CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector 28.08.2026 9.4
CVE-2026-18918 OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default 28.08.2026 9.1
CVE-2026-42007 28.08.2026 9.1
CVE-2026-82222 WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability 28.08.2026 10
CVE-2026-82244 Budibase before 3.41.3 Remote Code Execution via Plugin eval() 28.08.2026 9.4
CVE-2026-40541 28.08.2026 9
CVE-2026-76581 WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion 28.08.2026 9.8
CVE-2026-78032 28.08.2026 9.3
CVE-2026-82082 Green-Computing|NUMail - OS Command Injection 28.08.2026 9.3
CVE-2026-82090 28.08.2026 9.2
CVE-2026-13086 Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint 27.08.2026 9.3
CVE-2026-19313 Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution 27.08.2026 9.3
CVE-2026-19315 Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution 27.08.2026 9.3
CVE-2026-19318 Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution 27.08.2026 9.3
CVE-2026-61800 Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893) 27.08.2026 9.1
CVE-2026-78174 WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs 27.08.2026 9.3
CVE-2026-18717 Improper Certificate Validation in ASE 2000 27.08.2026 9.1
CVE-2026-50152 Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users 28.08.2026 9.1
CVE-2026-68929 FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization 27.08.2026 9.3
CVE-2026-69658 Ebyte NE2-D11 Cleartext Transmission of Sensitive Information 28.08.2026 9.3
CVE-2026-71187 Ebyte NE2-D11 Use of Client-Side Authentication 28.08.2026 9.3
CVE-2026-73125 Ebyte NE2-D11 Missing Authentication for Critical Function 28.08.2026 9.3
CVE-2026-76179 Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings 28.08.2026 9.3
CVE-2026-76943 Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel 28.08.2026 9.3
CVE-2026-78239 Xiiaozet LK100W Missing Authentication for Critical Function 28.08.2026 9.3
CVE-2026-18885 Unauthenticated Remote Code Execution in GraphQL Composite Data API 28.08.2026 10
CVE-2026-18886 Unauthenticated Privilege Escalation via System Configuration Image Upload Processor 27.08.2026 10
CVE-2026-19092 Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing 28.08.2026 9.8
CVE-2026-48996 Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client 27.08.2026 9.3
CVE-2026-53578 Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml 27.08.2026 9.3
CVE-2026-53579 Trilium: Note Import to RCE via Book Note 27.08.2026 9.3
CVE-2026-74820 Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause 27.08.2026 10
CVE-2026-81934 Redis TLS pending-data list use-after-free 28.08.2026 9.2
CVE-2026-16279 Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x 27.08.2026 9.3
CVE-2026-57499 Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) 27.08.2026 9.1
CVE-2026-81094 mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring Authentication 27.08.2026 9.3
CVE-2026-81096 ToolUniverse through 1.2.6 Unauthenticated Remote Code Execution via python_code_executor Sandbox Escape 27.08.2026 9.3
CVE-2026-81098 Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport 27.08.2026 9.3
CVE-2026-81680 openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal 27.08.2026 9.3
CVE-2026-81681 openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage 27.08.2026 9.3
CVE-2026-81685 openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata 27.08.2026 9.3
CVE-2026-81694 verify-usb before 1.4.9 Output Injection via Unsanitized Filenames 27.08.2026 9.3
CVE-2026-81695 openssl_encrypt before 1.4.9 Terminal Injection via key_id 27.08.2026 9.3
CVE-2026-81696 openssl_encrypt before 1.4.9 Terminal Injection via info Command 27.08.2026 9.3
CVE-2026-81698 openssl_encrypt before 1.4.9 Shell Injection via info command 27.08.2026 9.3
CVE-2026-81700 openssl_encrypt before 1.4.9 GPG Signature Verification Bypass 27.08.2026 9.3
CVE-2026-81701 openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin 27.08.2026 9.3
CVE-2026-81702 openssl_encrypt before 1.4.9 Key Substitution via Identity Load 27.08.2026 9.3
CVE-2026-81706 openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing 27.08.2026 9.3
CVE-2026-81707 openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email 27.08.2026 9.3
CVE-2026-81714 openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass 27.08.2026 9.3
CVE-2026-81717 openssl_encrypt before 1.4.9 Integrity Bypass via Added Files 27.08.2026 9.3
CVE-2026-81719 openssl_encrypt before 1.4.9 Remote Code Execution via Plugin 27.08.2026 9.3
CVE-2026-81735 UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution 27.08.2026 10
CVE-2026-81826 Flowintel Fails to Invalidate Active Sessions After Password Change 27.08.2026 9.1
CVE-2026-74232 Zbtlink MQWrt yunmgrd Cloud C2 Implant 27.08.2026 9.3
CVE-2026-74233 Zbtlink MQWrt infosrvd Command Injection 27.08.2026 9.3
CVE-2026-81672 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81673 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81674 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-81675 Multiple Vulnerabilities in TOOOLS' iSquad 27.08.2026 9.3
