CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution 21.07.2026 9.8
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) 21.07.2026 9.9
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default 21.07.2026 9.8
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset 21.07.2026 9.8
CVE-2026-64824 Home Assistant Core < 2026.6.0 Symlink Path Traversal RCE via backup-restore 21.07.2026 9.3
CVE-2026-64825 Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload 21.07.2026 9
CVE-2026-65048 Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index 21.07.2026 9.3
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData 21.07.2026 9.3
CVE-2026-1617 SQLi in Turkmesh's Turkhotspot 5651 Loglama 21.07.2026 9.8
CVE-2026-13439 Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint 21.07.2026 9.8
CVE-2026-64625 AVideo before 29.0 OS Command Injection via execAsync 20.07.2026 9.3
CVE-2026-13380 VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses 20.07.2026 9
CVE-2026-53595 FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL 21.07.2026 9.4
CVE-2026-16337 21.07.2026 9.4
CVE-2026-44231 RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint 21.07.2026 9.1
CVE-2026-63766 GPT-SoVITS 20250606v2pro OS Command Injection via webui.py 21.07.2026 9.3
CVE-2026-63767 ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ 21.07.2026 9.3
CVE-2026-61424 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 21.07.2026 10
CVE-2026-61425 Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 21.07.2026 9.4
CVE-2026-61900 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 20.07.2026 10
CVE-2026-60032 Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 21.07.2026 9.4
CVE-2026-60034 Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 21.07.2026 9.4
CVE-2026-39878 Chamilo stored XSS via user registration leads to admin account takeover 20.07.2026 9.3
CVE-2026-35048 Piwigo RCE via PHP Code Injection into Config File in Installer 20.07.2026 9.8
CVE-2026-41252 xrdp: lib_palette_update Heap Buffer Overflow & RCE 20.07.2026 9.8
CVE-2026-54051 Network-AI has an an OS Command Injection issue 20.07.2026 9.9
CVE-2026-35198 HeyForm vulnerable to stored XSS via form field titles 20.07.2026 9
CVE-2026-46428 lettre has TLS hostname verification disabled when using Boring TLS backend 21.07.2026 9.1
CVE-2026-51027 20.07.2026 9.9
CVE-2026-46412 Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm 20.07.2026 10
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport 21.07.2026 9
CVE-2026-57309 Blind SQL Injection in Windu CMS 20.07.2026 9.3
CVE-2026-63756 SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition 21.07.2026 9.2
CVE-2026-64620 FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common 21.07.2026 9.3
CVE-2026-64621 FreeRDP before 3.28.0 Double-Free via selectedmonitors 21.07.2026 9.3
CVE-2026-64622 Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox 21.07.2026 9.3
CVE-2026-16242 Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates 21.07.2026 9.4
CVE-2026-44359 Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow 20.07.2026 10
CVE-2026-64035 igc: set tx buffer type for SMD frames 20.07.2026 9.8
CVE-2026-64037 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled 20.07.2026 9.8
CVE-2026-64046 net: tls: prevent chain-after-chain in plain text SG 20.07.2026 9.8
CVE-2026-64047 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring 20.07.2026 9.8
CVE-2026-64055 net: ethernet: cortina: Carry over frag counter 20.07.2026 9.8
CVE-2026-64056 net: ethernet: cortina: Make RX SKB per-port 20.07.2026 9.8
CVE-2026-64061 netfs: Fix early put of sink folio in netfs_read_gaps() 20.07.2026 9.8
CVE-2026-64066 netfs: Fix netfs_read_to_pagecache() to pause on subreq failure 20.07.2026 9.8
CVE-2026-64067 netfs: Fix missing barriers when accessing stream->subrequests locklessly 20.07.2026 9.8
CVE-2026-64068 netfs: Fix missing locking around retry adding new subreqs 20.07.2026 9.8
CVE-2026-64069 netfs: Fix cancellation of a DIO and single read subrequests 20.07.2026 9.8
CVE-2026-64080 firmware: arm_ffa: Snapshot notifier callbacks under lock 20.07.2026 9.3
CVE-2026-64089 batman-adv: tt: fix negative last_changeset_len 20.07.2026 9.8
CVE-2026-64091 batman-adv: tt: fix TOCTOU race for reported vlans 20.07.2026 9.8
