| CVE-2026-15572 |
Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation |
05.08.2026 |
|
| CVE-2026-15587 |
Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header |
05.08.2026 |
|
| CVE-2026-16442 |
Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction |
05.08.2026 |
|
| CVE-2026-32835 |
|
05.08.2026 |
|
| CVE-2026-39923 |
Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset |
05.08.2026 |
|
| CVE-2026-39924 |
Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation |
05.08.2026 |
|
| CVE-2026-48834 |
Apache Answer: Denial of service via crafted Accept-Language header parsing |
05.08.2026 |
|
| CVE-2026-48911 |
Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow |
05.08.2026 |
|
| CVE-2026-48912 |
Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL |
05.08.2026 |
|
| CVE-2026-49331 |
Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths |
05.08.2026 |
|
| CVE-2026-50749 |
Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions |
05.08.2026 |
|
| CVE-2026-53992 |
Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date Parameters |
05.08.2026 |
|
| CVE-2026-60023 |
Apache Answer: Unauthorized disclosure of deleted or pending answer content |
05.08.2026 |
|
| CVE-2026-60053 |
Apache Answer: Residual Administrative API Key Access After Role or Account Revocation |
05.08.2026 |
|
| CVE-2026-70595 |
Ghost: Server-Side Request Forgery Mitigation Issue |
05.08.2026 |
4 |
| CVE-2026-70596 |
Ghost: Cross-Site Scripting in Feature Image Captions |
05.08.2026 |
4.3 |
| CVE-2026-70597 |
Electron: Parent process code-sign check is spoofable |
05.08.2026 |
6.3 |
| CVE-2026-12410 |
CCleaner local privilege escalation via link following on uninstall |
05.08.2026 |
7.8 |
| CVE-2026-15573 |
Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher |
05.08.2026 |
|
| CVE-2026-16071 |
Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary |
05.08.2026 |
|
| CVE-2026-16100 |
Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text |
05.08.2026 |
|
| CVE-2026-16102 |
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers |
05.08.2026 |
|
| CVE-2026-17613 |
CVE-2026-17613 |
05.08.2026 |
|
| CVE-2026-54876 |
Client-Side Memory Leak in OCSP Response Checking |
05.08.2026 |
|
| CVE-2025-70962 |
|
05.08.2026 |
|
| CVE-2026-15979 |
Content Egg <= 11.3.0 - Authenticated (Author+) Arbitrary File Deletion |
05.08.2026 |
8.1 |
| CVE-2026-16443 |
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation |
05.08.2026 |
|
| CVE-2026-17506 |
Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting |
05.08.2026 |
7.2 |
| CVE-2026-67623 |
Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook |
05.08.2026 |
|
| CVE-2026-7456 |
Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action |
05.08.2026 |
6.5 |
| CVE-2026-7529 |
wiseCampaign <= 1.1.16 - Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API |
05.08.2026 |
7.5 |
| CVE-2026-71226 |
Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path |
05.08.2026 |
|
| CVE-2026-71227 |
Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return |
05.08.2026 |
|
| CVE-2026-71259 |
ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution |
05.08.2026 |
8.6 |
| CVE-2026-71260 |
ESPHome web_server Plaintext Password Disclosure via JSON "value" Field |
05.08.2026 |
6.5 |
| CVE-2026-71261 |
dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buffer Overflow on 32-bit Builds |
05.08.2026 |
7.8 |
| CVE-2026-71262 |
IoTSharp BlobStorageController Missing Authentication and Path Traversal |
05.08.2026 |
9.8 |
| CVE-2026-71263 |
FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() |
05.08.2026 |
9.1 |
| CVE-2026-71264 |
WLED Unauthenticated Configuration Disclosure via /json/cfg and Global Settings-PIN Lock State |
05.08.2026 |
8.2 |
| CVE-2026-71265 |
Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy() |
05.08.2026 |
7.5 |
| CVE-2026-71266 |
tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing |
05.08.2026 |
7.8 |
| CVE-2026-71267 |
microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() |
05.08.2026 |
9.8 |
| CVE-2026-71268 |
OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write |
05.08.2026 |
9.9 |
| CVE-2026-71269 |
Node-RED Library API Path Traversal Leading to Arbitrary File Read/Write |
05.08.2026 |
7.2 |
| CVE-2026-71270 |
Stirling-PDF Server-Side Request Forgery via /api/v1/convert/url/pdf WeasyPrint Subprocess |
05.08.2026 |
8.6 |
| CVE-2026-71271 |
Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass |
05.08.2026 |
8.5 |
| CVE-2026-71272 |
Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext() |
05.08.2026 |
8.5 |
| CVE-2026-71273 |
OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable and WiFi Hijack |
05.08.2026 |
6.5 |
| CVE-2026-71274 |
OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels |
05.08.2026 |
8.5 |
| CVE-2026-71275 |
OpenBK7231T Reflected XSS via OTA host Parameter |
05.08.2026 |
5.4 |
| CVE-2026-71276 |
Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Parameter |
05.08.2026 |
7.1 |
| CVE-2026-71277 |
rust-iot-platform Authentication Bypass via Non-Validated Authorization Header |
05.08.2026 |
9.1 |
| CVE-2026-71278 |
rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation |
05.08.2026 |
9.8 |
| CVE-2026-71279 |
Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Execution |
05.08.2026 |
8.1 |
| CVE-2026-71280 |
go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch |
05.08.2026 |
8.5 |
| CVE-2026-71281 |
peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA and CorDA Modules |
05.08.2026 |
8.8 |
| CVE-2026-71282 |
ChirpStack SQLite Backend SQL Injection via Device Tag Key in ListDevices Filter |
05.08.2026 |
6.5 |
| CVE-2026-71283 |
Fledge IoT Gateway Backup Restore Tar Path Traversal |
05.08.2026 |
4.9 |
| CVE-2026-71284 |
Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename |
05.08.2026 |
7.2 |
| CVE-2026-71285 |
Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages |
05.08.2026 |
8.1 |
| CVE-2026-71286 |
ember-dynamic-render-template Client-Side Template Injection via Unsanitized templateString |
05.08.2026 |
6.1 |
| CVE-2026-71287 |
Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Blind SQL Injection |
05.08.2026 |
8.8 |
| CVE-2026-71288 |
Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.pl |
05.08.2026 |
8.8 |
| CVE-2026-71289 |
NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API |
05.08.2026 |
9.8 |
| CVE-2026-71291 |
Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering |
05.08.2026 |
8.8 |
| CVE-2026-71292 |
Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter |
05.08.2026 |
7.2 |
| CVE-2026-71293 |
Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable |
05.08.2026 |
6.2 |
| CVE-2026-71294 |
Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions |
05.08.2026 |
7.7 |
| CVE-2026-0516 |
|
05.08.2026 |
|
| CVE-2026-16022 |
Command Injection in @oblique/cli |
05.08.2026 |
7.8 |
| CVE-2026-71225 |
Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries |
05.08.2026 |
|
| CVE-2026-18933 |
wp-downloadmanager: Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal |
05.08.2026 |
7.2 |
| CVE-2026-46581 |
|
05.08.2026 |
|
| CVE-2026-61891 |
|
05.08.2026 |
7.5 |
| CVE-2026-64582 |
RDMA/rxe: Fix a use-after-free problem in rxe_mmap |
05.08.2026 |
|
| CVE-2026-71254 |
nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() |
05.08.2026 |
9.8 |
| CVE-2026-71255 |
nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res() |
05.08.2026 |
8.6 |
| CVE-2026-71256 |
nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id |
05.08.2026 |
9.8 |
