CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route 08.08.2026 9.8
CVE-2026-46409 OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution 07.08.2026 9.6
CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs 07.08.2026 9.2
CVE-2026-48170 scimPatch vulnerable to prototype pollution via unfiltered keys in patch 07.08.2026 9.1
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading 07.08.2026 9.6
CVE-2026-61808 LightRAG: Missing Authentication for Critical API Functions in Default Configuration 07.08.2026 9.8
CVE-2026-48039 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 07.08.2026 9.1
CVE-2026-71851 crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain 08.08.2026 9
CVE-2026-64637 07.08.2026 9.9
CVE-2022-4995 Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp 07.08.2026 9.3
CVE-2026-19264 Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover 07.08.2026 9.3
CVE-2026-66914 Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 07.08.2026 9.2
CVE-2026-54203 TeamDavid: Memory Leak leaking sensitive information 07.08.2026 9.2
CVE-2026-54210 TeamDavid: Buffer Overflow in file names of file upload functionalities 07.08.2026 9.5
CVE-2026-54211 TeamDavid: Buffer Overflow in multiple form data parameters 07.08.2026 9.5
CVE-2026-54212 TeamDavid: Buffer Overflow in JSON-parsing 07.08.2026 9.5
CVE-2026-54213 TeamDavid: Denial of Service via endpoint 'internalRestart' 07.08.2026 9.2
CVE-2026-14364 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' 07.08.2026 9.8
CVE-2026-14365 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' 07.08.2026 9.8
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability 07.08.2026 9.9
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability 07.08.2026 9.6
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability 08.08.2026 10
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability 07.08.2026 9.3
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability 07.08.2026 9.9
CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability 08.08.2026 9.8
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability 07.08.2026 9.6
CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability 07.08.2026 10
CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability 07.08.2026 10
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability 07.08.2026 9.1
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability 07.08.2026 9.6
CVE-2025-14561 Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allows Cross-Tenant Operations 07.08.2026 9
CVE-2026-11976 MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise 07.08.2026 10
CVE-2026-14812 Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) 07.08.2026 10
CVE-2026-17032 Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server 07.08.2026 9.8
CVE-2026-18367 07.08.2026 9.3
CVE-2026-3418 Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution 07.08.2026 9.1
CVE-2026-43629 llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore 07.08.2026 9.2
CVE-2026-43631 llama.cpp b7492–b9060 Use-After-Free RCE via llama-server 07.08.2026 9.2
CVE-2026-43632 llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints 08.08.2026 9.2
CVE-2026-48085 OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap 07.08.2026 9.8
CVE-2026-48086 OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN 07.08.2026 9.9
CVE-2026-48087 OpenReception: WebAuthn passkey injection allows account takeover 07.08.2026 9.8
CVE-2026-48088 OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory 08.08.2026 9.4
CVE-2026-53983 Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL 07.08.2026 9.2
CVE-2026-5857 Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments 08.08.2026 9.2
CVE-2026-70558 Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token 08.08.2026 9.3
CVE-2026-28005 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-28139 WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-53975 OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec 06.08.2026 9.3
CVE-2026-53976 OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter 06.08.2026 9.3
CVE-2026-54489 06.08.2026 9.1
CVE-2026-65507 WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-65508 WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65520 WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65546 WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-65548 WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.9
CVE-2026-65552 WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65553 WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) vulnerability 06.08.2026 10
CVE-2026-65556 WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65571 WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65572 WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65573 WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65574 WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65575 WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65576 WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65577 WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65578 WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65579 WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-65581 WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability 06.08.2026 9.8
