CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication 27.07.2026 9.1
CVE-2026-59527 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59533 WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59538 WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59549 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59550 WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-61511 vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php 27.07.2026 9.3
CVE-2026-65766 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 27.07.2026 9.2
CVE-2026-65876 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 27.07.2026 9.2
CVE-2026-12495 Stack-Based Buffer Overflow in the Mercusys MB115-4G 27.07.2026 9.2
CVE-2026-48144 Apache Thrift: c_glib TLS Client Missing Hostname Verification 27.07.2026 9.1
CVE-2026-55971 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() 27.07.2026 9.3
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle 27.07.2026 9.8
CVE-2026-66012 SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP 27.07.2026 10
CVE-2026-66013 OpenRemote before 1.26.2 Authentication Bypass via Console Registration 25.07.2026 9.3
CVE-2026-64523 net/handshake: Take a long-lived file reference at submit 27.07.2026 9.8
CVE-2026-64257 smb: client: reject overlapping data areas in SMB2 responses 27.07.2026 9.1
CVE-2026-64268 RDMA/siw: bound Read Response placement to the RREAD length 27.07.2026 9.8
CVE-2026-64269 RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg 27.07.2026 9.1
CVE-2026-64303 spi: fsl-lpspi: terminate the RX channel on TX prepare failure path 27.07.2026 9.8
CVE-2026-64319 nvmet-auth: validate reply message payload bounds against transfer length 27.07.2026 9.1
CVE-2026-64320 nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page 27.07.2026 9.1
CVE-2026-64355 bpf: Reject fragmented frames in devmap 27.07.2026 9.8
CVE-2026-64383 smb: client: fix double-free in SMB2_flush() replay 27.07.2026 9.8
CVE-2026-64384 smb: client: fix change notify replay double-free 27.07.2026 9.8
CVE-2026-64385 smb: client: fix double-free in SMB2_ioctl() replay 27.07.2026 9.8
CVE-2026-64386 smb: client: fix query_info() replay double-free 27.07.2026 9.8
CVE-2026-64387 smb: client: fix query directory replay double-free 27.07.2026 9.8
CVE-2026-64391 ksmbd: use opener credentials for ADS I/O 27.07.2026 9.8
CVE-2026-64392 ksmbd: use opener credentials for delete-on-close 27.07.2026 9.1
CVE-2026-64393 ksmbd: run set info with opener credentials 27.07.2026 9.1
CVE-2026-64397 ksmbd: serialize QUERY_DIRECTORY requests per file 27.07.2026 9.8
CVE-2026-64399 ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE 27.07.2026 9.8
CVE-2026-64410 netfilter: flowtable: IPIP tunnel hardware offload is not yet support 27.07.2026 9.8
CVE-2026-64439 crypto: krb5 - filter out async aead implementations at alloc 27.07.2026 9.8
CVE-2026-64450 tipc: fix out-of-bounds read in broadcast Gap ACK blocks 27.07.2026 9.1
CVE-2026-64459 tcp: restore RCU grace period in tcp_ao_destroy_sock 27.07.2026 9.8
CVE-2026-61884 Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel 27.07.2026 9.3
CVE-2026-62835 Azure Portal Information Disclosure Vulnerability 26.07.2026 9.3
CVE-2026-48021 epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau 25.07.2026 9.1
CVE-2026-64216 netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() 27.07.2026 9.8
CVE-2026-64232 block: recompute nr_integrity_segments in blk_insert_cloned_request 27.07.2026 9.8
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 26.07.2026 10
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability 26.07.2026 10
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability 26.07.2026 10
CVE-2026-12503 Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter 24.07.2026 9.2
CVE-2026-24727 SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type 24.07.2026 9.3
