CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-18248 @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header 03.08.2026 9.1
CVE-2026-18601 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection 03.08.2026 9.3
CVE-2026-64827 Telenia TVox 26.5.3 Authentication Bypass via set_env.php 03.08.2026 9.3
CVE-2026-68584 SiYuan before v3.7.3 Authentication Bypass via Content Endpoints 03.08.2026 9.2
CVE-2026-68586 SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc 03.08.2026 9.2
CVE-2026-68587 SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction 03.08.2026 9.2
CVE-2026-69083 SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent 03.08.2026 9.9
CVE-2026-69084 SiYuan before v3.7.3 SQL Injection via searchEmbedBlock 03.08.2026 9.9
CVE-2026-69085 SiYuan before v3.7.3 SQL Injection via searchDocs 03.08.2026 9.9
CVE-2026-18574 Authentication Bypass in Check Point Security Management Server 03.08.2026 9.3
CVE-2026-2346 IDOR in Menulux Software's Mobile App 03.08.2026 9.8
CVE-2026-33591 Authentication bypass on WaptServer 03.08.2026 10
CVE-2026-18588 Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow 03.08.2026 9.3
CVE-2026-18589 Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow 03.08.2026 9.3
CVE-2026-58062 Stapled OCSP response accepted without binding to the checked certificate 03.08.2026 9.3
CVE-2026-59638 JSSE hostname verifier CN-fallback enabled by default despite documented opt-in 03.08.2026 9.3
CVE-2026-59650 MTI/A0 DH agreement exponentiates unvalidated peer value 03.08.2026 9.3
CVE-2026-8763 Name Constraints bypass via trailing dot in rfc822Name and URI 03.08.2026 9.3
CVE-2026-65321 PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS 03.08.2026 9.3
CVE-2025-71401 better-auth before 1.4.2 basePath Modification DoS 03.08.2026 9.3
CVE-2026-68582 Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token 03.08.2026 9.3
CVE-2026-8457 WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT 01.08.2026 9.8
CVE-2026-66402 FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass 01.08.2026 9.3
CVE-2026-67289 FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection 01.08.2026 9.3
CVE-2026-67292 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure 01.08.2026 9.3
CVE-2026-67293 FreeRDP before 3.29.0 Improper Certificate Hostname Validation 01.08.2026 9.3
CVE-2026-67294 FreeRDP before 3.29.0 TLS Certificate EKU Bypass 01.08.2026 9.3
CVE-2026-67305 FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr 01.08.2026 9.4
CVE-2026-67308 Wazuh GitHub Actions Shell Injection via Fork Pull Request 02.08.2026 9.3
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options 01.08.2026 9.3
CVE-2026-67330 better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision 01.08.2026 9.4
CVE-2026-67336 better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider 03.08.2026 9.4
CVE-2026-67340 ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts 01.08.2026 9.3
CVE-2026-67341 ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION 01.08.2026 9.3
CVE-2026-67342 ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers 01.08.2026 9.3
CVE-2026-15964 Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change 01.08.2026 9.8
CVE-2026-3141 FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter 01.08.2026 9.1
CVE-2026-68771 ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization 31.07.2026 9.3
CVE-2026-68770 sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False 31.07.2026 9.3
CVE-2026-54725 vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API 31.07.2026 9.6
CVE-2026-52855 Wings exposes node configuration secrets through egg configuration-file templating 31.07.2026 9.9
CVE-2026-58048 01.08.2026 9.4
CVE-2026-17349 pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner 01.08.2026 9.3
CVE-2026-17351 pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) 01.08.2026 9.4
CVE-2026-17566 pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) 01.08.2026 9.4
CVE-2026-17561 Unauthenticated RCE in Innotim Software's Logsign SIEM 31.07.2026 9.8
CVE-2025-67649 Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script 31.07.2026 9.3
CVE-2026-14483 Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command 31.07.2026 9.8
CVE-2026-18452 Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials 31.07.2026 10
CVE-2026-63221 CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions 31.07.2026 9.4
CVE-2026-63223 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules 31.07.2026 9.8
CVE-2026-66418 OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field 31.07.2026 9.3
CVE-2026-68502 LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE 31.07.2026 9.8
CVE-2026-68503 LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard 31.07.2026 9.8
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability 31.07.2026 10
