use of hard-coded credentials in Prospero Flow CRM employee onboarding |
14.08.2026 |
9.3 |
| CVE-2026-72810 |
SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket |
14.08.2026 |
9.2 |
| CVE-2026-72811 |
SiYuan before v3.7.4 SQL Injection via backlink search |
14.08.2026 |
9.9 |
| CVE-2026-72822 |
Grav before 1.0.13 Authentication Bypass via disable2fa |
14.08.2026 |
9.3 |
| CVE-2026-72824 |
Grav before 1.0.13 API Key Scope Bypass via PagesController |
14.08.2026 |
9.3 |
| CVE-2026-72826 |
Grav before 1.0.13 Scope Bypass via createApiKey |
14.08.2026 |
9.3 |
| CVE-2026-72829 |
Grav before 1.0.13 API Key Scope Bypass via UsersController |
14.08.2026 |
9.3 |
| CVE-2026-72830 |
Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass |
14.08.2026 |
9.3 |
| CVE-2026-72836 |
FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass |
14.08.2026 |
9.2 |
| CVE-2026-12949 |
Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter |
14.08.2026 |
9.8 |
| CVE-2026-72839 |
filebrowser through 2.63.16 Privilege Escalation via Signup |
14.08.2026 |
9.3 |
| CVE-2026-72841 |
luci-app-openvpn Path Traversal RCE via instance_name2 |
14.08.2026 |
9.4 |
| CVE-2026-72842 |
OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass |
14.08.2026 |
9.4 |
| CVE-2026-72850 |
Budibase before 3.40.0 Arbitrary File Write via Path Traversal |
14.08.2026 |
9.4 |
| CVE-2026-72851 |
Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook |
14.08.2026 |
9 |
| CVE-2026-73302 |
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified |
14.08.2026 |
9 |
| CVE-2026-73420 |
NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass |
14.08.2026 |
9.1 |
| CVE-2026-73421 |
NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) |
13.08.2026 |
9.1 |
| CVE-2026-73842 |
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation |
13.08.2026 |
9 |
| CVE-2026-73843 |
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs |
14.08.2026 |
9.6 |
| CVE-2026-73665 |
FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection |
13.08.2026 |
9.3 |
| CVE-2026-19750 |
Tenda CH/CP/TX3 SSH hard-coded password |
14.08.2026 |
9.2 |
| CVE-2026-72776 |
AgenticSeek Unauthenticated RCE via /query API Endpoint |
14.08.2026 |
9.3 |
| CVE-2026-73663 |
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover |
14.08.2026 |
9.3 |
| CVE-2026-17482 |
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution |
13.08.2026 |
9.8 |
| CVE-2026-19297 |
Insufficient Authentication Brute Force Protection on Login Endpoint |
15.08.2026 |
9.1 |
| CVE-2026-8715 |
Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath |
14.08.2026 |
9.6 |
| CVE-2026-19747 |
Tenda CH7 ATE Module Kylin HandleCmd command injection |
14.08.2026 |
9.3 |
| CVE-2026-73656 |
Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state |
14.08.2026 |
9.9 |
| CVE-2026-14525 |
IBM WebSphere Application Server Liberty is affected by an authenication bypass |
15.08.2026 |
9.4 |
| CVE-2026-73653 |
Vitest: Browser Mode provider commands bypass the file-access permission gate |
13.08.2026 |
9.4 |
| CVE-2026-73644 |
OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant |
13.08.2026 |
9.6 |
| CVE-2026-73649 |
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) |
14.08.2026 |
9.8 |
| CVE-2026-73567 |
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock |
14.08.2026 |
9.1 |
| CVE-2026-67614 |
CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal |
14.08.2026 |
9.3 |
| CVE-2026-73532 |
Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build |
14.08.2026 |
9.3 |
| CVE-2026-73533 |
Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build |
14.08.2026 |
9.3 |
| CVE-2026-53790 |
rsync < 3.5.0 Command Injection via Multiple Code Paths |
14.08.2026 |
9.2 |