CVE-2026-15704 CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components 24.07.2026 9.8
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability 26.07.2026 9.9
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability 26.07.2026 9.9
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability 26.07.2026 9.1
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability 26.07.2026 9.8
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability 26.07.2026 10
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability 26.07.2026 10
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability 26.07.2026 10
CVE-2026-28698 Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs 24.07.2026 9.2
CVE-2026-42933 Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs 24.07.2026 10
CVE-2024-58353 Cal.com through 4.7.15 Cross-Site Scripting via booking questions 24.07.2026 9.3
CVE-2024-58355 Cal.com through 4.7.15 Cross-Site Scripting via booking questions 24.07.2026 9.3
CVE-2025-71389 Cal.com before 5.9.9 Remote Code Execution via RSC 24.07.2026 10
CVE-2026-63732 9router before 0.4.60 Remote Code Execution via default password 23.07.2026 9.4
CVE-2026-49035 Stack-based Buffer Overflow in MZ Automation libIEC61850 24.07.2026 9.2
CVE-2026-15981 SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter 24.07.2026 9.8
CVE-2026-47724 nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation 23.07.2026 9.9
CVE-2026-47669 DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE 24.07.2026 9.3
CVE-2026-47670 DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection 24.07.2026 9.4
CVE-2026-63359 Appriss Insights VINE SQLI 23.07.2026 9.3
CVE-2026-47668 DbGate: Unauthenticated Remote Code Execution via JSON Script Runner 24.07.2026 10
CVE-2026-6516 Remote Code Execution 24.07.2026 10
CVE-2026-47752 Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution 23.07.2026 9.9
CVE-2026-65700 h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API 23.07.2026 9.3
CVE-2026-65701 SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route 23.07.2026 9.3
CVE-2026-65760 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 24.07.2026 9.2
CVE-2026-65761 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 24.07.2026 9.3
CVE-2026-65687 Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing 24.07.2026 9.3
CVE-2026-65688 Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing 24.07.2026 9.3
CVE-2026-65689 Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download 24.07.2026 9.3
CVE-2026-65907 24.07.2026 9.1
CVE-2026-64812 24.07.2026 10
CVE-2026-64813 24.07.2026 10
CVE-2026-65605 SiYuan before v3.7.2 Stored XSS to RCE via Attribute View 24.07.2026 9.4
CVE-2026-65606 SiYuan before v3.7.2 Cross-Site Scripting to RCE 24.07.2026 9.4
CVE-2026-27064 WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-57784 WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-59514 WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59525 WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59526 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-59540 WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-59543 WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability 23.07.2026 9.9
CVE-2026-59544 WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability 23.07.2026 9.8
CVE-2026-59555 WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability 23.07.2026 10
CVE-2026-61948 WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61949 WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61950 WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability 23.07.2026 9.3
CVE-2026-61951 WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability 23.07.2026 9.8
CVE-2026-65455 WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65461 WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability 23.07.2026 9.1
