CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-16142 TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter 15.08.2026 9.8
CVE-2026-15826 User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter 15.08.2026 9.8
CVE-2026-14484 RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters 15.08.2026 9.1
CVE-2026-15303 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter 15.08.2026 9.8
CVE-2026-15341 User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters 15.08.2026 9.8
CVE-2026-73683 Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay 14.08.2026 9.2
CVE-2026-67365 Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 14.08.2026 9.2
CVE-2026-17181 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.3
CVE-2026-17182 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.8
CVE-2026-17184 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.8
CVE-2026-17186 IBM Db2 Mirror for i is affected by multiple vulnerabilities 14.08.2026 9.9
CVE-2026-50027 mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete 14.08.2026 9.8
CVE-2026-73678 MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec() 14.08.2026 10
CVE-2026-19188 Haiwell IoT Cloud HMI Gateway OS Command Injection 14.08.2026 10
CVE-2026-49457 QUIC has Broken TLS verification 14.08.2026 9.1
CVE-2026-19681 Command Injection 15.08.2026 9.4
CVE-2026-19682 Command Injection 15.08.2026 9.4
CVE-2026-48528 Metacat has an unauthenticated SQL injection vulnerability 14.08.2026 9.8
CVE-2026-73849 emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. 14.08.2026 9.8
CVE-2026-19626 Remote Code Execution 15.08.2026 9.4
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding 14.08.2026 9.3
CVE-2026-72810 SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket 14.08.2026 9.2
CVE-2026-72811 SiYuan before v3.7.4 SQL Injection via backlink search 14.08.2026 9.9
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa 14.08.2026 9.3
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController 14.08.2026 9.3
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey 14.08.2026 9.3
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController 14.08.2026 9.3
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass 14.08.2026 9.3
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass 14.08.2026 9.2
CVE-2026-12949 Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter 14.08.2026 9.8
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup 14.08.2026 9.3
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 14.08.2026 9.4
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass 14.08.2026 9.4
CVE-2026-72850 Budibase before 3.40.0 Arbitrary File Write via Path Traversal 14.08.2026 9.4
CVE-2026-72851 Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook 14.08.2026 9
CVE-2026-73302 Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified 14.08.2026 9
CVE-2026-73420 NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 14.08.2026 9.1
CVE-2026-73421 NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 13.08.2026 9.1
CVE-2026-73842 OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation 13.08.2026 9
CVE-2026-73843 OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs 14.08.2026 9.6
CVE-2026-73665 FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection 13.08.2026 9.3
CVE-2026-19750 Tenda CH/CP/TX3 SSH hard-coded password 14.08.2026 9.2
CVE-2026-72776 AgenticSeek Unauthenticated RCE via /query API Endpoint 14.08.2026 9.3
CVE-2026-73663 FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover 14.08.2026 9.3
CVE-2026-17482 IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution 13.08.2026 9.8
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint 15.08.2026 9.1
CVE-2026-8715 Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath 14.08.2026 9.6
CVE-2026-19747 Tenda CH7 ATE Module Kylin HandleCmd command injection 14.08.2026 9.3
CVE-2026-73656 Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state 14.08.2026 9.9
CVE-2026-14525 IBM WebSphere Application Server Liberty is affected by an authenication bypass 15.08.2026 9.4
CVE-2026-73653 Vitest: Browser Mode provider commands bypass the file-access permission gate 13.08.2026 9.4
CVE-2026-73644 OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant 13.08.2026 9.6
CVE-2026-73649 Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) 14.08.2026 9.8
CVE-2026-73567 sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock 14.08.2026 9.1
CVE-2026-67614 CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal 14.08.2026 9.3
