CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-65687 Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via SVG Processing 23.07.2026 9.3
CVE-2026-65688 Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Font Processing 23.07.2026 9.3
CVE-2026-65689 Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Database Download 23.07.2026 9.3
CVE-2026-65907 23.07.2026 9.1
CVE-2026-64812 23.07.2026 10
CVE-2026-64813 23.07.2026 10
CVE-2026-65605 SiYuan before v3.7.2 Stored XSS to RCE via Attribute View 23.07.2026 9.4
CVE-2026-65606 SiYuan before v3.7.2 Cross-Site Scripting to RCE 23.07.2026 9.4
CVE-2026-27064 WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-57784 WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-59514 WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59525 WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59526 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59540 WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-59543 WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability 23.07.2026 9.9
CVE-2026-59544 WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability 23.07.2026 9.8
CVE-2026-59555 WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability 23.07.2026 10
CVE-2026-61948 WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61949 WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61950 WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61951 WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-65455 WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65461 WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65471 WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-15015 MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint 23.07.2026 9.8
CVE-2026-14282 GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field 23.07.2026 9.8
CVE-2026-15011 Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter 23.07.2026 9.8
CVE-2026-16723 Remote Code Execution in fastjson 1.2.68–1.2.83 23.07.2026 9
CVE-2026-60366 23.07.2026 10
CVE-2026-60367 23.07.2026 9.8
CVE-2026-60369 23.07.2026 9.9
CVE-2026-60372 23.07.2026 9.8
CVE-2026-13072 MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption 23.07.2026 9.2
CVE-2026-64829 Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow 23.07.2026 9.1
CVE-2026-40712 22.07.2026 9.1
CVE-2026-46738 23.07.2026 9.1
CVE-2026-16606 Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris 22.07.2026 9.3
CVE-2026-2395 SQLi in Xpoda Türkiye Informatics Technology's No Code Platform 22.07.2026 9.8
CVE-2026-63048 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 23.07.2026 9.4
CVE-2026-47731 NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker) 22.07.2026 9.1
CVE-2026-60328 21.07.2026 9.8
CVE-2026-60329 21.07.2026 9.8
CVE-2026-60333 21.07.2026 9.9
CVE-2026-60355 21.07.2026 9.8
CVE-2026-60358 21.07.2026 10
CVE-2026-60360 21.07.2026 10
CVE-2026-60361 21.07.2026 9.9
CVE-2026-60362 21.07.2026 9.8
CVE-2026-60363 21.07.2026 9.8
CVE-2026-60364 21.07.2026 9.8
CVE-2026-60365 21.07.2026 10
CVE-2026-60374 21.07.2026 9.8
CVE-2026-60375 21.07.2026 9.8
CVE-2026-60376 21.07.2026 9.8
CVE-2026-60377 21.07.2026 9.9
CVE-2026-60378 21.07.2026 9.8
CVE-2026-60379 21.07.2026 10
CVE-2026-60380 21.07.2026 9.8
CVE-2026-60381 21.07.2026 9.9
CVE-2026-60384 21.07.2026 9.8
CVE-2026-60385 21.07.2026 9.8
CVE-2026-60386 21.07.2026 9.8
CVE-2026-60387 21.07.2026 9.8
CVE-2026-60388 21.07.2026 9.8
CVE-2026-60389 21.07.2026 10
CVE-2026-60402 21.07.2026 9.9
CVE-2026-60422 21.07.2026 9.9
CVE-2026-60424 21.07.2026 9
CVE-2026-60429 21.07.2026 9.9
CVE-2026-60435 21.07.2026 9.8
CVE-2026-60438 21.07.2026 9.1
CVE-2026-60441 21.07.2026 9.8
CVE-2026-60442 21.07.2026 9.8
CVE-2026-60445 21.07.2026 9.9
CVE-2026-60446 21.07.2026 9.8
CVE-2026-60447 21.07.2026 9.9
CVE-2026-60456 21.07.2026 9.9
CVE-2026-60457 21.07.2026 9.9
CVE-2026-60458 21.07.2026 9.9
CVE-2026-60459 21.07.2026 9.9
CVE-2026-60460 21.07.2026 9.8
CVE-2026-60461 21.07.2026 9.9
CVE-2026-60463 21.07.2026 9.8
CVE-2026-60524 21.07.2026 9.9
CVE-2026-60531 21.07.2026 9.9
CVE-2026-60532 21.07.2026 9.8
CVE-2026-60535 21.07.2026 9.8
CVE-2026-60537 21.07.2026 9.9
CVE-2026-60538 21.07.2026 9.8
CVE-2026-60540 21.07.2026 9.6
CVE-2026-60541 21.07.2026 9.8
CVE-2026-60542 21.07.2026 9.9
CVE-2026-60547 21.07.2026 9.9
CVE-2026-60551 21.07.2026 9.8
CVE-2026-60552 21.07.2026 9.9
CVE-2026-60555 21.07.2026 9.8
CVE-2026-60561 21.07.2026 9.9
CVE-2026-60562 21.07.2026 9.9
CVE-2026-60564 21.07.2026 9.6
CVE-2026-60565 21.07.2026 9.9
CVE-2026-60566 21.07.2026 9.8
CVE-2026-60567 21.07.2026 9.1
CVE-2026-60568 21.07.2026 9.9
CVE-2026-60606 21.07.2026 9.1
CVE-2026-60627 21.07.2026 9.9
CVE-2026-60631 21.07.2026 9.3
CVE-2026-60632 21.07.2026 9.3
CVE-2026-60644 21.07.2026 10
CVE-2026-60649 21.07.2026 9.1
CVE-2026-60663 21.07.2026 9.9
CVE-2026-60711 21.07.2026 9.9
CVE-2026-60719 21.07.2026 9.9
CVE-2026-60773 21.07.2026 9.6
CVE-2026-60880 21.07.2026 9.8
CVE-2026-60999 21.07.2026 9.8
CVE-2026-61041 21.07.2026 9.9
CVE-2026-61059 21.07.2026 9.1
CVE-2026-61065 21.07.2026 9.8
CVE-2026-61072 21.07.2026 9.9
CVE-2026-61076 21.07.2026 9.9
CVE-2026-61097 21.07.2026 9.6
CVE-2026-61100 21.07.2026 9.8
CVE-2026-61129 21.07.2026 9.8
CVE-2026-61130 21.07.2026 9.1
CVE-2026-61131 21.07.2026 9.8
CVE-2026-61140 21.07.2026 9.8
CVE-2026-61145 21.07.2026 9.8
CVE-2026-61146 21.07.2026 9.9
CVE-2026-61153 21.07.2026 9.1
CVE-2026-61154 21.07.2026 9.8
CVE-2026-61155 21.07.2026 9.1
CVE-2026-61156 21.07.2026 9.1
CVE-2026-61161 21.07.2026 9.8
CVE-2026-61167 21.07.2026 9.8
CVE-2026-61171 21.07.2026 9.1
CVE-2026-61174 23.07.2026 9
CVE-2026-61175 23.07.2026 9.3
CVE-2026-61178 23.07.2026 9.8
CVE-2026-61183 23.07.2026 9.8
CVE-2026-61184 23.07.2026 9.1
CVE-2026-61186 23.07.2026 9.4
CVE-2026-61196 22.07.2026 9.8
CVE-2026-61197 22.07.2026 9.1
CVE-2026-61201 22.07.2026 9
CVE-2026-61203 22.07.2026 9.4