CVE-2026-65471 WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability 23.07.2026 9.6
CVE-2026-15015 MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint 23.07.2026 9.8
CVE-2026-14282 GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field 23.07.2026 9.8
CVE-2026-15011 Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter 23.07.2026 9.8
CVE-2026-16723 Remote Code Execution in fastjson 1.2.68–1.2.83 23.07.2026 9
CVE-2026-60366 23.07.2026 10
CVE-2026-60367 23.07.2026 9.8
CVE-2026-60369 23.07.2026 9.9
CVE-2026-60372 23.07.2026 9.8
CVE-2026-13072 MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption 24.07.2026 9.2
CVE-2026-64829 Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow 24.07.2026 9.1
CVE-2026-40712 24.07.2026 9.1
CVE-2026-46738 24.07.2026 9.1
CVE-2026-16606 Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris 22.07.2026 9.3
CVE-2026-2395 SQLi in Xpoda Türkiye Informatics Technology's No Code Platform 22.07.2026 9.8
CVE-2026-63048 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 23.07.2026 9.4
CVE-2026-47731 NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker) 22.07.2026 9.1
CVE-2026-60328 23.07.2026 9.8
CVE-2026-60329 23.07.2026 9.8
CVE-2026-60333 24.07.2026 9.9
CVE-2026-60355 24.07.2026 9.8
CVE-2026-60358 24.07.2026 10
CVE-2026-60360 24.07.2026 10
CVE-2026-60361 24.07.2026 9.9
CVE-2026-60362 24.07.2026 9.8
CVE-2026-60363 24.07.2026 9.8
CVE-2026-60364 24.07.2026 9.8
CVE-2026-60365 24.07.2026 10
CVE-2026-60374 24.07.2026 9.8
CVE-2026-60375 24.07.2026 9.8
CVE-2026-60376 24.07.2026 9.8
CVE-2026-60377 24.07.2026 9.9
CVE-2026-60378 24.07.2026 9.8
CVE-2026-60379 24.07.2026 10
CVE-2026-60380 24.07.2026 9.8
CVE-2026-60381 24.07.2026 9.9
CVE-2026-60384 24.07.2026 9.8
CVE-2026-60385 24.07.2026 9.8
CVE-2026-60386 24.07.2026 9.8
CVE-2026-60387 24.07.2026 9.8
CVE-2026-60388 24.07.2026 9.8
CVE-2026-60389 24.07.2026 10
CVE-2026-60402 24.07.2026 9.9
CVE-2026-60422 24.07.2026 9.9
CVE-2026-60424 24.07.2026 9
CVE-2026-60429 24.07.2026 9.9
CVE-2026-60435 24.07.2026 9.8
CVE-2026-60438 24.07.2026 9.1
CVE-2026-60441 24.07.2026 9.8
CVE-2026-60442 24.07.2026 9.8
CVE-2026-60445 24.07.2026 9.9
CVE-2026-60446 24.07.2026 9.8
CVE-2026-60447 24.07.2026 9.9
CVE-2026-60456 24.07.2026 9.9
CVE-2026-60457 24.07.2026 9.9
CVE-2026-60458 24.07.2026 9.9
CVE-2026-60459 24.07.2026 9.9
CVE-2026-60460 24.07.2026 9.8
CVE-2026-60461 24.07.2026 9.9
CVE-2026-60463 24.07.2026 9.8
CVE-2026-60524 24.07.2026 9.9
CVE-2026-60531 27.07.2026 9.9
CVE-2026-60532 24.07.2026 9.8
CVE-2026-60535 24.07.2026 9.8
CVE-2026-60537 24.07.2026 9.9
CVE-2026-60538 24.07.2026 9.8
CVE-2026-60540 27.07.2026 9.6
CVE-2026-60541 27.07.2026 9.8
CVE-2026-60542 27.07.2026 9.9
CVE-2026-60547 27.07.2026 9.9
CVE-2026-60551 27.07.2026 9.8
CVE-2026-60552 27.07.2026 9.9
CVE-2026-60555 27.07.2026 9.8
CVE-2026-60561 27.07.2026 9.9
CVE-2026-60562 27.07.2026 9.9
CVE-2026-60564 27.07.2026 9.6
CVE-2026-60565 27.07.2026 9.9
CVE-2026-60566 27.07.2026 9.8
CVE-2026-60567 27.07.2026 9.1
CVE-2026-60568 27.07.2026 9.9
CVE-2026-60606 21.07.2026 9.1
CVE-2026-60627 25.07.2026 9.9
CVE-2026-60631 27.07.2026 9.3
CVE-2026-60632 27.07.2026 9.3
CVE-2026-60644 27.07.2026 10
CVE-2026-60649 27.07.2026 9.1
CVE-2026-60663 24.07.2026 9.9
CVE-2026-60711 25.07.2026 9.9
CVE-2026-60719 24.07.2026 9.9
CVE-2026-60773 24.07.2026 9.6
CVE-2026-60880 24.07.2026 9.8
CVE-2026-60999 24.07.2026 9.8
CVE-2026-61041 24.07.2026 9.9
CVE-2026-61059 24.07.2026 9.1
CVE-2026-61065 24.07.2026 9.8
CVE-2026-61072 24.07.2026 9.9
CVE-2026-61076 24.07.2026 9.9
CVE-2026-61097 23.07.2026 9.6
CVE-2026-61100 23.07.2026 9.8
CVE-2026-61129 23.07.2026 9.8
CVE-2026-61130 23.07.2026 9.1
CVE-2026-61131 23.07.2026 9.8
CVE-2026-61140 23.07.2026 9.8
CVE-2026-61145 23.07.2026 9.8
CVE-2026-61146 23.07.2026 9.9
CVE-2026-61153 23.07.2026 9.1
CVE-2026-61154 23.07.2026 9.8
CVE-2026-61155 23.07.2026 9.1
CVE-2026-61156 23.07.2026 9.1