CVE-2026-64102 RDMA/siw: Reject MPA FPDU length underflow before signed receive math 20.07.2026 9.8
CVE-2026-64106 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits 20.07.2026 9
CVE-2026-64113 ixgbevf: fix use-after-free in VEPA multicast source pruning 20.07.2026 9.8
CVE-2026-64122 net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover 20.07.2026 9.8
CVE-2026-64125 net: bcmgenet: keep RBUF EEE/PM disabled 20.07.2026 9.8
CVE-2026-64132 ipv6: ioam: refresh hdr pointer before ioam6_event() 20.07.2026 9.8
CVE-2026-64136 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() 20.07.2026 9.8
CVE-2026-64142 ksmbd: close durable scavenger races against m_fp_list lookups 20.07.2026 9.8
CVE-2026-64150 netfilter: nft_inner: release local_lock before re-enabling softirqs 20.07.2026 9.8
CVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_point 20.07.2026 9.8
CVE-2026-64162 idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() 20.07.2026 9.8
CVE-2026-64016 ksmbd: fix durable reconnect error path file lifetime 20.07.2026 9.8
CVE-2026-64018 net: mana: validate rx_req_idx to prevent out-of-bounds array access 20.07.2026 9.3
CVE-2026-64024 tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction 20.07.2026 9.4
CVE-2026-64025 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx 20.07.2026 9.8
CVE-2026-64033 RDMA/rtrs: Fix use-after-free in path file creation cleanup 20.07.2026 9.8
CVE-2026-64034 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer 20.07.2026 9.3
CVE-2026-63886 scsi: target: iscsi: Validate CHAP_R length before base64 decode 20.07.2026 9.8
CVE-2026-63887 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf 20.07.2026 9.8
CVE-2026-63888 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() 20.07.2026 9.8
CVE-2026-63912 xfrm: esp: restore combined single-frag length gate 20.07.2026 9.8
CVE-2026-63922 ipv6: exthdrs: refresh nh after handling HAO option 20.07.2026 9.8
CVE-2026-63924 ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() 20.07.2026 9.8
CVE-2026-63938 KVM: SEV: Check PSC request indices against the actual size of the buffer 20.07.2026 9.3
CVE-2026-63939 KVM: SEV: Compute the correct max length of the in-GHCB scratch area 20.07.2026 9.3
CVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0' 20.07.2026 9.3
CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit 20.07.2026 9.8
CVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doit 20.07.2026 9.8
CVE-2026-63984 ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() 20.07.2026 9.8
CVE-2026-63992 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() 20.07.2026 9.1
CVE-2026-63993 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() 20.07.2026 9.8
CVE-2026-63994 tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() 20.07.2026 9.8
CVE-2026-64000 net: hsr: fix potential OOB access in supervision frame handling 20.07.2026 9.8
CVE-2026-64007 netfilter: synproxy: refresh tcphdr after skb_ensure_writable 20.07.2026 9.8
CVE-2026-63857 net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() 20.07.2026 9.8
CVE-2026-53384 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails 20.07.2026 9.8
CVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanup 20.07.2026 9.8
CVE-2026-53399 nfsd: release layout stid on setlease failure 20.07.2026 9.8
CVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error path 20.07.2026 10
CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout() 20.07.2026 9.8
CVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry() 20.07.2026 9.8
CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes 20.07.2026 9.8
CVE-2026-63830 net: skmsg: preserve sg.copy across SG transforms 20.07.2026 9.4
CVE-2026-9323 Insecure PRNG and Information Exposure in urwid Web Display Backend 20.07.2026 9.2
CVE-2024-58366 SurrealDB before 1.1.1 Format String via Scripting Functions 20.07.2026 9
CVE-2025-71392 SurrealDB before 2.2.2 SurrealQL Injection via export 21.07.2026 9.4
CVE-2026-16117 @fastify/http-proxy vulnerable to prefix escape via URL-encoded characters 20.07.2026 10
CVE-2026-47865 VMware Avi Load Balancer Authentication Bypass Vulnerability 20.07.2026 9.8
CVE-2026-13446 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints 21.07.2026 9.8
