| CVE-2026-4703 |
WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission |
22.08.2026 |
9.8 |
| CVE-2026-63310 |
NLTK before 3.9.3 Missing Post-Download Integrity Verification |
22.08.2026 |
9.3 |
| CVE-2026-76571 |
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 |
22.08.2026 |
9.3 |
| CVE-2026-76602 |
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 |
22.08.2026 |
9.3 |
| CVE-2026-76604 |
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 |
22.08.2026 |
10 |
| CVE-2026-76605 |
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 |
22.08.2026 |
10 |
| CVE-2026-76606 |
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 |
22.08.2026 |
10 |
| CVE-2026-76607 |
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 |
22.08.2026 |
10 |
| CVE-2026-77992 |
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 |
22.08.2026 |
9.5 |
| CVE-2026-77946 |
TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow |
22.08.2026 |
10 |
| CVE-2026-78003 |
Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys |
22.08.2026 |
9.8 |
| CVE-2026-12710 |
Missing Authorization in Application Integration QueryEngineTask |
22.08.2026 |
9.3 |
| CVE-2026-49849 |
xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution |
21.08.2026 |
9.1 |
| CVE-2026-77415 |
JSONata: Arbitrary Code Execution via crafted JSONata expressions |
21.08.2026 |
9.3 |
| CVE-2026-77413 |
JSONata: Arbitrary Code Execution via crafted JSONata expressions |
21.08.2026 |
9.3 |
| CVE-2026-77414 |
JSONata: Arbitrary Code Execution via crafted JSONata expressions |
21.08.2026 |
9.3 |
| CVE-2026-61539 |
Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing |
21.08.2026 |
10 |
| CVE-2026-59989 |
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) |
21.08.2026 |
9.2 |
| CVE-2026-62283 |
Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check |
21.08.2026 |
9.9 |
| CVE-2026-76904 |
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers |
21.08.2026 |
9.8 |
| CVE-2026-77810 |
Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector |
21.08.2026 |
9.4 |
| CVE-2026-62674 |
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE |
21.08.2026 |
9 |
| CVE-2026-77234 |
Improper input validation in FreeRTOS-Kernel timer command handling |
21.08.2026 |
9.3 |
| CVE-2026-39909 |
llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler |
21.08.2026 |
9.2 |
| CVE-2026-69502 |
Azure SQL Database Elevation of Privilege Vulnerability |
21.08.2026 |
10 |
| CVE-2026-75932 |
Jet Admin tenant isolation failure |
21.08.2026 |
9.2 |
| CVE-2026-63343 |
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root |
21.08.2026 |
9.9 |
| CVE-2026-77087 |
Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding |
21.08.2026 |
9.4 |
| CVE-2026-48755 |
Incus has an argument injection in backup compression algorithm leading to AFW and ACE |
21.08.2026 |
9.9 |
| CVE-2026-48769 |
Incus has an arbitrary file write on its client due to trusted image hash |
21.08.2026 |
9.9 |
| CVE-2026-62867 |
Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution |
21.08.2026 |
9.9 |
| CVE-2026-62940 |
Incus has a project restriction bypass via instance migration config override |
21.08.2026 |
9.9 |
| CVE-2026-62941 |
Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge |
21.08.2026 |
9.9 |
| CVE-2026-63125 |
Incus vulnerable to root RCE via image backup.yaml symlink |
21.08.2026 |
9.9 |
| CVE-2026-48751 |
Incus has a restricted project bypass leading to arbitrary command execution |
21.08.2026 |
9.9 |
| CVE-2026-48752 |
Incus has arbitrary file read+write on host via templates/ symlink in malicious image |
21.08.2026 |
9.9 |
| CVE-2026-48753 |
Incus has an arbitrary file write via path traversal in S3 multipart upload |
21.08.2026 |
9.9 |
| CVE-2026-48749 |
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image |
21.08.2026 |
9.9 |
| CVE-2026-48750 |
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image |
21.08.2026 |
9.9 |
| CVE-2026-77812 |
Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE |
21.08.2026 |
9.4 |
| CVE-2026-77806 |
|
21.08.2026 |
9.8 |
| CVE-2026-76613 |
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 |
21.08.2026 |
9.2 |
| CVE-2026-77776 |
Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity |
21.08.2026 |
9.3 |
| CVE-2026-77086 |
SiYuan before v3.7.4 Path Traversal via packageName |
21.08.2026 |
9.4 |
| CVE-2026-77683 |
Comfast CF-N1-S mbox-config system command injection |
21.08.2026 |
9.4 |
| CVE-2026-77264 |
Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure |
21.08.2026 |
9.8 |
| CVE-2026-76158 |
Datiphy Data Management Center - External Control of File Name or Path |
21.08.2026 |
9.3 |
| CVE-2026-76155 |
Datiphy Data Management Center - Use of Default Credentials |
21.08.2026 |
9.3 |
| CVE-2026-76156 |
Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command |
21.08.2026 |
9.4 |
| CVE-2026-77649 |
|
21.08.2026 |
9.8 |
| CVE-2026-77650 |
|
21.08.2026 |
9.8 |
| CVE-2026-77651 |
|
21.08.2026 |
9.8 |
| CVE-2026-77647 |
|
21.08.2026 |
9.8 |
| CVE-2026-18835 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.9 |
| CVE-2026-77645 |
Critical Remote Code Execution (RCE) vulnerability reported in Windchill |
22.08.2026 |
9.2 |
| CVE-2026-17122 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-17136 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-17141 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-17142 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-17145 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.8 |
| CVE-2026-17152 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-17157 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-17160 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-17422 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.3 |
| CVE-2026-72843 |
EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover |
21.08.2026 |
9.3 |
| CVE-2026-77644 |
Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition |
22.08.2026 |
9.3 |
| CVE-2026-17040 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-17118 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-55769 |
CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path` |
21.08.2026 |
9.4 |
| CVE-2026-62834 |
Azure Data Factory Elevation of Privilege Vulnerability |
22.08.2026 |
9.3 |
| CVE-2026-63509 |
Microsoft Fabric Elevation of Privilege Vulnerability |
22.08.2026 |
9.9 |
| CVE-2026-65770 |
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability |
22.08.2026 |
10 |
| CVE-2026-65801 |
Microsoft Exchange Online Elevation of Privilege Vulnerability |
22.08.2026 |
10 |
| CVE-2026-65816 |
Azure Arc Elevation of Privilege Vulnerability |
22.08.2026 |
10 |
| CVE-2026-66309 |
Azure SQL Database Elevation of Privilege Vulnerability |
22.08.2026 |
9.1 |
| CVE-2026-68782 |
Azure SQL Database Elevation of Privilege Vulnerability |
22.08.2026 |
9.9 |
| CVE-2026-68789 |
Azure SQL Database Elevation of Privilege Vulnerability |
22.08.2026 |
9.9 |
| CVE-2026-69400 |
Azure Logic Apps Elevation of Privilege Vulnerability |
22.08.2026 |
9.6 |
| CVE-2026-69555 |
Azure Arc Elevation of Privilege Vulnerability |
22.08.2026 |
10 |
| CVE-2026-69836 |
Microsoft Entra ID Remote Code Execution Vulnerability |
22.08.2026 |
10 |
| CVE-2026-69851 |
Microsoft Entra ID Elevation of Privilege Vulnerability |
22.08.2026 |
9.9 |
| CVE-2026-71485 |
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends |
20.08.2026 |
9.1 |
| CVE-2026-67567 |
Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction |
21.08.2026 |
9.9 |
| CVE-2026-19586 |
Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways |
21.08.2026 |
9.3 |
| CVE-2026-66785 |
Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowedips / ipsec enables traffic hijack |
20.08.2026 |
9.9 |
| CVE-2026-66788 |
Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace |
20.08.2026 |
9.9 |
| CVE-2026-77148 |
Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow |
20.08.2026 |
9.4 |
| CVE-2026-2334 |
) Missing Server-Side File Extension Validation in vsDesk |
21.08.2026 |
9.4 |
| CVE-2026-63385 |
Libevent: HTTP header handling bugs create risk of access control bypass. |
21.08.2026 |
9.2 |
| CVE-2026-63382 |
libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling |
20.08.2026 |
9.2 |
| CVE-2026-53424 |
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions |
21.08.2026 |
9.1 |
| CVE-2026-73251 |
Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification |
20.08.2026 |
9.3 |
| CVE-2026-73253 |
Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching |
20.08.2026 |
9.1 |
| CVE-2026-73256 |
Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE |
21.08.2026 |
9.1 |
| CVE-2026-73257 |
Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling |
20.08.2026 |
9.1 |
| CVE-2026-55642 |
dbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured) |
20.08.2026 |
9.8 |
| CVE-2026-71428 |
unstructured: Server-Side Request Forgery in the URL-based partitioning |
20.08.2026 |
9.3 |
| CVE-2026-77022 |
Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow |
21.08.2026 |
9.4 |
| CVE-2026-18265 |
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-16926 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.1 |
| CVE-2026-15706 |
Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS |
20.08.2026 |
9.8 |
| CVE-2026-28164 |
WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability |
20.08.2026 |
9.6 |
| CVE-2025-15688 |
WordPress Capella theme <= 2.5.5 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2025-15689 |
WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-66583 |
WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-66592 |
WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66593 |
WordPress Security & Malware scan by CleanTalk plugin <= 2.184 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66600 |
WordPress Media LIbrary Assistant plugin <= 3.39 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.1 |
| CVE-2026-66609 |
WordPress TheGem (Elementor) theme <= 5.12.3 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66649 |
WordPress Directory Pro plugin <= 2.5.8 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66672 |
WordPress Flatastic theme <= 2.0 - PHP Object Injection vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-66680 |
WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66682 |
WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-68566 |
WordPress BookingPress Appointment Booking Pro plugin <= 6.0.2 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-73992 |
WordPress Query Wrangler plugin <= 1.5.57 - Remote Code Execution (RCE) vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-73993 |
WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-74001 |
WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-74014 |
WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-74016 |
WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-74018 |
WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-11861 |
Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships |
20.08.2026 |
9.6 |
| CVE-2026-13097 |
Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore |
21.08.2026 |
9.1 |
| CVE-2026-14950 |
Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic |
20.08.2026 |
9.2 |
| CVE-2026-76590 |
TRENDnet TEW-755AP ssi wan.cgi stack-based overflow |
21.08.2026 |
9.4 |
| CVE-2026-76850 |
LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector |
21.08.2026 |
9.3 |
| CVE-2026-76310 |
Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise |
21.08.2026 |
9.4 |
| CVE-2026-76311 |
Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise |
21.08.2026 |
9.4 |
| CVE-2026-76312 |
Improper Access Control through Embedded Reports in Splunk Enterprise |
21.08.2026 |
9.4 |
| CVE-2026-76404 |
Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app |
20.08.2026 |
9.1 |
| CVE-2026-76589 |
TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow |
19.08.2026 |
9.4 |
| CVE-2026-75595 |
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext |
20.08.2026 |
9.1 |
| CVE-2026-76584 |
TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow |
20.08.2026 |
9.4 |
| CVE-2026-53545 |
Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection |
21.08.2026 |
9.8 |
| CVE-2026-53546 |
Termix: Missing authorization in SSH host credential resolution exposes stored credentials |
20.08.2026 |
9.6 |
| CVE-2026-53548 |
Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users |
21.08.2026 |
9.6 |
| CVE-2026-16894 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-16903 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.6 |
| CVE-2026-16913 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-16917 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-16919 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-16882 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
21.08.2026 |
9.8 |
| CVE-2026-16885 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.8 |
| CVE-2026-16834 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.8 |
| CVE-2026-16839 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.4 |
| CVE-2026-16840 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-16845 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-16862 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-16864 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-16872 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-55085 |
Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite |
21.08.2026 |
9.6 |
| CVE-2026-55089 |
Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint |
19.08.2026 |
9.9 |
| CVE-2026-16822 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.3 |
| CVE-2026-22306 |
Critical flaw impacting OZOLS ERP's automatic update channel |
19.08.2026 |
10 |
| CVE-2026-16687 |
Power System Buffer Overflow |
22.08.2026 |
9.6 |
| CVE-2026-16835 |
Power System Improper Certificate Validation |
22.08.2026 |
9.6 |
| CVE-2026-18315 |
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter |
21.08.2026 |
9.8 |
| CVE-2026-70496 |
Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent via impersonate, rbac write, csr approve, and manifestwork |
19.08.2026 |
9.9 |
| CVE-2025-14600 |
Admin Account Takeover via Path Traversal in vsDesk |
19.08.2026 |
9.3 |
| CVE-2026-62682 |
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) |