CVE-2026-61161 23.07.2026 9.8
CVE-2026-61167 23.07.2026 9.8
CVE-2026-61171 23.07.2026 9.1
CVE-2026-61174 23.07.2026 9
CVE-2026-61175 23.07.2026 9.3
CVE-2026-61178 23.07.2026 9.8
CVE-2026-61183 23.07.2026 9.8
CVE-2026-61184 23.07.2026 9.1
CVE-2026-61186 23.07.2026 9.4
CVE-2026-61196 22.07.2026 9.8
CVE-2026-61197 22.07.2026 9.1
CVE-2026-61201 22.07.2026 9
CVE-2026-61203 22.07.2026 9.4
CVE-2026-61204 22.07.2026 9
CVE-2026-61207 22.07.2026 9.3
CVE-2026-61209 22.07.2026 9.9
CVE-2026-61211 22.07.2026 9.9
CVE-2026-61223 22.07.2026 9
CVE-2026-61233 22.07.2026 9.8
CVE-2026-61235 22.07.2026 9.1
CVE-2026-61237 22.07.2026 9.9
CVE-2026-61238 22.07.2026 9.1
CVE-2026-61239 22.07.2026 9.9
CVE-2026-61242 22.07.2026 9.9
CVE-2026-61244 22.07.2026 9.1
CVE-2026-61245 22.07.2026 9.8
CVE-2026-62546 22.07.2026 9.1
CVE-2026-62549 22.07.2026 9.6
CVE-2026-65318 Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader 22.07.2026 9.2
CVE-2026-35290 23.07.2026 9.8
CVE-2026-46876 23.07.2026 9.8
CVE-2026-46924 23.07.2026 9.8
CVE-2026-46982 23.07.2026 9.8
CVE-2026-46983 23.07.2026 9.8
CVE-2026-46989 23.07.2026 9.1
CVE-2026-46994 23.07.2026 9.8
CVE-2026-47036 25.07.2026 9.8
CVE-2026-47040 23.07.2026 9.1
CVE-2026-47056 23.07.2026 10
CVE-2026-60168 23.07.2026 9.1
CVE-2026-60173 23.07.2026 9.8
CVE-2026-60197 23.07.2026 9.8
CVE-2026-60198 23.07.2026 9.8
CVE-2026-60199 23.07.2026 9.8
CVE-2026-60200 23.07.2026 9.8
CVE-2026-60202 25.07.2026 9.8
CVE-2026-60204 25.07.2026 9.8
CVE-2026-60205 25.07.2026 9.8
CVE-2026-60206 25.07.2026 9.9
CVE-2026-60208 25.07.2026 9.1
CVE-2026-60209 23.07.2026 9.8
CVE-2026-60210 23.07.2026 9.8
CVE-2026-60212 23.07.2026 9.8
CVE-2026-60215 23.07.2026 9.8
CVE-2026-60216 23.07.2026 9.8
CVE-2026-60217 23.07.2026 10
CVE-2026-60219 23.07.2026 9.8
CVE-2026-60220 23.07.2026 9.3
CVE-2026-60221 23.07.2026 9.8
CVE-2026-60224 23.07.2026 9.8
CVE-2026-60225 23.07.2026 9.8
CVE-2026-60226 23.07.2026 9.8
CVE-2026-60227 23.07.2026 9.8
CVE-2026-60228 23.07.2026 9.8
CVE-2026-60229 23.07.2026 9.8
CVE-2026-60230 23.07.2026 9.8
CVE-2026-60232 23.07.2026 9.8
CVE-2026-60234 23.07.2026 9.8
CVE-2026-60236 23.07.2026 9.8
CVE-2026-60239 23.07.2026 9.6
CVE-2026-60240 23.07.2026 9.8
CVE-2026-60241 23.07.2026 9.8
CVE-2026-60242 23.07.2026 9.8
CVE-2026-60244 23.07.2026 9.8
CVE-2026-60246 23.07.2026 9.8
CVE-2026-60247 23.07.2026 9.8
CVE-2026-60248 23.07.2026 9.3
CVE-2026-60249 23.07.2026 9
CVE-2026-60250 23.07.2026 9.8
CVE-2026-60251 23.07.2026 9.8
CVE-2026-60253 23.07.2026 9.8
CVE-2026-60254 23.07.2026 9.8
CVE-2026-60256 23.07.2026 9.8
CVE-2026-60257 23.07.2026 9.8
CVE-2026-60258 23.07.2026 9.8
CVE-2026-60259 23.07.2026 9.8
CVE-2026-60262 23.07.2026 9.8
CVE-2026-60264 23.07.2026 9.8
CVE-2026-60267 23.07.2026 9.1
CVE-2026-60269 27.07.2026 9.8
CVE-2026-60272 23.07.2026 9.8
CVE-2026-60274 23.07.2026 9.8
CVE-2026-60275 23.07.2026 9.8
CVE-2026-60276 24.07.2026 9.8
CVE-2026-60278 23.07.2026 9.8
CVE-2026-60279 24.07.2026 9.8
CVE-2026-60280 23.07.2026 9.8
CVE-2026-60285 23.07.2026 9.8
CVE-2026-60286 23.07.2026 9.8
CVE-2026-60287 23.07.2026 9.8
CVE-2026-60288 23.07.2026 9.8
CVE-2026-60289 23.07.2026 9.8
CVE-2026-60290 23.07.2026 9.8
CVE-2026-60291 25.07.2026 9.8
CVE-2026-60292 25.07.2026 9.8
CVE-2026-60294 25.07.2026 9.8
CVE-2026-60296 21.07.2026 9.8
CVE-2026-60297 23.07.2026 9.8
CVE-2026-60298 23.07.2026 9.8
CVE-2026-60299 23.07.2026 9.8
CVE-2026-60300 23.07.2026 9.8
CVE-2026-60302 23.07.2026 9.8
CVE-2026-60306 23.07.2026 9.8
CVE-2026-60308 23.07.2026 9.8
CVE-2026-60326 23.07.2026 9.1
CVE-2026-65317 Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass 23.07.2026 9.2
CVE-2026-8984 Unauthenticated RCE 22.07.2026 10
CVE-2026-8985 Unauthenticated Command Injection 22.07.2026 10
CVE-2026-8986 Command Injection via Malicious OCPP Server 22.07.2026 9.5
CVE-2026-8987 Authenticated Heap Overflow 22.07.2026 9.4