CVE-2026-73532 Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build 14.08.2026 9.3
CVE-2026-73533 Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build 14.08.2026 9.3
CVE-2026-53790 rsync < 3.5.0 Command Injection via Multiple Code Paths 14.08.2026 9.2
CVE-2026-53791 rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header 14.08.2026 9.1
CVE-2026-53793 rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode 14.08.2026 9.1
CVE-2026-70452 rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure 14.08.2026 9.1
CVE-2026-70460 rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink 14.08.2026 9.2
CVE-2026-27544 WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability 13.08.2026 10
CVE-2026-28001 WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28008 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-28142 WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-28148 WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability 13.08.2026 9.8
CVE-2026-28149 WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability 13.08.2026 9.8
CVE-2026-28185 WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-61962 WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability 13.08.2026 10
CVE-2026-61966 WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-61967 WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-61969 WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66424 WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability 13.08.2026 9.8
CVE-2026-66436 WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66446 WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability 13.08.2026 9.8
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66465 WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability 13.08.2026 9.8
CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66478 WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability 13.08.2026 9.3
CVE-2026-66691 WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability 13.08.2026 9.8
CVE-2026-49827 WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) 13.08.2026 9.8
CVE-2026-73483 Flowise before 3.1.3 Sandbox Escape via Puppeteer 14.08.2026 9.4
CVE-2026-73485 Flowise before 3.1.3 Remote Code Execution via Airtable Agent 14.08.2026 9
CVE-2026-73486 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV 13.08.2026 9
CVE-2026-73487 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent 14.08.2026 9
CVE-2026-73601 Flowise before 3.1.3 Remote Code Execution via Custom MCP 14.08.2026 9
CVE-2026-73602 Flowise before 3.1.3 Sandbox Escape to RCE 13.08.2026 9
CVE-2026-73608 SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget 14.08.2026 9.2
CVE-2026-59503 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor 13.08.2026 9.1
CVE-2026-59504 Priority – CWE-602: Client-Side Enforcement of Server-Side Security 13.08.2026 9.1
CVE-2026-59506 Priority – CWE-306: Missing Authentication for Critical Function 13.08.2026 9.3
CVE-2026-59507 Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control 13.08.2026 9.3
CVE-2026-59500 Priority - CWE-287: Improper Authentication 13.08.2026 10
CVE-2026-15413 Link Factory - Backdoor 13.08.2026 10
CVE-2026-49819 UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd 13.08.2026 9.8
CVE-2026-49481 UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd 13.08.2026 9.6
CVE-2026-71193 13.08.2026 9.6
CVE-2026-71471 Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image 13.08.2026 9
CVE-2024-27253 IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request 13.08.2026 10
CVE-2026-73501 kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default 13.08.2026 9.1
CVE-2026-73519 WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret 13.08.2026 9.3
CVE-2026-19001 MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names 13.08.2026 9.5
CVE-2026-66898 Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE 13.08.2026 9.9
CVE-2026-63293 Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root 13.08.2026 9.9
CVE-2026-63294 Root RCE via image backup.yaml symlink 13.08.2026 9.9
CVE-2026-17083 IBM i is Affected By Multiple Vulnerabilities in the Debug Server 13.08.2026 9.8
CVE-2026-63296 Project restriction bypass via instance migration config override 13.08.2026 9.9
CVE-2026-63297 Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge 13.08.2026 9.9
CVE-2026-72508 Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*) 13.08.2026 9.9
CVE-2026-73414 Shescape: Shell injection via unescaped parentheses on Windows with CMD 14.08.2026 9.2