CVE-2026-32479 WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulnerability 27.08.2026 9.3
CVE-2026-32566 WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation vulnerability 27.08.2026 9.8
CVE-2026-59354 Spring Security OAuth2 Authorization Server: Insufficient validation of Dynamic Client Registration metadata 28.08.2026 9.6
CVE-2026-78260 WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability 27.08.2026 9.3
CVE-2026-78274 WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerability 27.08.2026 9.1
CVE-2026-78286 WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability 27.08.2026 9.8
CVE-2026-78288 WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerability 27.08.2026 9.3
CVE-2026-78292 WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability 27.08.2026 9.8
CVE-2026-59270 Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces 28.08.2026 9.4
CVE-2026-77991 Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 28.08.2026 9.4
CVE-2026-65956 KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF 26.08.2026 10
CVE-2026-65641 27.08.2026 9.3
CVE-2026-60004 26.08.2026 9.8
CVE-2026-19485 Bucket Squatting in Vertex AI Search for Commerce 26.08.2026 9.3
CVE-2026-70419 26.08.2026 9.1
CVE-2026-54569 SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core 26.08.2026 9.8
CVE-2026-80428 ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint 26.08.2026 9.3
CVE-2026-81032 NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration 26.08.2026 9.3
CVE-2026-75062 Eval Injection in google/langfun via default lf.query protocol 27.08.2026 9.2
CVE-2026-74737 net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG 27.08.2026 9.8
CVE-2026-74743 macvlan: inherit needed_headroom and needed_tailroom from lowerdev 27.08.2026 9.8
CVE-2026-74744 ipvlan: inherit needed_headroom and needed_tailroom from phy_dev 27.08.2026 9.8
CVE-2026-74746 netfilter: flowtable: publish GC-visible tuple last 27.08.2026 9.8
CVE-2026-74751 riscv: lib: Fix ZBB strnlen reading past count boundary 27.08.2026 9.4
CVE-2026-74752 sctp: validate cookie AUTH state before use 27.08.2026 9.8
CVE-2026-80519 ovpn: finish crypto callback cleanup before peer release 27.08.2026 9.8
CVE-2026-80528 ceph: avoid fs reclaim while using current->journal_info 27.08.2026 9.8
CVE-2026-80551 s390/vfio_ccw: Ensure first IDAW remains constant 27.08.2026 9.3
CVE-2026-80554 s390/vfio_ccw: Limit the number of channel program segments 27.08.2026 9.3
CVE-2026-80557 libceph: fix OOB read in decode_watchers() via missing bounds check 27.08.2026 9.8
CVE-2026-80558 libceph: Avoid using invalid osd indices from primary_temp 27.08.2026 9.8
CVE-2026-80561 libceph: fix multiple unsafe decodes in decode_locker() 27.08.2026 9.8
CVE-2026-80585 mptcp: fastopen: only mark MPTFO subflows with SYN data 27.08.2026 9.4
CVE-2026-80586 mptcp: options: reset DSS fields in case of unexpected size 27.08.2026 9.8
CVE-2026-80587 mptcp: avoid combining some incoming suboptions 27.08.2026 9.8
CVE-2026-80589 block: stop the timeout timer when releasing a never added disk 27.08.2026 9.8
CVE-2026-54523 Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system 26.08.2026 9.6
CVE-2026-75896 Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk 26.08.2026 9.1
CVE-2026-12717 Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection 26.08.2026 9.4
CVE-2026-18080 ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment 26.08.2026 9.8
CVE-2026-77532 26.08.2026 9.6
CVE-2026-77554 26.08.2026 10
CVE-2026-77557 26.08.2026 9.8
CVE-2026-77549 27.08.2026 9
CVE-2026-77550 27.08.2026 10
CVE-2026-77551 26.08.2026 9
CVE-2026-77552 26.08.2026 9.8
CVE-2026-77553 26.08.2026 9.9
CVE-2026-77546 26.08.2026 9.9
CVE-2026-77547 26.08.2026 9.9
CVE-2026-77548 26.08.2026 9.9
CVE-2026-80203 Grav before 1.0.18 Authentication Bypass via Scoped API Key 26.08.2026 9.3
CVE-2026-80204 Grav before 1.0.18 Authentication Bypass via Scoped API Key 26.08.2026 9.3
CVE-2026-77542 26.08.2026 9.1
CVE-2026-77543 26.08.2026 9.9
CVE-2026-77545 27.08.2026 9
CVE-2026-80349 TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter 26.08.2026 9.3
CVE-2026-77539 27.08.2026 9.1
CVE-2026-77540 27.08.2026 9.1
CVE-2026-77541 26.08.2026 9.1
CVE-2026-59683 OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings 26.08.2026 9.3
CVE-2026-77535 26.08.2026 9.1
CVE-2026-77536 27.08.2026 9.9
CVE-2026-77537 26.08.2026 10
CVE-2026-77534 27.08.2026 9.9
CVE-2026-77533 26.08.2026 9.9
CVE-2026-80235 Thinking Software Technology|EFence - Arbitrary File Upload 26.08.2026 9.3
CVE-2026-18431 Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write 27.08.2026 9.8
CVE-2026-15203 Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software 26.08.2026 9.3
CVE-2026-19632 TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure 26.08.2026 9.8
CVE-2026-80202 Kimai before 2.56.0 Authorization Bypass via TimesheetVoter 26.08.2026 9.3
CVE-2026-79911 TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow 27.08.2026 10
CVE-2026-80138 ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter 26.08.2026 9.2
CVE-2026-62862 TypeBot: Account takeover via brute-forceable 6-digit magic-link code 26.08.2026 9.1
