| CVE-2026-17561 |
Unauthenticated RCE in Innotim Software's Logsign SIEM |
31.07.2026 |
9.8 |
| CVE-2025-67649 |
Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script |
31.07.2026 |
9.3 |
| CVE-2026-14483 |
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command |
31.07.2026 |
9.8 |
| CVE-2026-18452 |
Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials |
31.07.2026 |
10 |
| CVE-2026-63221 |
CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions |
31.07.2026 |
9.4 |
| CVE-2026-63223 |
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules |
31.07.2026 |
9.8 |
| CVE-2026-66418 |
OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field |
30.07.2026 |
9.3 |
| CVE-2026-68502 |
LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE |
31.07.2026 |
9.8 |
| CVE-2026-68503 |
LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard |
30.07.2026 |
9.8 |
| CVE-2026-66803 |
Azure Cosmos DB Remote Code Execution Vulnerability |
31.07.2026 |
10 |
| CVE-2026-12946 |
Remote Code Execution in CUGA Component CodeAgent |
31.07.2026 |
9.9 |
| CVE-2026-67208 |
Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console |
31.07.2026 |
9.3 |
| CVE-2026-67594 |
Spikster Missing Authentication via API Route Group |
31.07.2026 |
9.3 |
| CVE-2026-66066 |
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing |
30.07.2026 |
9.5 |
| CVE-2026-12943 |
This Power Hardware Management Console update is being released to address |
31.07.2026 |
9.8 |
| CVE-2026-12118 |
IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data |
30.07.2026 |
9.8 |
| CVE-2026-13435 |
Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure |
31.07.2026 |
9.9 |
| CVE-2026-48499 |
Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache |
30.07.2026 |
9.3 |
| CVE-2026-12940 |
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints |
31.07.2026 |
9.8 |
| CVE-2026-28323 |
SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability |
31.07.2026 |
9.8 |
| CVE-2026-4978 |
SQLi in UMAI Vision's Traffic Analysis System |
30.07.2026 |
9.8 |
| CVE-2026-11707 |
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager |
30.07.2026 |
9.3 |
| CVE-2026-15435 |
IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability |
31.07.2026 |
9.8 |
| CVE-2026-53431 |
Boruta accepts expired JWT client assertions due to missing exp claim validation |
31.07.2026 |
9.1 |
| CVE-2026-47876 |
VMXNET3 out-of-bounds write vulnerability |
30.07.2026 |
9.3 |
| CVE-2026-54363 |
CentreStack < 17.5 Hardcoded Key Token Forgery RCE |
30.07.2026 |
9.3 |
| CVE-2026-59309 |
vCenter authentication-bypass vulnerability |
30.07.2026 |
9.8 |
| CVE-2026-59310 |
vCenter directory-traversal vulnerability |
30.07.2026 |
9.8 |
| CVE-2026-18363 |
Weak password recovery mechanism in osTicket by Enhancesoft LLC |
30.07.2026 |
9.1 |
| CVE-2026-44090 |
Missing authentication for MQTT Broker |
30.07.2026 |
9.3 |
| CVE-2026-44101 |
OCPP reconfiguration vulnerability |
30.07.2026 |
9.3 |
| CVE-2026-44104 |
ControllerAgent does not perform validation of firmware |
30.07.2026 |
9.3 |
| CVE-2026-44108 |
Firewall bypass during shutdown |
30.07.2026 |
9.3 |
| CVE-2026-7849 |
Command Injection in SCM (idledisconnect parameter) |
30.07.2026 |
9.3 |
| CVE-2026-58046 |
|
30.07.2026 |
9.9 |
| CVE-2026-58066 |
|
31.07.2026 |
9.8 |
| CVE-2026-16610 |
Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key |
30.07.2026 |
9.8 |
| CVE-2026-48449 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
30.07.2026 |
10 |
| CVE-2026-67595 |
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php |
30.07.2026 |
9.2 |
| CVE-2026-16326 |
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode |
29.07.2026 |
10 |
| CVE-2026-67426 |
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration |
29.07.2026 |
9.3 |
| CVE-2026-67429 |
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) |
29.07.2026 |
10 |
| CVE-2026-14529 |
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery |
30.07.2026 |
9.4 |
| CVE-2026-18236 |
Google-ADK Continuation Forgery |
29.07.2026 |
9.3 |
| CVE-2026-41939 |
Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly |
30.07.2026 |
9.3 |
| CVE-2026-54680 |
Logging operator has Fluentd configuration injection that allows remote code execution |
30.07.2026 |
9.9 |
| CVE-2026-8338 |
Authentication and Authorization Bypass in Coverity Connect |
29.07.2026 |
9.2 |
| CVE-2026-54735 |
prebid-server's request forgery vulnerability allows for possible host environment data extraction |
