CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-54569 SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core 26.08.2026 9.8
CVE-2026-80428 ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint 26.08.2026 9.3
CVE-2026-81032 NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration 26.08.2026 9.3
CVE-2026-75062 Eval Injection in google/langfun via default lf.query protocol 26.08.2026 9.2
CVE-2026-54523 Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system 26.08.2026 9.6
CVE-2026-75896 Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk 26.08.2026 9.1
CVE-2026-12717 Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection 26.08.2026 9.4
CVE-2026-18080 ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment 26.08.2026 9.8
CVE-2026-77532 26.08.2026 9.6
CVE-2026-77554 26.08.2026 10
CVE-2026-77557 26.08.2026 9.8
CVE-2026-77549 26.08.2026 9
CVE-2026-77550 26.08.2026 10
CVE-2026-77551 26.08.2026 9
CVE-2026-77552 26.08.2026 9.8
CVE-2026-77553 26.08.2026 9.9
CVE-2026-77546 26.08.2026 9.9
CVE-2026-77547 26.08.2026 9.9
CVE-2026-77548 26.08.2026 9.9
CVE-2026-80203 Grav before 1.0.18 Authentication Bypass via Scoped API Key 26.08.2026 9.3
CVE-2026-80204 Grav before 1.0.18 Authentication Bypass via Scoped API Key 26.08.2026 9.3
CVE-2026-77542 26.08.2026 9.1
CVE-2026-77543 26.08.2026 9.9
CVE-2026-77545 26.08.2026 9
CVE-2026-80349 TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter 26.08.2026 9.3
CVE-2026-77539 26.08.2026 9.1
CVE-2026-77540 26.08.2026 9.1
CVE-2026-77541 26.08.2026 9.1
CVE-2026-59683 OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings 26.08.2026 9.3
CVE-2026-77535 26.08.2026 9.1
CVE-2026-77536 26.08.2026 9.9
CVE-2026-77537 26.08.2026 10
CVE-2026-77534 26.08.2026 9.9
CVE-2026-77533 26.08.2026 9.9
CVE-2026-80235 Thinking Software Technology|EFence - Arbitrary File Upload 26.08.2026 9.3
CVE-2026-18431 Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write 26.08.2026 9.8
CVE-2026-15203 Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software 26.08.2026 9.3
CVE-2026-19632 TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure 26.08.2026 9.8
CVE-2026-80202 Kimai before 2.56.0 Authorization Bypass via TimesheetVoter 26.08.2026 9.3
CVE-2026-79911 TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow 25.08.2026 10
CVE-2026-80138 ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter 26.08.2026 9.2
CVE-2026-62862 TypeBot: Account takeover via brute-forceable 6-digit magic-link code 26.08.2026 9.1
CVE-2026-65083 25.08.2026 9.9
CVE-2026-65093 26.08.2026 9.9
CVE-2026-80104 DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename 25.08.2026 9.3
CVE-2026-45018 Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution 25.08.2026 9.8
CVE-2026-78379 Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools 25.08.2026 9.2
CVE-2026-79787 Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature 25.08.2026 9.3
CVE-2026-76193 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 25.08.2026 10
CVE-2026-76195 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 25.08.2026 10
CVE-2026-76197 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 25.08.2026 10
CVE-2026-55640 Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) 25.08.2026 9.1
CVE-2022-51000 Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxslt 25.08.2026 9.3
CVE-2024-58377 Nokogiri before 1.16.5 libxml2 Dependency Update 25.08.2026 9.3
CVE-2024-58378 Nokogiri before 1.16.2 Use-After-Free via xmlTextReader 25.08.2026 9.3
CVE-2025-71407 Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free 25.08.2026 9.3
CVE-2026-55536 Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) 25.08.2026 9.1
CVE-2026-55546 QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input 25.08.2026 9.8
CVE-2026-79675 NLTK before 3.10.3 JVM Argument Injection via Per-Call Options 26.08.2026 9.3
CVE-2026-79774 Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy 25.08.2026 9.3
CVE-2026-79782 rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect 25.08.2026 9.3
CVE-2026-16286 File Upload in TRTEK Software's Software Repository Management 25.08.2026 9.8
CVE-2026-77998 Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 26.08.2026 10
CVE-2026-57909 WatchGuard Agent path traversal allows unauthenticated remote code execution 26.08.2026 9.4
CVE-2026-57910 WatchGuard Agent improper authentication allows unauthenticated remote code execution 25.08.2026 9.3
CVE-2026-79657 NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization 25.08.2026 9.3
CVE-2026-79664 Ech0 before 4.7.3 Access Token Revocation Bypass 25.08.2026 9.1
CVE-2026-78570 Total Donations <= 2.0.5 - Unauthenticated Privilege Escalation 25.08.2026 9.8
