Vulnerability Intelligence
HIGH & CRITICAL severity โ CVSS score โฅ 7.0
Total
1440
NVD
1342
CISA KEV
50
Exploit-DB
48
ANSSI
0
| CVE ID | Title | Severity | CVSS | Source | Published |
|---|---|---|---|---|---|
| CVE-2026-42391 | An unauthenticated attacker can send an IMAP ID command with a very large number | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-42007 | An attacker that has valid credentials can use a Sieve script with the editheade | CRITICAL | 9.1 | NVD | Aug 28, 2026 |
| CVE-2026-40018 | None None None No publicly available exploits are known | HIGH | 7.4 | NVD | Aug 28, 2026 |
| CVE-2026-40017 | An attacker that can send mail to a user can craft a message header whose values | MEDIUM | 6.5 | NVD | Aug 28, 2026 |
| CVE-2026-40014 | An attacker that can send mail to a user can craft a message header that makes t | MEDIUM | 6.5 | NVD | Aug 28, 2026 |
| CVE-2026-33605 | An unauthenticated attacker can crash the ManageSieve login process by sending a | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-27852 | An attacker that can send mail to a user can craft a message whose headers conta | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-40541 | An improper neutralization of input during web page generation ('Cross-site Scri | CRITICAL | 9.0 | NVD | Aug 28, 2026 |
| CVE-2026-19423 | The Ultimate Member WordPress plugin before 2 | HIGH | 8.1 | NVD | Aug 28, 2026 |
| CVE-2026-19084 | The shared-files-pro WordPress plugin before 1 | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-14558 | The User Frontend WordPress plugin before 4 | HIGH | 7.2 | NVD | Aug 28, 2026 |
| CVE-2026-12513 | The Shared Files WordPress plugin before 1 | MEDIUM | 6.8 | NVD | Aug 28, 2026 |
| CVE-2026-82082 | NUMail developed by Green-Computing has an OS Command Injection vulnerability | CRITICAL | 9.8 | NVD | Aug 28, 2026 |
| CVE-2026-82081 | wallabag 2 through 2 | MEDIUM | 6.4 | NVD | Aug 28, 2026 |
| CVE-2026-77365 | The Optimole โ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image O | HIGH | 7.2 | NVD | Aug 28, 2026 |
| CVE-2026-76053 | The TranslatePress โ Translate Multilingual sites with AI Translation plugin for | HIGH | 7.2 | NVD | Aug 28, 2026 |
| CVE-2026-3129 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scri | MEDIUM | 6.4 | NVD | Aug 28, 2026 |
| CVE-2026-18983 | The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-18978 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scri | HIGH | 7.2 | NVD | Aug 28, 2026 |
| CVE-2026-18324 | The Forminator Forms โ Contact Form, Payment Form & Custom Form Builder plugin f | HIGH | 7.2 | NVD | Aug 28, 2026 |
| CVE-2026-16759 | The Tutor LMS โ eLearning and online course solution plugin for WordPress is vul | MEDIUM | 6.5 | NVD | Aug 28, 2026 |
| CVE-2026-16654 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Si | MEDIUM | 6.4 | NVD | Aug 28, 2026 |
| CVE-2026-15798 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scrip | MEDIUM | 6.4 | NVD | Aug 28, 2026 |
| CVE-2026-54330 | Ceph is an open-source distributed storage platform providing object, block, and | HIGH | 8.1 | NVD | Aug 28, 2026 |
| CVE-2026-54085 | Wazuh is an open-source security platform providing unified XDR and SIEM protect | HIGH | 7.1 | NVD | Aug 28, 2026 |
| CVE-2026-54083 | Wazuh is an open-source security platform providing unified XDR and SIEM protect | HIGH | 8.1 | NVD | Aug 28, 2026 |
| CVE-2026-50152 | Ceph is an open-source distributed storage platform providing object, block, and | CRITICAL | 9.1 | NVD | Aug 28, 2026 |
| CVE-2026-44629 | Improper access control to the Synergis Softwire installation folder | HIGH | 7.9 | NVD | Aug 28, 2026 |
| CVE-2026-39944 | Ceph is an open-source distributed storage platform providing object, block, and | HIGH | 8.8 | NVD | Aug 28, 2026 |
| CVE-2026-38350 | An integer overflow in the target_sws_fuzzer() function (libswscale/output | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-38349 | An integer overflow in the hScale16To19_c() function (libswscale/output | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-38348 | An integer overflow in the libswscale/utils | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-38346 | An integer overflow in the yuv2planeX_8_c() function (libswscale/output | HIGH | 7.5 | NVD | Aug 28, 2026 |
| CVE-2026-18965 | PayRange APIย is missing proper authorization on management endpoints, which allo | HIGH | 8.8 | NVD | Aug 28, 2026 |
| CVE-2026-18717 | ASE2000 2 | HIGH | 7.4 | NVD | Aug 28, 2026 |
| CVE-2025-30156 | Ceph is an open-source distributed storage platform providing object, block, and | HIGH | 8.9 | NVD | Aug 28, 2026 |
| CVE-2026-81658 | A flaw was found in Foreman | MEDIUM | 6.5 | NVD | Aug 27, 2026 |
| CVE-2026-74233 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, an | CRITICAL | 9.8 | NVD | Aug 27, 2026 |
| CVE-2026-74232 | Zbtlink L3_V2_8 firmware 3 | CRITICAL | 9.8 | NVD | Aug 27, 2026 |
| CVE-2026-66155 | A vulnerability has been identified in Element maps-ng V47 (All versions < V47 | HIGH | 7.6 | NVD | Aug 27, 2026 |
| CVE-2026-17562 | Authorization bypass through User-Controlled key vulnerability in Summit Securit | MEDIUM | 6.5 | NVD | Aug 27, 2026 |
| CVE-2026-13415 | The CMP WordPress plugin before 4 | HIGH | 7.2 | NVD | Aug 27, 2026 |
| CVE-2026-47856 | Spring Integration's JSON to object conversion uses the json__TypeId__ header to | MEDIUM | 6.3 | NVD | Aug 27, 2026 |