CVE-2026-19656 ScadaLTS Authenticated Remote Code Execution 12.08.2026 9.9
CVE-2026-62420 Cross-project cluster migration bypasses project restrictions via cluster notification flag 12.08.2026 9.9
CVE-2026-63300 Cross-project instance move bypasses all project restrictions allowing host command execution 13.08.2026 9.9
CVE-2026-72789 SiYuan before v3.7.4 Authentication Bypass via Encrypted Notebooks 14.08.2026 9.2
CVE-2026-72793 SiYuan before v3.7.4 Information Disclosure via /api/system/getConf 14.08.2026 9.2
CVE-2026-72794 siyuan before v3.7.4 Session Cookie Key Disclosure via getConf 14.08.2026 9.2
CVE-2026-72795 SiYuan before v3.7.4 Information Disclosure via Embed Block 14.08.2026 9.2
CVE-2026-72798 SiYuan before v3.7.4 Information Disclosure via renderAttributeView 14.08.2026 9.2
CVE-2026-72804 SiYuan before v3.7.4 Authentication Bypass via Graph Endpoints 14.08.2026 9.2
CVE-2026-73268 Cluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injection 12.08.2026 9.9
CVE-2026-73269 Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa 12.08.2026 9.9
CVE-2026-73329 CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint 14.08.2026 9.2
CVE-2026-73332 CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field 14.08.2026 9.2
CVE-2026-73407 Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) 12.08.2026 9
CVE-2026-73300 Budibase: SQL Injection via `multipleStatements: true` 12.08.2026 9.6
CVE-2026-16860 IBM i is Affected By Remote Code Execution Vulnerability [] 12.08.2026 9.9
CVE-2026-16956 IBM Db2 Mirror for i is vulnerable to OS command injection [] 12.08.2026 9.8
CVE-2026-17218 IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] 12.08.2026 9.8
CVE-2026-73299 Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer 12.08.2026 10
CVE-2026-17276 IBM i is Affected By Multiple Vulnerabilities in Navigator for i 12.08.2026 9.6
CVE-2026-73296 Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure 13.08.2026 9.4
CVE-2026-73294 Semaphore U: OS Command Injection 12.08.2026 9.9
CVE-2026-64639 14.08.2026 9.3
CVE-2026-73263 Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path 12.08.2026 9.9
CVE-2026-50561 Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse 13.08.2026 9.4
CVE-2026-67285 Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 14.08.2026 9.2
CVE-2026-57858 Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID 13.08.2026 9.3
CVE-2026-67282 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 12.08.2026 10
CVE-2025-41769 Unauthenticated Buffer Overflow in PROFINET Service 13.08.2026 9.3
CVE-2026-66659 WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability 12.08.2026 9.3
CVE-2026-70398 Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace 12.08.2026 9.6
CVE-2026-72526 Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation 12.08.2026 9.9
CVE-2026-68431 ksmbd: validate minimum PDU size for transform requests 13.08.2026 9.1
CVE-2026-5917 libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend 14.08.2026 9.4
CVE-2026-67568 Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials 12.08.2026 9.3
CVE-2026-68067 Mira Hormone Monitor, Mira Android App Weak Authentication 12.08.2026 9.3
CVE-2026-48765 TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding 12.08.2026 9.9
CVE-2026-16230 Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field 11.08.2026 9.8
CVE-2026-45618 LiquidJS is Vulnerable to Remote Code Execution 13.08.2026 10
CVE-2026-73034 DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header 14.08.2026 9.3
CVE-2026-73032 PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() 11.08.2026 9.4
CVE-2026-18691 Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure 11.08.2026 9
CVE-2026-72742 DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing 12.08.2026 9.2
CVE-2026-69102 MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust 14.08.2026 9.3
CVE-2026-27302 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-48381 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 11.08.2026 9
CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) 12.08.2026 9.1
CVE-2026-71398 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 13.08.2026 10
CVE-2026-47705 TypeBot vulnerable to CSV injection in result export 13.08.2026 9.6
CVE-2026-73090 PeerTube: Cross-origin remote video takeover via Update activity 13.08.2026 9.3
CVE-2026-73211 PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() 11.08.2026 9.8
CVE-2026-12571 Authentication Bypass Leading to Account Takeover 12.08.2026 9.8
