CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-76070 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter 24.08.2026 9.3
CVE-2026-76071 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter 24.08.2026 9.3
CVE-2026-78387 RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification 24.08.2026 9.4
CVE-2026-59568 Remote Code Execution 24.08.2026 9.1
CVE-2026-67602 phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache 24.08.2026 9.3
CVE-2026-59564 Authentication bypass between ZCC and client connector portal 24.08.2026 9.1
CVE-2026-77995 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 24.08.2026 10
CVE-2026-78370 RansomLook Unauthenticated Database Export Exposes Private Data 24.08.2026 9.2
CVE-2026-78372 RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data 24.08.2026 9.2
CVE-2026-78365 IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification 24.08.2026 9.3
CVE-2026-28165 WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-32551 WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability 24.08.2026 9.3
CVE-2026-32558 WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66587 WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability 24.08.2026 9.8
CVE-2026-66648 WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66650 WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability 24.08.2026 9.8
CVE-2026-66897 Instance template path traversal allows arbitrary host file write as root 24.08.2026 9.9
CVE-2026-77994 Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 24.08.2026 9.3
CVE-2026-78251 DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory 24.08.2026 9.3
CVE-2026-78211 4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection 24.08.2026 9.3
CVE-2026-78168 EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication 24.08.2026 9.3
CVE-2026-78169 UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow 24.08.2026 9.4
CVE-2026-78167 EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication 24.08.2026 10
CVE-2026-78207 exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization 24.08.2026 9.3
CVE-2026-5388 justhtml before 1.15.0 Multiple Security Issues 23.08.2026 9.3
CVE-2026-7808 justhtml before 1.16.0 Multiple Security Issues via Sanitization 23.08.2026 9.3
CVE-2026-8445 justhtml before 1.12.0 Sanitizer Bypass via Markdown 23.08.2026 9.3
CVE-2026-78155 Untrusted Search Path in StackGres 24.08.2026 9.9
CVE-2026-78050 Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow 24.08.2026 9.4
CVE-2026-4703 WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission 24.08.2026 9.8
CVE-2026-63310 NLTK before 3.9.3 Missing Post-Download Integrity Verification 22.08.2026 9.3
CVE-2026-76571 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 23.08.2026 9.3
CVE-2026-76602 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 24.08.2026 9.3
CVE-2026-76604 Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76605 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76606 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76607 Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-77992 Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 24.08.2026 9.5
CVE-2026-77946 TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow 22.08.2026 10
CVE-2026-78003 Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys 22.08.2026 9.8
CVE-2026-12710 Missing Authorization in Application Integration QueryEngineTask 22.08.2026 9.3
CVE-2026-49849 xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution 21.08.2026 9.1
CVE-2026-77415 JSONata: Arbitrary Code Execution via crafted JSONata expressions 21.08.2026 9.3
CVE-2026-77413 JSONata: Arbitrary Code Execution via crafted JSONata expressions 21.08.2026 9.3
CVE-2026-77414 JSONata: Arbitrary Code Execution via crafted JSONata expressions 21.08.2026 9.3
CVE-2026-61539 Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing 21.08.2026 10
CVE-2026-59989 Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) 21.08.2026 9.2
CVE-2026-62283 Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check 21.08.2026 9.9
CVE-2026-76904 GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers 21.08.2026 9.8
CVE-2026-77810 Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector 21.08.2026 9.4
CVE-2026-62674 Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE 21.08.2026 9
CVE-2026-77234 Improper input validation in FreeRTOS-Kernel timer command handling 21.08.2026 9.3
CVE-2026-39909 llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler 21.08.2026 9.2
CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability 21.08.2026 10
CVE-2026-75932 Jet Admin tenant isolation failure 21.08.2026 9.2
CVE-2026-63343 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 21.08.2026 9.9
CVE-2026-77087 Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding 21.08.2026 9.4
CVE-2026-48755 Incus has an argument injection in backup compression algorithm leading to AFW and ACE 21.08.2026 9.9
CVE-2026-48769 Incus has an arbitrary file write on its client due to trusted image hash 21.08.2026 9.9
CVE-2026-62867 Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution 21.08.2026 9.9
CVE-2026-62940 Incus has a project restriction bypass via instance migration config override 21.08.2026 9.9
CVE-2026-62941 Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 21.08.2026 9.9
CVE-2026-63125 Incus vulnerable to root RCE via image backup.yaml symlink 21.08.2026 9.9
CVE-2026-48751 Incus has a restricted project bypass leading to arbitrary command execution 21.08.2026 9.9
CVE-2026-48752 Incus has arbitrary file read+write on host via templates/ symlink in malicious image 21.08.2026 9.9