CVE-2026-61204 22.07.2026 9
CVE-2026-61207 22.07.2026 9.3
CVE-2026-61209 22.07.2026 9.9
CVE-2026-61211 22.07.2026 9.9
CVE-2026-61223 22.07.2026 9
CVE-2026-61233 22.07.2026 9.8
CVE-2026-61235 22.07.2026 9.1
CVE-2026-61237 22.07.2026 9.9
CVE-2026-61238 22.07.2026 9.1
CVE-2026-61239 22.07.2026 9.9
CVE-2026-61242 22.07.2026 9.9
CVE-2026-61244 22.07.2026 9.1
CVE-2026-61245 22.07.2026 9.8
CVE-2026-62546 22.07.2026 9.1
CVE-2026-62549 22.07.2026 9.6
CVE-2026-65318 Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader 22.07.2026 9.2
CVE-2026-35290 23.07.2026 9.8
CVE-2026-46876 23.07.2026 9.8
CVE-2026-46924 23.07.2026 9.8
CVE-2026-46982 23.07.2026 9.8
CVE-2026-46983 23.07.2026 9.8
CVE-2026-46989 23.07.2026 9.1
CVE-2026-46994 23.07.2026 9.8
CVE-2026-47036 23.07.2026 9.8
CVE-2026-47040 21.07.2026 9.1
CVE-2026-47056 21.07.2026 10
CVE-2026-60168 23.07.2026 9.1
CVE-2026-60173 21.07.2026 9.8
CVE-2026-60197 21.07.2026 9.8
CVE-2026-60198 21.07.2026 9.8
CVE-2026-60199 21.07.2026 9.8
CVE-2026-60200 21.07.2026 9.8
CVE-2026-60202 21.07.2026 9.8
CVE-2026-60204 21.07.2026 9.8
CVE-2026-60205 21.07.2026 9.8
CVE-2026-60206 21.07.2026 9.9
CVE-2026-60208 21.07.2026 9.1
CVE-2026-60209 21.07.2026 9.8
CVE-2026-60210 21.07.2026 9.8
CVE-2026-60212 21.07.2026 9.8
CVE-2026-60215 21.07.2026 9.8
CVE-2026-60216 21.07.2026 9.8
CVE-2026-60217 21.07.2026 10
CVE-2026-60219 21.07.2026 9.8
CVE-2026-60220 21.07.2026 9.3
CVE-2026-60221 21.07.2026 9.8
CVE-2026-60224 21.07.2026 9.8
CVE-2026-60225 21.07.2026 9.8
CVE-2026-60226 21.07.2026 9.8
CVE-2026-60227 21.07.2026 9.8
CVE-2026-60228 21.07.2026 9.8
CVE-2026-60229 21.07.2026 9.8
CVE-2026-60230 21.07.2026 9.8
CVE-2026-60232 21.07.2026 9.8
CVE-2026-60234 21.07.2026 9.8
CVE-2026-60236 21.07.2026 9.8
CVE-2026-60239 21.07.2026 9.6
CVE-2026-60240 21.07.2026 9.8
CVE-2026-60241 21.07.2026 9.8
CVE-2026-60242 21.07.2026 9.8
CVE-2026-60244 21.07.2026 9.8
CVE-2026-60246 21.07.2026 9.8
CVE-2026-60247 21.07.2026 9.8
CVE-2026-60248 21.07.2026 9.3
CVE-2026-60249 21.07.2026 9
CVE-2026-60250 21.07.2026 9.8
CVE-2026-60251 21.07.2026 9.8
CVE-2026-60253 21.07.2026 9.8
CVE-2026-60254 21.07.2026 9.8
CVE-2026-60256 21.07.2026 9.8
CVE-2026-60257 21.07.2026 9.8
CVE-2026-60258 21.07.2026 9.8
CVE-2026-60259 21.07.2026 9.8
CVE-2026-60262 21.07.2026 9.8
CVE-2026-60264 21.07.2026 9.8
CVE-2026-60267 21.07.2026 9.1
CVE-2026-60269 21.07.2026 9.8
CVE-2026-60272 21.07.2026 9.8
CVE-2026-60274 21.07.2026 9.8
CVE-2026-60275 21.07.2026 9.8
CVE-2026-60276 21.07.2026 9.8
CVE-2026-60278 21.07.2026 9.8
CVE-2026-60279 21.07.2026 9.8
CVE-2026-60280 21.07.2026 9.8
CVE-2026-60285 21.07.2026 9.8
CVE-2026-60286 21.07.2026 9.8
CVE-2026-60287 21.07.2026 9.8
CVE-2026-60288 21.07.2026 9.8
CVE-2026-60289 21.07.2026 9.8
CVE-2026-60290 21.07.2026 9.8
CVE-2026-60291 21.07.2026 9.8
CVE-2026-60292 21.07.2026 9.8
CVE-2026-60294 21.07.2026 9.8
CVE-2026-60296 21.07.2026 9.8
CVE-2026-60297 21.07.2026 9.8
CVE-2026-60298 21.07.2026 9.8
CVE-2026-60299 21.07.2026 9.8
CVE-2026-60300 21.07.2026 9.8
CVE-2026-60302 21.07.2026 9.8
CVE-2026-60306 21.07.2026 9.8
CVE-2026-60308 21.07.2026 9.8
CVE-2026-60326 21.07.2026 9.1
CVE-2026-65317 Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass 23.07.2026 9.2
CVE-2026-8984 Unauthenticated RCE 22.07.2026 10
CVE-2026-8985 Unauthenticated Command Injection 22.07.2026 10
CVE-2026-8986 Command Injection via Malicious OCPP Server 22.07.2026 9.5
CVE-2026-8987 Authenticated Heap Overflow 22.07.2026 9.4
CVE-2026-47708 MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper 22.07.2026 9.3
CVE-2026-65057 Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck 22.07.2026 9.2
CVE-2026-8982 Hard-coded / Backdoor Accounts 22.07.2026 10
CVE-2026-8983 Backdoor Authentication Token 22.07.2026 10
CVE-2026-63764 lmdeploy Server-Side Request Forgery via HTTP Redirect Bypass of Private-IP Guard in Vision Image Fetch 23.07.2026 9.2
CVE-2026-64878 Command Injection 22.07.2026 9.4
CVE-2026-64879 Command Injection 22.07.2026 9.4
CVE-2016-20096 Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp 22.07.2026 9.3
CVE-2026-64877 22.07.2026 9.4
CVE-2026-47413 praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members 22.07.2026 9.6
CVE-2026-47416 praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id} 22.07.2026 9.6
CVE-2026-47407 PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation 22.07.2026 9.4
CVE-2026-47410 praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset 22.07.2026 9.8
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution 23.07.2026 9.8
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) 21.07.2026 9.9
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default 22.07.2026 9.8
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset 22.07.2026 9.8
CVE-2026-64824 Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore 21.07.2026 9.3
CVE-2026-64825 Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload 21.07.2026 9
CVE-2026-65048 Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index 22.07.2026 9.3
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData 22.07.2026 9.3
CVE-2026-1617 SQLi in Turkmesh's Turkhotspot 5651 Loglama 21.07.2026 9.8
CVE-2026-13439 Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint 21.07.2026 9.8
CVE-2026-64625 AVideo before 29.0 OS Command Injection via execAsync 23.07.2026 9.3
CVE-2026-13380 VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses 21.07.2026 9
CVE-2026-53595 FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL 21.07.2026 9.4
CVE-2026-16337 21.07.2026 9.4
CVE-2026-44231 RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint 21.07.2026 9.1
CVE-2026-63766 GPT-SoVITS 20250606v2pro OS Command Injection via webui.py 21.07.2026 9.3
CVE-2026-63767 ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ 21.07.2026 9.3
CVE-2026-61424 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 23.07.2026 10