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 14.08.2026 9.4
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability 14.08.2026 9.8
CVE-2026-70306 Microsoft Office SharePoint Spoofing Vulnerability 14.08.2026 9.3
CVE-2026-48362 ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 12.08.2026 10
CVE-2026-71384 ColdFusion | Incorrect Authorization (CWE-863) 12.08.2026 9.6
CVE-2026-73080 SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle 13.08.2026 9.3
CVE-2025-31114 Fooocus webui vulnerable to Remote Code Execution 13.08.2026 9.3
CVE-2026-73069 Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution 11.08.2026 9.1
CVE-2026-17061 Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 11.08.2026 10
CVE-2026-47702 TypeBot API tokens stored in plaintext 11.08.2026 9.1
CVE-2026-72920 SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control 11.08.2026 9.8
CVE-2026-46670 YesWiki: Unauthenticated SQL Injection 13.08.2026 9.8
CVE-2026-48056 Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler 11.08.2026 10
CVE-2026-48046 Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler 13.08.2026 9.3
CVE-2026-18972 Velociraptor authenticated identity-spoofing vulnerability 11.08.2026 9.6
CVE-2026-58115 12.08.2026 10
CVE-2026-72785 Craft CMS before 5.10.6 Authorization Bypass via structures/move-element 11.08.2026 9.3
CVE-2026-13737 Command Restriction Bypass 11.08.2026 9.2
CVE-2026-13738 Improper Authorization Validation 11.08.2026 9.2
CVE-2026-72550 Friendica Friendica - SQL Injection 11.08.2026 9.8
CVE-2026-72599 e107 e107 - SQL Injection 11.08.2026 9.8
CVE-2026-72603 wg-easy wg-easy - OS Command Injection 11.08.2026 9.9
CVE-2026-58231 Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) 12.08.2026 10
CVE-2026-10579 Picketlink-federation: auth bypass in picketlink saml unsolicited-response 11.08.2026 9.8
CVE-2026-13716 Path Traversal: '.../...//' in Crafty Controller 11.08.2026 9.1
CVE-2026-19516 CVE-2026-19516 CVE Record 12.08.2026 9.1
CVE-2026-19425 Win Men Intermational|Travel Agency Management System - SQL Injection 12.08.2026 9.3
CVE-2026-34265 Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform 12.08.2026 9.8
CVE-2026-44758 Code Injection vulnerability in Manufacturing Integration and Intelligence 11.08.2026 9.1
CVE-2026-48161 react18-use was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-48160 react-tracked was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72911 ERPNext: Possibility of server-side template injection due to missing validation 13.08.2026 9.9
CVE-2026-14450 Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication 11.08.2026 9.9
CVE-2026-18948 Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server 11.08.2026 9.9
CVE-2026-72904 Firecrawl: Arbitrary file read via JSON Schema $ref expansion 11.08.2026 9.3
CVE-2026-72901 Dokploy: Remote Code Execution via volume-backup 13.08.2026 9.9
CVE-2026-72902 Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById 12.08.2026 9.9
CVE-2025-13293 Backdoor / default root credentials 12.08.2026 9.3
CVE-2025-13294 Unauthenticated SQL Injection 12.08.2026 9.3
CVE-2025-15681 Insufficient Webserver Authentication 12.08.2026 9.2
CVE-2026-72880 Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath` 11.08.2026 9.9
CVE-2026-72882 Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers 13.08.2026 9.9
CVE-2026-72886 Dokploy: Non-admin member gains root on the host by bypassing the owner/admin check on server-level schedules (incomplete fix of CVE-2026-45632) 10.08.2026 9.9
CVE-2026-72876 Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* 10.08.2026 9.9
CVE-2026-72877 Dokploy: Command Injection via dockerImage in buildRemoteDocker 13.08.2026 9.6
CVE-2026-72878 Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments 12.08.2026 9.6
CVE-2026-72879 Dokploy: Command Injection via Registry Credentials in Swarm Upload 11.08.2026 9.4
CVE-2026-72864 Dokploy Broken Access Control on docker-container-terminal WebSocket (Member -> Root in Arbitrary Containers) 11.08.2026 9.9
CVE-2026-72865 Dokploy: OS Command Injection via compose `composePath` 11.08.2026 9.9
CVE-2026-72867 Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts) 13.08.2026 9.9
CVE-2026-72868 Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection 12.08.2026 9.9
CVE-2026-72869 Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE 11.08.2026 9.9
CVE-2026-72872 Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` 13.08.2026 9.9
