CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 09.08.2026 9.3
CVE-2026-71992 MSI Radix AXE6600 v781521 Command Injection via macfilter 08.08.2026 9.3
CVE-2026-71993 MSI Radix AXE6600 v781521 Command Injection via openvpn function 09.08.2026 9.3
CVE-2026-71991 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 08.08.2026 9.3
CVE-2026-71986 MSI Radix AXE6600 v781521 Command Injection via dmz Function 08.08.2026 9.3
CVE-2026-71987 MSI Radix AXE6600 v781521 Command Injection via alg function 08.08.2026 9.3
CVE-2026-71988 MSI Radix AXE6600 v781521 Command Injection via portFw function 08.08.2026 9.3
CVE-2026-71989 MSI Radix AXE6600 v781521 Command Injection via porTrigger function 08.08.2026 9.3
CVE-2026-71990 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 08.08.2026 9.3
CVE-2026-71984 MSI Radix AXE6600 v781521 Command Injection via urlfilter 08.08.2026 9.3
CVE-2026-71985 MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function 08.08.2026 9.3
CVE-2026-71983 MSI Radix AXE6600 v781521 Command Injection via wps.cgi 08.08.2026 9.3
CVE-2026-71956 D-Link DWR-M961 Command Injection via app.cgi 08.08.2026 9.3
CVE-2026-71957 D-Link DWR-M961 Buffer Overflow via app.cgi 08.08.2026 9.3
CVE-2026-71958 D-Link DWR-M961 Buffer Overflow via quicksetup.cgi 08.08.2026 9.3
CVE-2026-71944 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel 08.08.2026 9.3
CVE-2026-71945 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom 08.08.2026 9.3
CVE-2026-71946 D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun 08.08.2026 9.3
CVE-2026-71947 D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun 08.08.2026 9.3
CVE-2026-71948 D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun 08.08.2026 9.3
CVE-2026-71949 D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup 08.08.2026 9.3
CVE-2026-71950 D-Link DWR-M961 Command Injection via /boafrm/formSmsManage 08.08.2026 9.3
CVE-2026-71951 D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup 08.08.2026 9.3
CVE-2026-71952 D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup 08.08.2026 9.3
CVE-2026-71953 D-Link DWR-M961 Command Injection via /boafrm/formNtp 08.08.2026 9.3
CVE-2026-71954 D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup 08.08.2026 9.3
CVE-2026-71955 D-Link DWR-M961 Command Injection via /boafrm/formWsc 08.08.2026 9.3
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route 08.08.2026 9.8
CVE-2026-46409 OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution 07.08.2026 9.6
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs 07.08.2026 9.2
CVE-2026-48170 scimPatch vulnerable to prototype pollution via unfiltered keys in patch 07.08.2026 9.1
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading 07.08.2026 9.6
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration 07.08.2026 9.8
CVE-2026-48039 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 07.08.2026 9.1
CVE-2026-71851 crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain 08.08.2026 9
CVE-2026-64637 07.08.2026 9.9
CVE-2022-4995 Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp 07.08.2026 9.3
CVE-2026-19264 Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover 07.08.2026 9.3
CVE-2026-66914 Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 07.08.2026 9.2
CVE-2026-54203 TeamDavid: Memory Leak leaking sensitive information 07.08.2026 9.2
CVE-2026-54210 TeamDavid: Buffer Overflow in file names of file upload functionalities 07.08.2026 9.5
CVE-2026-54211 TeamDavid: Buffer Overflow in multiple form data parameters 07.08.2026 9.5
CVE-2026-54212 TeamDavid: Buffer Overflow in JSON-parsing 07.08.2026 9.5
CVE-2026-54213 TeamDavid: Denial of Service via endpoint 'internalRestart' 07.08.2026 9.2
CVE-2026-14364 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' 07.08.2026 9.8
CVE-2026-14365 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' 07.08.2026 9.8
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability 07.08.2026 9.9
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability 07.08.2026 9.6
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability 08.08.2026 10
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability 07.08.2026 9.3
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability 08.08.2026 9.8
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability 07.08.2026 9.6
CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability 07.08.2026 10
CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability 07.08.2026 10
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability 07.08.2026 9.1
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability 07.08.2026 9.6
CVE-2025-14561 Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations 07.08.2026 9
CVE-2026-11976 MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise 07.08.2026 10
CVE-2026-14812 Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) 07.08.2026 10
CVE-2026-17032 Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server 07.08.2026 9.8
CVE-2026-18367 07.08.2026 9.3
CVE-2026-3418 Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution 07.08.2026 9.1
CVE-2026-43629 llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore 07.08.2026 9.2
CVE-2026-43631 llama.cpp b7492–b9060 Use-After-Free RCE via llama-server 07.08.2026 9.2
CVE-2026-43632 llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints 08.08.2026 9.2
CVE-2026-48085 OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap 07.08.2026 9.8
CVE-2026-48086 OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN 07.08.2026 9.9