CVE-2026-48062 CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule 20.07.2026 9.8
CVE-2026-54159 ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE 20.07.2026 10
CVE-2026-54466 websocket-driver: Message corruption via abuse of protocol length headers 20.07.2026 9.2
CVE-2026-55518 Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation 20.07.2026 9.6
CVE-2026-15091 Multiple Vulnerabilities in IBM Engineering AI hub. 20.07.2026 9.3
CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution 21.07.2026 9.8
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability 20.07.2026 9.9
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint 17.07.2026 9.9
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution 17.07.2026 9.8
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component 21.07.2026 9.9
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header 20.07.2026 9.9
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint 20.07.2026 9.8
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation 20.07.2026 9.9
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation 18.07.2026 9.8
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution 18.07.2026 9.8
CVE-2026-12693 IDOR in Vimesoft's Enterprise Video Platform 17.07.2026 9.4
CVE-2026-12694 Missing Authorization in Vimesoft's Enterprise Video Platform 17.07.2026 9.1
CVE-2026-54496 Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness 17.07.2026 9.3
CVE-2026-12692 Improper Authentication in Vimesoft's Enterprise Video Platform 17.07.2026 9.8
CVE-2026-8297 SQLi in GIS Informatics' GisLab Laboratory Management System 17.07.2026 9.8
CVE-2026-9586 Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB 17.07.2026 9.3
CVE-2024-23564 17.07.2026 9.1
CVE-2026-15982 Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function' 17.07.2026 9.8
CVE-2026-14956 Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter 21.07.2026 9.8
CVE-2026-62232 Grav < 2.0.4 2FA Bypass via Secret Regeneration 17.07.2026 9.1
CVE-2026-62241 clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery 17.07.2026 9.3
CVE-2026-44181 Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution 17.07.2026 10
CVE-2026-44182 Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering 17.07.2026 10
CVE-2026-44180 Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed 17.07.2026 9.8
CVE-2026-53412 Zoom Workplace VDI Plugin for Windows - Improper Input Validation 17.07.2026 9.8
CVE-2026-15422 SCTP needs to better-check INIT ACK chunk parameters 17.07.2026 9.1
CVE-2026-63089 WireGuard Easy Weak Token Generation Information Disclosure via OTL Route 18.07.2026 9
CVE-2026-46512 Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping 18.07.2026 9.9
CVE-2026-46515 Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution 16.07.2026 9.3
CVE-2026-45336 HireFlow: Use of Hard-coded Credentials 17.07.2026 10
CVE-2026-45568 zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths 17.07.2026 9.9
CVE-2026-44632 Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` 16.07.2026 9.1
CVE-2026-46562 Yamcs: Remote Code Execution via Mission Database algorithm override 16.07.2026 9.8
CVE-2026-46621 Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection 16.07.2026 9.1
CVE-2026-63087 Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint 17.07.2026 9.3
CVE-2026-45695 Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used 16.07.2026 9.8
CVE-2026-54733 moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint 16.07.2026 9.3
CVE-2026-59864 Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions 17.07.2026 9.3
CVE-2026-59865 Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` 17.07.2026 9.3
CVE-2026-59866 Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName 17.07.2026 9.3
CVE-2026-11386 ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution 16.07.2026 9
CVE-2026-63304 AVideo through 29.0 OS Command Injection via listFFmpegProcesses 20.07.2026 9.2
CVE-2026-63305 AVideo through 29.0 OS Command Injection via ffmpeg.json.php 20.07.2026 9.2
CVE-2026-63306 stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints 16.07.2026 9.2
CVE-2023-49899 Origin Validation Error in X-Rite MA-T6 18.07.2026 9.8
CVE-2023-49900 Origin Validation Error in X-Rite MA-T6 16.07.2026 9.8