| CVE-2026-53791 |
rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header |
14.08.2026 |
9.1 |
| CVE-2026-53793 |
rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode |
14.08.2026 |
9.1 |
| CVE-2026-70452 |
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure |
14.08.2026 |
9.1 |
| CVE-2026-70460 |
rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink |
14.08.2026 |
9.2 |
| CVE-2026-27544 |
WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability |
13.08.2026 |
10 |
| CVE-2026-28001 |
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-28008 |
WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-28142 |
WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-28148 |
WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-28149 |
WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-28185 |
WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-61962 |
WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability |
13.08.2026 |
10 |
| CVE-2026-61966 |
WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-61967 |
WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-61969 |
WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66424 |
WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-66436 |
WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66446 |
WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66453 |
WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-66458 |
WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66465 |
WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-66472 |
WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66478 |
WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability |
13.08.2026 |
9.3 |
| CVE-2026-66691 |
WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability |
13.08.2026 |
9.8 |
| CVE-2026-49827 |
WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) |
13.08.2026 |
9.8 |
| CVE-2026-73483 |
Flowise before 3.1.3 Sandbox Escape via Puppeteer |
14.08.2026 |
9.4 |
| CVE-2026-73485 |
Flowise before 3.1.3 Remote Code Execution via Airtable Agent |
14.08.2026 |
9 |
| CVE-2026-73486 |
Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV |
13.08.2026 |
9 |
| CVE-2026-73487 |
Flowise before 3.1.3 Prompt Injection RCE via CSV Agent |
14.08.2026 |
9 |
| CVE-2026-73601 |
Flowise before 3.1.3 Remote Code Execution via Custom MCP |
14.08.2026 |
9 |
| CVE-2026-73602 |
Flowise before 3.1.3 Sandbox Escape to RCE |
13.08.2026 |
9 |
| CVE-2026-73608 |
SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget |
14.08.2026 |
9.2 |
| CVE-2026-59503 |
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor |
13.08.2026 |
9.1 |
| CVE-2026-59504 |
Priority – CWE-602: Client-Side Enforcement of Server-Side Security |
13.08.2026 |
9.1 |
| CVE-2026-59506 |
Priority – CWE-306: Missing Authentication for Critical Function |
13.08.2026 |
9.3 |
| CVE-2026-59507 |
Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control |
13.08.2026 |
9.3 |
| CVE-2026-59500 |
Priority - CWE-287: Improper Authentication |
13.08.2026 |
10 |
| CVE-2026-15413 |
Link Factory - Backdoor |
13.08.2026 |
10 |
| CVE-2026-49819 |
UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd |
13.08.2026 |
9.8 |
| CVE-2026-49481 |
UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd |
13.08.2026 |
9.6 |
| CVE-2026-71193 |
|
13.08.2026 |
9.6 |
| CVE-2026-71471 |
Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image |
13.08.2026 |
9 |
| CVE-2024-27253 |
IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request |
13.08.2026 |
10 |
| CVE-2026-73501 |
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default |
13.08.2026 |
9.1 |
| CVE-2026-73519 |
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret |
13.08.2026 |
9.3 |
