CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-66012 SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP 25.07.2026 10
CVE-2026-66013 OpenRemote before 1.26.2 Authentication Bypass via Console Registration 25.07.2026 9.3
CVE-2026-61884 Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel 24.07.2026 9.3
CVE-2026-62835 Azure Portal Information Disclosure Vulnerability 25.07.2026 9.3
CVE-2026-48021 epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau 25.07.2026 9.1
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 25.07.2026 10
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability 24.07.2026 10
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability 25.07.2026 10
CVE-2026-12503 Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter 24.07.2026 9.2
CVE-2026-24727 SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type 24.07.2026 9.3
CVE-2026-15704 CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components 24.07.2026 9.8
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability 25.07.2026 9.9
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability 25.07.2026 9.9
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability 25.07.2026 9.1
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability 25.07.2026 9.8
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability 25.07.2026 10
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability 25.07.2026 10
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability 25.07.2026 10
CVE-2026-28698 Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs 24.07.2026 9.2
CVE-2026-42933 Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs 24.07.2026 10
CVE-2024-58353 Cal.com through 4.7.15 Cross-Site Scripting via booking questions 24.07.2026 9.3
CVE-2024-58355 Cal.com through 4.7.15 Cross-Site Scripting via booking questions 24.07.2026 9.3
CVE-2025-71389 Cal.com before 5.9.9 Remote Code Execution via RSC 24.07.2026 10
CVE-2026-63732 9router before 0.4.60 Remote Code Execution via default password 23.07.2026 9.4
CVE-2026-49035 Stack-based Buffer Overflow in MZ Automation libIEC61850 24.07.2026 9.2
CVE-2026-15981 SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter 24.07.2026 9.8
CVE-2026-47724 nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation 23.07.2026 9.9
CVE-2026-47669 DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE 24.07.2026 9.3
CVE-2026-47670 DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection 24.07.2026 9.4
CVE-2026-63359 Appriss Insights VINE SQLI 23.07.2026 9.3
CVE-2026-47668 DbGate: Unauthenticated Remote Code Execution via JSON Script Runner 24.07.2026 10
CVE-2026-6516 Remote Code Execution 24.07.2026 10
CVE-2026-47752 Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution 23.07.2026 9.9
CVE-2026-65700 h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API 23.07.2026 9.3
CVE-2026-65701 SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route 23.07.2026 9.3
CVE-2026-65760 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 24.07.2026 9.2
CVE-2026-65761 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 24.07.2026 9.3
CVE-2026-65687 Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing 24.07.2026 9.3
CVE-2026-65688 Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing 24.07.2026 9.3
CVE-2026-65689 Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download 24.07.2026 9.3
CVE-2026-65907 24.07.2026 9.1
CVE-2026-64812 24.07.2026 10
CVE-2026-64813 24.07.2026 10
