CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 09.08.2026 9.3
CVE-2026-71992 MSI Radix AXE6600 v781521 Command Injection via macfilter 08.08.2026 9.3
CVE-2026-71993 MSI Radix AXE6600 v781521 Command Injection via openvpn function 09.08.2026 9.3
CVE-2026-71991 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 08.08.2026 9.3
CVE-2026-71986 MSI Radix AXE6600 v781521 Command Injection via dmz Function 08.08.2026 9.3
CVE-2026-71987 MSI Radix AXE6600 v781521 Command Injection via alg function 08.08.2026 9.3
CVE-2026-71988 MSI Radix AXE6600 v781521 Command Injection via portFw function 08.08.2026 9.3
CVE-2026-71989 MSI Radix AXE6600 v781521 Command Injection via porTrigger function 08.08.2026 9.3
CVE-2026-71990 MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function 08.08.2026 9.3
CVE-2026-71984 MSI Radix AXE6600 v781521 Command Injection via urlfilter 08.08.2026 9.3
CVE-2026-71985 MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function 08.08.2026 9.3
CVE-2026-71983 MSI Radix AXE6600 v781521 Command Injection via wps.cgi 08.08.2026 9.3
CVE-2026-71956 D-Link DWR-M961 Command Injection via app.cgi 08.08.2026 9.3
CVE-2026-71957 D-Link DWR-M961 Buffer Overflow via app.cgi 08.08.2026 9.3
CVE-2026-71958 D-Link DWR-M961 Buffer Overflow via quicksetup.cgi 08.08.2026 9.3
CVE-2026-71944 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel 08.08.2026 9.3
CVE-2026-71945 D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom 08.08.2026 9.3
CVE-2026-71946 D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun 08.08.2026 9.3
CVE-2026-71947 D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun 08.08.2026 9.3
CVE-2026-71948 D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun 08.08.2026 9.3
CVE-2026-71949 D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup 08.08.2026 9.3
CVE-2026-71950 D-Link DWR-M961 Command Injection via /boafrm/formSmsManage 08.08.2026 9.3
CVE-2026-71951 D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup 08.08.2026 9.3
CVE-2026-71952 D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup 08.08.2026 9.3
CVE-2026-71953 D-Link DWR-M961 Command Injection via /boafrm/formNtp 08.08.2026 9.3
CVE-2026-71954 D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup 08.08.2026 9.3
CVE-2026-71955 D-Link DWR-M961 Command Injection via /boafrm/formWsc 08.08.2026 9.3
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route 08.08.2026 9.8
CVE-2026-46409 OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution 07.08.2026 9.6
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs 07.08.2026 9.2
CVE-2026-48170 scimPatch vulnerable to prototype pollution via unfiltered keys in patch 07.08.2026 9.1
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading 07.08.2026 9.6
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration 07.08.2026 9.8
CVE-2026-48039 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 07.08.2026 9.1
CVE-2026-71851 crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain 08.08.2026 9
CVE-2026-64637 07.08.2026 9.9
CVE-2022-4995 Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp 07.08.2026 9.3
CVE-2026-19264 Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover 07.08.2026 9.3
CVE-2026-66914 Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 07.08.2026 9.2
CVE-2026-54203 TeamDavid: Memory Leak leaking sensitive information 07.08.2026 9.2
CVE-2026-54210 TeamDavid: Buffer Overflow in file names of file upload functionalities 07.08.2026 9.5
CVE-2026-54211 TeamDavid: Buffer Overflow in multiple form data parameters 07.08.2026 9.5
CVE-2026-54212 TeamDavid: Buffer Overflow in JSON-parsing 07.08.2026 9.5
CVE-2026-54213 TeamDavid: Denial of Service via endpoint 'internalRestart' 07.08.2026 9.2
CVE-2026-14364 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' 07.08.2026 9.8
CVE-2026-14365 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' 07.08.2026 9.8
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability 07.08.2026 9.9
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability 07.08.2026 9.6
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability 08.08.2026 10
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability 07.08.2026 9.3
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability 08.08.2026 9.8
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability 07.08.2026 9.6
CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability 07.08.2026 10
CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability 07.08.2026 10
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability 07.08.2026 9.1
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability 07.08.2026 9.6
CVE-2025-14561 Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations 07.08.2026 9
CVE-2026-11976 MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise 07.08.2026 10
CVE-2026-14812 Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) 07.08.2026 10
CVE-2026-17032 Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server 07.08.2026 9.8
CVE-2026-18367 07.08.2026 9.3
CVE-2026-3418 Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution 07.08.2026 9.1
CVE-2026-43629 llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore 07.08.2026 9.2