CVE-2026-65083 26.08.2026 9.9
CVE-2026-65093 26.08.2026 9.9
CVE-2026-80104 DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename 25.08.2026 9.3
CVE-2026-45018 Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution 25.08.2026 9.8
CVE-2026-78379 Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools 25.08.2026 9.2
CVE-2026-79787 Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature 25.08.2026 9.3
CVE-2026-76193 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 27.08.2026 10
CVE-2026-76195 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 27.08.2026 10
CVE-2026-76197 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 27.08.2026 10
CVE-2026-55640 Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) 25.08.2026 9.1
CVE-2022-51000 Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxslt 28.08.2026 9.3
CVE-2024-58377 Nokogiri before 1.16.5 libxml2 Dependency Update 28.08.2026 9.3
CVE-2024-58378 Nokogiri before 1.16.2 Use-After-Free via xmlTextReader 28.08.2026 9.3
CVE-2025-71407 Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free 25.08.2026 9.3
CVE-2026-55536 Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) 25.08.2026 9.1
CVE-2026-55546 QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input 25.08.2026 9.8
CVE-2026-79675 NLTK before 3.10.3 JVM Argument Injection via Per-Call Options 27.08.2026 9.3
CVE-2026-79774 Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy 26.08.2026 9.3
CVE-2026-79782 rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect 25.08.2026 9.3
CVE-2026-16286 File Upload in TRTEK Software's Software Repository Management 25.08.2026 9.8
CVE-2026-77998 Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 26.08.2026 10
CVE-2026-57909 WatchGuard Agent path traversal allows unauthenticated remote code execution 26.08.2026 9.4
CVE-2026-57910 WatchGuard Agent improper authentication allows unauthenticated remote code execution 25.08.2026 9.3
CVE-2026-79657 NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization 25.08.2026 9.3
CVE-2026-79664 Ech0 before 4.7.3 Access Token Revocation Bypass 25.08.2026 9.1
CVE-2026-78570 Total Donations <= 2.0.5 - Unauthenticated Privilege Escalation 27.08.2026 9.8
CVE-2026-63586 Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface 25.08.2026 9.3
CVE-2026-77136 Server-Side Template Injection in extension "powermail" (powermail) 25.08.2026 9.5
CVE-2026-77138 Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail) 25.08.2026 9.3
CVE-2026-78568 Total Donations <= 2.0.5 - Unauthenticated SQL Injection 25.08.2026 9.8
CVE-2026-78477 Jawn <= 1.4.2 - Unauthenticated Privilege Escalation 25.08.2026 9.8
CVE-2026-13214 Stack buffer overflow in OCPP GetConfiguration key parsing 25.08.2026 9.8
CVE-2026-56705 Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection 25.08.2026 9.3
CVE-2026-56710 Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock 25.08.2026 9.3
CVE-2026-72699 Grav Login Plugin before 3.9.1 Email Enumeration via Registration 25.08.2026 9.3
CVE-2026-72702 Grav CMS before 2.0.16 Origin Validation Bypass via Referer 25.08.2026 9.3
CVE-2026-78676 GitPython before 3.1.59 Remote Code Execution via Config Injection 26.08.2026 9.3
CVE-2026-78683 NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization 25.08.2026 9.4
CVE-2026-32554 WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability 25.08.2026 9.3
CVE-2026-32555 WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability 25.08.2026 9.3
CVE-2026-32559 WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability 27.08.2026 9.9
CVE-2026-32563 WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability 25.08.2026 9.8
CVE-2026-77337 CakePHP: Potential Authentication bypass with CookieAuthenticator 25.08.2026 9.1
CVE-2026-78262 WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability 27.08.2026 9.8
CVE-2026-78265 WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability 25.08.2026 9.8
CVE-2026-78267 WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability 27.08.2026 9.8
CVE-2026-77635 CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver 25.08.2026 9.2
CVE-2026-78555 RansomLook API Key Disclosure Through /admin/apikeys HTML Source 24.08.2026 9.4
CVE-2026-39975 Combodo iTop: Remote code execution using external auth variable value 24.08.2026 9.4
CVE-2026-76835 OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy Set 24.08.2026 9.3
CVE-2026-71914 DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm 24.08.2026 9.3
CVE-2026-71921 DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi 27.08.2026 9.3
CVE-2025-36939 24.08.2026 10
CVE-2026-77915 rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php 26.08.2026 9.3
CVE-2026-76070 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter 24.08.2026 9.3
CVE-2026-76071 Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter 26.08.2026 9.3
CVE-2026-78387 RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification 24.08.2026 9.4
CVE-2026-59568 Remote Code Execution 25.08.2026 9.1
CVE-2026-67602 phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache 24.08.2026 9.3