CVE-2026-22752 Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata 21.07.2026 9.6
CVE-2026-15925 Improper TLS Hostname Verification in Snowflake Connector for Python 16.07.2026 9.2
CVE-2026-15013 SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion 16.07.2026 9.8
CVE-2026-54458 AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin 16.07.2026 9.6
CVE-2026-55445 Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication 18.07.2026 9.3
CVE-2026-52891 Wekan: Shell Injection via Avatar Upload 17.07.2026 9.9
CVE-2026-52893 Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook 18.07.2026 9.2
CVE-2026-55652 Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin) 17.07.2026 9.8
CVE-2026-46339 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes 16.07.2026 10
CVE-2026-49352 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass 16.07.2026 9.8
CVE-2026-54052 n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments 18.07.2026 9.9
CVE-2026-52887 NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE 20.07.2026 10
CVE-2026-45534 DataEase: RCE Vulnerability 16.07.2026 9
CVE-2026-46684 DataEase: Unauthorized Command Execution Vulnerability 17.07.2026 9.5
CVE-2026-49445 Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access 16.07.2026 9.2
CVE-2026-46421 Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) 15.07.2026 9.3
CVE-2026-62948 OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI 15.07.2026 9.6
CVE-2026-50562 FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows 15.07.2026 9.3
CVE-2026-53512 Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins 18.07.2026 9.1
CVE-2026-53513 Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration 15.07.2026 9.6
CVE-2026-62378 RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover 16.07.2026 9
CVE-2026-52842 Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass 15.07.2026 9.3
CVE-2026-52843 Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode 15.07.2026 9.3
CVE-2026-44986 Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile 15.07.2026 9.9
CVE-2026-50148 Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write 20.07.2026 10
CVE-2026-42533 NGINX Map directive and Regex matching vulnerability 16.07.2026 9.2
CVE-2026-61736 LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests 15.07.2026 9.3
CVE-2026-61740 LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection 15.07.2026 9.3
CVE-2026-56400 open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation 15.07.2026 9
CVE-2026-56699 Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index 15.07.2026 10
CVE-2026-61451 Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url 15.07.2026 9.4
CVE-2026-13385 16.07.2026 9.5
CVE-2026-45363 `jwt` (Ruby gem) - empty-key HMAC bypass 15.07.2026 9.1
CVE-2026-48334 Illustrator | Improper Input Validation (CWE-20) 15.07.2026 9.3
CVE-2026-48284 ColdFusion | Improper Input Validation (CWE-20) 15.07.2026 9.6
CVE-2026-48318 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 15.07.2026 9.9
CVE-2026-48319 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 15.07.2026 9.1
CVE-2026-48321 ColdFusion | Incorrect Authorization (CWE-863) 16.07.2026 9.3
CVE-2026-48322 ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94) 15.07.2026 9.6
CVE-2026-48324 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 15.07.2026 9.1
CVE-2026-48325 ColdFusion | Missing Authentication for Critical Function (CWE-306) 15.07.2026 9.3
CVE-2026-48327 ColdFusion | Incorrect Authorization (CWE-863) 15.07.2026 9
CVE-2026-15643 AWS HealthLake MCP Server SSRF via Pagination URL 15.07.2026 9.2
CVE-2026-53486 decompress: Archive extraction can create files and links outside the target directory 15.07.2026 9.1

Latest Updates

CVE Title Updated Score
CVE-2026-16450 zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization 21.07.2026
CVE-2026-28302 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability 21.07.2026 9.1
CVE-2026-28304 SolarWinds Serv-U Remote Code Execution Vulnerability 21.07.2026 9.1
CVE-2026-28305 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability 21.07.2026 9.1
CVE-2026-28306 SolarWinds Serv-U Privilege Escalation Vulnerability 21.07.2026 9.1
CVE-2026-28307 SolarWinds Serv-U Privilege Escalation Vulnerability 21.07.2026 9.1
