CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-76008 Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow 19.08.2026 10
CVE-2026-76003 UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow 19.08.2026 9.4
CVE-2026-76004 UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow 19.08.2026 9.4
CVE-2026-11751 19.08.2026 9.1
CVE-2026-75976 TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow 18.08.2026 9.4
CVE-2026-70905 18.08.2026 9.8
CVE-2026-70920 18.08.2026 9.9
CVE-2026-70921 18.08.2026 10
CVE-2026-70926 18.08.2026 9.8
CVE-2026-70953 18.08.2026 9.8
CVE-2026-70954 18.08.2026 9.8
CVE-2026-70958 18.08.2026 9.6
CVE-2026-70970 18.08.2026 9.8
CVE-2026-70976 18.08.2026 9.1
CVE-2026-70977 18.08.2026 9.1
CVE-2026-70978 18.08.2026 9.1
CVE-2026-70979 18.08.2026 9.1
CVE-2026-70980 18.08.2026 9
CVE-2026-70981 18.08.2026 9.1
CVE-2026-70984 18.08.2026 9.1
CVE-2026-70994 18.08.2026 9.1
CVE-2026-70995 18.08.2026 9.8
CVE-2026-70997 18.08.2026 9.1
CVE-2026-70998 18.08.2026 9.3
CVE-2026-71014 18.08.2026 9.1
CVE-2026-71015 18.08.2026 9.1
CVE-2026-71026 18.08.2026 9.1
CVE-2026-71036 18.08.2026 9.1
CVE-2026-71037 18.08.2026 9.3
CVE-2026-71040 18.08.2026 9.8
CVE-2026-71059 18.08.2026 9.9
CVE-2026-71063 18.08.2026 9.6
CVE-2026-71064 18.08.2026 9.6
CVE-2026-71065 18.08.2026 9.3
CVE-2026-71074 18.08.2026 9.8
CVE-2026-71102 18.08.2026 9.1
CVE-2026-71152 18.08.2026 9.8
CVE-2026-71164 18.08.2026 9.8
CVE-2026-71166 18.08.2026 9.4
CVE-2026-71167 18.08.2026 9.4
CVE-2026-73865 18.08.2026 9.1
CVE-2026-73866 18.08.2026 9.1
CVE-2026-73905 18.08.2026 9.8
CVE-2026-73912 18.08.2026 9.8
CVE-2026-73916 18.08.2026 9.1
CVE-2026-73917 18.08.2026 9.1
CVE-2026-73920 18.08.2026 9.4
CVE-2026-73921 18.08.2026 9.8
CVE-2026-73922 18.08.2026 9.1
CVE-2026-73924 18.08.2026 9.1
CVE-2026-73930 18.08.2026 9.9
CVE-2026-60591 18.08.2026 9.1
CVE-2026-60672 18.08.2026 9.8
CVE-2026-60696 18.08.2026 9.8
CVE-2026-60698 18.08.2026 9.8
CVE-2026-60702 18.08.2026 9.9
CVE-2026-60720 18.08.2026 9.9
CVE-2026-60721 18.08.2026 9.8
CVE-2026-60727 18.08.2026 9.8
CVE-2026-60728 18.08.2026 9.1
CVE-2026-60730 18.08.2026 9.9
CVE-2026-60737 18.08.2026 9.1
CVE-2026-60754 18.08.2026 9.1
CVE-2026-60782 18.08.2026 9.8
CVE-2026-60821 18.08.2026 9.8
CVE-2026-60858 18.08.2026 9.8
CVE-2026-60861 18.08.2026 9.6
CVE-2026-60905 18.08.2026 9.6
CVE-2026-60916 18.08.2026 9.9
CVE-2026-60921 18.08.2026 9.8
CVE-2026-60946 18.08.2026 9.8
CVE-2026-60947 18.08.2026 9.8
CVE-2026-60958 18.08.2026 9.8
CVE-2026-60970 18.08.2026 9.8
CVE-2026-60971 18.08.2026 9.8
CVE-2026-60977 18.08.2026 9.8
CVE-2026-60990 18.08.2026 9.9
CVE-2026-60995 18.08.2026 9.9
CVE-2026-61001 18.08.2026 9.6
CVE-2026-61003 18.08.2026 9.9
CVE-2026-61008 18.08.2026 9.1
CVE-2026-61018 18.08.2026 9.8
CVE-2026-61021 18.08.2026 9.9
CVE-2026-61029 18.08.2026 9
CVE-2026-61034 18.08.2026 9.1
CVE-2026-61066 18.08.2026 9.9
CVE-2026-61206 18.08.2026 9.9
CVE-2026-61241 18.08.2026 10
CVE-2026-61248 18.08.2026 9.9
CVE-2026-61258 18.08.2026 9.8
CVE-2026-61272 18.08.2026 9.8
CVE-2026-61317 18.08.2026 9.9
CVE-2026-61318 18.08.2026 9.8
CVE-2026-62452 18.08.2026 9.9
CVE-2026-62457 18.08.2026 9.8
CVE-2026-62463 18.08.2026 9.6
CVE-2026-62512 18.08.2026 9.9
CVE-2026-62539 18.08.2026 9.8
CVE-2026-62541 18.08.2026 9.8
CVE-2026-62543 18.08.2026 9.8
CVE-2026-62544 18.08.2026 9.8
CVE-2026-62582 18.08.2026 9.6
CVE-2026-62585 18.08.2026 9.8
CVE-2026-62588 18.08.2026 9.9
CVE-2026-62592 18.08.2026 9.8
CVE-2026-62608 18.08.2026 9.9
CVE-2026-62609 18.08.2026 9.8
CVE-2026-62610 18.08.2026 9.1
CVE-2026-62611 18.08.2026 9.8
CVE-2026-62613 18.08.2026 9.3
CVE-2026-62614 18.08.2026 9.8
CVE-2026-62617 18.08.2026 9.8
CVE-2026-62618 18.08.2026 9.3
CVE-2026-62621 18.08.2026 9.8
CVE-2026-62622 18.08.2026 9.8
CVE-2026-62624 18.08.2026 9.8
CVE-2026-62626 18.08.2026 9.8
CVE-2026-62629 18.08.2026 9.4
CVE-2026-62630 18.08.2026 9.8
CVE-2026-62632 18.08.2026 9.8
CVE-2026-62633 18.08.2026 9.8
CVE-2026-62634 18.08.2026 9.8
CVE-2026-62635 18.08.2026 9.8
CVE-2026-62637 18.08.2026 9.3
CVE-2026-62638 18.08.2026 9.1
CVE-2026-62639 18.08.2026 9.8
CVE-2026-62640 18.08.2026 9.8
CVE-2026-70668 18.08.2026 9.1
CVE-2026-70669 18.08.2026 9.8
CVE-2026-70670 18.08.2026 9.6
CVE-2026-70673 18.08.2026 9.3
CVE-2026-70689 18.08.2026 9.8
CVE-2026-70730 18.08.2026 9.1
CVE-2026-70739 18.08.2026 9.8
CVE-2026-70740 18.08.2026 9.8
CVE-2026-70741 18.08.2026 9.1
CVE-2026-70745 18.08.2026 9.8
CVE-2026-70817 18.08.2026 9.8
CVE-2026-70846 18.08.2026 9.6
CVE-2026-70854 18.08.2026 9.1
CVE-2026-70855 18.08.2026 9.3
CVE-2026-70862 18.08.2026 9.1
CVE-2026-70871 18.08.2026 9.8
CVE-2026-70872 18.08.2026 9.1
CVE-2026-70873 18.08.2026 9.8
CVE-2026-70876 18.08.2026 9.1
CVE-2026-70880 18.08.2026 10
CVE-2026-70883 18.08.2026 9.1
CVE-2026-70884 18.08.2026 9.1
CVE-2026-62988 Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints 18.08.2026 9
CVE-2026-67443 FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) 18.08.2026 9.2
CVE-2026-75877 TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow 18.08.2026 9.4
CVE-2026-52735 ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser 18.08.2026 9.3
CVE-2026-55166 Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR 18.08.2026 9.9
CVE-2026-47627 18.08.2026 9.8
CVE-2026-50161 libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow 18.08.2026 9.3
CVE-2026-75625 Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass 18.08.2026 9.1
CVE-2026-71878 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.2
CVE-2026-71879 Authentication bypass in Integrated Publishing Toolkit 18.08.2026 9.1
CVE-2026-66780 Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace 18.08.2026 9.9
CVE-2026-18963 Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass 19.08.2026 9.1
CVE-2026-57580 authentik: Account Takeover via SAML NameID Comment Truncation 18.08.2026 9.4
CVE-2026-52723 ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust 18.08.2026 9.1
CVE-2026-67271 19.08.2026 9.8
CVE-2026-45118 MyBB: Contact page reflected XSS 18.08.2026 9.3
CVE-2026-12564 Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf 18.08.2026 9.6
CVE-2026-45117 MyBB: Installer database configuration RCE 18.08.2026 9.8
CVE-2026-75926 Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant 18.08.2026 9.3
CVE-2026-75856 CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU 18.08.2026 9.2
CVE-2026-59940 Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization 18.08.2026 9.8
CVE-2026-32470 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-32474 WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-66627 WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-73187 WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73339 WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73341 WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73343 WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability 18.08.2026 10
CVE-2026-73355 WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73365 WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73366 WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73376 WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73380 WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73381 WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability 18.08.2026 9.1
CVE-2026-73392 WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73397 WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability 18.08.2026 9.8
CVE-2026-73996 WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability 18.08.2026 9.8
CVE-2026-74015 WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-75784 TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow 18.08.2026 10
CVE-2026-28192 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability 18.08.2026 9.6
CVE-2026-32444 WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability 18.08.2026 9.9
CVE-2026-32463 WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-75783 TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow 18.08.2026 9.4
CVE-2026-74902 SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload 18.08.2026 9.3
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log 18.08.2026 9.3
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass 18.08.2026 9.3
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass 18.08.2026 9.3
CVE-2026-75835 Grav API Plugin before 1.0.14 Missing Authorization 18.08.2026 9.3
CVE-2026-75837 Grav before 2.0.14 Privilege Escalation via Group Access Field 18.08.2026 9.3
CVE-2026-75843 ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction 18.08.2026 9.4
CVE-2026-75851 ArcadeDB before 26.8.1 Authentication Bypass via Async Command 18.08.2026 9.4
CVE-2026-75852 ArcadeDB MongoDB wire protocol authentication bypass cross-database 18.08.2026 9.3
CVE-2026-75854 ArcadeDB Redis Wire-Protocol Plugin Missing Authentication 18.08.2026 9.3
CVE-2026-75626 SpiderFoot Stored Cross-Site Scripting via Correlation Titles 18.08.2026 9.3
CVE-2026-75627 Bastillion Authentication Bypass via Path-Prefix Routing Mismatch 18.08.2026 9.3
CVE-2026-15748 Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration 18.08.2026 9.8
CVE-2026-75094 COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection 18.08.2026 9.4
CVE-2026-71424 Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers 18.08.2026 9.6
CVE-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) 19.08.2026 9.3
CVE-2026-47686 vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE 19.08.2026 9.9
CVE-2026-47698 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators 19.08.2026 9.8
CVE-2026-65974 ERPNext: Server-Side Template Injection leading to Remote Code Execution 18.08.2026 9.9
CVE-2026-66795 Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does not validate certificate subject, signername, or requester identity 18.08.2026 9.1
CVE-2026-75106 OpnForm Editable Submission Secret Derivation via Empty Hashids Salt 18.08.2026 9.3
CVE-2026-75110 MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET 18.08.2026 9.3
CVE-2026-19478 Improper Control of Generation of Code ('Code Injection') in GitLab 17.08.2026 9.4
CVE-2026-71472 Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem 17.08.2026 9.1
CVE-2026-66792 Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clusters 18.08.2026 9.9
CVE-2026-74253 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 17.08.2026 10
CVE-2026-74254 Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 18.08.2026 9.3
CVE-2026-71479 New API: Integer overflow in quota billing yields negative charges (self-crediting) 17.08.2026 9.1
CVE-2026-75045 18.08.2026 9.1
CVE-2026-64859 New API: User List API Leaks Root User Access Token Leading to Privilege Escalation 17.08.2026 9.1
CVE-2026-55674 Discourse: Cache poisoning/XSS via color scheme cookies 18.08.2026 9.3
CVE-2026-71566 KubeVirt backend is not authenticated 17.08.2026 9.3
CVE-2026-14564 Sensitive Data Exposure in Innotim Software's Logsign SIEM 17.08.2026 9
CVE-2026-74843 Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow 17.08.2026 10
CVE-2026-74798 SiYuan kernel Path Traversal via database_clean MCP tool 18.08.2026 9.3
CVE-2026-74799 SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure 17.08.2026 9.2
CVE-2026-74800 SiYuan before v3.7.4 Stored XSS via assets endpoint 17.08.2026 9.4
CVE-2026-74872 openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool 18.08.2026 9.3
CVE-2026-74875 openssl_encrypt before 1.4.0 Schema Validation Bypass 17.08.2026 9.3
CVE-2026-74876 openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption 17.08.2026 9.3
CVE-2026-74878 openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass 17.08.2026 9.3
CVE-2026-74880 openssl_encrypt before 1.4.0 Token Leakage via Query Parameters 17.08.2026 9.3
CVE-2026-74885 openssl_encrypt before 1.4.0 Logging Bug and Race Condition 17.08.2026 9.3
CVE-2026-74886 openssl_encrypt before 1.4.0 Plugin Import Guard Bypass 17.08.2026 9.3
CVE-2026-74887 openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module 18.08.2026 9.3
CVE-2026-74889 openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF 17.08.2026 9.3
CVE-2026-74890 openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable 17.08.2026 9.3
CVE-2026-74894 openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token 17.08.2026 9.3
CVE-2026-74895 openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation 17.08.2026 9.3
CVE-2026-74896 openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal 17.08.2026 9.3
CVE-2026-74899 openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy 18.08.2026 9.3
CVE-2026-74900 openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode 17.08.2026 9.3
CVE-2026-74901 openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback 17.08.2026 9.3
CVE-2026-15623 Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service 17.08.2026 9.4
CVE-2026-19977 EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication 18.08.2026 10
CVE-2026-19961 Edimax EW-7478APC formWlSiteSurvey buffer overflow 17.08.2026 9.4
CVE-2026-19959 Edimax EW-7478APC formWanTcpipSetup stack-based overflow 18.08.2026 9.4
CVE-2026-73056 SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token 17.08.2026 9.3
CVE-2026-73061 Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor 17.08.2026 9.3
CVE-2026-74790 Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache 17.08.2026 9.3
CVE-2026-74791 Scriban before 7.0.0 Authorization Bypass via Stale Include Cache 17.08.2026 9.2
CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 18.08.2026 9.3
CVE-2024-13784 Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection 17.08.2026 9.8
CVE-2026-18316 Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action 17.08.2026 9.1
CVE-2026-14524 ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters 17.08.2026 9.1
CVE-2026-16098 ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override 18.08.2026 9.8
CVE-2026-18432 Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter 18.08.2026 9.8
CVE-2026-19924 Tenda AC10 httpd R7WebsSecurityHandler improper authentication 16.08.2026 9.3
CVE-2026-73041 SiYuan before v3.7.4 Remote Code Execution via PDF Annotations 17.08.2026 9.4