CVE-2026-43631 llama.cpp b7492–b9060 Use-After-Free RCE via llama-server 07.08.2026 9.2
CVE-2026-43632 llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints 08.08.2026 9.2
CVE-2026-48085 OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap 07.08.2026 9.8
CVE-2026-48086 OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN 07.08.2026 9.9
CVE-2026-48087 OpenReception: WebAuthn passkey injection allows account takeover 07.08.2026 9.8
CVE-2026-48088 OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory 08.08.2026 9.4
CVE-2026-53983 Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL 07.08.2026 9.2
CVE-2026-5857 Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments 08.08.2026 9.2
CVE-2026-70558 Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token 08.08.2026 9.3
CVE-2026-28005 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-28139 WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-53975 OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec 06.08.2026 9.3
CVE-2026-53976 OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter 06.08.2026 9.3
CVE-2026-54489 06.08.2026 9.1
CVE-2026-65507 WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-65508 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65520 WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65546 WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65548 WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.9
CVE-2026-65552 WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65553 WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability 06.08.2026 10
CVE-2026-65556 WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65571 WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65572 WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65573 WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65574 WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65575 WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65576 WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65577 WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65578 WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65579 WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65581 WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-66447 WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-66665 WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability 06.08.2026 10
CVE-2026-66709 WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.1
CVE-2026-67261 06.08.2026 9.8
CVE-2026-12605 06.08.2026 9.6
CVE-2026-5134 SQLi in Loca Software's CMS 06.08.2026 9.8
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products 06.08.2026 9.4
CVE-2026-1728 Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover 06.08.2026 9.8
CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover 06.08.2026 10
CVE-2026-64597 smb: client: fix double-free in SMB2_close() replay 08.08.2026 9.8
CVE-2026-67531 FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool 06.08.2026 9.3
CVE-2026-71319 Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution 07.08.2026 9.6
CVE-2026-48168 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name 05.08.2026 10
CVE-2026-20267 Cisco IOS XE Software Security Hardening Release 06.08.2026 9
CVE-2026-20272 Cisco IOS XE Software Security Hardening Release 06.08.2026 9.8
CVE-2026-20303 Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities 06.08.2026 9.9
CVE-2026-20304 Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities 06.08.2026 9.9
CVE-2026-20310 Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access 06.08.2026 9.1
CVE-2026-7329 Privilege escalation in Progress MarkLogic Server REST query interfaces 07.08.2026 9.9
CVE-2026-7557 SAML authentication bypass in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-8709 Privilege escalation in Progress MarkLogic Server REST document patch operation 07.08.2026 9.9
CVE-2026-9190 HTTP request smuggling in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-9192 Authentication bypass in Progress MarkLogic Server ODBC App Server 07.08.2026 9.8
CVE-2026-9193 Privilege escalation in Progress MarkLogic Server Hadoop integration 07.08.2026 9.9
CVE-2026-9195 Cross-site scripting in Progress MarkLogic Server Query Console 05.08.2026 9.3
CVE-2026-15587 Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header 05.08.2026 9.4
CVE-2026-39923 Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset 05.08.2026 9.2
CVE-2026-71262 IoTSharp BlobStorageController Missing Authentication and Path Traversal 05.08.2026 9.8
CVE-2026-71263 FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() 05.08.2026 9.1
CVE-2026-71267 microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() 05.08.2026 9.8
CVE-2026-71268 OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write 05.08.2026 9.9
CVE-2026-71277 rust-iot-platform Authentication Bypass via Non-Validated Authorization Header 05.08.2026 9.1
CVE-2026-71278 rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation 05.08.2026 9.8
CVE-2026-71289 NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API 05.08.2026 9.8
CVE-2026-71254 nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() 05.08.2026 9.8
CVE-2026-71256 nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id 05.08.2026 9.8