CVE-2026-28308 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability 21.07.2026 9.1
CVE-2026-28309 SolarWinds Serv-U Broken Access Control Vulnerability 21.07.2026 9.1
CVE-2026-28310 SolarWinds Serv-U Privilege Escalation Vulnerability 21.07.2026 9.1
CVE-2026-28312 SolarWinds Serv-U Privilege Escalation Vulnerability 21.07.2026 9.1
CVE-2026-28313 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability 21.07.2026 9.1
CVE-2026-28314 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability 21.07.2026 9.1
CVE-2026-28315 SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability 21.07.2026 6.2
CVE-2026-28316 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability 21.07.2026 9.1
CVE-2026-28317 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability 21.07.2026 9.1
CVE-2026-28321 SolarWinds Serv-U Broken Access Control Vulnerability 21.07.2026 9.1
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution 21.07.2026 9.8
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) 21.07.2026 9.9
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default 21.07.2026 9.8
CVE-2026-47394 PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate 21.07.2026
CVE-2026-47395 PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context 21.07.2026 5.5
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset 21.07.2026 9.8
CVE-2026-64824 Home Assistant Core < 2026.6.0 Symlink Path Traversal RCE via backup-restore 21.07.2026
CVE-2026-64825 Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload 21.07.2026
CVE-2026-16449 zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection 21.07.2026
CVE-2026-47390 PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings 21.07.2026 5.5
CVE-2026-56585 HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing 21.07.2026 3.1
CVE-2026-56586 HCL IEM was affected with X-Content-Type-Options Header Missing 21.07.2026 3.1
CVE-2026-64823 Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI 21.07.2026
CVE-2024-5300 AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd 21.07.2026 5.6
CVE-2026-11876 Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml 21.07.2026
CVE-2026-15226 snapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp Templates 21.07.2026 8.4
CVE-2026-16448 D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection 21.07.2026
CVE-2026-46681 @nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty 21.07.2026
CVE-2026-47122 Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection 21.07.2026 4.2
CVE-2026-56584 HCL IEM was affected with the Information disclosure nginx server 21.07.2026 3.7
CVE-2026-56587 HCL IEM was affected with Strict transport security not enforced 21.07.2026 3.7
CVE-2026-59849 Libssh: libssh: denial of service via automatic certificate authentication loop 21.07.2026
CVE-2026-59850 Libssh: libssh: use-after-free via data callbacks on closed channels 21.07.2026
CVE-2026-59851 Libssh: libssh: authentication bypass via missing gssapi principal check 21.07.2026
CVE-2026-65048 Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index 21.07.2026
CVE-2026-65049 Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_all_data AJAX Action 21.07.2026
CVE-2026-65050 Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Submissions to Unauthenticated Visitors 21.07.2026
CVE-2026-65051 Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in AJAX Submission Handler 21.07.2026
CVE-2026-65052 Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields 21.07.2026
CVE-2026-8933 snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Execution Environment Setup 21.07.2026 7.8
CVE-2025-66390 21.07.2026
CVE-2026-16447 D-Link DNS-320 multi_uploadify.php unrestricted upload 21.07.2026
CVE-2026-47121 Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta 21.07.2026 6.1
CVE-2026-59847 Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification 21.07.2026
CVE-2026-59848 Libssh: libssh: denial of service via sftp responses with unknown request ids 21.07.2026
CVE-2026-9499 Out-of-bounds read in QTextCodec::codecForName() in Qt 21.07.2026
CVE-2026-16445 Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module 21.07.2026
CVE-2026-59846 Libssh: libssh: information disclosure via proxycommand %r username expansion 21.07.2026
CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component 21.07.2026
CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component 21.07.2026
CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component 21.07.2026
CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component 21.07.2026
CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component 21.07.2026
CVE-2026-16354 Information disclosure in the Graphics: ImageLib component 21.07.2026
CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component 21.07.2026
CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component 21.07.2026
CVE-2026-16357 Incorrect boundary conditions in the Graphics component 21.07.2026
CVE-2026-16358 Site isolation issue in the Graphics: WebRender component 21.07.2026
CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component 21.07.2026
CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 21.07.2026
CVE-2026-16361 Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 21.07.2026
CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component 21.07.2026
CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component 21.07.2026
CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component 21.07.2026
CVE-2026-16365 Privilege escalation in the DOM: Workers component 21.07.2026
CVE-2026-16366 Privilege escalation in the DOM: Navigation component 21.07.2026
CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component 21.07.2026
CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component 21.07.2026
CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component 21.07.2026
CVE-2026-16370 Mitigation bypass in the DOM: Networking component 21.07.2026
CVE-2026-16371 Privilege escalation in the DOM: Navigation component 21.07.2026
CVE-2026-16372 Privilege escalation in the DOM: Content Processes component 21.07.2026
CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android 21.07.2026
CVE-2026-16374 Information disclosure in the Framework component in DevTools 21.07.2026
CVE-2026-16375 Site isolation issue in the Networking: HTTP component 21.07.2026
CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component 21.07.2026
CVE-2026-16377 Mitigation bypass in the PDF Viewer component 21.07.2026
CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component 21.07.2026
CVE-2026-16379 Privilege escalation in the DOM: Content Processes component 21.07.2026
CVE-2026-16380 Mitigation bypass in the Networking component 21.07.2026
CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component 21.07.2026
CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component 21.07.2026
CVE-2026-16383 Mitigation bypass in the DOM: Networking component 21.07.2026
CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component 21.07.2026
CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component 21.07.2026
CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component 21.07.2026
CVE-2026-16387 Site isolation issue in the Networking component 21.07.2026
CVE-2026-16388 Sandbox escape in the DOM: Networking component 21.07.2026
CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS 21.07.2026
CVE-2026-16390 Mitigation bypass in the Enterprise Policies component 21.07.2026
CVE-2026-16391 Information disclosure in the Storage: IndexedDB component 21.07.2026
CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component 21.07.2026
CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component 21.07.2026
CVE-2026-16394 Mitigation bypass in the DOM: Security component 21.07.2026
CVE-2026-16395 Integer overflow in the Audio/Video component 21.07.2026
CVE-2026-16396 Privilege escalation in WebExtensions 21.07.2026
CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android 21.07.2026
CVE-2026-16398 Site isolation issue in the Graphics component 21.07.2026
CVE-2026-16399 Site isolation issue in the DOM: Navigation component 21.07.2026
CVE-2026-16400 Information disclosure in the DOM: Security component 21.07.2026
CVE-2026-16401 Privilege escalation in the Data Loss Prevention component 21.07.2026
CVE-2026-16402 Integer overflow in the Graphics: ImageLib component 21.07.2026
CVE-2026-16403 Spoofing issue in the Address Bar component 21.07.2026
CVE-2026-16404 Spoofing issue in Firefox for Android 21.07.2026