CVE-2026-73042 SiYuan before v3.7.4 Remote Code Execution via Menu Metadata 17.08.2026 9.4
CVE-2026-73043 SiYuan before v3.7.4 Remote Code Execution via Template Calculation 17.08.2026 9.4
CVE-2026-73044 SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width 17.08.2026 9.4
CVE-2026-73046 SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth 17.08.2026 9.3
CVE-2026-73050 SiYuan before v3.7.4 Stored XSS via select option color 17.08.2026 9.4
CVE-2026-73052 SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names 17.08.2026 9.4
CVE-2026-73053 SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji 18.08.2026 9.4
CVE-2026-73055 Shescape before 2.1.15 Home Directory Disclosure via BusyBox 17.08.2026 9.3
CVE-2026-74764 Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora 17.08.2026 10
CVE-2026-18855 Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter 17.08.2026 9.1
CVE-2026-19598 Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router 17.08.2026 9.8
CVE-2026-19901 LB-LINK X-PRO easycwmp hard-coded credentials 18.08.2026 9.2
CVE-2026-19900 LB-LINK X-PRO shadow hard-coded credentials 17.08.2026 9.2
CVE-2026-74473 vxlan: use pskb_network_may_pull() in route_shortcircuit() 17.08.2026 9.8
CVE-2026-74474 vxlan: use pskb_network_may_pull() for transmit path header pulls 17.08.2026 9.8
CVE-2026-74475 vxlan: use neigh_ha_snapshot() in route_shortcircuit() 17.08.2026 10
CVE-2026-74476 veth: convert frag_list skbs before running XDP 17.08.2026 9.1
CVE-2026-74478 um: vector: fix use-after-free in vector_mmsg_rx() 17.08.2026 9.8
CVE-2026-74480 net: bridge: stop fast-leave after deleting a port group 17.08.2026 9.8
CVE-2026-74493 net/smc: fix socket use-after-free during link group termination 17.08.2026 9.8
CVE-2026-74495 igbvf: Fix leak in TX DMA error cleanup 17.08.2026 9.8
CVE-2026-74517 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs 17.08.2026 9.3
CVE-2026-74521 ksmbd: use memcmp() to compare ClientGUIDs 17.08.2026 9.1
CVE-2026-74545 rtase: fix double free of multi-frag skb on DMA map failure 17.08.2026 9.8
CVE-2026-74556 scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer 17.08.2026 9.8
CVE-2026-74568 KVM: arm64: vgic: Fix race between LPI release and re-registration 17.08.2026 9.3
CVE-2026-74569 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() 17.08.2026 9.8
CVE-2026-74570 ntfs: harden runlist realloc size calculations 17.08.2026 9.8
CVE-2026-74573 iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE 17.08.2026 9.3
CVE-2026-16142 TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter 17.08.2026 9.8
CVE-2026-15826 User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter 17.08.2026 9.8
CVE-2026-72496 RDMA/bnxt_re: Proper rollback if the ioremap fails 17.08.2026 9.2
CVE-2026-74255 tipc: fix UAF in tipc_l2_send_msg() 17.08.2026 9.8
CVE-2026-74267 net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 17.08.2026 9.8
CVE-2026-74268 tcp: clear sock_ops cb flags before force-closing a child socket 17.08.2026 9.8
CVE-2026-74269 bnxt: fix head underflow on XDP head-grow 17.08.2026 9.8
CVE-2026-74279 crypto: cavium/cpt - fix DMA cleanup using wrong loop index 17.08.2026 10
CVE-2026-74280 crypto: marvell/octeontx - fix DMA cleanup using wrong loop index 17.08.2026 10
CVE-2026-74287 sctp: validate embedded address parameter length 17.08.2026 9.1
CVE-2026-74309 vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler 17.08.2026 10
CVE-2026-74310 vhost/net: complete zerocopy ubufs only once 17.08.2026 9.3
CVE-2026-74315 lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() 17.08.2026 9.8
CVE-2026-74345 RDMA/siw: Fix endpoint/socket association handling 17.08.2026 9.8
CVE-2026-74350 ocfs2: validate fast symlink target during inode read 17.08.2026 9.8
CVE-2026-74361 nvme: fix FDP fdpcidx bounds check 17.08.2026 9.8
CVE-2026-74376 md/raid10: reset read_slot when reusing r10bio for discard 17.08.2026 9.8
CVE-2026-74384 nvme-multipath: fix flex array size in struct nvme_ns_head 17.08.2026 9.8
CVE-2026-74394 RDMA/srpt: fix integer overflow in immediate data length check 17.08.2026 9.8
CVE-2026-74398 ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD 17.08.2026 9.8
CVE-2026-74401 dlm: fix add msg handle in send_queue ordered 17.08.2026 9.8
CVE-2026-74406 vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). 17.08.2026 9.8
CVE-2026-74427 afs: Fix netns teardown to cancel the preallocation charger 17.08.2026 9.8
CVE-2026-74428 rxrpc: Fix double unlock in rxrpc_recvmsg() 17.08.2026 9.8
CVE-2026-74433 rxrpc: Fix UAF in rxgk_issue_challenge() 17.08.2026 9.8
CVE-2026-74434 rxrpc: Don't move a peeked OOB message onto the pending queue 17.08.2026 9.8
CVE-2026-74436 rxrpc: serialize kernel accept preallocation with socket teardown 17.08.2026 9.8
CVE-2026-74439 iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry 17.08.2026 9.3
CVE-2026-68457 ksmbd: use opener credentials for FSCTL mutations 18.08.2026 9.1
CVE-2026-68476 ipvs: reload ip header after head reallocation 17.08.2026 9.8
CVE-2026-68477 ipvs: fix more places with wrong ipv6 transport offsets 17.08.2026 9.8
CVE-2026-72014 drbd: reject data replies with an out-of-range payload size 17.08.2026 9.8
CVE-2026-72020 ipvs: reset full ip_vs_seq structs in ip_vs_conn_new 17.08.2026 9.8
CVE-2026-72033 orangefs: keep the readdir entry size 64-bit in fill_from_part() 17.08.2026 9.8
CVE-2026-72041 espintcp: use sk_msg_free_partial to fix partial send 17.08.2026 9.8
CVE-2026-72046 gve: fix header buffer corruption with header-split and HW-GRO 17.08.2026 9.8
CVE-2026-72064 net: mana: Sync page pool RX frags for CPU 17.08.2026 9.8
CVE-2026-72065 net: mana: Validate the packet length reported by the NIC 17.08.2026 9.8
CVE-2026-72069 locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() 17.08.2026 9.8
CVE-2026-72083 scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE 17.08.2026 9.8
CVE-2026-72084 scsi: target: Bound PR-OUT TransportID parsing to the received buffer 17.08.2026 9.8
CVE-2026-72085 scsi: xen: scsiback: Free unsubmitted command instead of double-putting it 17.08.2026 9.3
CVE-2026-72098 dm-verity: fix buffer overflow in FEC calculation 17.08.2026 9.8
CVE-2026-72129 nvmet-rdma: handle inline data with a nonzero offset 17.08.2026 9.8
CVE-2026-72130 nvmet-auth: reject short AUTH_RECEIVE buffers 17.08.2026 9.8
CVE-2026-72137 xfrm: nat_keepalive: avoid double free on send error 17.08.2026 9.8
CVE-2026-72139 tcp: defer md5sig_info kfree past RCU grace period in tcp_connect 17.08.2026 9.8
CVE-2026-72185 ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() 17.08.2026 9.8
CVE-2026-72186 ntfs: make system files immutable to prevent corruption 17.08.2026 9.1
CVE-2026-72188 ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name() 17.08.2026 9.1
CVE-2026-72191 ntfs3: validate split-point offset in indx_insert_into_buffer 17.08.2026 9.8
CVE-2026-72192 ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head 17.08.2026 9.8
CVE-2026-72194 fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow 17.08.2026 9.8
CVE-2026-72199 ntfs: validate resident index root values on lookup 18.08.2026 9.8
CVE-2026-72200 ntfs: detect mapping-pairs LCN accumulator overflow 19.08.2026 9.8
CVE-2026-72201 ntfs: validate index entries on reading 18.08.2026 9.8
CVE-2026-72206 ntfs: validate index block header more strictly 18.08.2026 9.8
CVE-2026-72207 ntfs: not change 0-byte $DATA attribute to non-resident 18.08.2026 9.8
CVE-2026-72208 ntfs: add bounds check before accessing EA entries 18.08.2026 9.8
CVE-2026-72209 ntfs: validate attribute values on lookup 17.08.2026 9.8
CVE-2026-72210 ntfs: fix off-by-one in mapping pairs decoding bounds checks 19.08.2026 9.8
CVE-2026-72211 ntfs: grow index root value before reparent header update 18.08.2026 9.8
CVE-2026-72217 SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing 17.08.2026 9.8
CVE-2026-72220 sunrpc: harden rq_procinfo lifecycle to prevent double-free 17.08.2026 9.8
CVE-2026-72221 sunrpc: wait for in-flight TLS handshake callback when cancel loses race 17.08.2026 9.8
CVE-2026-72222 sunrpc: pin svc_xprt across the asynchronous TLS handshake callback 17.08.2026 9.8
CVE-2026-72226 batman-adv: tt: prevent TVLV OOB check overflow 17.08.2026 9.8
CVE-2026-72234 batman-adv: access unicast_ttvn skb->data only after skb realloc 17.08.2026 9.8
CVE-2026-72239 x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" 17.08.2026 9.3
CVE-2026-72248 netfilter: flowtable: support IPIP tunnel with direct xmit 17.08.2026 9.8
CVE-2026-72249 netfilter: flowtable: use dst in this direction when pushing IPIP header 17.08.2026 9.8
CVE-2026-72251 netfilter: nf_nat_sip: reload possible stale data pointer 17.08.2026 9.8
CVE-2026-72277 KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory 17.08.2026 9.3
CVE-2026-72278 KVM: arm64: nv: Re-translate VNCR before injecting abort 17.08.2026 9.3
CVE-2026-72279 KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR 17.08.2026 9
CVE-2026-72288 KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling 17.08.2026 9.3
CVE-2026-72289 KVM: arm64: vgic: Check the interrupt is still ours before migrating it 17.08.2026 9.3
CVE-2026-72291 KVM: s390: Fix unlikely race in try_get_locked_pte() 17.08.2026 9.3
CVE-2026-72296 net: ife: require ETH_HLEN to be pullable in ife_decode() 17.08.2026 9.1
CVE-2026-72299 tipc: restrict socket queue dumps in enqueue tracepoints 17.08.2026 9.8
CVE-2026-72317 SUNRPC: pin upper rpc_clnt across the TLS connect_worker 17.08.2026 9.8
CVE-2026-72318 cifs: validate DFS referral string offsets 17.08.2026 9.4
CVE-2026-72319 ipvs: ensure inner headers in ICMP errors are in headroom 17.08.2026 9.8
CVE-2026-72320 netfilter: nft_lookup: fix catchall element handling with inverted lookups 17.08.2026 9.1
CVE-2026-72322 ipv6: mcast: Fix potential UAF in MLD delayed work 17.08.2026 9.8
CVE-2026-72323 ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() 17.08.2026 9.8
CVE-2026-72329 net/liquidio: drop cached VF pci_dev LUT 17.08.2026 9.3
CVE-2026-72339 qede: fix off-by-one in BD ring consumption on build_skb failure 17.08.2026 9.8
CVE-2026-72348 netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop 17.08.2026 9.1
CVE-2026-72351 gue: validate REMCSUM private option length 17.08.2026 9.8
CVE-2026-72355 netfs: Fix barriering when walking subrequest list 17.08.2026 9.8
CVE-2026-72366 netfs: Fix netfs_create_write_req() to handle async cache object creation 17.08.2026 9.8
CVE-2026-72381 ksmbd: fix use-after-free of fp->owner.name in durable handle owner check 17.08.2026 9.8
CVE-2026-72393 eth: fbnic: don't cache shinfo across skb realloc 17.08.2026 9.8
CVE-2026-72398 sctp: add INIT verification after cookie unpacking 17.08.2026 9.8
CVE-2026-72399 net: enetc: check the number of BDs needed for xdp_frame 17.08.2026 9.8
CVE-2026-72407 geneve: validate inner network offset in geneve_gro_complete() 17.08.2026 10
CVE-2026-72408 geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint 17.08.2026 10
CVE-2026-72412 s390/mm: Fix handling of _PAGE_UNUSED pte bit 17.08.2026 9.3
CVE-2026-72417 netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() 17.08.2026 9.8
CVE-2026-72421 ipv4: fib: Don't ignore error route in local/main tables. 17.08.2026 10
CVE-2026-72422 ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE 17.08.2026 9.8
CVE-2026-72429 ipv6: ioam: fix type confusion of dst_entry 17.08.2026 9.8
CVE-2026-72436 netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types 17.08.2026 9.8
CVE-2026-72442 netfilter: flowtable: fix and simplify IP6IP6 tunnel handling 17.08.2026 9.8
CVE-2026-72451 xfrm: Fix xfrm state cache insertion race 17.08.2026 9.8
CVE-2026-72463 xfrm: Fix dev use-after-free in xfrm async resumption 17.08.2026 9.8
CVE-2026-72466 xprtrdma: Fix bcall rep leak and unbounded peek 17.08.2026 9.8
CVE-2026-72472 nfs: use nfsi->rwsem to protect traversal of the file lock list 17.08.2026 9.8
CVE-2026-72473 xprtrdma: Decouple req recycling from RPC completion 17.08.2026 9.8
CVE-2026-72477 fs/ntfs3: call _ntfs_bad_inode() when failing to rename 17.08.2026 9.8
CVE-2026-72491 net/9p: fix race condition on rdma->state in trans_rdma.c 17.08.2026 9.8
CVE-2026-72493 net: serialize netif_running() check in enqueue_to_backlog() 17.08.2026 9.9
CVE-2026-72494 RDMA/irdma: Replace waitqueue and flag with completion 17.08.2026 9.8
CVE-2026-72495 RDMA/bnxt_re: Avoid repeated requests to allocate WC pages 17.08.2026 9.3
CVE-2026-14484 RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters 17.08.2026 9.1
CVE-2026-15303 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter 17.08.2026 9.8
CVE-2026-15341 User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters 17.08.2026 9.8
CVE-2026-73683 Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay 18.08.2026 9.2
CVE-2026-67365 Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 18.08.2026 9.2
CVE-2026-17181 IBM Db2 Mirror for i is affected by multiple vulnerabilities 18.08.2026 9.3
CVE-2026-17182 IBM Db2 Mirror for i is affected by multiple vulnerabilities 17.08.2026 9.8
CVE-2026-17184 IBM Db2 Mirror for i is affected by multiple vulnerabilities 18.08.2026 9.8
CVE-2026-17186 IBM Db2 Mirror for i is affected by multiple vulnerabilities 17.08.2026 9.9
CVE-2026-50027 mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete 17.08.2026 9.8
CVE-2026-73678 MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec() 17.08.2026 10
CVE-2026-19188 Haiwell IoT Cloud HMI Gateway OS Command Injection 14.08.2026 10
CVE-2026-49457 QUIC has Broken TLS verification 14.08.2026 9.1
CVE-2026-19681 Command Injection 15.08.2026 9.4
CVE-2026-19682 Command Injection 15.08.2026 9.4
CVE-2026-48528 Metacat has an unauthenticated SQL injection vulnerability 17.08.2026 9.8
CVE-2026-73849 emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. 18.08.2026 9.8
CVE-2026-19626 Remote Code Execution 15.08.2026 9.4
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding 14.08.2026 9.3
CVE-2026-72810 SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket 18.08.2026 9.2
CVE-2026-72811 SiYuan before v3.7.4 SQL Injection via backlink search 14.08.2026 9.9
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa 14.08.2026 9.3