CVE-2026-63586 Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface 25.08.2026 9.3
CVE-2026-77136 Server-Side Template Injection in extension "powermail" (powermail) 25.08.2026 9.5
CVE-2026-77138 Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail) 25.08.2026 9.3
CVE-2026-78568 Total Donations <= 2.0.5 - Unauthenticated SQL Injection 25.08.2026 9.8
CVE-2026-78477 Jawn <= 1.4.2 - Unauthenticated Privilege Escalation 25.08.2026 9.8
CVE-2026-13214 Stack buffer overflow in OCPP GetConfiguration key parsing 25.08.2026 9.8
CVE-2026-56705 Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection 25.08.2026 9.3
CVE-2026-56710 Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock 25.08.2026 9.3
CVE-2026-72699 Grav Login Plugin before 3.9.1 Email Enumeration via Registration 25.08.2026 9.3
CVE-2026-72702 Grav CMS before 2.0.16 Origin Validation Bypass via Referer 25.08.2026 9.3
CVE-2026-78676 GitPython before 3.1.59 Remote Code Execution via Config Injection 25.08.2026 9.3
CVE-2026-78683 NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization 25.08.2026 9.4
CVE-2026-32554 WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability 25.08.2026 9.3
CVE-2026-32555 WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability 25.08.2026 9.3
CVE-2026-32559 WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability 25.08.2026 9.9
CVE-2026-32563 WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability 25.08.2026 9.8
CVE-2026-77337 CakePHP: Potential Authentication bypass with CookieAuthenticator 25.08.2026 9.1
CVE-2026-78262 WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability 24.08.2026 9.8
CVE-2026-78265 WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability 25.08.2026 9.8
CVE-2026-78267 WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-77635 CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver 25.08.2026 9.2
CVE-2026-78555 RansomLook API Key Disclosure Through /admin/apikeys HTML Source 24.08.2026 9.4
CVE-2026-39975 Combodo iTop: Remote code execution using external auth variable value 24.08.2026 9.4
CVE-2026-76835 OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy Set 24.08.2026 9.3
CVE-2026-71914 DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm 24.08.2026 9.3
CVE-2026-71921 DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi 24.08.2026 9.3
CVE-2025-36939 24.08.2026 10
CVE-2026-77915 rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php 25.08.2026 9.3
CVE-2026-76070 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter 24.08.2026 9.3
CVE-2026-76071 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter 24.08.2026 9.3
CVE-2026-78387 RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification 24.08.2026 9.4
CVE-2026-59568 Remote Code Execution 25.08.2026 9.1
CVE-2026-67602 phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache 24.08.2026 9.3
CVE-2026-59564 Authentication bypass between ZCC and client connector portal 25.08.2026 9.1
CVE-2026-77995 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 25.08.2026 10
CVE-2026-78370 RansomLook Unauthenticated Database Export Exposes Private Data 24.08.2026 9.2
CVE-2026-78372 RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data 24.08.2026 9.2
CVE-2026-78365 IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification 24.08.2026 9.3
CVE-2026-28165 WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-32551 WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability 24.08.2026 9.3
CVE-2026-32558 WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66587 WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability 24.08.2026 9.8
CVE-2026-66648 WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66650 WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability 24.08.2026 9.8
CVE-2026-66897 Instance template path traversal allows arbitrary host file write as root 25.08.2026 9.9
CVE-2026-77994 Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 25.08.2026 9.3
CVE-2026-78251 DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory 24.08.2026 9.3
CVE-2026-78211 4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection 24.08.2026 9.3
CVE-2026-78168 EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication 24.08.2026 9.3
CVE-2026-78169 UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow 24.08.2026 9.4
CVE-2026-78167 EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication 24.08.2026 10
CVE-2026-78207 exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization 24.08.2026 9.3
CVE-2026-5388 justhtml before 1.15.0 Multiple Security Issues 23.08.2026 9.3
CVE-2026-7808 justhtml before 1.16.0 Multiple Security Issues via Sanitization 24.08.2026 9.3