CVE-2026-48753 Incus has an arbitrary file write via path traversal in S3 multipart upload 21.08.2026 9.9
CVE-2026-48749 Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image 21.08.2026 9.9
CVE-2026-48750 Incus has an arbitrary file write on host via `exec-output` symlink in crafted image 21.08.2026 9.9
CVE-2026-77812 Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE 24.08.2026 9.4
CVE-2026-77806 21.08.2026 9.8
CVE-2026-77776 Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity 21.08.2026 9.3
CVE-2026-77086 SiYuan before v3.7.4 Path Traversal via packageName 21.08.2026 9.4
CVE-2026-77683 Comfast CF-N1-S mbox-config system command injection 21.08.2026 9.4
CVE-2026-77264 Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure 21.08.2026 9.8
CVE-2026-76158 Datiphy Data Management Center - External Control of File Name or Path 21.08.2026 9.3
CVE-2026-76155 Datiphy Data Management Center - Use of Default Credentials 21.08.2026 9.3
CVE-2026-76156 Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command 21.08.2026 9.4
CVE-2026-77649 21.08.2026 9.8
CVE-2026-77650 21.08.2026 9.8
CVE-2026-77651 21.08.2026 9.8
CVE-2026-77647 21.08.2026 9.8
CVE-2026-18835 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.9
CVE-2026-77645 Critical Remote Code Execution (RCE) vulnerability reported in Windchill 22.08.2026 9.2
CVE-2026-17122 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17136 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17141 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17142 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17145 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-17152 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17157 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-17160 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-17422 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.3
CVE-2026-72843 EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover 21.08.2026 9.3
CVE-2026-77644 Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition 22.08.2026 9.3
CVE-2026-17040 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-17118 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-55769 CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path` 21.08.2026 9.4
CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability 22.08.2026 9.3
CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability 22.08.2026 10
CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability 22.08.2026 10
CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability 22.08.2026 10
CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability 22.08.2026 9.1
CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability 22.08.2026 9.6
CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability 24.08.2026 10
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability 22.08.2026 10
CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability 22.08.2026 9.9
CVE-2026-71485 Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends 20.08.2026 9.1
CVE-2026-67567 Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction 21.08.2026 9.9
CVE-2026-19586 Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways 21.08.2026 9.3
CVE-2026-66785 Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowedips / ipsec enables traffic hijack 20.08.2026 9.9
CVE-2026-66788 Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace 20.08.2026 9.9
CVE-2026-77148 Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow 20.08.2026 9.4
CVE-2026-2334 ) Missing Server-Side File Extension Validation in vsDesk 21.08.2026 9.4
CVE-2026-63385 Libevent: HTTP header handling bugs create risk of access control bypass. 21.08.2026 9.2
CVE-2026-63382 libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling 20.08.2026 9.2
CVE-2026-53424 Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions 21.08.2026 9.1
CVE-2026-73251 Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification 20.08.2026 9.3
CVE-2026-73253 Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching 20.08.2026 9.1
CVE-2026-73256 Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE 21.08.2026 9.1
CVE-2026-73257 Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling 20.08.2026 9.1
CVE-2026-55642 dbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured) 20.08.2026 9.8
CVE-2026-71428 unstructured: Server-Side Request Forgery in the URL-based partitioning 20.08.2026 9.3
CVE-2026-77022 Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow 21.08.2026 9.4
CVE-2026-18265 OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability 20.08.2026 9.8
CVE-2026-16926 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.1
CVE-2026-15706 Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS 24.08.2026 9.8
CVE-2026-28164 WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability 20.08.2026 9.6
CVE-2025-15688 WordPress Capella theme <= 2.5.5 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2025-15689 WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-66583 WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-66592 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66593 WordPress Security & Malware scan by CleanTalk plugin <= 2.184 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66600 WordPress Media LIbrary Assistant plugin <= 3.39 - Arbitrary File Upload vulnerability 20.08.2026 9.1