19.08.2026 |
9.3 |
| CVE-2026-72717 |
Orval: Import-time RCE via schema default -> zod module-level template literal |
21.08.2026 |
9.3 |
| CVE-2026-62681 |
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) |
21.08.2026 |
9.3 |
| CVE-2026-66794 |
Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route |
21.08.2026 |
9.3 |
| CVE-2026-71864 |
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client |
19.08.2026 |
9.3 |
| CVE-2026-71865 |
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli |
21.08.2026 |
9.3 |
| CVE-2026-71866 |
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client |
19.08.2026 |
9.3 |
| CVE-2026-71867 |
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator |
19.08.2026 |
9.3 |
| CVE-2026-71868 |
Orval: Import-time RCE via enum-typed default -> zod module-level template literal |
21.08.2026 |
9.3 |
| CVE-2026-71869 |
Orval: Import-time RCE via array-items default -> zod module-level template literal |
19.08.2026 |
9.3 |
| CVE-2026-71871 |
Orval: Import-time RCE via header-parameter default -> zod module-level template literal |
21.08.2026 |
9.3 |
| CVE-2026-72716 |
Orval: Import-time RCE via query-parameter default -> zod module-level template literal |
19.08.2026 |
9.3 |
| CVE-2026-32475 |
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability |
20.08.2026 |
9 |
| CVE-2026-71470 |
Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa |
20.08.2026 |
9.1 |
| CVE-2026-72529 |
|
21.08.2026 |
9.3 |
| CVE-2026-72530 |
|
21.08.2026 |
9.5 |
| CVE-2026-75143 |
FFmpeg Heap Buffer Overflow via RIST Protocol Reader |
21.08.2026 |
9.3 |
| CVE-2026-20030 |
Cisco Crosswork Security Hardening Release: August 2026 |
19.08.2026 |
10 |
| CVE-2026-20231 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities |
20.08.2026 |
9.9 |
| CVE-2026-20315 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities |
20.08.2026 |
10 |
| CVE-2026-20317 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities |
20.08.2026 |
10 |
| CVE-2026-20318 |
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation Vulnerabilities |
20.08.2026 |
9.6 |
| CVE-2026-20357 |
Cisco Crosswork Security Hardening Release: August 2026 |
21.08.2026 |
10 |
| CVE-2026-20358 |
Cisco Crosswork Security Hardening Release: August 2026 |
21.08.2026 |
10 |
| CVE-2026-20359 |
Cisco Crosswork Security Hardening Release: August 2026 |
20.08.2026 |
9.9 |
| CVE-2026-48024 |
Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager |
21.08.2026 |
9.1 |
| CVE-2026-48162 |
Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager |
19.08.2026 |
9.1 |
| CVE-2026-49441 |
Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager |
19.08.2026 |
9.1 |
| CVE-2026-62668 |
Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols |
19.08.2026 |
9.4 |
| CVE-2026-16656 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.8 |
| CVE-2026-16816 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.9 |
| CVE-2026-52889 |
Formie: Server-Side Template Injection in Formie Hidden field defaults |
19.08.2026 |
9.8 |
| CVE-2026-45272 |
MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File |
19.08.2026 |
9.4 |
| CVE-2026-47187 |
SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write |
20.08.2026 |
9.3 |
| CVE-2026-53451 |
Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution |
21.08.2026 |
9.8 |
| CVE-2026-75949 |
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 |
21.08.2026 |
10 |
| CVE-2026-75954 |
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 |
21.08.2026 |
9.3 |
| CVE-2026-15065 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.1 |
| CVE-2026-15068 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
20.08.2026 |
9.9 |
| CVE-2026-71960 |
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT |
21.08.2026 |
9.3 |
| CVE-2024-58376 |
Renovate 37.158.0 before 37.199.0 Command Injection via helmv3 |
20.08.2026 |
9.3 |
| CVE-2026-16019 |
SQL Injection in Faydam Innovation's FAYDAM Datalogger |
20.08.2026 |
9.8 |
| CVE-2026-75916 |
SiYuan XSS-to-RCE via unescaped block metadata in hint popup |
21.08.2026 |
9.3 |
| CVE-2026-75917 |
SiYuan before v3.7.4 XSS-to-RCE via pathName.ts |
20.08.2026 |
9.3 |
| CVE-2026-76213 |
phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle |
19.08.2026 |
9.1 |
| CVE-2026-76214 |
phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge |
21.08.2026 |
9.1 |
| CVE-2026-76242 |
stigmem Federation Peer Registration Authentication Bypass |
20.08.2026 |
9.1 |
| CVE-2026-76243 |
stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth |
19.08.2026 |
9.2 |
| CVE-2026-76244 |
stigmem-node Insecure Federation Transport Configuration |
19.08.2026 |
9.1 |
| CVE-2026-74803 |
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 |
21.08.2026 |
10 |
| CVE-2026-74804 |
Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 |
21.08.2026 |
9.3 |
| CVE-2026-19490 |
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 |
20.08.2026 |
9.3 |
| CVE-2026-67364 |
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 |
21.08.2026 |
10 |
| CVE-2026-66613 |
WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-73183 |
WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability |
19.08.2026 |
9.3 |
| CVE-2026-73185 |
WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-73347 |
WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-73364 |
WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability |
19.08.2026 |
9.8 |
| CVE-2026-73388 |
WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability |
19.08.2026 |
9.3 |
| CVE-2026-73389 |
WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-73390 |
WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-73391 |
WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability |
19.08.2026 |
9.3 |
| CVE-2026-76008 |
Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow |
19.08.2026 |
10 |
| CVE-2026-76003 |
UTT HiPER 1200GW formGroupConfig strcpy stack-based overflow |
21.08.2026 |
9.4 |
| CVE-2026-76004 |
UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow |
19.08.2026 |
9.4 |
| CVE-2026-11751 |
|
20.08.2026 |
9.1 |
| CVE-2026-75976 |
TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow |
18.08.2026 |
9.4 |
| CVE-2026-70905 |
|
22.08.2026 |
9.8 |
| CVE-2026-70920 |
|
22.08.2026 |
9.9 |
| CVE-2026-70921 |
|
22.08.2026 |
10 |
| CVE-2026-70926 |
|
22.08.2026 |
9.8 |
| CVE-2026-70953 |
|
22.08.2026 |
9.8 |
| CVE-2026-70954 |
|
22.08.2026 |
9.8 |
| CVE-2026-70958 |
|
22.08.2026 |
9.6 |
| CVE-2026-70970 |
|
20.08.2026 |
9.8 |
| CVE-2026-70976 |
|
22.08.2026 |
9.1 |
| CVE-2026-70977 |
|
22.08.2026 |
9.1 |
| CVE-2026-70978 |
|
22.08.2026 |
9.1 |
| CVE-2026-70979 |
|
22.08.2026 |
9.1 |
| CVE-2026-70980 |
|
19.08.2026 |
9 |
| CVE-2026-70981 |
|
19.08.2026 |
9.1 |
| CVE-2026-70984 |
|
19.08.2026 |
9.1 |
| CVE-2026-70994 |
|
20.08.2026 |
9.1 |
| CVE-2026-70995 |
|
20.08.2026 |
9.8 |
| CVE-2026-70997 |
|
20.08.2026 |
9.1 |
| CVE-2026-70998 |
|
20.08.2026 |
9.3 |
| CVE-2026-71014 |
|
22.08.2026 |
9.1 |
| CVE-2026-71015 |
|
22.08.2026 |
9.1 |
| CVE-2026-71026 |
|
19.08.2026 |
9.1 |
| CVE-2026-71036 |
|
21.08.2026 |
9.1 |
| CVE-2026-71037 |
|
19.08.2026 |
9.3 |
| CVE-2026-71040 |
|
19.08.2026 |
9.8 |
| CVE-2026-71059 |
|
19.08.2026 |
9.9 |
| CVE-2026-71063 |
|
19.08.2026 |
9.6 |
| CVE-2026-71064 |
|
22.08.2026 |
9.6 |
| CVE-2026-71065 |
|
22.08.2026 |
9.3 |
| CVE-2026-71074 |
|
19.08.2026 |
9.8 |
| CVE-2026-71102 |
|
19.08.2026 |
9.1 |
| CVE-2026-71152 |
|
21.08.2026 |
9.8 |
| CVE-2026-71164 |
|
19.08.2026 |
9.8 |
| CVE-2026-71166 |
|
20.08.2026 |
9.4 |
| CVE-2026-71167 |
|
20.08.2026 |
9.4 |
| CVE-2026-73865 |
|
19.08.2026 |
9.1 |
| CVE-2026-73866 |
|
19.08.2026 |
9.1 |
| CVE-2026-73905 |
|
19.08.2026 |
9.8 |
| CVE-2026-73912 |
|
19.08.2026 |
9.8 |
| CVE-2026-73916 |
|
19.08.2026 |
9.1 |
| CVE-2026-73917 |
|
19.08.2026 |
9.1 |
| CVE-2026-73920 |
|
20.08.2026 |
9.4 |
| CVE-2026-73921 |
|
19.08.2026 |
9.8 |
| CVE-2026-73922 |
|
19.08.2026 |
9.1 |
| CVE-2026-73924 |
|
19.08.2026 |
9.1 |
| CVE-2026-73930 |
|
19.08.2026 |
9.9 |
| CVE-2026-60591 |
|
20.08.2026 |
9.1 |
| CVE-2026-60672 |
|
20.08.2026 |
9.8 |
| CVE-2026-60696 |
|
19.08.2026 |
9.8 |
| CVE-2026-60698 |
|
19.08.2026 |
9.8 |
| CVE-2026-60702 |
|
19.08.2026 |
9.9 |
| CVE-2026-60720 |
|
21.08.2026 |
9.9 |
| CVE-2026-60721 |
|
20.08.2026 |
9.8 |
| CVE-2026-60727 |
|
19.08.2026 |
9.8 |
| CVE-2026-60728 |
|
19.08.2026 |
9.1 |
| CVE-2026-60730 |
|
19.08.2026 |
9.9 |
| CVE-2026-60737 |
|
20.08.2026 |
9.1 |
| CVE-2026-60754 |
|
20.08.2026 |
9.1 |
| CVE-2026-60782 |
|
20.08.2026 |
9.8 |
| CVE-2026-60821 |
|
21.08.2026 |
9.8 |
| CVE-2026-60858 |
|
20.08.2026 |
9.8 |
| CVE-2026-60861 |
|
20.08.2026 |
9.6 |
| CVE-2026-60905 |
|
20.08.2026 |
9.6 |
| CVE-2026-60916 |
|
19.08.2026 |
9.9 |
| CVE-2026-60921 |
|
21.08.2026 |
9.8 |
| CVE-2026-60946 |
|
21.08.2026 |
9.8 |
| CVE-2026-60947 |
|
21.08.2026 |
9.8 |
| CVE-2026-60958 |
|
21.08.2026 |
9.8 |
| CVE-2026-60970 |
|
21.08.2026 |
9.8 |
| CVE-2026-60971 |
|
21.08.2026 |
9.8 |
| CVE-2026-60977 |
|
21.08.2026 |
9.8 |
| CVE-2026-60990 |
|
21.08.2026 |
9.9 |
| CVE-2026-60995 |
|
21.08.2026 |
9.9 |
| CVE-2026-61001 |
|
21.08.2026 |
9.6 |
| CVE-2026-61003 |
|
21.08.2026 |
9.9 |
| CVE-2026-61008 |
|
20.08.2026 |
9.1 |
| CVE-2026-61018 |
|
21.08.2026 |
9.8 |
| CVE-2026-61021 |
|
20.08.2026 |
9.9 |
| CVE-2026-61029 |
|
20.08.2026 |
9 |
| CVE-2026-61034 |
|
20.08.2026 |
9.1 |
| CVE-2026-61066 |
|
21.08.2026 |
9.9 |
| CVE-2026-61206 |
|
21.08.2026 |
9.9 |
| CVE-2026-61241 |
|
21.08.2026 |
10 |
| CVE-2026-61248 |
|
21.08.2026 |
9.9 |