CVE-2026-8445 justhtml before 1.12.0 Sanitizer Bypass via Markdown 24.08.2026 9.3
CVE-2026-78155 Untrusted Search Path in StackGres 24.08.2026 9.9
CVE-2026-78050 Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow 24.08.2026 9.4
CVE-2026-4703 WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission 24.08.2026 9.8
CVE-2026-74586 sctp: clear new_transport when removing a peer 25.08.2026 9.8
CVE-2026-74587 sctp: fix use-after-free of cached ASCONF chunk 25.08.2026 9.8
CVE-2026-74588 sctp: keep chunk->transport in step with the list it is queued on 25.08.2026 9.8
CVE-2026-74591 mm/filemap: __filemap_add_folio() restore index before retrying 25.08.2026 9.8
CVE-2026-74597 ip6_tunnel: clear skb2->cb[] in ip6ip6_err() 25.08.2026 9.8
CVE-2026-74608 smb: client: Fix use-after-free in cifs_try_adding_channels() 25.08.2026 9.8
CVE-2026-74611 tls: rx: restore msg_iter before TLS 1.3 optimistic retry 25.08.2026 9.8
CVE-2026-74612 veth: fix skb length accounting after XDP frag adjustment 25.08.2026 10
CVE-2026-74616 xdp: reject clones that overrun skb_shared_info tailroom 25.08.2026 9.8
CVE-2026-74617 dibs: initialise dibs->lock in dibs_dev_alloc() 25.08.2026 9.8
CVE-2026-74628 net/x25: fix use-after-free of the socket by its timers 25.08.2026 9.8
CVE-2026-74662 inet: frags: publish queues before arming timer 25.08.2026 9.8
CVE-2026-74665 net: fix skb length accounting after generic XDP frag adjustment 25.08.2026 9.1
CVE-2026-74669 ipvs: clear IPv4 options after rebasing tunnel ICMP errors 25.08.2026 9.8
CVE-2026-74688 sctp: clear control chunk transport if it is being removed 25.08.2026 9.8
CVE-2026-74705 udp: fix potential use-after-free in tunnel segmentation 25.08.2026 10
CVE-2026-74712 vdpa/mlx5: Fix buffer length in create_direct_keys() 25.08.2026 9.3
CVE-2026-74723 btrfs: lzo: reject inline extents without valid headers 25.08.2026 9.8
CVE-2026-74727 ovpn: skip rehash for peers already removed from by_id 25.08.2026 9.8
CVE-2026-74730 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call 25.08.2026 9.8
CVE-2026-63310 NLTK before 3.9.3 Missing Post-Download Integrity Verification 24.08.2026 9.3
CVE-2026-76571 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 25.08.2026 9.3
CVE-2026-76602 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 24.08.2026 9.3
CVE-2026-76604 Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76605 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76606 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76607 Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-77992 Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 24.08.2026 9.5
CVE-2026-77946 TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow 22.08.2026 10
CVE-2026-78003 Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys 25.08.2026 9.8
CVE-2026-12710 Missing Authorization in Application Integration QueryEngineTask 22.08.2026 9.3
CVE-2026-49849 xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution 25.08.2026 9.1
CVE-2026-77415 JSONata: Arbitrary Code Execution via crafted JSONata expressions 25.08.2026 9.3
CVE-2026-77413 JSONata: Arbitrary Code Execution via crafted JSONata expressions 24.08.2026 9.3
CVE-2026-77414 JSONata: Arbitrary Code Execution via crafted JSONata expressions 21.08.2026 9.3
CVE-2026-61539 Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing 24.08.2026 10
CVE-2026-59989 Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) 25.08.2026 9.2
CVE-2026-62283 Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check 21.08.2026 9.9
CVE-2026-76904 GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers 25.08.2026 9.8
CVE-2026-77810 Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector 21.08.2026 9.4
CVE-2026-62674 Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE 25.08.2026 9
CVE-2026-77234 Improper input validation in FreeRTOS-Kernel timer command handling 21.08.2026 9.3
CVE-2026-39909 llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler 25.08.2026 9.2
CVE-2026-74581 net: ipv6: clear suppressed fib6 rule result 25.08.2026 9.8
CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability 25.08.2026 10
CVE-2026-75932 Jet Admin tenant isolation failure 21.08.2026 9.2
CVE-2026-63343 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 21.08.2026 9.9
CVE-2026-77087 Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding 21.08.2026 9.4
CVE-2026-48755 Incus has an argument injection in backup compression algorithm leading to AFW and ACE 21.08.2026 9.9
CVE-2026-48769 Incus has an arbitrary file write on its client due to trusted image hash 21.08.2026 9.9
CVE-2026-62867 Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution 21.08.2026 9.9