CVE-2026-48087 OpenReception: WebAuthn passkey injection allows account takeover 07.08.2026 9.8
CVE-2026-48088 OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory 08.08.2026 9.4
CVE-2026-53983 Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL 07.08.2026 9.2
CVE-2026-5857 Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments 08.08.2026 9.2
CVE-2026-70558 Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token 08.08.2026 9.3
CVE-2026-28005 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-28139 WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-53975 OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec 06.08.2026 9.3
CVE-2026-53976 OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter 06.08.2026 9.3
CVE-2026-54489 06.08.2026 9.1
CVE-2026-65507 WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-65508 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65520 WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65546 WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65548 WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.9
CVE-2026-65552 WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65553 WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability 06.08.2026 10
CVE-2026-65556 WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65571 WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65572 WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65573 WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65574 WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65575 WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65576 WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65577 WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65578 WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65579 WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65581 WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-66447 WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-66665 WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability 06.08.2026 10
CVE-2026-66709 WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.1
CVE-2026-67261 06.08.2026 9.8
CVE-2026-12605 06.08.2026 9.6
CVE-2026-5134 SQLi in Loca Software's CMS 06.08.2026 9.8
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products 06.08.2026 9.4
CVE-2026-1728 Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover 06.08.2026 9.8
CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover 06.08.2026 10
CVE-2026-64597 smb: client: fix double-free in SMB2_close() replay 08.08.2026 9.8
CVE-2026-67531 FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool 06.08.2026 9.3
CVE-2026-71319 Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution 07.08.2026 9.6
CVE-2026-48168 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name 05.08.2026 10
CVE-2026-20267 Cisco IOS XE Software Security Hardening Release 06.08.2026 9
CVE-2026-20272 Cisco IOS XE Software Security Hardening Release 06.08.2026 9.8
CVE-2026-20303 Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities 06.08.2026 9.9
CVE-2026-20304 Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities 06.08.2026 9.9
CVE-2026-20310 Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access 06.08.2026 9.1
CVE-2026-7329 Privilege escalation in Progress MarkLogic Server REST query interfaces 07.08.2026 9.9
CVE-2026-7557 SAML authentication bypass in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-8709 Privilege escalation in Progress MarkLogic Server REST document patch operation 07.08.2026 9.9
CVE-2026-9190 HTTP request smuggling in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-9192 Authentication bypass in Progress MarkLogic Server ODBC App Server 07.08.2026 9.8
CVE-2026-9193 Privilege escalation in Progress MarkLogic Server Hadoop integration 07.08.2026 9.9
CVE-2026-9195 Cross-site scripting in Progress MarkLogic Server Query Console 05.08.2026 9.3
CVE-2026-15587 Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header 05.08.2026 9.4
CVE-2026-39923 Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset 05.08.2026 9.2
CVE-2026-71262 IoTSharp BlobStorageController Missing Authentication and Path Traversal 05.08.2026 9.8
CVE-2026-71263 FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() 05.08.2026 9.1
CVE-2026-71267 microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() 05.08.2026 9.8
CVE-2026-71268 OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write 05.08.2026 9.9
CVE-2026-71277 rust-iot-platform Authentication Bypass via Non-Validated Authorization Header 05.08.2026 9.1
CVE-2026-71278 rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation 05.08.2026 9.8
CVE-2026-71289 NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API 05.08.2026 9.8
CVE-2026-71254 nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() 05.08.2026 9.8
CVE-2026-71256 nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id 05.08.2026 9.8
CVE-2026-66747 ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant 05.08.2026 9.3
CVE-2026-71231 IOTSmartHome: Unauthenticated SQL Injection via lastLogin Cookie 05.08.2026 9.8
CVE-2026-71237 Miantang IoT-PHP: Unauthenticated SQL Injection in /userlogin 05.08.2026 9.8
CVE-2026-71238 DjangoCRM: Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery 05.08.2026 9.1
CVE-2026-71248 Inventory-Management-System-PHP: Unauthenticated SQL Injection in Login and Product Deletion 05.08.2026 9.8
CVE-2026-44945 Cross-Cluster Impersonation Confused-Deputy Privilege Escalation 06.08.2026 9.1