CVE-2026-66747 ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant 05.08.2026 9.3
CVE-2026-71231 IOTSmartHome: Unauthenticated SQL Injection via lastLogin Cookie 05.08.2026 9.8
CVE-2026-71237 Miantang IoT-PHP: Unauthenticated SQL Injection in /userlogin 05.08.2026 9.8
CVE-2026-71238 DjangoCRM: Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery 05.08.2026 9.1
CVE-2026-71248 Inventory-Management-System-PHP: Unauthenticated SQL Injection in Login and Product Deletion 05.08.2026 9.8
CVE-2026-44945 Cross-Cluster Impersonation Confused-Deputy Privilege Escalation 06.08.2026 9.1
CVE-2026-10059 Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token 05.08.2026 9.1
CVE-2026-10090 Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription 05.08.2026 9.9
CVE-2026-4431 Easy Post Submission <= 2.3.0 - Missing Authorization 05.08.2026 9.1
CVE-2026-64566 xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() 08.08.2026 9.8
CVE-2026-5581 Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion 05.08.2026 9.1
CVE-2026-70376 Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE 05.08.2026 9.6
CVE-2026-71207 Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass 05.08.2026 9.8
CVE-2026-71213 typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force 05.08.2026 9.1
CVE-2026-71214 NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server 05.08.2026 9.8
CVE-2026-9273 Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover 05.08.2026 9.3
CVE-2026-45537 OpenSIPS: Global Buffer Overflow in construct_uri 05.08.2026 9.1
CVE-2026-45100 OpenSIPS: Buffer Overflow in Base64 Encode Transformation 05.08.2026 9.1
CVE-2026-45538 OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy 05.08.2026 9.8
CVE-2026-70554 MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie 05.08.2026 9.3
CVE-2026-70477 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability 05.08.2026 9.5
CVE-2026-70478 Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service 05.08.2026 9.2
CVE-2026-70552 MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php 05.08.2026 9.3
CVE-2026-70553 MaxSite CMS Unauthenticated RCE via Install Endpoint 05.08.2026 9.3
CVE-2017-20241 Keysight IxChariot Endpoint heap-based buffer overflow 04.08.2026 9.3
CVE-2017-20242 Keysight IxChariot Endpoint stack-based buffer overflow 04.08.2026 9.3
CVE-2026-49435 Keysight IxChariot-related products stack-based buffer overflow 04.08.2026 9.3
CVE-2026-69703 Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit 04.08.2026 9.3
CVE-2026-24254 04.08.2026 9.8
CVE-2026-69264 Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation 04.08.2026 9.4
CVE-2026-70470 Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE 04.08.2026 9.5
CVE-2026-63455 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-63456 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-58072 05.08.2026 9
CVE-2026-58073 05.08.2026 9.5
CVE-2026-64633 05.08.2026 10
CVE-2026-69255 Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified 04.08.2026 9.2
CVE-2026-69256 Flowise: Remote Code Execution Vulnerability in CSVAgent 05.08.2026 9.4
CVE-2026-69259 Flowise RCE via SQLite Record Manager Node 04.08.2026 9.4
CVE-2026-18801 Stored Clickhouse SQL Injection Through Customer Usage Attribution 04.08.2026 9.3
CVE-2026-25289 Stack-based Buffer Overflow in WLAN Firmware 05.08.2026 9.6
CVE-2026-69098 kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization 05.08.2026 9.3
CVE-2026-69110 OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music 04.08.2026 9.3
CVE-2026-69253 Flowise Sandbox Escape to RCE 05.08.2026 9
CVE-2026-69254 Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override 04.08.2026 9.4
CVE-2026-61514 Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 04.08.2026 9.3
CVE-2026-61515 Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell 05.08.2026 9.3
CVE-2026-69251 Flowise RCE via TypeORM DataSource 04.08.2026 9
CVE-2026-60007 04.08.2026 9.1
CVE-2026-14175 Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-14804 Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.1
CVE-2026-15721 Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-18753 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) 04.08.2026 9.1
CVE-2026-18754 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) 04.08.2026 9.1
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing 09.08.2026 9.8
CVE-2026-18686 GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection 04.08.2026 9.3
CVE-2026-18685 GL.iNet GL-MT3000 modem.so glc set_upgrade command injection 04.08.2026 9.3
CVE-2026-18684 GL.iNet GL-MT3000 modem.so glc remove_profile command injection 04.08.2026 9.3
CVE-2026-48317 Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 04.08.2026 9.6
CVE-2026-48323 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 04.08.2026 10
CVE-2026-48326 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 04.08.2026 9.9
CVE-2026-48330 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 05.08.2026 10
CVE-2026-48331 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 04.08.2026 10
CVE-2026-48333 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 04.08.2026 9.8
CVE-2026-18667 Sensor Proxy Version 1.4.2 Fixes One Vulnerability 05.08.2026 9.3