CVE-2026-72863 Dokploy: Missing authorization in WebSocket handlers allows a low-privilege member to gain root on the Docker host 10.08.2026 9.9
CVE-2026-16626 JasperReports Server: XXE Injection Vulnerability (Unauthenticated) 11.08.2026 9.3
CVE-2026-48159 use-reducer-async was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-72740 Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan` 10.08.2026 9.9
CVE-2026-72862 Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE 13.08.2026 9.9
CVE-2026-72898 Metabase SQL injection via password reset endpoint 12.08.2026 10
CVE-2026-72899 Metabase SQL injection via public card or dashboard 11.08.2026 10
CVE-2026-72735 Dokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote execution 10.08.2026 9.9
CVE-2026-72736 Dokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCE 10.08.2026 9.9
CVE-2026-72737 Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups 13.08.2026 9.6
CVE-2026-72738 Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter 10.08.2026 9.9
CVE-2026-72733 Dokploy: OS Command Injection via `databaseName` / `backupFile` in database restore 10.08.2026 9.9
CVE-2026-48158 use-context-selector was vulnerable to malicious code execution via compromised commits 11.08.2026 9.3
CVE-2026-47754 unauthenticated path traversal in Metacat 2.x 10.08.2026 9.3
CVE-2026-63106 ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php 10.08.2026 9.3
CVE-2026-13206 Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection 10.08.2026 9.8
CVE-2026-68117 tipc: clear sock->sk on the failed-insert path in tipc_sk_create() 13.08.2026 9.8
CVE-2026-68123 openvswitch: fix GSO userspace truncation underflow 13.08.2026 9.8
CVE-2026-68124 mctp: serial: handle zero-length frames to prevent rx buffer overflow 13.08.2026 9.6
CVE-2026-68127 ila: reload IPv6 header after pskb_may_pull in checksum adjust 13.08.2026 9.8
CVE-2026-68136 net: gro: fix double aggregation of flush-marked skbs 13.08.2026 9.8
CVE-2026-68137 net/x25: fix use-after-free in x25_kill_by_neigh() 13.08.2026 9.8
CVE-2026-68144 phonet: pep: fix use-after-free in pep_get_sb() 13.08.2026 9.8
CVE-2026-68154 libceph: reject zero bucket types in crush_decode 13.08.2026 9.8
CVE-2026-68156 libceph: refresh auth->authorizer_buf{,_len} after authorizer update 13.08.2026 9.8
CVE-2026-68158 libceph: Fix multiplication overflow in decode_new_up_state_weight() 13.08.2026 9.8
CVE-2026-68159 libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE 13.08.2026 9.8
CVE-2026-68160 ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() 13.08.2026 9.8
CVE-2026-68161 sctp: close UDP tunnel sockets during netns teardown 13.08.2026 9.8
CVE-2026-68170 mptcp: fix stale skb->sk reference on subflow close 13.08.2026 9.8
CVE-2026-68300 sctp: auth: verify auth requirement when auth_chunk is NULL 13.08.2026 9.8
CVE-2026-68302 amt: re-read skb header pointers after every pull 13.08.2026 9.8
CVE-2026-68343 smb: client: validate DFS referral PathConsumed 13.08.2026 9.1
CVE-2026-68381 ksmbd: pin conn during async oplock break notification 13.08.2026 9.8
CVE-2026-68385 s390/checksum: Fix csum_partial() without vector facility 13.08.2026 9.8
CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate 13.08.2026 9.8
CVE-2026-68426 xfrm: fix stale skb->prev after async crypto steals a GSO segment 13.08.2026 9.8
CVE-2026-68083 ksmbd: fix path resolution in ksmbd_vfs_kern_path_create 13.08.2026 9.1
CVE-2026-72564 fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication 10.08.2026 9.6
CVE-2026-72565 Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass 10.08.2026 9.8
CVE-2026-72567 deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete 10.08.2026 9.8
CVE-2026-72569 cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion 10.08.2026 9.1
CVE-2026-72575 daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects 10.08.2026 9.1
CVE-2026-72577 NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection 10.08.2026 9.8
CVE-2026-72580 duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints 10.08.2026 9.8
CVE-2026-72589 alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field 10.08.2026 9.8
CVE-2026-72590 alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter 10.08.2026 9.8
CVE-2026-72592 dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload 10.08.2026 9.8
CVE-2026-72593 dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access 10.08.2026 9.8
CVE-2026-66915 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.9 12.08.2026 10