CVE-2026-66609 WordPress TheGem (Elementor) theme <= 5.12.3 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66649 WordPress Directory Pro plugin <= 2.5.8 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66672 WordPress Flatastic theme <= 2.0 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-66680 WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66682 WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-68566 WordPress BookingPress Appointment Booking Pro plugin <= 6.0.2 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-73992 WordPress Query Wrangler plugin <= 1.5.57 - Remote Code Execution (RCE) vulnerability 20.08.2026 9.9
CVE-2026-73993 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-74001 WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability 20.08.2026 9.8
CVE-2026-74014 WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-74016 WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-74018 WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-11861 Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships 20.08.2026 9.6
CVE-2026-13097 Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore 21.08.2026 9.1
CVE-2026-14950 Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic 20.08.2026 9.2
CVE-2026-76590 TRENDnet TEW-755AP ssi wan.cgi stack-based overflow 21.08.2026 9.4
CVE-2026-76850 LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector 21.08.2026 9.3
CVE-2026-76310 Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise 21.08.2026 9.4
CVE-2026-76311 Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise 21.08.2026 9.4
CVE-2026-76312 Improper Access Control through Embedded Reports in Splunk Enterprise 21.08.2026 9.4
CVE-2026-76404 Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app 20.08.2026 9.1
CVE-2026-76589 TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow 19.08.2026 9.4
CVE-2026-75595 Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext 20.08.2026 9.1
CVE-2026-76584 TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow 20.08.2026 9.4
CVE-2026-53545 Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection 21.08.2026 9.8
CVE-2026-53546 Termix: Missing authorization in SSH host credential resolution exposes stored credentials 20.08.2026 9.6
CVE-2026-53548 Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users 21.08.2026 9.6
CVE-2026-16894 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16903 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.6
CVE-2026-16913 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16917 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16919 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16882 Vulnerabilities in IBM AIX and PowerVM VIOS 21.08.2026 9.8
CVE-2026-16885 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16834 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16839 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.4
CVE-2026-16840 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16845 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16862 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16864 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-16872 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-55085 Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite 21.08.2026 9.6
CVE-2026-55089 Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint 19.08.2026 9.9
CVE-2026-16822 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.3
CVE-2026-22306 Critical flaw impacting OZOLS ERP's automatic update channel 19.08.2026 10
CVE-2026-16687 Power System Buffer Overflow 22.08.2026 9.6
CVE-2026-16835 Power System Improper Certificate Validation 22.08.2026 9.6
CVE-2026-18315 TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter 21.08.2026 9.8
CVE-2026-70496 Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork 19.08.2026 9.9
CVE-2025-14600 Admin Account Takeover via Path Traversal in vsDesk 19.08.2026 9.3
CVE-2026-62682 Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) 19.08.2026 9.3
CVE-2026-72717 Orval: Import-time RCE via schema default -> zod module-level template literal 21.08.2026 9.3
CVE-2026-62681 Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) 21.08.2026 9.3
CVE-2026-66794 Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route 21.08.2026 9.3
CVE-2026-71864 Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client 19.08.2026 9.3
CVE-2026-71865 Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli 21.08.2026 9.3
CVE-2026-71866 Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client 19.08.2026 9.3
CVE-2026-71867 Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator 19.08.2026 9.3
CVE-2026-71868 Orval: Import-time RCE via enum-typed default -> zod module-level template literal 21.08.2026 9.3
CVE-2026-71869 Orval: Import-time RCE via array-items default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-71871 Orval: Import-time RCE via header-parameter default -> zod module-level template literal 21.08.2026 9.3
CVE-2026-72716 Orval: Import-time RCE via query-parameter default -> zod module-level template literal 19.08.2026 9.3
CVE-2026-32475 WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability 20.08.2026 9
CVE-2026-71470 Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa 20.08.2026 9.1
CVE-2026-72529 21.08.2026 9.3
CVE-2026-72530 21.08.2026 9.5
CVE-2026-75143 FFmpeg Heap Buffer Overflow via RIST Protocol Reader 21.08.2026 9.3
CVE-2026-20030 Cisco Crosswork Security Hardening Release: August 2026 19.08.2026 10
CVE-2026-20231 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities 20.08.2026 9.9
CVE-2026-20315 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities 20.08.2026 10
CVE-2026-20317 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities 20.08.2026 10
