CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-28005 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-28139 WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-53975 OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec 06.08.2026 9.3
CVE-2026-53976 OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter 06.08.2026 9.3
CVE-2026-54489 06.08.2026 9.1
CVE-2026-65507 WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-65508 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65520 WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65546 WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65548 WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.9
CVE-2026-65552 WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65553 WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability 06.08.2026 10
CVE-2026-65556 WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65571 WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65572 WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65573 WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65574 WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65575 WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65576 WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65577 WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65578 WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65579 WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65581 WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-66447 WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-66665 WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability 06.08.2026 10
CVE-2026-66709 WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.1
CVE-2026-67261 06.08.2026 9.8
CVE-2026-12605 06.08.2026 9.6
CVE-2026-5134 SQLi in Loca Software's CMS 06.08.2026 9.8
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products 06.08.2026 9.4
CVE-2026-1728 Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover 06.08.2026 9.8
CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover 06.08.2026 10
CVE-2026-67531 FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool 05.08.2026 9.3
CVE-2026-71319 Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution 06.08.2026 9.6
CVE-2026-48168 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name 05.08.2026 10
CVE-2026-20267 Cisco IOS XE Software Security Hardening Release 06.08.2026 9
CVE-2026-20272 Cisco IOS XE Software Security Hardening Release 06.08.2026 9.8
CVE-2026-20303 Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities 06.08.2026 9.9
CVE-2026-20304 Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities 06.08.2026 9.9
CVE-2026-20310 Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access 06.08.2026 9.1
CVE-2026-7329 Privilege escalation in Progress MarkLogic Server REST query interfaces 05.08.2026 9.9
CVE-2026-7557 SAML authentication bypass in Progress MarkLogic Server 05.08.2026 9.1
CVE-2026-8709 Privilege escalation in Progress MarkLogic Server REST document patch operation 05.08.2026 9.9
CVE-2026-9190 HTTP request smuggling in Progress MarkLogic Server 05.08.2026 9.1
CVE-2026-9192 Authentication bypass in Progress MarkLogic Server ODBC App Server 05.08.2026 9.8
CVE-2026-9193 Privilege escalation in Progress MarkLogic Server Hadoop integration 05.08.2026 9.9
CVE-2026-9195 Cross-site scripting in Progress MarkLogic Server Query Console 05.08.2026 9.3
CVE-2026-15587 Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header 05.08.2026 9.4
CVE-2026-39923 Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset 05.08.2026 9.2
CVE-2026-71262 IoTSharp BlobStorageController Missing Authentication and Path Traversal 05.08.2026 9.8
CVE-2026-71263 FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() 05.08.2026 9.1
CVE-2026-71267 microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() 05.08.2026 9.8
CVE-2026-71268 OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write 05.08.2026 9.9
CVE-2026-71277 rust-iot-platform Authentication Bypass via Non-Validated Authorization Header 05.08.2026 9.1
CVE-2026-71278 rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation 05.08.2026 9.8
CVE-2026-71289 NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API 05.08.2026 9.8
CVE-2026-71254 nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() 05.08.2026 9.8
CVE-2026-71256 nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id 05.08.2026 9.8
CVE-2026-66747 ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant 05.08.2026 9.3
CVE-2026-71231 IOTSmartHome: Unauthenticated SQL Injection via lastLogin Cookie 05.08.2026 9.8
CVE-2026-71237 Miantang IoT-PHP: Unauthenticated SQL Injection in /userlogin 05.08.2026 9.8
CVE-2026-71238 DjangoCRM: Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery 05.08.2026 9.1
CVE-2026-71248 Inventory-Management-System-PHP: Unauthenticated SQL Injection in Login and Product Deletion 05.08.2026 9.8
CVE-2026-44945 Cross-Cluster Impersonation Confused-Deputy Privilege Escalation 06.08.2026 9.1
CVE-2026-10059 Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token 05.08.2026 9.1