CVE-2026-59564 Authentication bypass between ZCC and client connector portal 25.08.2026 9.1
CVE-2026-77995 Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 25.08.2026 10
CVE-2026-78370 RansomLook Unauthenticated Database Export Exposes Private Data 24.08.2026 9.2
CVE-2026-78372 RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data 24.08.2026 9.2
CVE-2026-78365 IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification 24.08.2026 9.3
CVE-2026-28165 WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-32551 WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability 24.08.2026 9.3
CVE-2026-32558 WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66587 WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability 24.08.2026 9.8
CVE-2026-66648 WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability 24.08.2026 9.8
CVE-2026-66650 WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability 24.08.2026 9.8
CVE-2026-66897 Instance template path traversal allows arbitrary host file write as root 25.08.2026 9.9
CVE-2026-77994 Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 25.08.2026 9.3
CVE-2026-78251 DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory 27.08.2026 9.3
CVE-2026-78211 4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection 24.08.2026 9.3
CVE-2026-78168 EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication 27.08.2026 9.3
CVE-2026-78169 UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow 24.08.2026 9.4
CVE-2026-78167 EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication 24.08.2026 10
CVE-2026-78207 exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization 24.08.2026 9.3
CVE-2026-5388 justhtml before 1.15.0 Multiple Security Issues 26.08.2026 9.3
CVE-2026-7808 justhtml before 1.16.0 Multiple Security Issues via Sanitization 24.08.2026 9.3
CVE-2026-8445 justhtml before 1.12.0 Sanitizer Bypass via Markdown 24.08.2026 9.3
CVE-2026-78155 Untrusted Search Path in StackGres 24.08.2026 9.9
CVE-2026-78050 Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow 24.08.2026 9.4
CVE-2026-4703 WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission 24.08.2026 9.8
CVE-2026-74586 sctp: clear new_transport when removing a peer 25.08.2026 9.8
CVE-2026-74587 sctp: fix use-after-free of cached ASCONF chunk 25.08.2026 9.8
CVE-2026-74588 sctp: keep chunk->transport in step with the list it is queued on 25.08.2026 9.8
CVE-2026-74591 mm/filemap: __filemap_add_folio() restore index before retrying 25.08.2026 9.8
CVE-2026-74597 ip6_tunnel: clear skb2->cb[] in ip6ip6_err() 25.08.2026 9.8
CVE-2026-74608 smb: client: Fix use-after-free in cifs_try_adding_channels() 25.08.2026 9.8
CVE-2026-74611 tls: rx: restore msg_iter before TLS 1.3 optimistic retry 25.08.2026 9.8
CVE-2026-74612 veth: fix skb length accounting after XDP frag adjustment 25.08.2026 10
CVE-2026-74616 xdp: reject clones that overrun skb_shared_info tailroom 25.08.2026 9.8
CVE-2026-74617 dibs: initialise dibs->lock in dibs_dev_alloc() 25.08.2026 9.8
CVE-2026-74628 net/x25: fix use-after-free of the socket by its timers 27.08.2026 9.8
CVE-2026-74662 inet: frags: publish queues before arming timer 27.08.2026 9.8
CVE-2026-74665 net: fix skb length accounting after generic XDP frag adjustment 25.08.2026 9.1
CVE-2026-74669 ipvs: clear IPv4 options after rebasing tunnel ICMP errors 25.08.2026 9.8
CVE-2026-74688 sctp: clear control chunk transport if it is being removed 25.08.2026 9.8
CVE-2026-74705 udp: fix potential use-after-free in tunnel segmentation 25.08.2026 10
CVE-2026-74712 vdpa/mlx5: Fix buffer length in create_direct_keys() 25.08.2026 9.3
CVE-2026-74723 btrfs: lzo: reject inline extents without valid headers 25.08.2026 9.8
CVE-2026-74727 ovpn: skip rehash for peers already removed from by_id 25.08.2026 9.8
CVE-2026-74730 NFS: Pin the 'struct nfs_server' during a FREE_STATEID call 25.08.2026 9.8
CVE-2026-63310 NLTK before 3.9.3 Missing Post-Download Integrity Verification 24.08.2026 9.3
CVE-2026-76571 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 25.08.2026 9.3
CVE-2026-76602 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 24.08.2026 9.3
CVE-2026-76604 Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76605 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76606 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-76607 Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2 24.08.2026 10
CVE-2026-77992 Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 24.08.2026 9.5
CVE-2026-77946 TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow 26.08.2026 10
CVE-2026-78003 Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys 25.08.2026 9.8
CVE-2026-12710 Missing Authorization in Application Integration QueryEngineTask 26.08.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-13761 Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping. 28.08.2026
CVE-2026-14942 28.08.2026
CVE-2026-15603 morgan vulnerable to Log Forging via unescaped Unicode line separators 28.08.2026 5.3
CVE-2026-19412 Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router 28.08.2026
CVE-2026-37236 28.08.2026