CVE-2026-46713 Misskey: JSON-LD signature validation + compaction may lead to improper activity handling 04.08.2026 9.2
CVE-2026-48063 Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload 04.08.2026 9.3
CVE-2026-69240 Sequelize: SQL Injection (Oracle DB) 04.08.2026 9.8
CVE-2026-48031 Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery 03.08.2026 9.1
CVE-2026-67598 Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php 04.08.2026 9.1
CVE-2026-18616 GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection 04.08.2026 9.3
CVE-2026-18614 GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection 03.08.2026 9.3
CVE-2026-18615 GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection 03.08.2026 9.3
CVE-2026-18612 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection 03.08.2026 9.3
CVE-2026-18613 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection 03.08.2026 9.3
CVE-2026-18602 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection 03.08.2026 9.3
CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection 03.08.2026 9.4
CVE-2026-41452 Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup 03.08.2026 9.3
CVE-2026-18248 @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header 03.08.2026 9.1
CVE-2026-18601 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection 03.08.2026 9.3
CVE-2026-64827 Telenia TVox 26.5.3 Authentication Bypass via set_env.php 07.08.2026 9.3
CVE-2026-68584 SiYuan before v3.7.3 Authentication Bypass via Content Endpoints 03.08.2026 9.2
CVE-2026-68586 SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc 03.08.2026 9.2
CVE-2026-68587 SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction 03.08.2026 9.2
CVE-2026-69083 SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent 03.08.2026 9.9
CVE-2026-69084 SiYuan before v3.7.3 SQL Injection via searchEmbedBlock 03.08.2026 9.9
CVE-2026-69085 SiYuan before v3.7.3 SQL Injection via searchDocs 03.08.2026 9.9
CVE-2026-18574 Authentication Bypass in Check Point Security Management Server 05.08.2026 9.3
CVE-2026-2346 IDOR in Menulux Software's Mobile App 03.08.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-21058 10.08.2026
CVE-2026-21059 10.08.2026
CVE-2026-21060 10.08.2026
CVE-2026-21061 10.08.2026
CVE-2026-21062 10.08.2026
CVE-2026-57279 10.08.2026
CVE-2026-64940 10.08.2026 8.6
CVE-2026-12570 Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras 10.08.2026
CVE-2026-12971 LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature 10.08.2026
CVE-2026-13133 10.08.2026
CVE-2026-13170 Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting 10.08.2026
CVE-2026-13600 AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron 10.08.2026
CVE-2026-13701 Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting 10.08.2026
CVE-2026-14206 HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure 10.08.2026
CVE-2026-14211 Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR 10.08.2026
CVE-2026-14237 Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation 10.08.2026
CVE-2026-14238 Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report 10.08.2026
CVE-2026-14293 Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor 10.08.2026
CVE-2026-14860 Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery 10.08.2026
CVE-2026-14941 Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions 10.08.2026
CVE-2026-15047 s2Member < 260805 - Contributor+ Stored XSS via Shortcode 10.08.2026
CVE-2026-15229 Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary Booking Price Manipulation 10.08.2026
CVE-2026-15237 Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint 10.08.2026
CVE-2026-15238 Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR 10.08.2026
CVE-2026-16257 Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling 10.08.2026
CVE-2026-16298 FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset 10.08.2026
CVE-2026-16299 Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset 10.08.2026
CVE-2026-16949 Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup 10.08.2026
CVE-2026-16985 Squeeze < 1.7.12 - Author+ Arbitrary File Upload 10.08.2026
CVE-2026-17010 Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta 10.08.2026
CVE-2026-17012 Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email 10.08.2026
CVE-2026-17016 Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment 10.08.2026
CVE-2026-17018 CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR 10.08.2026
CVE-2026-17019 JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG) 10.08.2026
CVE-2026-17020 Salon Booking System – Free Version <= 10.30.33 - Subscriber+ Arbitrary Booking PII Disclosure via IDOR 10.08.2026
CVE-2026-17021 Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Arbitrary Booking Total Tampering 10.08.2026
CVE-2026-17022 Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Booking Information Disclosure via Booking Wizard 10.08.2026
CVE-2026-17023 Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback 10.08.2026
CVE-2026-17540 Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch 10.08.2026
CVE-2026-17541 Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure 10.08.2026
CVE-2026-17542 Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector 10.08.2026
CVE-2026-18030 Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms 10.08.2026