CVE-2026-66447 WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability 06.08.2026 9.3
CVE-2026-66662 WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalation vulnerability 06.08.2026 9.8
CVE-2026-66665 WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability 06.08.2026 10
CVE-2026-66709 WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability 06.08.2026 9.1
CVE-2026-67261 06.08.2026 9.8
CVE-2026-12605 06.08.2026 9.6
CVE-2026-5134 SQLi in Loca Software's CMS 06.08.2026 9.8
CVE-2025-15039 Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products 06.08.2026 9.4
CVE-2026-1728 Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover 06.08.2026 9.8
CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover 06.08.2026 10
CVE-2026-64597 smb: client: fix double-free in SMB2_close() replay 08.08.2026 9.8
CVE-2026-67531 FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool 06.08.2026 9.3
CVE-2026-71319 Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution 07.08.2026 9.6
CVE-2026-48168 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name 05.08.2026 10
CVE-2026-20267 Cisco IOS XE Software Security Hardening Release 06.08.2026 9
CVE-2026-20272 Cisco IOS XE Software Security Hardening Release 06.08.2026 9.8
CVE-2026-20303 Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities 06.08.2026 9.9
CVE-2026-20304 Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities 06.08.2026 9.9
CVE-2026-20310 Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access 06.08.2026 9.1
CVE-2026-7329 Privilege escalation in Progress MarkLogic Server REST query interfaces 07.08.2026 9.9
CVE-2026-7557 SAML authentication bypass in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-8709 Privilege escalation in Progress MarkLogic Server REST document patch operation 07.08.2026 9.9
CVE-2026-9190 HTTP request smuggling in Progress MarkLogic Server 07.08.2026 9.1
CVE-2026-9192 Authentication bypass in Progress MarkLogic Server ODBC App Server 07.08.2026 9.8
CVE-2026-9193 Privilege escalation in Progress MarkLogic Server Hadoop integration 07.08.2026 9.9
CVE-2026-9195 Cross-site scripting in Progress MarkLogic Server Query Console 05.08.2026 9.3
CVE-2026-15587 Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header 05.08.2026 9.4
CVE-2026-39923 Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset 05.08.2026 9.2
CVE-2026-71262 IoTSharp BlobStorageController Missing Authentication and Path Traversal 05.08.2026 9.8
CVE-2026-71263 FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() 05.08.2026 9.1
CVE-2026-71267 microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() 05.08.2026 9.8
CVE-2026-71268 OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write 05.08.2026 9.9
CVE-2026-71277 rust-iot-platform Authentication Bypass via Non-Validated Authorization Header 05.08.2026 9.1
CVE-2026-71278 rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation 05.08.2026 9.8
CVE-2026-71289 NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API 05.08.2026 9.8
CVE-2026-71254 nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() 05.08.2026 9.8
CVE-2026-71256 nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id 05.08.2026 9.8
CVE-2026-66747 ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant 05.08.2026 9.3
CVE-2026-71231 IOTSmartHome: Unauthenticated SQL Injection via lastLogin Cookie 05.08.2026 9.8
CVE-2026-71237 Miantang IoT-PHP: Unauthenticated SQL Injection in /userlogin 05.08.2026 9.8
CVE-2026-71238 DjangoCRM: Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery 05.08.2026 9.1
CVE-2026-71248 Inventory-Management-System-PHP: Unauthenticated SQL Injection in Login and Product Deletion 05.08.2026 9.8
CVE-2026-44945 Cross-Cluster Impersonation Confused-Deputy Privilege Escalation 06.08.2026 9.1
CVE-2026-10059 Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token 05.08.2026 9.1
CVE-2026-10090 Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription 05.08.2026 9.9
CVE-2026-4431 Easy Post Submission <= 2.3.0 - Missing Authorization 05.08.2026 9.1
CVE-2026-64566 xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() 08.08.2026 9.8
CVE-2026-5581 Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Media Deletion 05.08.2026 9.1
CVE-2026-70376 Pluck CMS: CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE 05.08.2026 9.6
CVE-2026-71207 Stock-Inventory-Management-System: Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass 05.08.2026 9.8
CVE-2026-71213 typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force 05.08.2026 9.1
CVE-2026-71214 NASA-AMMOS plandev: Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server 05.08.2026 9.8