CVE-2026-61425 Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 23.07.2026 9.4
CVE-2026-61900 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 23.07.2026 10
CVE-2026-60032 Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 23.07.2026 9.4
CVE-2026-60034 Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 23.07.2026 9.4
CVE-2026-39878 Chamilo stored XSS via user registration leads to admin account takeover 20.07.2026 9.3
CVE-2026-35048 Piwigo RCE via PHP Code Injection into Config File in Installer 20.07.2026 9.8
CVE-2026-41252 xrdp: lib_palette_update Heap Buffer Overflow & RCE 23.07.2026 9.8
CVE-2026-54051 Network-AI has an an OS Command Injection issue 21.07.2026 9.9
CVE-2026-35198 HeyForm vulnerable to stored XSS via form field titles 20.07.2026 9
CVE-2026-46428 lettre has TLS hostname verification disabled when using Boring TLS backend 21.07.2026 9.1
CVE-2026-51027 20.07.2026 9.9
CVE-2026-46412 Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm 20.07.2026 10
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport 22.07.2026 9
CVE-2026-57309 Blind SQL Injection in Windu CMS 20.07.2026 9.3
CVE-2026-63756 SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition 21.07.2026 9.2
CVE-2026-64620 FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common 21.07.2026 9.3
CVE-2026-64621 FreeRDP before 3.28.0 Double-Free via selectedmonitors 21.07.2026 9.3
CVE-2026-64622 Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox 21.07.2026 9.3
CVE-2026-16242 Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates 21.07.2026 9.4
CVE-2026-44359 Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow 20.07.2026 10
CVE-2026-64035 igc: set tx buffer type for SMD frames 20.07.2026 9.8
CVE-2026-64037 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled 20.07.2026 9.8
CVE-2026-64046 net: tls: prevent chain-after-chain in plain text SG 20.07.2026 9.8
CVE-2026-64047 net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring 20.07.2026 9.8
CVE-2026-64055 net: ethernet: cortina: Carry over frag counter 20.07.2026 9.8
CVE-2026-64056 net: ethernet: cortina: Make RX SKB per-port 20.07.2026 9.8
CVE-2026-64061 netfs: Fix early put of sink folio in netfs_read_gaps() 20.07.2026 9.8
CVE-2026-64066 netfs: Fix netfs_read_to_pagecache() to pause on subreq failure 20.07.2026 9.8
CVE-2026-64067 netfs: Fix missing barriers when accessing stream->subrequests locklessly 20.07.2026 9.8
CVE-2026-64068 netfs: Fix missing locking around retry adding new subreqs 20.07.2026 9.8
CVE-2026-64069 netfs: Fix cancellation of a DIO and single read subrequests 20.07.2026 9.8
CVE-2026-64080 firmware: arm_ffa: Snapshot notifier callbacks under lock 20.07.2026 9.3
CVE-2026-64089 batman-adv: tt: fix negative last_changeset_len 20.07.2026 9.8
CVE-2026-64091 batman-adv: tt: fix TOCTOU race for reported vlans 20.07.2026 9.8
CVE-2026-64102 RDMA/siw: Reject MPA FPDU length underflow before signed receive math 20.07.2026 9.8
CVE-2026-64106 KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits 20.07.2026 9
CVE-2026-64113 ixgbevf: fix use-after-free in VEPA multicast source pruning 20.07.2026 9.8
CVE-2026-64122 net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover 20.07.2026 9.8
CVE-2026-64125 net: bcmgenet: keep RBUF EEE/PM disabled 20.07.2026 9.8
CVE-2026-64132 ipv6: ioam: refresh hdr pointer before ioam6_event() 20.07.2026 9.8
CVE-2026-64136 smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() 20.07.2026 9.8
CVE-2026-64142 ksmbd: close durable scavenger races against m_fp_list lookups 20.07.2026 9.8
CVE-2026-64150 netfilter: nft_inner: release local_lock before re-enabling softirqs 20.07.2026 9.8
CVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_point 20.07.2026 9.8
CVE-2026-64162 idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() 20.07.2026 9.8
CVE-2026-64016 ksmbd: fix durable reconnect error path file lifetime 20.07.2026 9.8
CVE-2026-64018 net: mana: validate rx_req_idx to prevent out-of-bounds array access 20.07.2026 9.3
CVE-2026-64024 tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction 20.07.2026 9.4
CVE-2026-64025 bpf, skmsg: fix verdict sk_data_ready racing with ktls rx 20.07.2026 9.8
CVE-2026-64033 RDMA/rtrs: Fix use-after-free in path file creation cleanup 20.07.2026 9.8
CVE-2026-64034 net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer 20.07.2026 9.3
CVE-2026-63886 scsi: target: iscsi: Validate CHAP_R length before base64 decode 20.07.2026 9.8
CVE-2026-63887 scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf 20.07.2026 9.8
CVE-2026-63888 scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() 20.07.2026 9.8
CVE-2026-63912 xfrm: esp: restore combined single-frag length gate 20.07.2026 9.8
CVE-2026-63922 ipv6: exthdrs: refresh nh after handling HAO option 20.07.2026 9.8
CVE-2026-63924 ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() 20.07.2026 9.8
CVE-2026-63938 KVM: SEV: Check PSC request indices against the actual size of the buffer 20.07.2026 9.3
CVE-2026-63939 KVM: SEV: Compute the correct max length of the in-GHCB scratch area 20.07.2026 9.3
CVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0' 20.07.2026 9.3
CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit 20.07.2026 9.8
CVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doit 20.07.2026 9.8
CVE-2026-63984 ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() 20.07.2026 9.8
CVE-2026-63992 tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() 20.07.2026 9.1
CVE-2026-63993 vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() 20.07.2026 9.8
CVE-2026-63994 tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() 20.07.2026 9.8
CVE-2026-64000 net: hsr: fix potential OOB access in supervision frame handling 20.07.2026 9.8
CVE-2026-64007 netfilter: synproxy: refresh tcphdr after skb_ensure_writable 20.07.2026 9.8
CVE-2026-63857 net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() 20.07.2026 9.8