| CVE-2026-19001 |
MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names |
13.08.2026 |
9.5 |
| CVE-2026-66898 |
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE |
13.08.2026 |
9.9 |
| CVE-2026-63293 |
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root |
13.08.2026 |
9.9 |
| CVE-2026-63294 |
Root RCE via image backup.yaml symlink |
13.08.2026 |
9.9 |
| CVE-2026-17083 |
IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
13.08.2026 |
9.8 |
| CVE-2026-63296 |
Project restriction bypass via instance migration config override |
13.08.2026 |
9.9 |
| CVE-2026-63297 |
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge |
13.08.2026 |
9.9 |
| CVE-2026-72508 |
Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) |
13.08.2026 |
9.9 |
| CVE-2026-73414 |
Shescape: Shell injection via unescaped parentheses on Windows with CMD |
14.08.2026 |
9.2 |
| CVE-2026-19656 |
ScadaLTS Authenticated Remote Code Execution |
12.08.2026 |
9.9 |
| CVE-2026-62420 |
Cross-project cluster migration bypasses project restrictions via cluster notification flag |
12.08.2026 |
9.9 |
| CVE-2026-63300 |
Cross-project instance move bypasses all project restrictions allowing host command execution |
13.08.2026 |
9.9 |
| CVE-2026-72789 |
SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks |
14.08.2026 |
9.2 |
| CVE-2026-72793 |
SiYuan before v3.7.4 Information Disclosure via /api/system/getConf |
14.08.2026 |
9.2 |
| CVE-2026-72794 |
siyuan before v3.7.4 Session Cookie Key Disclosure via getConf |
14.08.2026 |
9.2 |
| CVE-2026-72795 |
SiYuan before v3.7.4 Information Disclosure via Embed Block |
14.08.2026 |
9.2 |
| CVE-2026-72798 |
SiYuan before v3.7.4 Information Disclosure via renderAttributeView |
14.08.2026 |
9.2 |
| CVE-2026-72804 |
SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints |
14.08.2026 |
9.2 |
| CVE-2026-73268 |
Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection |
12.08.2026 |
9.9 |
| CVE-2026-73269 |
Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa |
12.08.2026 |
9.9 |
| CVE-2026-73329 |
CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint |
14.08.2026 |
9.2 |
| CVE-2026-73332 |
CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field |
14.08.2026 |
9.2 |
| CVE-2026-73407 |
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) |
12.08.2026 |
9 |
| CVE-2026-73300 |
Budibase: SQL Injection via `multipleStatements: true` |
12.08.2026 |
9.6 |
| CVE-2026-16860 |
IBM i is Affected By Remote Code Execution Vulnerability [] |
12.08.2026 |
9.9 |
| CVE-2026-16956 |
IBM Db2 Mirror for i is vulnerable to OS command injection [] |
12.08.2026 |
9.8 |
| CVE-2026-17218 |
IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] |
12.08.2026 |
9.8 |
| CVE-2026-73299 |
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer |
12.08.2026 |
10 |
| CVE-2026-17276 |
IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
12.08.2026 |
9.6 |
| CVE-2026-73296 |
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure |
13.08.2026 |
9.4 |
| CVE-2026-73294 |
Semaphore U: OS Command Injection |
12.08.2026 |
9.9 |
| CVE-2026-64639 |
|
14.08.2026 |
9.3 |
| CVE-2026-73263 |
Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path |
12.08.2026 |
9.9 |
| CVE-2026-50561 |
Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse |
13.08.2026 |
9.4 |
| CVE-2026-67285 |
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 |
14.08.2026 |
9.2 |
| CVE-2026-57858 |
Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID |
13.08.2026 |
9.3 |
| CVE-2026-67282 |
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 |
12.08.2026 |
10 |
| CVE-2025-41769 |
Unauthenticated Buffer Overflow in PROFINET Service |
13.08.2026 |
9.3 |
| CVE-2026-66659 |
WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability |
12.08.2026 |
9.3 |
| CVE-2026-70398 |
Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace |
12.08.2026 |
9.6 |
| CVE-2026-72526 |
Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation |
12.08.2026 |
9.9 |
| CVE-2026-68431 |
ksmbd: validate minimum PDU size for transform requests |
17.08.2026 |
9.1 |
| CVE-2026-5917 |
libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend |
14.08.2026 |
9.4 |
| CVE-2026-67568 |
Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials |
12.08.2026 |
9.3 |
| CVE-2026-68067 |
Mira Hormone Monitor, Mira Android App Weak Authentication |
12.08.2026 |
9.3 |
| CVE-2026-48765 |
TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding |
12.08.2026 |
9.9 |
| CVE-2026-16230 |
Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field |
11.08.2026 |
9.8 |
| CVE-2026-45618 |
LiquidJS is Vulnerable to Remote Code Execution |
13.08.2026 |
10 |
| CVE-2026-73034 |
DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header |
14.08.2026 |
9.3 |
| CVE-2026-73032 |
PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() |
11.08.2026 |
9.4 |
| CVE-2026-18691 |
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure |
11.08.2026 |
9 |
| CVE-2026-72742 |
DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing |
12.08.2026 |
9.2 |
| CVE-2026-69102 |
MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust |
14.08.2026 |
9.3 |
| CVE-2026-27302 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
13.08.2026 |
10 |
| CVE-2026-48381 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
11.08.2026 |
9 |
| CVE-2026-71362 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
12.08.2026 |
9.1 |
| CVE-2026-71398 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
13.08.2026 |
10 |
| CVE-2026-47705 |
TypeBot vulnerable to CSV injection in result export |
13.08.2026 |
9.6 |
| CVE-2026-73090 |
PeerTube: Cross-origin remote video takeover via Update activity |
13.08.2026 |
9.3 |
| CVE-2026-73211 |
PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() |
11.08.2026 |
9.8 |
| CVE-2026-12571 |
Authentication Bypass Leading to Account Takeover |
12.08.2026 |
9.8 |
| CVE-2026-50516 |
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
16.08.2026 |
9.4 |
| CVE-2026-59124 |
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability |
16.08.2026 |
9.8 |
| CVE-2026-62815 |
Microsoft QUIC Remote Code Execution Vulnerability |
16.08.2026 |
9.8 |
| CVE-2026-62878 |
Windows DNS Server Remote Code Execution Vulnerability |
16.08.2026 |
9.8 |
| CVE-2026-62893 |
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
16.08.2026 |
9.8 |
| CVE-2026-65791 |
Windows iSCSI Target Service Remote Code Execution Vulnerability |
16.08.2026 |
9.8 |
| CVE-2026-70306 |
Microsoft Office SharePoint Spoofing Vulnerability |
16.08.2026 |
9.3 |
| CVE-2026-48362 |
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
12.08.2026 |
10 |
| CVE-2026-71384 |
ColdFusion | Incorrect Authorization (CWE-863) |
12.08.2026 |
9.6 |
| CVE-2026-73080 |
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle |
13.08.2026 |
9.3 |
| CVE-2025-31114 |
Fooocus webui vulnerable to Remote Code Execution |
13.08.2026 |
9.3 |
| CVE-2026-73069 |
Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution |
11.08.2026 |
9.1 |
| CVE-2026-17061 |
Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 |
11.08.2026 |
10 |
| CVE-2026-47702 |
TypeBot API tokens stored in plaintext |
11.08.2026 |
9.1 |
| CVE-2026-72920 |
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control |
11.08.2026 |
9.8 |
| CVE-2026-46670 |
YesWiki: Unauthenticated SQL Injection |
13.08.2026 |
9.8 |
| CVE-2026-48056 |
Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler |
11.08.2026 |
10 |