| CVE-2026-12609 |
|
05.08.2026 |
7.5 |
| CVE-2026-14304 |
|
05.08.2026 |
|
| CVE-2026-14574 |
|
05.08.2026 |
|
| CVE-2026-17578 |
Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement |
05.08.2026 |
|
| CVE-2026-60009 |
|
05.08.2026 |
8.8 |
| CVE-2026-66747 |
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant |
05.08.2026 |
|
| CVE-2026-71231 |
IOTSmartHome: Unauthenticated SQL Injection via lastLogin Cookie |
05.08.2026 |
9.8 |
| CVE-2026-71232 |
MacCMS10: Incomplete Function Blacklist in Template Editor Enables Authenticated RCE |
05.08.2026 |
7.2 |
| CVE-2026-71233 |
InvoiceNinja: Stored XSS via Invoice/Quote Terms Field |
05.08.2026 |
8.7 |
| CVE-2026-71234 |
Documize Community: Attachment Download Authorization Bypass via Non-Validated secure Token |
05.08.2026 |
7.5 |
| CVE-2026-71235 |
Magistrala IoT Platform: Unrestricted Go/Lua Script Execution in Rules Engine |
05.08.2026 |
8.8 |
| CVE-2026-71236 |
Grocy: Stored XSS via HTMLPurifier Output Double-Decode |
05.08.2026 |
8.7 |
| CVE-2026-71237 |
Miantang IoT-PHP: Unauthenticated SQL Injection in /userlogin |
05.08.2026 |
9.8 |
| CVE-2026-71238 |
DjangoCRM: Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery |
05.08.2026 |
9.1 |
| CVE-2026-71239 |
DjangoCRM: Server-Side Template Injection in Mass Mail Message Rendering |
05.08.2026 |
8.1 |
| CVE-2026-71240 |
DjangoCRM: Unauthenticated Open Redirect via toggle_default_sorting next_url Parameter |
05.08.2026 |
4.3 |
| CVE-2026-71241 |
Book-Management-System: Unauthenticated Disclosure of Student PII and Borrowing History |
05.08.2026 |
7.5 |
| CVE-2026-71242 |
Crater: Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy |
05.08.2026 |
8.2 |
| CVE-2026-71243 |
backmeup (npm): OS Command Injection via Backup Option Values |
05.08.2026 |
8.8 |
| CVE-2026-71244 |
Paperless-ngx: Mail Account Test Connection Leaks Stored IMAP/OAuth Credentials to Attacker-Controlled Host |
05.08.2026 |
6.5 |
| CVE-2026-71245 |
Mautic: SQL Injection via field Parameter in Lead-by-Field-Value AJAX Endpoint |
05.08.2026 |
7.1 |
| CVE-2026-71246 |
Pixelfed: Authenticated SSRF via Remote URL Search |
05.08.2026 |
4.3 |
| CVE-2026-71247 |
Documenso: Assistant Recipient Can Forge Another Signer's Signature in Sequential-Signing Documents |
05.08.2026 |
6.5 |
| CVE-2026-71248 |
Inventory-Management-System-PHP: Unauthenticated SQL Injection in Login and Product Deletion |
05.08.2026 |
9.8 |
| CVE-2026-71249 |
299Ko: Unauthenticated Reflected XSS in Public Contact Form |
05.08.2026 |
6.1 |
| CVE-2026-71250 |
Firefly III: Webhook URL Validation Explicitly Allows Loopback and Is Bypassable via DNS Rebinding |
05.08.2026 |
4.3 |
| CVE-2026-71251 |
Akaunting: Cross-Company Media IDOR in Customer Portal Download Endpoint |
05.08.2026 |
6.5 |
| CVE-2026-71252 |
toner-management: Unauthenticated State-Changing Admin Actions |
05.08.2026 |
8.2 |
| CVE-2026-0931 |
Denial-of-service vulnerability in M-Files Server |
05.08.2026 |
|
| CVE-2026-15452 |
Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String |
05.08.2026 |
4.7 |
| CVE-2026-25703 |
Potential information leakage from manager /network/graph API in NeuVector |
05.08.2026 |
7.3 |
| CVE-2026-44945 |
Cross-Cluster Impersonation Confused-Deputy Privilege Escalation |
05.08.2026 |
9.1 |
| CVE-2026-10059 |
Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token |
05.08.2026 |
|
| CVE-2026-10090 |
Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription |
05.08.2026 |
|
| CVE-2026-8029 |
SQL Injection Vulnerability in ZTE SmartLife App |
05.08.2026 |
3.9 |
| CVE-2026-11920 |
JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order' Parameter |
05.08.2026 |
4.9 |
| CVE-2026-11969 |
WP TripAdvisor Review Slider <= 14.3 - Authenticated (Administrator+) SQL Injection |
