| CVE-2026-54569 |
SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core |
26.08.2026 |
9.8 |
| CVE-2026-80428 |
ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint |
26.08.2026 |
9.3 |
| CVE-2026-81032 |
NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration |
26.08.2026 |
9.3 |
| CVE-2026-75062 |
Eval Injection in google/langfun via default lf.query protocol |
26.08.2026 |
9.2 |
| CVE-2026-54523 |
Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system |
26.08.2026 |
9.6 |
| CVE-2026-75896 |
Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk |
26.08.2026 |
9.1 |
| CVE-2026-12717 |
Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection |
26.08.2026 |
9.4 |
| CVE-2026-18080 |
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment |
26.08.2026 |
9.8 |
| CVE-2026-77532 |
|
26.08.2026 |
9.6 |
| CVE-2026-77554 |
|
26.08.2026 |
10 |
| CVE-2026-77557 |
|
26.08.2026 |
9.8 |
| CVE-2026-77549 |
|
26.08.2026 |
9 |
| CVE-2026-77550 |
|
26.08.2026 |
10 |
| CVE-2026-77551 |
|
26.08.2026 |
9 |
| CVE-2026-77552 |
|
26.08.2026 |
9.8 |
| CVE-2026-77553 |
|
26.08.2026 |
9.9 |
| CVE-2026-77546 |
|
26.08.2026 |
9.9 |
| CVE-2026-77547 |
|
26.08.2026 |
9.9 |
| CVE-2026-77548 |
|
26.08.2026 |
9.9 |
| CVE-2026-80203 |
Grav before 1.0.18 Authentication Bypass via Scoped API Key |
26.08.2026 |
9.3 |
| CVE-2026-80204 |
Grav before 1.0.18 Authentication Bypass via Scoped API Key |
26.08.2026 |
9.3 |
| CVE-2026-77542 |
|
26.08.2026 |
9.1 |
| CVE-2026-77543 |
|
26.08.2026 |
9.9 |
| CVE-2026-77545 |
|
26.08.2026 |
9 |
| CVE-2026-80349 |
TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter |
26.08.2026 |
9.3 |
| CVE-2026-77539 |
|
26.08.2026 |
9.1 |
| CVE-2026-77540 |
|
26.08.2026 |
9.1 |
| CVE-2026-77541 |
|
26.08.2026 |
9.1 |
| CVE-2026-59683 |
OpenRGB: local and remote system compromise via arbitrary file write using attacker controlled strings |
26.08.2026 |
9.3 |
| CVE-2026-77535 |
|
26.08.2026 |
9.1 |
| CVE-2026-77536 |
|
26.08.2026 |
9.9 |
| CVE-2026-77537 |
|
26.08.2026 |
10 |
| CVE-2026-77534 |
|
26.08.2026 |
9.9 |
| CVE-2026-77533 |
|
26.08.2026 |
9.9 |
| CVE-2026-80235 |
Thinking Software Technology|EFence - Arbitrary File Upload |
26.08.2026 |
9.3 |
| CVE-2026-18431 |
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write |
26.08.2026 |
9.8 |
| CVE-2026-15203 |
Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid software |
26.08.2026 |
9.3 |
| CVE-2026-19632 |
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure |
26.08.2026 |
9.8 |
| CVE-2026-80202 |
Kimai before 2.56.0 Authorization Bypass via TimesheetVoter |
26.08.2026 |
9.3 |
| CVE-2026-79911 |
TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow |
25.08.2026 |
10 |
| CVE-2026-80138 |
ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter |
26.08.2026 |
9.2 |
| CVE-2026-62862 |
TypeBot: Account takeover via brute-forceable 6-digit magic-link code |
26.08.2026 |
9.1 |
| CVE-2026-65083 |
|
25.08.2026 |
9.9 |
| CVE-2026-65093 |
|
26.08.2026 |
9.9 |
| CVE-2026-80104 |
DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename |
25.08.2026 |
9.3 |
| CVE-2026-45018 |
Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution |
25.08.2026 |
9.8 |
| CVE-2026-78379 |
Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools |
25.08.2026 |
9.2 |
| CVE-2026-79787 |
Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature |
25.08.2026 |
9.3 |
| CVE-2026-76193 |
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
25.08.2026 |
10 |
| CVE-2026-76195 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
25.08.2026 |
10 |
| CVE-2026-76197 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
25.08.2026 |
10 |
| CVE-2026-55640 |
Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) |
25.08.2026 |
9.1 |
| CVE-2022-51000 |
Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxslt |
25.08.2026 |
9.3 |
| CVE-2024-58377 |
Nokogiri before 1.16.5 libxml2 Dependency Update |
25.08.2026 |
9.3 |
| CVE-2024-58378 |
Nokogiri before 1.16.2 Use-After-Free via xmlTextReader |
25.08.2026 |
9.3 |
| CVE-2025-71407 |
Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free |
25.08.2026 |
9.3 |
| CVE-2026-55536 |
Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) |
25.08.2026 |
9.1 |
| CVE-2026-55546 |
QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input |
25.08.2026 |
9.8 |
| CVE-2026-79675 |
NLTK before 3.10.3 JVM Argument Injection via Per-Call Options |
26.08.2026 |
9.3 |
| CVE-2026-79774 |
Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy |
25.08.2026 |
9.3 |
| CVE-2026-79782 |
rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect |
25.08.2026 |
9.3 |
| CVE-2026-16286 |
File Upload in TRTEK Software's Software Repository Management |
25.08.2026 |
9.8 |
| CVE-2026-77998 |
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 |
26.08.2026 |
10 |
| CVE-2026-57909 |
WatchGuard Agent path traversal allows unauthenticated remote code execution |
26.08.2026 |
9.4 |
| CVE-2026-57910 |
WatchGuard Agent improper authentication allows unauthenticated remote code execution |
25.08.2026 |
9.3 |
| CVE-2026-79657 |
NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization |
25.08.2026 |
9.3 |
| CVE-2026-79664 |
Ech0 before 4.7.3 Access Token Revocation Bypass |
25.08.2026 |
9.1 |
| CVE-2026-78570 |
Total Donations <= 2.0.5 - Unauthenticated Privilege Escalation |
25.08.2026 |
9.8 |
| CVE-2026-63586 |
Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface |
25.08.2026 |
9.3 |
| CVE-2026-77136 |
Server-Side Template Injection in extension "powermail" (powermail) |
25.08.2026 |
9.5 |
| CVE-2026-77138 |
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail) |
25.08.2026 |
9.3 |
| CVE-2026-78568 |
Total Donations <= 2.0.5 - Unauthenticated SQL Injection |
25.08.2026 |
9.8 |
| CVE-2026-78477 |
Jawn <= 1.4.2 - Unauthenticated Privilege Escalation |
25.08.2026 |
9.8 |
| CVE-2026-13214 |
Stack buffer overflow in OCPP GetConfiguration key parsing |
25.08.2026 |
9.8 |
| CVE-2026-56705 |
Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection |
25.08.2026 |
9.3 |
| CVE-2026-56710 |
Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock |
25.08.2026 |
9.3 |
| CVE-2026-72699 |
Grav Login Plugin before 3.9.1 Email Enumeration via Registration |
25.08.2026 |
9.3 |
| CVE-2026-72702 |
Grav CMS before 2.0.16 Origin Validation Bypass via Referer |
25.08.2026 |
9.3 |
| CVE-2026-78676 |
GitPython before 3.1.59 Remote Code Execution via Config Injection |
25.08.2026 |
9.3 |
| CVE-2026-78683 |
NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization |
25.08.2026 |
9.4 |
| CVE-2026-32554 |
WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability |
25.08.2026 |
9.3 |
| CVE-2026-32555 |
WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability |
25.08.2026 |
9.3 |
| CVE-2026-32559 |
WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability |
25.08.2026 |
9.9 |
| CVE-2026-32563 |
WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability |
25.08.2026 |
9.8 |
| CVE-2026-77337 |
CakePHP: Potential Authentication bypass with CookieAuthenticator |
25.08.2026 |
9.1 |
| CVE-2026-78262 |
WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability |
24.08.2026 |
9.8 |
| CVE-2026-78265 |
WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability |
25.08.2026 |
9.8 |
| CVE-2026-78267 |
WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability |
24.08.2026 |
9.8 |
| CVE-2026-77635 |
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver |
25.08.2026 |
9.2 |
| CVE-2026-78555 |
RansomLook API Key Disclosure Through /admin/apikeys HTML Source |
24.08.2026 |
9.4 |
| CVE-2026-39975 |
Combodo iTop: Remote code execution using external auth variable value |
24.08.2026 |
9.4 |
| CVE-2026-76835 |
OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy Set |
24.08.2026 |
9.3 |
| CVE-2026-71914 |
DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm |
24.08.2026 |
9.3 |
| CVE-2026-71921 |
DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi |
24.08.2026 |
9.3 |
| CVE-2025-36939 |
|
24.08.2026 |
10 |
| CVE-2026-77915 |
rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php |
25.08.2026 |
9.3 |
| CVE-2026-76070 |