| CVE-2026-48046 |
Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler |
13.08.2026 |
9.3 |
| CVE-2026-18972 |
Velociraptor authenticated identity-spoofing vulnerability |
11.08.2026 |
9.6 |
| CVE-2026-58115 |
|
12.08.2026 |
10 |
| CVE-2026-72785 |
Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
11.08.2026 |
9.3 |
| CVE-2026-13737 |
Command Restriction Bypass |
11.08.2026 |
9.2 |
| CVE-2026-13738 |
Improper Authorization Validation |
11.08.2026 |
9.2 |
| CVE-2026-72550 |
Friendica Friendica - SQL Injection |
11.08.2026 |
9.8 |
| CVE-2026-72599 |
e107 e107 - SQL Injection |
11.08.2026 |
9.8 |
| CVE-2026-72603 |
wg-easy wg-easy - OS Command Injection |
11.08.2026 |
9.9 |
| CVE-2026-58231 |
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) |
12.08.2026 |
10 |
| CVE-2026-10579 |
Picketlink-federation: auth bypass in picketlink saml unsolicited-response |
11.08.2026 |
9.8 |
| CVE-2026-13716 |
Path Traversal: '.../...//' in Crafty Controller |
11.08.2026 |
9.1 |
| CVE-2026-19516 |
CVE-2026-19516 CVE Record |
12.08.2026 |
9.1 |
| CVE-2026-19425 |
Win Men Intermational|Travel Agency Management System - SQL Injection |
12.08.2026 |
9.3 |
| CVE-2026-34265 |
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform |
12.08.2026 |
9.8 |
| CVE-2026-44758 |
Code Injection vulnerability in Manufacturing Integration and Intelligence |
11.08.2026 |
9.1 |
| CVE-2026-48161 |
react18-use was vulnerable to malicious code execution via compromised commits |
11.08.2026 |
9.3 |
| CVE-2026-48160 |
react-tracked was vulnerable to malicious code execution via compromised commits |
11.08.2026 |
9.3 |
| CVE-2026-72911 |
ERPNext: Possibility of server-side template injection due to missing validation |
13.08.2026 |
9.9 |
| CVE-2026-14450 |
Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication |
11.08.2026 |
9.9 |
| CVE-2026-18948 |
Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server |
11.08.2026 |
9.9 |
| CVE-2026-72904 |
Firecrawl: Arbitrary file read via JSON Schema $ref expansion |
11.08.2026 |
9.3 |
| CVE-2026-72901 |
Dokploy: Remote Code Execution via volume-backup |
13.08.2026 |
9.9 |
| CVE-2026-72902 |
Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById |
12.08.2026 |
9.9 |
| CVE-2025-13293 |
Backdoor / default root credentials |
12.08.2026 |
9.3 |
| CVE-2025-13294 |
Unauthenticated SQL Injection |
12.08.2026 |
9.3 |
| CVE-2025-15681 |
Insufficient Webserver Authentication |
12.08.2026 |
9.2 |
| CVE-2026-72880 |
Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` |
11.08.2026 |
9.9 |
| CVE-2026-72882 |
Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers |
13.08.2026 |
9.9 |
| CVE-2026-72886 |
Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) |
10.08.2026 |
9.9 |
| CVE-2026-72876 |
Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* |
10.08.2026 |
9.9 |
| CVE-2026-72877 |
Dokploy: Command Injection via dockerImage in buildRemoteDocker |
13.08.2026 |
9.6 |
| CVE-2026-72878 |
Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments |
12.08.2026 |
9.6 |
| CVE-2026-72879 |
Dokploy: Command Injection via Registry Credentials in Swarm Upload |
11.08.2026 |
9.4 |
| CVE-2026-72864 |
Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) |
11.08.2026 |
9.9 |
| CVE-2026-72865 |
Dokploy: OS Command Injection via compose `composePath` |
11.08.2026 |
9.9 |
| CVE-2026-72867 |
Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) |
13.08.2026 |
9.9 |
| CVE-2026-72868 |
Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection |
12.08.2026 |
9.9 |
| CVE-2026-72869 |
Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE |
11.08.2026 |
9.9 |
| CVE-2026-72872 |
Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` |
13.08.2026 |
9.9 |
| CVE-2026-72863 |
Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host |
10.08.2026 |
9.9 |
| CVE-2026-16626 |
JasperReports Server: XXE Injection Vulnerability (Unauthenticated) |
11.08.2026 |
9.3 |
| CVE-2026-48159 |
use-reducer-async was vulnerable to malicious code execution via compromised commits |
11.08.2026 |
9.3 |
| CVE-2026-72740 |
Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` |
10.08.2026 |
9.9 |
| CVE-2026-72862 |
Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE |
13.08.2026 |
9.9 |
| CVE-2026-72898 |
Metabase SQL injection via password reset endpoint |
12.08.2026 |
10 |
| CVE-2026-72899 |
Metabase SQL injection via public card or dashboard |
11.08.2026 |
10 |
| CVE-2026-72735 |
Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution |
10.08.2026 |
9.9 |
| CVE-2026-72736 |
Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE |
10.08.2026 |
9.9 |
| CVE-2026-72737 |
Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups |
13.08.2026 |
9.6 |
| CVE-2026-72738 |
Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter |
10.08.2026 |
9.9 |
| CVE-2026-72733 |
Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore |
10.08.2026 |
9.9 |
| CVE-2026-48158 |
use-context-selector was vulnerable to malicious code execution via compromised commits |
11.08.2026 |
9.3 |
| CVE-2026-47754 |
unauthenticated path traversal in Metacat 2.x |
10.08.2026 |
9.3 |
| CVE-2026-63106 |
ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php |
10.08.2026 |
9.3 |
| CVE-2026-13206 |
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection |
10.08.2026 |
9.8 |
| CVE-2026-68117 |
tipc: clear sock->sk on the failed-insert path in tipc_sk_create() |
17.08.2026 |
9.8 |
| CVE-2026-68123 |
openvswitch: fix GSO userspace truncation underflow |
17.08.2026 |
9.8 |
| CVE-2026-68124 |
mctp: serial: handle zero-length frames to prevent rx buffer overflow |
17.08.2026 |
9.6 |
| CVE-2026-68127 |
ila: reload IPv6 header after pskb_may_pull in checksum adjust |
17.08.2026 |
9.8 |
| CVE-2026-68136 |
net: gro: fix double aggregation of flush-marked skbs |
17.08.2026 |
9.8 |
| CVE-2026-68137 |
net/x25: fix use-after-free in x25_kill_by_neigh() |
17.08.2026 |
9.8 |
| CVE-2026-68144 |
phonet: pep: fix use-after-free in pep_get_sb() |
17.08.2026 |
9.8 |
| CVE-2026-68154 |
libceph: reject zero bucket types in crush_decode |
17.08.2026 |
9.8 |
| CVE-2026-68156 |
libceph: refresh auth->authorizer_buf{,_len} after authorizer update |
17.08.2026 |
9.8 |
| CVE-2026-68158 |
libceph: Fix multiplication overflow in decode_new_up_state_weight() |
17.08.2026 |
9.8 |
| CVE-2026-68159 |
libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE |
17.08.2026 |
9.8 |
| CVE-2026-68160 |
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() |
17.08.2026 |
9.8 |
| CVE-2026-68161 |
sctp: close UDP tunnel sockets during netns teardown |
17.08.2026 |
9.8 |
| CVE-2026-68170 |
mptcp: fix stale skb->sk reference on subflow close |
17.08.2026 |
9.8 |
| CVE-2026-68300 |
sctp: auth: verify auth requirement when auth_chunk is NULL |
17.08.2026 |
9.8 |
| CVE-2026-68302 |
amt: re-read skb header pointers after every pull |
17.08.2026 |
9.8 |
| CVE-2026-68343 |
smb: client: validate DFS referral PathConsumed |
17.08.2026 |
9.1 |
| CVE-2026-68381 |
ksmbd: pin conn during async oplock break notification |
17.08.2026 |
9.8 |
| CVE-2026-68385 |
s390/checksum: Fix csum_partial() without vector facility |
17.08.2026 |
9.8 |
| CVE-2026-68388 |
smb/client: handle overlapping allocated ranges in fallocate |
17.08.2026 |
9.8 |
| CVE-2026-68426 |
xfrm: fix stale skb->prev after async crypto steals a GSO segment |
17.08.2026 |
9.8 |
| CVE-2026-68083 |
ksmbd: fix path resolution in ksmbd_vfs_kern_path_create |
17.08.2026 |
9.1 |