CVE-2026-20318 Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation Vulnerabilities 20.08.2026 9.6
CVE-2026-20357 Cisco Crosswork Security Hardening Release: August 2026 21.08.2026 10
CVE-2026-20358 Cisco Crosswork Security Hardening Release: August 2026 21.08.2026 10
CVE-2026-20359 Cisco Crosswork Security Hardening Release: August 2026 20.08.2026 9.9
CVE-2026-48024 Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager 21.08.2026 9.1
CVE-2026-48162 Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager 19.08.2026 9.1
CVE-2026-49441 Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager 19.08.2026 9.1
CVE-2026-62668 Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols 19.08.2026 9.4
CVE-2026-16656 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.8
CVE-2026-16816 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-52889 Formie: Server-Side Template Injection in Formie Hidden field defaults 19.08.2026 9.8
CVE-2026-45272 MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File 19.08.2026 9.4
CVE-2026-47187 SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write 20.08.2026 9.3
CVE-2026-53451 Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution 21.08.2026 9.8
CVE-2026-75949 Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 21.08.2026 10
CVE-2026-75954 Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 21.08.2026 9.3
CVE-2026-15065 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.1
CVE-2026-15068 Vulnerabilities in IBM AIX and PowerVM VIOS 20.08.2026 9.9
CVE-2026-71960 Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT 21.08.2026 9.3
CVE-2024-58376 Renovate 37.158.0 before 37.199.0 Command Injection via helmv3 20.08.2026 9.3
CVE-2026-16019 SQL Injection in Faydam Innovation's FAYDAM Datalogger 20.08.2026 9.8
CVE-2026-75916 SiYuan XSS-to-RCE via unescaped block metadata in hint popup 21.08.2026 9.3
CVE-2026-75917 SiYuan before v3.7.4 XSS-to-RCE via pathName.ts 20.08.2026 9.3
CVE-2026-76213 phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle 19.08.2026 9.1
CVE-2026-76214 phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge 21.08.2026 9.1
CVE-2026-76242 stigmem Federation Peer Registration Authentication Bypass 20.08.2026 9.1
CVE-2026-76243 stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth 19.08.2026 9.2
CVE-2026-76244 stigmem-node Insecure Federation Transport Configuration 19.08.2026 9.1
CVE-2026-74803 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 21.08.2026 10
CVE-2026-74804 Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 21.08.2026 9.3
CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 20.08.2026 9.3
CVE-2026-67364 Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 21.08.2026 10
CVE-2026-66613 WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability 20.08.2026 9.8
CVE-2026-73183 WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73185 WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-73347 WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-73364 WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability 19.08.2026 9.8
CVE-2026-73388 WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-73389 WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-73390 WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-73391 WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability 19.08.2026 9.3
CVE-2026-76008 Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow 19.08.2026 10
CVE-2026-76003 UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow 21.08.2026 9.4
CVE-2026-76004 UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow 19.08.2026 9.4
CVE-2026-11751 20.08.2026 9.1
CVE-2026-75976 TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow 18.08.2026 9.4
CVE-2026-70905 22.08.2026 9.8
CVE-2026-70920 22.08.2026 9.9
CVE-2026-70921 22.08.2026 10
CVE-2026-70926 22.08.2026 9.8
CVE-2026-70953 22.08.2026 9.8
CVE-2026-70954 22.08.2026 9.8
CVE-2026-70958 22.08.2026 9.6
CVE-2026-70970 20.08.2026 9.8
CVE-2026-70976 22.08.2026 9.1
CVE-2026-70977 22.08.2026 9.1
CVE-2026-70978 22.08.2026 9.1
CVE-2026-70979 22.08.2026 9.1
CVE-2026-70980 19.08.2026 9
CVE-2026-70981 19.08.2026 9.1
CVE-2026-70984 19.08.2026 9.1
CVE-2026-70994 20.08.2026 9.1
CVE-2026-70995 20.08.2026 9.8
CVE-2026-70997 20.08.2026 9.1
CVE-2026-70998 20.08.2026 9.3
CVE-2026-71014 22.08.2026 9.1
CVE-2026-71015 22.08.2026 9.1
CVE-2026-71026 19.08.2026 9.1
CVE-2026-71036 21.08.2026 9.1
CVE-2026-71037 19.08.2026 9.3
CVE-2026-71040 19.08.2026 9.8
CVE-2026-71059 19.08.2026 9.9
CVE-2026-71063 19.08.2026 9.6
CVE-2026-71064 22.08.2026 9.6
CVE-2026-71065 22.08.2026 9.3
CVE-2026-71074 19.08.2026 9.8
CVE-2026-71102 19.08.2026 9.1
CVE-2026-71152 21.08.2026 9.8
CVE-2026-71164 19.08.2026 9.8
CVE-2026-71166 20.08.2026 9.4
CVE-2026-71167 20.08.2026 9.4
CVE-2026-73865 19.08.2026 9.1
CVE-2026-73866 19.08.2026 9.1
CVE-2026-73905 19.08.2026 9.8
CVE-2026-73912 19.08.2026 9.8
CVE-2026-73916 19.08.2026 9.1
CVE-2026-73917 19.08.2026 9.1
CVE-2026-73920 20.08.2026 9.4
CVE-2026-73921 19.08.2026 9.8
CVE-2026-73922 19.08.2026 9.1
CVE-2026-73924 19.08.2026 9.1
CVE-2026-73930 19.08.2026 9.9
CVE-2026-60591 20.08.2026 9.1
CVE-2026-60672 20.08.2026 9.8
CVE-2026-60696 19.08.2026 9.8
CVE-2026-60698 19.08.2026 9.8
CVE-2026-60702 19.08.2026 9.9
CVE-2026-60720 21.08.2026 9.9
CVE-2026-60721 20.08.2026 9.8
CVE-2026-60727 19.08.2026 9.8
CVE-2026-60728 19.08.2026 9.1
CVE-2026-60730 19.08.2026 9.9
CVE-2026-60737 20.08.2026 9.1
CVE-2026-60754 20.08.2026 9.1
CVE-2026-60782 20.08.2026 9.8
CVE-2026-60821 21.08.2026 9.8
CVE-2026-60858 20.08.2026 9.8
CVE-2026-60861 20.08.2026 9.6