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter |
24.08.2026 |
9.3 |
| CVE-2026-76071 |
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter |
24.08.2026 |
9.3 |
| CVE-2026-78387 |
RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification |
24.08.2026 |
9.4 |
| CVE-2026-59568 |
Remote Code Execution |
25.08.2026 |
9.1 |
| CVE-2026-67602 |
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache |
24.08.2026 |
9.3 |
| CVE-2026-59564 |
Authentication bypass between ZCC and client connector portal |
25.08.2026 |
9.1 |
| CVE-2026-77995 |
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 |
25.08.2026 |
10 |
| CVE-2026-78370 |
RansomLook Unauthenticated Database Export Exposes Private Data |
24.08.2026 |
9.2 |
| CVE-2026-78372 |
RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data |
24.08.2026 |
9.2 |
| CVE-2026-78365 |
IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification |
24.08.2026 |
9.3 |
| CVE-2026-28165 |
WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability |
24.08.2026 |
9.8 |
| CVE-2026-32551 |
WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability |
24.08.2026 |
9.3 |
| CVE-2026-32558 |
WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability |
24.08.2026 |
9.8 |
| CVE-2026-66587 |
WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability |
24.08.2026 |
9.8 |
| CVE-2026-66648 |
WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability |
24.08.2026 |
9.8 |
| CVE-2026-66650 |
WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability |
24.08.2026 |
9.8 |
| CVE-2026-66897 |
Instance template path traversal allows arbitrary host file write as root |
25.08.2026 |
9.9 |
| CVE-2026-77994 |
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 |
25.08.2026 |
9.3 |
| CVE-2026-78251 |
DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory |
24.08.2026 |
9.3 |
| CVE-2026-78211 |
4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection |
24.08.2026 |
9.3 |
| CVE-2026-78168 |
EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication |
24.08.2026 |
9.3 |
| CVE-2026-78169 |
UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow |
24.08.2026 |
9.4 |
| CVE-2026-78167 |
EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication |
24.08.2026 |
10 |
| CVE-2026-78207 |
exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization |
24.08.2026 |
9.3 |
| CVE-2026-5388 |
justhtml before 1.15.0 Multiple Security Issues |
23.08.2026 |
9.3 |
| CVE-2026-7808 |
justhtml before 1.16.0 Multiple Security Issues via Sanitization |
24.08.2026 |
9.3 |
| CVE-2026-8445 |
justhtml before 1.12.0 Sanitizer Bypass via Markdown |
24.08.2026 |
9.3 |
| CVE-2026-78155 |
Untrusted Search Path in StackGres |
24.08.2026 |
9.9 |
| CVE-2026-78050 |
Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow |
24.08.2026 |
9.4 |
| CVE-2026-4703 |
WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission |
24.08.2026 |
9.8 |
| CVE-2026-74586 |
sctp: clear new_transport when removing a peer |
25.08.2026 |
9.8 |
| CVE-2026-74587 |
sctp: fix use-after-free of cached ASCONF chunk |
25.08.2026 |
9.8 |
| CVE-2026-74588 |
sctp: keep chunk->transport in step with the list it is queued on |
25.08.2026 |
9.8 |
| CVE-2026-74591 |
mm/filemap: __filemap_add_folio() restore index before retrying |
25.08.2026 |
9.8 |
| CVE-2026-74597 |
ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
25.08.2026 |
9.8 |
| CVE-2026-74608 |
smb: client: Fix use-after-free in cifs_try_adding_channels() |
25.08.2026 |
9.8 |
| CVE-2026-74611 |
tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
25.08.2026 |
9.8 |
| CVE-2026-74612 |
veth: fix skb length accounting after XDP frag adjustment |
25.08.2026 |
10 |
| CVE-2026-74616 |
xdp: reject clones that overrun skb_shared_info tailroom |
25.08.2026 |
9.8 |
| CVE-2026-74617 |
dibs: initialise dibs->lock in dibs_dev_alloc() |
25.08.2026 |
9.8 |
| CVE-2026-74628 |
net/x25: fix use-after-free of the socket by its timers |
25.08.2026 |
9.8 |
| CVE-2026-74662 |
inet: frags: publish queues before arming timer |
25.08.2026 |
9.8 |
| CVE-2026-74665 |