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent 31.07.2026 9.9
CVE-2026-67208 Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console 31.07.2026 9.3
CVE-2026-67594 Spikster Missing Authentication via API Route Group 31.07.2026 9.3
CVE-2026-66066 Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing 01.08.2026 9.5
CVE-2026-12943 This Power Hardware Management Console update is being released to address 31.07.2026 9.8
CVE-2026-12118 IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data 30.07.2026 9.8
CVE-2026-13435 Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure 31.07.2026 9.9
CVE-2026-48499 Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache 30.07.2026 9.3
CVE-2026-12940 Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints 31.07.2026 9.8
CVE-2026-28323 SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability 31.07.2026 9.8
CVE-2026-4978 SQLi in UMAI Vision's Traffic Analysis System 30.07.2026 9.8
CVE-2026-11707 Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager 30.07.2026 9.3
CVE-2026-15435 IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability 31.07.2026 9.8
CVE-2026-53431 Boruta accepts expired JWT client assertions due to missing exp claim validation 31.07.2026 9.1
CVE-2026-47876 VMXNET3 out-of-bounds write vulnerability 30.07.2026 9.3
CVE-2026-54363 CentreStack < 17.5 Hardcoded Key Token Forgery RCE 30.07.2026 9.3
CVE-2026-59309 vCenter authentication-bypass vulnerability 30.07.2026 9.8
CVE-2026-59310 vCenter directory-traversal vulnerability 30.07.2026 9.8
CVE-2026-18363 Weak password recovery mechanism in osTicket by Enhancesoft LLC 30.07.2026 9.1
CVE-2026-44090 Missing authentication for MQTT Broker 30.07.2026 9.3
CVE-2026-44101 OCPP reconfiguration vulnerability 31.07.2026 9.3
CVE-2026-44104 ControllerAgent does not perform validation of firmware 30.07.2026 9.3
CVE-2026-44108 Firewall bypass during shutdown 30.07.2026 9.3
CVE-2026-7849 Command Injection in SCM (idledisconnect parameter) 30.07.2026 9.3
CVE-2026-58046 30.07.2026 9.9
CVE-2026-58066 31.07.2026 9.8
CVE-2026-16610 Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key 30.07.2026 9.8
CVE-2026-48449 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 30.07.2026 10
CVE-2026-67595 VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php 30.07.2026 9.2
CVE-2026-16326 consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 29.07.2026 10
CVE-2026-67426 Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration 29.07.2026 9.3
CVE-2026-67429 Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) 29.07.2026 10
CVE-2026-14529 IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery 30.07.2026 9.4
CVE-2026-18236 Google-ADK Continuation Forgery 29.07.2026 9.3
CVE-2026-41939 Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly 30.07.2026 9.3
CVE-2026-54680 Logging operator has Fluentd configuration injection that allows remote code execution 30.07.2026 9.9
CVE-2026-8338 Authentication and Authorization Bypass in Coverity Connect 29.07.2026 9.2
CVE-2026-54735 prebid-server's request forgery vulnerability allows for possible host environment data extraction 29.07.2026 10
CVE-2026-60112 AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() 29.07.2026 9.3
CVE-2026-60113 AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes 30.07.2026 9.3
CVE-2026-67191 Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser 29.07.2026 9.3
CVE-2026-67192 Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher 29.07.2026 9.2
CVE-2026-65886 Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65887 Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 01.08.2026 10
CVE-2026-65888 Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 01.08.2026 10
CVE-2026-65889 Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-65890 Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 29.07.2026 9.2
CVE-2026-9177 Server-Side Template Injection in SecureTransport's Apache Velocity mail templates 31.07.2026 9.4
CVE-2026-0667 29.07.2026 9.3
CVE-2026-65884 Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 30.07.2026 10
CVE-2026-65885 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 30.07.2026 9.4
CVE-2026-14488 Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter 29.07.2026 9.1
CVE-2026-14900 Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter 29.07.2026 9.8
CVE-2026-65883 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 29.07.2026 10
CVE-2025-10656 Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation 29.07.2026 9.8
CVE-2026-58161 Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server 29.07.2026 9.2
CVE-2026-58179 Apache Traffic Server: regex_remap plugin overflows the stack from attacker input 30.07.2026 9.2
CVE-2026-58154 Apache Traffic Server: Memory-safety errors in MIME and header parsing 29.07.2026 9.2
CVE-2026-58155 Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling 29.07.2026 9.2