CVE-2026-62940 Incus has a project restriction bypass via instance migration config override 21.08.2026 9.9
CVE-2026-62941 Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 21.08.2026 9.9
CVE-2026-63125 Incus vulnerable to root RCE via image backup.yaml symlink 21.08.2026 9.9
CVE-2026-48751 Incus has a restricted project bypass leading to arbitrary command execution 21.08.2026 9.9
CVE-2026-48752 Incus has arbitrary file read+write on host via templates/ symlink in malicious image 21.08.2026 9.9
CVE-2026-48753 Incus has an arbitrary file write via path traversal in S3 multipart upload 21.08.2026 9.9
CVE-2026-48749 Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image 21.08.2026 9.9
CVE-2026-48750 Incus has an arbitrary file write on host via `exec-output` symlink in crafted image 21.08.2026 9.9
CVE-2026-77812 Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE 24.08.2026 9.4
CVE-2026-77806 21.08.2026 9.8
CVE-2026-77776 Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity 21.08.2026 9.3
CVE-2026-77086 SiYuan before v3.7.4 Path Traversal via packageName 21.08.2026 9.4
CVE-2026-77683 Comfast CF-N1-S mbox-config system command injection 21.08.2026 9.4
CVE-2026-77264 Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure 21.08.2026 9.8
CVE-2026-76158 Datiphy Data Management Center - External Control of File Name or Path 21.08.2026 9.3
CVE-2026-76155 Datiphy Data Management Center - Use of Default Credentials 21.08.2026 9.3
CVE-2026-76156 Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command 21.08.2026 9.4
CVE-2026-77649 21.08.2026 9.8
CVE-2026-77650 21.08.2026 9.8
CVE-2026-77651 21.08.2026 9.8
CVE-2026-77647 21.08.2026 9.8
CVE-2026-18835 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.9
CVE-2026-77645 Critical Remote Code Execution (RCE) vulnerability reported in Windchill 22.08.2026 9.2
CVE-2026-17122 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-17136 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-17141 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-17142 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-17145 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-17152 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-17157 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-17160 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.8
CVE-2026-17422 Vulnerabilities in IBM AIX and PowerVM VIOS 22.08.2026 9.3
CVE-2026-72843 EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover 21.08.2026 9.3
CVE-2026-77644 Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition 26.08.2026 9.3
CVE-2026-17040 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-17118 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.8
CVE-2026-55769 CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path` 21.08.2026 9.4
CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability 25.08.2026 9.3
CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability 25.08.2026 9.9
CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability 25.08.2026 10
CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability 25.08.2026 10
CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability 25.08.2026 10
CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability 25.08.2026 9.1
CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability 25.08.2026 9.9
CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability 25.08.2026 9.9
CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability 25.08.2026 9.6
CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability 25.08.2026 10
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability 25.08.2026 10
CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability 25.08.2026 9.9
CVE-2026-71485 Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends 25.08.2026 9.1
CVE-2026-67567 Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction 21.08.2026 9.9
CVE-2026-19586 Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways 21.08.2026 9.3
CVE-2026-66785 Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowedips / ipsec enables traffic hijack 25.08.2026 9.9
CVE-2026-66788 Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace 20.08.2026 9.9
CVE-2026-77148 Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow 20.08.2026 9.4
CVE-2026-2334 ) Missing Server-Side File Extension Validation in vsDesk 21.08.2026 9.4
CVE-2026-63385 Libevent: HTTP header handling bugs create risk of access control bypass. 21.08.2026 9.2
CVE-2026-63382 libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling 20.08.2026 9.2
CVE-2026-53424 Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions 21.08.2026 9.1