CVE-2026-60905 20.08.2026 9.6
CVE-2026-60916 19.08.2026 9.9
CVE-2026-60921 21.08.2026 9.8
CVE-2026-60946 21.08.2026 9.8
CVE-2026-60947 21.08.2026 9.8
CVE-2026-60958 21.08.2026 9.8
CVE-2026-60970 21.08.2026 9.8
CVE-2026-60971 21.08.2026 9.8
CVE-2026-60977 21.08.2026 9.8
CVE-2026-60990 21.08.2026 9.9
CVE-2026-60995 21.08.2026 9.9
CVE-2026-61001 21.08.2026 9.6
CVE-2026-61003 21.08.2026 9.9
CVE-2026-61008 20.08.2026 9.1
CVE-2026-61018 21.08.2026 9.8
CVE-2026-61021 20.08.2026 9.9
CVE-2026-61029 20.08.2026 9
CVE-2026-61034 20.08.2026 9.1
CVE-2026-61066 21.08.2026 9.9
CVE-2026-61206 21.08.2026 9.9
CVE-2026-61241 21.08.2026 10
CVE-2026-61248 21.08.2026 9.9
CVE-2026-61258 21.08.2026 9.8
CVE-2026-61272 21.08.2026 9.8
CVE-2026-61317 20.08.2026 9.9
CVE-2026-61318 20.08.2026 9.8
CVE-2026-62452 19.08.2026 9.9
CVE-2026-62457 24.08.2026 9.8
CVE-2026-62463 18.08.2026 9.6
CVE-2026-62512 21.08.2026 9.9
CVE-2026-62539 18.08.2026 9.8
CVE-2026-62541 18.08.2026 9.8
CVE-2026-62543 18.08.2026 9.8
CVE-2026-62544 18.08.2026 9.8
CVE-2026-62582 18.08.2026 9.6
CVE-2026-62585 21.08.2026 9.8
CVE-2026-62588 20.08.2026 9.9
CVE-2026-62592 20.08.2026 9.8
CVE-2026-62608 18.08.2026 9.9
CVE-2026-62609 18.08.2026 9.8
CVE-2026-62610 18.08.2026 9.1
CVE-2026-62611 18.08.2026 9.8
CVE-2026-62613 18.08.2026 9.3
CVE-2026-62614 18.08.2026 9.8
CVE-2026-62617 18.08.2026 9.8
CVE-2026-62618 18.08.2026 9.3
CVE-2026-62621 18.08.2026 9.8
CVE-2026-62622 18.08.2026 9.8
CVE-2026-62624 18.08.2026 9.8
CVE-2026-62626 18.08.2026 9.8
CVE-2026-62629 18.08.2026 9.4
CVE-2026-62630 18.08.2026 9.8
CVE-2026-62632 18.08.2026 9.8
CVE-2026-62633 18.08.2026 9.8
CVE-2026-62634 18.08.2026 9.8
CVE-2026-62635 18.08.2026 9.8
CVE-2026-62637 18.08.2026 9.3
CVE-2026-62638 18.08.2026 9.1
CVE-2026-62639 18.08.2026 9.8
CVE-2026-62640 18.08.2026 9.8
CVE-2026-70668 18.08.2026 9.1
CVE-2026-70669 18.08.2026 9.8
CVE-2026-70670 18.08.2026 9.6
CVE-2026-70673 18.08.2026 9.3
CVE-2026-70689 18.08.2026 9.8
CVE-2026-70730 18.08.2026 9.1
CVE-2026-70739 18.08.2026 9.8
CVE-2026-70740 18.08.2026 9.8
CVE-2026-70741 18.08.2026 9.1
CVE-2026-70745 18.08.2026 9.8
CVE-2026-70817 24.08.2026 9.8
CVE-2026-70846 24.08.2026 9.6
CVE-2026-70854 24.08.2026 9.1
CVE-2026-70855 18.08.2026 9.3
CVE-2026-70862 24.08.2026 9.1
CVE-2026-70871 24.08.2026 9.8
CVE-2026-70872 24.08.2026 9.1
CVE-2026-70873 24.08.2026 9.8
CVE-2026-70876 24.08.2026 9.1
CVE-2026-70880 24.08.2026 10
CVE-2026-70883 24.08.2026 9.1
CVE-2026-70884 24.08.2026 9.1
CVE-2026-62988 Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints 21.08.2026 9
CVE-2026-67443 FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) 21.08.2026 9.2
CVE-2026-75877 TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow 19.08.2026 9.4
CVE-2026-52735 ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser 18.08.2026 9.3
CVE-2026-55166 Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR 18.08.2026 9.9
CVE-2026-47627 20.08.2026 9.8
CVE-2026-50161 libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow 19.08.2026 9.3
CVE-2026-75625 Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass 18.08.2026 9.1
CVE-2026-71878 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.2
CVE-2026-71879 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.1
CVE-2026-66780 Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace 18.08.2026 9.9
CVE-2026-18963 Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass 20.08.2026 9.1
CVE-2026-57580 authentik: Account Takeover via SAML NameID Comment Truncation 18.08.2026 9.4
CVE-2026-52723 ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust 18.08.2026 9.1
CVE-2026-67271 19.08.2026 9.8
CVE-2026-45118 MyBB: Contact page reflected XSS 18.08.2026 9.3
CVE-2026-12564 Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf 18.08.2026 9.6
CVE-2026-45117 MyBB: Installer database configuration RCE 18.08.2026 9.8
CVE-2026-75926 Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant 20.08.2026 9.3
CVE-2026-75856 CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU 18.08.2026 9.2
CVE-2026-59940 Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization 18.08.2026 9.8
CVE-2026-32470 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-32474 WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-66627 WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-73187 WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73339 WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73341 WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73343 WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability 18.08.2026 10
CVE-2026-73355 WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73365 WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73366 WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73376 WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73380 WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73381 WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability 18.08.2026 9.1
CVE-2026-73392 WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73397 WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability 18.08.2026 9.8
CVE-2026-73996 WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability 18.08.2026 9.8
CVE-2026-74015 WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-75784 TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow 20.08.2026 10
CVE-2026-28192 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability 18.08.2026 9.6
CVE-2026-32444 WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability 18.08.2026 9.9