| CVE-2026-61258 |
|
21.08.2026 |
9.8 |
| CVE-2026-61272 |
|
21.08.2026 |
9.8 |
| CVE-2026-61317 |
|
20.08.2026 |
9.9 |
| CVE-2026-61318 |
|
20.08.2026 |
9.8 |
| CVE-2026-62452 |
|
19.08.2026 |
9.9 |
| CVE-2026-62457 |
|
18.08.2026 |
9.8 |
| CVE-2026-62463 |
|
18.08.2026 |
9.6 |
| CVE-2026-62512 |
|
21.08.2026 |
9.9 |
| CVE-2026-62539 |
|
18.08.2026 |
9.8 |
| CVE-2026-62541 |
|
18.08.2026 |
9.8 |
| CVE-2026-62543 |
|
18.08.2026 |
9.8 |
| CVE-2026-62544 |
|
18.08.2026 |
9.8 |
| CVE-2026-62582 |
|
18.08.2026 |
9.6 |
| CVE-2026-62585 |
|
21.08.2026 |
9.8 |
| CVE-2026-62588 |
|
20.08.2026 |
9.9 |
| CVE-2026-62592 |
|
20.08.2026 |
9.8 |
| CVE-2026-62608 |
|
18.08.2026 |
9.9 |
| CVE-2026-62609 |
|
18.08.2026 |
9.8 |
| CVE-2026-62610 |
|
18.08.2026 |
9.1 |
| CVE-2026-62611 |
|
18.08.2026 |
9.8 |
| CVE-2026-62613 |
|
18.08.2026 |
9.3 |
| CVE-2026-62614 |
|
18.08.2026 |
9.8 |
| CVE-2026-62617 |
|
18.08.2026 |
9.8 |
| CVE-2026-62618 |
|
18.08.2026 |
9.3 |
| CVE-2026-62621 |
|
18.08.2026 |
9.8 |
| CVE-2026-62622 |
|
18.08.2026 |
9.8 |
| CVE-2026-62624 |
|
18.08.2026 |
9.8 |
| CVE-2026-62626 |
|
18.08.2026 |
9.8 |
| CVE-2026-62629 |
|
18.08.2026 |
9.4 |
| CVE-2026-62630 |
|
18.08.2026 |
9.8 |
| CVE-2026-62632 |
|
18.08.2026 |
9.8 |
| CVE-2026-62633 |
|
18.08.2026 |
9.8 |
| CVE-2026-62634 |
|
18.08.2026 |
9.8 |
| CVE-2026-62635 |
|
18.08.2026 |
9.8 |
| CVE-2026-62637 |
|
18.08.2026 |
9.3 |
| CVE-2026-62638 |
|
18.08.2026 |
9.1 |
| CVE-2026-62639 |
|
18.08.2026 |
9.8 |
| CVE-2026-62640 |
|
18.08.2026 |
9.8 |
| CVE-2026-70668 |
|
18.08.2026 |
9.1 |
| CVE-2026-70669 |
|
18.08.2026 |
9.8 |
| CVE-2026-70670 |
|
18.08.2026 |
9.6 |
| CVE-2026-70673 |
|
18.08.2026 |
9.3 |
| CVE-2026-70689 |
|
18.08.2026 |
9.8 |
| CVE-2026-70730 |
|
18.08.2026 |
9.1 |
| CVE-2026-70739 |
|
18.08.2026 |
9.8 |
| CVE-2026-70740 |
|
18.08.2026 |
9.8 |
| CVE-2026-70741 |
|
18.08.2026 |
9.1 |
| CVE-2026-70745 |
|
18.08.2026 |
9.8 |
| CVE-2026-70817 |
|
18.08.2026 |
9.8 |
| CVE-2026-70846 |
|
18.08.2026 |
9.6 |
| CVE-2026-70854 |
|
18.08.2026 |
9.1 |
| CVE-2026-70855 |
|
18.08.2026 |
9.3 |
| CVE-2026-70862 |
|
18.08.2026 |
9.1 |
| CVE-2026-70871 |
|
18.08.2026 |
9.8 |
| CVE-2026-70872 |
|
18.08.2026 |
9.1 |
| CVE-2026-70873 |
|
18.08.2026 |
9.8 |
| CVE-2026-70876 |
|
18.08.2026 |
9.1 |
| CVE-2026-70880 |
|
18.08.2026 |
10 |
| CVE-2026-70883 |
|
18.08.2026 |
9.1 |
| CVE-2026-70884 |
|
18.08.2026 |
9.1 |
| CVE-2026-62988 |
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints |
21.08.2026 |
9 |
| CVE-2026-67443 |
FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) |
21.08.2026 |
9.2 |
| CVE-2026-75877 |
TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow |
19.08.2026 |
9.4 |
| CVE-2026-52735 |
ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser |
18.08.2026 |
9.3 |
| CVE-2026-55166 |
Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR |
18.08.2026 |
9.9 |
| CVE-2026-47627 |
|
20.08.2026 |
9.8 |
| CVE-2026-50161 |
libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow |
19.08.2026 |
9.3 |
| CVE-2026-75625 |
Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass |
18.08.2026 |
9.1 |
| CVE-2026-71878 |
Authentication bypass in Integrated Publishing Toolkit |
18.08.2026 |
9.2 |
| CVE-2026-71879 |
Authentication bypass in Integrated Publishing Toolkit |
18.08.2026 |
9.1 |
| CVE-2026-66780 |
Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace |
18.08.2026 |
9.9 |
| CVE-2026-18963 |
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass |
20.08.2026 |
9.1 |
| CVE-2026-57580 |
authentik: Account Takeover via SAML NameID Comment Truncation |
18.08.2026 |
9.4 |
| CVE-2026-52723 |
ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust |
18.08.2026 |
9.1 |
| CVE-2026-67271 |
|
19.08.2026 |
9.8 |
| CVE-2026-45118 |
MyBB: Contact page reflected XSS |
18.08.2026 |
9.3 |
| CVE-2026-12564 |
Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf |
18.08.2026 |
9.6 |
| CVE-2026-45117 |
MyBB: Installer database configuration RCE |
18.08.2026 |
9.8 |
| CVE-2026-75926 |
Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant |
20.08.2026 |
9.3 |
| CVE-2026-75856 |
CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU |
18.08.2026 |
9.2 |
| CVE-2026-59940 |
Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization |
18.08.2026 |
9.8 |
| CVE-2026-32470 |
WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability |
18.08.2026 |
9.8 |
| CVE-2026-32474 |
WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability |
18.08.2026 |
9.9 |
| CVE-2026-66627 |
WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability |
18.08.2026 |
9.9 |
| CVE-2026-73187 |
WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability |
18.08.2026 |
9.3 |
| CVE-2026-73339 |
WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability |
18.08.2026 |
9.3 |
| CVE-2026-73341 |
WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability |
18.08.2026 |
9.8 |
| CVE-2026-73343 |
WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability |
18.08.2026 |
10 |
| CVE-2026-73355 |
WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability |
18.08.2026 |
9.3 |
| CVE-2026-73365 |
WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability |
18.08.2026 |
9.3 |
| CVE-2026-73366 |
WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability |
18.08.2026 |
9.8 |
| CVE-2026-73376 |
WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vulnerability |
18.08.2026 |
9.8 |
| CVE-2026-73380 |
WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability |
18.08.2026 |
9.8 |
| CVE-2026-73381 |
WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability |
18.08.2026 |
9.1 |
| CVE-2026-73392 |
WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability |
18.08.2026 |
9.3 |
| CVE-2026-73397 |
WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnerability |
18.08.2026 |
9.8 |
| CVE-2026-73996 |
WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability |
18.08.2026 |
9.8 |
| CVE-2026-74015 |
WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability |
18.08.2026 |
9.3 |
| CVE-2026-75784 |
TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow |
20.08.2026 |
10 |
| CVE-2026-28192 |
WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability |
18.08.2026 |
9.6 |
| CVE-2026-32444 |
WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability |
18.08.2026 |
9.9 |
| CVE-2026-32463 |
WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability |
18.08.2026 |
9.9 |
| CVE-2026-75783 |
TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow |
18.08.2026 |
9.4 |
| CVE-2026-74902 |
SiYuan before v3.7.4 XSS-to-RCE via malicious filename upload |
18.08.2026 |
9.3 |
| CVE-2026-75827 |
Grav before 2.0.15 Arbitrary File Write via error_log |
19.08.2026 |
9.3 |
| CVE-2026-75828 |
Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass |
18.08.2026 |
9.3 |
| CVE-2026-75832 |
Grav API Plugin before 1.0.14 Authorization Bypass |
19.08.2026 |
9.3 |
| CVE-2026-75835 |
Grav API Plugin before 1.0.14 Missing Authorization |
18.08.2026 |
9.3 |
| CVE-2026-75837 |
Grav before 2.0.14 Privilege Escalation via Group Access Field |
19.08.2026 |
9.3 |
| CVE-2026-75843 |
ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction |
18.08.2026 |
9.4 |
| CVE-2026-75851 |
ArcadeDB before 26.8.1 Authentication Bypass via Async Command |
18.08.2026 |
9.4 |
| CVE-2026-75852 |
ArcadeDB MongoDB wire protocol authentication bypass cross-database |
18.08.2026 |
9.3 |
| CVE-2026-75854 |
ArcadeDB Redis Wire-Protocol Plugin Missing Authentication |
18.08.2026 |
9.3 |
| CVE-2026-75626 |
SpiderFoot Stored Cross-Site Scripting via Correlation Titles |
19.08.2026 |
9.3 |
| CVE-2026-75627 |
Bastillion Authentication Bypass via Path-Prefix Routing Mismatch |
18.08.2026 |
9.3 |
| CVE-2026-15748 |
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration |
18.08.2026 |
9.8 |
| CVE-2026-75094 |
COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection |
18.08.2026 |
9.4 |
| CVE-2026-71424 |
Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers |
18.08.2026 |
9.6 |
| CVE-2026-64849 |
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) |
20.08.2026 |
9.3 |
| CVE-2026-47686 |
vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE |
19.08.2026 |
9.9 |
| CVE-2026-47698 |
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators |
19.08.2026 |
9.8 |
| CVE-2026-65974 |
ERPNext: Server-Side Template Injection leading to Remote Code Execution |
18.08.2026 |
9.9 |
| CVE-2026-66795 |
Managedcluster-import-controller: managedcluster-import-controller: csr auto-approver does not validate certificate subject, signername, or requester identity |
18.08.2026 |
9.1 |
| CVE-2026-75106 |
OpnForm Editable Submission Secret Derivation via Empty Hashids Salt |
21.08.2026 |
9.3 |
| CVE-2026-75110 |
MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET |
18.08.2026 |
9.3 |
| CVE-2026-19478 |
Improper Control of Generation of Code ('Code Injection') in GitLab |
17.08.2026 |
9.4 |
| CVE-2026-71472 |
Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem |
20.08.2026 |
9.1 |
| CVE-2026-66792 |
Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clusters |
20.08.2026 |
9.9 |
| CVE-2026-74253 |
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 |
17.08.2026 |
10 |
| CVE-2026-74254 |
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 |
18.08.2026 |
9.3 |
| CVE-2026-71479 |
New API: Integer overflow in quota billing yields negative charges (self-crediting) |
17.08.2026 |
9.1 |
| CVE-2026-75045 |
|
18.08.2026 |
9.1 |
| CVE-2026-64859 |
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation |
17.08.2026 |
9.1 |
| CVE-2026-55674 |
Discourse: Cache poisoning/XSS via color scheme cookies |
18.08.2026 |
9.3 |
| CVE-2026-71566 |
KubeVirt backend is not authenticated |
17.08.2026 |
9.3 |
| CVE-2026-14564 |
Sensitive Data Exposure in Innotim Software's Logsign SIEM |
17.08.2026 |
9 |
| CVE-2026-74843 |
Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow |
17.08.2026 |
10 |
| CVE-2026-74798 |
SiYuan kernel Path Traversal via database_clean MCP tool |
18.08.2026 |
9.3 |
| CVE-2026-74799 |
SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure |
17.08.2026 |
9.2 |
| CVE-2026-74800 |
SiYuan before v3.7.4 Stored XSS via assets endpoint |
17.08.2026 |
9.4 |
| CVE-2026-74872 |
openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool |
18.08.2026 |
9.3 |
| CVE-2026-74875 |
openssl_encrypt before 1.4.0 Schema Validation Bypass |
17.08.2026 |
9.3 |
| CVE-2026-74876 |
openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption |
17.08.2026 |
9.3 |
| CVE-2026-74878 |
openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass |
17.08.2026 |
9.3 |
| CVE-2026-74880 |
openssl_encrypt before 1.4.0 Token Leakage via Query Parameters |
17.08.2026 |
9.3 |
| CVE-2026-74885 |
openssl_encrypt before 1.4.0 Logging Bug and Race Condition |
17.08.2026 |
9.3 |
| CVE-2026-74886 |
openssl_encrypt before 1.4.0 Plugin Import Guard Bypass |
17.08.2026 |
9.3 |
| CVE-2026-74887 |
openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module |
18.08.2026 |
9.3 |
| CVE-2026-74889 |
openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF |
17.08.2026 |
9.3 |
| CVE-2026-74890 |
openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable |
17.08.2026 |
9.3 |
| CVE-2026-74894 |
openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token |
17.08.2026 |
9.3 |
| CVE-2026-74895 |
openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation |
17.08.2026 |
9.3 |
| CVE-2026-74896 |
openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal |
17.08.2026 |
9.3 |
| CVE-2026-74899 |
openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy |
18.08.2026 |
9.3 |
| CVE-2026-74900 |
openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode |
17.08.2026 |
9.3 |
| CVE-2026-74901 |
openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback |
17.08.2026 |
9.3 |
| CVE-2026-15623 |
Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service |
17.08.2026 |
9.4 |
| CVE-2026-19977 |
EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication |
18.08.2026 |
10 |
| CVE-2026-19961 |
Edimax EW-7478APC formWlSiteSurvey buffer overflow |
17.08.2026 |
9.4 |
| CVE-2026-19959 |
Edimax EW-7478APC formWanTcpipSetup stack-based overflow |
18.08.2026 |
9.4 |
| CVE-2026-73056 |
SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token |
17.08.2026 |
9.3 |
| CVE-2026-73061 |
Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor |
17.08.2026 |
9.3 |
| CVE-2026-74790 |
Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache |
17.08.2026 |
9.3 |
| CVE-2026-74791 |
Scriban before 7.0.0 Authorization Bypass via Stale Include Cache |
17.08.2026 |
9.2 |
| CVE-2026-74251 |
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 |
18.08.2026 |
9.3 |
| CVE-2024-13784 |
Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection |
17.08.2026 |
9.8 |
| CVE-2026-18316 |
Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action |
17.08.2026 |
9.1 |
| CVE-2026-14524 |
ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters |
17.08.2026 |
9.1 |
| CVE-2026-16098 |
ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override |
18.08.2026 |
9.8 |
| CVE-2026-18432 |
Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter |
18.08.2026 |
9.8 |
| CVE-2026-19924 |
Tenda AC10 httpd R7WebsSecurityHandler improper authentication |
19.08.2026 |
9.3 |
| CVE-2026-73041 |
SiYuan before v3.7.4 Remote Code Execution via PDF Annotations |
17.08.2026 |
9.4 |
| CVE-2026-73042 |
SiYuan before v3.7.4 Remote Code Execution via Menu Metadata |
17.08.2026 |
9.4 |
| CVE-2026-73043 |
SiYuan before v3.7.4 Remote Code Execution via Template Calculation |
17.08.2026 |
9.4 |
| CVE-2026-73044 |
SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width |
17.08.2026 |
9.4 |
| CVE-2026-73046 |
SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth |
17.08.2026 |
9.3 |
| CVE-2026-73050 |
SiYuan before v3.7.4 Stored XSS via select option color |
17.08.2026 |
9.4 |
| CVE-2026-73052 |
SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names |
17.08.2026 |
9.4 |
| CVE-2026-73053 |
SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji |
18.08.2026 |
9.4 |
| CVE-2026-73055 |
Shescape before 2.1.15 Home Directory Disclosure via BusyBox |
17.08.2026 |
9.3 |
| CVE-2026-74764 |
Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora |
17.08.2026 |
10 |