CVE-2026-73251 Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification 20.08.2026 9.3
CVE-2026-73253 Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching 20.08.2026 9.1
CVE-2026-73256 Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE 21.08.2026 9.1
CVE-2026-73257 Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling 20.08.2026 9.1
CVE-2026-55642 dbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured) 20.08.2026 9.8
CVE-2026-71428 unstructured: Server-Side Request Forgery in the URL-based partitioning 25.08.2026 9.3
CVE-2026-77022 Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow 21.08.2026 9.4
CVE-2026-18265 OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability 20.08.2026 9.8
CVE-2026-16926 Vulnerabilities in IBM AIX and PowerVM VIOS 25.08.2026 9.1
CVE-2026-15706 Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS 24.08.2026 9.8
CVE-2026-28164 WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability 20.08.2026 9.6
CVE-2025-15688 WordPress Capella theme <= 2.5.5 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2025-15689 WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-66583 WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-66592 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66593 WordPress Security & Malware scan by CleanTalk plugin <= 2.184 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66600 WordPress Media LIbrary Assistant plugin <= 3.39 - Arbitrary File Upload vulnerability 20.08.2026 9.1
CVE-2026-66609 WordPress TheGem (Elementor) theme <= 5.12.3 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66649 WordPress Directory Pro plugin <= 2.5.8 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66672 WordPress Flatastic theme <= 2.0 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-66680 WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-66682 WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability 20.08.2026 9.8
CVE-2026-68566 WordPress BookingPress Appointment Booking Pro plugin <= 6.0.2 - SQL Injection vulnerability 20.08.2026 9.3
CVE-2026-73992 WordPress Query Wrangler plugin <= 1.5.57 - Remote Code Execution (RCE) vulnerability 20.08.2026 9.9
CVE-2026-73993 WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability 20.08.2026 9.8
CVE-2026-74001 WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability 20.08.2026 9.8
CVE-2026-74014 WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-74016 WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-74018 WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability 20.08.2026 9.9
CVE-2026-11861 Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships 20.08.2026 9.6
CVE-2026-13097 Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore 21.08.2026 9.1
CVE-2026-14950 Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic 20.08.2026 9.2

Latest Updates

CVE Title Updated Score
CVE-2026-48548 Nagios Core CSRF via cmd.cgi 26.08.2026
CVE-2026-48549 Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie 26.08.2026
CVE-2026-54569 SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core 26.08.2026 9.8
CVE-2026-54606 SunEditor: DOM XSS in SunEditor Embed Plugin via External Script Element After Iframe Embed 26.08.2026
CVE-2026-54614 DebugKit: MailPreview contains unsafe reflection 26.08.2026 4.3
CVE-2026-80426 FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Description 26.08.2026
CVE-2026-80427 bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Option Delimiter 26.08.2026
CVE-2026-80428 ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint 26.08.2026
CVE-2026-81027 one-api through 0.6.10 Missing Authorization on URL-Parameter Channel Pinning 26.08.2026
CVE-2026-81028 ZLMediaKit downloadFile Root-Directory Confinement Bypass via Prefix Collision 26.08.2026
CVE-2026-81029 OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI 26.08.2026
CVE-2026-81030 Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint 26.08.2026
CVE-2026-81031 IDURAR ERP CRM through 4.1.1 Account Takeover via Unverified Identifier on Password Update 26.08.2026
CVE-2026-81032 NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration 26.08.2026
CVE-2026-81033 Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Discrepancy 26.08.2026
CVE-2026-81034 Netmaker through 1.6.0 Improper Certificate Validation in SMTP Client 26.08.2026
CVE-2026-81035 Midday Missing Owner Check on Team Deletion 26.08.2026
CVE-2026-81036 Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri 26.08.2026
CVE-2026-75062 Eval Injection in google/langfun via default lf.query protocol 26.08.2026
CVE-2026-54511 @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys 26.08.2026 8.6