| CVE-2026-47852 | A local attacker on a multi-user host can pre-create the deterministic cache pat | HIGH | 7.5 | NVD | Aug 27, 2026 |
| CVE-2026-47851 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a Sta | HIGH | 7.5 | NVD | Aug 27, 2026 |
| CVE-2026-66384 | JFrog - Artifactory | CRITICAL | N/A | CISA | Aug 27, 2026 |
| CVE-2023-49105 | ownCloud - ownCloud | CRITICAL | N/A | CISA | Aug 27, 2026 |
| CVE-2026-53362 | Linux - Kernel | CRITICAL | N/A | CISA | Aug 27, 2026 |
| CVE-2026-81203 | A vulnerability has been found in SourceCodester Simple Online Food Ordering Sys | HIGH | 7.3 | NVD | Aug 26, 2026 |
| CVE-2026-75340 | The device metadata import interface /device/instance/{productId}/property-metad | CRITICAL | 9.1 | NVD | Aug 26, 2026 |
| CVE-2026-75338 | disconf (Distributed Configuration Management Platform) 2 | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2026-75336 | Funiture 1 | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2026-75332 | Zyplayer-Doc <=1 | CRITICAL | 9.1 | NVD | Aug 26, 2026 |
| CVE-2026-75330 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of s | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2026-47666 | Penpot is an open-source design and prototyping platform | HIGH | 7.6 | NVD | Aug 26, 2026 |
| CVE-2026-47665 | Penpot is an open-source design and prototyping platform | HIGH | 8.7 | NVD | Aug 26, 2026 |
| CVE-2025-61163 | Cohere North AI v1 | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2025-61162 | Incorrect access control in Cohere North AI v1 | HIGH | 7.5 | NVD | Aug 26, 2026 |
| CVE-2026-58474 | whichllm before 0 | HIGH | 8.8 | NVD | Aug 26, 2026 |
| CVE-2026-47841 | An application using Spring Security's WebAuthn support may be vulnerable to use | HIGH | 7.4 | NVD | Aug 26, 2026 |
| CVE-2026-47837 | Missing Authentication for Critical Function vulnerability in Spring Spring Clou | MEDIUM | 6.8 | NVD | Aug 26, 2026 |
| CVE-2026-47836 | The base directory (spring | HIGH | 7.2 | NVD | Aug 26, 2026 |
| CVE-2026-32639 | Winter CMS is a content management system built on the Laravel PHP framework | MEDIUM | 6.8 | NVD | Aug 26, 2026 |
| CVE-2025-56798 | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc | HIGH | 8.8 | NVD | Aug 26, 2026 |
| CVE-2026-32258 | Winter is a free, open-source content management system (CMS) based on the Larav | HIGH | 8.1 | NVD | Aug 26, 2026 |
| CVE-2026-32257 | Winter is a free, open-source content management system (CMS) based on the Larav | HIGH | 8.1 | NVD | Aug 26, 2026 |
| CVE-2026-63041 | Apisix โ Reliance on Untrusted Inputs in a Security Decision vulnerab | HIGH | 8.8 | NVD | Aug 26, 2026 |
| CVE-2026-15985 | The Classified Listing - Mobile Number Verification plugin for WordPress is vuln | HIGH | 8.1 | NVD | Aug 26, 2026 |
| CVE-2026-80205 | NLTK versions before 3 | HIGH | 7.5 | NVD | Aug 26, 2026 |
| CVE-2026-80203 | The getgrav/grav-plugin-api plugin before 1 | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2026-77557 | A malicious actor with access to the network could exploit an Improper Access Co | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2026-77554 | A malicious actor with access to the network could exploit an Improper Input Val | CRITICAL | 10.0 | NVD | Aug 26, 2026 |
| CVE-2026-77553 | A malicious actor with access to the network and low privileges could exploit an | CRITICAL | 9.9 | NVD | Aug 26, 2026 |
| CVE-2026-77552 | A malicious actor with access to the network could exploit an Improper Input Val | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2026-77551 | A malicious actor with access to the network and under certain conditions could | CRITICAL | 9.0 | NVD | Aug 26, 2026 |
| CVE-2026-77550 | A malicious actor with access to the network could exploit an Improper Neutraliz | CRITICAL | 10.0 | NVD | Aug 26, 2026 |
| CVE-2026-77549 | A malicious actor with access to the network and under certain conditions could | CRITICAL | 9.0 | NVD | Aug 26, 2026 |
| CVE-2026-77548 | A malicious actor with access to the network and low privileges could exploit an | CRITICAL | 9.9 | NVD | Aug 26, 2026 |
| CVE-2026-77547 | A malicious actor with access to the network and low privileges could exploit an | CRITICAL | 9.9 | NVD | Aug 26, 2026 |
| CVE-2026-77546 | A malicious actor with access to the network and low privileges could exploit an | CRITICAL | 9.9 | NVD | Aug 26, 2026 |
| CVE-2026-77532 | A malicious actor with access to an adjacent network could exploit a Buffer Over | CRITICAL | 9.6 | NVD | Aug 26, 2026 |
| CVE-2026-5092 | The Greenshift โ animation and page builder blocks plugin for WordPress is vulne | MEDIUM | 6.4 | NVD | Aug 26, 2026 |
| CVE-2026-18080 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for Wo | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2026-80196 | Kimai before 2 | HIGH | 7.5 | NVD | Aug 26, 2026 |
| CVE-2026-80193 | Kimai before 2 | HIGH | 8.8 | NVD | Aug 26, 2026 |
| CVE-2026-80192 | @better-auth/sso before 1 | HIGH | 8.1 | NVD | Aug 26, 2026 |
| CVE-2026-80191 | GROWI applies its page-viewer permission check to attachment requests only when | HIGH | 7.5 | NVD | Aug 26, 2026 |
| CVE-2026-80189 | LeafWiki extracts an uploaded ZIP archive without limiting how much data it will | MEDIUM | 6.5 | NVD | Aug 26, 2026 |