CVE-2026-10090 Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription 05.08.2026 9.9
CVE-2026-4431 Easy Post Submission <= 2.3.0 - Missing Authorization 05.08.2026 9.1
CVE-2026-5581 Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion 05.08.2026 9.1
CVE-2026-70376 Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE 05.08.2026 9.6
CVE-2026-71207 Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass 05.08.2026 9.8
CVE-2026-71213 typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force 05.08.2026 9.1
CVE-2026-71214 NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server 05.08.2026 9.8
CVE-2026-9273 Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover 05.08.2026 9.3
CVE-2026-45537 OpenSIPS: Global Buffer Overflow in construct_uri 05.08.2026 9.1
CVE-2026-45100 OpenSIPS: Buffer Overflow in Base64 Encode Transformation 05.08.2026 9.1
CVE-2026-45538 OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy 05.08.2026 9.8
CVE-2026-70554 MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie 05.08.2026 9.3
CVE-2026-70477 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability 05.08.2026 9.5
CVE-2026-70478 Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service 05.08.2026 9.2
CVE-2026-70552 MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php 05.08.2026 9.3
CVE-2026-70553 MaxSite CMS Unauthenticated RCE via Install Endpoint 05.08.2026 9.3
CVE-2017-20241 Keysight IxChariot Endpoint heap-based buffer overflow 04.08.2026 9.3
CVE-2017-20242 Keysight IxChariot Endpoint stack-based buffer overflow 04.08.2026 9.3
CVE-2026-49435 Keysight IxChariot-related products stack-based buffer overflow 04.08.2026 9.3
CVE-2026-69703 Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit 04.08.2026 9.3
CVE-2026-24254 04.08.2026 9.8
CVE-2026-69264 Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation 04.08.2026 9.4
CVE-2026-70470 Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE 04.08.2026 9.5
CVE-2026-63455 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-63456 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-58072 05.08.2026 9
CVE-2026-58073 05.08.2026 9.5
CVE-2026-64633 05.08.2026 10
CVE-2026-69255 Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified 04.08.2026 9.2
CVE-2026-69256 Flowise: Remote Code Execution Vulnerability in CSVAgent 05.08.2026 9.4
CVE-2026-69259 Flowise RCE via SQLite Record Manager Node 04.08.2026 9.4
CVE-2026-18801 Stored Clickhouse SQL Injection Through Customer Usage Attribution 04.08.2026 9.3
CVE-2026-25289 Stack-based Buffer Overflow in WLAN Firmware 05.08.2026 9.6
CVE-2026-69098 kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization 05.08.2026 9.3
CVE-2026-69110 OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music 04.08.2026 9.3
CVE-2026-69253 Flowise Sandbox Escape to RCE 05.08.2026 9
CVE-2026-69254 Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override 04.08.2026 9.4
CVE-2026-61514 Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 04.08.2026 9.3
CVE-2026-61515 Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell 05.08.2026 9.3
CVE-2026-69251 Flowise RCE via TypeORM DataSource 04.08.2026 9
CVE-2026-60007 04.08.2026 9.1
CVE-2026-14175 Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-14804 Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.1
CVE-2026-15721 Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-18753 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) 04.08.2026 9.1
CVE-2026-18754 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) 04.08.2026 9.1
CVE-2026-18686 GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection 04.08.2026 9.3
CVE-2026-18685 GL.iNet GL-MT3000 modem.so glc set_upgrade command injection 04.08.2026 9.3
CVE-2026-18684 GL.iNet GL-MT3000 modem.so glc remove_profile command injection 04.08.2026 9.3
CVE-2026-48317 Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 04.08.2026 9.6
CVE-2026-48323 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 04.08.2026 10
CVE-2026-48326 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 04.08.2026 9.9
CVE-2026-48330 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 05.08.2026 10
CVE-2026-48331 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 04.08.2026 10
CVE-2026-48333 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 04.08.2026 9.8
CVE-2026-18667 Sensor Proxy Version 1.4.2 Fixes One Vulnerability 05.08.2026 9.3
CVE-2026-46713 Misskey: JSON-LD signature validation + compaction may lead to improper activity handling 04.08.2026 9.2
CVE-2026-48063 Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload 04.08.2026 9.3
CVE-2026-69240 Sequelize: SQL Injection (Oracle DB) 04.08.2026 9.8
CVE-2026-48031 Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery 03.08.2026 9.1
CVE-2026-67598 Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php 04.08.2026 9.1
CVE-2026-18616 GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection 04.08.2026 9.3
CVE-2026-18614 GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection 03.08.2026 9.3
CVE-2026-18615 GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection 03.08.2026 9.3