CVE-2026-54550 IzPack: Path Traversal in UnpackerBase allows writing files outside the installation directory via malicious pack entries 26.08.2026 7.4
CVE-2026-74734 firewire: ohci: fix NULL pointer dereference in ar_context_release 26.08.2026
CVE-2026-74735 l2tp: fix tunnel and session refcount leak on seq_file release 26.08.2026
CVE-2026-74736 net/sched: cls_bpf: reject dev-bound programs bound to a different device 26.08.2026
CVE-2026-74737 net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG 26.08.2026
CVE-2026-74738 regmap: sdw-mbq: don't call an unset readable_reg callback 26.08.2026
CVE-2026-74739 net/sched: cls_u32: skip hash tables in u32_bind_class() 26.08.2026
CVE-2026-74740 net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain 26.08.2026
CVE-2026-74741 net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling 26.08.2026
CVE-2026-74742 veth: fix queue index used to wake the peer txq in veth_poll 26.08.2026
CVE-2026-74743 macvlan: inherit needed_headroom and needed_tailroom from lowerdev 26.08.2026
CVE-2026-74744 ipvlan: inherit needed_headroom and needed_tailroom from phy_dev 26.08.2026
CVE-2026-74745 eth: bnxt: avoid deadlock when canceling IRQ affinity notifier 26.08.2026
CVE-2026-74746 netfilter: flowtable: publish GC-visible tuple last 26.08.2026
CVE-2026-74747 ipvs: revalidate ihl to prevent out-of-bounds access 26.08.2026
CVE-2026-74748 netfilter: ipset: fix refcount race between list:set GC and swap 26.08.2026
CVE-2026-74749 rseq: Prevent hard lockup on granted time slice extension 26.08.2026
CVE-2026-74750 ovpn: defer key slot crypto freeing to workqueue 26.08.2026
CVE-2026-74751 riscv: lib: Fix ZBB strnlen reading past count boundary 26.08.2026
CVE-2026-74752 sctp: validate cookie AUTH state before use 26.08.2026
CVE-2026-74753 perf: Reject exited events as group leaders 26.08.2026
CVE-2026-74754 scsi: core: pair EH runtime PM get and put 26.08.2026
CVE-2026-80519 ovpn: finish crypto callback cleanup before peer release 26.08.2026
CVE-2026-80520 ovpn: fix NULL dereference when killing missing key 26.08.2026
CVE-2026-80521 af_unix: Unlink scc_entry in unix_del_edge(). 26.08.2026
CVE-2026-80522 crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() 26.08.2026
CVE-2026-80523 clk: spacemit: k3: set hdma clock as critical 26.08.2026
CVE-2026-80524 optee: ffa: Add NULL check in optee_ffa_lend_protmem 26.08.2026
CVE-2026-80525 ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup 26.08.2026
CVE-2026-80526 ASoC: tas2562: Validate values for volume writes 26.08.2026
CVE-2026-80527 ceph: fix hanging __ceph_get_caps() with stale mds_wanted 26.08.2026
CVE-2026-80528 ceph: avoid fs reclaim while using current->journal_info 26.08.2026
CVE-2026-80529 xfs: don't swallow dquot recovery verification errors 26.08.2026
CVE-2026-80530 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN 26.08.2026
CVE-2026-80531 xfs: avoid UAF on sc->tempip in xrep_tempfile_create 26.08.2026
CVE-2026-80532 xfs: fix another iunlink infinite loop bug in online fsck 26.08.2026
CVE-2026-80533 xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair 26.08.2026
CVE-2026-80534 xfs: fix ilock leak on error in xfs_dq_get_next_id 26.08.2026
CVE-2026-80535 xfs: don't double-lock when deleting a self-referential directory 26.08.2026
CVE-2026-80536 xfs: bounds-check buffer log item's dirty bitmap 26.08.2026
CVE-2026-80537 xfs: fix off-by-one in rtrefcount btree root level validation 26.08.2026
CVE-2026-80538 xfs: propagate errors from xfs_rtginode_load 26.08.2026
CVE-2026-80539 drm/amdgpu: disallow multiple FENCE chunks in one submit 26.08.2026
CVE-2026-80540 drm/amdgpu: Fix UVD decode image min size calculation 26.08.2026
CVE-2026-80541 drm/amdgpu: validate GEM_CREATE domain combinations 26.08.2026
CVE-2026-80542 drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() 26.08.2026
CVE-2026-80543 s390/zcrypt: Pad trailing CCA or EP11 message with zeros 26.08.2026
CVE-2026-80544 s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing 26.08.2026
CVE-2026-80545 s390/zcrypt: Improve EP11 CPRB length and overflow checks 26.08.2026
CVE-2026-80546 s390/zcrypt: Improve CCA CPRB length and overflow checks 26.08.2026
CVE-2026-80547 s390/vfio_ccw: Implement a crw lock 26.08.2026
CVE-2026-80548 s390/vfio_ccw: Selectively expand io_mutex 26.08.2026
CVE-2026-80549 s390/vfio_ccw: Move cp cleanup out of not operational 26.08.2026
CVE-2026-80550 s390/vfio_ccw: Fix out of bounds check on CCW array 26.08.2026
CVE-2026-80551 s390/vfio_ccw: Ensure first IDAW remains constant 26.08.2026
CVE-2026-80552 s390/vfio_ccw: Ensure index for read/write regions are within range 26.08.2026