| CVE-2026-58092 | In FreeBSD 15 | HIGH | 8.1 | NVD | Aug 26, 2026 |
| CVE-2026-58091 | The implementation of this ioctl attempts to acquire locks on all channels in a | HIGH | 7.8 | NVD | Aug 26, 2026 |
| CVE-2026-58090 | The SOCK_STREAM receive path in the unix socket implementation failed to fully d | HIGH | 7.8 | NVD | Aug 26, 2026 |
| CVE-2026-58089 | When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is | HIGH | 7.8 | NVD | Aug 26, 2026 |
| CVE-2026-57171 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing | HIGH | 7.7 | NVD | Aug 26, 2026 |
| CVE-2026-57170 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing | HIGH | 7.8 | NVD | Aug 26, 2026 |
| CVE-2026-54467 | On the Trusted Firmware-M (TF-M) 2 through 2 | HIGH | 7.0 | NVD | Aug 26, 2026 |
| CVE-2026-29988 | A cleartext transmission of sensitive information vulnerability in the NFC inter | HIGH | 7.6 | NVD | Aug 26, 2026 |
| CVE-2026-19632 | The TranslatePress โ Translate Multilingual sites with AI Translation plugin for | CRITICAL | 9.8 | NVD | Aug 26, 2026 |
| CVE-2019-1068 | Microsoft - SQL Server | CRITICAL | N/A | CISA | Aug 26, 2026 |
| CVE-2015-3246 | Red Hat - Libuser | CRITICAL | N/A | CISA | Aug 26, 2026 |
| CVE-2015-5287 | Red Hat - Automatic Bug Reporting Tool | CRITICAL | N/A | CISA | Aug 26, 2026 |
| CVE-2022-0995 | Linux - Kernel | CRITICAL | N/A | CISA | Aug 26, 2026 |
| CVE-2026-8452 | Citrix - NetScaler ADC and NetScaler Gateway | CRITICAL | N/A | CISA | Aug 26, 2026 |
| CVE-2021-23758 | Ajax.NET Professional - Ajax.NET Professional | CRITICAL | N/A | CISA | Aug 26, 2026 |
| CVE-2026-54757 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing | HIGH | 7.8 | NVD | Aug 25, 2026 |
| CVE-2026-41707 | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security | HIGH | 7.4 | NVD | Aug 25, 2026 |
| CVE-2026-18985 | Incorrect Authorization vulnerability in Drupal Edit in-place field allows Force | HIGH | 8.1 | NVD | Aug 25, 2026 |
| CVE-2026-18259 | Observable Timing Discrepancy vulnerability in Drupal Token Content Access allow | HIGH | 7.5 | NVD | Aug 25, 2026 |
| CVE-2026-16645 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript | CRITICAL | 9.1 | NVD | Aug 25, 2026 |
| CVE-2026-16644 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Bro | CRITICAL | 9.1 | NVD | Aug 25, 2026 |
| CVE-2026-16641 | Vulnerability in Drupal Commerce Elavon | CRITICAL | 9.8 | NVD | Aug 25, 2026 |
| CVE-2026-16640 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti | MEDIUM | 6.1 | NVD | Aug 25, 2026 |
| CVE-2026-16639 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal | CRITICAL | 9.8 | NVD | Aug 25, 2026 |
| CVE-2026-16638 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripti | MEDIUM | 6.1 | NVD | Aug 25, 2026 |
| CVE-2026-55553 | urllib is an HTTP client for Node | HIGH | 7.5 | NVD | Aug 25, 2026 |
| CVE-2026-47626 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privil | HIGH | 8.2 | NVD | Aug 25, 2026 |
| CVE-2026-47624 | NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/a | MEDIUM | 6.0 | NVD | Aug 25, 2026 |
| CVE-2026-24263 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privil | HIGH | 8.2 | NVD | Aug 25, 2026 |
| CVE-2026-24262 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privil | HIGH | 8.2 | NVD | Aug 25, 2026 |
| CVE-2026-24225 | NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an | MEDIUM | 6.0 | NVD | Aug 25, 2026 |
| CVE-2026-24170 | NVIDIA UFM Enterprise contains a vulnerability in the web interface authorizatio | HIGH | 8.8 | NVD | Aug 25, 2026 |
| CVE-2026-24169 | NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, whe | HIGH | 8.0 | NVD | Aug 25, 2026 |
| CVE-2026-24168 | NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an aut | MEDIUM | 6.8 | NVD | Aug 25, 2026 |
| CVE-2026-24167 | NVIDIA UFM Enterprise contains a vulnerability in the user management component, | MEDIUM | 6.8 | NVD | Aug 25, 2026 |
| CVE-2026-19913 | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure v | HIGH | 7.5 | NVD | Aug 25, 2026 |
| CVE-2026-18445 | There is an integer overflow vulnerability resulting in an out-of-bounds write r | MEDIUM | 6.6 | NVD | Aug 25, 2026 |
| CVE-2026-18444 | There is an integer conversion vulnerability resulting in an out-of-bounds read | MEDIUM | 6.6 | NVD | Aug 25, 2026 |
| CVE-2026-16234 | There is a memory corruption vulnerability recently discovered in NI LabVIEW tha | HIGH | 7.8 | NVD | Aug 25, 2026 |
| CVE-2026-16233 | There is a memory corruption vulnerability recently discovered in NI LabVIEW tha | HIGH | 7.8 | NVD | Aug 25, 2026 |
| CVE-2026-13216 | The virtio PCI driver (drivers/virtio/virtio_pci | MEDIUM | 6.1 | NVD | Aug 25, 2026 |
| CVE-2026-75971 | The ShopEngine Elementor WooCommerce Builder Addon โ All in One WooCommerce Solu | HIGH | 7.2 | NVD | Aug 25, 2026 |
| CVE-2026-19949 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL | HIGH | 8.8 | NVD | Aug 25, 2026 |
| CVE-2026-18547 | The Ultimate Member โ User Profile, Registration, Login, Member Directory, Conte | MEDIUM | 6.4 | NVD | Aug 25, 2026 |
| CVE-2026-78863 | A vulnerability was found in liketrek TREK up to 3 | MEDIUM | 6.3 | NVD | Aug 25, 2026 |
| CVE-2026-59335 | Improper handling of case sensitivity (CWE-178) in the identity zone authorizati | HIGH | 8.7 | NVD | Aug 25, 2026 |