05.08.2026 |
4.9 |
| CVE-2026-11977 |
WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection |
05.08.2026 |
6.5 |
| CVE-2026-4431 |
Easy Post Submission <= 2.3.0 - Missing Authorization |
05.08.2026 |
9.1 |
| CVE-2026-55996 |
Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent |
05.08.2026 |
4.3 |
| CVE-2026-55997 |
Long-lived Rancher registration token exposed in plaintext |
05.08.2026 |
8.8 |
| CVE-2026-55998 |
Cluster Existence Oracle via Unauthenticated Import Endpoint |
05.08.2026 |
5.3 |
| CVE-2026-59675 |
Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service |
05.08.2026 |
7.5 |
| CVE-2026-64566 |
xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() |
05.08.2026 |
|
| CVE-2026-64567 |
btrfs: reject free space cache with more entries than pages |
05.08.2026 |
|
| CVE-2026-64568 |
wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure |
05.08.2026 |
|
| CVE-2026-64569 |
mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n |
05.08.2026 |
|
| CVE-2026-64570 |
wifi: mac80211: fix fils_discovery double free on alloc failure |
05.08.2026 |
|
| CVE-2026-64571 |
wifi: p54: validate RX frame length in p54_rx_eeprom_readback() |
05.08.2026 |
|
| CVE-2026-64572 |
ipv4: fib: free fib_alias with kfree_rcu() on insert error path |
05.08.2026 |
|
| CVE-2026-64573 |
Bluetooth: qca: fix NVM tag length underflow in TLV parser |
05.08.2026 |
|
| CVE-2026-64574 |
wifi: mac80211: tear down new links on vif update error path |
05.08.2026 |
|
| CVE-2026-64575 |
bpf: tcp: fix double sock release on batch realloc |
05.08.2026 |
|
| CVE-2026-64576 |
nexthop: initialize extack in nh_res_bucket_migrate() |
05.08.2026 |
|
| CVE-2026-64577 |
gtp: check skb_pull_data() return in gtp1u_send_echo_resp() |
05.08.2026 |
|
| CVE-2026-64578 |
ksmbd: validate compound request size before reading StructureSize2 |
05.08.2026 |
|
| CVE-2026-64579 |
xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert |
05.08.2026 |
|
| CVE-2026-64580 |
xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() |
05.08.2026 |
|
| CVE-2026-64581 |
xfrm: fix sk_dst_cache double-free in xfrm_user_policy() |
05.08.2026 |
|
| CVE-2026-6020 |
ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API |
05.08.2026 |
7.2 |
| CVE-2026-7520 |
MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action |
05.08.2026 |
8.1 |
| CVE-2026-11454 |
Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure Direct Object Reference |
05.08.2026 |
6.5 |
| CVE-2026-12000 |
Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API |
05.08.2026 |
7.5 |
| CVE-2026-15281 |
User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection |
05.08.2026 |
6.5 |
| CVE-2026-17505 |
TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting |
05.08.2026 |
6.1 |
| CVE-2026-17532 |
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting |
05.08.2026 |
6.1 |
| CVE-2026-18881 |
TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter |
05.08.2026 |
7.5 |
| CVE-2026-54416 |
Pluck CMS: Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist |
05.08.2026 |
|
| CVE-2026-54418 |
Leantime: Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and Bypass |
05.08.2026 |
|
| CVE-2026-55739 |
Crater: Missing Tenant-Ownership Check in CustomerPolicy Allows Cross-Company Customer Data Theft and Deletion |
05.08.2026 |
|
| CVE-2026-55747 |
PocketFlow: Path Traversal in pocketflow-coding-agent Cookbook Example File Tools |
05.08.2026 |
|
| CVE-2026-5108 |
Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting |
05.08.2026 |
4.4 |
| CVE-2026-5116 |
Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting |
05.08.2026 |
4.4 |
| CVE-2026-5581 |
Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion |
05.08.2026 |
9.1 |
| CVE-2026-5651 |
Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter |
05.08.2026 |
4.9 |
| CVE-2026-61483 |
Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow DoS |
05.08.2026 |
|
| CVE-2026-61484 |
Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoS |
05.08.2026 |
|
| CVE-2026-61485 |
Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation reading an index |
05.08.2026 |
|
| CVE-2026-61486 |
Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed input |
05.08.2026 |
|
| CVE-2026-6079 |
Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion |
05.08.2026 |
7.3 |
| CVE-2026-6147 |
LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload |
05.08.2026 |
8.8 |
| CVE-2026-6627 |
WPFormify <= 1.1.1 - Missing Authorization |
05.08.2026 |
8.2 |
| CVE-2026-6639 |
AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenticated Sensitive Information Exposure |
05.08.2026 |
7.5 |
| CVE-2026-6972 |
SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting |
05.08.2026 |
6.4 |
| CVE-2026-70376 |
Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE |
05.08.2026 |
|
| CVE-2026-70377 |
imagecli: Uncontrolled Memory Allocation via Unbounded scale Ratio Causes Denial of Service |
05.08.2026 |
|
| CVE-2026-70378 |
imagecli: Negative carve Ratio Bypasses Bounds Check and Crashes Process via Reachable Panic |
05.08.2026 |
|
| CVE-2026-71202 |
raster: Integer Underflow in crop() Offset Handling Causes Capacity-Overflow Panic |
05.08.2026 |
|
| CVE-2026-71203 |
changedetection.io: Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema |
05.08.2026 |
|
| CVE-2026-71204 |
changedetection.io: Omitted Checkbox in /settings Save Silently Disables API Key Enforcement |
05.08.2026 |
|
| CVE-2026-71205 |
changedetection.io: No Rate Limiting on /login Enables Unlimited Password Brute-Force |
05.08.2026 |
|
| CVE-2026-71206 |
shiori: JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion |
05.08.2026 |
|
| CVE-2026-71207 |
Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass |
05.08.2026 |
|
| CVE-2026-71208 |
KubeSphere: SSRF via Unvalidated Cluster CRD Connection Endpoint in Cluster Reconciliation |
05.08.2026 |
|
| CVE-2026-71209 |
audiobookshelf: %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal |
05.08.2026 |
|
| CVE-2026-71210 |
mealie: DNS-Rebinding TOCTOU in SSRF Guard Allows Internal Network and Cloud Metadata Access |
05.08.2026 |
|
| CVE-2026-71211 |
mlflow: Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint |
05.08.2026 |
|
| CVE-2026-71212 |
xidown: Argument Injection via Unterminated yt-dlp Command Line Construction |
05.08.2026 |
|
| CVE-2026-71213 |
typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force |
05.08.2026 |
|
| CVE-2026-71214 |
NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server |
05.08.2026 |
|
| CVE-2026-71215 |
art-template: Path Traversal in Sub-Template Resolution via include()/extend() |
05.08.2026 |
|
| CVE-2026-7105 |
Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function |
05.08.2026 |
4.3 |
| CVE-2026-7441 |
Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting |
05.08.2026 |
6.4 |
| CVE-2026-7444 |
Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery |
05.08.2026 |
8.1 |
| CVE-2026-7693 |
Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter |
05.08.2026 |
7.2 |
| CVE-2026-7726 |
Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action |
05.08.2026 |
6.5 |
| CVE-2025-15677 |
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories |
05.08.2026 |
|
| CVE-2026-14553 |
Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload |
05.08.2026 |
|
| CVE-2026-15210 |
Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force |
05.08.2026 |
|
| CVE-2026-15230 |
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure |
05.08.2026 |
|
| CVE-2026-15360 |
Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args |
05.08.2026 |
|
| CVE-2026-15372 |
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider |
05.08.2026 |
|
| CVE-2026-16036 |
miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding |
05.08.2026 |
|
| CVE-2026-16055 |
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login |
05.08.2026 |
|
| CVE-2026-16561 |
Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure |
05.08.2026 |
|
| CVE-2026-16573 |
Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload |
05.08.2026 |
|
| CVE-2026-16583 |
Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload |
05.08.2026 |
|
| CVE-2026-16602 |
Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint |
05.08.2026 |
|
| CVE-2026-16603 |
Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API |
05.08.2026 |
|
| CVE-2026-16604 |
Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute |
05.08.2026 |
|
| CVE-2026-16605 |
MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization |
05.08.2026 |
|
| CVE-2026-16613 |
GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF |
05.08.2026 |
|
| CVE-2026-16736 |
User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled |
05.08.2026 |
|
| CVE-2026-16746 |
MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint |
05.08.2026 |
|
| CVE-2026-16940 |
Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal |
05.08.2026 |
|
| CVE-2026-16942 |
WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS |
05.08.2026 |
|
| CVE-2026-16968 |
GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users |
05.08.2026 |
|
| CVE-2026-16981 |
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR |
05.08.2026 |
|
| CVE-2026-16993 |
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory |
05.08.2026 |
|
| CVE-2026-17515 |
MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item |
05.08.2026 |
|
| CVE-2026-49004 |
PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product |
05.08.2026 |
6.5 |
| CVE-2026-66274 |
Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow |
05.08.2026 |
|
| CVE-2026-66275 |
Apache Qpid Proton-J: Incoming session flow control window can be exceeded |
05.08.2026 |
|
| CVE-2026-66276 |
Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service |
05.08.2026 |
|
| CVE-2026-66277 |
Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery |
05.08.2026 |
|
| CVE-2026-67552 |
Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow |
05.08.2026 |
|
| CVE-2026-67553 |
Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded |
05.08.2026 |
|
| CVE-2026-67554 |
Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service |
05.08.2026 |
|
| CVE-2026-67555 |
Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery |
05.08.2026 |
|
| CVE-2026-67590 |
Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow |
05.08.2026 |
|
| CVE-2026-67591 |
Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded |
05.08.2026 |
|
| CVE-2026-67592 |
Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery |
05.08.2026 |
|
| CVE-2026-68073 |
Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow |
05.08.2026 |
|
| CVE-2026-68075 |
Apache Qpid Broker-J: Incoming session flow control window can be exceeded |
05.08.2026 |
|
| CVE-2026-68077 |
Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service |
05.08.2026 |
|
| CVE-2026-68078 |
Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery |
05.08.2026 |
|
| CVE-2026-68080 |
Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service |
05.08.2026 |
|
| CVE-2026-70374 |
HashBrown CMS: OS Command Injection in Media Upload Thumbnail Generation |
05.08.2026 |
8.8 |
| CVE-2026-70375 |
HashBrown CMS: OS Command Injection via Git Deployer Branch Field |
05.08.2026 |
8.8 |
| CVE-2026-71201 |
|
05.08.2026 |
5 |
| CVE-2026-11421 |