CVE-2026-80553 s390/vfio_ccw: Cancel existing workqueues 26.08.2026
CVE-2026-80554 s390/vfio_ccw: Limit the number of channel program segments 26.08.2026
CVE-2026-80555 s390/vfio_ccw: Free all memory if cp_init() fails 26.08.2026
CVE-2026-80556 mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition 26.08.2026
CVE-2026-80557 libceph: fix OOB read in decode_watchers() via missing bounds check 26.08.2026
CVE-2026-80558 libceph: Avoid using invalid osd indices from primary_temp 26.08.2026
CVE-2026-80559 Input: sur40 - fix input device registration ordering 26.08.2026
CVE-2026-80560 openrisc: signal: do not restore privileged SR bits on sigreturn 26.08.2026
CVE-2026-80561 libceph: fix multiple unsafe decodes in decode_locker() 26.08.2026
CVE-2026-80562 gpio: ml-ioh: use raw_spinlock_t for the register lock 26.08.2026
CVE-2026-80563 gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind 26.08.2026
CVE-2026-80564 gve: fix NULL dereference due to missing ptp adjfine 26.08.2026
CVE-2026-80565 crypto: qce - fix error path in devm_qce_register_algs 26.08.2026
CVE-2026-80566 Input: hynitron_cstxxx - validate touch count and finger IDs 26.08.2026
CVE-2026-80567 Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue 26.08.2026
CVE-2026-80568 Input: synaptics-rmi4 - block s_input when F54 queue is busy 26.08.2026
CVE-2026-80569 Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer 26.08.2026
CVE-2026-80570 Input: synaptics-rmi4 - zero report size on F54 work error 26.08.2026
CVE-2026-80571 powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak 26.08.2026
CVE-2026-80572 Input: byd - synchronize timer deletion before freeing private data 26.08.2026
CVE-2026-80573 Input: iforce - validate input packet lengths 26.08.2026
CVE-2026-80574 Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet 26.08.2026
CVE-2026-80575 Input: cs40l50-vibra - validate custom data from user space 26.08.2026
CVE-2026-80576 drm/amdgpu: reject oversized IBs with per-ring packet limits 26.08.2026
CVE-2026-80577 drm/panthor: skip zero-sized firmware sections 26.08.2026
CVE-2026-80578 fbdev: core: Fix pointer desynchronization in fb_io_read() 26.08.2026
CVE-2026-80579 fbdev: clear fb_info->mode before deleting a videomode 26.08.2026
CVE-2026-80580 fbdev: bound mode sysfs output to the sysfs buffer 26.08.2026
CVE-2026-80581 ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout 26.08.2026
CVE-2026-80582 drm/shmem_helper: Check VMA boundaries for PMD mappings 26.08.2026
CVE-2026-80583 ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses 26.08.2026
CVE-2026-80584 s390/qeth: validate user buffer length in SNMP and ARP query ioctls 26.08.2026
CVE-2026-80585 mptcp: fastopen: only mark MPTFO subflows with SYN data 26.08.2026
CVE-2026-80586 mptcp: options: reset DSS fields in case of unexpected size 26.08.2026
CVE-2026-80587 mptcp: avoid combining some incoming suboptions 26.08.2026
CVE-2026-80588 mptcp: reclaim forward-allocated memory on RX path errors 26.08.2026
CVE-2026-80589 block: stop the timeout timer when releasing a never added disk 26.08.2026
CVE-2026-13479 Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler 26.08.2026 3.1
CVE-2026-13480 Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler 26.08.2026 3.1
CVE-2026-13481 Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP 26.08.2026 5.4
CVE-2026-54523 Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system 26.08.2026 9.6
CVE-2026-54548 kas: Persistent SSH Host Key Checking Disablement 26.08.2026 3.3
CVE-2026-54553 Starlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS 26.08.2026 5.4
CVE-2026-54556 Http4s: HTTP/2 Denial of Service with Ember Backend 26.08.2026
CVE-2026-19271 Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk 26.08.2026 7.5
CVE-2025-10903 Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab 26.08.2026 6.5
CVE-2026-15387 Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab 26.08.2026 4.3
CVE-2026-15990 Formidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' Parameter 26.08.2026 7.5
CVE-2026-18252 Inclusion of Functionality from Untrusted Control Sphere in GitLab 26.08.2026 7.3
CVE-2026-3035 Authentication Bypass Using an Alternate Path or Channel in GitLab 26.08.2026 5.5
CVE-2026-75896 Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk 26.08.2026 9.1
CVE-2026-75960 Insufficiently Protected Credentials in Rently Smart Home 26.08.2026
CVE-2026-77801 Allocation of Resources Without Limits or Throttling in GitLab 26.08.2026 6.5
CVE-2026-79902 Gimp: stack vla size underflow denial of service in seattle 26.08.2026
CVE-2026-7487 Access Control Check Implemented After Asset is Accessed in GitLab 26.08.2026 3.5