| CVE-2026-55976 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hiv | CRITICAL | 9.1 | NVD | Aug 25, 2026 |
| CVE-2026-53561 | An improper authentication vulnerability in HiveServer2 SAML bearer-token valida | HIGH | 7.4 | NVD | Aug 25, 2026 |
| CVE-2026-49845 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache H | CRITICAL | 9.8 | NVD | Aug 25, 2026 |
| CVE-2026-18100 | The MetForm โ Contact Form, Survey, Quiz, & Custom Form Builder for Elementor pl | MEDIUM | 6.4 | NVD | Aug 25, 2026 |
| CVE-2026-16601 | The CM Map Locations โ Visualize and share your locations in a few clicks plugin | HIGH | 8.8 | NVD | Aug 25, 2026 |
| CVE-2026-78656 | A vulnerability was found in itsourcecode Sales and Inventory System 1 | MEDIUM | 6.3 | NVD | Aug 25, 2026 |
| CVE-2026-78654 | A vulnerability has been found in cleverbrush framework and deep up to 4 | HIGH | 7.3 | NVD | Aug 25, 2026 |
| CVE-2026-78478 | The Mane theme for WordPress is vulnerable to Local File Inclusion in all versio | HIGH | 8.1 | NVD | Aug 25, 2026 |
| CVE-2026-78477 | The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versio | CRITICAL | 9.8 | NVD | Aug 25, 2026 |
| CVE-2026-78470 | The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection i | MEDIUM | 6.5 | NVD | Aug 25, 2026 |
| CVE-2026-78637 | A vulnerability was detected in Fdawgs node-poppler up to 9 | HIGH | 7.3 | NVD | Aug 25, 2026 |
| CVE-2026-13215 | The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field o | MEDIUM | 6.8 | NVD | Aug 25, 2026 |
| CVE-2026-13214 | The OCPP 1 | CRITICAL | 9.8 | NVD | Aug 25, 2026 |
| CVE-2026-12561 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scri | MEDIUM | 6.4 | NVD | Aug 25, 2026 |
| CVE-2026-56706 | Adminer before 5 | MEDIUM | 6.8 | NVD | Aug 25, 2026 |
| CVE-2026-56705 | Adminer before 5 | CRITICAL | 9.8 | NVD | Aug 25, 2026 |
| CVE-2026-56704 | Adminer before 5 | MEDIUM | 6.1 | NVD | Aug 25, 2026 |
| CVE-2026-56703 | Adminer before 5 | HIGH | 7.2 | NVD | Aug 25, 2026 |
| CVE-2026-56702 | Adminer versions before 5 | HIGH | 8.8 | NVD | Aug 25, 2026 |
| CVE-2026-34968 | Adminer before 5 | HIGH | 8.1 | NVD | Aug 25, 2026 |
| CVE-2026-15023 | The Events Manager โ Calendar, Bookings, Tickets, and more! plugin for WordPress | MEDIUM | 6.5 | NVD | Aug 25, 2026 |
| CVE-2026-66766 | SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular | HIGH | 7.5 | NVD | Aug 25, 2026 |
| CVE-2026-55373 | OpenEXR is the reference implementation and specification for the EXR image form | MEDIUM | 6.2 | NVD | Aug 25, 2026 |
| CVE-2026-55059 | OpenEXR is the reference implementation and specification for the EXR image form | MEDIUM | 6.1 | NVD | Aug 25, 2026 |
| EDB-52658 | [remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE | HIGH | 8.1 | EXPLOIT-DB | Aug 25, 2026 |
| CVE-2026-60004 | Gitea - Gitea | CRITICAL | N/A | CISA | Aug 25, 2026 |
| CVE-2026-78465 | A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only | HIGH | 7.0 | NVD | Aug 24, 2026 |
| CVE-2026-77915 | rConfig Core 8 | CRITICAL | 9.8 | NVD | Aug 24, 2026 |
| CVE-2026-77914 | rConfig Core 8 | MEDIUM | 6.5 | NVD | Aug 24, 2026 |
| CVE-2026-71300 | Improper input validation vulnerability in Apache Camel Atmosphere Websocket com | CRITICAL | 9.8 | NVD | Aug 24, 2026 |
| CVE-2026-66908 | Improper Authentication vulnerability in Apache Camel Platform HTTP Main compone | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-66907 | Relative path traversal vulnerability in Apache Camel Google Storage component | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-66906 | Relative path traversal vulnerability in Apache Camel Azure Storage Blob compone | CRITICAL | 9.1 | NVD | Aug 24, 2026 |
| CVE-2026-59230 | Improper input validation vulnerability in Apache Camel | MEDIUM | 6.5 | NVD | Aug 24, 2026 |
| CVE-2026-19685 | NetworkManager did not apply the private_user restriction to the 802-1x | HIGH | 7.1 | NVD | Aug 24, 2026 |
| CVE-2025-36940 | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which cou | HIGH | 8.8 | NVD | Aug 24, 2026 |
| CVE-2026-32477 | Unauthenticated Arbitrary File Deletion in ShopBuilder Pro โ Elementor WooCommer | HIGH | 8.6 | NVD | Aug 24, 2026 |
| CVE-2026-32476 | Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0 | HIGH | 7.1 | NVD | Aug 24, 2026 |
| CVE-2026-32471 | Subscriber SQL Injection in ProLancer Element <= 1 | HIGH | 8.5 | NVD | Aug 24, 2026 |
| CVE-2026-28190 | Subscriber Broken Access Control in ProLancer Element <= 1 | HIGH | 7.1 | NVD | Aug 24, 2026 |
| CVE-2026-28171 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10 | HIGH | 8.6 | NVD | Aug 24, 2026 |
| CVE-2026-28167 | Unauthenticated Arbitrary File Download in Super Forms <= 6 | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-28166 | Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5 | HIGH | 7.1 | NVD | Aug 24, 2026 |
| CVE-2026-28165 | Unauthenticated Privilege Escalation in Digits <= 9 | CRITICAL | 9.8 | NVD | Aug 24, 2026 |
| CVE-2026-28162 | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3 | HIGH | 7.1 | NVD | Aug 24, 2026 |
| CVE-2026-28153 | Unauthenticated Broken Access Control in Notification Master – Real-Time W | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-28152 | Unauthenticated Local File Inclusion in Tonda Core < 2 | HIGH | 8.1 | NVD | Aug 24, 2026 |
| CVE-2026-28151 | Unauthenticated Local File Inclusion in Tonda < 2 | HIGH | 8.1 | NVD | Aug 24, 2026 |
