| CVE-2022-4995 |
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp |
07.08.2026 |
9.3 |
| CVE-2026-19264 |
Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover |
07.08.2026 |
9.3 |
| CVE-2026-66914 |
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 |
07.08.2026 |
9.2 |
| CVE-2026-54203 |
TeamDavid: Memory Leak leaking sensitive information |
07.08.2026 |
9.2 |
| CVE-2026-54210 |
TeamDavid: Buffer Overflow in file names of file upload functionalities |
07.08.2026 |
9.5 |
| CVE-2026-54211 |
TeamDavid: Buffer Overflow in multiple form data parameters |
07.08.2026 |
9.5 |
| CVE-2026-54212 |
TeamDavid: Buffer Overflow in JSON-parsing |
07.08.2026 |
9.5 |
| CVE-2026-54213 |
TeamDavid: Denial of Service via endpoint 'internalRestart' |
07.08.2026 |
9.2 |
| CVE-2026-14364 |
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' |
07.08.2026 |
9.8 |
| CVE-2026-14365 |
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' |
07.08.2026 |
9.8 |
| CVE-2026-50481 |
Azure Active Directory Elevation of Privilege Vulnerability |
07.08.2026 |
9.9 |
| CVE-2026-50515 |
Azure Service Bus Remote Code Execution Vulnerability |
07.08.2026 |
9.9 |
| CVE-2026-56161 |
Azure Logic Apps Information Disclosure Vulnerability |
07.08.2026 |
9.6 |
| CVE-2026-56162 |
Azure SQL Database Elevation of Privilege Vulnerability |
07.08.2026 |
10 |
| CVE-2026-59115 |
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability |
07.08.2026 |
9.9 |
| CVE-2026-59118 |
Microsoft Power Apps Elevation of Privilege Vulnerability |
07.08.2026 |
9.3 |
| CVE-2026-62830 |
Azure SRE Agent Elevation of Privilege Vulnerability |
07.08.2026 |
9.9 |
| CVE-2026-62873 |
Microsoft 365 Admin Center Elevation of Privilege Vulnerability |
07.08.2026 |
9.8 |
| CVE-2026-62896 |
Microsoft Teams Elevation of Privilege Vulnerability |
07.08.2026 |
9.6 |
| CVE-2026-63508 |
Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability |
07.08.2026 |
10 |
| CVE-2026-65667 |
Microsoft Teams Elevation of Privilege Vulnerability |
07.08.2026 |
10 |
| CVE-2026-68823 |
Azure Confidential Ledger Remote Code Execution Vulnerability |
07.08.2026 |
9.1 |
| CVE-2026-70332 |
Microsoft Office SharePoint Spoofing Vulnerability |
07.08.2026 |
9.6 |
| CVE-2025-14561 |
Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations |
06.08.2026 |
9 |
| CVE-2026-11976 |
MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise |
07.08.2026 |
10 |
| CVE-2026-14812 |
Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) |
07.08.2026 |
10 |
| CVE-2026-17032 |
Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server |
07.08.2026 |
9.8 |
| CVE-2026-18367 |
|
07.08.2026 |
9.3 |
| CVE-2026-3418 |
Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution |
06.08.2026 |
9.1 |
| CVE-2026-43629 |
llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore |
06.08.2026 |
9.2 |
| CVE-2026-43631 |
llama.cpp b7492–b9060 Use-After-Free RCE via llama-server |
07.08.2026 |
9.2 |
| CVE-2026-43632 |
llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints |
06.08.2026 |
9.2 |
| CVE-2026-48085 |
OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap |
06.08.2026 |
9.8 |
| CVE-2026-48086 |
OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN |
07.08.2026 |
9.9 |
| CVE-2026-48087 |
OpenReception: WebAuthn passkey injection allows account takeover |
06.08.2026 |
9.8 |
| CVE-2026-48088 |
OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory |
06.08.2026 |
9.4 |
| CVE-2026-53983 |
Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL |
07.08.2026 |
9.2 |
| CVE-2026-5857 |
Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments |
06.08.2026 |
9.2 |
| CVE-2026-70558 |
Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token |
06.08.2026 |
9.3 |
| CVE-2026-28005 |
WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-28139 |
WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-53975 |
OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec |
06.08.2026 |
9.3 |
| CVE-2026-53976 |
OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter |
06.08.2026 |
9.3 |
| CVE-2026-54489 |
|
06.08.2026 |
9.1 |
| CVE-2026-65507 |
WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65508 |
WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-65520 |
WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-65546 |
WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-65548 |
WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability |
06.08.2026 |
9.9 |
| CVE-2026-65552 |
WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65553 |
WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability |
06.08.2026 |
10 |
| CVE-2026-65556 |
WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65571 |
WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65572 |
WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65573 |
WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65574 |
WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65575 |
WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65576 |
WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65577 |
WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65578 |
WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65579 |
WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-65581 |
WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-66447 |
WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability |
06.08.2026 |
9.3 |
| CVE-2026-66662 |
WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability |
06.08.2026 |
9.8 |
| CVE-2026-66665 |
WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability |
06.08.2026 |
10 |
| CVE-2026-66709 |
WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability |
06.08.2026 |
9.1 |
| CVE-2026-67261 |
|
06.08.2026 |
9.8 |
| CVE-2026-12605 |
|
06.08.2026 |
9.6 |
| CVE-2026-5134 |
SQLi in Loca Software's CMS |
06.08.2026 |
9.8 |
| CVE-2025-15039 |
Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products |
06.08.2026 |
9.4 |
| CVE-2026-1728 |
Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover |
06.08.2026 |
9.8 |
| CVE-2026-5430 |
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover |
06.08.2026 |
10 |
| CVE-2026-67531 |
FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool |
06.08.2026 |
9.3 |
| CVE-2026-71319 |
Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution |
07.08.2026 |
9.6 |
| CVE-2026-48168 |
PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name |
05.08.2026 |
10 |
| CVE-2026-20267 |
Cisco IOS XE Software Security Hardening Release |
06.08.2026 |
9 |
| CVE-2026-20272 |
Cisco IOS XE Software Security Hardening Release |
06.08.2026 |
9.8 |
| CVE-2026-20303 |
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities |
06.08.2026 |
9.9 |
| CVE-2026-20304 |
Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities |
06.08.2026 |
9.9 |
| CVE-2026-20310 |
Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access |
06.08.2026 |
9.1 |
| CVE-2026-7329 |
Privilege escalation in Progress MarkLogic Server REST query interfaces |
07.08.2026 |
9.9 |
| CVE-2026-7557 |
SAML authentication bypass in Progress MarkLogic Server |
07.08.2026 |
9.1 |
| CVE-2026-8709 |
Privilege escalation in Progress MarkLogic Server REST document patch operation |
07.08.2026 |
9.9 |
| CVE-2026-9190 |
HTTP request smuggling in Progress MarkLogic Server |
07.08.2026 |
9.1 |
| CVE-2026-9192 |
Authentication bypass in Progress MarkLogic Server ODBC App Server |
07.08.2026 |
9.8 |
| CVE-2026-9193 |
Privilege escalation in Progress MarkLogic Server Hadoop integration |
07.08.2026 |
9.9 |
| CVE-2026-9195 |
Cross-site scripting in Progress MarkLogic Server Query Console |
05.08.2026 |
9.3 |
| CVE-2026-15587 |
Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header |
05.08.2026 |
9.4 |
| CVE-2026-39923 |
Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset |
05.08.2026 |
9.2 |
| CVE-2026-71262 |
IoTSharp BlobStorageController Missing Authentication and Path Traversal |
05.08.2026 |
9.8 |
| CVE-2026-71263 |
FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() |
05.08.2026 |
9.1 |
| CVE-2026-71267 |
microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() |
05.08.2026 |
9.8 |
| CVE-2026-71268 |
OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write |
05.08.2026 |
9.9 |
| CVE-2026-71277 |
rust-iot-platform Authentication Bypass via Non-Validated Authorization Header |
05.08.2026 |
9.1 |
| CVE-2026-71278 |
rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation |
05.08.2026 |
9.8 |
| CVE-2026-71289 |
NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API |
05.08.2026 |
9.8 |
| CVE-2026-71254 |
nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() |
05.08.2026 |
9.8 |
| CVE-2026-71256 |
nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id |
05.08.2026 |
9.8 |
| CVE-2026-66747 |
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant |
05.08.2026 |
9.3 |
| CVE-2026-71231 |
IOTSmartHome: Unauthenticated SQL Injection via lastLogin Cookie |
05.08.2026 |
9.8 |
| CVE-2026-71237 |
Miantang IoT-PHP: Unauthenticated SQL Injection in /userlogin |
05.08.2026 |
9.8 |
| CVE-2026-71238 |
DjangoCRM: Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery |
05.08.2026 |
9.1 |
| CVE-2026-71248 |
Inventory-Management-System-PHP: Unauthenticated SQL Injection in Login and Product Deletion |
05.08.2026 |
9.8 |
| CVE-2026-44945 |
Cross-Cluster Impersonation Confused-Deputy Privilege Escalation |
06.08.2026 |
9.1 |
| CVE-2026-10059 |
Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token |
05.08.2026 |
9.1 |
| CVE-2026-10090 |
Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription |
05.08.2026 |
9.9 |
| CVE-2026-4431 |
Easy Post Submission <= 2.3.0 - Missing Authorization |
05.08.2026 |
9.1 |
| CVE-2026-5581 |
Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion |
05.08.2026 |
9.1 |
| CVE-2026-70376 |
Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE |
05.08.2026 |
9.6 |
| CVE-2026-71207 |
Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass |
05.08.2026 |
9.8 |
| CVE-2026-71213 |
typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force |
05.08.2026 |
9.1 |
| CVE-2026-71214 |
NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server |
05.08.2026 |
9.8 |
| CVE-2026-9273 |
Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover |
05.08.2026 |
9.3 |
| CVE-2026-45537 |
OpenSIPS: Global Buffer Overflow in construct_uri |
05.08.2026 |
9.1 |
| CVE-2026-45100 |
OpenSIPS: Buffer Overflow in Base64 Encode Transformation |
05.08.2026 |
9.1 |
| CVE-2026-45538 |
OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
05.08.2026 |
9.8 |
| CVE-2026-70554 |
MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie |
05.08.2026 |
9.3 |
| CVE-2026-70477 |
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability |
05.08.2026 |
9.5 |
| CVE-2026-70478 |
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service |
05.08.2026 |
9.2 |
| CVE-2026-70552 |
MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php |
05.08.2026 |
9.3 |
| CVE-2026-70553 |
MaxSite CMS Unauthenticated RCE via Install Endpoint |
05.08.2026 |
9.3 |
| CVE-2017-20241 |
Keysight IxChariot Endpoint heap-based buffer overflow |
04.08.2026 |
9.3 |
| CVE-2017-20242 |
Keysight IxChariot Endpoint stack-based buffer overflow |
04.08.2026 |
9.3 |
| CVE-2026-49435 |
Keysight IxChariot-related products stack-based buffer overflow |
04.08.2026 |
9.3 |
| CVE-2026-69703 |
Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit |
04.08.2026 |
9.3 |
| CVE-2026-24254 |
|
04.08.2026 |
9.8 |
| CVE-2026-69264 |
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation |
04.08.2026 |
9.4 |
| CVE-2026-70470 |
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE |
04.08.2026 |
9.5 |