CVE-2026-19348 Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection 10.08.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-19898 VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authentication 15.08.2026
CVE-2026-19897 mangroup dtale Login Endpoint auth.py login excessive authentication 15.08.2026
CVE-2026-19896 mangroup dtale Flask Session Cookie app.py build_secret_key random values 15.08.2026
CVE-2026-18165 @fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies 15.08.2026 4.2
CVE-2026-15689 Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send 15.08.2026
CVE-2026-18549 @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit 15.08.2026 7.5
CVE-2026-19474 @fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted upload 15.08.2026 7.5
CVE-2026-19895 opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication 15.08.2026
CVE-2026-18500 @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key 15.08.2026 8.1
CVE-2026-74440 drm/xe: Wait on external BO kernel fences in exec IOCTL 15.08.2026
CVE-2026-74441 usb: typec: ucsi: Fix race condition and ordering in port unregistration 15.08.2026
CVE-2026-74442 drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure 15.08.2026
CVE-2026-74443 drm/vmwgfx: bound DMA command body size against suffix pointer 15.08.2026
CVE-2026-74444 drm/vmwgfx: validate DRAW_PRIMITIVES header size before division 15.08.2026
CVE-2026-74445 drm/vmwgfx: reject DX_BIND_QUERY without a DX context 15.08.2026
CVE-2026-74446 drm/amdkfd: hold event_mutex while checkpointing CRIU events 15.08.2026
CVE-2026-74447 drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment 15.08.2026
CVE-2026-74448 drm/amdkfd: fix QID bit leak in pqm_create_queue() 15.08.2026
CVE-2026-74449 drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport 15.08.2026
CVE-2026-74450 drm/amd/pm: fix pptable use-after-free 15.08.2026
CVE-2026-74451 drm/panthor: validate firmware interface structure sizes 15.08.2026
CVE-2026-74452 drm/panthor: reject firmware sections with oversized data 15.08.2026
CVE-2026-74453 drm/vc4: Zero the tile state data array before each BIN job 15.08.2026
CVE-2026-74454 drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size 15.08.2026
CVE-2026-74455 can: peak_usb: validate uCAN receive record lengths 15.08.2026
CVE-2026-74456 can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error 15.08.2026
CVE-2026-74457 can: peak_usb: add bounds check for USB channel index 15.08.2026
CVE-2026-74458 can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents 15.08.2026
CVE-2026-74459 can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure 15.08.2026
CVE-2026-74460 can: ems_usb: validate CPC message lengths 15.08.2026
CVE-2026-74461 i2c: imx: Cancel hrtimer before clearing slave pointer 15.08.2026
CVE-2026-74462 i2c: imx: mark I2C adapter when hardware is powered down 15.08.2026
CVE-2026-74463 i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock 15.08.2026
CVE-2026-74464 net: openvswitch: fix skb leak on flow key update failure during ct 15.08.2026
CVE-2026-74465 net: openvswitch: fix potential UAF on meter attach failure 15.08.2026
CVE-2026-74466 s390/zcrypt: Close speculative mem read possibility 15.08.2026
CVE-2026-74467 s390/qeth: Check CAP_NET_ADMIN for private ioctls 15.08.2026
CVE-2026-74468 gpio: pch: use raw_spinlock_t for the register lock 15.08.2026
CVE-2026-74469 sctp: prevent peer transport count overflow 15.08.2026
CVE-2026-74470 scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write 15.08.2026
CVE-2026-74471 tracing: Check return value of __register_event() in trace_module_add_events() 15.08.2026
CVE-2026-74472 ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() 15.08.2026
CVE-2026-74473 vxlan: use pskb_network_may_pull() in route_shortcircuit() 15.08.2026
CVE-2026-74474 vxlan: use pskb_network_may_pull() for transmit path header pulls 15.08.2026
CVE-2026-74475 vxlan: use neigh_ha_snapshot() in route_shortcircuit() 15.08.2026
CVE-2026-74476 veth: convert frag_list skbs before running XDP 15.08.2026
CVE-2026-74477 uprobes: Fix NULL pointer dereference in hprobe_expire() 15.08.2026
CVE-2026-74478 um: vector: fix use-after-free in vector_mmsg_rx() 15.08.2026
CVE-2026-74479 net: pktgen: fix proc entry use-after-free 15.08.2026
CVE-2026-74480 net: bridge: stop fast-leave after deleting a port group 15.08.2026
CVE-2026-74481 mm/page_reporting: use system_freezable_wq to fix UAF during suspend 15.08.2026
CVE-2026-74482 mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios 15.08.2026
CVE-2026-74483 binfmt_misc: don't leak the user namespace when the mount fails 15.08.2026