CVE-2026-37237 28.08.2026
CVE-2026-37710 28.08.2026
CVE-2026-37736 28.08.2026
CVE-2026-37751 28.08.2026
CVE-2026-38093 28.08.2026
CVE-2026-38636 28.08.2026
CVE-2026-38638 28.08.2026
CVE-2026-38725 28.08.2026
CVE-2026-3423 Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description 28.08.2026 6.4
CVE-2026-4378 Stored XSS in Akıllı Ticaret's E-Commerce Pack 28.08.2026 5.4
CVE-2026-50979 28.08.2026
CVE-2026-56854 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh 28.08.2026
CVE-2026-58106 Incomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into fullPath+2, writing 2 bytes past the buffer on every CodeChecker log invocation 28.08.2026
CVE-2026-58107 Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun 28.08.2026
CVE-2026-5096 Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value' 28.08.2026 5.3
CVE-2026-5800 Reflected XSS in Dayneks Software's E-Commerce Platform 28.08.2026 6.1
CVE-2026-5934 WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint 28.08.2026 7.2
CVE-2026-5953 Reflected XSS in Ceviz Informatics's Web Design 28.08.2026 6.1
CVE-2026-6176 Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form 28.08.2026 7.2
CVE-2026-75758 Unbounded recursion between Inspect.List charlist rendering and List.to_string/1 error path in Elixir 28.08.2026
CVE-2026-81019 wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record 28.08.2026 7.4
CVE-2026-81020 wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record 28.08.2026 7.4
CVE-2026-81284 WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability 28.08.2026 4.3
CVE-2026-81285 WordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial of Service Attack vulnerability 28.08.2026 7.5
CVE-2026-81299 WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (IDOR) vulnerability 28.08.2026 4.3
CVE-2026-81341 wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records 28.08.2026 6.5
CVE-2026-81578 PaperCut MF/NG: Authentication Bypass 28.08.2026
CVE-2026-81757 WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerability 28.08.2026 7.2
CVE-2026-81759 WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability 28.08.2026 5.4
CVE-2026-81760 WordPress JetEngine plugin <= 3.8.14.2 - Cross Site Scripting (XSS) vulnerability 28.08.2026 7.1
CVE-2026-81761 WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability 28.08.2026 4.3
CVE-2026-81767 WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability 28.08.2026 7.5
CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector 28.08.2026
CVE-2026-82112 houtini-ai houtini-lm code_task_files index.ts path traversal 28.08.2026
CVE-2026-82181 Le-yan|Medical Practice Management System - Sensitive Data in URL 28.08.2026
CVE-2026-82220 WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability 28.08.2026 5.3
CVE-2026-82227 WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability 28.08.2026 8.5
CVE-2026-82324 Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0 28.08.2026
CVE-2026-82327 Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data 28.08.2026
CVE-2026-82328 Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count 28.08.2026
CVE-2026-82330 Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check 28.08.2026
CVE-2026-18393 Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursor 28.08.2026
CVE-2026-18918 OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default 28.08.2026
CVE-2026-27852 28.08.2026 7.5
CVE-2026-33263 28.08.2026 4.3
CVE-2026-33604 28.08.2026 5.9
CVE-2026-33605 28.08.2026 7.5
CVE-2026-33606 28.08.2026 4.8
CVE-2026-33607 28.08.2026 4.3
CVE-2026-40013 28.08.2026 4.3
CVE-2026-40014 28.08.2026 6.5
CVE-2026-40015 28.08.2026 4.3
CVE-2026-40017 28.08.2026 6.5
CVE-2026-40018 28.08.2026 7.4
CVE-2026-40019 28.08.2026 5.9
CVE-2026-40203 28.08.2026 3.7
CVE-2026-40204 28.08.2026 3.1
CVE-2026-40205 28.08.2026 5.9
CVE-2026-42007 28.08.2026 9.1
CVE-2026-42008 28.08.2026 4.3
CVE-2026-42391 28.08.2026 7.5
CVE-2026-42392 28.08.2026 4.3
CVE-2026-42393 28.08.2026 3.1
CVE-2026-42395 28.08.2026 4.3
CVE-2026-52681 28.08.2026 3.1
CVE-2026-52687 28.08.2026 6.5
CVE-2026-5510 GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 28.08.2026 6.4
CVE-2026-6128 All-in-One WP Migration Unlimited Extension <= 2.84 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ai1wm_backups_path' Parameter 28.08.2026 6.4
CVE-2026-73208 28.08.2026 7.4
CVE-2026-73209 28.08.2026 6.5
CVE-2026-78070 Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 28.08.2026
CVE-2026-78071 Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 28.08.2026
CVE-2026-78072 Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1 28.08.2026
CVE-2026-78073 Joomla Extension - j2commerce.com - Reflected XSS attribute in All Video Share 1.0.0-4.5.0 28.08.2026
CVE-2026-81732 WWBN AVideo through 30.0 Information Disclosure via report4.json.php 28.08.2026
CVE-2026-81733 WWBN AVideo through 30.0 CSRF via myLiveControls.save.json.php 28.08.2026
CVE-2026-81777 WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerability vulnerability 28.08.2026 5.3
CVE-2026-82111 iswalle getnote-mcp upload_image index.ts fs.readFileSync path traversal 28.08.2026