CVE-2026-65605 SiYuan before v3.7.2 Stored XSS to RCE via Attribute View 24.07.2026 9.4
CVE-2026-65606 SiYuan before v3.7.2 Cross-Site Scripting to RCE 24.07.2026 9.4
CVE-2026-27064 WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-57784 WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-59514 WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59525 WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59526 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59540 WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-59543 WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability 23.07.2026 9.9
CVE-2026-59544 WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability 23.07.2026 9.8
CVE-2026-59555 WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability 23.07.2026 10
CVE-2026-61948 WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61949 WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61950 WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61951 WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-65455 WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65461 WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65471 WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-15015 MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint 23.07.2026 9.8
CVE-2026-14282 GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field 23.07.2026 9.8
CVE-2026-15011 Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter 23.07.2026 9.8
CVE-2026-16723 Remote Code Execution in fastjson 1.2.68–1.2.83 23.07.2026 9
CVE-2026-60366 23.07.2026 10
CVE-2026-60367 23.07.2026 9.8
CVE-2026-60369 23.07.2026 9.9
CVE-2026-60372 23.07.2026 9.8
CVE-2026-13072 MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption 24.07.2026 9.2
CVE-2026-64829 Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow 24.07.2026 9.1
CVE-2026-40712 24.07.2026 9.1
CVE-2026-46738 24.07.2026 9.1
CVE-2026-16606 Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris 22.07.2026 9.3
CVE-2026-2395 SQLi in Xpoda Türkiye Informatics Technology's No Code Platform 22.07.2026 9.8
CVE-2026-63048 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 23.07.2026 9.4
CVE-2026-47731 NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker) 22.07.2026 9.1
CVE-2026-60328 23.07.2026 9.8
CVE-2026-60329 23.07.2026 9.8
CVE-2026-60333 24.07.2026 9.9
CVE-2026-60355 24.07.2026 9.8
CVE-2026-60358 24.07.2026 10
CVE-2026-60360 24.07.2026 10
CVE-2026-60361 24.07.2026 9.9
CVE-2026-60362 24.07.2026 9.8
CVE-2026-60363 24.07.2026 9.8
CVE-2026-60364 24.07.2026 9.8
CVE-2026-60365 24.07.2026 10
CVE-2026-60374 24.07.2026 9.8
CVE-2026-60375 24.07.2026 9.8
CVE-2026-60376 24.07.2026 9.8
CVE-2026-60377 24.07.2026 9.9
CVE-2026-60378 24.07.2026 9.8
CVE-2026-60379 24.07.2026 10
CVE-2026-60380 24.07.2026 9.8
CVE-2026-60381 24.07.2026 9.9
CVE-2026-60384 24.07.2026 9.8
CVE-2026-60385 24.07.2026 9.8
CVE-2026-60386 24.07.2026 9.8
CVE-2026-60387 24.07.2026 9.8
CVE-2026-60388 24.07.2026 9.8
CVE-2026-60389 24.07.2026 10
CVE-2026-60402 24.07.2026 9.9
CVE-2026-60422 24.07.2026 9.9
CVE-2026-60424 24.07.2026 9
CVE-2026-60429 24.07.2026 9.9
CVE-2026-60435 24.07.2026 9.8
CVE-2026-60438 24.07.2026 9.1
CVE-2026-60441 24.07.2026 9.8
CVE-2026-60442 24.07.2026 9.8
CVE-2026-60445 24.07.2026 9.9
CVE-2026-60446 24.07.2026 9.8
CVE-2026-60447 24.07.2026 9.9
CVE-2026-60456 24.07.2026 9.9
CVE-2026-60457 24.07.2026 9.9
CVE-2026-60458 24.07.2026 9.9