| CVE-2026-78245 | A flaw has been found in itsourcecode Online Pharmacy System 1 | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-78244 | A vulnerability was detected in itsourcecode Real Estate Management System 1 | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-76172 | fast-uri is a URI parser for Node | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-10582 | Hugo's security | HIGH | 7.4 | NVD | Aug 24, 2026 |
| CVE-2026-75931 | fast-uri is a URI parser for Node | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-75899 | fast-uri is a URI parser for Node | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-66897 | A path traversal vulnerability in LXD's instance template processing allows an a | CRITICAL | 9.9 | NVD | Aug 24, 2026 |
| CVE-2026-78202 | A vulnerability was found in itsourcecode Payroll System 1 | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-78201 | A vulnerability has been found in itsourcecode Payroll System 1 | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-78200 | A flaw has been found in itsourcecode Library Management System 1 | MEDIUM | 6.3 | NVD | Aug 24, 2026 |
| CVE-2026-78199 | A vulnerability was detected in SourceCodester Simple Online Food Ordering Syste | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-78198 | A security vulnerability has been detected in SourceCodester Simple Online Food | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-78197 | A weakness has been identified in SourceCodester Simple Online Food Ordering Sys | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-78167 | A weakness has been identified in EFM ipTIME T16000M 14 | CRITICAL | 10.0 | NVD | Aug 24, 2026 |
| CVE-2026-78166 | A security flaw has been discovered in provectus kafka-ui up to 0 | MEDIUM | 6.3 | NVD | Aug 24, 2026 |
| CVE-2026-78209 | exceljs-hardened versions before 5 | HIGH | 8.2 | NVD | Aug 24, 2026 |
| CVE-2026-78208 | exceljs-hardened before 5 | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-78207 | exceljs-hardened before 5 | CRITICAL | 9.4 | NVD | Aug 24, 2026 |
| CVE-2026-78206 | exceljs-hardened before 5 | HIGH | 7.5 | NVD | Aug 24, 2026 |
| CVE-2026-78203 | Ghostwriter before 7 | HIGH | 7.1 | NVD | Aug 24, 2026 |
| CVE-2026-78161 | A vulnerability was found in warmcat libwebsockets 4 | HIGH | 7.3 | NVD | Aug 24, 2026 |
| CVE-2026-78160 | A vulnerability has been found in Dolibarr ERP up to 18 | MEDIUM | 6.3 | NVD | Aug 24, 2026 |
| CVE-2026-78158 | A flaw has been found in Open5GS 2 | MEDIUM | 6.3 | NVD | Aug 24, 2026 |
| CVE-2026-78157 | A vulnerability was detected in Open5GS 2 | HIGH | 7.4 | NVD | Aug 24, 2026 |
| CVE-2026-78156 | A security vulnerability has been detected in Open5GS 2 | HIGH | 7.4 | NVD | Aug 24, 2026 |
| CVE-2026-21962 | Oracle - HTTP Server and Oracle Weblogic Server Proxy Plug-in | CRITICAL | N/A | CISA | Aug 24, 2026 |
| CVE-2026-78147 | A vulnerability was found in ggml-org llama | HIGH | 7.3 | NVD | Aug 23, 2026 |
| CVE-2026-78144 | A vulnerability was identified in code-projects Barangay Resident Profiling Mana | MEDIUM | 6.3 | NVD | Aug 23, 2026 |
| CVE-2026-78143 | A vulnerability was determined in code-projects Barangay Resident Profiling Mana | HIGH | 7.3 | NVD | Aug 23, 2026 |
| CVE-2026-78142 | A vulnerability was found in code-projects Barangay Resident Profiling Managemen | MEDIUM | 6.3 | NVD | Aug 23, 2026 |
| CVE-2026-78141 | A vulnerability has been found in Tenda CH22 1 | HIGH | 7.4 | NVD | Aug 23, 2026 |
| CVE-2026-9769 | justhtml through 1 | HIGH | 7.5 | NVD | Aug 23, 2026 |
| CVE-2026-8630 | justhtml before 1 | MEDIUM | 6.1 | NVD | Aug 23, 2026 |
| CVE-2026-8445 | justhtml versions <= 1 | CRITICAL | 9.8 | NVD | Aug 23, 2026 |
| CVE-2026-7808 | justhtml before 1 | CRITICAL | 9.8 | NVD | Aug 23, 2026 |
| CVE-2026-77088 | justhtml versions 0 | MEDIUM | 6.1 | NVD | Aug 23, 2026 |
| CVE-2026-74793 | justhtml before 3 | MEDIUM | 6.1 | NVD | Aug 23, 2026 |
| CVE-2026-6827 | justhtml before 1 | MEDIUM | 6.1 | NVD | Aug 23, 2026 |
| CVE-2026-5751 | justhtml versions 1 | MEDIUM | 6.1 | NVD | Aug 23, 2026 |
| CVE-2026-5389 | justhtml versions before 1 | MEDIUM | 6.1 | NVD | Aug 23, 2026 |
| CVE-2026-5388 | justhtml before 1 | CRITICAL | 9.8 | NVD | Aug 23, 2026 |
| CVE-2026-4671 | justhtml before 1 | HIGH | 7.5 | NVD | Aug 23, 2026 |
| CVE-2026-78155 | privilege escalation in StackGres operator allows a low-privilege tenant who own | CRITICAL | 9.9 | NVD | Aug 23, 2026 |
| CVE-2026-78112 | A flaw has been found in itsourcecode Hospital Management System Project in PHP | MEDIUM | 6.3 | NVD | Aug 23, 2026 |
| CVE-2026-10053 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18 | HIGH | 8.5 | NVD | Aug 23, 2026 |
| CVE-2026-77115 | Brave Popup Builder (brave-popup-builder) up to version 0 | HIGH | 7.1 | NVD | Aug 23, 2026 |
| CVE-2026-78063 | A security flaw has been discovered in Tenda CH22 1 | HIGH | 7.4 | NVD | Aug 23, 2026 |
| CVE-2026-78062 | A vulnerability was identified in vas3k TaxHacker up to 0 | HIGH | 7.3 | NVD | Aug 23, 2026 |
| CVE-2026-78061 | A vulnerability was determined in vas3k TaxHacker up to 0 | MEDIUM | 6.3 | NVD | Aug 23, 2026 |
| CVE-2026-78057 | A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e903 | MEDIUM | 6.3 | NVD | Aug 23, 2026 |