CVE-2026-9273 Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover 05.08.2026 9.3
CVE-2026-45537 OpenSIPS: Global Buffer Overflow in construct_uri 05.08.2026 9.1
CVE-2026-45100 OpenSIPS: Buffer Overflow in Base64 Encode Transformation 05.08.2026 9.1
CVE-2026-45538 OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy 05.08.2026 9.8
CVE-2026-70554 MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie 05.08.2026 9.3
CVE-2026-70477 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability 05.08.2026 9.5
CVE-2026-70478 Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service 05.08.2026 9.2
CVE-2026-70552 MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php 05.08.2026 9.3
CVE-2026-70553 MaxSite CMS Unauthenticated RCE via Install Endpoint 05.08.2026 9.3
CVE-2017-20241 Keysight IxChariot Endpoint heap-based buffer overflow 04.08.2026 9.3
CVE-2017-20242 Keysight IxChariot Endpoint stack-based buffer overflow 04.08.2026 9.3
CVE-2026-49435 Keysight IxChariot-related products stack-based buffer overflow 04.08.2026 9.3
CVE-2026-69703 Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit 04.08.2026 9.3
CVE-2026-24254 04.08.2026 9.8
CVE-2026-69264 Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation 04.08.2026 9.4
CVE-2026-70470 Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE 04.08.2026 9.5
CVE-2026-63455 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-63456 Authentication bypass via spoofed HTTP headers Orchestrator REST API 04.08.2026 9.8
CVE-2026-58072 05.08.2026 9
CVE-2026-58073 05.08.2026 9.5
CVE-2026-64633 05.08.2026 10
CVE-2026-69255 Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified 04.08.2026 9.2
CVE-2026-69256 Flowise: Remote Code Execution Vulnerability in CSVAgent 05.08.2026 9.4
CVE-2026-69259 Flowise RCE via SQLite Record Manager Node 04.08.2026 9.4
CVE-2026-18801 Stored Clickhouse SQL Injection Through Customer Usage Attribution 04.08.2026 9.3
CVE-2026-25289 Stack-based Buffer Overflow in WLAN Firmware 05.08.2026 9.6
CVE-2026-69098 kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization 05.08.2026 9.3
CVE-2026-69110 OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music 04.08.2026 9.3
CVE-2026-69253 Flowise Sandbox Escape to RCE 05.08.2026 9
CVE-2026-69254 Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override 04.08.2026 9.4
CVE-2026-61514 Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 04.08.2026 9.3
CVE-2026-61515 Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell 05.08.2026 9.3
CVE-2026-69251 Flowise RCE via TypeORM DataSource 04.08.2026 9
CVE-2026-60007 04.08.2026 9.1
CVE-2026-14175 Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-14804 Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.1
CVE-2026-15721 Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMANIST Digital Human Resources 04.08.2026 9.8
CVE-2026-18753 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) 04.08.2026 9.1
CVE-2026-18754 Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) 04.08.2026 9.1
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing 08.08.2026 9.8
CVE-2026-18686 GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection 04.08.2026 9.3
CVE-2026-18685 GL.iNet GL-MT3000 modem.so glc set_upgrade command injection 04.08.2026 9.3
CVE-2026-18684 GL.iNet GL-MT3000 modem.so glc remove_profile command injection 04.08.2026 9.3
CVE-2026-48317 Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 04.08.2026 9.6
CVE-2026-48323 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 04.08.2026 10
CVE-2026-48326 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 04.08.2026 9.9
CVE-2026-48330 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 05.08.2026 10
CVE-2026-48331 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 04.08.2026 10
CVE-2026-48333 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 04.08.2026 9.8
CVE-2026-18667 Sensor Proxy Version 1.4.2 Fixes One Vulnerability 05.08.2026 9.3
CVE-2026-46713 Misskey: JSON-LD signature validation + compaction may lead to improper activity handling 04.08.2026 9.2
CVE-2026-48063 Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload 04.08.2026 9.3
CVE-2026-69240 Sequelize: SQL Injection (Oracle DB) 04.08.2026 9.8
CVE-2026-48031 Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery 03.08.2026 9.1
CVE-2026-67598 Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php 04.08.2026 9.1
CVE-2026-18616 GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection 04.08.2026 9.3
CVE-2026-18614 GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection 03.08.2026 9.3
CVE-2026-18615 GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection 03.08.2026 9.3
CVE-2026-18612 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection 03.08.2026 9.3
CVE-2026-18613 GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection 03.08.2026 9.3
CVE-2026-18602 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection 03.08.2026 9.3
CVE-2026-39932 OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection 03.08.2026 9.4