CVE-2026-47708 MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper 22.07.2026 9.3
CVE-2026-65057 Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck 22.07.2026 9.2
CVE-2026-8982 Hard-coded / Backdoor Accounts 22.07.2026 10
CVE-2026-8983 Backdoor Authentication Token 22.07.2026 10
CVE-2026-64878 Command Injection 24.07.2026 9.4
CVE-2026-64879 Command Injection 24.07.2026 9.4
CVE-2016-20096 Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp 22.07.2026 9.3
CVE-2026-64877 24.07.2026 9.4
CVE-2026-47413 praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members 22.07.2026 9.6
CVE-2026-47416 praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id} 22.07.2026 9.6
CVE-2026-47407 PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation 22.07.2026 9.4
CVE-2026-47410 praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset 22.07.2026 9.8
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution 23.07.2026 9.8
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) 21.07.2026 9.9
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default 22.07.2026 9.8
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset 22.07.2026 9.8
CVE-2026-64824 Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore 21.07.2026 9.3
CVE-2026-64825 Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload 21.07.2026 9
CVE-2026-65048 Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index 22.07.2026 9.3
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData 22.07.2026 9.3
CVE-2026-1617 SQLi in Turkmesh's Turkhotspot 5651 Loglama 21.07.2026 9.8
CVE-2026-13439 Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint 21.07.2026 9.8
CVE-2026-64625 AVideo before 29.0 OS Command Injection via execAsync 23.07.2026 9.3
CVE-2026-13380 VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses 21.07.2026 9
CVE-2026-53595 FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL 21.07.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2025-50455 27.07.2026
CVE-2026-17529 AstrBotDevs AstrBot astr_main_agent.py authorization 27.07.2026
CVE-2026-17572 HDF5 SOHM List Index Heap Buffer Overflow 27.07.2026
CVE-2026-17573 Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field 27.07.2026
CVE-2026-17574 NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag 27.07.2026
CVE-2026-42792 epmd permanent DoS via EMFILE on accept(2) in erts 27.07.2026
CVE-2026-47078 Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass 27.07.2026
CVE-2026-51296 27.07.2026
CVE-2026-51297 27.07.2026
CVE-2026-51298 27.07.2026
CVE-2026-51300 27.07.2026
CVE-2026-51302 27.07.2026
CVE-2026-51303 27.07.2026
CVE-2026-51304 27.07.2026
CVE-2026-55737 Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder 27.07.2026
CVE-2026-55953 TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication 27.07.2026
CVE-2026-58227 TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain 27.07.2026
CVE-2026-59250 Megaco flex scanner buffer overflow via oversized property parm name 27.07.2026
CVE-2025-59172 Improper Neutralization of Special Elements used in an OS Command Vulnerability 27.07.2026
CVE-2025-59177 Generation of Error Message Containing Sensitive Information Vulnerability 27.07.2026
CVE-2025-59178 Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability 27.07.2026
CVE-2025-59180 Use of Hard-coded Credentials Vulnerability 27.07.2026
CVE-2025-59181 Path traversal Vulnerability 27.07.2026
CVE-2026-10600 Denial of service via unbounded document content extraction in Mattermost Server 27.07.2026 4.3
CVE-2026-10819 Mattermost Server Denial of Service via Animated GIF Emoji Upload 27.07.2026 6.5
CVE-2026-59527 WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59528 WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure vulnerability 27.07.2026 7.5
CVE-2026-59529 WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability 27.07.2026 7.5