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController 14.08.2026 9.3
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey 18.08.2026 9.3
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController 14.08.2026 9.3
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass 14.08.2026 9.3
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass 18.08.2026 9.2
CVE-2026-12949 Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter 14.08.2026 9.8
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup 14.08.2026 9.3
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 18.08.2026 9.4
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass 14.08.2026 9.4
CVE-2026-72850 Budibase before 3.40.0 Arbitrary File Write via Path Traversal 14.08.2026 9.4
CVE-2026-72851 Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook 14.08.2026 9
CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified 14.08.2026 9
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 14.08.2026 9.1
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 18.08.2026 9.1
CVE-2026-73842 OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation 18.08.2026 9
CVE-2026-73843 OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs 14.08.2026 9.6
CVE-2026-73665 FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection 18.08.2026 9.3
CVE-2026-19750 Tenda CH/CP/TX3 SSH hard-coded password 14.08.2026 9.2
CVE-2026-72776 AgenticSeek Unauthenticated RCE via /query API Endpoint 18.08.2026 9.3
CVE-2026-73663 FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover 14.08.2026 9.3
CVE-2026-17482 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 17.08.2026 9.8
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint 15.08.2026 9.1
CVE-2026-8715 Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath 14.08.2026 9.6
CVE-2026-19747 Tenda CH7 ATE Module Kylin HandleCmd command injection 14.08.2026 9.3
CVE-2026-73656 Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state 14.08.2026 9.9
CVE-2026-14525 IBM WebSphere Application Server Liberty is affected by an authenication bypass 15.08.2026 9.4
CVE-2026-73653 Vitest: Browser Mode provider commands bypass the file-access permission gate 13.08.2026 9.4
CVE-2026-73644 OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant 18.08.2026 9.6
CVE-2026-73649 Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) 14.08.2026 9.8
CVE-2026-73567 sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock 14.08.2026 9.1
CVE-2026-67614 CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal 14.08.2026 9.3
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build 14.08.2026 9.3
CVE-2026-73533 Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build 17.08.2026 9.3
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths 14.08.2026 9.2
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header 14.08.2026 9.1
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode 14.08.2026 9.1
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure 14.08.2026 9.1
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink 14.08.2026 9.2
CVE-2026-27544 WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability 13.08.2026 10
CVE-2026-28001 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28008 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28142 WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28148 WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability 13.08.2026 9.8
CVE-2026-28149 WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability 13.08.2026 9.8
CVE-2026-28185 WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-61962 WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability 13.08.2026 10
CVE-2026-61966 WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61967 WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-61969 WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-66436 WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66446 WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability 13.08.2026 9.8
CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66478 WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66691 WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability 13.08.2026 9.8
CVE-2026-49827 WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) 13.08.2026 9.8
CVE-2026-73483 Flowise before 3.1.3 Sandbox Escape via Puppeteer 14.08.2026 9.4
CVE-2026-73485 Flowise before 3.1.3 Remote Code Execution via Airtable Agent 14.08.2026 9
CVE-2026-73486 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV 13.08.2026 9
CVE-2026-73487 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent 14.08.2026 9
CVE-2026-73601 Flowise before 3.1.3 Remote Code Execution via Custom MCP 14.08.2026 9
CVE-2026-73602 Flowise before 3.1.3 Sandbox Escape to RCE 13.08.2026 9
CVE-2026-73608 SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget 14.08.2026 9.2
CVE-2026-59503 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor 13.08.2026 9.1
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security 13.08.2026 9.1
CVE-2026-59506 Priority – CWE-306: Missing Authentication for Critical Function 13.08.2026 9.3
CVE-2026-59507 Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control 13.08.2026 9.3
CVE-2026-59500 Priority - CWE-287: Improper Authentication 13.08.2026 10
CVE-2026-15413 Link Factory - Backdoor 13.08.2026 10
CVE-2026-49819 UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd 13.08.2026 9.8
CVE-2026-49481 UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd 13.08.2026 9.6
CVE-2026-71193 13.08.2026 9.6
CVE-2026-71471 Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image 13.08.2026 9
CVE-2024-27253 IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request 13.08.2026 10
CVE-2026-73501 kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default 13.08.2026 9.1
CVE-2026-73519 WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret 13.08.2026 9.3
CVE-2026-19001 MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names 13.08.2026 9.5
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE 13.08.2026 9.9
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 13.08.2026 9.9
CVE-2026-63294 Root RCE via image backup.yaml symlink 13.08.2026 9.9
CVE-2026-17083 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 13.08.2026 9.8
CVE-2026-63296 Project restriction bypass via instance migration config override 13.08.2026 9.9
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 13.08.2026 9.9
CVE-2026-72508 Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) 13.08.2026 9.9
CVE-2026-73414 Shescape: Shell injection via unescaped parentheses on Windows with CMD 14.08.2026 9.2
CVE-2026-19656 ScadaLTS Authenticated Remote Code Execution 12.08.2026 9.9
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag 12.08.2026 9.9
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution 13.08.2026 9.9
CVE-2026-72789 SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks 14.08.2026 9.2
CVE-2026-72793 SiYuan before v3.7.4 Information Disclosure via /api/system/getConf 14.08.2026 9.2
CVE-2026-72794 siyuan before v3.7.4 Session Cookie Key Disclosure via getConf 14.08.2026 9.2
CVE-2026-72795 SiYuan before v3.7.4 Information Disclosure via Embed Block 14.08.2026 9.2
CVE-2026-72798 SiYuan before v3.7.4 Information Disclosure via renderAttributeView 14.08.2026 9.2
CVE-2026-72804 SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints 14.08.2026 9.2
CVE-2026-73268 Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection 12.08.2026 9.9
CVE-2026-73269 Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa 12.08.2026 9.9
CVE-2026-73329 CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint 14.08.2026 9.2
CVE-2026-73332 CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field 14.08.2026 9.2
CVE-2026-73407 Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) 12.08.2026 9
CVE-2026-73300 Budibase: SQL Injection via `multipleStatements: true` 12.08.2026 9.6
CVE-2026-16860 IBM i is Affected By Remote Code Execution Vulnerability [] 12.08.2026 9.9
CVE-2026-16956 IBM Db2 Mirror for i is vulnerable to OS command injection [] 12.08.2026 9.8
CVE-2026-17218 IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] 12.08.2026 9.8
CVE-2026-73299 Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer 12.08.2026 10
CVE-2026-17276 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 9.6
CVE-2026-73296 Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure 13.08.2026 9.4
CVE-2026-73294 Semaphore U: OS Command Injection 12.08.2026 9.9
CVE-2026-64639 14.08.2026 9.3
CVE-2026-73263 Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path 12.08.2026 9.9
CVE-2026-50561 Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse 13.08.2026 9.4
CVE-2026-67285 Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 14.08.2026 9.2
CVE-2026-57858 Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID 13.08.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-58087 Heap out-of-bounds access in semctl(2) 19.08.2026
CVE-2026-58088 Race condition in ELF core dump segment counting 19.08.2026
CVE-2026-75900 Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch 19.08.2026
CVE-2026-58083 Use-after-free in kqueue copy-on-fork 19.08.2026
CVE-2026-58084 Kernel stack disclosure via timer_settime(2) 19.08.2026
CVE-2026-58085 Missing MAC validation in wg(4) packet decryption 19.08.2026
CVE-2026-58086 ktrace(2) privilege incorrectly validated in jails 19.08.2026
CVE-2026-49424 Kernel stack disclosure in Linux compatibility layer 19.08.2026
CVE-2026-49425 Kernel stack disclosure in 32-bit compatibility support 19.08.2026
CVE-2026-58081 Heap based buffer overflow in iconv(3) 19.08.2026
CVE-2026-58082 Stack based buffer overflow in iconv(3) 19.08.2026
CVE-2026-72889 Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify 19.08.2026
CVE-2026-75589 Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify 19.08.2026
CVE-2026-49423 Remote DOS via uninitialized memory access in KTLS receive 19.08.2026
CVE-2026-15446 EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content 19.08.2026 6.4
CVE-2026-15780 WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter 19.08.2026 7.2
CVE-2026-75981 TranslatePress – Translate Multilingual sites with AI Translation <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting 19.08.2026 7.2
CVE-2026-11565 Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui 19.08.2026
CVE-2026-12983 Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection 19.08.2026
CVE-2026-13169 Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR 19.08.2026
CVE-2026-13173 Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation 19.08.2026
CVE-2026-13174 Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR 19.08.2026
CVE-2026-13175 Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR 19.08.2026
CVE-2026-14196 WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR 19.08.2026
CVE-2026-14287 TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass 19.08.2026
CVE-2026-14334 Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload 19.08.2026
CVE-2026-14825 Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDOR 19.08.2026
CVE-2026-14826 Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR 19.08.2026
CVE-2026-14861 User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR 19.08.2026
CVE-2026-15253 Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title 19.08.2026
CVE-2026-16058 YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration 19.08.2026
CVE-2026-16570 NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callback 19.08.2026
CVE-2026-16616 Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal 19.08.2026
CVE-2026-16617 Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description 19.08.2026
CVE-2026-16950 Product Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_products 19.08.2026
CVE-2026-16979 SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration 19.08.2026
CVE-2026-17565 Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery 19.08.2026
CVE-2026-18031 TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback 19.08.2026
CVE-2026-18051 W3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key 19.08.2026
CVE-2026-18202 JetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload 19.08.2026
CVE-2026-18231 WP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user 19.08.2026
CVE-2026-18466 WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation 19.08.2026
CVE-2026-18776 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions 19.08.2026
CVE-2026-18777 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status 19.08.2026
CVE-2026-18778 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX Actions 19.08.2026
CVE-2026-18779 TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked 19.08.2026
CVE-2026-18937 Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection 19.08.2026
CVE-2026-19055 ProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters 19.08.2026
CVE-2026-19056 ProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter 19.08.2026
CVE-2026-19406 Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing 19.08.2026
CVE-2026-19416 KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR 19.08.2026
CVE-2026-19417 KiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR 19.08.2026
CVE-2026-19709 Membership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass 19.08.2026
CVE-2026-19782 WPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_users 19.08.2026
CVE-2026-19842 SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite 19.08.2026
CVE-2026-49426 Incorrect audit records for ptrace(2) syscall requests 19.08.2026
CVE-2026-8810 HDD Password leakage vulnerability 19.08.2026 6.9
CVE-2026-49427 posixshm: largepage shared memory objects not explicitly wired 19.08.2026
CVE-2026-49428 posixshm: system calls can incorrectly free memory of largepage objects 19.08.2026
CVE-2026-49420 Buffer overflow in libalias RTSP handler 19.08.2026
CVE-2026-49421 unlinkat(2) ignores AT_RESOLVE_BENEATH flag 19.08.2026
CVE-2026-49422 Use-after-free in TCP RACK stack option handler 19.08.2026