CVE-2026-10059 Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token 05.08.2026 9.1
CVE-2026-10090 Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription 05.08.2026 9.9
CVE-2026-4431 Easy Post Submission <= 2.3.0 - Missing Authorization 05.08.2026 9.1
CVE-2026-64566 xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() 08.08.2026 9.8
CVE-2026-5581 Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion 05.08.2026 9.1
CVE-2026-70376 Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE 05.08.2026 9.6
CVE-2026-71207 Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass 05.08.2026 9.8
CVE-2026-71213 typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force 05.08.2026 9.1
CVE-2026-71214 NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server 05.08.2026 9.8
CVE-2026-9273 Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover 05.08.2026 9.3
CVE-2026-45537 OpenSIPS: Global Buffer Overflow in construct_uri 05.08.2026 9.1
CVE-2026-45100 OpenSIPS: Buffer Overflow in Base64 Encode Transformation 05.08.2026 9.1
CVE-2026-45538 OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy 05.08.2026 9.8
CVE-2026-70554 MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie 05.08.2026 9.3
CVE-2026-70477 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability 05.08.2026 9.5
CVE-2026-70478 Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service 05.08.2026 9.2
CVE-2026-70552 MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php 05.08.2026 9.3
CVE-2026-70553 MaxSite CMS Unauthenticated RCE via Install Endpoint 05.08.2026 9.3
CVE-2017-20241 Keysight IxChariot Endpoint heap-based buffer overflow 04.08.2026 9.3
CVE-2017-20242 Keysight IxChariot Endpoint stack-based buffer overflow 04.08.2026 9.3
CVE-2026-49435 Keysight IxChariot-related products stack-based buffer overflow 04.08.2026 9.3
CVE-2026-69703 Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit 04.08.2026 9.3
CVE-2026-24254 04.08.2026 9.8
CVE-2026-69264 Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation 04.08.2026 9.4
CVE-2026-70470 Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE 04.08.2026 9.5
CVE-2026-63455 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-63456 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-58072 05.08.2026 9
CVE-2026-58073 05.08.2026 9.5
CVE-2026-64633 05.08.2026 10
CVE-2026-69255 Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified 04.08.2026 9.2
CVE-2026-69256 Flowise: Remote Code Execution Vulnerability in CSVAgent 05.08.2026 9.4
CVE-2026-69259 Flowise RCE via SQLite Record Manager Node 04.08.2026 9.4
CVE-2026-18801 Stored Clickhouse SQL Injection Through Customer Usage Attribution 04.08.2026 9.3
CVE-2026-25289 Stack-based Buffer Overflow in WLAN Firmware 05.08.2026 9.6
CVE-2026-69098 kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization 05.08.2026 9.3
CVE-2026-69110 OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music 04.08.2026 9.3
CVE-2026-69253 Flowise Sandbox Escape to RCE 05.08.2026 9
CVE-2026-69254 Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override 04.08.2026 9.4
CVE-2026-61514 Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 04.08.2026 9.3
CVE-2026-61515 Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell 05.08.2026 9.3
CVE-2026-69251 Flowise RCE via TypeORM DataSource 04.08.2026 9
CVE-2026-60007 04.08.2026 9.1
CVE-2026-14175 Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-14804 Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.1
CVE-2026-15721 Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-18753 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) 04.08.2026 9.1
CVE-2026-18754 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) 04.08.2026 9.1
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing 09.08.2026 9.8
CVE-2026-18686 GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection 04.08.2026 9.3
CVE-2026-18685 GL.iNet GL-MT3000 modem.so glc set_upgrade command injection 04.08.2026 9.3
CVE-2026-18684 GL.iNet GL-MT3000 modem.so glc remove_profile command injection 04.08.2026 9.3
CVE-2026-48317 Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 04.08.2026 9.6
CVE-2026-48323 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 04.08.2026 10
CVE-2026-48326 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 04.08.2026 9.9
CVE-2026-48330 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 05.08.2026 10
CVE-2026-48331 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 04.08.2026 10
CVE-2026-48333 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 04.08.2026 9.8
CVE-2026-18667 Sensor Proxy Version 1.4.2 Fixes One Vulnerability 05.08.2026 9.3
CVE-2026-46713 Misskey: JSON-LD signature validation + compaction may lead to improper activity handling 04.08.2026 9.2
CVE-2026-48063 Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload 04.08.2026 9.3
CVE-2026-69240 Sequelize: SQL Injection (Oracle DB) 04.08.2026 9.8
CVE-2026-48031 Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery 03.08.2026 9.1
CVE-2026-67598 Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php 04.08.2026 9.1
CVE-2026-18616 GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection 04.08.2026 9.3
CVE-2026-18614 GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection 03.08.2026 9.3
CVE-2026-18615 GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection 03.08.2026 9.3
CVE-2026-18612 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection 03.08.2026 9.3