CVE-2026-18612 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection 03.08.2026 9.3
CVE-2026-18613 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection 03.08.2026 9.3
CVE-2026-18602 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection 03.08.2026 9.3
CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection 03.08.2026 9.4
CVE-2026-41452 Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup 03.08.2026 9.3
CVE-2026-18248 @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header 03.08.2026 9.1
CVE-2026-18601 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection 03.08.2026 9.3
CVE-2026-64827 Telenia TVox 26.5.3 Authentication Bypass via set_env.php 03.08.2026 9.3
CVE-2026-68584 SiYuan before v3.7.3 Authentication Bypass via Content Endpoints 03.08.2026 9.2
CVE-2026-68586 SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc 03.08.2026 9.2
CVE-2026-68587 SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction 03.08.2026 9.2
CVE-2026-69083 SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent 03.08.2026 9.9
CVE-2026-69084 SiYuan before v3.7.3 SQL Injection via searchEmbedBlock 03.08.2026 9.9
CVE-2026-69085 SiYuan before v3.7.3 SQL Injection via searchDocs 03.08.2026 9.9
CVE-2026-18574 Authentication Bypass in Check Point Security Management Server 05.08.2026 9.3
CVE-2026-2346 IDOR in Menulux Software's Mobile App 03.08.2026 9.8
CVE-2026-33591 Authentication bypass on WaptServer 03.08.2026 10
CVE-2026-18588 Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow 03.08.2026 9.3
CVE-2026-18589 Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow 03.08.2026 9.3
CVE-2026-58062 Stapled OCSP response accepted without binding to the checked certificate 03.08.2026 9.3
CVE-2026-59638 JSSE hostname verifier CN-fallback enabled by default despite documented opt-in 03.08.2026 9.3
CVE-2026-59650 MTI/A0 DH agreement exponentiates unvalidated peer value 03.08.2026 9.3
CVE-2026-8763 Name Constraints bypass via trailing dot in rfc822Name and URI 03.08.2026 9.3
CVE-2026-65321 PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS 03.08.2026 9.3
CVE-2025-71401 better-auth before 1.4.2 basePath Modification DoS 03.08.2026 9.3
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token 03.08.2026 9.3
CVE-2026-8457 WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT 03.08.2026 9.8
CVE-2026-66402 FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass 05.08.2026 9.3
CVE-2026-67289 FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection 05.08.2026 9.3
CVE-2026-67292 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure 03.08.2026 9.3
CVE-2026-67293 FreeRDP before 3.29.0 Improper Certificate Hostname Validation 05.08.2026 9.3
CVE-2026-67294 FreeRDP before 3.29.0 TLS Certificate EKU Bypass 03.08.2026 9.3
CVE-2026-67305 FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr 05.08.2026 9.4
CVE-2026-67308 Wazuh GitHub Actions Shell Injection via Fork Pull Request 03.08.2026 9.3
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options 05.08.2026 9.3
CVE-2026-67330 better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision 03.08.2026 9.4
CVE-2026-67336 better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider 03.08.2026 9.4
CVE-2026-67340 ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts 03.08.2026 9.3
CVE-2026-67341 ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION 03.08.2026 9.3
CVE-2026-67342 ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers 03.08.2026 9.3
CVE-2026-15964 Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change 03.08.2026 9.8
CVE-2026-3141 FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter 03.08.2026 9.1
CVE-2026-68771 ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization 03.08.2026 9.3
CVE-2026-68770 sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False 03.08.2026 9.3
CVE-2026-54725 vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API 31.07.2026 9.6
CVE-2026-52855 Wings exposes node configuration secrets through egg configuration-file templating 31.07.2026 9.9
CVE-2026-58048 01.08.2026 9.4
CVE-2026-17349 pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner 01.08.2026 9.3
CVE-2026-17351 pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) 01.08.2026 9.4
CVE-2026-17566 pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) 01.08.2026 9.4
CVE-2026-17561 Unauthenticated RCE in Innotim Software's Logsign SIEM 31.07.2026 9.8
CVE-2025-67649 Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script 31.07.2026 9.3
CVE-2026-14483 Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command 31.07.2026 9.8
CVE-2026-18452 Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials 31.07.2026 10
CVE-2026-63221 CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions 31.07.2026 9.4
CVE-2026-63223 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules 31.07.2026 9.8
CVE-2026-66418 OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field 31.07.2026 9.3
CVE-2026-68502 LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE 31.07.2026 9.8
CVE-2026-68503 LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard 31.07.2026 9.8
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability 03.08.2026 10