CVE-2026-53384 serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails 20.07.2026 9.8
CVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanup 20.07.2026 9.8
CVE-2026-53399 nfsd: release layout stid on setlease failure 20.07.2026 9.8
CVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error path 20.07.2026 10
CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout() 20.07.2026 9.8
CVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry() 20.07.2026 9.8
CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes 20.07.2026 9.8
CVE-2026-63830 net: skmsg: preserve sg.copy across SG transforms 20.07.2026 9.4
CVE-2026-9323 Insecure PRNG and Information Exposure in urwid Web Display Backend 20.07.2026 9.2
CVE-2024-58366 SurrealDB before 1.1.1 Format String via Scripting Functions 20.07.2026 9
CVE-2025-71392 SurrealDB before 2.2.2 SurrealQL Injection via export 21.07.2026 9.4
CVE-2026-16117 @fastify/http-proxy vulnerable to prefix escape via URL-encoded characters 20.07.2026 10
CVE-2026-47865 VMware Avi Load Balancer Authentication Bypass Vulnerability 23.07.2026 9.8
CVE-2026-13446 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints 23.07.2026 9.8
CVE-2026-48062 CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule 20.07.2026 9.8
CVE-2026-54159 ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE 20.07.2026 10
CVE-2026-54466 websocket-driver: Message corruption via abuse of protocol length headers 20.07.2026 9.2
CVE-2026-55518 Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation 20.07.2026 9.6
CVE-2026-15091 Multiple Vulnerabilities in IBM Engineering AI hub. 20.07.2026 9.3
CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution 22.07.2026 9.8
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability 23.07.2026 9.9
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint 23.07.2026 9.9
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution 23.07.2026 9.8
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component 23.07.2026 9.9
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header 23.07.2026 9.9
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint 23.07.2026 9.8
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation 23.07.2026 9.9
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation 18.07.2026 9.8
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution 18.07.2026 9.8
CVE-2026-12693 IDOR in Vimesoft's Enterprise Video Platform 17.07.2026 9.4
CVE-2026-12694 Missing Authorization in Vimesoft's Enterprise Video Platform 17.07.2026 9.1
CVE-2026-54496 Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness 17.07.2026 9.3
CVE-2026-12692 Improper Authentication in Vimesoft's Enterprise Video Platform 17.07.2026 9.8
CVE-2026-8297 SQLi in GIS Informatics' GisLab Laboratory Management System 17.07.2026 9.8
CVE-2026-9586 Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB 17.07.2026 9.3
CVE-2024-23564 17.07.2026 9.1
CVE-2026-15982 Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function' 17.07.2026 9.8
CVE-2026-14956 Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter 21.07.2026 9.8
CVE-2026-62232 Grav < 2.0.4 2FA Bypass via Secret Regeneration 17.07.2026 9.1
CVE-2026-62241 clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery 17.07.2026 9.3
CVE-2026-44181 Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution 17.07.2026 10
CVE-2026-44182 Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering 17.07.2026 10
CVE-2026-44180 Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed 17.07.2026 9.8
CVE-2026-53412 Zoom Workplace VDI Plugin for Windows - Improper Input Validation 17.07.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-11804 Program Module Vulnerability 23.07.2026 5.2
CVE-2026-16584 AWS API MCP Server Security Policy Bypass via Startup Failure 23.07.2026 7
CVE-2026-48530 GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx 23.07.2026
CVE-2026-48531 GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx 23.07.2026
CVE-2026-48532 GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx 23.07.2026
CVE-2026-48533 23.07.2026
CVE-2026-48534 GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx 23.07.2026
CVE-2026-48535 GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx 23.07.2026
CVE-2026-48536 GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx 23.07.2026
CVE-2026-48537 GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx 23.07.2026
CVE-2026-48538 GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx 23.07.2026
CVE-2026-48539 GFI Archiver < 15.13 Stored XSS via MailInsights.aspx 23.07.2026
CVE-2026-43820 23.07.2026
CVE-2026-43823 23.07.2026
CVE-2026-16733 bahmutov find-cypress-specs Branch index.js shell.exec os command injection 23.07.2026
CVE-2026-16735 release-it conventional-changelog Changelog File index.js writeChangelog os command injection 23.07.2026
CVE-2026-65687 Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via SVG Processing 23.07.2026
CVE-2026-65688 Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Font Processing 23.07.2026
CVE-2026-65689 Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Database Download 23.07.2026
CVE-2026-65690 Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload 23.07.2026
CVE-2026-8287 Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting Software 23.07.2026 4.3
CVE-2026-14257 brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash 23.07.2026 7.5
CVE-2026-65898 DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig 23.07.2026
CVE-2026-65899 DOMPurify before 3.4.9 Trusted Types Policy State Contamination 23.07.2026
CVE-2026-65900 DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM 23.07.2026
CVE-2026-65901 DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName 23.07.2026
CVE-2026-65902 DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags 23.07.2026