CVE-2026-16405 Information disclosure in the Networking: WebSockets component 21.07.2026
CVE-2026-16406 Mitigation bypass in the Networking component 21.07.2026
CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component 21.07.2026
CVE-2026-16408 Integer overflow in the Audio/Video: Playback component 21.07.2026
CVE-2026-16409 Invalid pointer in the Security: PSM component 21.07.2026
CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component 21.07.2026
CVE-2026-16411 Memory safety bugs fixed in Firefox 153 21.07.2026
CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 21.07.2026
CVE-2026-6792 Improper Authorization in Universal Sotware's FlexCity 21.07.2026 6.5
CVE-2026-8284 Open Redirect in Universal Sotware's FlexCity 21.07.2026 6.1
CVE-2026-8285 OTP Bypass in Universal Sotware's FlexCity 21.07.2026 4.3
CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting 21.07.2026
CVE-2026-59844 Libssh: libssh: denial of service via oversized sftp read length 21.07.2026
CVE-2026-64627 Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion 21.07.2026
CVE-2026-64628 Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers 21.07.2026
CVE-2026-65007 Grav before 1.0.8 Missing Authorization on API Key Generation 21.07.2026
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData 21.07.2026
CVE-2026-65009 OpenRemote before 1.26.2 Information Disclosure via Syslog REST API 21.07.2026
CVE-2026-1617 SQLi in Turkmesh's Turkhotspot 5651 Loglama 21.07.2026 9.8
CVE-2026-59842 Libssh: libssh: information disclosure via short gssapi curve25519 public key 21.07.2026
CVE-2026-59843 Libssh: libssh: denial of service via zero advertised channel packet size 21.07.2026
CVE-2026-59845 Libssh: libssh: denial of service via unchecked proxycommand fork() failure 21.07.2026
CVE-2026-60080 Apache Fory: Rust MetaString heap use-after-free 21.07.2026
CVE-2026-64606 Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface 21.07.2026
CVE-2026-62415 Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 21.07.2026
CVE-2026-64608 Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths 21.07.2026
CVE-2026-64609 Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization 21.07.2026
CVE-2026-15370 Libssh: libssh: stack buffer overflow in sftp server longname construction 21.07.2026
CVE-2026-15145 Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget 21.07.2026 6.4
CVE-2026-1372 Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation 21.07.2026 4.3
CVE-2026-1771 MapSVG <= 8.14.0 - Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint 21.07.2026 7.2
CVE-2026-3183 Multi Factor Auth Bypass 21.07.2026 7.1
CVE-2026-8593 Fix Business Intelligence API Pack permission 21.07.2026
CVE-2026-11767 CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form 21.07.2026
CVE-2026-13693 Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal 21.07.2026
CVE-2026-13694 Bit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication Bypass 21.07.2026
CVE-2026-14183 Classified Listing < 5.3.9 - Subscriber+ Payment Receipt Disclosure via IDOR 21.07.2026
CVE-2026-14184 Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR 21.07.2026
CVE-2026-14185 WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update 21.07.2026
CVE-2026-8082 Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection 21.07.2026
CVE-2023-37507 An information disclosure vulnerability affects HCL DevOps Plan 21.07.2026
CVE-2026-13439 Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint 21.07.2026 9.8
CVE-2026-15782 WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content 21.07.2026 4.9
CVE-2026-15811 Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes 21.07.2026
CVE-2026-15812 Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links 21.07.2026
CVE-2026-15927 Quay: mirror-registry: ssrf: repo-level mirror accepts external_reference without url validation 21.07.2026
CVE-2026-16266 21.07.2026 4
CVE-2026-3182 Sensitive Data Exposure 21.07.2026 4.3
CVE-2023-37508 HCL DevOps Plan is susceptible to a Cross-Site Scripting (XSS) vulnerability 21.07.2026
CVE-2026-15156 Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings 21.07.2026 6.4
CVE-2026-16336 trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect 21.07.2026
CVE-2026-59776 21.07.2026