29.07.2026 |
10 |
| CVE-2026-60112 |
AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() |
29.07.2026 |
9.3 |
| CVE-2026-60113 |
AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes |
30.07.2026 |
9.3 |
| CVE-2026-67191 |
Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser |
29.07.2026 |
9.3 |
| CVE-2026-67192 |
Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher |
29.07.2026 |
9.2 |
| CVE-2026-65886 |
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 |
29.07.2026 |
9.2 |
| CVE-2026-65887 |
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 |
30.07.2026 |
10 |
| CVE-2026-65888 |
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 |
30.07.2026 |
10 |
| CVE-2026-65889 |
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2 |
29.07.2026 |
9.2 |
| CVE-2026-65890 |
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 |
29.07.2026 |
9.2 |
| CVE-2026-9177 |
Server-Side Template Injection in SecureTransport's Apache Velocity mail templates |
31.07.2026 |
9.4 |
| CVE-2026-0667 |
|
29.07.2026 |
9.3 |
| CVE-2026-65884 |
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 |
30.07.2026 |
10 |
| CVE-2026-65885 |
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 |
30.07.2026 |
9.4 |
| CVE-2026-14488 |
Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter |
29.07.2026 |
9.1 |
| CVE-2026-14900 |
Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter |
29.07.2026 |
9.8 |
| CVE-2026-65883 |
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 |
29.07.2026 |
10 |
| CVE-2025-10656 |
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation |
29.07.2026 |
9.8 |
| CVE-2026-58161 |
Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server |
29.07.2026 |
9.2 |
| CVE-2026-58179 |
Apache Traffic Server: regex_remap plugin overflows the stack from attacker input |
30.07.2026 |
9.2 |
| CVE-2026-58154 |
Apache Traffic Server: Memory-safety errors in MIME and header parsing |
29.07.2026 |
9.2 |
| CVE-2026-58155 |
Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling |
29.07.2026 |
9.2 |
| CVE-2026-18191 |
Vacron|IP Camera - Hidden Functionality |
29.07.2026 |
9.3 |
| CVE-2026-63227 |
Unrestricted SCORM file upload vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-63229 |
Pre-authentication blind SQL injection vulnerability |
29.07.2026 |
9.1 |
| CVE-2026-63230 |
Pre-authentication error-based SQL injection vulnerability |
29.07.2026 |
9.1 |
| CVE-2026-63232 |
SQL injection and unsafe deserialisation vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-63233 |
SQL injection and unsafe deserialisation vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-63234 |
SQL injection and unsafe deserialisation vulnerability |
29.07.2026 |
9.9 |
| CVE-2026-18072 |
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter |
29.07.2026 |
9.8 |
| CVE-2026-54658 |
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution |
29.07.2026 |
9.8 |
| CVE-2026-62325 |
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) |
29.07.2026 |
9.1 |
| CVE-2026-64863 |
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite |
29.07.2026 |
9.1 |
| CVE-2026-14446 |
IBM WebSphere Application Server is affected by a privilege escalation |
30.07.2026 |
9.8 |
| CVE-2026-14512 |
IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information |
30.07.2026 |
9.8 |
| CVE-2026-14958 |
OS command injection in IBM Aspera Faspex |
30.07.2026 |
9.1 |
| CVE-2026-14959 |
OS Command Injection in IBM Aspera Faspex |
30.07.2026 |
9.1 |
| CVE-2026-14973 |
Path Traversal in IBM Desktop App |
31.07.2026 |
9.3 |
| CVE-2026-6881 |
Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance |
29.07.2026 |
9.4 |
| CVE-2026-16498 |
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode |
28.07.2026 |
10 |
| CVE-2026-50736 |
|
28.07.2026 |
9 |
| CVE-2026-50737 |
|
28.07.2026 |
9 |
| CVE-2026-67174 |
DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick |
28.07.2026 |
9.2 |
| CVE-2026-65880 |
Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 |
28.07.2026 |
10 |
| CVE-2026-11841 |
CVE-2026-11841 |
28.07.2026 |
9.4 |
| CVE-2026-16462 |
SQL injection via unauthenticated GetGridData endpoint |
28.07.2026 |
9.3 |
| CVE-2026-11756 |
Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x |
28.07.2026 |
10 |
| CVE-2026-15014 |
SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter |
28.07.2026 |
9.8 |
| CVE-2026-64541 |
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket |
30.07.2026 |
9.8 |
| CVE-2026-64551 |