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17.4 - Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter |
05.08.2026 |
6.5 |
| CVE-2026-15918 |
VikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection |
05.08.2026 |
7.5 |
| CVE-2026-15941 |
Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection |
05.08.2026 |
6.5 |
| CVE-2026-16143 |
VikRentItems Flexible Rental Management System <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting |
05.08.2026 |
7.2 |
| CVE-2026-18322 |
Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator |
05.08.2026 |
8.8 |
| CVE-2026-18902 |
H3C NX15 esps repeaterproc command injection |
05.08.2026 |
|
| CVE-2026-18903 |
yeqifu warehouse FileController.java path traversal |
05.08.2026 |
|
| CVE-2026-55707 |
|
05.08.2026 |
|
| CVE-2026-5062 |
PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter |
05.08.2026 |
4.9 |
| CVE-2026-66257 |
Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion |
05.08.2026 |
|
| CVE-2026-66273 |
Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication |
05.08.2026 |
|
| CVE-2026-66344 |
|
05.08.2026 |
|
| CVE-2026-66839 |
|
05.08.2026 |
|
| CVE-2026-67465 |
Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion |
05.08.2026 |
|
| CVE-2026-67551 |
Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication |
05.08.2026 |
|
| CVE-2026-67588 |
Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion |
05.08.2026 |
|
| CVE-2026-67589 |
Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication |
05.08.2026 |
|
| CVE-2026-68060 |
Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication |
05.08.2026 |
|
| CVE-2026-68074 |
Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion |
05.08.2026 |
|
| CVE-2026-71190 |
|
05.08.2026 |
|
| CVE-2026-71191 |
|
05.08.2026 |
|
| CVE-2026-71192 |
|
05.08.2026 |
|
| CVE-2026-7753 |
Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure |
05.08.2026 |
6.5 |
| CVE-2026-8761 |
Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege Escalation |
05.08.2026 |
8.8 |
| CVE-2026-8790 |
Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Scripting |
05.08.2026 |
6.1 |
| CVE-2026-9273 |
Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover |
05.08.2026 |
9.3 |
| CVE-2026-18900 |
H3C NX15 Backend RPC esps file.exec os command injection |
05.08.2026 |
|
| CVE-2026-18901 |
H3C NX15 Web API esps service.add routine |
05.08.2026 |
|
| CVE-2026-18898 |
UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow |
05.08.2026 |
|
| CVE-2026-18895 |
UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow |
05.08.2026 |
|
| CVE-2026-18896 |
lavkush-maurya Student-Registration-System changepass.php sql injection |
05.08.2026 |
|
| CVE-2026-18897 |
UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow |
05.08.2026 |
|
| CVE-2026-18907 |
PathTravelsal Vulnerability in com.talpa.hibrowser |
05.08.2026 |
|
| CVE-2026-18856 |
Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery |
05.08.2026 |
|
| CVE-2026-18859 |
ESAFENET CDG usbkey;logindojojs sql injection |
05.08.2026 |
|
| CVE-2026-18853 |
ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal |
05.08.2026 |
|
| CVE-2026-18854 |
Shandong Hoteam PDM Product Data Management System DataService GetStoredClassByFilter sql injection |
05.08.2026 |
|
| CVE-2026-46334 |
OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning |
05.08.2026 |
|
| CVE-2026-45809 |
OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI |
05.08.2026 |
|
| CVE-2026-18103 |
Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapi |
05.08.2026 |
|
| CVE-2026-18852 |
epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition |
05.08.2026 |
|
| CVE-2026-45705 |
OpenSIPS: OOB Read in Multipart Body Boundary Parsing |
05.08.2026 |
5.3 |
| CVE-2026-18819 |
RackTables cross-site request forgery |