CVE-2026-59530 WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vulnerability 27.07.2026 7.5
CVE-2026-59531 WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown vulnerability 27.07.2026 7.5
CVE-2026-59532 WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerability 27.07.2026 7.5
CVE-2026-59533 WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59534 WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability 27.07.2026 7.5
CVE-2026-59535 WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability 27.07.2026 7.3
CVE-2026-59536 WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerability 27.07.2026 7.5
CVE-2026-59537 WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.10.22 - SQL Injection vulnerability 27.07.2026 7.6
CVE-2026-59538 WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59539 WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object References (IDOR) vulnerability 27.07.2026 7.5
CVE-2026-59546 WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability 27.07.2026 7.4
CVE-2026-59548 WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vulnerability 27.07.2026 7.5
CVE-2026-59549 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59550 WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability 27.07.2026 9.3
CVE-2026-59551 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability 27.07.2026 8.5
CVE-2026-59552 WordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Request Forgery (SSRF) vulnerability 27.07.2026 7.2
CVE-2026-59553 WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) vulnerability 27.07.2026 7.1
CVE-2026-59556 WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.11 - Cross Site Scripting (XSS) vulnerability 27.07.2026 7.1
CVE-2026-59557 WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability 27.07.2026 6.5
CVE-2026-59558 WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vulnerability 27.07.2026 7.1
CVE-2026-59559 WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability 27.07.2026 6.5
CVE-2026-59560 WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability 27.07.2026 6.5
CVE-2026-65433 WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control vulnerability 27.07.2026 6.5
CVE-2026-65434 WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure vulnerability 27.07.2026 6.5
CVE-2026-65435 WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerability 27.07.2026 6.5
CVE-2026-65436 WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability 27.07.2026 6.8
CVE-2026-65557 WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Scripting (XSS) vulnerability 27.07.2026 5.9
CVE-2026-65558 WordPress AffiliateX plugin <= 2.3.5 - Server Side Request Forgery (SSRF) vulnerability 27.07.2026 5.4
CVE-2026-65561 WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability 27.07.2026 6.5
CVE-2026-65562 WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability 27.07.2026 6.5
CVE-2026-65563 WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability 27.07.2026 5.9
CVE-2026-65564 WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Exposure vulnerability 27.07.2026 5.3
CVE-2026-65567 WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability 27.07.2026 5.3
CVE-2026-65568 WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access Control vulnerability 27.07.2026 5
CVE-2026-66050 NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server 27.07.2026
CVE-2026-66427 WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability 27.07.2026 7.6
CVE-2026-66428 WordPress WP Google Review Slider plugin <= 18.4 - Cross Site Request Forgery (CSRF) vulnerability 27.07.2026 4.3
CVE-2026-66433 WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability 27.07.2026 6.5
CVE-2026-66434 WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.33 - Cross Site Scripting (XSS) vulnerability 27.07.2026 6.5
CVE-2026-66437 WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnerability 27.07.2026 4.9