CVE-2026-16332 D-Link DNS-320 multi_uploadify.php unrestricted upload 21.07.2026
CVE-2026-16334 itsourcecode Hospital Management System prescriptionorder.php sql injection 21.07.2026
CVE-2026-63729 TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File 21.07.2026
CVE-2026-6952 21.07.2026 7.2
CVE-2026-16329 D-Link DNS-320 uploadify.php unrestricted upload 21.07.2026
CVE-2026-16330 D-Link DNS-320 uploadify.php unrestricted upload 21.07.2026
CVE-2026-16331 D-Link DNS-320 save_ajax.php unrestricted upload 21.07.2026
CVE-2026-16327 D-Link DNS-320 upload.php unrestricted upload 21.07.2026
CVE-2026-63728 Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature 20.07.2026
CVE-2026-55831 Netty SPDY SETTINGS frame count materializes unbounded settings map 20.07.2026 7.5
CVE-2026-55833 Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation 21.07.2026 7.5
CVE-2026-15899 20.07.2026
CVE-2026-15900 20.07.2026
CVE-2026-15901 20.07.2026
CVE-2026-15902 20.07.2026
CVE-2026-15903 20.07.2026
CVE-2026-15904 20.07.2026
CVE-2026-15905 21.07.2026
CVE-2026-47144 Shamefile has an arbitrary file read via shamefile.yaml in shame next 20.07.2026 5.5
CVE-2026-47255 AgenticMail API/storage and outbound relay hardening 21.07.2026 8.2
CVE-2026-57494 AgenticMail: Cross-agent task authorization bypass in AgenticMail API 21.07.2026
CVE-2026-57495 AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake) 20.07.2026
CVE-2026-57852 Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check 21.07.2026 5.6
CVE-2026-64624 FreeRDP RDP File Parser Remote Code Execution via CLI Options 20.07.2026
CVE-2026-64625 AVideo before 29.0 OS Command Injection via execAsync 20.07.2026
CVE-2026-64626 AVideo Encoder downloadURL SSRF via unpinned retry fallback 20.07.2026
CVE-2026-12900 Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block 20.07.2026 6.4
CVE-2026-16324 Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload 20.07.2026
CVE-2026-47128 nono: Sandbox escape on Linux via D-Bus: `systemd-run --user` 21.07.2026 6.1
CVE-2026-51025 21.07.2026
CVE-2026-51031 21.07.2026
CVE-2026-51385 21.07.2026 6.9
CVE-2026-52656 21.07.2026
CVE-2024-51312 21.07.2026
CVE-2024-51314 21.07.2026
CVE-2024-51315 21.07.2026
CVE-2024-51316 21.07.2026
CVE-2026-44510 21.07.2026
CVE-2026-47133 ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshots 21.07.2026
CVE-2026-47134 ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy 21.07.2026
CVE-2026-55544 NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering 20.07.2026 7.6
CVE-2026-55550 NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product Catalog 20.07.2026 7.1
CVE-2024-51311 21.07.2026
CVE-2024-51313 21.07.2026
CVE-2026-44507 21.07.2026
CVE-2026-44508 21.07.2026
CVE-2026-44509 21.07.2026
CVE-2026-47129 NextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accounts 21.07.2026 8.1
CVE-2026-47130 NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering 20.07.2026 7.1
CVE-2026-56452 Apache MINA SSHD: Path traversal in SCP file reception 20.07.2026
CVE-2026-56623 Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows 20.07.2026
CVE-2026-56624 Apache MINA SSHD: SSH certificate options lack validations 20.07.2026
CVE-2026-58624 Apache MINA SSHD: Remote execution of JGit commands can write files on the server 20.07.2026
CVE-2026-64650 AI SDK Codex Harness Tool Relay Authorization Bypass 20.07.2026
CVE-2026-64651 AI SDK OpenCode Harness Tool Relay Authorization Bypass 21.07.2026
CVE-2026-13380 VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses 20.07.2026
CVE-2026-13381 VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion 20.07.2026
CVE-2026-44583 Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module 20.07.2026 5.3
CVE-2026-44585 Paymenter: Broken object level authorization via service reference manipulation on ticket creation 21.07.2026 5.4
CVE-2026-47198 Paymenter: URL parameter injection bypasses paid plan limits at checkout 20.07.2026 8.5
CVE-2026-53594 FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path 21.07.2026 4.9
CVE-2026-53595 FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL 21.07.2026 9.4
CVE-2026-53596 FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS) 20.07.2026 5.3
CVE-2026-55219 Paymenter: Race condition in payWithCredit() enables credit double-spend 20.07.2026 5.3