Latest Updates

CVE Title Updated Score
CVE-2026-18258 Authorization Bypass Through User-Controlled Key in eScriptorium 06.08.2026 8.8
CVE-2026-18275 Authorization Bypass Through User-Controlled Key in eScriptorium 06.08.2026 6.5
CVE-2026-18276 Missing Authorization in eScriptorium 06.08.2026 4.3
CVE-2026-18277 Missing Authorization in eScriptorium 06.08.2026 7.1
CVE-2026-18359 Server-Side Request Forgery (SSRF) in eScriptorium 06.08.2026 8.5
CVE-2026-18427 @fastify/static vulnerable to route guard bypass via non-canonical path segments 06.08.2026 7.5
CVE-2026-19046 NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts path traversal 06.08.2026
CVE-2026-19047 NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection 06.08.2026
CVE-2026-3430 Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi 06.08.2026 8.6
CVE-2026-43622 llama.cpp b1886–b7445 Double Free via llama-android.cpp 06.08.2026
CVE-2026-53977 OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown 06.08.2026
CVE-2026-53985 Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO 06.08.2026
CVE-2026-5423 Subscription Authentication Bypass via Unverified connectionParams.jwt 06.08.2026
CVE-2026-66370 html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking 06.08.2026
CVE-2026-66829 html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection 06.08.2026
CVE-2026-66843 html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding 06.08.2026
CVE-2026-68747 CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input 06.08.2026
CVE-2026-68749 Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service 06.08.2026
CVE-2026-68750 Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service 06.08.2026
CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack 06.08.2026
CVE-2026-15246 RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass 06.08.2026 4.3
CVE-2026-19044 LeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injection 06.08.2026
CVE-2026-19045 NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.showSecretDialog command injection 06.08.2026
CVE-2026-25403 WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access Control vulnerability 06.08.2026 6.5
CVE-2026-28005 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-28082 WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-28111 WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability 06.08.2026 8.8
CVE-2026-28139 WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-28140 WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability 06.08.2026 7.5
CVE-2026-28141 WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-28143 WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-28146 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.14 - Arbitrary File Download vulnerability 06.08.2026 6.5
CVE-2026-28169 WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data Exposure vulnerability 06.08.2026 5.3
CVE-2026-28172 WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerability 06.08.2026 7.1
CVE-2026-28177 WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-28178 WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability 06.08.2026 6.5
CVE-2026-28179 WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability 06.08.2026 5.9
CVE-2026-28180 WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Direct Object References (IDOR) vulnerability 06.08.2026 5.3
CVE-2026-28183 WordPress PublishPress Capabilities plugin <= 2.45.0 - Privilege Escalation vulnerability 06.08.2026 7.2
CVE-2026-32327 Apache Portable Runtime Utility: apr-util XML stack recursion crash 06.08.2026
CVE-2026-32469 WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability 06.08.2026 5.3
CVE-2026-32548 WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability 06.08.2026 5.3
CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle 06.08.2026
CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client 06.08.2026
CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client 06.08.2026
CVE-2026-53975 OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec 06.08.2026
CVE-2026-53976 OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter 06.08.2026
CVE-2026-54489 06.08.2026 9.1
CVE-2026-61959 WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vulnerability 06.08.2026 6.5
CVE-2026-61961 WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-61963 WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-61964 WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-61982 WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65502 WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability 06.08.2026 5.3
CVE-2026-65504 WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vulnerability 06.08.2026 7.5
CVE-2026-65507 WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-65508 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65509 WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65513 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65515 WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65517 WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65520 WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65523 WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0.1 - Insecure Direct Object References (IDOR) vulnerability 06.08.2026 7.5