CVE-2026-18613 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection 03.08.2026 9.3
CVE-2026-18602 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection 03.08.2026 9.3
CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection 03.08.2026 9.4
CVE-2026-41452 Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup 03.08.2026 9.3
CVE-2026-18248 @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header 03.08.2026 9.1
CVE-2026-18601 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection 03.08.2026 9.3
CVE-2026-64827 Telenia TVox 26.5.3 Authentication Bypass via set_env.php 07.08.2026 9.3
CVE-2026-68584 SiYuan before v3.7.3 Authentication Bypass via Content Endpoints 03.08.2026 9.2
CVE-2026-68586 SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc 03.08.2026 9.2
CVE-2026-68587 SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction 03.08.2026 9.2
CVE-2026-69083 SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent 03.08.2026 9.9
CVE-2026-69084 SiYuan before v3.7.3 SQL Injection via searchEmbedBlock 03.08.2026 9.9
CVE-2026-69085 SiYuan before v3.7.3 SQL Injection via searchDocs 03.08.2026 9.9
CVE-2026-18574 Authentication Bypass in Check Point Security Management Server 05.08.2026 9.3
CVE-2026-2346 IDOR in Menulux Software's Mobile App 03.08.2026 9.8
CVE-2026-33591 Authentication bypass on WaptServer 03.08.2026 10
CVE-2026-18588 Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow 03.08.2026 9.3
CVE-2026-18589 Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow 03.08.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-19358 3CORESec Trapdoor DefaultFunction access control 09.08.2026
CVE-2026-19357 MingSoft MCMS ms-mdiy get information disclosure 09.08.2026
CVE-2026-19356 MingSoft MCMS ms-mdiy list information disclosure 09.08.2026
CVE-2026-19354 lock-upme OPMS IN Clause message.go sql injection 09.08.2026
CVE-2026-19355 MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection 09.08.2026
CVE-2026-19353 DedeCMS Installation Wizard index.php _4_Setup file inclusion 09.08.2026
CVE-2026-19352 mifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery 09.08.2026
CVE-2026-19351 dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection 09.08.2026
CVE-2026-19350 Dolibarr ERP TakePOS invoice.php fail authorization 09.08.2026
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 09.08.2026
CVE-2026-19347 itsourcecode Hospital Management System viewdoctor.php sql injection 09.08.2026
CVE-2026-19346 Tenda CH22 CertListInfo formCertListInfo command injection 09.08.2026
CVE-2026-19345 code-projects Task Management System UpdateTaskStatus.php authorization 09.08.2026
CVE-2026-19344 code-projects Task Management System comment_count_user.php sql injection 09.08.2026
CVE-2026-19343 code-projects Task Management System AdminLogin.php sql injection 09.08.2026
CVE-2026-19342 code-projects Task Management System Login index.php improper authentication 09.08.2026
CVE-2026-19340 anubissbe ProjectHub-Mcp Webhooks API complete_backend.js server-side request forgery 09.08.2026
CVE-2026-19341 UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow 09.08.2026
CVE-2026-19339 aliyun alibabacloud-dataworks-mcp-server initResources.ts ReadResourceRequestSchema server-side request forgery 09.08.2026
CVE-2026-19338 automateyournetwork MCPyATS generate_mermaid_markdown index.ts processGenerateRequest path traversal 09.08.2026
CVE-2026-15038 InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite 09.08.2026
CVE-2026-16032 LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring 09.08.2026
CVE-2026-16957 Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure 09.08.2026
CVE-2026-16965 Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status 09.08.2026
CVE-2026-16988 GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint 09.08.2026
CVE-2026-16992 Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication 09.08.2026
CVE-2026-17011 Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection 09.08.2026
CVE-2026-17014 WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips 09.08.2026
CVE-2026-17017 CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation 09.08.2026
CVE-2026-17044 WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid 09.08.2026
CVE-2026-18032 WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass 09.08.2026
CVE-2026-18037 Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication 09.08.2026
CVE-2026-18357 WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure 09.08.2026
CVE-2026-18464 WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service 09.08.2026
CVE-2026-18465 WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion 09.08.2026
CVE-2026-18473 WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter 09.08.2026
CVE-2026-18603 Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure via Reorder AJAX Actions 09.08.2026
CVE-2026-19337 adenot mcp-google-search read_webpage index.ts server-side request forgery 09.08.2026
CVE-2026-19336 Pimzino spec-workflow-mcp approvals.ts ApprovalStorage.createApproval path traversal 09.08.2026
CVE-2026-19335 Jane-xiaoer skill-vision-control config.ts getSkillVersionsDir path traversal 09.08.2026
CVE-2026-19333 NightTrek Supabase-MCP generate_types command injection 09.08.2026
CVE-2026-19334 NightTrek Ollama-mcp index.ts command injection 09.08.2026
CVE-2026-19331 bazylhorsey obsidian-mcp-server CanvasService.ts writeCanvas path traversal 09.08.2026
CVE-2026-19332 NellyW8 MCP4EDA run_openlane/view_waveform command injection 09.08.2026