net: fix skb length accounting after generic XDP frag adjustment |
25.08.2026 |
9.1 |
| CVE-2026-74669 |
ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
25.08.2026 |
9.8 |
| CVE-2026-74688 |
sctp: clear control chunk transport if it is being removed |
25.08.2026 |
9.8 |
| CVE-2026-74705 |
udp: fix potential use-after-free in tunnel segmentation |
25.08.2026 |
10 |
| CVE-2026-74712 |
vdpa/mlx5: Fix buffer length in create_direct_keys() |
25.08.2026 |
9.3 |
| CVE-2026-74723 |
btrfs: lzo: reject inline extents without valid headers |
25.08.2026 |
9.8 |
| CVE-2026-74727 |
ovpn: skip rehash for peers already removed from by_id |
25.08.2026 |
9.8 |
| CVE-2026-74730 |
NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
25.08.2026 |
9.8 |
| CVE-2026-63310 |
NLTK before 3.9.3 Missing Post-Download Integrity Verification |
24.08.2026 |
9.3 |
| CVE-2026-76571 |
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 |
25.08.2026 |
9.3 |
| CVE-2026-76602 |
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 |
24.08.2026 |
9.3 |
| CVE-2026-76604 |
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 |
24.08.2026 |
10 |
| CVE-2026-76605 |
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2 |
24.08.2026 |
10 |
| CVE-2026-76606 |
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2 |
24.08.2026 |
10 |
| CVE-2026-76607 |
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2 |
24.08.2026 |
10 |
| CVE-2026-77992 |
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 |
24.08.2026 |
9.5 |
| CVE-2026-77946 |
TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow |
22.08.2026 |
10 |
| CVE-2026-78003 |
Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys |
25.08.2026 |
9.8 |
| CVE-2026-12710 |
Missing Authorization in Application Integration QueryEngineTask |
22.08.2026 |
9.3 |
| CVE-2026-49849 |
xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution |
25.08.2026 |
9.1 |
| CVE-2026-77415 |
JSONata: Arbitrary Code Execution via crafted JSONata expressions |
25.08.2026 |
9.3 |
| CVE-2026-77413 |
JSONata: Arbitrary Code Execution via crafted JSONata expressions |
24.08.2026 |
9.3 |
| CVE-2026-77414 |
JSONata: Arbitrary Code Execution via crafted JSONata expressions |
21.08.2026 |
9.3 |
| CVE-2026-61539 |
Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing |
24.08.2026 |
10 |
| CVE-2026-59989 |
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) |
25.08.2026 |
9.2 |
| CVE-2026-62283 |
Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check |
21.08.2026 |
9.9 |
| CVE-2026-76904 |
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers |
25.08.2026 |
9.8 |
| CVE-2026-77810 |
Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector |
21.08.2026 |
9.4 |
| CVE-2026-62674 |
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE |
25.08.2026 |
9 |
| CVE-2026-77234 |
Improper input validation in FreeRTOS-Kernel timer command handling |
21.08.2026 |
9.3 |
| CVE-2026-39909 |
llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler |
25.08.2026 |
9.2 |
| CVE-2026-74581 |
net: ipv6: clear suppressed fib6 rule result |
25.08.2026 |
9.8 |
| CVE-2026-69502 |
Azure SQL Database Elevation of Privilege Vulnerability |
25.08.2026 |
10 |
| CVE-2026-75932 |
Jet Admin tenant isolation failure |
21.08.2026 |
9.2 |
| CVE-2026-63343 |
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root |
21.08.2026 |
9.9 |
| CVE-2026-77087 |
Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding |
21.08.2026 |
9.4 |
| CVE-2026-48755 |
Incus has an argument injection in backup compression algorithm leading to AFW and ACE |
21.08.2026 |
9.9 |
| CVE-2026-48769 |
Incus has an arbitrary file write on its client due to trusted image hash |
21.08.2026 |
9.9 |
| CVE-2026-62867 |
Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution |
21.08.2026 |
9.9 |
| CVE-2026-62940 |
Incus has a project restriction bypass via instance migration config override |
21.08.2026 |
9.9 |
| CVE-2026-62941 |
Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge |
21.08.2026 |
9.9 |
| CVE-2026-63125 |
Incus vulnerable to root RCE via image backup.yaml symlink |