CVE-2026-60459 24.07.2026 9.9
CVE-2026-60460 24.07.2026 9.8
CVE-2026-60461 24.07.2026 9.9
CVE-2026-60463 24.07.2026 9.8
CVE-2026-60524 24.07.2026 9.9
CVE-2026-60531 24.07.2026 9.9
CVE-2026-60532 24.07.2026 9.8
CVE-2026-60535 24.07.2026 9.8
CVE-2026-60537 24.07.2026 9.9
CVE-2026-60538 24.07.2026 9.8
CVE-2026-60540 21.07.2026 9.6
CVE-2026-60541 21.07.2026 9.8
CVE-2026-60542 21.07.2026 9.9
CVE-2026-60547 21.07.2026 9.9
CVE-2026-60551 21.07.2026 9.8
CVE-2026-60552 21.07.2026 9.9
CVE-2026-60555 21.07.2026 9.8
CVE-2026-60561 21.07.2026 9.9
CVE-2026-60562 21.07.2026 9.9
CVE-2026-60564 21.07.2026 9.6
CVE-2026-60565 21.07.2026 9.9
CVE-2026-60566 21.07.2026 9.8
CVE-2026-60567 21.07.2026 9.1
CVE-2026-60568 21.07.2026 9.9
CVE-2026-60606 21.07.2026 9.1
CVE-2026-60627 25.07.2026 9.9
CVE-2026-60631 21.07.2026 9.3
CVE-2026-60632 21.07.2026 9.3
CVE-2026-60644 21.07.2026 10
CVE-2026-60649 21.07.2026 9.1
CVE-2026-60663 24.07.2026 9.9
CVE-2026-60711 25.07.2026 9.9
CVE-2026-60719 24.07.2026 9.9
CVE-2026-60773 24.07.2026 9.6
CVE-2026-60880 24.07.2026 9.8
CVE-2026-60999 24.07.2026 9.8
CVE-2026-61041 24.07.2026 9.9
CVE-2026-61059 24.07.2026 9.1
CVE-2026-61065 24.07.2026 9.8
CVE-2026-61072 24.07.2026 9.9
CVE-2026-61076 24.07.2026 9.9
CVE-2026-61097 23.07.2026 9.6
CVE-2026-61100 23.07.2026 9.8
CVE-2026-61129 23.07.2026 9.8
CVE-2026-61130 23.07.2026 9.1
CVE-2026-61131 23.07.2026 9.8
CVE-2026-61140 23.07.2026 9.8
CVE-2026-61145 23.07.2026 9.8
CVE-2026-61146 23.07.2026 9.9
CVE-2026-61153 23.07.2026 9.1
CVE-2026-61154 23.07.2026 9.8
CVE-2026-61155 23.07.2026 9.1
CVE-2026-61156 23.07.2026 9.1
CVE-2026-61161 23.07.2026 9.8
CVE-2026-61167 23.07.2026 9.8
CVE-2026-61171 23.07.2026 9.1
CVE-2026-61174 23.07.2026 9
CVE-2026-61175 23.07.2026 9.3
CVE-2026-61178 23.07.2026 9.8
CVE-2026-61183 23.07.2026 9.8
CVE-2026-61184 23.07.2026 9.1
CVE-2026-61186 23.07.2026 9.4
CVE-2026-61196 22.07.2026 9.8
CVE-2026-61197 22.07.2026 9.1
CVE-2026-61201 22.07.2026 9
CVE-2026-61203 22.07.2026 9.4
CVE-2026-61204 22.07.2026 9
CVE-2026-61207 22.07.2026 9.3
CVE-2026-61209 22.07.2026 9.9
CVE-2026-61211 22.07.2026 9.9
CVE-2026-61223 22.07.2026 9
CVE-2026-61233 22.07.2026 9.8
CVE-2026-61235 22.07.2026 9.1
CVE-2026-61237 22.07.2026 9.9
CVE-2026-61238 22.07.2026 9.1
CVE-2026-61239 22.07.2026 9.9
CVE-2026-61242 22.07.2026 9.9
CVE-2026-61244 22.07.2026 9.1
CVE-2026-61245 22.07.2026 9.8
CVE-2026-62546 22.07.2026 9.1
CVE-2026-62549 22.07.2026 9.6
CVE-2026-65318 Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader 22.07.2026 9.2
CVE-2026-35290 23.07.2026 9.8
CVE-2026-46876 23.07.2026 9.8
CVE-2026-46924 23.07.2026 9.8
CVE-2026-46982 23.07.2026 9.8
CVE-2026-46983 23.07.2026 9.8
CVE-2026-46989 23.07.2026 9.1
CVE-2026-46994 23.07.2026 9.8
CVE-2026-47036 25.07.2026 9.8
CVE-2026-47040 23.07.2026 9.1
CVE-2026-47056 23.07.2026 10
CVE-2026-60168 23.07.2026 9.1
CVE-2026-60173 23.07.2026 9.8
CVE-2026-60197 23.07.2026 9.8
CVE-2026-60198 23.07.2026 9.8
CVE-2026-60199 23.07.2026 9.8
CVE-2026-60200 23.07.2026 9.8
CVE-2026-60202 25.07.2026 9.8
CVE-2026-60204 25.07.2026 9.8
CVE-2026-60205 25.07.2026 9.8
CVE-2026-60206 25.07.2026 9.9
CVE-2026-60208 25.07.2026 9.1
CVE-2026-60209 23.07.2026 9.8
CVE-2026-60210 23.07.2026 9.8
CVE-2026-60212 23.07.2026 9.8
CVE-2026-60215 23.07.2026 9.8
CVE-2026-60216 23.07.2026 9.8
CVE-2026-60217 23.07.2026 10
CVE-2026-60219 23.07.2026 9.8
CVE-2026-60220 23.07.2026 9.3
CVE-2026-60221 23.07.2026 9.8
CVE-2026-60224 23.07.2026 9.8
CVE-2026-60225 23.07.2026 9.8