CVE-2026-12717 Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection 26.08.2026
CVE-2026-73102 RustDesk Path Traversal via macOS Clipboard File-Paste 26.08.2026
CVE-2026-73108 RustDesk < 1.4.7 Uncontrolled Memory Allocation DoS via BytesCodec 26.08.2026
CVE-2026-79619 OpenZFS: user-namespace capability check allows unprivileged local authorization bypass 26.08.2026
CVE-2026-12587 Embedded credentials in Virtuagym 26.08.2026
CVE-2026-77658 Dia: dia: stack buffer overflow in bus object via unvalidated handle count in project files 26.08.2026
CVE-2026-15985 Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login 26.08.2026 8.1
CVE-2026-63041 Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers 26.08.2026
CVE-2026-18080 ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment 26.08.2026 9.8
CVE-2026-3235 WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5.68 - Unauthenticated Insecure Direct Object Reference to Data Access 26.08.2026 5.3
CVE-2026-5092 Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI 26.08.2026 6.4
CVE-2026-77532 26.08.2026 9.6
CVE-2026-77554 26.08.2026 10
CVE-2026-77557 26.08.2026 9.8
CVE-2026-77549 26.08.2026 9
CVE-2026-77550 26.08.2026 10
CVE-2026-77551 26.08.2026 9
CVE-2026-77552 26.08.2026 9.8
CVE-2026-77553 26.08.2026 9.9
CVE-2026-80206 NLTK 3.10.2 Regular Expression Denial of Service via tgrep 26.08.2026
CVE-2026-77546 26.08.2026 9.9
CVE-2026-77547 26.08.2026 9.9
CVE-2026-77548 26.08.2026 9.9
CVE-2026-80203 Grav before 1.0.18 Authentication Bypass via Scoped API Key 26.08.2026
CVE-2026-80204 Grav before 1.0.18 Authentication Bypass via Scoped API Key 26.08.2026
CVE-2026-80205 NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex 26.08.2026
CVE-2026-77542 26.08.2026 9.1
CVE-2026-77543 26.08.2026 9.9
CVE-2026-77545 26.08.2026 9
CVE-2026-80346 StarRocks through 4.0.13 Missing Authorization on DROP MATERIALIZED VIEW for Legacy Synchronous Materialized Views 26.08.2026
CVE-2026-80347 mcp-fetch through 1.6.3 Server-Side Request Forgery via Unstripped IPv6 Literal Brackets 26.08.2026
CVE-2026-80348 TarsWeb through 3.0.16 Missing Authorization on Patch Deploy, Download and Delete Endpoints 26.08.2026
CVE-2026-80349 TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter 26.08.2026
CVE-2026-80350 OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URL 26.08.2026
CVE-2026-77538 26.08.2026 8.2
CVE-2026-77539 26.08.2026 9.1
CVE-2026-77540 26.08.2026 9.1
CVE-2026-77541 26.08.2026 9.1
CVE-2026-18794 OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite 26.08.2026
CVE-2026-2388 Reviews and Rating – Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes 26.08.2026 6.4
CVE-2026-59683 OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings 26.08.2026
CVE-2026-77535 26.08.2026 9.1
CVE-2026-77536 26.08.2026 9.9
CVE-2026-77537 26.08.2026 10
CVE-2026-16444 Improper Validation of File Paths in TeamViewer Desktop Clients 26.08.2026 7.5
CVE-2026-19042 Command Injection in TeamViewer Desktop Client for Linux through Chat Link Handling 26.08.2026 8.8
CVE-2026-59682 Arbitrary file overwrite and deletion local and remote in OpenRGB 26.08.2026
CVE-2026-77534 26.08.2026 9.9
CVE-2026-19197 Broken access control in dashboard snapshots 26.08.2026 6.3
CVE-2026-19538 Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS 26.08.2026
CVE-2026-77533 26.08.2026 9.9
CVE-2026-18664 Wrong interpretation of ACL ranges 26.08.2026
CVE-2026-18916 Remote TCP DoS by throttling the TCP receive window 26.08.2026
CVE-2026-19401 Remote UDP DoS by sending multiple DNS Cookie options 26.08.2026
CVE-2026-80236 Thinking Software Technology|Efence - SQL Injection 26.08.2026 8.2
CVE-2026-80237 Thinking Software Technology|Efence - Arbitrary File Upload 26.08.2026 8.8
CVE-2026-80233 CAYIN Technology|CAYIN CMS-WS/CMS-SE/SMP - Arbitrary File Upload 26.08.2026 7.2
CVE-2026-80234 CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication 26.08.2026 5.3
CVE-2026-80235 Thinking Software Technology|EFence - Arbitrary File Upload 26.08.2026 9.8
CVE-2026-9668 SQL injection vulnerability in ZTE SCP product 26.08.2026 6.3
CVE-2026-18884 WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters 26.08.2026 7.5
CVE-2026-6178 Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode 26.08.2026 6.4
CVE-2026-75977 Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie 26.08.2026 8.8
CVE-2026-78236 Insecure PIN derivation mechanism in Admin By Request (ABR) 26.08.2026 8.8
CVE-2026-78237 Insufficient input validation in Admin By Request (ABR) 26.08.2026 7.8
CVE-2026-15365 26.08.2026
CVE-2026-15366 26.08.2026
CVE-2026-58108 Personal access token delete filters on Session columns while deleting from PersonalAccessTokenDB 26.08.2026