CVE-2026-65541 WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability 06.08.2026 7.3
CVE-2026-65542 WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerability 06.08.2026 8.8
CVE-2026-65543 WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability 06.08.2026 7.5
CVE-2026-65544 WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65545 WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65546 WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65547 WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability 06.08.2026 8.5
CVE-2026-65548 WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.9
CVE-2026-65549 WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerability 06.08.2026 7.2
CVE-2026-65552 WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65553 WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability 06.08.2026 10
CVE-2026-65554 WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control vulnerability 06.08.2026 7.1
CVE-2026-65556 WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65559 WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability 06.08.2026 7.2
CVE-2026-65560 WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65565 WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-65569 WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability 06.08.2026 8.5
CVE-2026-65570 WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vulnerability 06.08.2026 8.1
CVE-2026-65571 WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65572 WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65573 WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65574 WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65575 WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65576 WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65577 WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65578 WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65579 WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65581 WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-66425 WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication vulnerability 06.08.2026 6.5
CVE-2026-66439 WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66440 WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66447 WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-66451 WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerability 06.08.2026 6.5
CVE-2026-66452 WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Broken Access Control vulnerability 06.08.2026 6.5
CVE-2026-66457 WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66470 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Control vulnerability 06.08.2026 7.1
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-66663 WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66664 WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66665 WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability 06.08.2026 10
CVE-2026-66678 WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken Access Control vulnerability 06.08.2026 4.3
CVE-2026-66681 WordPress theme My Login plugin <= 7.1.14 - Cross Site Request Forgery (CSRF) vulnerability 06.08.2026 4.3
CVE-2026-66683 WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposure vulnerability 06.08.2026 5.3
CVE-2026-66684 WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulnerability 06.08.2026 5.3
CVE-2026-66685 WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability 06.08.2026 5.3
CVE-2026-66686 WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross Site Request Forgery (CSRF) vulnerability 06.08.2026 6.5
CVE-2026-66688 WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability 06.08.2026 6.5
CVE-2026-66690 WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66692 WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Insecure Direct Object References (IDOR) vulnerability 06.08.2026 4.3
CVE-2026-66694 WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66695 WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability 06.08.2026 6.5
CVE-2026-66696 WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data Exposure vulnerability 06.08.2026 4.3
CVE-2026-66699 WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability 06.08.2026 5.3
CVE-2026-66701 WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability 06.08.2026 5.3
CVE-2026-66702 WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66703 WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability 06.08.2026 6.5
CVE-2026-66705 WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66706 WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability 06.08.2026 5.9
CVE-2026-66707 WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66708 WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability 06.08.2026 8.2
CVE-2026-66709 WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.1
CVE-2026-66710 WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability 06.08.2026 8.1