| CVE-2026-78056 | A vulnerability was detected in sambitraj Student-Management-System up to 56ba28 | MEDIUM | 6.3 | NVD | Aug 23, 2026 |
| CVE-2026-78136 | chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data | HIGH | 7.8 | NVD | Aug 23, 2026 |
| CVE-2026-78050 | A vulnerability was found in Comfast CF-N1-S 2 | CRITICAL | 9.9 | NVD | Aug 23, 2026 |
| CVE-2026-18027 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping | MEDIUM | 6.5 | NVD | Aug 23, 2026 |
| CVE-2026-16149 | The Security Hardener plugin for WordPress is vulnerable to Missing Authorizatio | HIGH | 8.8 | NVD | Aug 23, 2026 |
| CVE-2026-0551 | The PPWP โ Password Protect Pages plugin for WordPress is vulnerable to PHP Obje | HIGH | 8.8 | NVD | Aug 23, 2026 |
| CVE-2026-78122 | docker-socket-proxy fails to properly gate read endpoints in the /containers Doc | HIGH | 7.4 | NVD | Aug 22, 2026 |
| CVE-2026-47895 | In strongSwan before 6 | HIGH | 7.5 | NVD | Aug 22, 2026 |
| CVE-2026-59808 | AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability w | HIGH | 8.8 | NVD | Aug 22, 2026 |
| CVE-2026-59256 | WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerabili | HIGH | 7.5 | NVD | Aug 22, 2026 |
| CVE-2026-58003 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulner | HIGH | 7.1 | NVD | Aug 22, 2026 |
| CVE-2026-58002 | WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an | MEDIUM | 6.5 | NVD | Aug 22, 2026 |
| CVE-2026-57998 | better-npm-audit through 3 | HIGH | 7.8 | NVD | Aug 22, 2026 |
| CVE-2026-77988 | A weakness has been identified in TRENDnet TEW-823DRU 1 | MEDIUM | 6.6 | NVD | Aug 22, 2026 |
| CVE-2026-77946 | A vulnerability was determined in TRENDnet TEW-821DAP 2 | CRITICAL | 10.0 | NVD | Aug 22, 2026 |
| CVE-2026-77945 | A vulnerability was found in TRENDnet TEW-821DAP 2 | HIGH | 7.4 | NVD | Aug 22, 2026 |
| CVE-2026-78003 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Requ | CRITICAL | 9.8 | NVD | Aug 22, 2026 |
| CVE-2026-77002 | The SmilePass Selfie Login WordPress plugin through 1 | CRITICAL | 9.8 | NVD | Aug 22, 2026 |
| CVE-2026-77001 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin t | CRITICAL | 9.8 | NVD | Aug 22, 2026 |
| CVE-2026-77000 | The WP Social Media Login WordPress plugin through 1 | CRITICAL | 9.8 | NVD | Aug 22, 2026 |
| CVE-2026-76793 | The Firebase Authentication WordPress plugin before 1 | HIGH | 8.1 | NVD | Aug 22, 2026 |
| CVE-2026-76789 | The Slider Hero with Video Background, Animation WordPress plugin before 9 | HIGH | 8.8 | NVD | Aug 22, 2026 |
| CVE-2026-19222 | The Forminator Forms WordPress plugin before 1 | MEDIUM | 6.6 | NVD | Aug 22, 2026 |
| CVE-2026-19221 | The Forminator Forms WordPress plugin before 1 | HIGH | 7.2 | NVD | Aug 22, 2026 |
| CVE-2026-19093 | The Tutor LMS WordPress plugin before 4 | MEDIUM | 6.8 | NVD | Aug 22, 2026 |
| CVE-2026-18052 | The ManageWP Worker WordPress plugin before 4 | HIGH | 8.1 | NVD | Aug 22, 2026 |
| CVE-2026-16260 | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1 | MEDIUM | 6.8 | NVD | Aug 22, 2026 |
| CVE-2026-19883 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorize | HIGH | 8.8 | NVD | Aug 22, 2026 |
| CVE-2026-53525 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client | HIGH | 7.4 | NVD | Aug 21, 2026 |
| CVE-2026-53524 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client | MEDIUM | 6.5 | NVD | Aug 21, 2026 |
| CVE-2026-34949 | Combodo iTop is a web based IT service management tool | MEDIUM | 6.5 | NVD | Aug 21, 2026 |
| CVE-2026-34948 | Combodo iTop is a web based IT service management tool | HIGH | 7.7 | NVD | Aug 21, 2026 |
| CVE-2026-39909 | llama | HIGH | 8.1 | NVD | Aug 21, 2026 |
| CVE-2026-59279 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not | HIGH | 7.5 | NVD | Aug 21, 2026 |
| CVE-2026-19848 | The ProfilePress WordPress plugin before 4 | MEDIUM | 6.5 | NVD | Aug 21, 2026 |
| CVE-2026-77769 | The report | MEDIUM | 6.5 | NVD | Aug 21, 2026 |
| CVE-2026-77768 | The report | MEDIUM | 6.5 | NVD | Aug 21, 2026 |
| CVE-2026-77767 | Reconmap's API applies a fallback authorization policy in apps/api/app/Program | HIGH | 7.5 | NVD | Aug 21, 2026 |
| CVE-2026-77763 | The filestore backend in pkg/object/file | MEDIUM | 6.5 | NVD | Aug 21, 2026 |
| CVE-2026-77683 | A security flaw has been discovered in Comfast CF-N1-S 2 | CRITICAL | 9.9 | NVD | Aug 21, 2026 |
| CVE-2026-77086 | SiYuan before v3 | CRITICAL | 9.1 | NVD | Aug 21, 2026 |
| CVE-2026-50112 | SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a | HIGH | 8.8 | NVD | Aug 21, 2026 |
| CVE-2026-77264 | The Automation Web Platform โ Notifications and OTP for WooCommerce, Advanced Co | CRITICAL | 9.8 | NVD | Aug 21, 2026 |
| CVE-2026-16323 | Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics | HIGH | 7.5 | NVD | Aug 21, 2026 |
| CVE-2026-75796 | The AI Engine WordPress plugin before 3 | HIGH | 7.2 | NVD | Aug 21, 2026 |
| CVE-2026-18781 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin befor | HIGH | 8.1 | NVD | Aug 21, 2026 |
| CVE-2026-16959 | The Media Library Assistant WordPress plugin before 3 | MEDIUM | 6.8 | NVD | Aug 21, 2026 |
| CVE-2026-16576 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress pl | HIGH | 7.2 | NVD | Aug 21, 2026 |
| CVE-2026-14601 | The Link Whisper Free WordPress plugin before 0 | MEDIUM | 6.8 | NVD | Aug 21, 2026 |
| CVE-2026-18409 | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scriptin | HIGH | 7.2 | NVD | Aug 21, 2026 |