CVE-2026-82222 WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability 28.08.2026 10
CVE-2026-82233 SiYuan before v3.8.1 Path Traversal via asset.upload 28.08.2026
CVE-2026-82234 SiYuan before v3.8.1 SSRF via DNS-Rebinding TOCTOU 28.08.2026
CVE-2026-82235 filebrowser through 2.63.23 Denial of Service via named pipes 28.08.2026
CVE-2026-82236 File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion 28.08.2026
CVE-2026-82237 filebrowser through 2.63.23 Stale Share Link via File Rename 28.08.2026
CVE-2026-82238 filebrowser 2.24.0 Race Condition via TUS concurrent PATCH uploads 28.08.2026
CVE-2026-82239 Budibase before 3.41.3 Authorization Bypass via datasources/query 28.08.2026
CVE-2026-82240 Budibase before 3.41.3 Privilege Escalation via User Update API 28.08.2026
CVE-2026-82241 Budibase backend-core SSRF via incomplete default blacklist 28.08.2026
CVE-2026-82242 Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization 28.08.2026
CVE-2026-82243 Budibase Server before 3.41.3 SSRF with Credential Leakage 28.08.2026
CVE-2026-82244 Budibase before 3.41.3 Remote Code Execution via Plugin eval() 28.08.2026
CVE-2026-82245 Budibase before 3.41.3 Missing Authorization License Management 28.08.2026
CVE-2026-82246 Budibase Server before 3.41.3 SSRF via Query Import 28.08.2026
CVE-2026-82247 gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing 28.08.2026
CVE-2026-82248 gitoxide before 0.33.0 Path Traversal via symlink following 28.08.2026
CVE-2026-82249 gitoxide before 0.38.2 Credential Helper Protocol Field Injection 28.08.2026
CVE-2026-82250 gitoxide gix-packetline before 0.21.5 Denial of Service 28.08.2026
CVE-2026-82251 gitoxide before 0.52.1 Path Traversal via Submodule Name 28.08.2026
CVE-2026-82252 gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules 28.08.2026
CVE-2026-82253 gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass 28.08.2026
CVE-2026-82254 gitoxide before 0.69.0 Denial of Service via gix-pack 28.08.2026
CVE-2026-82255 gitoxide 0.25.4 HTTP Credential Leak via Redirect 28.08.2026
CVE-2026-82256 SvelteKit before 2.69.1 Denial of Service via Remote Form 28.08.2026
CVE-2026-82257 SvelteKit before 2.69.1 Prototype Pollution via File Input 28.08.2026
CVE-2026-82258 SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch 28.08.2026
CVE-2026-82259 SvelteKit 2.49.0 before 2.53.3 Denial of Service via form 28.08.2026
CVE-2026-82260 SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization 28.08.2026
CVE-2026-82261 SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization 28.08.2026
CVE-2026-12513 Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal 28.08.2026
CVE-2026-12514 Shared Files < 1.7.70 - Unauthenticated Limited File Upload 28.08.2026
CVE-2026-14558 WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder 28.08.2026
CVE-2026-14567 WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure via User Directory 28.08.2026
CVE-2026-19084 Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read 28.08.2026
CVE-2026-19423 Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms 28.08.2026
CVE-2026-40541 28.08.2026 9
CVE-2026-4246 ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter 28.08.2026 6.1
CVE-2026-5097 wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter 28.08.2026 7.5
CVE-2026-6286 Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission 28.08.2026 7.2
CVE-2026-73827 28.08.2026
CVE-2026-76581 WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion 28.08.2026 9.8
CVE-2026-77701 WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders 28.08.2026
CVE-2026-77838 28.08.2026
CVE-2026-78032 28.08.2026
CVE-2026-78238 28.08.2026
CVE-2026-79615 Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR 28.08.2026
CVE-2026-79706 Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal 28.08.2026
CVE-2026-79995 User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via IDOR 28.08.2026
CVE-2026-79996 User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Settings 28.08.2026
CVE-2026-80590 inet: frags: strip GSO state from fragments before reassembly 28.08.2026
CVE-2026-80591 f2fs: fix listxattr handling of corrupted xattr entries 28.08.2026
CVE-2026-80592 samples/damon/mtier: fail early if address range parameters are invalid 28.08.2026
CVE-2026-80593 hwmon: (asus_atk0110) Check package count before accessing element 28.08.2026
CVE-2026-80594 Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing 28.08.2026
CVE-2026-80595 Input: ims-pcu - add response length checks 28.08.2026
CVE-2026-80596 Input: ims-pcu - only expose sysfs attributes on control interface 28.08.2026
CVE-2026-80597 mtd: maps: vmu-flash: fix NULL pointer dereference in initialization 28.08.2026
CVE-2026-80598 ntfs3: fix out-of-bounds read in decompress_lznt 28.08.2026
CVE-2026-80599 batman-adv: dat: ensure accessible eth_hdr proto field 28.08.2026
CVE-2026-80600 batman-adv: dat: acquire ARP hw source only after skb realloc 28.08.2026
CVE-2026-80601 batman-adv: gw: acquire ethernet header only after skb realloc 28.08.2026
CVE-2026-80602 perf/x86/amd/lbr: Fix kernel address leakage 28.08.2026