sctp: validate STALE_COOKIE cause length before reading staleness |
30.07.2026 |
9.1 |
| CVE-2026-66824 |
Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding |
28.07.2026 |
9.2 |
| CVE-2026-48030 |
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78) |
27.07.2026 |
9.9 |
| CVE-2026-55579 |
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise |
27.07.2026 |
9.8 |
| CVE-2026-63077 |
|
28.07.2026 |
9.8 |
| CVE-2026-16812 |
VeloCloud Orchestrator OS Command Injection |
28.07.2026 |
10 |
| CVE-2026-66394 |
SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass |
28.07.2026 |
9.3 |
| CVE-2026-66395 |
SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol |
28.07.2026 |
9.4 |
| CVE-2026-66396 |
SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL |
28.07.2026 |
9.3 |
| CVE-2026-66398 |
phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API |
28.07.2026 |
9.4 |
| CVE-2026-55953 |
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication |
28.07.2026 |
9.1 |
| CVE-2026-59527 |
WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59533 |
WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59538 |
WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59549 |
WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-59550 |
WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability |
27.07.2026 |
9.3 |
| CVE-2026-61511 |
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php |
29.07.2026 |
9.3 |
| CVE-2026-65766 |
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 |
28.07.2026 |
9.2 |
| CVE-2026-65876 |
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 |
28.07.2026 |
9.2 |
| CVE-2026-48144 |
Apache Thrift: c_glib TLS Client Missing Hostname Verification |
28.07.2026 |
9.1 |
| CVE-2026-55971 |
Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() |
28.07.2026 |
9.3 |
| CVE-2026-64534 |
nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path |
30.07.2026 |
9.8 |
| CVE-2026-64535 |
nvmet-tcp: Fix potential UAF when ddgst mismatch |
30.07.2026 |
9.8 |
| CVE-2026-64530 |
net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle |
27.07.2026 |
9.8 |
| CVE-2026-66012 |
SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP |
28.07.2026 |
10 |
| CVE-2026-66013 |
OpenRemote before 1.26.2 Authentication Bypass via Console Registration |
29.07.2026 |
9.3 |
| CVE-2026-64523 |
net/handshake: Take a long-lived file reference at submit |
27.07.2026 |
9.8 |
| CVE-2026-64257 |
smb: client: reject overlapping data areas in SMB2 responses |
27.07.2026 |
9.1 |
| CVE-2026-64268 |
RDMA/siw: bound Read Response placement to the RREAD length |
27.07.2026 |
9.8 |
| CVE-2026-64269 |
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg |
27.07.2026 |
9.1 |
| CVE-2026-64303 |
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path |
27.07.2026 |
9.8 |
| CVE-2026-64319 |
nvmet-auth: validate reply message payload bounds against transfer length |
27.07.2026 |
9.1 |
| CVE-2026-64320 |
nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page |
27.07.2026 |
9.1 |
| CVE-2026-64355 |
bpf: Reject fragmented frames in devmap |
27.07.2026 |
9.8 |
| CVE-2026-64383 |
smb: client: fix double-free in SMB2_flush() replay |
27.07.2026 |
9.8 |
| CVE-2026-64384 |
smb: client: fix change notify replay double-free |
27.07.2026 |
9.8 |
| CVE-2026-64385 |
smb: client: fix double-free in SMB2_ioctl() replay |
27.07.2026 |
9.8 |
| CVE-2026-64386 |
smb: client: fix query_info() replay double-free |
27.07.2026 |
9.8 |
| CVE-2026-64387 |
smb: client: fix query directory replay double-free |
27.07.2026 |
9.8 |
| CVE-2026-64391 |
ksmbd: use opener credentials for ADS I/O |
27.07.2026 |
9.8 |
| CVE-2026-64392 |
ksmbd: use opener credentials for delete-on-close |
27.07.2026 |
9.1 |
| CVE-2026-64393 |
ksmbd: run set info with opener credentials |
27.07.2026 |
9.1 |
| CVE-2026-64397 |
ksmbd: serialize QUERY_DIRECTORY requests per file |
27.07.2026 |
9.8 |
| CVE-2026-64399 |
ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE |
27.07.2026 |
9.8 |
| CVE-2026-64410 |
netfilter: flowtable: IPIP tunnel hardware offload is not yet support |
27.07.2026 |
9.8 |
| CVE-2026-64439 |
crypto: krb5 - filter out async aead implementations at alloc |
27.07.2026 |
9.8 |
| CVE-2026-64450 |
tipc: fix out-of-bounds read in broadcast Gap ACK blocks |
27.07.2026 |
9.1 |
| CVE-2026-64459 |
tcp: restore RCU grace period in tcp_ao_destroy_sock |
27.07.2026 |
9.8 |
| CVE-2026-61884 |
Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel |
27.07.2026 |
9.3 |