CVE-2026-66438 WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposure vulnerability 27.07.2026 5.3
CVE-2026-66442 WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability 27.07.2026 5.4
CVE-2026-66445 WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnerability 27.07.2026 6.5
CVE-2026-66448 WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability 27.07.2026 6.5
CVE-2026-66474 WordPress Insert Headers and Footers Code – HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerability 27.07.2026 4.3
CVE-2026-66475 WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability 27.07.2026 5.9
CVE-2026-66476 WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability 27.07.2026 4.9
CVE-2026-66477 WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability 27.07.2026 5.3
CVE-2026-15003 Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service 27.07.2026
CVE-2026-17513 ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertion 27.07.2026
CVE-2026-17514 ZJONSSON node-unzipper extract.js Extract path traversal 27.07.2026
CVE-2026-61511 vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php 27.07.2026
CVE-2026-65766 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 27.07.2026
CVE-2026-65876 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 27.07.2026
CVE-2026-65877 Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 27.07.2026
CVE-2026-65878 Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1 27.07.2026
CVE-2026-65879 Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 27.07.2026
CVE-2026-12989 Multiple vulnerabilities in Ghost Robotics' Vision 60 27.07.2026
CVE-2026-12990 Multiple vulnerabilities in Ghost Robotics' Vision 60 27.07.2026
CVE-2026-12991 Multiple vulnerabilities in Ghost Robotics' Vision 60 27.07.2026
CVE-2026-17512 ggml-org whisper.cpp log_mel_spectrogram out-of-bounds 27.07.2026
CVE-2026-56537 HCL Connections is vulnerable to information disclosure 27.07.2026 3.5
CVE-2026-56538 HCL Connections is vulnerable to information disclosure 27.07.2026 3.5
CVE-2026-59686 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface 27.07.2026 8.4
CVE-2026-59687 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface 27.07.2026 8.4
CVE-2026-59688 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality 27.07.2026 8.4
CVE-2026-59689 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root 27.07.2026 8
CVE-2026-59690 Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API 27.07.2026 8
CVE-2026-12495 Stack-Based Buffer Overflow in the Mercusys MB115-4G 27.07.2026
CVE-2026-14856 Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager 27.07.2026
CVE-2026-41608 Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport 27.07.2026
CVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit 27.07.2026
CVE-2026-45112 Apache Thrift: Unbounded Read Leading to Denial of Service 27.07.2026
CVE-2026-48144 Apache Thrift: c_glib TLS Client Missing Hostname Verification 27.07.2026
CVE-2026-48145 Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass 27.07.2026
CVE-2026-48586 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit 27.07.2026
CVE-2026-49158 Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb 27.07.2026 7.5
CVE-2026-55968 Apache Thrift: Node.js quadratic-time DoS in server receive transports 27.07.2026
CVE-2026-55969 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable() 27.07.2026
CVE-2026-55970 Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat() 27.07.2026
CVE-2026-55971 Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform() 27.07.2026
CVE-2026-57916 Arbitrary Path Execution via CPS URI in proCertum SmartSign 27.07.2026
CVE-2026-57917 Improper Restriction of XML External Entity Reference in proCertum SmartSign 27.07.2026
CVE-2026-58023 Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path 27.07.2026