CVE-2026-18191 Vacron|IP Camera - Hidden Functionality 29.07.2026 9.3
CVE-2026-63227 Unrestricted SCORM file upload vulnerability 29.07.2026 9.9
CVE-2026-63229 Pre-authentication blind SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63230 Pre-authentication error-based SQL injection vulnerability 29.07.2026 9.1
CVE-2026-63232 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63233 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-63234 SQL injection and unsafe deserialisation vulnerability 29.07.2026 9.9
CVE-2026-18072 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter 29.07.2026 9.8
CVE-2026-54658 @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution 29.07.2026 9.8
CVE-2026-62325 goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) 29.07.2026 9.1
CVE-2026-64863 goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite 29.07.2026 9.1
CVE-2026-14446 IBM WebSphere Application Server is affected by a privilege escalation 30.07.2026 9.8
CVE-2026-14512 IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information 30.07.2026 9.8
CVE-2026-14958 OS command injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14959 OS Command Injection in IBM Aspera Faspex 30.07.2026 9.1
CVE-2026-14973 Path Traversal in IBM Desktop App 31.07.2026 9.3
CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance 29.07.2026 9.4
CVE-2026-16498 terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode 28.07.2026 10
CVE-2026-50736 28.07.2026 9
CVE-2026-50737 28.07.2026 9
CVE-2026-67174 DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick 28.07.2026 9.2
CVE-2026-65880 Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 28.07.2026 10
CVE-2026-11841 CVE-2026-11841 28.07.2026 9.4
CVE-2026-16462 SQL injection via unauthenticated GetGridData endpoint 28.07.2026 9.3
CVE-2026-11756 Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x 28.07.2026 10
CVE-2026-15014 SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter 28.07.2026 9.8
CVE-2026-64541 net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket 30.07.2026 9.8
CVE-2026-64551 sctp: validate STALE_COOKIE cause length before reading staleness 30.07.2026 9.1

Latest Updates

CVE Title Updated Score
CVE-2026-15430 CVE-2026-15430 03.08.2026
CVE-2026-18248 @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header 03.08.2026 9.1
CVE-2026-18508 Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite 03.08.2026
CVE-2026-18568 XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check 03.08.2026
CVE-2026-18651 389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account 03.08.2026
CVE-2026-67609 Telenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration 03.08.2026
CVE-2026-18089 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured 03.08.2026
CVE-2026-18092 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree 03.08.2026
CVE-2026-18108 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature 03.08.2026
CVE-2026-18600 GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection 03.08.2026
CVE-2026-18601 GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection 03.08.2026
CVE-2026-18642 Remote Code Execution via Insecure Deserialization in TÜBİTAK BİLGEM's eta-otp-lock 03.08.2026 7.8
CVE-2026-64827 Telenia TVox 26.5.3 Authentication Bypass via set_env.php 03.08.2026
CVE-2026-67608 Telenia TVox 26.5.3 OS Command Injection via action_audio.php 03.08.2026
CVE-2026-68584 SiYuan before v3.7.3 Authentication Bypass via Content Endpoints 03.08.2026
CVE-2026-68585 SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo 03.08.2026
CVE-2026-68586 SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc 03.08.2026
CVE-2026-68587 SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction 03.08.2026
CVE-2026-69083 SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent 03.08.2026
CVE-2026-69084 SiYuan before v3.7.3 SQL Injection via searchEmbedBlock 03.08.2026
CVE-2026-69085 SiYuan before v3.7.3 SQL Injection via searchDocs 03.08.2026
CVE-2026-69086 SiYuan before v3.7.3 Path Traversal via unvalidated avID 03.08.2026
CVE-2026-69087 Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twig 03.08.2026
CVE-2026-69088 Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint 03.08.2026
CVE-2026-69089 Grav CMS before 2.0.11 Path Traversal via watermark 03.08.2026
CVE-2026-69090 Admidio before 5.0.11 Cross-Organization Role Modification 03.08.2026
CVE-2026-69091 Admidio before 5.0.11 Authentication Bypass via forum.php 03.08.2026
CVE-2026-69092 Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpoint 03.08.2026
CVE-2026-69093 Admidio before 5.0.11 CSRF via category-report preferences 03.08.2026
CVE-2026-69094 Admidio before 5.0.11 IDOR via save_temporary mylist_function.php 03.08.2026
CVE-2026-69095 OpenWrt luci-app-bmx7 Path Traversal via bmx7-info 03.08.2026