CVE-2026-80603 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read 28.08.2026
CVE-2026-80604 HID: core: Fix OOB read in hid_get_report for numbered reports 28.08.2026
CVE-2026-80605 HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() 28.08.2026
CVE-2026-80606 drm/xe/userptr: Hold notifier_lock for write on inject test path 28.08.2026
CVE-2026-80607 tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg 28.08.2026
CVE-2026-80608 accel/amdxdna: Fix iommu domain lifetime race during device removal 28.08.2026
CVE-2026-80609 qede: fix out-of-bounds check for cqe->len_list[] 28.08.2026
CVE-2026-80610 net: enetc: fix potential divide-by-zero when num_vsi is zero 28.08.2026
CVE-2026-80611 ACPI: processor_idle: Mark LPI enter functions as __cpuidle 28.08.2026
CVE-2026-80612 net: lwtunnel: Drop skb metadata before LWT encapsulation 28.08.2026
CVE-2026-80613 veth: fix NAPI leak in XDP enable error path 28.08.2026
CVE-2026-80614 net: emac: Fix NULL pointer dereference in emac_probe 28.08.2026
CVE-2026-80615 net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone 28.08.2026
CVE-2026-80616 ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() 28.08.2026
CVE-2026-80617 net: airoha: fix foe_check_time allocation size 28.08.2026
CVE-2026-80618 drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free 28.08.2026
CVE-2026-80619 apparmor: fix potential UAF in aa_replace_profiles 28.08.2026
CVE-2026-80620 Revert "PCI/MSI: Unmap MSI-X region on error" 28.08.2026
CVE-2026-80621 PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability 28.08.2026
CVE-2026-80622 char: tlclk: fix use-after-free in tlclk_cleanup() 28.08.2026
CVE-2026-80623 coresight: ete: Always save state on power down 28.08.2026
CVE-2026-80624 mfd: cs42l43: Sanity check firmware size 28.08.2026
CVE-2026-80625 RDMA/hns: Fix memory leak of bonding resources 28.08.2026
CVE-2026-80626 powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del 28.08.2026
CVE-2026-80627 MIPS: mm: Fix out-of-bounds write in maar_res_walk() 28.08.2026
CVE-2026-80628 ALSA: seq: oss: Serialize readq reset state with q->lock 28.08.2026
CVE-2026-80629 octeontx2-af: npc: Fix size of entry2cntr_map 28.08.2026
CVE-2026-80630 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 28.08.2026
CVE-2026-80631 btrfs: lzo: reject compressed segment that overflows the compressed input 28.08.2026
CVE-2026-80632 wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues() 28.08.2026
CVE-2026-80633 iommufd: Take dma_resv lock before dma_buf_unpin() in release path 28.08.2026
CVE-2026-80634 netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag 28.08.2026
CVE-2026-80635 wifi: wcn36xx: fix OOB read from short trigger BA firmware response 28.08.2026
CVE-2026-80636 netfilter: conntrack: revert ct extension genid infrastructure 28.08.2026
CVE-2026-80637 netfilter: synproxy: fix unaligned memory access in timestamp adjustment 28.08.2026
CVE-2026-80638 ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent 28.08.2026
CVE-2026-80639 cxl/test: Fix __fortify_panic 28.08.2026
CVE-2026-80640 cxl/fwctl: Fix __fortify_panic 28.08.2026
CVE-2026-80641 wifi: wlcore: enable the right set of ciphers 28.08.2026
CVE-2026-80642 liveupdate: Reference count incoming FLB data 28.08.2026
CVE-2026-80643 EDAC/igen6: Fix call trace due to missing release() 28.08.2026
CVE-2026-80644 ocfs2: don't BUG_ON an invalid journal dinode 28.08.2026
CVE-2026-80645 rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() 28.08.2026
CVE-2026-80646 ipv6: guard against possible NULL deref in __in6_dev_stats_get() 28.08.2026
CVE-2026-80647 RDMA/hns: Fix warning in poll cq direct mode 28.08.2026
CVE-2026-80648 pinctrl: spacemit: fix NULL check in spacemit_pin_set_config 28.08.2026
CVE-2026-80649 firmware: arm_scmi: Fix OOB in scmi_power_name_get() 28.08.2026
CVE-2026-80650 media: atomisp: gc2235: fix UAF and memory leak 28.08.2026
CVE-2026-80651 crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL 28.08.2026
CVE-2026-80652 crypto: ccp - Treat zero-length cert chain as query for blob lengths 28.08.2026
CVE-2026-80653 scsi: hisi_sas: Add slave_destroy interface for v3 hw 28.08.2026
CVE-2026-80654 soc: xilinx: Shutdown and free rx mailbox channel 28.08.2026
CVE-2026-80655 soc: xilinx: Fix race condition in event registration 28.08.2026
CVE-2026-80656 hfsplus: Add a sanity check for btree node size 28.08.2026
CVE-2026-80657 accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer 28.08.2026
CVE-2026-80658 drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() 28.08.2026
CVE-2026-80659 mmc: vub300: defer reset until cmd_mutex is unlocked 28.08.2026
CVE-2026-80660 hwmon: (occ) unregister sysfs devices outside occ lock 28.08.2026
CVE-2026-80661 ufs: core: tracing: Do not dereference pointers in TP_printk() 28.08.2026
CVE-2026-80662 cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size 28.08.2026
CVE-2026-80663 tools/power/x86/intel-speed-select: Harden daemon pidfile open 28.08.2026
CVE-2026-80664 netfilter: xt_nat: reject unsupported target families 28.08.2026
CVE-2026-80665 KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN 28.08.2026