CVE-2026-65903 DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS 23.07.2026
CVE-2026-65904 DOMPurify before 3.4.4 Cross-Site Scripting via IN_PLACE mode 23.07.2026
CVE-2026-65911 DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage 23.07.2026
CVE-2026-65912 DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR 23.07.2026
CVE-2026-65913 DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES 23.07.2026
CVE-2026-65914 DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization 23.07.2026
CVE-2026-15037 XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization 23.07.2026
CVE-2026-65906 23.07.2026 8.8
CVE-2026-65907 23.07.2026 9.1
CVE-2026-65908 23.07.2026 8.6
CVE-2026-57626 WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 7.1
CVE-2026-61945 WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability 23.07.2026 6.5
CVE-2026-64800 23.07.2026 3.5
CVE-2026-64802 23.07.2026 7.8
CVE-2026-64803 23.07.2026 7.8
CVE-2026-64804 23.07.2026 8.4
CVE-2026-64805 23.07.2026 8.4
CVE-2026-64806 23.07.2026 8.4
CVE-2026-64807 23.07.2026 7.8
CVE-2026-64808 23.07.2026 8.4
CVE-2026-64809 23.07.2026 8.4
CVE-2026-64810 23.07.2026 4.3
CVE-2026-64811 23.07.2026 7.8
CVE-2026-64812 23.07.2026 10
CVE-2026-64813 23.07.2026 10
CVE-2026-64814 23.07.2026 8.6
CVE-2026-64815 23.07.2026 8.1
CVE-2026-65475 WordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65605 SiYuan before v3.7.2 Stored XSS to RCE via Attribute View 23.07.2026
CVE-2026-65606 SiYuan before v3.7.2 Cross-Site Scripting to RCE 23.07.2026
CVE-2026-65607 SiYuan before v3.7.2 Path Traversal via /export/temp/ 23.07.2026
CVE-2026-65608 Grav before 2.0.9 Remote Code Execution via FlexDirectory 23.07.2026
CVE-2026-65895 Grav API Plugin before 1.0.10 Broken Access Control 23.07.2026
CVE-2026-65896 Grav API Plugin before 1.0.10 Path Traversal via move 23.07.2026
CVE-2026-65897 Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups 23.07.2026
CVE-2025-68081 WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability 23.07.2026 5.9
CVE-2026-24537 WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 4.3
CVE-2026-24552 WordPress Create by Mediavine plugin <= 2.5.3 - SQL Injection vulnerability 23.07.2026 8.5
CVE-2026-24628 WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting (XSS) vulnerability 23.07.2026 5.9
CVE-2026-24639 WordPress Photo Block plugin <= 1.7.1 - Server Side Request Forgery (SSRF) vulnerability 23.07.2026 4.4
CVE-2026-25405 WordPress eRoom plugin <= 1.7.1 - SQL Injection vulnerability 23.07.2026 8.5
CVE-2026-25424 WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-25427 WordPress eRoom plugin <= 1.7.1 - Broken Access Control vulnerability 23.07.2026 5.4
CVE-2026-25466 WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-27064 WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-27355 WordPress Ditty plugin <= 3.1.66 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-27372 WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure vulnerability 23.07.2026 6.5
CVE-2026-27377 WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0.16 - Broken Access Control vulnerability 23.07.2026 6.7
CVE-2026-27391 WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability 23.07.2026 5.4
CVE-2026-27392 WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-27399 WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-27403 WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-27418 WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-27422 WordPress YT Player plugin <= 2.0.9 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-27423 WordPress Participants Database plugin <= 2.7.8.4 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-57367 WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnerability 23.07.2026 7.1
CVE-2026-57370 WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflected Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57373 WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.4 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-57374 WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.7 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57384 WordPress WishList Member X plugin <= 3.32.0 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-57397 WordPress Coaching theme <= 3.9.2 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57425 WordPress Autopay dla WooCommerce plugin <= 2.2.27 - Broken Access Control vulnerability 23.07.2026 6.5
CVE-2026-57427 WordPress Download Monitor - WPForms Lock plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57428 WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57696 WordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerability 23.07.2026 7.1
CVE-2026-57699 WordPress Slider Pro plugin <= 4.8.13 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57701 WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57703 WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerability 23.07.2026 6.3
CVE-2026-57704 WordPress Smart Manager plugin <= 8.90.0 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57716 WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vulnerability 23.07.2026 5.3
CVE-2026-57717 WordPress Knit Pay plugin <= 9.6.0.0 - Broken Access Control vulnerability 23.07.2026 6.5
CVE-2026-57735 WordPress Breakdance plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57767 WordPress WP Google Maps Pro plugin <= 10.1.02 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57769 WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-57784 WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-57785 WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 8.8
CVE-2026-57808 WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability 23.07.2026 6.5