CVE-2026-32463 WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-75783 TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow 18.08.2026 9.4
CVE-2026-74902 SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload 18.08.2026 9.3
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log 19.08.2026 9.3
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass 18.08.2026 9.3
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass 19.08.2026 9.3
CVE-2026-75835 Grav API Plugin before 1.0.14 Missing Authorization 18.08.2026 9.3
CVE-2026-75837 Grav before 2.0.14 Privilege Escalation via Group Access Field 19.08.2026 9.3
CVE-2026-75843 ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction 18.08.2026 9.4
CVE-2026-75851 ArcadeDB before 26.8.1 Authentication Bypass via Async Command 18.08.2026 9.4
CVE-2026-75852 ArcadeDB MongoDB wire protocol authentication bypass cross-database 18.08.2026 9.3
CVE-2026-75854 ArcadeDB Redis Wire-Protocol Plugin Missing Authentication 18.08.2026 9.3
CVE-2026-75626 SpiderFoot Stored Cross-Site Scripting via Correlation Titles 19.08.2026 9.3
CVE-2026-75627 Bastillion Authentication Bypass via Path-Prefix Routing Mismatch 18.08.2026 9.3
CVE-2026-15748 Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration 18.08.2026 9.8
CVE-2026-75094 COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection 18.08.2026 9.4
CVE-2026-71424 Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers 18.08.2026 9.6

Latest Updates

CVE Title Updated Score
CVE-2025-68825 HCL Hive is affected by incorrect default permissions 24.08.2026 7.5
CVE-2026-13212 Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring descriptor id 24.08.2026 8.8
CVE-2026-13343 Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder 24.08.2026 5.3
CVE-2026-67204 BookStack < 26.05.4 Broken Access Control via Image Gallery API 24.08.2026
CVE-2026-71366 Awx: notification backends allow ssrf and credential leakage 24.08.2026
CVE-2026-76070 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter 24.08.2026
CVE-2026-76071 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter 24.08.2026
CVE-2026-78416 Authenticated RCE via `condition.config` JSON cleanse bypass 24.08.2026
CVE-2026-21752 HCL Hive is affected by a use of vulnerable third-party components 24.08.2026 7.5
CVE-2026-71364 Awx: project archive extraction allows path traversal file writes 24.08.2026
CVE-2026-19874 Konami's Metal Gear Online 3 contains a heap-based buffer overflow 24.08.2026
CVE-2026-65053 Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Name 24.08.2026
CVE-2026-78414 Cross-site scripting in Nx Witness VMS Web Administration allows session token exfiltration via a rogue peer site name 24.08.2026 8
CVE-2026-9728 TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory 24.08.2026 6.4
CVE-2026-21755 HCL Hive is affected by a missing rate limit 24.08.2026 5.3
CVE-2026-39914 TIM Flow < 26.0.6 Unauthorized SQL Query Execution via Dashboard Export Endpoint 24.08.2026
CVE-2026-39915 TIM Flow < 26.0.6 CRLF Injection via rt Parameter 24.08.2026
CVE-2026-76054 24.08.2026
CVE-2026-76055 24.08.2026
CVE-2026-78387 RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification 24.08.2026
CVE-2026-78391 Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook 24.08.2026
CVE-2025-68833 HCL Hive is affected by use of a cryptographic primitive with a risky implementation 24.08.2026 5.3
CVE-2026-17033 CVE-2026-17033 CVE Record 24.08.2026 6.8
CVE-2026-30512 24.08.2026
CVE-2026-59565 Local and kernel denial-of-service 24.08.2026 8.8
CVE-2026-59566 Local denial-of-service 24.08.2026 8.4
CVE-2026-59567 Local privilege escalation 24.08.2026 8.8
CVE-2026-59568 Remote Code Execution 24.08.2026 9.1
CVE-2026-67602 phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache 24.08.2026
CVE-2026-78367 Rpm: rpmbuild gettarspec() crafted tar member name → macro injection 24.08.2026
CVE-2026-78385 RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local File Access 24.08.2026
CVE-2026-78386 Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook API 24.08.2026
CVE-2026-59564 Authentication bypass between ZCC and client connector portal 24.08.2026 9.1
CVE-2026-78376 Webkitgtk: use-after-free of jscvalue function parameters 24.08.2026
CVE-2026-78378 Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data 24.08.2026
CVE-2026-78380 Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLook 24.08.2026
CVE-2026-78381 RansomLook Arbitrary File Read via Path Traversal in Post screen Field 24.08.2026
CVE-2026-21751 HCL Hive is affected by use of a cryptographic primitive with a risky implementation 24.08.2026 7.4
CVE-2026-76840 RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileContentsResponse Length 24.08.2026
CVE-2026-76841 Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Model Loaders 24.08.2026
CVE-2026-76842 Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients 24.08.2026
CVE-2026-76843 Flair 0.15.0 and 0.15.1 Deserialization of Untrusted Data via ClusteringModel.load 24.08.2026
CVE-2026-76844 webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPath 24.08.2026
CVE-2026-76845 adm-zip 0.5.9 through 0.6.0 Arbitrary File Overwrite via Symlink Following on Extraction 24.08.2026
CVE-2026-76847 act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend 24.08.2026
CVE-2026-76848 TypeORM 0.2.21 through 1.1.0 SQL Injection via SelectQueryBuilder.distinctOn 24.08.2026
CVE-2026-77995 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 24.08.2026
CVE-2026-78248 SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection 24.08.2026
CVE-2026-78250 bytebot-ai bytebot Agent Execution Workflow infinite loop 24.08.2026