CVE-2026-74484 binfmt_misc: don't let an 'F' entry pin its own instance 15.08.2026
CVE-2026-74485 binfmt_misc: reject a flag character as the field delimiter 15.08.2026
CVE-2026-74486 binfmt_misc: use exe_file_deny_write_access() for the interpreter clone 15.08.2026
CVE-2026-74487 binfmt_misc: restore write access when removing an entry 15.08.2026
CVE-2026-74488 wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames 15.08.2026
CVE-2026-74489 wifi: mac80211: fix tid_tx use-after-free on BA session stop 15.08.2026
CVE-2026-74490 tipc: avoid use-after-free in poll trace queue dumps 15.08.2026
CVE-2026-74491 of/address: Fix NULL bus dereference in of_pci_range_parser_one() 15.08.2026
CVE-2026-74492 netfilter: ipset: do not update comments from kernel-side hash adds 15.08.2026
CVE-2026-74493 net/smc: fix socket use-after-free during link group termination 15.08.2026
CVE-2026-74494 ksmbd: reject repeated SMB2 NEGOTIATE requests 15.08.2026
CVE-2026-74495 igbvf: Fix leak in TX DMA error cleanup 15.08.2026
CVE-2026-74496 fou: Fix use-after-free in fou_create() 15.08.2026
CVE-2026-74497 ALSA: usb-audio: Clamp frame size in implicit-feedback mode 15.08.2026
CVE-2026-74498 ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set 15.08.2026
CVE-2026-74499 ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() 15.08.2026
CVE-2026-74500 ALSA: usb-audio: fix stack info leak in RME Digiface status 15.08.2026
CVE-2026-74501 ALSA: usb-audio: fix use-after-free in ump_to_endpoint() 15.08.2026
CVE-2026-74502 ALSA: ump: fix double free of out_cvts on rawmidi error 15.08.2026
CVE-2026-74503 ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes 15.08.2026
CVE-2026-74504 ALSA: seq: Fix division by zero in initialize_timer() 15.08.2026
CVE-2026-74505 ALSA: 6fire: Fix UAF at error handling during probe 15.08.2026
CVE-2026-74506 afs: Fix UAF when sending a message 15.08.2026
CVE-2026-74507 Bluetooth: HIDP: validate numbered report payloads 15.08.2026
CVE-2026-74508 Bluetooth: HIDP: reject frames without a transaction header 15.08.2026
CVE-2026-74509 Bluetooth: hci_sync: Fix advertising data UAFs 15.08.2026
CVE-2026-74510 Bluetooth: mgmt: fix UAF in pair command cancellation 15.08.2026
CVE-2026-74511 Bluetooth: mgmt: fix pending command UAF in EIR updates 15.08.2026
CVE-2026-74512 audit: fix potential use-after-free in audit_del_rule() 15.08.2026
CVE-2026-74513 dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister 15.08.2026
CVE-2026-74514 KVM: s390: pci: Fix memory accounting for pinned/unpinned pages 15.08.2026
CVE-2026-74515 KVM: s390: pci: Reject adapter interrupt forwarding if already enabled 15.08.2026
CVE-2026-74516 KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active 15.08.2026
CVE-2026-74517 KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs 15.08.2026
CVE-2026-74518 mm/hugetlb: fix list corruption in allocate_file_region_entries() 15.08.2026
CVE-2026-74519 pinctrl: devicetree: don't free uninitialized dev_name on error path 15.08.2026
CVE-2026-74520 iommu/iommufd: Fix IOPF group ownership UAF 15.08.2026
CVE-2026-74521 ksmbd: use memcmp() to compare ClientGUIDs 15.08.2026
CVE-2026-74522 ksmbd: fix use-after-free in __close_file_table_ids() 15.08.2026
CVE-2026-74523 qede: sync udp_tunnel ports outside qede_lock in the recovery path 15.08.2026
CVE-2026-74524 riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove 15.08.2026
CVE-2026-74525 net: sxgbe: free TX rings on RX allocation failure 15.08.2026
CVE-2026-74526 scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit 15.08.2026
CVE-2026-74527 octeontx2-af: Block VFs from clobbering special CGX PKIND state 15.08.2026
CVE-2026-74528 Bluetooth: hci_sync: hold conn in hci_past_sync() callback 15.08.2026
CVE-2026-74529 Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback 15.08.2026
CVE-2026-74530 Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback 15.08.2026
CVE-2026-74531 Bluetooth: hci_conn: hold conn reference in abort_conn_sync() 15.08.2026
CVE-2026-74532 Bluetooth: btintel: Validate length before parsing diagnostics TLV 15.08.2026
CVE-2026-74533 Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero 15.08.2026
CVE-2026-74534 Bluetooth: ISO: fix refcounting of iso_conn 15.08.2026
CVE-2026-74535 Bluetooth: ISO: avoid deadlocks in iso_sock_timeout 15.08.2026
CVE-2026-74536 Bluetooth: ISO: fix leaking sk after socket release 15.08.2026
CVE-2026-74537 Bluetooth: ISO: hold sk properly in iso_conn_ready 15.08.2026