CVE-2026-57809 WordPress AffiliateWP plugin <= 2.34.0 - Reflected Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-59512 WordPress Product Enquiry for WooCommerce plugin <= 2.2.34.43 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-59513 WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-59514 WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59517 WordPress Easy Form Builder plugin <= 4.0.12 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-59522 WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability 23.07.2026 6.5
CVE-2026-59524 WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability 23.07.2026 6.5
CVE-2026-59525 WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59526 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59540 WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-59541 WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability 23.07.2026 8.8
CVE-2026-59542 WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability 23.07.2026 7.7
CVE-2026-59543 WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability 23.07.2026 9.9
CVE-2026-59544 WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability 23.07.2026 9.8
CVE-2026-59545 WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability 23.07.2026 8.1
CVE-2026-59547 WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.1.4 - Broken Access Control vulnerability 23.07.2026 7.5
CVE-2026-59554 WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability 23.07.2026 7.5
CVE-2026-59555 WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability 23.07.2026 10
CVE-2026-61943 WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vulnerability 23.07.2026 7.5
CVE-2026-61944 WordPress Bookly plugin <= 27.7 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-61946 WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability 23.07.2026 6.5
CVE-2026-61947 WordPress Form Vibes – Database Manager for Forms plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-61948 WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61949 WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61950 WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61951 WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-61954 WordPress PayU India plugin <= 3.8.9 - Broken Access Control vulnerability 23.07.2026 7.5
CVE-2026-61972 WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-61973 WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-61981 WordPress Simple Link Directory Pro plugin <= 15.0.8 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 5.4
CVE-2026-65449 WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65450 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 23.07.2026 8.5
CVE-2026-65451 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 23.07.2026 8.5
CVE-2026-65452 WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65453 WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65454 WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability 23.07.2026 8.5
CVE-2026-65455 WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65456 WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object References (IDOR) vulnerability 23.07.2026 4.3
CVE-2026-65457 WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-65458 WordPress Polylang plugin <= 3.8.5 - Sensitive Data Exposure vulnerability 23.07.2026 4.3
CVE-2026-65460 WordPress Zarinpal Gateway plugin <= 5.1.0 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 4.3
CVE-2026-65461 WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65462 WordPress Uncanny Automator plugin <= 7.3.2 - SQL Injection vulnerability 23.07.2026 7.6
CVE-2026-65463 WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerability 23.07.2026 5.4
CVE-2026-65464 WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 5.4
CVE-2026-65465 WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65466 WordPress JetBooking plugin <= 4.1.2 - Server Side Request Forgery (SSRF) vulnerability 23.07.2026 4.9
CVE-2026-65467 WordPress JetEngine plugin <= 3.8.11 - Server Side Request Forgery (SSRF) vulnerability 23.07.2026 4.9
CVE-2026-65468 WordPress JetBooking plugin <= 4.1.2 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65469 WordPress AWP Classifieds plugin <= 4.4.7 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65470 WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65471 WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-65472 WordPress Kit (formerly ConvertKit) plugin <= 3.3.5 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65473 WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65474 WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability 23.07.2026 5.3
CVE-2026-65476 WordPress Civi theme <= 2.2.4 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65477 WordPress Tonda Core plugin <= 2.1.2 - Local File Inclusion vulnerability 23.07.2026 7.5
CVE-2026-65478 WordPress ListingPro plugin <= 2.9.10 - Broken Access Control vulnerability 23.07.2026 5.4
CVE-2026-65479 WordPress Reviewer plugin <= 3.14.2 - Broken Access Control vulnerability 23.07.2026 5.4
CVE-2026-65480 WordPress TheGem theme <= 5.11.1 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65481 WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability 23.07.2026 7.5
CVE-2026-65482 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65483 WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability 23.07.2026 5.9
CVE-2026-65484 WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability 23.07.2026 6.3
CVE-2026-65485 WordPress Content Control plugin <= 2.6.5 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65486 WordPress Event post plugin <= 6.0.1 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65487 WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65488 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability 23.07.2026 7.1
CVE-2026-65489 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65490 WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulnerability 23.07.2026 5.3