CVE-2026-60226 23.07.2026 9.8
CVE-2026-60227 23.07.2026 9.8
CVE-2026-60228 23.07.2026 9.8
CVE-2026-60229 23.07.2026 9.8
CVE-2026-60230 23.07.2026 9.8
CVE-2026-60232 23.07.2026 9.8
CVE-2026-60234 23.07.2026 9.8
CVE-2026-60236 23.07.2026 9.8
CVE-2026-60239 23.07.2026 9.6
CVE-2026-60240 23.07.2026 9.8
CVE-2026-60241 23.07.2026 9.8
CVE-2026-60242 23.07.2026 9.8
CVE-2026-60244 23.07.2026 9.8
CVE-2026-60246 23.07.2026 9.8
CVE-2026-60247 23.07.2026 9.8
CVE-2026-60248 23.07.2026 9.3
CVE-2026-60249 23.07.2026 9
CVE-2026-60250 23.07.2026 9.8
CVE-2026-60251 23.07.2026 9.8
CVE-2026-60253 23.07.2026 9.8
CVE-2026-60254 23.07.2026 9.8
CVE-2026-60256 23.07.2026 9.8
CVE-2026-60257 23.07.2026 9.8
CVE-2026-60258 23.07.2026 9.8
CVE-2026-60259 23.07.2026 9.8
CVE-2026-60262 23.07.2026 9.8
CVE-2026-60264 23.07.2026 9.8
CVE-2026-60267 23.07.2026 9.1
CVE-2026-60269 24.07.2026 9.8
CVE-2026-60272 23.07.2026 9.8
CVE-2026-60274 23.07.2026 9.8
CVE-2026-60275 23.07.2026 9.8
CVE-2026-60276 24.07.2026 9.8
CVE-2026-60278 23.07.2026 9.8
CVE-2026-60279 24.07.2026 9.8
CVE-2026-60280 23.07.2026 9.8
CVE-2026-60285 23.07.2026 9.8
CVE-2026-60286 23.07.2026 9.8
CVE-2026-60287 23.07.2026 9.8
CVE-2026-60288 23.07.2026 9.8
CVE-2026-60289 23.07.2026 9.8
CVE-2026-60290 23.07.2026 9.8
CVE-2026-60291 25.07.2026 9.8
CVE-2026-60292 25.07.2026 9.8
CVE-2026-60294 25.07.2026 9.8
CVE-2026-60296 21.07.2026 9.8
CVE-2026-60297 23.07.2026 9.8
CVE-2026-60298 23.07.2026 9.8
CVE-2026-60299 23.07.2026 9.8
CVE-2026-60300 23.07.2026 9.8
CVE-2026-60302 23.07.2026 9.8
CVE-2026-60306 23.07.2026 9.8
CVE-2026-60308 23.07.2026 9.8
CVE-2026-60326 23.07.2026 9.1
CVE-2026-65317 Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass 23.07.2026 9.2
CVE-2026-8984 Unauthenticated RCE 22.07.2026 10
CVE-2026-8985 Unauthenticated Command Injection 22.07.2026 10
CVE-2026-8986 Command Injection via Malicious OCPP Server 22.07.2026 9.5
CVE-2026-8987 Authenticated Heap Overflow 22.07.2026 9.4
CVE-2026-47708 MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper 22.07.2026 9.3
CVE-2026-65057 Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck 22.07.2026 9.2
CVE-2026-8982 Hard-coded / Backdoor Accounts 22.07.2026 10
CVE-2026-8983 Backdoor Authentication Token 22.07.2026 10
CVE-2026-64878 Command Injection 24.07.2026 9.4
CVE-2026-64879 Command Injection 24.07.2026 9.4
CVE-2016-20096 Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp 22.07.2026 9.3
CVE-2026-64877 24.07.2026 9.4
CVE-2026-47413 praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members 22.07.2026 9.6
CVE-2026-47416 praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id} 22.07.2026 9.6
CVE-2026-47407 PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation 22.07.2026 9.4
CVE-2026-47410 praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset 22.07.2026 9.8
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution 23.07.2026 9.8
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) 21.07.2026 9.9
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default 22.07.2026 9.8
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset 22.07.2026 9.8
CVE-2026-64824 Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore 21.07.2026 9.3
CVE-2026-64825 Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload 21.07.2026 9
CVE-2026-65048 Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index 22.07.2026 9.3
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData 22.07.2026 9.3