CVE-2026-58389 Apache Thrift: Rust binary protocol non-strict path missing string size limit 27.07.2026
CVE-2026-58662 Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass 27.07.2026
CVE-2026-66053 Apache Thrift: Python TSSLSocket Hostname Matcher Import 27.07.2026 5.9
CVE-2026-17523 Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges 27.07.2026
CVE-2026-17527 Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone 27.07.2026
CVE-2026-17534 Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and redirects 27.07.2026 5.5
CVE-2026-40000 Path Traversal Vulnerability in ZTE Blade A75 Pro 5G 27.07.2026 1.8
CVE-2026-15799 27.07.2026
CVE-2026-16554 Integer Overflow Leading to Heap Buffer Overflow in cJSON 27.07.2026
CVE-2026-65764 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.1.1 27.07.2026
CVE-2026-65765 Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.1 27.07.2026
CVE-2026-14837 SSH Enablement Signature Verification Bypass 27.07.2026
CVE-2026-64531 net: openvswitch: reject oversized nested action attrs 27.07.2026
CVE-2026-64532 fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} 27.07.2026
CVE-2026-64533 fs/ntfs3: validate lcns_follow in log_replay conversion 27.07.2026
CVE-2026-64534 nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path 27.07.2026
CVE-2026-64535 nvmet-tcp: Fix potential UAF when ddgst mismatch 27.07.2026
CVE-2026-64536 staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop 27.07.2026
CVE-2026-65893 Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera 27.07.2026
CVE-2026-65894 Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera 27.07.2026
CVE-2025-15662 Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery 27.07.2026
CVE-2026-10082 Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter 27.07.2026
CVE-2026-12255 MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration 27.07.2026
CVE-2026-12394 MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator 27.07.2026
CVE-2026-12493 Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order 27.07.2026
CVE-2026-12982 Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery 27.07.2026
CVE-2026-13152 Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation 27.07.2026
CVE-2026-13332 Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service) 27.07.2026
CVE-2026-13390 The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation 27.07.2026
CVE-2026-13400 Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information 27.07.2026
CVE-2026-13597 QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover 27.07.2026
CVE-2026-13714 Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution 27.07.2026
CVE-2026-13726 Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode 27.07.2026
CVE-2026-14189 WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields 27.07.2026
CVE-2026-14190 Sina Extension for Elementor < 3.10.2 - Reflected XSS 27.07.2026
CVE-2026-14203 Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title 27.07.2026
CVE-2026-14235 WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key 27.07.2026
CVE-2026-14236 Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect 27.07.2026
CVE-2026-14289 WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution 27.07.2026
CVE-2026-14568 WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion 27.07.2026
CVE-2026-14820 Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login 27.07.2026
CVE-2026-14827 Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter 27.07.2026
CVE-2026-66412 Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC 27.07.2026
CVE-2026-9830 BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug 27.07.2026
CVE-2026-15928 27.07.2026
CVE-2026-17500 ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference 27.07.2026
CVE-2026-17501 ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform allocation of resources 27.07.2026