CVE-2026-49429 Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl 19.08.2026
CVE-2026-49430 Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl 19.08.2026
CVE-2026-49431 Incorrect user validation in ZFS_IOC_SET_PROP ioctl 19.08.2026
CVE-2026-70408 19.08.2026
CVE-2026-49415 Local privilege escalation via execve(2) TOCTOU race 19.08.2026
CVE-2026-66358 19.08.2026
CVE-2026-19942 Atarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta 19.08.2026 8.1
CVE-2026-49419 Jail reference count underflow 19.08.2026
CVE-2026-49418 Use-after-free in device pager page list 19.08.2026
CVE-2026-76050 SourceCodester Simple Online Food Ordering System ajax.php delete_menu sql injection 19.08.2026
CVE-2026-76049 SourceCodester Simple Online Food Ordering System ajax.php save_menu sql injection 19.08.2026
CVE-2026-76014 BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference 19.08.2026
CVE-2026-76048 SourceCodester Simple Online Food Ordering System ajax.php login sql injection 19.08.2026
CVE-2026-76008 Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow 19.08.2026
CVE-2026-76003 UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow 19.08.2026
CVE-2026-76004 UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow 19.08.2026
CVE-2026-11751 19.08.2026
CVE-2026-15421 Speed Optimizer <= 7.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes 19.08.2026 6.4
CVE-2026-75985 TRENDnet Router ping.cgi command injection 19.08.2026
CVE-2026-75986 code-projects Online Job Portal System Password Recovery ForPass.php sql injection 19.08.2026
CVE-2026-75987 SPLWare esProc SocketData.java ObjectInputStream.readUnshared deserialization 19.08.2026
CVE-2026-75979 xianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText special elements in template engine 19.08.2026
CVE-2026-75984 TRENDnet TEW-823DRU admin.cgi command injection 19.08.2026
CVE-2026-75978 xianrendzw EasyReport QueryerFactory DataSourceController.java DataSourceController.add permission 19.08.2026
CVE-2026-75976 TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow 18.08.2026
CVE-2025-11729 PPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Improper Authorization To Authenticated (Contributor+) Master Password Exposure 18.08.2026 4.3
CVE-2026-27365 WordPress PublishPress Series plugin <= 2.17.0 - Cross Site Scripting (XSS) vulnerability 18.08.2026 5.9
CVE-2026-66589 WordPress B2BKing plugin <= 5.2.30 - Broken Access Control vulnerability 18.08.2026 5.4
CVE-2026-66591 WordPress Media LIbrary Assistant plugin <= 3.39 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66602 WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) vulnerability 18.08.2026 8.8
CVE-2026-21580 18.08.2026
CVE-2026-21582 18.08.2026
CVE-2026-21584 18.08.2026
CVE-2026-66603 WordPress Draft List plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-53959 4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user 18.08.2026 6.5
CVE-2026-15315 Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C200 18.08.2026
CVE-2026-15316 Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200 18.08.2026
CVE-2026-47699 Confidential Containers Guest Components image-rs: zip-slip-class arbitrary file write via absolute entry path in hardlink fallback 18.08.2026 6.4
CVE-2026-50186 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export 18.08.2026 8.8
CVE-2026-50191 4gaBoards: Pre-Account Takeover via SSO Email Linkage 18.08.2026 8.8
CVE-2026-52854 mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser function 18.08.2026 8.6
CVE-2026-52872 Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol 18.08.2026 8.8
CVE-2026-52873 Streambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electron Renderer 18.08.2026 6.9
CVE-2026-52875 Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler 18.08.2026
CVE-2026-52876 Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback 18.08.2026 8.8
CVE-2026-52877 Streambert : Insecure Protocol Execution in open-external IPC Handler 18.08.2026 8.3
CVE-2026-53958 4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment 18.08.2026 7.6
CVE-2026-48796 CefSharp: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder 18.08.2026 5.3
CVE-2026-50142 libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check) 18.08.2026 7.5
CVE-2026-62289 libheif: Integer underflow in Fraction constructor via double clap transform application 18.08.2026 4.3
CVE-2026-62291 libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions 18.08.2026 5.3
CVE-2026-62292 libheif: Out-of-bounds read in uncompressed unci tile range slicing 18.08.2026
CVE-2026-62377 libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110) 18.08.2026 4.3
CVE-2026-73973 Linuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined --filename in logfile plugin (sudoers LPE) 18.08.2026 5.5
CVE-2026-73974 linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE) 18.08.2026 5.5
CVE-2026-41921 Koha Stored XSS via Purchase Suggestion Handler 18.08.2026
CVE-2026-70894 18.08.2026 7.7
CVE-2026-70895 18.08.2026 6.5
CVE-2026-70896 18.08.2026 7.5
CVE-2026-70897 18.08.2026 8.2
CVE-2026-70898 18.08.2026 7.4
CVE-2026-70899 18.08.2026 8.8
CVE-2026-70900 18.08.2026 8.7
CVE-2026-70901 18.08.2026 8.1
CVE-2026-70902 18.08.2026 7.1
CVE-2026-70903 18.08.2026 8.7
CVE-2026-70904 18.08.2026 8.1
CVE-2026-70905 18.08.2026 9.8
CVE-2026-70906 18.08.2026 7.5
CVE-2026-70907 18.08.2026 5.3
CVE-2026-70908 18.08.2026 7.5
CVE-2026-70909 18.08.2026 8.2
CVE-2026-70910 18.08.2026 7.5
CVE-2026-70911 18.08.2026 5.3
CVE-2026-70912 18.08.2026 5.3
CVE-2026-70914 18.08.2026 7
CVE-2026-70916 18.08.2026 4
CVE-2026-70917 18.08.2026 4
CVE-2026-70918 18.08.2026 8.8
CVE-2026-70919 18.08.2026 2.5
CVE-2026-70920 18.08.2026 9.9
CVE-2026-70921 18.08.2026 10
CVE-2026-70922 18.08.2026 8.8
CVE-2026-70923 18.08.2026 6.1
CVE-2026-70924 18.08.2026 8.1
CVE-2026-70925 18.08.2026 8.1
CVE-2026-70926 18.08.2026 9.8
CVE-2026-70927 18.08.2026 7.5
CVE-2026-70928 18.08.2026 8.8
CVE-2026-70929 18.08.2026 8.1
CVE-2026-70930 18.08.2026 7.5
CVE-2026-70931 18.08.2026 8.1
CVE-2026-70932 18.08.2026 7.2
CVE-2026-70933 18.08.2026 7.1
CVE-2026-70934 18.08.2026 7.1
CVE-2026-70935 18.08.2026 7.1
CVE-2026-70936 18.08.2026 7.1
CVE-2026-70937 18.08.2026 7.5
CVE-2026-70938 18.08.2026 6.5
CVE-2026-70939 18.08.2026 7.2
CVE-2026-70940 18.08.2026 8.8
CVE-2026-70941 18.08.2026 8.8
CVE-2026-70942 18.08.2026 7.7
CVE-2026-70943 18.08.2026 8.1
CVE-2026-70944 18.08.2026 8.8
CVE-2026-70945 18.08.2026 7.7
CVE-2026-70946 18.08.2026 7.5
CVE-2026-70947 18.08.2026 7.5
CVE-2026-70948 18.08.2026 8.8
CVE-2026-70949 18.08.2026 8.8
CVE-2026-70950 18.08.2026 7.2
CVE-2026-70951 18.08.2026 8.8
CVE-2026-70952 18.08.2026 8.2
CVE-2026-70953 18.08.2026 9.8
CVE-2026-70954 18.08.2026 9.8
CVE-2026-70955 18.08.2026 7.5
CVE-2026-70956 18.08.2026 8.8
CVE-2026-70957 18.08.2026 8.1
CVE-2026-70958 18.08.2026 9.6
CVE-2026-70959 18.08.2026 8.1
CVE-2026-70960 18.08.2026 7.6
CVE-2026-70961 18.08.2026 6.1
CVE-2026-70962 18.08.2026 3.3
CVE-2026-70963 18.08.2026 4.2
CVE-2026-70964 18.08.2026 8.2
CVE-2026-70965 18.08.2026 8.8
CVE-2026-70966 18.08.2026 8.8
CVE-2026-70967 18.08.2026 7.1
CVE-2026-70968 18.08.2026 6.5
CVE-2026-70969 18.08.2026 6.5
CVE-2026-70970 18.08.2026 9.8
CVE-2026-70971 18.08.2026 7.1
CVE-2026-70972 18.08.2026 6.8
CVE-2026-70973 18.08.2026 7.5
CVE-2026-70974 18.08.2026 5.3
CVE-2026-70975 18.08.2026 6.5
CVE-2026-70976 18.08.2026 9.1
CVE-2026-70977 18.08.2026 9.1
CVE-2026-70978 18.08.2026 9.1
CVE-2026-70979 18.08.2026 9.1
CVE-2026-70980 18.08.2026 9
CVE-2026-70981 18.08.2026 9.1
CVE-2026-70982 18.08.2026 6.8
CVE-2026-70983 18.08.2026 6.8
CVE-2026-70984 18.08.2026 9.1
CVE-2026-70985 18.08.2026 7.5
CVE-2026-70986 18.08.2026 7.5
CVE-2026-70987 18.08.2026 7.5
CVE-2026-70988 18.08.2026 7.7
CVE-2026-70989 18.08.2026 6.5
CVE-2026-70990 18.08.2026 6.8
CVE-2026-70991 18.08.2026 6.3
CVE-2026-70992 18.08.2026 7
CVE-2026-70993 18.08.2026 8.2
CVE-2026-70994 18.08.2026 9.1
CVE-2026-70995 18.08.2026 9.8
CVE-2026-70996 18.08.2026 8.6
CVE-2026-70997 18.08.2026 9.1
CVE-2026-70998 18.08.2026 9.3
CVE-2026-70999 18.08.2026 8.1
CVE-2026-71000 18.08.2026 8.7
CVE-2026-71001 18.08.2026 6.5
CVE-2026-71002 18.08.2026 8.5
CVE-2026-71003 18.08.2026 7.1
CVE-2026-71004 18.08.2026 6.1
CVE-2026-71005 18.08.2026 6.1
CVE-2026-71006 18.08.2026 6.1
CVE-2026-71007 18.08.2026 6.8
CVE-2026-71008 18.08.2026 6.8
CVE-2026-71009 18.08.2026 7.4
CVE-2026-71010 18.08.2026 7.8
CVE-2026-71011 18.08.2026 6.1
CVE-2026-71012 18.08.2026 7.1
CVE-2026-71013 18.08.2026 6
CVE-2026-71014 18.08.2026 9.1
CVE-2026-71015 18.08.2026 9.1
CVE-2026-71016 18.08.2026 8.2
CVE-2026-71017 18.08.2026 6.5
CVE-2026-71018 18.08.2026 8.2
CVE-2026-71019 18.08.2026 6.1
CVE-2026-71020 18.08.2026 7.6
CVE-2026-71021 18.08.2026 7.6
CVE-2026-71022 18.08.2026 7.6
CVE-2026-71023 18.08.2026 7.5
CVE-2026-71024 18.08.2026 8.2
CVE-2026-71025 18.08.2026 6.1
CVE-2026-71026 18.08.2026 9.1
CVE-2026-71027 18.08.2026 7.6
CVE-2026-71028 18.08.2026 7.8
CVE-2026-71029 18.08.2026 6.8
CVE-2026-71030 18.08.2026 7.2
CVE-2026-71031 18.08.2026 6.1
CVE-2026-71032 18.08.2026 7.2
CVE-2026-71033 18.08.2026 5.5
CVE-2026-71034 18.08.2026 7.5
CVE-2026-71035 18.08.2026 8.1
CVE-2026-71036 18.08.2026 9.1
CVE-2026-71037 18.08.2026 9.3
CVE-2026-71038 18.08.2026 7.5
CVE-2026-71039 18.08.2026 8.8
CVE-2026-71040 18.08.2026 9.8
CVE-2026-71041 18.08.2026 7
CVE-2026-71042 18.08.2026 8.1
CVE-2026-71043 18.08.2026 7.5
CVE-2026-71044 18.08.2026 8.8
CVE-2026-71045 18.08.2026 8.8
CVE-2026-71046 18.08.2026 8.8
CVE-2026-71048 18.08.2026 7.6
CVE-2026-71049 18.08.2026 8.5
CVE-2026-71050 18.08.2026 8.7
CVE-2026-71051 18.08.2026 8.8
CVE-2026-71052 18.08.2026 8.8
CVE-2026-71053 18.08.2026 8.1
CVE-2026-71055 18.08.2026 8.8
CVE-2026-71056 18.08.2026 7.7
CVE-2026-71057 18.08.2026 8.5
CVE-2026-71058 18.08.2026 8.8
CVE-2026-71059 18.08.2026 9.9
CVE-2026-71060 18.08.2026 4.4
CVE-2026-71061 18.08.2026 7.5
CVE-2026-71062 18.08.2026 8.5
CVE-2026-71063 18.08.2026 9.6
CVE-2026-71064 18.08.2026 9.6
CVE-2026-71065 18.08.2026 9.3
CVE-2026-71066 18.08.2026 4.5
CVE-2026-71067 18.08.2026 8.8
CVE-2026-71068 18.08.2026 8.1
CVE-2026-71069 18.08.2026 7.5
CVE-2026-71070 18.08.2026 6.5
CVE-2026-71071 18.08.2026 4.6
CVE-2026-71072 18.08.2026 3.3
CVE-2026-71073 18.08.2026 5.5
CVE-2026-71074 18.08.2026 9.8
CVE-2026-71075 18.08.2026 5.9
CVE-2026-71076 18.08.2026 5.3
CVE-2026-71077 18.08.2026 5.3
CVE-2026-71078 18.08.2026 4.2
CVE-2026-71079 18.08.2026 6.5
CVE-2026-71080 18.08.2026 3.7
CVE-2026-71081 18.08.2026 1.9
CVE-2026-71082 18.08.2026 2.5
CVE-2026-71083 18.08.2026 1.8
CVE-2026-71084 18.08.2026 6.8
CVE-2026-71085 18.08.2026 4.9
CVE-2026-71087 18.08.2026 5.3
CVE-2026-71088 18.08.2026 4.8
CVE-2026-71089 18.08.2026 3.3
CVE-2026-71090 18.08.2026 6.4
CVE-2026-71091 18.08.2026 6.5
CVE-2026-71092 18.08.2026 7.5
CVE-2026-71094 18.08.2026 7.3
CVE-2026-71095 18.08.2026 8.3
CVE-2026-71096 18.08.2026 8.2
CVE-2026-71097 18.08.2026 7.8
CVE-2026-71098 18.08.2026 7
CVE-2026-71099 18.08.2026 7.2
CVE-2026-71100 18.08.2026 5.3
CVE-2026-71101 18.08.2026 7.8
CVE-2026-71102 18.08.2026 9.1
CVE-2026-71103 18.08.2026 6.3
CVE-2026-71104 18.08.2026 7.2
CVE-2026-71105 18.08.2026 4.7
CVE-2026-71106 18.08.2026 8.8
CVE-2026-71107 18.08.2026 7.5
CVE-2026-71108 18.08.2026 5.3
CVE-2026-71109 18.08.2026 6.7
CVE-2026-71110 18.08.2026 8.1
CVE-2026-71111 18.08.2026 7.8
CVE-2026-71112 18.08.2026 8.1
CVE-2026-71113 18.08.2026 7.5
CVE-2026-71114 18.08.2026 6
CVE-2026-71115 18.08.2026 6
CVE-2026-71116 18.08.2026 7.5
CVE-2026-71117 18.08.2026 7.5
CVE-2026-71118 18.08.2026 4.8
CVE-2026-71119 18.08.2026 6.4
CVE-2026-71120 18.08.2026 5.3
CVE-2026-71121 18.08.2026 6.5
CVE-2026-71122 18.08.2026 8
CVE-2026-71123 18.08.2026 5.4
CVE-2026-71124 18.08.2026 4.3
CVE-2026-71125 18.08.2026 6.1
CVE-2026-71126 18.08.2026 7.8
CVE-2026-71127 18.08.2026 6
CVE-2026-71128 18.08.2026 6
CVE-2026-71129 18.08.2026 8.2
CVE-2026-71130 18.08.2026 8.2
CVE-2026-71131 18.08.2026 8.6
CVE-2026-71132 18.08.2026 5.3
CVE-2026-71134 18.08.2026 5.7
CVE-2026-71135 18.08.2026 6
CVE-2026-71136 18.08.2026 7.3
CVE-2026-71137 18.08.2026 6
CVE-2026-71138 18.08.2026 7.3
CVE-2026-71139 18.08.2026 4.4
CVE-2026-71140 18.08.2026 3.4
CVE-2026-71141 18.08.2026 7.7
CVE-2026-71142 18.08.2026 7.5
CVE-2026-71143 18.08.2026 7.4
CVE-2026-71144 18.08.2026 3
CVE-2026-71145 18.08.2026 4.4
CVE-2026-71146 18.08.2026 1.9
CVE-2026-71147 18.08.2026 4.2
CVE-2026-71148 18.08.2026 5.3
CVE-2026-71149 18.08.2026 4.2
CVE-2026-71150 18.08.2026 8.8
CVE-2026-71151 18.08.2026 5.6
CVE-2026-71152 18.08.2026 9.8
CVE-2026-71153 18.08.2026 7.5
CVE-2026-71154 18.08.2026 6.1
CVE-2026-71155 18.08.2026 8.5
CVE-2026-71156 18.08.2026 5.3
CVE-2026-71157 18.08.2026 5.3
CVE-2026-71158 18.08.2026 7.5
CVE-2026-71159 18.08.2026 8.2
CVE-2026-71160 18.08.2026 7.5
CVE-2026-71161 18.08.2026 5.3
CVE-2026-71162 18.08.2026 6.5
CVE-2026-71164 18.08.2026 9.8
CVE-2026-71165 18.08.2026 5.4
CVE-2026-71166 18.08.2026 9.4
CVE-2026-71167 18.08.2026 9.4
CVE-2026-73865 18.08.2026 9.1
CVE-2026-73866 18.08.2026 9.1
CVE-2026-73867 18.08.2026 6.5
CVE-2026-73868 18.08.2026 6.5
CVE-2026-73869 18.08.2026 6.1
CVE-2026-73870 18.08.2026 6.1
CVE-2026-73871 18.08.2026 5.3
CVE-2026-73872 18.08.2026 5.3
CVE-2026-73873 18.08.2026 4.2
CVE-2026-73874 18.08.2026 5.4
CVE-2026-73875 18.08.2026 7.2
CVE-2026-73876 18.08.2026 7.2
CVE-2026-73877 18.08.2026 5.3
CVE-2026-73878 18.08.2026 7.5
CVE-2026-73879 18.08.2026 7.5
CVE-2026-73880 18.08.2026 4.4
CVE-2026-73881 18.08.2026 5.4
CVE-2026-73882 18.08.2026 7.5
CVE-2026-73883 18.08.2026 7.5
CVE-2026-73884 18.08.2026 7.5
CVE-2026-73885 18.08.2026 7.2
CVE-2026-73886 18.08.2026 7.2
CVE-2026-73887 18.08.2026 7.5
CVE-2026-73888 18.08.2026 5.3
CVE-2026-73889 18.08.2026 5.3
CVE-2026-73890 18.08.2026 7.5
CVE-2026-73891 18.08.2026 7.3
CVE-2026-73892 18.08.2026 6.5
CVE-2026-73893 18.08.2026 6.5
CVE-2026-73894 18.08.2026 7.3
CVE-2026-73895 18.08.2026 5.3
CVE-2026-73896 18.08.2026 6.5
CVE-2026-73897 18.08.2026 6.5
CVE-2026-73898 18.08.2026 6.1
CVE-2026-73899 18.08.2026 5.3
CVE-2026-73900 18.08.2026 5.3
CVE-2026-73901 18.08.2026 4.8
CVE-2026-73902 18.08.2026 7.5
CVE-2026-73903 18.08.2026 7.5
CVE-2026-73904 18.08.2026 6.5
CVE-2026-73905 18.08.2026 9.8
CVE-2026-73906 18.08.2026 5.3
CVE-2026-73907 18.08.2026 7.5