CVE-2026-65491 WordPress Query Wrangler plugin <= 1.5.57 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-65492 WordPress Dokan Pro plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-65493 WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability 23.07.2026 7.5
CVE-2026-65494 WordPress Dokan Pro plugin <= 5.0.2 - SQL Injection vulnerability 23.07.2026 7.1
CVE-2026-65495 WordPress Dokan Pro plugin <= 5.0.3 - Broken Access Control vulnerability 23.07.2026 7.5
CVE-2026-65496 WordPress Complianz plugin <= 7.5.0 - Server Side Request Forgery (SSRF) vulnerability 23.07.2026 4.4
CVE-2026-65497 WordPress Complianz plugin <= 7.5.0 - PHP Object Injection vulnerability 23.07.2026 7.2
CVE-2026-65498 WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability 23.07.2026 5.3
CVE-2026-65499 WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Broken Access Control vulnerability 23.07.2026 6.5
CVE-2026-65500 WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Broken Access Control vulnerability 23.07.2026 7.5
CVE-2026-65501 WordPress Shiptastic for WooCommerce plugin <= 5.1.0 - Insecure Direct Object References (IDOR) vulnerability 23.07.2026 5.3
CVE-2026-65503 WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65505 WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Data Exposure vulnerability 23.07.2026 5.3
CVE-2026-65506 WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.12 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65510 WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-65511 WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability 23.07.2026 7.1
CVE-2026-65512 WordPress WP Activity Log plugin <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 5.4
CVE-2026-65514 WordPress Appointment Hour Booking plugin <= 1.5.86 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65516 WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulnerability 23.07.2026 7.2
CVE-2026-65518 WordPress Accept Donations with PayPal & Stripe plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65519 WordPress Photo Gallery plugin <= 2.7.7.29 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65521 WordPress WP Social Ninja plugin <= 4.3.0 - Sensitive Data Exposure vulnerability 23.07.2026 5.3
CVE-2026-65522 WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65524 WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-65525 WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65526 WordPress Visualizer plugin <= 4.0.6 - SQL Injection vulnerability 23.07.2026 8.5
CVE-2026-65527 WordPress LIQUID SPEECH BALLOON plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65528 WordPress BSK PDF Manager plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65529 WordPress Graphina plugin <= 3.1.12 - Broken Access Control vulnerability 23.07.2026 5.3
CVE-2026-65530 WordPress TemplateSpare plugin <= 4.2.2 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-65531 WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability 23.07.2026 4.8
CVE-2026-65532 WordPress Persian Woocommerce SMS plugin <= 7.2.2 - SQL Injection vulnerability 23.07.2026 7.6
CVE-2026-65533 WordPress Smart SEO Tool plugin <= 4.1.2 - Cross Site Scripting (XSS) vulnerability 23.07.2026 6.5
CVE-2026-65534 WordPress Custom links in Elementor Image Carousel plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability 23.07.2026 5.9
CVE-2026-65535 WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerability 23.07.2026 4.3
CVE-2026-65536 WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 6.5
CVE-2026-65537 WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerability 23.07.2026 4.3
CVE-2026-65538 WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability 23.07.2026 5.9
CVE-2026-65539 WordPress Kwayy HTML Sitemap plugin <= 4.0 - CSRF to Stored XSS vulnerability 23.07.2026 7.1
CVE-2026-65540 WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 7.1
CVE-2026-65550 WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability 23.07.2026 5.9
CVE-2026-16745 Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation 23.07.2026
CVE-2026-64611 Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel() 23.07.2026
CVE-2026-13009 AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Parameter 23.07.2026 6.5
CVE-2026-13119 Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter 23.07.2026 6.5
CVE-2026-15015 MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint 23.07.2026 9.8
CVE-2026-15017 MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers 23.07.2026 8.8
CVE-2026-15348 Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter 23.07.2026 6.3
CVE-2026-15394 Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta 23.07.2026 6.4
CVE-2026-15448 Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter 23.07.2026 6.5
CVE-2026-15786 WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter 23.07.2026 4.9
CVE-2026-65758 Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 23.07.2026
CVE-2026-14282 GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field 23.07.2026 9.8
CVE-2026-14481 Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter 23.07.2026 6.4
CVE-2026-15011 Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter 23.07.2026 9.8
CVE-2026-15404 Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title 23.07.2026 6.4
CVE-2026-15646 Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute 23.07.2026 6.4
CVE-2026-15647 Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field 23.07.2026 4.4
CVE-2026-15761 Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter 23.07.2026 6.5
CVE-2026-15794 Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute 23.07.2026 6.4
CVE-2026-15827 GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints 23.07.2026 5.3
CVE-2026-15906 Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' Parameter 23.07.2026 6.5