CVE-2026-78369 Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook 24.08.2026
CVE-2026-78370 RansomLook Unauthenticated Database Export Exposes Private Data 24.08.2026
CVE-2026-78372 RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data 24.08.2026
CVE-2026-21756 HCL Hive is affected by a broken access control vulnerability 24.08.2026 7.2
CVE-2026-78247 SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection 24.08.2026
CVE-2026-78365 IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification 24.08.2026
CVE-2026-21759 HCL Hive is affected by an information exposure vulnerability 24.08.2026 4.3
CVE-2026-28151 WordPress Tonda theme < 2.6 - Local File Inclusion vulnerability 24.08.2026 8.1
CVE-2026-28152 WordPress Tonda Core plugin < 2.6 - Local File Inclusion vulnerability 24.08.2026 8.1
CVE-2026-28153 WordPress Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin <= 1.7.1 - Broken Access Control vulnerability 24.08.2026 7.5
CVE-2026-28162 WordPress Events Made Easy plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability 24.08.2026 7.1
CVE-2026-28165 WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-28166 WordPress Tourmaster plugin <= 5.4.9 - Cross Site Scripting (XSS) vulnerability 24.08.2026 7.1
CVE-2026-28167 WordPress Super Forms plugin <= 6.3.315 - Arbitrary File Download vulnerability 24.08.2026 7.5
CVE-2026-28171 WordPress WooCommerce File Approval plugin <= 10.7 - Arbitrary File Deletion vulnerability 24.08.2026 8.6
CVE-2026-28190 WordPress ProLancer Element plugin <= 1.4.8 - Broken Access Control vulnerability 24.08.2026 7.1
CVE-2026-32471 WordPress ProLancer Element plugin <= 1.4.8 - SQL Injection vulnerability 24.08.2026 8.5
CVE-2026-32476 WordPress Brave Conversion Engine (PRO) plugin <= 0.8.6 - Cross Site Scripting (XSS) vulnerability 24.08.2026 7.1
CVE-2026-32477 WordPress ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion vulnerability 24.08.2026 8.6
CVE-2026-32478 WordPress WP Project Manager Pro plugin <= 4.0.1 - SQL Injection vulnerability 24.08.2026 8.5
CVE-2026-32551 WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability 24.08.2026 9.3
CVE-2026-32558 WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66585 WordPress WP Cafe Pro plugin < 3.0.15 - Sensitive Data Exposure vulnerability 24.08.2026 7.5
CVE-2026-66587 WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability 24.08.2026 9.8
CVE-2026-66610 WordPress Urna theme <= 2.6.2 - Cross Site Scripting (XSS) vulnerability 24.08.2026 7.1
CVE-2026-66648 WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66650 WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability 24.08.2026 9.8
CVE-2026-66670 WordPress Måne theme <= 1.7 - Local File Inclusion vulnerability 24.08.2026 8.1
CVE-2026-66671 WordPress Verdure Core plugin <= 1.2 - Local File Inclusion vulnerability 24.08.2026 8.1
CVE-2026-66584 WordPress 12 Step Meeting List plugin <= 3.19.16 - Cross Site Scripting (XSS) vulnerability 24.08.2026 7.1
CVE-2026-66599 WordPress WPComplete plugin <= 2.9.5.6 - Cross Site Scripting (XSS) vulnerability 24.08.2026 7.1
CVE-2026-66623 WordPress Social Media & Share Icons plugin <= 2.9.9 - Cross Site Scripting (XSS) vulnerability 24.08.2026 7.1
CVE-2026-78258 WordPress Booking and Rental Manager plugin <= 2.7.5 - Broken Access Control vulnerability 24.08.2026 5.3
CVE-2026-78269 WordPress Shared Files plugin <= 1.7.69 - Server Side Request Forgery (SSRF) vulnerability 24.08.2026 6.4
CVE-2026-78270 WordPress FluentCRM Pro plugin <= 3.1.12 - SQL Injection vulnerability 24.08.2026 7.6
CVE-2026-78272 WordPress Fluent Support Pro plugin <= 2.3.1 - Broken Access Control vulnerability 24.08.2026 5.4
CVE-2026-78277 WordPress FluentCRM Pro plugin <= 3.1.12 - Server Side Request Forgery (SSRF) vulnerability 24.08.2026 4.9
CVE-2026-78278 WordPress Fluent Boards Pro plugin <= 2.0.11 - Insecure Direct Object References (IDOR) vulnerability 24.08.2026 5.3
CVE-2026-78279 WordPress Fluent Support Pro plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability 24.08.2026 5.4
CVE-2026-78280 WordPress Hash Form plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerability 24.08.2026 4.3
CVE-2026-78290 WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability 24.08.2026 6.5
CVE-2026-78291 WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerability 24.08.2026 5.3
CVE-2026-78246 itsourcecode Online Clinic Management System Admin Login login.php sql injection 24.08.2026
CVE-2025-63080 Authenticated RCE in KAON PG5298 24.08.2026
CVE-2026-6017 Missing Authentication for Critical Function in KAON PG5298 24.08.2026
CVE-2026-78323 Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates 24.08.2026
CVE-2026-78245 itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload 24.08.2026
CVE-2026-78337 Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG 24.08.2026
CVE-2026-10582 Hugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.urls Lacking Destination Address Validation 24.08.2026
CVE-2026-10618 Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribute Values 24.08.2026
CVE-2026-78244 itsourcecode Real Estate Management System search.php sql injection 24.08.2026
CVE-2026-59295 Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulnerability 24.08.2026 5.9
CVE-2026-76172 fast-uri vulnerable to host confusion via percent-encoded scheme normalization 24.08.2026 7.5
CVE-2026-75975 fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization 24.08.2026 7.5
CVE-2026-75899 fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding 24.08.2026 7.5
CVE-2026-75931 fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references 24.08.2026 7.5