CVE-2026-41452 Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup 03.08.2026 9.3
CVE-2026-18248 @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header 03.08.2026 9.1
CVE-2026-18601 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection 03.08.2026 9.3
CVE-2026-64827 Telenia TVox 26.5.3 Authentication Bypass via set_env.php 07.08.2026 9.3
CVE-2026-68584 SiYuan before v3.7.3 Authentication Bypass via Content Endpoints 03.08.2026 9.2
CVE-2026-68586 SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc 03.08.2026 9.2
CVE-2026-68587 SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction 03.08.2026 9.2
CVE-2026-69083 SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent 03.08.2026 9.9
CVE-2026-69084 SiYuan before v3.7.3 SQL Injection via searchEmbedBlock 03.08.2026 9.9
CVE-2026-69085 SiYuan before v3.7.3 SQL Injection via searchDocs 03.08.2026 9.9
CVE-2026-18574 Authentication Bypass in Check Point Security Management Server 05.08.2026 9.3
CVE-2026-2346 IDOR in Menulux Software's Mobile App 03.08.2026 9.8
CVE-2026-33591 Authentication bypass on WaptServer 03.08.2026 10
CVE-2026-18588 Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow 03.08.2026 9.3
CVE-2026-18589 Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow 03.08.2026 9.3
CVE-2026-58062 Stapled OCSP response accepted without binding to the checked certificate 03.08.2026 9.3
CVE-2026-59638 JSSE hostname verifier CN-fallback enabled by default despite documented opt-in 03.08.2026 9.3
CVE-2026-59650 MTI/A0 DH agreement exponentiates unvalidated peer value 03.08.2026 9.3
CVE-2026-8763 Name Constraints bypass via trailing dot in rfc822Name and URI 03.08.2026 9.3
CVE-2026-65321 PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS 06.08.2026 9.3
CVE-2025-71401 better-auth before 1.4.2 basePath Modification DoS 03.08.2026 9.3
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token 03.08.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-42170 Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c) 08.08.2026
CVE-2026-19287 abrinsmead mindpilot-mcp HistoryService path traversal 08.08.2026
CVE-2026-19288 astralisone rive-mcp-server-core importRiveFile Flow importRiveFile.ts path traversal 08.08.2026
CVE-2026-19284 MauricioMilano coder-api Projects Endpoint projects.ts createProject command injection 08.08.2026
CVE-2026-19285 aaronsb memory-graph memoryTools.ts JsonMemoryStorage.saveMemories path traversal 08.08.2026
CVE-2026-19282 andreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injection 08.08.2026
CVE-2026-19281 adolfosalasgomez3011 slidev-builder-mcp generateAssets Tool generateAssets.ts generateChart command injection 08.08.2026
CVE-2026-19279 MIMICLab mcp-pdf-vision index.ts load_pdf command injection 08.08.2026
CVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state 08.08.2026
CVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers() 08.08.2026
CVE-2026-19268 abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection 08.08.2026
CVE-2026-19270 Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal 08.08.2026
CVE-2026-19266 Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection 08.08.2026
CVE-2026-19263 INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection 08.08.2026
CVE-2026-14526 AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route 08.08.2026 9.8
CVE-2026-16267 Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field 08.08.2026
CVE-2026-16269 Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling 08.08.2026
CVE-2026-16282 Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter 08.08.2026
CVE-2026-16535 Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel 08.08.2026
CVE-2026-16558 YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema 08.08.2026
CVE-2026-16559 YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload 08.08.2026
CVE-2026-16562 WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers 08.08.2026
CVE-2026-16574 Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint 08.08.2026
CVE-2026-16578 Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route 08.08.2026
CVE-2026-16589 WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter 08.08.2026
CVE-2026-16590 WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure 08.08.2026
CVE-2026-16594 WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure 08.08.2026
CVE-2026-16595 WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure 08.08.2026
CVE-2026-16608 Download Monitor < 5.2.6 - Unauthenticated Download Log Injection 08.08.2026
CVE-2026-16948 Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure 08.08.2026
CVE-2026-16953 AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie 08.08.2026
CVE-2026-16955 AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription 08.08.2026
CVE-2026-19259 MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow 08.08.2026
CVE-2026-18988 Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute 08.08.2026 6.4