CVE-2026-1617 SQLi in Turkmesh's Turkhotspot 5651 Loglama 21.07.2026 9.8
CVE-2026-13439 Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint 21.07.2026 9.8
CVE-2026-64625 AVideo before 29.0 OS Command Injection via execAsync 23.07.2026 9.3
CVE-2026-13380 VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses 21.07.2026 9
CVE-2026-53595 FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL 21.07.2026 9.4
CVE-2026-16337 21.07.2026 9.4
CVE-2026-44231 RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint 21.07.2026 9.1
CVE-2026-63766 GPT-SoVITS 20250606v2pro OS Command Injection via webui.py 21.07.2026 9.3
CVE-2026-63767 ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ 21.07.2026 9.3
CVE-2026-61424 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 23.07.2026 10
CVE-2026-61425 Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 23.07.2026 9.4
CVE-2026-61900 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 23.07.2026 10
CVE-2026-60032 Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 23.07.2026 9.4
CVE-2026-60034 Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 23.07.2026 9.4
CVE-2026-39878 Chamilo stored XSS via user registration leads to admin account takeover 20.07.2026 9.3
CVE-2026-35048 Piwigo RCE via PHP Code Injection into Config File in Installer 20.07.2026 9.8
CVE-2026-41252 xrdp: lib_palette_update Heap Buffer Overflow & RCE 23.07.2026 9.8
CVE-2026-54051 Network-AI has an an OS Command Injection issue 21.07.2026 9.9
CVE-2026-35198 HeyForm vulnerable to stored XSS via form field titles 20.07.2026 9
CVE-2026-46428 lettre has TLS hostname verification disabled when using Boring TLS backend 21.07.2026 9.1
CVE-2026-51027 20.07.2026 9.9
CVE-2026-46412 Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm 20.07.2026 10
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport 22.07.2026 9
CVE-2026-57309 Blind SQL Injection in Windu CMS 20.07.2026 9.3
CVE-2026-63756 SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition 21.07.2026 9.2
CVE-2026-64620 FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common 21.07.2026 9.3
CVE-2026-64621 FreeRDP before 3.28.0 Double-Free via selectedmonitors 23.07.2026 9.3
CVE-2026-64622 Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox 21.07.2026 9.3
CVE-2026-16242 Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates 24.07.2026 9.4
CVE-2026-44359 Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow 24.07.2026 10

Latest Updates

CVE Title Updated Score
CVE-2026-17496 NoteGen chat preview XSS via unsanitized AI/skill HTML rendering 26.07.2026 8.1
CVE-2026-17497 NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python 26.07.2026 8.3
CVE-2026-17458 mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery 26.07.2026
CVE-2026-17459 perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink 26.07.2026
CVE-2026-17457 mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure 26.07.2026
CVE-2024-14040 net: nexthop: Increase weight to u16 26.07.2026
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle 26.07.2026
CVE-2026-63720 datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field 26.07.2026
CVE-2026-17434 nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization 26.07.2026
CVE-2026-17433 nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization 26.07.2026
CVE-2026-15962 Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field 26.07.2026 8.8
CVE-2026-17432 NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control 26.07.2026