CVE-2026-69096 OpenWrt luci-app-dockerman Read ACL Remote Code Execution 03.08.2026
CVE-2026-69097 GitPython before 3.1.53 Config Injection via Submodule Names 03.08.2026
CVE-2026-9390 XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup 03.08.2026
CVE-2026-9487 XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID 03.08.2026
CVE-2026-18574 Authentication Bypass in Check Point Security Management Server 03.08.2026
CVE-2026-18598 GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection 03.08.2026
CVE-2026-18599 GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection 03.08.2026
CVE-2026-2346 IDOR in Menulux Software's Mobile App 03.08.2026 9.8
CVE-2026-56608 HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609). 03.08.2026 3.7
CVE-2026-56609 HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609). 03.08.2026 4.8
CVE-2026-0392 eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update 03.08.2026
CVE-2026-33591 Authentication bypass on WaptServer 03.08.2026
CVE-2026-68742 Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr 03.08.2026
CVE-2026-69078 Server-Side Request Forgery and Local File Disclosure in CTI-Transmute Evaluation PDF Rendering 03.08.2026
CVE-2026-69079 Unauthenticated Denial of Service via Unbounded Activity-Timeline Range in CTI-Transmute 03.08.2026
CVE-2026-69082 Cross-Site Request Forgery in the Administrative User Deletion Endpoint 03.08.2026
CVE-2026-60011 03.08.2026 5.3
CVE-2026-62416 03.08.2026 5.3
CVE-2026-63545 03.08.2026 2.4
CVE-2026-63563 03.08.2026 6.5
CVE-2026-69075 Stored Cross-Site Scripting via Vue Template Injection in FlowIntel 03.08.2026
CVE-2026-12259 Improper Input Validation in nltk/nltk 03.08.2026
CVE-2026-18590 Wavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injection 03.08.2026
CVE-2026-18591 Meesho Online Shopping App com.meesho.supply cleartext storage 03.08.2026
CVE-2026-18592 osCommerce Email Template Configuration EmailController.php EmailController sql injection 03.08.2026
CVE-2026-18593 vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox 03.08.2026
CVE-2026-21548 03.08.2026 7.5
CVE-2026-21549 03.08.2026 7.5
CVE-2026-21550 03.08.2026 7.5
CVE-2026-21551 03.08.2026 7.5
CVE-2026-21552 03.08.2026 7.5
CVE-2026-21553 03.08.2026 7.5
CVE-2026-21554 03.08.2026 7.5
CVE-2026-21555 03.08.2026 7.5
CVE-2026-28147 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability 03.08.2026 5.4
CVE-2026-8793 PaperCut NG/MF: Insufficient brute-force protection 03.08.2026
CVE-2026-8794 PaperCut NG/MF: User enumeration via timing attack 03.08.2026
CVE-2025-15672 Chama < 1.0.13 - Unauthenticated PHP Object Injection 03.08.2026
CVE-2025-15673 Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read 03.08.2026
CVE-2026-12872 Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload 03.08.2026
CVE-2026-12965 Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking 03.08.2026
CVE-2026-13340 SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass 03.08.2026
CVE-2026-14557 SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass 03.08.2026
CVE-2026-15231 TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR 03.08.2026
CVE-2026-15254 Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode 03.08.2026
CVE-2026-15260 Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR 03.08.2026
CVE-2026-15383 Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header 03.08.2026
CVE-2026-15930 Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision 03.08.2026
CVE-2026-15931 Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name 03.08.2026
CVE-2026-16057 Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library 03.08.2026
CVE-2026-16060 Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload 03.08.2026
CVE-2026-16250 Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload 03.08.2026
CVE-2026-16274 Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts 03.08.2026
CVE-2026-16276 Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search 03.08.2026
CVE-2026-16289 ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group 03.08.2026
CVE-2026-16297 Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import 03.08.2026
CVE-2026-16300 Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset 03.08.2026
CVE-2026-16532 Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form 03.08.2026
CVE-2026-16534 Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import 03.08.2026
CVE-2026-16539 SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication 03.08.2026
CVE-2026-16563 Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint 03.08.2026
CVE-2026-16564 Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint 03.08.2026
CVE-2026-16565 Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API 03.08.2026
CVE-2026-16572 LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie 03.08.2026
CVE-2026-18587 Wavlink WL-NU516U1 Config Import os command injection 03.08.2026