21.08.2026 |
9.9 |
| CVE-2026-48751 |
Incus has a restricted project bypass leading to arbitrary command execution |
21.08.2026 |
9.9 |
| CVE-2026-48752 |
Incus has arbitrary file read+write on host via templates/ symlink in malicious image |
21.08.2026 |
9.9 |
| CVE-2026-48753 |
Incus has an arbitrary file write via path traversal in S3 multipart upload |
21.08.2026 |
9.9 |
| CVE-2026-48749 |
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image |
21.08.2026 |
9.9 |
| CVE-2026-48750 |
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image |
21.08.2026 |
9.9 |
| CVE-2026-77812 |
Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE |
24.08.2026 |
9.4 |
| CVE-2026-77806 |
|
21.08.2026 |
9.8 |
| CVE-2026-77776 |
Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity |
21.08.2026 |
9.3 |
| CVE-2026-77086 |
SiYuan before v3.7.4 Path Traversal via packageName |
21.08.2026 |
9.4 |
| CVE-2026-77683 |
Comfast CF-N1-S mbox-config system command injection |
21.08.2026 |
9.4 |
| CVE-2026-77264 |
Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure |
21.08.2026 |
9.8 |
| CVE-2026-76158 |
Datiphy Data Management Center - External Control of File Name or Path |
21.08.2026 |
9.3 |
| CVE-2026-76155 |
Datiphy Data Management Center - Use of Default Credentials |
21.08.2026 |
9.3 |
| CVE-2026-76156 |
Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command |
21.08.2026 |
9.4 |
| CVE-2026-77649 |
|
21.08.2026 |
9.8 |
| CVE-2026-77650 |
|
21.08.2026 |
9.8 |
| CVE-2026-77651 |
|
21.08.2026 |
9.8 |
| CVE-2026-77647 |
|
21.08.2026 |
9.8 |
| CVE-2026-18835 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.9 |
| CVE-2026-77645 |
Critical Remote Code Execution (RCE) vulnerability reported in Windchill |
22.08.2026 |
9.2 |
| CVE-2026-17122 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-17136 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-17141 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-17142 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-17145 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-17152 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-17157 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-17160 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.8 |
| CVE-2026-17422 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
22.08.2026 |
9.3 |
| CVE-2026-72843 |
EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover |
21.08.2026 |
9.3 |
| CVE-2026-77644 |
Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition |
26.08.2026 |
9.3 |
| CVE-2026-17040 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-17118 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.8 |
| CVE-2026-55769 |
CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path` |
21.08.2026 |
9.4 |
| CVE-2026-62834 |
Azure Data Factory Elevation of Privilege Vulnerability |
25.08.2026 |
9.3 |
| CVE-2026-63509 |
Microsoft Fabric Elevation of Privilege Vulnerability |
25.08.2026 |
9.9 |
| CVE-2026-65770 |
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability |
25.08.2026 |
10 |
| CVE-2026-65801 |
Microsoft Exchange Online Elevation of Privilege Vulnerability |
25.08.2026 |
10 |
| CVE-2026-65816 |
Azure Arc Elevation of Privilege Vulnerability |
25.08.2026 |
10 |
| CVE-2026-66309 |
Azure SQL Database Elevation of Privilege Vulnerability |
25.08.2026 |
9.1 |
| CVE-2026-68782 |
Azure SQL Database Elevation of Privilege Vulnerability |
25.08.2026 |
9.9 |
| CVE-2026-68789 |
Azure SQL Database Elevation of Privilege Vulnerability |
25.08.2026 |
9.9 |
| CVE-2026-69400 |
Azure Logic Apps Elevation of Privilege Vulnerability |
25.08.2026 |
9.6 |
| CVE-2026-69555 |
Azure Arc Elevation of Privilege Vulnerability |
25.08.2026 |
10 |
| CVE-2026-69836 |
Microsoft Entra ID Remote Code Execution Vulnerability |
25.08.2026 |
10 |
| CVE-2026-69851 |
Microsoft Entra ID Elevation of Privilege Vulnerability |
25.08.2026 |
9.9 |
| CVE-2026-71485 |
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends |
25.08.2026 |
9.1 |
| CVE-2026-67567 |
Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction |
21.08.2026 |
9.9 |
| CVE-2026-19586 |
Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways |
21.08.2026 |
9.3 |
| CVE-2026-66785 |
Submariner: submariner: unvalidated endpoint.spec.subnets propagated into wireguard allowedips / ipsec enables traffic hijack |
25.08.2026 |
9.9 |
| CVE-2026-66788 |
Lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled labelsourcenamespace |
20.08.2026 |
9.9 |
| CVE-2026-77148 |
Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow |
20.08.2026 |
9.4 |
| CVE-2026-2334 |
) Missing Server-Side File Extension Validation in vsDesk |
21.08.2026 |
9.4 |
| CVE-2026-63385 |
Libevent: HTTP header handling bugs create risk of access control bypass. |
21.08.2026 |
9.2 |
| CVE-2026-63382 |
libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling |
20.08.2026 |
9.2 |
| CVE-2026-53424 |
Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions |
21.08.2026 |
9.1 |
| CVE-2026-73251 |
Mongoose Built-in TLS: CA-bundle certificate chain accepted without any signature verification |
20.08.2026 |
9.3 |
| CVE-2026-73253 |
Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching |
20.08.2026 |
9.1 |
| CVE-2026-73256 |
Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE |
21.08.2026 |
9.1 |
| CVE-2026-73257 |
Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling |
20.08.2026 |
9.1 |
| CVE-2026-55642 |
dbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured) |
20.08.2026 |
9.8 |
| CVE-2026-71428 |
unstructured: Server-Side Request Forgery in the URL-based partitioning |
25.08.2026 |
9.3 |
| CVE-2026-77022 |
Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow |
21.08.2026 |
9.4 |
| CVE-2026-18265 |
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-16926 |
Vulnerabilities in IBM AIX and PowerVM VIOS |
25.08.2026 |
9.1 |
| CVE-2026-15706 |
Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS |
24.08.2026 |
9.8 |
| CVE-2026-28164 |
WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability |
20.08.2026 |
9.6 |
| CVE-2025-15688 |
WordPress Capella theme <= 2.5.5 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2025-15689 |
WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-66583 |
WordPress Forminator plugin <= 1.57.0 - PHP Object Injection vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-66592 |
WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66593 |
WordPress Security & Malware scan by CleanTalk plugin <= 2.184 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66600 |
WordPress Media LIbrary Assistant plugin <= 3.39 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.1 |
| CVE-2026-66609 |
WordPress TheGem (Elementor) theme <= 5.12.3 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66649 |
WordPress Directory Pro plugin <= 2.5.8 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66672 |
WordPress Flatastic theme <= 2.0 - PHP Object Injection vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-66680 |
WordPress Locatoraid Store Locator plugin <= 3.9.72 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-66682 |
WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-68566 |
WordPress BookingPress Appointment Booking Pro plugin <= 6.0.2 - SQL Injection vulnerability |
20.08.2026 |
9.3 |
| CVE-2026-73992 |
WordPress Query Wrangler plugin <= 1.5.57 - Remote Code Execution (RCE) vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-73993 |
WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-74001 |
WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability |
20.08.2026 |
9.8 |
| CVE-2026-74014 |
WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-74016 |
WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-74018 |
WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability |
20.08.2026 |
9.9 |
| CVE-2026-11861 |
Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships |
20.08.2026 |
9.6 |
| CVE-2026-13097 |
Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore |
21.08.2026 |
9.1 |
| CVE-2026-14950 |
Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic |
20.08.2026 |
9.2 |