CVE-2026-73908 18.08.2026 7.5
CVE-2026-73909 18.08.2026 5.9
CVE-2026-73910 18.08.2026 5.3
CVE-2026-73911 18.08.2026 5.4
CVE-2026-73912 18.08.2026 9.8
CVE-2026-73913 18.08.2026 5.4
CVE-2026-73914 18.08.2026 6.5
CVE-2026-73915 18.08.2026 7.5
CVE-2026-73916 18.08.2026 9.1
CVE-2026-73917 18.08.2026 9.1
CVE-2026-73918 18.08.2026 7.3
CVE-2026-73919 18.08.2026 5.4
CVE-2026-73920 18.08.2026 9.4
CVE-2026-73921 18.08.2026 9.8
CVE-2026-73922 18.08.2026 9.1
CVE-2026-73923 18.08.2026 3.7
CVE-2026-73924 18.08.2026 9.1
CVE-2026-73925 18.08.2026 8.2
CVE-2026-73927 18.08.2026 7.5
CVE-2026-73928 18.08.2026 7.2
CVE-2026-73929 18.08.2026 8.3
CVE-2026-73930 18.08.2026 9.9
CVE-2026-73931 18.08.2026 8.3
CVE-2026-73932 18.08.2026 5.3
CVE-2026-73933 18.08.2026 7.3
CVE-2026-73934 18.08.2026 7.5
CVE-2026-73935 18.08.2026 7.5
CVE-2026-73936 18.08.2026 7.5
CVE-2026-73937 18.08.2026 8.2
CVE-2026-73938 18.08.2026 7.5
CVE-2026-73939 18.08.2026 8.6
CVE-2026-12631 Broken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr kernel 18.08.2026 6.5
CVE-2026-12632 Out-of-bounds read in Zephyr PTP message parsing from unvalidated message type 18.08.2026 6.5
CVE-2026-53759 linuxfabrik-lib: Insecure creation of SQLite databases 18.08.2026
CVE-2026-55426 linuxfabrik-lib: Local privilege escalation using embedded command 18.08.2026 7.8
CVE-2026-60391 18.08.2026 7.5
CVE-2026-60392 18.08.2026 7.8
CVE-2026-60393 18.08.2026 7.5
CVE-2026-60412 18.08.2026 7.8
CVE-2026-60413 18.08.2026 7.8
CVE-2026-60414 18.08.2026 7.8
CVE-2026-60415 18.08.2026 8.1
CVE-2026-60589 18.08.2026 3.7
CVE-2026-60590 18.08.2026 7.5
CVE-2026-60591 18.08.2026 9.1
CVE-2026-60592 18.08.2026 8.2
CVE-2026-60672 18.08.2026 9.8
CVE-2026-60679 18.08.2026 7.5
CVE-2026-60680 18.08.2026 8.1
CVE-2026-60682 18.08.2026 6.5
CVE-2026-60693 18.08.2026 7.1
CVE-2026-60696 18.08.2026 9.8
CVE-2026-60698 18.08.2026 9.8
CVE-2026-60699 18.08.2026 8.6
CVE-2026-60702 18.08.2026 9.9
CVE-2026-60707 18.08.2026 8.7
CVE-2026-60715 18.08.2026 8.8
CVE-2026-60716 18.08.2026 8.8
CVE-2026-60720 18.08.2026 9.9
CVE-2026-60721 18.08.2026 9.8
CVE-2026-60722 18.08.2026 8.8
CVE-2026-60726 18.08.2026 8.8
CVE-2026-60727 18.08.2026 9.8
CVE-2026-60728 18.08.2026 9.1
CVE-2026-60729 18.08.2026 8.8
CVE-2026-60730 18.08.2026 9.9
CVE-2026-60731 18.08.2026 8.8
CVE-2026-60733 18.08.2026 7.7
CVE-2026-60737 18.08.2026 9.1
CVE-2026-60742 18.08.2026 8.1
CVE-2026-60748 18.08.2026 7.6
CVE-2026-60751 18.08.2026 8.8
CVE-2026-60752 18.08.2026 7.1
CVE-2026-60753 18.08.2026 7.8
CVE-2026-60754 18.08.2026 9.1
CVE-2026-60757 18.08.2026 8.1
CVE-2026-60758 18.08.2026 8.5
CVE-2026-60759 18.08.2026 7.4
CVE-2026-60765 18.08.2026 7.5
CVE-2026-60766 18.08.2026 7.4
CVE-2026-60767 18.08.2026 8.8
CVE-2026-60769 18.08.2026 7.5
CVE-2026-60779 18.08.2026 8.1
CVE-2026-60781 18.08.2026 7.1
CVE-2026-60782 18.08.2026 9.8
CVE-2026-60791 18.08.2026 8.1
CVE-2026-60792 18.08.2026 7.4
CVE-2026-60796 18.08.2026 8.2
CVE-2026-60797 18.08.2026 7.4
CVE-2026-60798 18.08.2026 8.5
CVE-2026-60803 18.08.2026 7.4
CVE-2026-60808 18.08.2026 7.5
CVE-2026-60820 18.08.2026 7.4
CVE-2026-60821 18.08.2026 9.8
CVE-2026-60822 18.08.2026 7.8
CVE-2026-60830 18.08.2026 6.5
CVE-2026-60831 18.08.2026 8.1
CVE-2026-60841 18.08.2026 8.5
CVE-2026-60849 18.08.2026 8.5
CVE-2026-60850 18.08.2026 7.5
CVE-2026-60853 18.08.2026 3.7
CVE-2026-60856 18.08.2026 7.4
CVE-2026-60858 18.08.2026 9.8
CVE-2026-60860 18.08.2026 8.7
CVE-2026-60861 18.08.2026 9.6
CVE-2026-60865 18.08.2026 6.8
CVE-2026-60866 18.08.2026 6.5
CVE-2026-60873 18.08.2026 7.2
CVE-2026-60879 18.08.2026 8.8
CVE-2026-60883 18.08.2026 7.2
CVE-2026-60884 18.08.2026 4.4
CVE-2026-60889 18.08.2026 7.5
CVE-2026-60895 18.08.2026 6.8
CVE-2026-60902 18.08.2026 7
CVE-2026-60903 18.08.2026 8.7
CVE-2026-60905 18.08.2026 9.6
CVE-2026-60906 18.08.2026 7.5
CVE-2026-60909 18.08.2026 7.6
CVE-2026-60914 18.08.2026 7.5
CVE-2026-60915 18.08.2026 7.4
CVE-2026-60916 18.08.2026 9.9
CVE-2026-60921 18.08.2026 9.8
CVE-2026-60928 18.08.2026 8.4
CVE-2026-60933 18.08.2026 7.4
CVE-2026-60934 18.08.2026 8.7
CVE-2026-60935 18.08.2026 8.7
CVE-2026-60944 18.08.2026 8.2
CVE-2026-60946 18.08.2026 9.8
CVE-2026-60947 18.08.2026 9.8
CVE-2026-60949 18.08.2026 7.1
CVE-2026-60954 18.08.2026 8.7
CVE-2026-60955 18.08.2026 8.2
CVE-2026-60956 18.08.2026 7.5
CVE-2026-60958 18.08.2026 9.8
CVE-2026-60961 18.08.2026 8
CVE-2026-60967 18.08.2026 8.8
CVE-2026-60969 18.08.2026 7.7
CVE-2026-60970 18.08.2026 9.8
CVE-2026-60971 18.08.2026 9.8
CVE-2026-60975 18.08.2026 7.5
CVE-2026-60976 18.08.2026 8.8
CVE-2026-60977 18.08.2026 9.8
CVE-2026-60980 18.08.2026 8.7
CVE-2026-60981 18.08.2026 8.7
CVE-2026-60983 18.08.2026 7.7
CVE-2026-60990 18.08.2026 9.9
CVE-2026-60991 18.08.2026 7.8
CVE-2026-60992 18.08.2026 8.1
CVE-2026-60993 18.08.2026 7.5
CVE-2026-60994 18.08.2026 7.2
CVE-2026-60995 18.08.2026 9.9
CVE-2026-60996 18.08.2026 8.7
CVE-2026-60998 18.08.2026 8
CVE-2026-61001 18.08.2026 9.6
CVE-2026-61002 18.08.2026 8.8
CVE-2026-61003 18.08.2026 9.9
CVE-2026-61007 18.08.2026 7.5
CVE-2026-61008 18.08.2026 9.1
CVE-2026-61011 18.08.2026 8.2
CVE-2026-61016 18.08.2026 8.2
CVE-2026-61017 18.08.2026 8.8
CVE-2026-61018 18.08.2026 9.8
CVE-2026-61021 18.08.2026 9.9
CVE-2026-61022 18.08.2026 8.8
CVE-2026-61029 18.08.2026 9
CVE-2026-61032 18.08.2026 8.8
CVE-2026-61033 18.08.2026 8.6
CVE-2026-61034 18.08.2026 9.1
CVE-2026-61038 18.08.2026 8.2
CVE-2026-61040 18.08.2026 8.8
CVE-2026-61042 18.08.2026 8.8
CVE-2026-61045 18.08.2026 8.6
CVE-2026-61054 18.08.2026 8.2
CVE-2026-61058 18.08.2026 8.8
CVE-2026-61066 18.08.2026 9.9
CVE-2026-61118 18.08.2026 8.8
CVE-2026-61124 18.08.2026 7.1
CVE-2026-61139 18.08.2026 6.3
CVE-2026-61177 18.08.2026 8.1
CVE-2026-61193 18.08.2026 8.7
CVE-2026-61198 18.08.2026 6.5
CVE-2026-61199 18.08.2026 7.7
CVE-2026-61206 18.08.2026 9.9
CVE-2026-61208 18.08.2026 7.6
CVE-2026-61212 18.08.2026 8.5
CVE-2026-61213 18.08.2026 8.8
CVE-2026-61215 18.08.2026 8.7
CVE-2026-61219 18.08.2026 8.7
CVE-2026-61222 18.08.2026 8.2
CVE-2026-61227 18.08.2026 7.6
CVE-2026-61228 18.08.2026 8.6
CVE-2026-61229 18.08.2026 8.1
CVE-2026-61230 18.08.2026 8.6
CVE-2026-61231 18.08.2026 8.8
CVE-2026-61241 18.08.2026 10
CVE-2026-61248 18.08.2026 9.9
CVE-2026-61258 18.08.2026 9.8
CVE-2026-61259 18.08.2026 7.1
CVE-2026-61265 18.08.2026 8.1
CVE-2026-61268 18.08.2026 8.1
CVE-2026-61270 18.08.2026 8.1
CVE-2026-61272 18.08.2026 9.8
CVE-2026-61273 18.08.2026 8.8
CVE-2026-61276 18.08.2026 8.8
CVE-2026-61281 18.08.2026 8.1
CVE-2026-61284 18.08.2026 8.8
CVE-2026-61286 18.08.2026 8.6
CVE-2026-61288 18.08.2026 7.1
CVE-2026-61290 18.08.2026 7.1
CVE-2026-61291 18.08.2026 7.8
CVE-2026-61293 18.08.2026 8.1
CVE-2026-61295 18.08.2026 7.1
CVE-2026-61296 18.08.2026 7.6
CVE-2026-61298 18.08.2026 5.6
CVE-2026-61300 18.08.2026 7.8
CVE-2026-61302 18.08.2026 8.2
CVE-2026-61305 18.08.2026 8.3
CVE-2026-61306 18.08.2026 7.1
CVE-2026-61307 18.08.2026 8.1
CVE-2026-61308 18.08.2026 6.8
CVE-2026-61313 18.08.2026 6.7
CVE-2026-61317 18.08.2026 9.9
CVE-2026-61318 18.08.2026 9.8
CVE-2026-61319 18.08.2026 8.8
CVE-2026-61321 18.08.2026 8.1
CVE-2026-61326 18.08.2026 8.5
CVE-2026-61330 18.08.2026 8.8
CVE-2026-61331 18.08.2026 7.7
CVE-2026-61332 18.08.2026 8.7
CVE-2026-61339 18.08.2026 7.3
CVE-2026-61340 18.08.2026 8.2
CVE-2026-61341 18.08.2026 8.8
CVE-2026-61342 18.08.2026 5.3
CVE-2026-62441 18.08.2026 5.4
CVE-2026-62442 18.08.2026 8.1
CVE-2026-62446 18.08.2026 5.3
CVE-2026-62448 18.08.2026 8.2
CVE-2026-62449 18.08.2026 7
CVE-2026-62450 18.08.2026 8.8
CVE-2026-62452 18.08.2026 9.9
CVE-2026-62454 18.08.2026 7.8
CVE-2026-62455 18.08.2026 8.3
CVE-2026-62457 18.08.2026 9.8
CVE-2026-62458 18.08.2026 7.1
CVE-2026-62459 18.08.2026 7.2
CVE-2026-62460 18.08.2026 5
CVE-2026-62461 18.08.2026 3.1
CVE-2026-62462 18.08.2026 8.8
CVE-2026-62463 18.08.2026 9.6
CVE-2026-62467 18.08.2026 7.7
CVE-2026-62471 18.08.2026 8.1
CVE-2026-62475 18.08.2026 6.6
CVE-2026-62477 18.08.2026 8.1
CVE-2026-62481 18.08.2026 7.5
CVE-2026-62485 18.08.2026 8.2
CVE-2026-62491 18.08.2026 8.1
CVE-2026-62492 18.08.2026 7.4
CVE-2026-62499 18.08.2026 6.1
CVE-2026-62500 18.08.2026 8.8
CVE-2026-62501 18.08.2026 8.1
CVE-2026-62502 18.08.2026 8.1
CVE-2026-62506 18.08.2026 6.5
CVE-2026-62509 18.08.2026 5.3
CVE-2026-62510 18.08.2026 5.3
CVE-2026-62511 18.08.2026 3
CVE-2026-62512 18.08.2026 9.9
CVE-2026-62520 18.08.2026 4.8
CVE-2026-62522 18.08.2026 7.1
CVE-2026-62523 18.08.2026 6.5
CVE-2026-62526 18.08.2026 3.3
CVE-2026-62529 18.08.2026 3.5
CVE-2026-62531 18.08.2026 8.1
CVE-2026-62532 18.08.2026 3.8
CVE-2026-62533 18.08.2026 3.7
CVE-2026-62535 18.08.2026 8.6
CVE-2026-62536 18.08.2026 7.1
CVE-2026-62537 18.08.2026 7.1
CVE-2026-62538 18.08.2026 7.4
CVE-2026-62539 18.08.2026 9.8
CVE-2026-62540 18.08.2026 7.2
CVE-2026-62541 18.08.2026 9.8
CVE-2026-62543 18.08.2026 9.8
CVE-2026-62544 18.08.2026 9.8
CVE-2026-62545 18.08.2026 7.5
CVE-2026-62550 18.08.2026 7.5
CVE-2026-62551 18.08.2026 7.3
CVE-2026-62552 18.08.2026 7.5
CVE-2026-62553 18.08.2026 5.5
CVE-2026-62554 18.08.2026 7.5
CVE-2026-62555 18.08.2026 6.5
CVE-2026-62558 18.08.2026 6.3
CVE-2026-62564 18.08.2026 5.5
CVE-2026-62566 18.08.2026 5.3
CVE-2026-62568 18.08.2026 6.1
CVE-2026-62569 18.08.2026 3.4
CVE-2026-62570 18.08.2026 3
CVE-2026-62571 18.08.2026 7.7
CVE-2026-62572 18.08.2026 6.5
CVE-2026-62573 18.08.2026 5.5
CVE-2026-62575 18.08.2026 4.7
CVE-2026-62576 18.08.2026 6.5
CVE-2026-62577 18.08.2026 3.3
CVE-2026-62578 18.08.2026 6.5
CVE-2026-62579 18.08.2026 5.3
CVE-2026-62580 18.08.2026 2.6
CVE-2026-62581 18.08.2026 7.8
CVE-2026-62582 18.08.2026 9.6
CVE-2026-62583 18.08.2026 3
CVE-2026-62584 18.08.2026 4
CVE-2026-62585 18.08.2026 9.8
CVE-2026-62586 18.08.2026 8.6
CVE-2026-62587 18.08.2026 7.1
CVE-2026-62588 18.08.2026 9.9
CVE-2026-62589 18.08.2026 8.7
CVE-2026-62590 18.08.2026 8.5
CVE-2026-62591 18.08.2026 8.1
CVE-2026-62592 18.08.2026 9.8
CVE-2026-62593 18.08.2026 7.7
CVE-2026-62594 18.08.2026 7.7
CVE-2026-62595 18.08.2026 8.1
CVE-2026-62596 18.08.2026 8.5
CVE-2026-62598 18.08.2026 8.2
CVE-2026-62599 18.08.2026 8.6
CVE-2026-62600 18.08.2026 8.1
CVE-2026-62601 18.08.2026 7.1
CVE-2026-62602 18.08.2026 8
CVE-2026-62603 18.08.2026 5.4
CVE-2026-62604 18.08.2026 3.1
CVE-2026-62605 18.08.2026 8.2
CVE-2026-62606 18.08.2026 3.1
CVE-2026-62607 18.08.2026 8.7
CVE-2026-62608 18.08.2026 9.9
CVE-2026-62609 18.08.2026 9.8
CVE-2026-62610 18.08.2026 9.1
CVE-2026-62611 18.08.2026 9.8
CVE-2026-62612 18.08.2026 8.8
CVE-2026-62613 18.08.2026 9.3
CVE-2026-62614 18.08.2026 9.8
CVE-2026-62615 18.08.2026 8.5
CVE-2026-62616 18.08.2026 7.2
CVE-2026-62617 18.08.2026 9.8
CVE-2026-62618 18.08.2026 9.3
CVE-2026-62619 18.08.2026 8.8
CVE-2026-62620 18.08.2026 8.6
CVE-2026-62621 18.08.2026 9.8
CVE-2026-62622 18.08.2026 9.8
CVE-2026-62623 18.08.2026 8.8
CVE-2026-62624 18.08.2026 9.8
CVE-2026-62625 18.08.2026 8.6
CVE-2026-62626 18.08.2026 9.8
CVE-2026-62627 18.08.2026 7.1
CVE-2026-62628 18.08.2026 8.6
CVE-2026-62629 18.08.2026 9.4
CVE-2026-62630 18.08.2026 9.8
CVE-2026-62631 18.08.2026 8.8
CVE-2026-62632 18.08.2026 9.8
CVE-2026-62633 18.08.2026 9.8
CVE-2026-62634 18.08.2026 9.8
CVE-2026-62635 18.08.2026 9.8
CVE-2026-62636 18.08.2026 8.6
CVE-2026-62637 18.08.2026 9.3
CVE-2026-62638 18.08.2026 9.1
CVE-2026-62639 18.08.2026 9.8
CVE-2026-62640 18.08.2026 9.8
CVE-2026-70668 18.08.2026 9.1
CVE-2026-70669 18.08.2026 9.8
CVE-2026-70670 18.08.2026 9.6
CVE-2026-70671 18.08.2026 8.1
CVE-2026-70672 18.08.2026 7.4
CVE-2026-70673 18.08.2026 9.3
CVE-2026-70674 18.08.2026 8.8
CVE-2026-70675 18.08.2026 8.1
CVE-2026-70676 18.08.2026 7
CVE-2026-70677 18.08.2026 5.9
CVE-2026-70678 18.08.2026 7.6
CVE-2026-70679 18.08.2026 5.3
CVE-2026-70680 18.08.2026 7.1
CVE-2026-70681 18.08.2026 7.5
CVE-2026-70682 18.08.2026 3.7
CVE-2026-70683 18.08.2026 4.3
CVE-2026-70684 18.08.2026 8.1
CVE-2026-70685 18.08.2026 7.9
CVE-2026-70686 18.08.2026 8.8
CVE-2026-70687 18.08.2026 7.7
CVE-2026-70688 18.08.2026 8.8
CVE-2026-70689 18.08.2026 9.8
CVE-2026-70690 18.08.2026 8
CVE-2026-70691 18.08.2026 7.5
CVE-2026-70692 18.08.2026 7.7
CVE-2026-70693 18.08.2026 6.3
CVE-2026-70694 18.08.2026 7.7
CVE-2026-70695 18.08.2026 7.7
CVE-2026-70696 18.08.2026 7.5
CVE-2026-70697 18.08.2026 7
CVE-2026-70698 18.08.2026 6.7
CVE-2026-70699 18.08.2026 7.4
CVE-2026-70700 18.08.2026 7.5
CVE-2026-70701 18.08.2026 8.1
CVE-2026-70702 18.08.2026 8.2
CVE-2026-70703 18.08.2026 8.2
CVE-2026-70704 18.08.2026 8.1
CVE-2026-70705 18.08.2026 7.1
CVE-2026-70706 18.08.2026 7.5
CVE-2026-70707 18.08.2026 8.8
CVE-2026-70708 18.08.2026 8.1
CVE-2026-70709 18.08.2026 4.8
CVE-2026-70710 18.08.2026 8.8
CVE-2026-70711 18.08.2026 3.6
CVE-2026-70712 18.08.2026 6.4
CVE-2026-70713 18.08.2026 7.5
CVE-2026-70714 18.08.2026 4.1
CVE-2026-70715 18.08.2026 8.8
CVE-2026-70716 18.08.2026 5.9
CVE-2026-70717 18.08.2026 7.7
CVE-2026-70718 18.08.2026 8.5
CVE-2026-70719 18.08.2026 4
CVE-2026-70720 18.08.2026 6.5
CVE-2026-70721 18.08.2026 8.6
CVE-2026-70722 18.08.2026 8.2
CVE-2026-70723 18.08.2026 7.7
CVE-2026-70724 18.08.2026 7.5
CVE-2026-70725 18.08.2026 7.6
CVE-2026-70726 18.08.2026 6
CVE-2026-70727 18.08.2026 5.3
CVE-2026-70728 18.08.2026 8.5
CVE-2026-70729 18.08.2026 8.8
CVE-2026-70730 18.08.2026 9.1
CVE-2026-70731 18.08.2026 8.4
CVE-2026-70732 18.08.2026 6.5
CVE-2026-70733 18.08.2026 7.1
CVE-2026-70734 18.08.2026 7.4
CVE-2026-70735 18.08.2026 7.2
CVE-2026-70736 18.08.2026 7.1
CVE-2026-70737 18.08.2026 8.8
CVE-2026-70738 18.08.2026 8.1
CVE-2026-70739 18.08.2026 9.8
CVE-2026-70740 18.08.2026 9.8
CVE-2026-70741 18.08.2026 9.1
CVE-2026-70742 18.08.2026 8.8
CVE-2026-70743 18.08.2026 8.2
CVE-2026-70744 18.08.2026 8.1
CVE-2026-70745 18.08.2026 9.8
CVE-2026-70746 18.08.2026 8.1
CVE-2026-70747 18.08.2026 8.8
CVE-2026-70749 18.08.2026 8.1
CVE-2026-70750 18.08.2026 7.8
CVE-2026-70751 18.08.2026 6.8
CVE-2026-70752 18.08.2026 7.5
CVE-2026-70753 18.08.2026 6.3
CVE-2026-70754 18.08.2026 5.3
CVE-2026-70758 18.08.2026 5.3
CVE-2026-70759 18.08.2026 5.4
CVE-2026-70760 18.08.2026 7.1
CVE-2026-70761 18.08.2026 8.8
CVE-2026-70762 18.08.2026 8.1
CVE-2026-70763 18.08.2026 7.5
CVE-2026-70764 18.08.2026 7.6
CVE-2026-70765 18.08.2026 6.1
CVE-2026-70766 18.08.2026 5.4
CVE-2026-70767 18.08.2026 6.5
CVE-2026-70768 18.08.2026 6.1
CVE-2026-70769 18.08.2026 6.5
CVE-2026-70770 18.08.2026 8.3