CVE-2026-78314 DIAEnergie - SQL Injection 24.08.2026 8.8
CVE-2026-78315 DIAEnergie - SQL Injection 24.08.2026 8.8
CVE-2026-78316 DIAEnergie - SQL Injection 24.08.2026 8.8
CVE-2026-78317 DIAEnergie - SQL Injection 24.08.2026 8.8
CVE-2026-16249 24.08.2026
CVE-2026-66897 Instance template path traversal allows arbitrary host file write as root 24.08.2026 9.9
CVE-2026-78321 DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion 24.08.2026
CVE-2026-78306 DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution 24.08.2026
CVE-2026-77993 Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 24.08.2026
CVE-2026-77994 Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 24.08.2026
CVE-2026-78255 DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media 24.08.2026
CVE-2026-78251 DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory 24.08.2026
CVE-2026-8173 Information Disclosure via 'Copy learned MAC Addresses' Function 24.08.2026
CVE-2026-78202 itsourcecode Payroll System admin_class.php save_settings unrestricted upload 24.08.2026
CVE-2026-78201 itsourcecode Payroll System admin_class.php login sql injection 24.08.2026
CVE-2026-78200 itsourcecode Library Management System editbooks.php sql injection 24.08.2026
CVE-2026-78199 SourceCodester Simple Online Food Ordering System view_prod.php sql injection 24.08.2026
CVE-2026-78198 SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection 24.08.2026
CVE-2026-59561 24.08.2026
CVE-2026-78197 SourceCodester Simple Online Food Ordering System ajax.php save_user sql injection 24.08.2026
CVE-2026-78187 Piwigo Public Authentication cross site scripting 24.08.2026
CVE-2026-78196 achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt getDataColumn path traversal 24.08.2026
CVE-2026-78186 Open5GS HSS hss-cx-path.c assertion 24.08.2026
CVE-2026-78185 itsourcecode Sales and Inventory System cust_edit.php sql injection 24.08.2026
CVE-2026-78213 Hepta Platforms|Heptabase - Stored Cross-Site Scripting 24.08.2026 8.7
CVE-2026-19852 CyberTutor|NewSiteServer (NSS) - Arbitrary File Upload 24.08.2026 6.1
CVE-2026-19853 CyberTutor|NewSiteServer (NSS) - Missing Authentication 24.08.2026 5.3
CVE-2026-78181 ractivejs ractive Keypath Ractive#set prototype pollution 24.08.2026
CVE-2026-78182 Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System plansImmediate PlanController.getImmediatePlans sql injection 24.08.2026
CVE-2026-78211 4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection 24.08.2026 9.8
CVE-2026-78212 4MOSAn Security Technology|4MOSAn Management Center - Arbitrary File Read 24.08.2026 7.5
CVE-2026-19200 Velociraptor Analyst overwrites live built-in artifacts through verify() 24.08.2026 8.9
CVE-2026-78179 rexrainbow phaser3-rex-notes BehaviorTree Blackboard Data SetValue.js SetValue prototype pollution 24.08.2026
CVE-2026-78180 alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution 24.08.2026
CVE-2026-78178 jQWidgets jqx-all.js jqxBaseFramework.extend prototype pollution 24.08.2026
CVE-2026-78171 itsourcecode Sales and Inventory System processlogin.php sql injection 24.08.2026
CVE-2026-78177 TanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injection 24.08.2026
CVE-2026-78168 EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication 24.08.2026
CVE-2026-78169 UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow 24.08.2026
CVE-2026-78170 UTT HiPER 1200GW formConfigFastDirectionW strcpy buffer overflow 24.08.2026
CVE-2026-78166 provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection 24.08.2026
CVE-2026-78167 EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication 24.08.2026
CVE-2026-78161 warmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write 24.08.2026
CVE-2026-78160 Dolibarr ERP User Notes note.php authorization 24.08.2026
CVE-2026-78203 Ghostwriter before 7.1.2 Cross-Client Report Template Disclosure via Unauthorized Template Swap 24.08.2026
CVE-2026-78204 Ghostwriter through 7.2.6 Missing Authorization on Report Template Lint Endpoints 24.08.2026
CVE-2026-78205 BentoML 1.4.19 through 1.4.39 Server-Side Request Forgery via Unfiltered RFC 6598 Shared Address Space 24.08.2026
CVE-2026-78206 exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression 24.08.2026
CVE-2026-78207 exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization 24.08.2026
CVE-2026-78208 exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename 24.08.2026
CVE-2026-78209 exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values 24.08.2026
CVE-2026-78157 Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds 24.08.2026
CVE-2026-78158 Open5GS AMF UEContextReleaseRequest Path improper authorization 24.08.2026
CVE-2026-78156 Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflow 23.08.2026
CVE-2026-78154 the-momentum open-wearables Public Invitation-Code Redemption Endpoint user_invitation_code.py redeem_invitation_code missing authentication 23.08.2026
CVE-2026-78148 ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference 23.08.2026
CVE-2026-78147 ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserialization 23.08.2026
CVE-2026-78145 CTFd __init__.py _is_safe_url redirect 23.08.2026
CVE-2026-78144 code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization 23.08.2026
CVE-2026-78143 code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection 23.08.2026
CVE-2026-78142 code-projects Barangay Resident Profiling Management System Restore/Delete archived_records.php authorization 24.08.2026
CVE-2026-78141 Tenda CH22 exeCommand formexeCommand command injection 23.08.2026