| CVE-2026-63455 |
Authentication bypass via spoofed HTTP headers Orchestrator REST API |
04.08.2026 |
9.8 |
| CVE-2026-63456 |
Authentication bypass via spoofed HTTP headers Orchestrator REST API |
04.08.2026 |
9.8 |
| CVE-2026-58072 |
|
05.08.2026 |
9 |
| CVE-2026-58073 |
|
05.08.2026 |
9.5 |
| CVE-2026-64633 |
|
05.08.2026 |
10 |
| CVE-2026-69255 |
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified |
04.08.2026 |
9.2 |
| CVE-2026-69256 |
Flowise: Remote Code Execution Vulnerability in CSVAgent |
05.08.2026 |
9.4 |
| CVE-2026-69259 |
Flowise RCE via SQLite Record Manager Node |
04.08.2026 |
9.4 |
| CVE-2026-18801 |
Stored Clickhouse SQL Injection Through Customer Usage Attribution |
04.08.2026 |
9.3 |
| CVE-2026-25289 |
Stack-based Buffer Overflow in WLAN Firmware |
05.08.2026 |
9.6 |
| CVE-2026-69098 |
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization |
05.08.2026 |
9.3 |
| CVE-2026-69110 |
OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music |
04.08.2026 |
9.3 |
| CVE-2026-69253 |
Flowise Sandbox Escape to RCE |
05.08.2026 |
9 |
| CVE-2026-69254 |
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override |
04.08.2026 |
9.4 |
| CVE-2026-61514 |
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 |
04.08.2026 |
9.3 |
| CVE-2026-61515 |
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell |
05.08.2026 |
9.3 |
| CVE-2026-69251 |
Flowise RCE via TypeORM DataSource |
04.08.2026 |
9 |
| CVE-2026-60007 |
|
04.08.2026 |
9.1 |
| CVE-2026-14175 |
Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
9.8 |
| CVE-2026-14804 |
Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
9.1 |
| CVE-2026-15721 |
Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources |
04.08.2026 |
9.8 |
| CVE-2026-18753 |
Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) |
04.08.2026 |
9.1 |
| CVE-2026-18754 |
Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) |
04.08.2026 |
9.1 |
| CVE-2026-18686 |
GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection |
04.08.2026 |
9.3 |
| CVE-2026-18685 |
GL.iNet GL-MT3000 modem.so glc set_upgrade command injection |
04.08.2026 |
9.3 |
| CVE-2026-18684 |
GL.iNet GL-MT3000 modem.so glc remove_profile command injection |
04.08.2026 |
9.3 |
| CVE-2026-48317 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) |
04.08.2026 |
9.6 |
| CVE-2026-48323 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) |
04.08.2026 |
10 |
| CVE-2026-48326 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
04.08.2026 |
9.9 |
| CVE-2026-48330 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
05.08.2026 |
10 |
| CVE-2026-48331 |
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
04.08.2026 |
10 |
| CVE-2026-48333 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
04.08.2026 |
9.8 |
| CVE-2026-18667 |
Sensor Proxy Version 1.4.2 Fixes One Vulnerability |
05.08.2026 |
9.3 |
| CVE-2026-46713 |
Misskey: JSON-LD signature validation + compaction may lead to improper activity handling |
04.08.2026 |
9.2 |
| CVE-2026-48063 |
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload |
04.08.2026 |
9.3 |
| CVE-2026-69240 |
Sequelize: SQL Injection (Oracle DB) |
04.08.2026 |
9.8 |
| CVE-2026-48031 |
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery |
03.08.2026 |
9.1 |
| CVE-2026-67598 |
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php |
04.08.2026 |
9.1 |
| CVE-2026-18616 |
GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection |
04.08.2026 |
9.3 |
| CVE-2026-18614 |
GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection |
03.08.2026 |
9.3 |
| CVE-2026-18615 |
GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection |
03.08.2026 |
9.3 |
| CVE-2026-18612 |
GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection |
03.08.2026 |
9.3 |
| CVE-2026-18613 |
GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection |
03.08.2026 |
9.3 |
| CVE-2026-18602 |
GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection |
03.08.2026 |
9.3 |
| CVE-2026-39932 |
OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection |
03.08.2026 |
9.4 |
| CVE-2026-41452 |
Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup |
03.08.2026 |
9.3 |
| CVE-2026-18248 |
@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header |
03.08.2026 |
9.1 |
| CVE-2026-18601 |
GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection |
03.08.2026 |
9.3 |
| CVE-2026-64827 |
Telenia TVox 26.5.3 Authentication Bypass via set_env.php |
07.08.2026 |
9.3 |
| CVE-2026-68584 |
SiYuan before v3.7.3 Authentication Bypass via Content Endpoints |
03.08.2026 |
9.2 |
| CVE-2026-68586 |
SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc |
03.08.2026 |
9.2 |
| CVE-2026-68587 |
SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction |
03.08.2026 |
9.2 |
| CVE-2026-69083 |
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent |
03.08.2026 |
9.9 |
| CVE-2026-69084 |
SiYuan before v3.7.3 SQL Injection via searchEmbedBlock |
03.08.2026 |
9.9 |
| CVE-2026-69085 |
SiYuan before v3.7.3 SQL Injection via searchDocs |
03.08.2026 |
9.9 |
| CVE-2026-18574 |
Authentication Bypass in Check Point Security Management Server |
05.08.2026 |
9.3 |
| CVE-2026-2346 |
IDOR in Menulux Software's Mobile App |
03.08.2026 |
9.8 |
| CVE-2026-33591 |
Authentication bypass on WaptServer |
03.08.2026 |
10 |
| CVE-2026-18588 |
Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow |
03.08.2026 |
9.3 |
| CVE-2026-18589 |
Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow |
03.08.2026 |
9.3 |
| CVE-2026-58062 |
Stapled OCSP response accepted without binding to the checked certificate |
03.08.2026 |
9.3 |
| CVE-2026-59638 |
JSSE hostname verifier CN-fallback enabled by default despite documented opt-in |
03.08.2026 |
9.3 |
| CVE-2026-59650 |
MTI/A0 DH agreement exponentiates unvalidated peer value |
03.08.2026 |
9.3 |
| CVE-2026-8763 |
Name Constraints bypass via trailing dot in rfc822Name and URI |
03.08.2026 |
9.3 |
| CVE-2026-65321 |
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS |
06.08.2026 |
9.3 |
| CVE-2025-71401 |
better-auth before 1.4.2 basePath Modification DoS |
03.08.2026 |
9.3 |
| CVE-2026-68582 |
Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token |
03.08.2026 |
9.3 |
| CVE-2026-8457 |
WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT |
03.08.2026 |
9.8 |
| CVE-2026-66402 |
FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass |
05.08.2026 |
9.3 |
| CVE-2026-67289 |
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection |
05.08.2026 |
9.3 |
| CVE-2026-67292 |
FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure |
03.08.2026 |
9.3 |
| CVE-2026-67293 |
FreeRDP before 3.29.0 Improper Certificate Hostname Validation |
05.08.2026 |
9.3 |
| CVE-2026-67294 |
FreeRDP before 3.29.0 TLS Certificate EKU Bypass |
03.08.2026 |
9.3 |
| CVE-2026-67305 |
FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr |
05.08.2026 |
9.4 |
| CVE-2026-67308 |
Wazuh GitHub Actions Shell Injection via Fork Pull Request |
03.08.2026 |
9.3 |
| CVE-2026-67324 |
GitPython 3.1.50 Authentication Bypass via Joined Short Options |
05.08.2026 |
9.3 |
| CVE-2026-67330 |
better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision |
03.08.2026 |
9.4 |
| CVE-2026-67336 |
better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider |
03.08.2026 |
9.4 |
| CVE-2026-67340 |
ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts |
03.08.2026 |
9.3 |
| CVE-2026-67341 |
ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION |
03.08.2026 |
9.3 |
| CVE-2026-67342 |
ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers |
03.08.2026 |
9.3 |
| CVE-2026-15964 |
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change |
03.08.2026 |
9.8 |
| CVE-2026-3141 |
FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter |
03.08.2026 |
9.1 |