CVE-2026-70771 18.08.2026 7.7
CVE-2026-70772 18.08.2026 7.5
CVE-2026-70773 18.08.2026 8.2
CVE-2026-70774 18.08.2026 7.1
CVE-2026-70775 18.08.2026 6.3
CVE-2026-70776 18.08.2026 2.6
CVE-2026-70777 18.08.2026 7.5
CVE-2026-70778 18.08.2026 8.7
CVE-2026-70779 18.08.2026 7.4
CVE-2026-70780 18.08.2026 6.8
CVE-2026-70781 18.08.2026 7.2
CVE-2026-70782 18.08.2026 8.1
CVE-2026-70783 18.08.2026 7.4
CVE-2026-70784 18.08.2026 5.3
CVE-2026-70785 18.08.2026 3.7
CVE-2026-70786 18.08.2026 7.6
CVE-2026-70787 18.08.2026 8.8
CVE-2026-70788 18.08.2026 6.5
CVE-2026-70789 18.08.2026 5.9
CVE-2026-70790 18.08.2026 7.4
CVE-2026-70791 18.08.2026 7.6
CVE-2026-70792 18.08.2026 8.8
CVE-2026-70793 18.08.2026 4.2
CVE-2026-70794 18.08.2026 4.7
CVE-2026-70795 18.08.2026 8.1
CVE-2026-70796 18.08.2026 7.2
CVE-2026-70797 18.08.2026 7.2
CVE-2026-70798 18.08.2026 7.8
CVE-2026-70799 18.08.2026 7.5
CVE-2026-70800 18.08.2026 7.3
CVE-2026-70801 18.08.2026 7.1
CVE-2026-70802 18.08.2026 8
CVE-2026-70803 18.08.2026 7.6
CVE-2026-70804 18.08.2026 7.7
CVE-2026-70805 18.08.2026 8.1
CVE-2026-70806 18.08.2026 7.1
CVE-2026-70807 18.08.2026 8.5
CVE-2026-70808 18.08.2026 7.1
CVE-2026-70809 18.08.2026 7.1
CVE-2026-70810 18.08.2026 7.5
CVE-2026-70811 18.08.2026 8.1
CVE-2026-70812 18.08.2026 8.8
CVE-2026-70813 18.08.2026 8.8
CVE-2026-70814 18.08.2026 8.1
CVE-2026-70815 18.08.2026 8.1
CVE-2026-70816 18.08.2026 7.1
CVE-2026-70817 18.08.2026 9.8
CVE-2026-70818 18.08.2026 8.8
CVE-2026-70819 18.08.2026 8.8
CVE-2026-70820 18.08.2026 7.2
CVE-2026-70821 18.08.2026 8.8
CVE-2026-70822 18.08.2026 7.5
CVE-2026-70823 18.08.2026 7.4
CVE-2026-70824 18.08.2026 6.5
CVE-2026-70825 18.08.2026 6.5
CVE-2026-70826 18.08.2026 6.5
CVE-2026-70827 18.08.2026 7.7
CVE-2026-70828 18.08.2026 7.7
CVE-2026-70829 18.08.2026 7.5
CVE-2026-70830 18.08.2026 8.1
CVE-2026-70831 18.08.2026 6.5
CVE-2026-70832 18.08.2026 7.5
CVE-2026-70833 18.08.2026 7.1
CVE-2026-70834 18.08.2026 7.2
CVE-2026-70835 18.08.2026 8.1
CVE-2026-70836 18.08.2026 5.5
CVE-2026-70837 18.08.2026 7.1
CVE-2026-70838 18.08.2026 6.1
CVE-2026-70839 18.08.2026 7.1
CVE-2026-70840 18.08.2026 8.4
CVE-2026-70841 18.08.2026 5.6
CVE-2026-70842 18.08.2026 8.4
CVE-2026-70843 18.08.2026 6.8
CVE-2026-70844 18.08.2026 7.1
CVE-2026-70845 18.08.2026 7.1
CVE-2026-70846 18.08.2026 9.6
CVE-2026-70847 18.08.2026 6.5
CVE-2026-70848 18.08.2026 3.7
CVE-2026-70849 18.08.2026 6.5
CVE-2026-70850 18.08.2026 3
CVE-2026-70851 18.08.2026 3.1
CVE-2026-70852 18.08.2026 8.2
CVE-2026-70853 18.08.2026 3.3
CVE-2026-70854 18.08.2026 9.1
CVE-2026-70855 18.08.2026 9.3
CVE-2026-70856 18.08.2026 7.5
CVE-2026-70857 18.08.2026 7.7
CVE-2026-70858 18.08.2026 7.1
CVE-2026-70859 18.08.2026 8.5
CVE-2026-70861 18.08.2026 7.2
CVE-2026-70862 18.08.2026 9.1
CVE-2026-70863 18.08.2026 8.8
CVE-2026-70864 18.08.2026 7.6
CVE-2026-70865 18.08.2026 7.5
CVE-2026-70866 18.08.2026 7.8
CVE-2026-70867 18.08.2026 7.1
CVE-2026-70868 18.08.2026 8.1
CVE-2026-70870 18.08.2026 8.2
CVE-2026-70871 18.08.2026 9.8
CVE-2026-70872 18.08.2026 9.1
CVE-2026-70873 18.08.2026 9.8
CVE-2026-70874 18.08.2026 8.8
CVE-2026-70875 18.08.2026 7.5
CVE-2026-70876 18.08.2026 9.1
CVE-2026-70877 18.08.2026 8.8
CVE-2026-70878 18.08.2026 8.1
CVE-2026-70879 18.08.2026 7.8
CVE-2026-70880 18.08.2026 10
CVE-2026-70881 18.08.2026 8.1
CVE-2026-70882 18.08.2026 8.7
CVE-2026-70883 18.08.2026 9.1
CVE-2026-70884 18.08.2026 9.1
CVE-2026-70885 18.08.2026 8.5
CVE-2026-70886 18.08.2026 8.8
CVE-2026-70887 18.08.2026 8.2
CVE-2026-70888 18.08.2026 6.6
CVE-2026-70889 18.08.2026 7.5
CVE-2026-70890 18.08.2026 7.5
CVE-2026-70891 18.08.2026 7.5
CVE-2026-70892 18.08.2026 8.2
CVE-2026-70893 18.08.2026 8.2
CVE-2026-52817 Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escalation 18.08.2026
CVE-2026-53453 Blueprint Studio API authorization bypass for non-admin Home Assistant users 18.08.2026
CVE-2026-53454 Blueprint Studio stored Git credentials in plaintext Git credential store 18.08.2026
CVE-2026-53455 Blueprint Studio Git credential helper command injection 18.08.2026
CVE-2026-53456 Blueprint Studio terminal SSH private key written to disk 18.08.2026
CVE-2026-53457 Blueprint Studio terminal command working directory not bounded to config directory 18.08.2026
CVE-2026-53458 Blueprint Studio API exposed internal exception details 18.08.2026
CVE-2026-56867 18.08.2026
CVE-2026-56868 18.08.2026
CVE-2026-56869 18.08.2026
CVE-2026-56870 18.08.2026
CVE-2026-56871 18.08.2026
CVE-2026-56872 18.08.2026
CVE-2026-56873 18.08.2026
CVE-2026-56874 18.08.2026
CVE-2026-15571 Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client 19.08.2026
CVE-2026-76033 18.08.2026
CVE-2026-76034 18.08.2026
CVE-2026-76035 18.08.2026
CVE-2026-76036 18.08.2026
CVE-2026-76037 18.08.2026
CVE-2026-76038 18.08.2026
CVE-2026-76039 18.08.2026
CVE-2026-76040 18.08.2026
CVE-2026-76041 18.08.2026
CVE-2026-76042 18.08.2026
CVE-2026-76043 18.08.2026
CVE-2026-76044 18.08.2026
CVE-2026-76045 18.08.2026
CVE-2026-76046 18.08.2026
CVE-2026-76047 18.08.2026
CVE-2026-16732 fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count 18.08.2026 6.1
CVE-2026-18504 fastify vulnerable to schema validation bypass via root primitive coercion mismatch 18.08.2026 5.4
CVE-2026-55593 Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery Protection 18.08.2026 6.5
CVE-2026-52793 Froxlor: API Authentication bypasses 2FA Authentication 18.08.2026 8.1
CVE-2026-54347 Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover 18.08.2026 8.7
CVE-2026-54348 Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration 18.08.2026 7.2
CVE-2026-54543 Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields 18.08.2026 5.4
CVE-2026-62988 Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints 18.08.2026 9
CVE-2026-67442 FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup 18.08.2026 2
CVE-2026-47719 FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading 18.08.2026 8.2
CVE-2026-47721 FUXA: Scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions 18.08.2026 6.3
CVE-2026-57826 18.08.2026
CVE-2026-65984 FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions 18.08.2026
CVE-2026-65985 FUXA: SSRF hardening for `device-webapi-request` 18.08.2026
CVE-2026-67440 FUXA: Unauthenticated Socket.IO read events 18.08.2026
CVE-2026-67443 FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) 18.08.2026
CVE-2026-71675 18.08.2026
CVE-2026-47720 FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString 18.08.2026 5.3
CVE-2026-49500 18.08.2026 6
CVE-2026-52480 18.08.2026
CVE-2026-52481 18.08.2026
CVE-2026-59915 19.08.2026 7.3
CVE-2026-71676 18.08.2026
CVE-2026-73104 18.08.2026
CVE-2026-73105 18.08.2026
CVE-2026-73106 18.08.2026
CVE-2026-73111 18.08.2026
CVE-2026-73112 18.08.2026
CVE-2026-75877 TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow 18.08.2026
CVE-2026-76032 Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler 18.08.2026
CVE-2026-12520 Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers 18.08.2026 6.4
CVE-2026-73103 18.08.2026
CVE-2026-75935 Memory-amplification denial of service via declared-length preallocation in Amazon ion-java 18.08.2026 7.5
CVE-2026-75936 Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java 18.08.2026 7.5
CVE-2026-52731 ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate 18.08.2026 6.5
CVE-2026-52732 ZEBRA: Mempool transaction admission denial via single-peer inbound queue saturation 18.08.2026 5.3
CVE-2026-52733 ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip 18.08.2026 6.5
CVE-2026-52734 ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention 18.08.2026 5.3
CVE-2026-52735 ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser 18.08.2026
CVE-2026-52736 ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache 18.08.2026
CVE-2026-52737 ZEBRA: Sync restart poisoning from single unauthenticated peer via above-lookahead block 18.08.2026 5.3
CVE-2026-52738 ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks 18.08.2026
CVE-2026-52739 ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection 18.08.2026 5.9
CVE-2026-52829 ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book 18.08.2026 7.5
CVE-2026-19670 Incorrect Authorization in CISA Malcolm 18.08.2026
CVE-2026-19671 Improper handling of highly compressed data (data amplification) in CISA Malcolm 18.08.2026
CVE-2026-70666 Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs 18.08.2026 7.4
CVE-2026-71303 Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist 18.08.2026 7.7
CVE-2026-71307 Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API 18.08.2026 7.7
CVE-2026-71308 Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates 18.08.2026 8.1
CVE-2026-71317 Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority 18.08.2026 6.5
CVE-2026-71322 Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False 18.08.2026 4.3
CVE-2026-71417 Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it 18.08.2026 7.3
CVE-2026-73529 Plainpad Missing Rate Limiting via POST /v1/sessions 18.08.2026
CVE-2026-75876 xianrendzw EasyReport Move Operations ModuleController.java sql injection 18.08.2026
CVE-2026-55162 Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded certificates 18.08.2026 6.3
CVE-2026-55163 Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membership 18.08.2026 6.3
CVE-2026-55164 Lemur: Plaintext password storage in Lemur user-update path 18.08.2026 4.9
CVE-2026-55165 Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosure 18.08.2026 4.8
CVE-2026-55166 Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR 18.08.2026 9.9
CVE-2026-70667 Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for CVE-2026-55162) 18.08.2026 6.3
CVE-2025-9210 Missing JSON Web Token signature validation in Otalio Ship Property Management System 18.08.2026 8.1
CVE-2025-9211 Cross-site scripting in Otalio Ship Property Management System 18.08.2026 6.7
CVE-2026-17106 Tar extraction in moby/go-archive can write outside the destination directory via link following 19.08.2026
CVE-2021-43718 18.08.2026
CVE-2026-24183 18.08.2026 7.8
CVE-2026-24184 18.08.2026 7.5
CVE-2026-24185 18.08.2026 7.1
CVE-2026-47606 18.08.2026 6.5
CVE-2026-47627 18.08.2026 9.8
CVE-2026-47628 18.08.2026 7.5
CVE-2026-47629 18.08.2026 7.5
CVE-2026-47630 18.08.2026 5.5
CVE-2026-65959 Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data 18.08.2026 5.3
CVE-2021-43716 18.08.2026
CVE-2021-43717 18.08.2026
CVE-2026-18392 18.08.2026
CVE-2026-48508 Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission 18.08.2026 8.8
CVE-2026-49452 WeasyPrint: CSS Injection via Presentational Hints 18.08.2026 6.5
CVE-2026-50167 Kurrier: Authenticated cross-user authorization bypass in Kurrier API 18.08.2026
CVE-2026-69160 OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API 18.08.2026 6.5
CVE-2026-71551 Super Productivity: Arbitrary OS Command Execution via IPC EXEC Handler with Persistent Whitelist 18.08.2026 7.8
CVE-2026-75130 Context7 2.1.2 Prompt Injection via Custom AI Instructions 18.08.2026
CVE-2026-32657 19.08.2026 7.3
CVE-2026-50143 Actor MCP path authority injection leaks Apify token 18.08.2026 8.1
CVE-2026-50161 libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow 18.08.2026
CVE-2026-53533 aiosmtplib: SMTP command injection via CR/LF in sender/recipient address 18.08.2026
CVE-2026-61696 Forem: Stored XSS in Admin Abuse Report Rendering 18.08.2026 6.3
CVE-2026-67846 18.08.2026
CVE-2026-71880 Server-side template injection in Integrated Publishing Toolkit 18.08.2026
CVE-2026-73502 kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema 18.08.2026 5.3
CVE-2026-75625 Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass 18.08.2026
CVE-2026-54552 sh _uid does not drop supplementary groups (incomplete privilege drop) 18.08.2026 7.9
CVE-2026-54570 AngleSharp: HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass 18.08.2026 6.9
CVE-2026-67921 18.08.2026
CVE-2026-68922 MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads 18.08.2026 5.5
CVE-2026-68923 MobSF: CSRF checks not enforced after Django migration 18.08.2026 6.5
CVE-2026-68924 MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction 18.08.2026 4.9
CVE-2026-68927 MobSF: SSRF port restriction bypass in assetlinks_check 18.08.2026 3
CVE-2026-71878 Authentication bypass in Integrated Publishing Toolkit 18.08.2026
CVE-2026-71879 Authentication bypass in Integrated Publishing Toolkit 18.08.2026
CVE-2026-52610 18.08.2026
CVE-2026-63640 MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables 18.08.2026 4.3
CVE-2026-66780 Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace 18.08.2026
CVE-2026-67262 19.08.2026 8.1
CVE-2026-67920 18.08.2026
CVE-2026-74038 Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment 18.08.2026
CVE-2026-74039 Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context 18.08.2026
CVE-2026-74044 Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello 18.08.2026
CVE-2026-74046 Wazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip Bomb 18.08.2026
CVE-2026-44472 Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge 18.08.2026 8.1
CVE-2026-52607 18.08.2026
CVE-2026-52608 18.08.2026
CVE-2026-52609 18.08.2026
CVE-2026-63641 MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions 18.08.2026
CVE-2026-63642 MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery 18.08.2026
CVE-2026-63643 MagicMirror: ssrf calendar .js 18.08.2026
CVE-2026-18963 Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass 19.08.2026
CVE-2026-30250 18.08.2026
CVE-2026-48744 Saleor: Anonymous users can modify channel settings via `channelUpdate` due to `all([])` bypass in permission check 18.08.2026 6.5
CVE-2026-52606 18.08.2026
CVE-2026-57580 authentik: Account Takeover via SAML NameID Comment Truncation 18.08.2026
CVE-2026-66781 Submariner-operator: submariner-operator: ipsec psk stored cleartext in submariner cr spec 18.08.2026
CVE-2026-66782 Submariner-operator: submariner-operator: broker api bearer token stored cleartext in cr spec 18.08.2026
CVE-2026-66783 Submariner-operator: submariner-operator: arbitrary image override enables privileged code execution on every node 18.08.2026