05.08.2026 |
|
| CVE-2026-45537 |
OpenSIPS: Global Buffer Overflow in construct_uri |
04.08.2026 |
9.1 |
| CVE-2026-18818 |
Ehco1996 django-sspanel Support Ticket views.py TicketDetailView authorization |
04.08.2026 |
|
| CVE-2026-18816 |
Baserow 2FA Verify Endpoint views.py verify improper authentication |
05.08.2026 |
|
| CVE-2026-18817 |
Baserow Inactive Non-Staff User serializers.py BaserowImpersonateAuthTokenSerializer improper authorization |
05.08.2026 |
|
| CVE-2026-45100 |
OpenSIPS: Buffer Overflow in Base64 Encode Transformation |
05.08.2026 |
9.1 |
| CVE-2026-45103 |
OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow |
04.08.2026 |
7.5 |
| CVE-2026-67859 |
|
05.08.2026 |
7.5 |
| CVE-2026-67860 |
|
04.08.2026 |
|
| CVE-2026-67862 |
|
04.08.2026 |
|
| CVE-2026-70591 |
Ghost: Server-Side Request Forgery in Image Fetching |
05.08.2026 |
4.1 |
| CVE-2026-70592 |
Ghost: Database Backup Path Traversal |
05.08.2026 |
5.5 |
| CVE-2026-70593 |
Ghost: Theme Upload Path Traversal |
05.08.2026 |
6.6 |
| CVE-2026-70594 |
Ghost: Session Fixation in Ghost Admin |
05.08.2026 |
6.7 |
| CVE-2026-18814 |
H3C NX15 esps reload.reload_config command injection |
05.08.2026 |
|
| CVE-2026-45084 |
OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state |
05.08.2026 |
|
| CVE-2026-51144 |
|
05.08.2026 |
|
| CVE-2026-52370 |
|
04.08.2026 |
|
| CVE-2026-67855 |
|
04.08.2026 |
|
| CVE-2026-67856 |
|
04.08.2026 |
|
| CVE-2026-67857 |
|
05.08.2026 |
7.5 |
| CVE-2026-67858 |
|
05.08.2026 |
7.5 |
| CVE-2026-67861 |
|
05.08.2026 |
7.5 |
| CVE-2026-70589 |
Ghost: Archived Offers can be Redeemed |
05.08.2026 |
4.8 |
| CVE-2026-70590 |
Ghost: Blind Password Hash Disclosure in Ghost Admin API |
05.08.2026 |
4.8 |
| CVE-2026-70619 |
Odysseus Missing Admin Authorization via Embedding Endpoint Routes |
05.08.2026 |
|
| CVE-2026-70620 |
Odysseus SSRF via Embedding Endpoint Configuration |
05.08.2026 |
|
| CVE-2026-13227 |
ERPNext v16.25.0 - Improper authorization in Prospect opportunities API |
05.08.2026 |
|
| CVE-2026-18813 |
H3C NX15 esps delete command injection |
05.08.2026 |
|
| CVE-2026-45538 |
OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
05.08.2026 |
9.8 |
| CVE-2026-51400 |
|
04.08.2026 |
|
| CVE-2026-51401 |
|
04.08.2026 |
|
| CVE-2026-66901 |
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON |
04.08.2026 |
|
| CVE-2026-66902 |
Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call |
04.08.2026 |
|
| CVE-2026-67979 |
|
04.08.2026 |
|
| CVE-2026-70489 |
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing |
05.08.2026 |
6.5 |
| CVE-2026-70490 |
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check |
04.08.2026 |
6.3 |
| CVE-2026-70491 |
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints |
05.08.2026 |
6.5 |
| CVE-2026-70492 |
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages |
05.08.2026 |
8.7 |
| CVE-2026-70493 |
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically |
05.08.2026 |
6.5 |
| CVE-2026-70494 |
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder |
05.08.2026 |
8.1 |
| CVE-2026-70588 |
Ghost: Cross-Site Scripting in Universal Import |
04.08.2026 |
5 |
| CVE-2026-18811 |
H3C NX15 esps add command injection |
05.08.2026 |
|
| CVE-2026-18812 |
H3C NX15 esps esps.ipv6.wan command injection |
04.08.2026 |
|
| CVE-2026-54020 |
Open WebUI: DNS Rebinding SSRF Bypass |
05.08.2026 |
6.3 |
| CVE-2026-65986 |
CVAT has stored XSS via annotation guide assets |
04.08.2026 |
|
| CVE-2026-70487 |
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata |
05.08.2026 |
5.3 |
| CVE-2026-70488 |
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup |
05.08.2026 |
4.3 |
| CVE-2026-70554 |
MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie |
05.08.2026 |
|