CVE-2026-74538 Bluetooth: ISO: lock sk in iso_connect_ind 15.08.2026
CVE-2026-74539 Bluetooth: ISO: lock sk in iso_sock_getname 15.08.2026
CVE-2026-74540 Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp 15.08.2026
CVE-2026-74541 Bluetooth: ISO: clear iso_data always when detaching conn from hcon 15.08.2026
CVE-2026-74542 netfs: Fix folio_queue ENOMEM in writeback by adding a mempool 15.08.2026
CVE-2026-74543 net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() 15.08.2026
CVE-2026-74544 net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds 15.08.2026
CVE-2026-74545 rtase: fix double free of multi-frag skb on DMA map failure 15.08.2026
CVE-2026-74546 hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read 15.08.2026
CVE-2026-74547 hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread 15.08.2026
CVE-2026-74548 forcedeth: fix UAF of txrx_stats in nv_remove 15.08.2026
CVE-2026-74549 hwmon: (nct6775-core) Prevent access to unsupported weight registers 15.08.2026
CVE-2026-74550 net: do not send ICMP/NDISC Redirects when peer allocation fails 15.08.2026
CVE-2026-74551 hwmon: (nzxt-smart2) DMA-align output buffer 15.08.2026
CVE-2026-74552 hwmon: (lm90) Only report alarms if driver is ready 15.08.2026
CVE-2026-74553 hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 15.08.2026
CVE-2026-74554 wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() 15.08.2026
CVE-2026-74555 scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race 15.08.2026
CVE-2026-74556 scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer 15.08.2026
CVE-2026-74557 scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer 15.08.2026
CVE-2026-74558 xsk: reclaim invalid Tx descriptors in ZC batch path 15.08.2026
CVE-2026-74559 xsk: drain continuation descs after overflow in xsk_build_skb() 15.08.2026
CVE-2026-74560 xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx 15.08.2026
CVE-2026-74561 nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush 15.08.2026
CVE-2026-74562 nexthop: take nh->lock for f6i_list walks in replace check and notify 15.08.2026
CVE-2026-74563 rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() 15.08.2026
CVE-2026-74564 netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH 15.08.2026
CVE-2026-74565 netfilter: nf_tables: make nft_object rhltable per table 15.08.2026
CVE-2026-74566 keys: make keyring key-chunk byte order agree with keyring_diff_objects() 15.08.2026
CVE-2026-74567 keys: fix out-of-bounds read in keyring_get_key_chunk() 15.08.2026
CVE-2026-74568 KVM: arm64: vgic: Fix race between LPI release and re-registration 15.08.2026
CVE-2026-74569 netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() 15.08.2026
CVE-2026-74570 ntfs: harden runlist realloc size calculations 15.08.2026
CVE-2026-74571 btrfs: skip global block reserve accounting for rescue mounts 15.08.2026
CVE-2026-74572 btrfs: zoned: fix deadlock between metadata writeback and transaction commit 15.08.2026
CVE-2026-74573 iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE 15.08.2026
CVE-2026-74574 dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() 15.08.2026
CVE-2026-74575 thunderbolt: Prevent XDomain delayed work use-after-free on disconnect 15.08.2026
CVE-2026-74576 mm/slab: prevent unbounded recursion in free path with new kmalloc type 15.08.2026
CVE-2026-74577 net: mpls: initialize rtm_tos in mpls_getroute() 15.08.2026
CVE-2026-19894 itsourcecode Hospital Management System viewmedicine.php sql injection 15.08.2026
CVE-2026-73193 DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse 15.08.2026
CVE-2026-73194 DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse 15.08.2026
CVE-2026-19893 D-Link DIR-842 vsftpd vsftpd.conf default permission 15.08.2026
CVE-2026-12248 WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter 15.08.2026 6.5
CVE-2026-19891 TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption 15.08.2026
CVE-2026-73631 Apache Struts: Shared parsing state in the JSON plugin 15.08.2026
CVE-2026-73632 Apache Struts: Shared serialization state in the JSON plugin 15.08.2026
CVE-2026-73634 Apache Struts: Unbounded read of a Content Security Policy violation report 15.08.2026
CVE-2026-73635 Apache Struts: Unbounded growth of localized-text caches driven by the request locale 15.08.2026
CVE-2026-18438 Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch 15.08.2026 8.8
CVE-2026-15142 Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision 15.08.2026 7.5
CVE-2026-16142 TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter 15.08.2026 9.8