CVE-2026-75897 Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards 18.08.2026 7.5
CVE-2026-50576 ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests 18.08.2026 6.8
CVE-2026-50577 ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter 18.08.2026 7.4
CVE-2026-50578 ePA 3.x Integration: TLS Certificate Verification Universally Disabled 18.08.2026 7.5
CVE-2026-52723 ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust 18.08.2026 9.1
CVE-2026-54730 authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView 18.08.2026
CVE-2026-55106 authentik: Unauthenticated LDAP directory data disclosure 18.08.2026 5.3
CVE-2026-61574 authentik RAC: access any endpoint via an unrelated application 18.08.2026 8.8
CVE-2026-70415 19.08.2026 8.1
CVE-2026-19869 Privilege Escalation via Dropped Field-Level @authentication 18.08.2026
CVE-2026-50126 adaguc-server GeoJSON coordinate parser (CConvertGeoJSON.cpp) vulnerable to out-of-bounds read and NULL pointer dereference 18.08.2026 4
CVE-2026-61634 RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max 18.08.2026
CVE-2026-67271 19.08.2026 9.8
CVE-2026-49222 Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products 18.08.2026 7.6
CVE-2026-49223 Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete reviews under other Vendors' products 18.08.2026 7.6
CVE-2026-49224 Vvveb post revision authorization bypass allows Authors to read, restore, or delete other Authors' post revisions 18.08.2026 8.3
CVE-2026-49225 Vvveb product revision authorization bypass allows Vendors to read, restore, or delete other Vendors' product revisions 18.08.2026 8.3
CVE-2026-63335 RabbitMQ Java client malformed body frame triggers raw command assembler exception 18.08.2026
CVE-2026-63336 RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM 18.08.2026
CVE-2026-63337 RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading 18.08.2026
CVE-2026-69219 RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation 18.08.2026
CVE-2026-69220 RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS 18.08.2026
CVE-2026-75924 Managed-serviceaccount: managed-serviceaccount: hub addon-manager clusterrole grants cluster-wide secret read/write and csr approval 18.08.2026
CVE-2026-49228 Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products 18.08.2026 8.8
CVE-2026-71572 Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-71573 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-72531 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-73336 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-73372 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 19.08.2026
CVE-2026-45118 MyBB: Contact page reflected XSS 18.08.2026 9.3
CVE-2026-49221 Vvveb digital asset authorization bypass allows Vendors to list, read, edit, or delete other Vendors' digital assets 18.08.2026 8.8
CVE-2026-49226 Vvveb post authorization bypass allows Authors to view, duplicate, or delete other Authors' posts 18.08.2026 8.3
CVE-2026-49227 Vvveb comment authorization bypass allows Authors to read, approve, edit, or delete comments under other Authors' posts 18.08.2026 7.6
CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-72532 Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 19.08.2026
CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 19.08.2026
CVE-2026-12564 Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf 18.08.2026
CVE-2026-15806 `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching 18.08.2026
CVE-2026-45115 MyBB: Buddy/ignore list username XSS 18.08.2026 8.7
CVE-2026-45116 MyBB: Profile field type confusion XSS 18.08.2026 8.7
CVE-2026-45117 MyBB: Installer database configuration RCE 18.08.2026 9.8
CVE-2026-45119 MyBB: ACP UTF-8 Conversion CSRF 18.08.2026 4.6
CVE-2026-45120 MyBB: Insufficient authorization for private calendar events 18.08.2026 5.4
CVE-2026-45121 MyBB: Insufficient permission check for calendar select 18.08.2026 4.3
CVE-2026-45122 MyBB: Insufficient permission check for calendar event move 18.08.2026 4.3
CVE-2026-45123 MyBB: IPv6 SSRF 18.08.2026 4.3
CVE-2026-45124 MyBB: Mod CP report resolution missing authorization 18.08.2026 4.3
CVE-2026-45125 MyBB: Email User CRLF injection 18.08.2026 5.3
CVE-2026-45126 MyBB: ACP Questions state CSRF 18.08.2026 3.5
CVE-2026-45128 MyBB: ACP Users View Manager default CSRF 18.08.2026 3.5
CVE-2026-45129 MyBB: ACP Recovery Codes CSRF 18.08.2026 4.6
CVE-2026-45734 MyBB: Default CAPTCHA missing invalidation 18.08.2026 5.3
CVE-2026-46482 MyBB: Security Question insufficient validation 18.08.2026 5.3
CVE-2026-47245 MyBB: Buddy list corruption 18.08.2026 4.3
CVE-2026-71365 Awx: webhook status callback ssrf leaks the git pat 18.08.2026
CVE-2026-75926 Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant 18.08.2026
CVE-2026-45127 MyBB: ACP Mass Mail draft resend CSRF 18.08.2026 3.5
CVE-2026-55839 Kestra: Stored XSS via custom Markdown [[link]] attribute injection 18.08.2026 8.7
CVE-2026-19500 SureForms contains an uncontrolled resource consumption vulnerability 18.08.2026
CVE-2026-19501 CVE-2026-19501 18.08.2026
CVE-2026-62357 DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap out-of-bounds write 18.08.2026
CVE-2026-62684 File Browser: Share API exposes the password hash and bypass token 18.08.2026 2.7
CVE-2026-63328 Trivy: Path Traversal in Trivy Plugin Manager Allows Arbitrary File Write 18.08.2026
CVE-2026-71477 mise: Incorrect file ownership, when installed by the root user using `install.sh` 18.08.2026 6.7
CVE-2026-73073 Vim: Arbitrary Ex Command Execution in C Omni-Completion 18.08.2026
CVE-2026-73834 Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redaction 18.08.2026
CVE-2026-75485 Must-gather: must-gather: cluster proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials 18.08.2026
CVE-2026-75856 CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU 18.08.2026
CVE-2026-75857 CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact 18.08.2026
CVE-2026-75858 CodeWhale rlm_eval before 0.8.64 Remote Code Execution 18.08.2026
CVE-2026-75859 CodeWhale before 0.8.64 Arbitrary File Read via instructions 18.08.2026
CVE-2026-75904 libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI File 18.08.2026
CVE-2026-75911 CodeWhale before 0.8.64 Remote Code Execution via allow_shell 18.08.2026
CVE-2026-75912 CodeWhale before 0.8.64 Argument Injection via git_blame 18.08.2026
CVE-2026-75913 CodeWhale before 0.8.64 Argument Injection via git_show 18.08.2026
CVE-2026-75914 CodeWhale before 0.8.64 Path Traversal via image_analyze symlink 18.08.2026
CVE-2026-75915 CodeWhale before 0.8.64 Environment Variable Leak via js_execution 18.08.2026
CVE-2026-45733 Trilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop app 18.08.2026 8.3
CVE-2026-50139 goshs: Share-link ?token=… redemption races past download limit 18.08.2026 5.9
CVE-2026-50187 Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious .env files 18.08.2026 8.8
CVE-2026-59825 Mastodon: Unwanted deactivation of SSL/TLS certificate verification 18.08.2026 7.4
CVE-2026-66793 Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via managedclusteraddon annotation enables rce on spoke 18.08.2026
CVE-2026-68939 Pyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual) 18.08.2026
CVE-2026-69189 Hoppscotch: Cross-user private data exposure and UserHistory IDOR via team GraphQL resolvers 18.08.2026 7.6
CVE-2026-18534 Address bar spoofing risk in affected iOS versions of Arc Search 18.08.2026 7.4
CVE-2026-48798 SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames 18.08.2026 7.1
CVE-2026-50138 goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags 18.08.2026 8.1
CVE-2026-59949 yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI) 18.08.2026 6.5
CVE-2026-63632 ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape 18.08.2026 3.3
CVE-2026-70657 Copyparty: file/dirkey confusion 18.08.2026 4.3
CVE-2026-59940 Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization 18.08.2026 9.8
CVE-2026-61407 18.08.2026 8.8
CVE-2026-71539 n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution 19.08.2026
CVE-2026-75032 Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder 18.08.2026
CVE-2026-75890 18.08.2026
CVE-2026-56684 Valkey: TLS pending-data processing use-after-free may allow remote code execution 19.08.2026 7.5
CVE-2026-63639 Valkey: UAF in stream deserialization may lead to remote code execution 19.08.2026 8.8
CVE-2026-73426 Trix: Stored XSS vulnerability through serialized attributes 18.08.2026 4.6
CVE-2026-75898 RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component 18.08.2026
CVE-2026-32470 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-32472 WordPress Online Contact Widget plugin <= 1.3.0 - Broken Access Control vulnerability 18.08.2026 7.5
CVE-2026-32473 WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Request Forgery (SSRF) vulnerability 18.08.2026 7.2
CVE-2026-32474 WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-32481 WordPress Ezoic plugin <= 2.22.11 - Broken Authentication vulnerability 18.08.2026 7.5
CVE-2026-32547 WordPress BP Better Messages plugin <= 2.15.22 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-32549 WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability 18.08.2026 7.5
CVE-2026-32553 WordPress OttoKit plugin <= 1.1.35 - Server Side Request Forgery (SSRF) vulnerability 18.08.2026 7.2
CVE-2026-66046 Expat Denial of Service via storeAtts() Quadratic Complexity 18.08.2026
CVE-2026-66620 WordPress OptionTree plugin <= 2.7.3 - PHP Object Injection vulnerability 18.08.2026 7.2
CVE-2026-66621 WordPress Ultimate Dashboard plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-66622 WordPress Depicter Slider plugin <= 4.8.0 - SQL Injection vulnerability 18.08.2026 7.5
CVE-2026-66627 WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-66629 WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-66633 WordPress Fluent Forms Pro Add On Pack plugin < 6.2.12 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-66634 WordPress Modal Survey plugin <= 2.0.2.2.3 - Insecure Direct Object References (IDOR) vulnerability 18.08.2026 4.3
CVE-2026-66635 WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability 18.08.2026 7.4
CVE-2026-66636 WordPress Wise Chat plugin <= 3.4 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66637 WordPress Featured Video Plus plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66638 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66639 WordPress WPZOOM Forms – Contact Form plugin for Gutenberg plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66640 WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66641 WordPress Video Conferencing with Zoom plugin <= 4.6.8 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66643 WordPress Wufoo Shortcode plugin <= 1.55 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66644 WordPress Typing Effect plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66645 WordPress Table Of Contents Block plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66646 WordPress WP Tab Widget plugin <= 1.2.11 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-66651 WordPress MultiVendorX plugin <= 5.0.14 - Broken Access Control vulnerability 18.08.2026 6.5
CVE-2026-66667 WordPress Templately plugin <= 3.7.1 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-66679 WordPress Appointment Hour Booking plugin <= 1.5.91 - Broken Access Control vulnerability 18.08.2026 6.5
CVE-2026-68565 WordPress GeoDirectory plugin <= 2.8.172 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-68567 WordPress Convert Pro plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-68568 WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability 18.08.2026 6.3
CVE-2026-73181 WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbitrary File Download vulnerability 18.08.2026 7.5
CVE-2026-73187 WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73189 WordPress WP Crowdfunding plugin < 2.2.1 - Insecure Direct Object References (IDOR) vulnerability 18.08.2026 6.5
CVE-2026-73190 WordPress WPDM – Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73338 WordPress Autopay plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73339 WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73341 WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73342 WordPress WP Multilang plugin <= 2.4.31 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73343 WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability 18.08.2026 10
CVE-2026-73345 WordPress License Manager for WooCommerce plugin <= 3.0.18 - SQL Injection vulnerability 18.08.2026 7.1
CVE-2026-73348 WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability 18.08.2026 6.5
CVE-2026-73350 WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability 18.08.2026 8.2
CVE-2026-73351 WordPress WordPress Social Login and Register plugin <= 7.8.1 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73352 WordPress GiveWP plugin <= 4.16.5.1 - Broken Access Control vulnerability 18.08.2026 6.5
CVE-2026-73355 WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73356 WordPress Breeze plugin <= 2.5.12 - Arbitrary Content Deletion vulnerability 18.08.2026 8.2
CVE-2026-73358 WordPress Affiliates Manager plugin <= 2.9.53 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73359 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.3.9 - Cross Site Scripting (XSS) vulnerability 18.08.2026 6.5
CVE-2026-73360 WordPress Chaty Pro plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73361 WordPress Recipe Card Blocks for Gutenberg & Elementor plugin <= 3.4.18 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73362 WordPress URL Shortify plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73365 WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73366 WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73367 WordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerability 18.08.2026 7.2
CVE-2026-73375 WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73376 WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73377 WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - Broken Access Control vulnerability 18.08.2026 7.5