CVE-2026-16078 WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter 23.07.2026 6.5
CVE-2026-64799 Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions 23.07.2026
CVE-2026-64871 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension 23.07.2026
CVE-2026-64872 Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension 23.07.2026
CVE-2026-64873 Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension 23.07.2026
CVE-2026-64874 Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension 23.07.2026
CVE-2026-64875 Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension 23.07.2026
CVE-2026-64876 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension 23.07.2026
CVE-2026-65430 Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension 23.07.2026
CVE-2026-65431 Joomla Extension - regularlabs.com - Zipslip in GeoIP extension 23.07.2026
CVE-2026-65712 Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension 23.07.2026
CVE-2026-65713 Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension 23.07.2026
CVE-2026-65754 Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension 23.07.2026
CVE-2026-65755 Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension 23.07.2026
CVE-2026-65756 Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension 23.07.2026
CVE-2026-65757 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension 23.07.2026
CVE-2024-58023 23.07.2026 8.4
CVE-2024-58330 23.07.2026 7.5
CVE-2026-16287 Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update 23.07.2026 7.8
CVE-2026-16723 Remote Code Execution in fastjson 1.2.68–1.2.83 23.07.2026 9
CVE-2026-52684 Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack 23.07.2026 3.7
CVE-2026-52686 Wildcard CNAME proof validation bypass 23.07.2026 3.7
CVE-2026-52688 RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation 23.07.2026 7.5
CVE-2026-12421 ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values 23.07.2026 7.2
CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare 23.07.2026
CVE-2026-59678 portprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager 23.07.2026
CVE-2026-9635 WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute 23.07.2026 6.4
CVE-2026-9713 Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload 23.07.2026 7.5
CVE-2026-9729 Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter 23.07.2026 6.4
CVE-2026-12082 Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure) 23.07.2026
CVE-2026-14291 Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa 23.07.2026
CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare 23.07.2026
CVE-2026-9066 WP Compress < 7.10.04 - Reflected XSS via test_zone 23.07.2026
CVE-2026-9577 Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter 23.07.2026
CVE-2026-63226 23.07.2026
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK 23.07.2026
CVE-2026-7232 FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters 23.07.2026 7.2
CVE-2026-7534 SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter 23.07.2026 7.2
CVE-2026-6390 Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling. 23.07.2026
CVE-2026-15074 @fastify/static vulnerable to route guard bypass via path traversal 23.07.2026 7.5
CVE-2026-7120 @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths 23.07.2026 5.3
CVE-2026-21723 CVE-2026-21723 Record 23.07.2026 5.3
CVE-2026-16653 boazsegev facil.io Public Folder http.c http_sendfile2 path traversal 23.07.2026
CVE-2026-16631 publint package-manager pack.js child_process.exec os command injection 23.07.2026
CVE-2026-16632 boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation 23.07.2026
CVE-2026-16630 syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection 23.07.2026
CVE-2026-38763 22.07.2026
CVE-2026-38765 22.07.2026
CVE-2026-38766 22.07.2026
CVE-2026-60366 23.07.2026 10
CVE-2026-60367 23.07.2026 9.8
CVE-2026-60368 23.07.2026 8.8
CVE-2026-60369 23.07.2026 9.9
CVE-2026-60370 23.07.2026 7.5
CVE-2026-60371 23.07.2026 8
CVE-2026-60372 23.07.2026 9.8
CVE-2026-60373 23.07.2026 8.8
CVE-2026-60439 23.07.2026 8.8
CVE-2026-60455 23.07.2026 8.8
CVE-2026-61246 23.07.2026 8.8
CVE-2026-16628 oclif JIT Plugin Entry child_process.exec os command injection 23.07.2026
CVE-2026-16629 danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection 22.07.2026
CVE-2025-50330 22.07.2026
CVE-2025-60835 22.07.2026
CVE-2026-13089 OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify 22.07.2026
CVE-2026-63265 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints 23.07.2026
CVE-2026-63280 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager 23.07.2026
CVE-2026-63281 Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager 23.07.2026
CVE-2026-63683 Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager 23.07.2026
CVE-2026-63684 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension 23.07.2026
CVE-2026-63685 Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension 23.07.2026
CVE-2026-64791 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager 23.07.2026
CVE-2026-64792 Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions 23.07.2026
CVE-2026-64793 Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions 23.07.2026
CVE-2026-64794 Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions 23.07.2026
CVE-2026-64795 Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions 23.07.2026
CVE-2026-64796 Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension 23.07.2026
CVE-2026-64797 Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension 23.07.2026
CVE-2026-64798 Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension 23.07.2026
CVE-2025-44089 22.07.2026
CVE-2025-44090 22.07.2026
CVE-2025-50324 22.07.2026
CVE-2025-50325 22.07.2026
CVE-2025-50327 22.07.2026
CVE-2025-50329 22.07.2026
CVE-2026-64829 Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow 23.07.2026