| CVE-2026-73267 | A flaw was found in the clusterclaims-controller component of multicluster engin | HIGH | 7.7 | NVD | Aug 21, 2026 |
| CVE-2026-77392 | A weakness has been identified in SourceCodester Dynamic Input Field Generator U | MEDIUM | 6.3 | NVD | Aug 21, 2026 |
| CVE-2026-77651 | The arrayref crate 0 | CRITICAL | 9.8 | NVD | Aug 21, 2026 |
| CVE-2026-77650 | The append-only-vec crate 0 | CRITICAL | 9.8 | NVD | Aug 21, 2026 |
| CVE-2026-77649 | The internment crate 0 | CRITICAL | 9.8 | NVD | Aug 21, 2026 |
| CVE-2026-77647 | SPIP before 4 | CRITICAL | 9.8 | NVD | Aug 20, 2026 |
| CVE-2026-66590 | Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7 | HIGH | 7.1 | NVD | Aug 20, 2026 |
| CVE-2026-66586 | Author Local File Inclusion in WP Cafe Pro < 3 | MEDIUM | 6.6 | NVD | Aug 20, 2026 |
| CVE-2026-66583 | Unauthenticated PHP Object Injection in Forminator <= 1 | CRITICAL | 9.8 | NVD | Aug 20, 2026 |
| CVE-2026-66582 | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3 | HIGH | 7.1 | NVD | Aug 20, 2026 |
| CVE-2026-66581 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3 | HIGH | 7.1 | NVD | Aug 20, 2026 |
| CVE-2026-28150 | Unauthenticated Local File Inclusion in Golo Framework < 1 | HIGH | 8.1 | NVD | Aug 20, 2026 |
| CVE-2025-53999 | Unauthenticated Broken Access Control in Altair <= 5 | MEDIUM | 6.5 | NVD | Aug 20, 2026 |
| CVE-2025-15689 | Unauthenticated Privilege Escalation in Capella <= 2 | CRITICAL | 9.8 | NVD | Aug 20, 2026 |
| CVE-2025-15688 | Unauthenticated SQL Injection in Capella <= 2 | CRITICAL | 9.3 | NVD | Aug 20, 2026 |
| CVE-2025-15637 | Unauthenticated Local File Inclusion in Shuffle <= 1 | HIGH | 8.1 | NVD | Aug 20, 2026 |
| CVE-2026-73199 | A flaw was found in the `ipa-enrollment` SLAPI plugin | MEDIUM | 6.5 | NVD | Aug 20, 2026 |
| CVE-2026-73198 | A flaw was found in FreeIPA | HIGH | 7.5 | NVD | Aug 20, 2026 |
| CVE-2026-73197 | A flaw was found in FreeIPA | HIGH | 7.5 | NVD | Aug 20, 2026 |
| CVE-2026-13097 | A privilege escalation flaw was found in FreeIPA | CRITICAL | 9.1 | NVD | Aug 20, 2026 |
| CVE-2026-11861 | A flaw was found in FreeIPA | CRITICAL | 9.6 | NVD | Aug 20, 2026 |
| CVE-2026-75963 | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion | HIGH | 7.5 | NVD | Aug 20, 2026 |
| CVE-2026-75860 | The JSON Options WordPress plugin through 0 | CRITICAL | 9.8 | NVD | Aug 20, 2026 |
| CVE-2026-74992 | The Kirki WordPress plugin before 6 | MEDIUM | 6.8 | NVD | Aug 20, 2026 |
| CVE-2026-19697 | The GutenKit WordPress plugin before 2 | MEDIUM | 6.8 | NVD | Aug 20, 2026 |
| CVE-2026-19615 | The Admin and Site Enhancements (ASE) WordPress plugin before 9 | MEDIUM | 6.8 | NVD | Aug 20, 2026 |
| CVE-2026-15049 | The Depicter โ Popup & Slider Builder WordPress plugin before 4 | HIGH | 7.2 | NVD | Aug 20, 2026 |
| CVE-2026-13405 | The Royal Addons for Elementor WordPress plugin before 1 | MEDIUM | 6.6 | NVD | Aug 20, 2026 |
| CVE-2026-19582 | In binutils 2 | HIGH | 7.8 | NVD | Aug 20, 2026 |
| CVE-2026-72529 | TrueConf - Server | CRITICAL | N/A | CISA | Aug 20, 2026 |
| CVE-2026-72530 | TrueConf - Server | CRITICAL | N/A | CISA | Aug 20, 2026 |
| CVE-2026-76886 | C12 | HIGH | 8.1 | NVD | Aug 19, 2026 |
| CVE-2026-76880 | RRC protocol dissector crash in 4 | HIGH | 7.5 | NVD | Aug 19, 2026 |
| CVE-2026-76879 | C12 | HIGH | 7.5 | NVD | Aug 19, 2026 |
| CVE-2026-76761 | A vulnerability was identified in chenhg5 cc-connect up to 1 | HIGH | 7.3 | NVD | Aug 19, 2026 |
| CVE-2026-76760 | A vulnerability was found in chenhg5 cc-connect up to 1 | HIGH | 7.3 | NVD | Aug 19, 2026 |
| CVE-2026-44901 | Wazuh is a free and open source platform used for threat prevention, detection, | HIGH | 8.4 | NVD | Aug 19, 2026 |
| CVE-2026-41424 | Wazuh is a free and open source platform used for threat prevention, detection, | HIGH | 8.2 | NVD | Aug 19, 2026 |
| CVE-2026-20359 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 9.9 | NVD | Aug 19, 2026 |
| CVE-2026-20358 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 10.0 | NVD | Aug 19, 2026 |
| CVE-2026-20357 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 10.0 | NVD | Aug 19, 2026 |
| CVE-2026-20327 | A vulnerability in the web-based management interface of Cisco Unified Intellige | MEDIUM | 6.5 | NVD | Aug 19, 2026 |
| CVE-2026-20320 | A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWork | HIGH | 7.5 | NVD | Aug 19, 2026 |
| CVE-2026-20319 | As part of Cisco's ongoing commitment to proactive security and product quality, | HIGH | 7.5 | NVD | Aug 19, 2026 |
| CVE-2026-20318 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 9.6 | NVD | Aug 19, 2026 |
| CVE-2026-20317 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 10.0 | NVD | Aug 19, 2026 |
| CVE-2026-20315 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 10.0 | NVD | Aug 19, 2026 |
| CVE-2026-20302 | A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated | MEDIUM | 6.1 | NVD | Aug 19, 2026 |
| CVE-2026-20231 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 9.9 | NVD | Aug 19, 2026 |
| CVE-2026-20030 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 10.0 | NVD | Aug 19, 2026 |
| CVE-2024-13942 | Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use at | HIGH | 7.6 | NVD | Aug 19, 2026 |
| CVE-2026-73364 | Customer PHP Object Injection in Flexible Subscriptions <= 1 | CRITICAL | 9.8 | NVD | Aug 19, 2026 |