CVE-2026-66711 WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Site Scripting (XSS) vulnerability 06.08.2026 7.1
CVE-2026-66712 WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability 06.08.2026 7.5
CVE-2026-67261 06.08.2026 9.8
CVE-2026-70637 LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c 06.08.2026
CVE-2026-70646 aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler 06.08.2026 7.5
CVE-2026-12605 06.08.2026 9.6
CVE-2026-16315 Authentication and authorization bypass via cryptographic timing side-channel attack in StationGuard 06.08.2026
CVE-2026-16316 Malformed IEC 61850 Sampled Values frames cause partial denial of service in StationGuard 06.08.2026
CVE-2026-16731 Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout 06.08.2026
CVE-2026-18501 UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution 06.08.2026 6.4
CVE-2026-19040 MissionSquad mcp-api dcrClients.ts server-side request forgery 06.08.2026
CVE-2026-19041 MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection 06.08.2026
CVE-2026-5134 SQLi in Loca Software's CMS 06.08.2026 9.8
CVE-2026-64993 06.08.2026 6.8
CVE-2026-15599 Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner 06.08.2026 3.3
CVE-2026-19037 WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow 06.08.2026
CVE-2026-19038 MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotElement path traversal 06.08.2026
CVE-2026-19039 Kino-Kafkaesque ssh-mcp-server SSH index.ts ssh_exec command injection 06.08.2026
CVE-2026-65551 WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability 06.08.2026 7.5
CVE-2026-66732 Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager 06.08.2026
CVE-2026-66733 Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache 06.08.2026
CVE-2026-0673 Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection 06.08.2026 5.3
CVE-2026-19036 Shibby Tomato wanoptions sub_40F88C os command injection 06.08.2026
CVE-2026-70556 Hubzilla 11.2.1 CSRF via OAuth2 /authorize Endpoint App Registration 06.08.2026
CVE-2025-15028 FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting 06.08.2026 7.2
CVE-2025-9266 Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation 06.08.2026 4.3
CVE-2026-11983 Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via ai_ajax 06.08.2026 5.3
CVE-2026-19035 Shibby Tomato qoslimit new_qoslimit_start os command injection 06.08.2026
CVE-2026-57818 Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider 06.08.2026
CVE-2026-5158 PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block 06.08.2026 6.4
CVE-2026-5391 LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 06.08.2026 6.4
CVE-2026-61466 Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation 06.08.2026
CVE-2026-63687 Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters 06.08.2026
CVE-2026-65583 Apache CXF: Self-issued ID token claims validation skipped 06.08.2026
CVE-2026-68079 Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay 06.08.2026
CVE-2026-68481 Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider 06.08.2026
CVE-2026-8166 Stored XSS in Logo Software's e-Logo Purchasing Portal 06.08.2026 5.4
CVE-2026-19034 Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection 06.08.2026
CVE-2026-54225 Apache CXF: Denial of Service attack via large attachments 06.08.2026
CVE-2026-57817 Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow 06.08.2026
CVE-2026-57819 Apache CXF: No default restriction on the amount of form parameters per message 06.08.2026
CVE-2026-64958 Apache CXF: Denial of service via message header attachments 06.08.2026
CVE-2026-65432 Apache CXF: XXE via WSDL/XSD import parsing 06.08.2026
CVE-2026-66909 Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage 06.08.2026
CVE-2026-55978 Improper access control vulnerability in CatchPulse 06.08.2026 8.4
CVE-2026-55979 Improper access control check in CatchPulse's named pipe communication interface 06.08.2026 5.2
CVE-2026-55980 Denial-of-service vulnerability in CatchPulse 06.08.2026 5.5
CVE-2026-19022 OpenHands send_pull_request.py initialize_repo command injection 06.08.2026
CVE-2026-64640 Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation 06.08.2026
CVE-2024-10302 Improper Input Validation via Signup Process in Multiple WSO2 Products Enables Content Manipulation and Data Exposure 06.08.2026 4
CVE-2024-6832 Account Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force Attacks 06.08.2026 5.9
CVE-2024-8995 Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access 06.08.2026 4.9
CVE-2025-11850 Improper Implicit Association via User Store Initialization in WSO2 Identity Server [Identity Confusion / External IDP Use] 06.08.2026 4.3
CVE-2025-12627 Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Identity Server Enables Continued Unauthorized Actions 06.08.2026 2.4
CVE-2025-13394 Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Products Enables Unauthorized Actions 06.08.2026 5.4
CVE-2025-13736 Username Enumeration via Login Interface in Multiple WSO2 Products Allows User Account Discovery 06.08.2026 3.7