CVE-2026-73378 WordPress Contact Form by Supsystic plugin < 1.10.0 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73379 WordPress Contact Form by Supsystic plugin < 1.10.0 - Bypass Vulnerability vulnerability 18.08.2026 6.5
CVE-2026-73380 WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability 18.08.2026 9.8
CVE-2026-73381 WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability 18.08.2026 9.1
CVE-2026-73382 WordPress Site Reviews plugin <= 8.2.0 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73383 WordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerability 18.08.2026 4.9
CVE-2026-73392 WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-73393 WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-73395 WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Insecure Direct Object References (IDOR) vulnerability 18.08.2026 6.5
CVE-2026-73396 WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication vulnerability 18.08.2026 7.1
CVE-2026-73397 WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability 18.08.2026 9.8
CVE-2026-73398 WordPress Piraeus Bank WooCommerce Payment Gateway plugin 3.2.0 - Broken Authentication vulnerability 18.08.2026 6.5
CVE-2026-73399 WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vulnerability 18.08.2026 6.5
CVE-2026-73400 WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerability 18.08.2026 8.1
CVE-2026-73404 WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability 18.08.2026 6.5
CVE-2026-73994 WordPress Charitable plugin <= 1.8.11.3 - Broken Access Control vulnerability 18.08.2026 7.5
CVE-2026-73995 WordPress User Registration plugin <= 5.2.6 - Broken Authentication vulnerability 18.08.2026 5.4
CVE-2026-73996 WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability 18.08.2026 9.8
CVE-2026-73997 WordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service Attack vulnerability 18.08.2026 7.5
CVE-2026-74003 WordPress RomethemeForm For Elementor plugin <= 1.2.6 - Broken Access Control vulnerability 18.08.2026 4.3
CVE-2026-74004 WordPress Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control vulnerability 18.08.2026 5.4
CVE-2026-74006 WordPress WP Table Builder plugin <= 2.2.0 - Broken Access Control vulnerability 18.08.2026 4.3
CVE-2026-74007 WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure vulnerability 18.08.2026 5.3
CVE-2026-74008 WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.22 - Sensitive Data Exposure vulnerability 18.08.2026 5.3
CVE-2026-74009 WordPress Razorpay for WooCommerce plugin <= 4.8.7 - Insecure Direct Object References (IDOR) vulnerability 18.08.2026 5.3
CVE-2026-74012 WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability 18.08.2026 8.8
CVE-2026-74015 WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability 18.08.2026 9.3
CVE-2026-75784 TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow 18.08.2026
CVE-2026-75872 HTML Injection in MailerUp double opt-in verification email 18.08.2026
CVE-2026-17084 stringprep.map_table_b2() deviates from RFC 3454 Table B.2 19.08.2026
CVE-2026-28191 WordPress The Grid plugin <= 2.7.9.1 - Privilege Escalation vulnerability 18.08.2026 8.8
CVE-2026-28192 WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability 18.08.2026 9.6
CVE-2026-28567 WordPress WP Sort Order plugin <= 1.3.5 - Broken Access Control vulnerability 18.08.2026 7.5
CVE-2026-28568 WordPress Quill Forms plugin <= 5.7.1 - Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-28569 WordPress SSL Zen plugin <= 4.7.43 - Reflected Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-28570 WordPress Vavo Core plugin <= 2.3.0 - Local File Inclusion vulnerability 18.08.2026 8.1
CVE-2026-28571 WordPress FormyChat plugin <= 2.15.7 - Broken Access Control vulnerability 18.08.2026 7.5
CVE-2026-32333 WordPress Mayosis Core plugin <= 5.4.7 - Reflected Cross Site Scripting (XSS) vulnerability 18.08.2026 7.1
CVE-2026-32444 WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability 18.08.2026 9.9
CVE-2026-32463 WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability 18.08.2026 9.9
CVE-2026-32464 WordPress Theme Test Drive plugin <= 2.9.1 - Local File Inclusion vulnerability 18.08.2026 8.1
CVE-2026-32465 WordPress Essential Real Estate plugin <= 5.3.3 - PHP Object Injection vulnerability 18.08.2026 8.8
CVE-2026-32466 WordPress Gravity Forms Bookings premium plugin <= 2.1 - SQL Injection vulnerability 18.08.2026 8.5
CVE-2026-32467 WordPress [Aotuman] Grab WeChat Articles plugin <= 2.0.1 - Server Side Request Forgery (SSRF) vulnerability 18.08.2026 6
CVE-2026-32468 WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability 18.08.2026 7.5
CVE-2026-50575 BetterDesk has a replay behavior vulnerability when devices are deleted 18.08.2026 7.7
CVE-2026-73692 18.08.2026
CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability 18.08.2026 8.8
CVE-2026-16309 IDOR in Netiket Information Technologies' EdoWEB 18.08.2026 5.3
CVE-2026-45532 DataEase has a Path Traversal Vulnerability 18.08.2026
CVE-2026-75783 TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow 18.08.2026
CVE-2026-18751 Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751 19.08.2026
CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component 18.08.2026
CVE-2026-74935 Privilege escalation in the DOM: Networking component 18.08.2026
CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component 18.08.2026
CVE-2026-74937 Use-after-free in the JavaScript: GC component 18.08.2026
CVE-2026-74938 Mitigation bypass in the JavaScript: GC component 18.08.2026
CVE-2026-74939 Privilege escalation in the DOM: Navigation component 18.08.2026
CVE-2026-74940 Use-after-free in the Graphics: Text component 18.08.2026
CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component 18.08.2026
CVE-2026-74942 Privilege escalation in the Remote Settings Client component 18.08.2026
CVE-2026-74943 Use-after-free in the Graphics: ImageLib component 18.08.2026
CVE-2026-74944 Use-after-free in the DOM: Core & HTML component 18.08.2026
CVE-2026-74945 Information disclosure in the Graphics: Text component 18.08.2026
CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component 18.08.2026
CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component 18.08.2026
CVE-2026-74948 Information disclosure in the Graphics component 18.08.2026
CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component 18.08.2026
CVE-2026-74950 Privilege escalation in the Downloads API component 18.08.2026
CVE-2026-74951 Clickjacking issue in Firefox for Android 18.08.2026
CVE-2026-74952 Privilege escalation in the Application Update component 18.08.2026
CVE-2026-74953 Privilege escalation in the Networking: Cookies component 18.08.2026
CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component 18.08.2026
CVE-2026-74955 Privilege escalation in the Request Handling component 18.08.2026
CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component 18.08.2026
CVE-2026-74957 Mitigation bypass in the Safe Browsing component 18.08.2026
CVE-2026-74958 Information disclosure in the WebRTC component 18.08.2026
CVE-2026-74959 Mitigation bypass in the Storage: Cache API component 18.08.2026
CVE-2026-74960 Site isolation issue in the WebExtensions component 18.08.2026
CVE-2026-74961 Side-channel in the Web Audio component 18.08.2026
CVE-2026-74962 Site isolation issue in the Networking: Cookies component 18.08.2026
CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component 18.08.2026
CVE-2026-74964 Integer overflow in the Graphics component 18.08.2026
CVE-2026-74965 Privilege escalation in the Shell Integration component 18.08.2026
CVE-2026-74966 Information disclosure in the Form Autofill component 18.08.2026
CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component 18.08.2026
CVE-2026-74968 Site isolation issue in the Graphics: WebRender component 18.08.2026
CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component 18.08.2026
CVE-2026-74970 Site isolation issue in the Graphics component 18.08.2026
CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component 18.08.2026
CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component 18.08.2026
CVE-2026-74973 Race condition, use-after-free in the Graphics component 18.08.2026
CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component 18.08.2026
CVE-2026-74975 Spoofing issue in the Downloads component in Firefox for Android 18.08.2026
CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component 18.08.2026
CVE-2026-74977 Integer overflow in the Graphics component 18.08.2026
CVE-2026-74978 Clickjacking issue in the Widget component 18.08.2026
CVE-2026-74979 Mitigation bypass in the Add-ons Manager component 18.08.2026
CVE-2026-74980 Clickjacking issue in the Downloads component in Firefox for Android 18.08.2026
CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component 18.08.2026
CVE-2026-74982 Denial-of-service in the Widget component 18.08.2026
CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component 18.08.2026
CVE-2026-74984 Race condition in the JavaScript Engine component 18.08.2026
CVE-2026-74985 Privilege escalation in the Enterprise Policies component 18.08.2026
CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component 18.08.2026
CVE-2026-74987 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 18.08.2026
CVE-2026-74988 Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 18.08.2026
CVE-2026-74989 Internally found bugs fixed in Thunderbird 154 18.08.2026
CVE-2026-74990 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 18.08.2026
CVE-2026-75874 Sandbox escape in the Remote Settings Client component 18.08.2026
CVE-2026-1199 API and Frontend login lockout race condition 18.08.2026
CVE-2026-23922 Email media OAuth secret leak to Super Admin 18.08.2026
CVE-2026-23929 Prototype pollution leading to stored XSS 19.08.2026
CVE-2026-23930 Frontend DoS via the popup.testtriggerexpr action 18.08.2026
CVE-2026-23931 Frontend plaintext macro value enumeration via the validatate.api.exists action 18.08.2026
CVE-2026-23933 Hardcoded session key in Zabbix 7.4 19.08.2026
CVE-2026-23934 Frontend DoS via the validate.api.exists action 18.08.2026
CVE-2026-23935 Use-after-free read in script item/preprocessing HttpRequest body 18.08.2026
CVE-2026-23937 Host PSK extraction in Zabbix API 18.08.2026
CVE-2026-23938 Server DoS via JavaScript preprocessing or script items 18.08.2026
CVE-2026-59781 Improper validation of custom installation directories on Windows could allow installation into locations with unsafe permissions, increasing the risk of DLL sideloading. 19.08.2026
CVE-2026-75778 code-projects Task Management System Login Form index.php select_with_multiple_condition sql injection 18.08.2026
CVE-2026-5224 Sensitive Data Exposure in Kriptek Crypto's Cryptosim 18.08.2026 5.7
CVE-2026-15585 Path Traversal in AKIN Software's Wolvox9 ERP 18.08.2026 7.5
CVE-2026-74902 SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload 18.08.2026
CVE-2026-74903 SiYuan before v3.7.4 Insufficient Access Control via spinBlockDOM 18.08.2026
CVE-2026-74904 SiYuan before v3.7.4 Missing Authorization via block API 18.08.2026
CVE-2026-74905 SiYuan before v3.7.4 SSRF via IPv6 Transition Address Bypass 18.08.2026
CVE-2026-74906 SiYuan before v3.7.4 Incorrect Authorization via Publish Access 18.08.2026
CVE-2026-74907 Grav before 2.0.15 Path Traversal via plugin-asset-map.php 18.08.2026
CVE-2026-74908 Grav plugin-api before 1.0.15 Script Injection via SVG 18.08.2026
CVE-2026-75107 Grav Form Plugin before 9.1.19 Stored XSS via Field Properties 18.08.2026
CVE-2026-75774 karakeep-app karakeep OAuth Sign-In auth.ts improper authentication 18.08.2026
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log 18.08.2026
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass 18.08.2026
CVE-2026-75829 grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint 18.08.2026
CVE-2026-75830 grav-plugin-api before 1.0.15 Path Traversal via batchCopy 18.08.2026
CVE-2026-75831 Grav before 2.0.15 Stored XSS via audio/video source URL 18.08.2026
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass 18.08.2026
CVE-2026-75833 Grav API Plugin Open Redirect via Backslash Bypass 18.08.2026
CVE-2026-75834 Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte 18.08.2026
CVE-2026-75835 Grav API Plugin before 1.0.14 Missing Authorization 18.08.2026
CVE-2026-75836 Grav API Plugin before 1.0.14 Missing Authorization 18.08.2026
CVE-2026-75837 Grav before 2.0.14 Privilege Escalation via Group Access Field 18.08.2026
CVE-2026-75838 DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook 18.08.2026
CVE-2026-75839 ArcadeDB before 26.8.1 Information Disclosure via Cluster Endpoints 18.08.2026
CVE-2026-75840 ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex 18.08.2026
CVE-2026-75841 ArcadeDB before 26.8.1 Denial of Service via range() 18.08.2026
CVE-2026-75842 ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV 18.08.2026
CVE-2026-75843 ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction 18.08.2026
CVE-2026-75844 ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass 18.08.2026
CVE-2026-75845 ArcadeDB 26.4.2 before 26.8.1 Authorization Bypass via set_server_setting 18.08.2026
CVE-2026-75846 ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTION 18.08.2026
CVE-2026-75850 ArcadeDB before 26.8.1 Per-Type ACL Bypass via Batch Handlers 18.08.2026
CVE-2026-75851 ArcadeDB before 26.8.1 Authentication Bypass via Async Command 18.08.2026
CVE-2026-75852 ArcadeDB MongoDB wire protocol authentication bypass cross-database 18.08.2026
CVE-2026-75853 ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database 18.08.2026
CVE-2026-75854 ArcadeDB Redis Wire-Protocol Plugin Missing Authentication 18.08.2026
CVE-2026-75855 ArcadeDB before 26.8.1 Path Traversal via create/drop database 18.08.2026
CVE-2026-19608 Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy path-specific group policies 18.08.2026
CVE-2026-19447 Stored XSS in Fileorbis Informatics's FileOrbis 19.08.2026 5.4
CVE-2026-75773 karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication 18.08.2026