CVE-2026-18588 Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow 03.08.2026
CVE-2026-18589 Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow 03.08.2026
CVE-2026-4793 03.08.2026 7.3
CVE-2026-9593 iDTM FDI Unauthorized Debug Interface Enablement 03.08.2026
CVE-2026-18583 mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-bounds 03.08.2026
CVE-2026-18584 GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization 03.08.2026
CVE-2026-18585 GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow 03.08.2026
CVE-2026-6694 Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk 03.08.2026
CVE-2026-6695 Gimp: gimp: remote code execution via crafted paa file 03.08.2026
CVE-2026-12802 CMS AuthEnvelopedData fails to enforce tag-length on decryption 03.08.2026
CVE-2026-12803 KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) 03.08.2026
CVE-2026-12816 IESEngine stream-mode MAC forgery via length-dependent KDF split 03.08.2026
CVE-2026-12817 OpenPGP AEAD decryption skips final tag on chunk-aligned data 03.08.2026
CVE-2026-12852 MLS wire decoder allocates attacker-declared opaque length before bounds check 03.08.2026
CVE-2026-12860 RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path 03.08.2026
CVE-2026-13506 Lazy ASN.1 sequence forcing resets nesting-depth guard 03.08.2026
CVE-2026-13586 PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS) 03.08.2026
CVE-2026-14682 Possible OOM from unbounded up-front allocation on a definite-length read 03.08.2026
CVE-2026-20464 03.08.2026
CVE-2026-20465 03.08.2026
CVE-2026-20466 03.08.2026
CVE-2026-20467 03.08.2026
CVE-2026-20468 03.08.2026
CVE-2026-20469 03.08.2026
CVE-2026-20470 03.08.2026
CVE-2026-20471 03.08.2026
CVE-2026-20472 03.08.2026
CVE-2026-20473 03.08.2026
CVE-2026-20474 03.08.2026
CVE-2026-20475 03.08.2026
CVE-2026-20476 03.08.2026
CVE-2026-20477 03.08.2026
CVE-2026-20478 03.08.2026
CVE-2026-20479 03.08.2026
CVE-2026-20480 03.08.2026
CVE-2026-20481 03.08.2026
CVE-2026-20482 03.08.2026
CVE-2026-20483 03.08.2026
CVE-2026-20484 03.08.2026
CVE-2026-20485 03.08.2026
CVE-2026-20486 03.08.2026
CVE-2026-20488 03.08.2026
CVE-2026-20489 03.08.2026
CVE-2026-20490 03.08.2026
CVE-2026-20491 03.08.2026
CVE-2026-20492 03.08.2026
CVE-2026-20493 03.08.2026
CVE-2026-20494 03.08.2026
CVE-2026-20495 03.08.2026
CVE-2026-20496 03.08.2026
CVE-2026-20497 03.08.2026
CVE-2026-20498 03.08.2026
CVE-2026-58059 Quadratic-time escaping when stringifying X.500 distinguished names 03.08.2026
CVE-2026-58060 HSS public-key level count unbounded, enabling huge allocation on verify 03.08.2026
CVE-2026-58061 CCM-family modes write plaintext to caller buffer before tag check 03.08.2026
CVE-2026-58062 Stapled OCSP response accepted without binding to the checked certificate 03.08.2026
CVE-2026-58063 BCFKS keystore load honours unbounded KDF cost from untrusted file 03.08.2026
CVE-2026-18582 mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap 03.08.2026
CVE-2026-12185 BKS/UBER keystore allocates from untrusted lengths before integrity check 03.08.2026
CVE-2026-15055 PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input 03.08.2026
CVE-2026-18581 ggml-org llama.cpp Jinja Minja Template parser.cpp assertion 03.08.2026
CVE-2026-59638 JSSE hostname verifier CN-fallback enabled by default despite documented opt-in 03.08.2026
CVE-2026-59639 CMS verifySignatures returns true for SignedData with zero signers 03.08.2026
CVE-2026-59640 OpenPGP CFB quick-check oracle active on symmetric/session-key paths 03.08.2026
CVE-2026-59641 S/MIME validator trusts signer-asserted signingTime for path validation 03.08.2026
CVE-2026-59642 CMS AuthenticatedData content not bound to MAC when authAttrs present 03.08.2026
CVE-2026-59643 OpenPGP inline-signature policy failures silently ignored 03.08.2026
CVE-2026-59644 MLS hash-ratchet honours arbitrary 32-bit generation counter from sender 03.08.2026
CVE-2026-59645 OER parser recurses without depth limit on self-referential IEEE 1609.2 schema 03.08.2026
CVE-2026-59646 DTLS handshake reassembler allocates buffer from unchecked 24-bit length 03.08.2026
CVE-2026-59647 CRMF/CMP password-MAC honours unbounded iteration count 03.08.2026
CVE-2026-59648 OpenPGP Argon2 S2K honours attacker-chosen memory and passes 03.08.2026
CVE-2026-59649 OpenPGP user-attribute subpacket length bounded only by JVM max memory 03.08.2026
CVE-2026-59650 MTI/A0 DH agreement exponentiates unvalidated peer value 03.08.2026
CVE-2026-59651 BKS keystore accepts legacy version with 16-bit integrity MAC key 03.08.2026
CVE-2026-59652 LDAP filter injection in legacy jdk1.4 LDAPStoreHelper 03.08.2026
CVE-2026-8763 Name Constraints bypass via trailing dot in rfc822Name and URI 03.08.2026
CVE-2026-65875 03.08.2026 7.1
CVE-2026-3245 03.08.2026
CVE-2026-18577 Incomplete patch leads to administrative account takeover 03.08.2026