CVE-2025-13909 Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity Server Allows Cross-Tenant PII Exposure 06.08.2026 4.3
CVE-2025-14779 Improper Access Control via Secret Type Management API in WSO2 Identity Server 06.08.2026 3.8
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products 06.08.2026 9.4
CVE-2026-0637 Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2 Products 06.08.2026 4.4
CVE-2026-18597 Blind SSRF on Foxit PDF Services API 06.08.2026 8.5
CVE-2026-18915 Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock 06.08.2026 5
CVE-2026-19019 poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup 06.08.2026
CVE-2026-19020 itsourcecode Hospital Management System servicetype.php sql injection 06.08.2026
CVE-2026-19021 SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection 06.08.2026
CVE-2026-1728 Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover 06.08.2026 9.8
CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover 06.08.2026 10
CVE-2023-7353 06.08.2026
CVE-2023-7354 06.08.2026
CVE-2023-7355 06.08.2026
CVE-2026-18649 Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders 06.08.2026
CVE-2026-19008 mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following 06.08.2026
CVE-2026-19009 TinyAGI Message API Endpoint response.ts collectFiles file inclusion 06.08.2026
CVE-2026-19010 TinyAGI Message API Endpoint index.ts processMessage authorization 06.08.2026
CVE-2026-19011 TinyAGI agents.ts buildSystemPrompt file inclusion 06.08.2026
CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown 06.08.2026
CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object 06.08.2026
CVE-2026-64585 can: esd_usb: kill anchored URBs before freeing netdevs 06.08.2026
CVE-2026-64586 wifi: brcmfmac: drain bus_reset work on device removal 06.08.2026
CVE-2026-64587 net: ethernet: arc: emac: quiesce interrupts before requesting IRQ 06.08.2026
CVE-2026-64588 fuse-uring: fix data races on ring->ready 06.08.2026
CVE-2026-64589 i2c: core: fix NULL-deref on adapter registration failure 06.08.2026
CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning 06.08.2026
CVE-2026-64591 iommu/vt-d: Avoid WARNING in sva unbind path 06.08.2026
CVE-2026-64592 riscv: mm: Unconditionally sfence.vma for spurious fault 06.08.2026
CVE-2026-64593 btrfs: do not trim a device which is not writeable 06.08.2026
CVE-2026-64594 usb: gadget: f_fs: initialize reset_work at allocation time 06.08.2026
CVE-2026-64595 HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove() 06.08.2026
CVE-2026-64596 libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo() 06.08.2026
CVE-2026-64597 smb: client: fix double-free in SMB2_close() replay 06.08.2026
CVE-2026-64598 smb/client: Fix error code in smb2_aead_req_alloc() 06.08.2026
CVE-2026-64599 crypto: amlogic - avoid double cleanup in meson_crypto_probe() 06.08.2026
CVE-2026-64601 ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission 06.08.2026
CVE-2026-64602 iio: adc: spear: Initialize completion before requesting IRQ 06.08.2026
CVE-2026-64603 platform/x86: intel-hid: Protect ACPI notify handler against recursion 06.08.2026
CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode 06.08.2026
CVE-2025-15678 Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload 06.08.2026
CVE-2026-11588 EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation 06.08.2026
CVE-2026-12713 WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number 06.08.2026
CVE-2026-13153 Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint 06.08.2026
CVE-2026-13154 Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint 06.08.2026
CVE-2026-13703 SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect Rule Disclosure 06.08.2026
CVE-2026-14204 Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF 06.08.2026
CVE-2026-14240 Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export 06.08.2026
CVE-2026-14313 PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering via IDOR 06.08.2026
CVE-2026-14314 PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR 06.08.2026
CVE-2026-14547 Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form 06.08.2026
CVE-2026-14829 Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret 06.08.2026
CVE-2026-16054 Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated File Deletion via Nonce Oracle 06.08.2026
CVE-2026-16065 Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import 06.08.2026
CVE-2026-16268 Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler 06.08.2026
CVE-2026-16290 ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group 06.08.2026
CVE-2026-16537 Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode 06.08.2026
CVE-2026-16734 Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount Manipulation 06.08.2026
CVE-2026-16954 AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens 06.08.2026
CVE-2026-18050 Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads 06.08.2026
CVE-2026-18395 Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes 06.08.2026
CVE-2026-18400 Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting 06.08.2026 6.4
CVE-2026-18510 TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content 06.08.2026 7.2