CVE-2026-18200 FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update 10.08.2026
CVE-2026-18468 Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header 10.08.2026
CVE-2026-18469 Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute Force 10.08.2026
CVE-2026-18470 Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response 10.08.2026
CVE-2026-18666 Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value 10.08.2026
CVE-2026-18786 CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass 10.08.2026
CVE-2026-18934 RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Deletion 10.08.2026
CVE-2026-18946 Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable Filename 10.08.2026
CVE-2026-18960 Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords 10.08.2026
CVE-2026-19049 ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie 10.08.2026
CVE-2026-19053 ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter 10.08.2026
CVE-2026-19074 Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure 10.08.2026
CVE-2026-19075 All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter 10.08.2026
CVE-2026-19077 Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization 10.08.2026
CVE-2026-19089 Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload 10.08.2026
CVE-2026-17519 10.08.2026
CVE-2026-72522 10.08.2026 6.2
CVE-2026-19387 Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder 10.08.2026
CVE-2026-19389 Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read 10.08.2026
CVE-2026-19384 SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection 10.08.2026
CVE-2026-19383 saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload 10.08.2026
CVE-2026-19382 Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak 10.08.2026
CVE-2026-19379 EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection 10.08.2026
CVE-2026-19380 Mullvad wireguard.sys IOCTL AdapterState reference count 10.08.2026
CVE-2026-19381 Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management 10.08.2026
CVE-2026-19378 code-projects Task Management System CommentSave.php cross site scripting 09.08.2026
CVE-2026-19376 Uasoft Badaso File API api.php class permission 09.08.2026
CVE-2026-19375 dmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery 09.08.2026
CVE-2026-19374 adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery 09.08.2026
CVE-2026-12372 Server-Side Request Forgery (SSRF) in nltk/nltk 09.08.2026
CVE-2026-19373 PhialsBasement KoboldCPP-MCP-Server BaseConfigSchema index.ts makeRequest server-side request forgery 09.08.2026
CVE-2026-19372 Handwriting-OCR handwriting-ocr-mcp-server upload_document index.ts fs.readFileSync path traversal 09.08.2026
CVE-2026-19371 Nikolaibibo claude-comfyui-mcp comfy_upload_image utils.ts copyFileSync path traversal 09.08.2026
CVE-2026-19370 bartekke8it56w2 new-mcp geminithinking index.ts fs.readFileSync path traversal 09.08.2026
CVE-2026-19369 KS-GEN-AI jira-mcp-server add_attachment_from_public_url index.ts axios.get server-side request forgery 09.08.2026
CVE-2026-19368 PV-Bhat gemsuite-mcp gemini_search unified-gemini.ts path traversal 09.08.2026
CVE-2026-19367 NocteDefensor LudusMCP read_range_config rangeConfig.ts server-side request forgery 09.08.2026
CVE-2026-19366 NocteDefensor LudusMCP insert_creds_range_config insertCredsRangeConfig.ts path traversal 09.08.2026
CVE-2026-19365 Ichigo3766 image-gen-mcp upscale_images index.ts path traversal 09.08.2026
CVE-2026-70395 Predicate injection in manage_relationship belongs_to lookup discloses secret lookup keys in Ash 09.08.2026
CVE-2026-19364 itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection 09.08.2026
CVE-2026-69659 Memory exhaustion via unbounded deserialization of keyset pagination cursors in Ash.Page.Keyset 09.08.2026
CVE-2026-15534 Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch 09.08.2026
CVE-2026-19363 lmammino oidc-authorizer Fixed Message handler.rs unwrap deserialization 09.08.2026
CVE-2026-19362 lmammino oidc-authorizer Authorization Header Parsing parse_token_from_header.rs parse_token_from_header denial of service 09.08.2026
CVE-2026-19361 macrozheng mall mall-portal getAuthCode password recovery 09.08.2026
CVE-2026-19360 wongcyrus ExcelLexBot Lambda Function ExcelLexBotS3TriggerFunction privileges management 09.08.2026
CVE-2026-19359 nxp-auto-goldvip gvip Lambda Function SitewiseCustomFunction access control 09.08.2026
CVE-2026-19358 3CORESec Trapdoor DefaultFunction access control 09.08.2026
CVE-2026-19357 MingSoft MCMS ms-mdiy get information disclosure 09.08.2026
CVE-2026-19356 MingSoft MCMS ms-mdiy list information disclosure 09.08.2026
CVE-2026-19354 lock-upme OPMS IN Clause message.go sql injection 09.08.2026
CVE-2026-19355 MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection 09.08.2026
CVE-2026-19353 DedeCMS Installation Wizard index.php _4_Setup file inclusion 09.08.2026
CVE-2026-19352 mifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery 09.08.2026
CVE-2026-19351 dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection 09.08.2026
CVE-2026-19350 Dolibarr ERP TakePOS invoice.php fail authorization 09.08.2026
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 09.08.2026