CVE-2026-80666 Bluetooth: sco: Fix a race condition in sco_sock_timeout() 28.08.2026
CVE-2026-80667 net/mlx5: LAG, MPESW, Fix missing complete() on devcom error 28.08.2026
CVE-2026-80668 netfilter: nf_conntrack_expect: use conntrack GC to reap expectations 28.08.2026
CVE-2026-80669 bpf: Disable xfrm_decode_session hook attachment 28.08.2026
CVE-2026-80670 perf tools: Use perf_env__get_cpu_topology() in machine__resolve() 28.08.2026
CVE-2026-80671 perf sched: Fix register_pid() overflow, strcpy, and BUG_ON 28.08.2026
CVE-2026-80672 ntfs: fix u16 truncation of restart-area length check 28.08.2026
CVE-2026-80673 ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() 28.08.2026
CVE-2026-80674 ntfs: validate resident attribute lists and harden the validator 28.08.2026
CVE-2026-80675 libbpf: Reject non-exclusive metadata maps in the signed loader 28.08.2026
CVE-2026-80676 Drivers: hv: vmbus: use generic driver_override infrastructure 28.08.2026
CVE-2026-80677 driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() 28.08.2026
CVE-2026-80678 i2c: imx: Fix slave registration race and error handling 28.08.2026
CVE-2026-80679 s390/dasd: Fix potential NULL pointer dereference 28.08.2026
CVE-2026-80680 i2c: amd-mp2: Unregister callback on adapter add failure 28.08.2026
CVE-2026-80681 vxlan: re-fetch eth header after route_shortcircuit() 28.08.2026
CVE-2026-80682 riscv/mm: use physical alignment for vmemmap_start_pfn 28.08.2026
CVE-2026-80683 Bluetooth: SCO: give the socket its own sco_conn reference 28.08.2026
CVE-2026-80684 KVM: s390: pci: Fix NULL dereference on AIBV allocation failure 28.08.2026
CVE-2026-80685 mm/util: don't read __page_2 for order-1 folios in snapshot_page() 28.08.2026
CVE-2026-80686 mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE 28.08.2026
CVE-2026-80687 iommufd/viommu: Release the igroup lock on the vdevice_size error path 28.08.2026
CVE-2026-80688 riscv: drop __init from vec_check_unaligned_access_speed_all_cpus 28.08.2026
CVE-2026-80689 tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions 28.08.2026
CVE-2026-80690 scsi: ufs: core: Initialize hba->rpmbs list in ufshcd 28.08.2026
CVE-2026-80691 scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE 28.08.2026
CVE-2026-80692 Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks 28.08.2026
CVE-2026-80693 idpf: bound interrupt-vector register fill to the allocated array 28.08.2026
CVE-2026-80694 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller 28.08.2026
CVE-2026-80695 hwmon: (sht3x) Fix unaligned accesses 28.08.2026
CVE-2026-80696 hwmon: (ltc4282) Fix reading the minimum alarm voltage 28.08.2026
CVE-2026-80697 erofs: ensure valid f_path for page cache sharing 28.08.2026
CVE-2026-80698 dmaengine: idxd: fix double free of wq, engine, and group structs 28.08.2026
CVE-2026-80699 KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context 28.08.2026
CVE-2026-80700 drm/vmwgfx: validate external BO copy bounds for both stride paths 28.08.2026
CVE-2026-80701 drm/vmwgfx: enforce cursor size limits for MOB cursors 28.08.2026
CVE-2026-80702 drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size 28.08.2026
CVE-2026-80703 drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE 28.08.2026
CVE-2026-80704 drm/amd/display: use proper context for logging 28.08.2026
CVE-2026-80705 drm/amd/display: check if dml21_add_phantom_plane() is successful 28.08.2026
CVE-2026-80706 can: softing: fw_parse(): validate firmware record spans 28.08.2026
CVE-2026-80707 can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer 28.08.2026
CVE-2026-80708 s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() 28.08.2026
CVE-2026-80709 s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs 28.08.2026
CVE-2026-80710 s390/dasd: Fix undersized format-check buffer 28.08.2026
CVE-2026-80711 power: supply: max17040: handle missing status supplier 28.08.2026
CVE-2026-80712 spi: spi-qpic-snand: write the feature value before executing SET_FEATURE 28.08.2026
CVE-2026-80713 io_uring: preserve task restrictions across exec 28.08.2026
CVE-2026-80714 ipvs: do not propagate one-packet flag to synced conns 28.08.2026
CVE-2026-80715 igc: remove napi_synchronize() in igc_down() 28.08.2026
CVE-2026-80716 ALSA: pcm: wake linked drain waiters on unlink 28.08.2026
CVE-2026-80717 sctp: validate Adaptation Indication parameter length 28.08.2026
CVE-2026-80718 mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() 28.08.2026
CVE-2026-80719 mm: mglru: fix stale batch updates after memcg reparenting 28.08.2026
CVE-2026-80720 iomap: add a separate bio_set for iomap_split_ioend 28.08.2026
CVE-2026-80721 Bluetooth: ISO: ensure no dangling hcon references in iso_conn 28.08.2026
CVE-2026-80722 wifi: mac80211: validate individual TWT params before driver setup 28.08.2026
CVE-2026-80723 of: reserved_mem: prevent OOB when too many dynamic regions are defined 28.08.2026
CVE-2026-80724 ptp: vmclock: prevent read-only mappings from becoming writable 28.08.2026
CVE-2026-82123 WordPress Loops & Logic - Reflected XSS 28.08.2026 6.5
CVE-2026-9491 28.08.2026 4.3
CVE-2026-9548 28.08.2026 6.5