CVE-2026-18967 Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow 06.08.2026
CVE-2026-19005 nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges management 06.08.2026
CVE-2026-19006 mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization 06.08.2026
CVE-2026-19007 mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management 06.08.2026
CVE-2026-15459 WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint 06.08.2026 8.1
CVE-2026-18997 cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization 06.08.2026
CVE-2026-18998 cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization 06.08.2026
CVE-2026-19000 JeecgBoot Anonymous Chat Attachment send server-side request forgery 06.08.2026
CVE-2026-15991 File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter 06.08.2026 8.8
CVE-2026-16636 FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs 06.08.2026 7.2
CVE-2026-18325 Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field 06.08.2026 7.2
CVE-2026-18909 06.08.2026
CVE-2026-18992 zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization 06.08.2026
CVE-2026-18993 NousResearch hermes-agent Memory Toolset model_tools.py access control 06.08.2026
CVE-2026-18995 netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure 06.08.2026
CVE-2026-18996 cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment 06.08.2026
CVE-2026-18990 letta-ai LettaBot API Status Route server.ts missing authentication 06.08.2026
CVE-2026-18991 nanocoai NanoClaw send_file core.ts path traversal 06.08.2026
CVE-2026-18976 NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment 06.08.2026
CVE-2026-18980 nearai ironclaw shell.rs classify_command_risk command injection 06.08.2026
CVE-2026-18973 heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery 06.08.2026
CVE-2026-18974 heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure 06.08.2026
CVE-2023-54375 05.08.2026
CVE-2023-54376 05.08.2026
CVE-2023-54377 05.08.2026
CVE-2023-54378 05.08.2026
CVE-2023-54379 05.08.2026
CVE-2023-54380 05.08.2026
CVE-2023-54381 05.08.2026
CVE-2023-54382 05.08.2026
CVE-2023-54383 05.08.2026
CVE-2023-54384 05.08.2026
CVE-2023-54385 05.08.2026
CVE-2023-54386 05.08.2026
CVE-2023-54387 05.08.2026
CVE-2023-54388 05.08.2026
CVE-2023-54389 06.08.2026
CVE-2026-18970 Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection 06.08.2026
CVE-2026-18969 Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload 06.08.2026
CVE-2026-52466 06.08.2026
CVE-2026-18968 ttttonyhe OBlog tags.php cross site scripting 06.08.2026
CVE-2026-19027 HDF5 out-of-bounds heap read in N-Bit filter decompression 06.08.2026
CVE-2026-19028 HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read 06.08.2026
CVE-2026-67531 FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool 05.08.2026
CVE-2026-67869 06.08.2026 7.5
CVE-2026-67870 05.08.2026
CVE-2026-67871 06.08.2026
CVE-2026-67872 06.08.2026
CVE-2026-67873 06.08.2026
CVE-2026-19025 HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open 06.08.2026
CVE-2026-19026 Nbit filter NULL/short parameter-array dereference 06.08.2026
CVE-2026-19023 HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets 06.08.2026
CVE-2026-19024 HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message 06.08.2026
CVE-2026-67863 06.08.2026 7.5
CVE-2026-67866 06.08.2026
CVE-2026-67867 06.08.2026
CVE-2025-63822 06.08.2026
CVE-2025-63823 06.08.2026
CVE-2026-67864 06.08.2026
CVE-2026-67865 06.08.2026
CVE-2026-71321 Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation 06.08.2026 7.5
CVE-2026-71316 Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients 05.08.2026 7.5
CVE-2026-71318 Nuxt: Unauthorized Component Instantiation via Server Island Props 06.08.2026 4.8
CVE-2026-71319 Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution 06.08.2026 9.6
CVE-2026-71320 Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props 06.08.2026 8.1
CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelp 06.08.2026
CVE-2026-71313 rclone: Local Encoding Path Traversal 06.08.2026 6.9
CVE-2026-71314 Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering 06.08.2026 7.5
CVE-2026-71315 Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) 06.08.2026 8.2
CVE-2026-15996 Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters 06.08.2026
CVE-2026-17583 Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check 06.08.2026 8.4
CVE-2026-18411 Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100 06.08.2026
CVE-2026-18959 yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal 05.08.2026
CVE-2026-34966 Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass 06.08.2026
CVE-2026-71309 rclone: Incomplete path validation allows backend root escape in serve restic 06.08.2026
CVE-2026-71310 rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory 06.08.2026 5.9
CVE-2026-71311 rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines 05.08.2026 6.4
CVE-2026-71312 rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution 06.08.2026 8
CVE-2026-21766 HCL Digital Experience and Digital Experience Compose insufficiently protects credentials 06.08.2026 5.4