| CVE-2026-73363 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < | MEDIUM | 6.5 | NVD | Aug 19, 2026 |
| CVE-2026-73354 | Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3 | HIGH | 7.1 | NVD | Aug 19, 2026 |
| CVE-2026-73347 | Unauthenticated Privilege Escalation in TrueBooker <= 1 | CRITICAL | 9.8 | NVD | Aug 19, 2026 |
| CVE-2026-73185 | Unauthenticated SQL Injection in NGG Smart Image Search < 4 | CRITICAL | 9.3 | NVD | Aug 19, 2026 |
| CVE-2026-73184 | Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11 | HIGH | 7.1 | NVD | Aug 19, 2026 |
| CVE-2026-73183 | Unauthenticated SQL Injection in Maps Marker Pro <= 4 | CRITICAL | 9.3 | NVD | Aug 19, 2026 |
| CVE-2026-73182 | Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3 | HIGH | 7.1 | NVD | Aug 19, 2026 |
| CVE-2026-66668 | Subscriber SQL Injection in Community by PeepSo <= 9 | HIGH | 8.5 | NVD | Aug 19, 2026 |
| CVE-2026-66613 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3 | CRITICAL | 9.8 | NVD | Aug 19, 2026 |
| CVE-2026-66596 | Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9 | HIGH | 7.1 | NVD | Aug 19, 2026 |
| CVE-2026-61986 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30 | HIGH | 7.1 | NVD | Aug 19, 2026 |
| CVE-2026-32552 | Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2 | HIGH | 8.5 | NVD | Aug 19, 2026 |
| CVE-2026-15253 | The Easy Media Replace WordPress plugin through 0 | MEDIUM | 6.8 | NVD | Aug 19, 2026 |
| CVE-2026-14861 | The User Verification by PickPlugins WordPress plugin through 2 | HIGH | 7.5 | NVD | Aug 19, 2026 |
| CVE-2026-14334 | The Booking calendar, Appointment Booking System WordPress plugin through 3 | HIGH | 8.8 | NVD | Aug 19, 2026 |
| CVE-2026-13175 | The Eventin WordPress plugin before 4 | MEDIUM | 6.5 | NVD | Aug 19, 2026 |
| CVE-2026-13174 | The Eventin WordPress plugin before 4 | HIGH | 7.2 | NVD | Aug 19, 2026 |
| CVE-2026-13169 | The Eventin WordPress plugin before 4 | HIGH | 8.1 | NVD | Aug 19, 2026 |
| CVE-2026-12983 | The Dinatur WordPress plugin through 1 | HIGH | 8.6 | NVD | Aug 19, 2026 |
| CVE-2026-11565 | The Advanced File Manager WordPress plugin before 5 | HIGH | 8.5 | NVD | Aug 19, 2026 |
| CVE-2026-49419 | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() rel | HIGH | 8.8 | NVD | Aug 19, 2026 |
| CVE-2026-49418 | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, | HIGH | 8.8 | NVD | Aug 19, 2026 |
| CVE-2026-49415 | During execve(2) of a SUID binary, the new virtual address space is installed be | HIGH | 8.8 | NVD | Aug 19, 2026 |
| CVE-2026-19942 | The Atarim โ AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO | HIGH | 8.1 | NVD | Aug 19, 2026 |
| CVE-2026-76050 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1 | HIGH | 7.3 | NVD | Aug 19, 2026 |
| CVE-2026-76049 | A vulnerability has been found in SourceCodester Simple Online Food Ordering Sys | HIGH | 7.3 | NVD | Aug 19, 2026 |
| CVE-2026-76048 | A flaw has been found in SourceCodester Simple Online Food Ordering System 1 | HIGH | 7.3 | NVD | Aug 19, 2026 |
| CVE-2026-76008 | A flaw has been found in Comfast CF-N1-S 2 | CRITICAL | 10.0 | NVD | Aug 19, 2026 |
| CVE-2026-76004 | A security vulnerability has been detected in UTT HiPER 1250GW up to 3 | CRITICAL | 9.9 | NVD | Aug 19, 2026 |
| CVE-2026-76003 | A weakness has been identified in UTT HiPER 1200GW up to 2 | CRITICAL | 9.9 | NVD | Aug 19, 2026 |
| CVE-2026-75987 | A vulnerability was found in SPLWare esProc up to 20260507 | HIGH | 7.3 | NVD | Aug 19, 2026 |
| CVE-2026-75986 | A vulnerability has been found in code-projects Online Job Portal System 1 | HIGH | 7.3 | NVD | Aug 19, 2026 |
| CVE-2026-75985 | A flaw has been found in TRENDnet Router 1 | HIGH | 7.4 | NVD | Aug 19, 2026 |
| CVE-2026-15421 | The Speed Optimizer โ The All-In-One Performance-Boosting Plugin plugin for Word | MEDIUM | 6.4 | NVD | Aug 19, 2026 |
| CVE-2026-75984 | A vulnerability was detected in TRENDnet TEW-823DRU 1 | HIGH | 7.4 | NVD | Aug 19, 2026 |
| CVE-2026-75979 | A vulnerability was found in xianrendzw EasyReport up to 2 | MEDIUM | 6.3 | NVD | Aug 19, 2026 |
| CVE-2026-75978 | A security vulnerability has been detected in xianrendzw EasyReport up to 2 | MEDIUM | 6.3 | NVD | Aug 19, 2026 |
| CVE-2026-75976 | A weakness has been identified in TRENDnet TEW-823DRU 1 | CRITICAL | 9.9 | NVD | Aug 19, 2026 |
| CVE-2026-64849 | MLflow - MLflow | CRITICAL | N/A | CISA | Aug 19, 2026 |
| CVE-2026-66591 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti | MEDIUM | 6.5 | NVD | Aug 18, 2026 |
| CVE-2026-61574 | authentik is an open-source identity provider | HIGH | 8.8 | NVD | Aug 18, 2026 |
| CVE-2026-52723 | ePA 3 | CRITICAL | 9.1 | NVD | Aug 18, 2026 |
| CVE-2026-52606 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8 | MEDIUM | 6.1 | NVD | Aug 18, 2026 |
| CVE-2026-50578 | ePA 3 | HIGH | 7.5 | NVD | Aug 18, 2026 |
| CVE-2026-50577 | ePA 3 | HIGH | 7.4 | NVD | Aug 18, 2026 |
| CVE-2026-50576 | ePA 3 | MEDIUM | 6.8 | NVD | Aug 18, 2026 |
| CVE-2026-49228 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blo | HIGH | 8.8 | NVD | Aug 18, 2026 |
| CVE-2026-49225 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blo | HIGH | 8.3 | NVD | Aug 18, 2026 |
| CVE-2026-49224 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blo | HIGH | 8.3 | NVD | Aug 18, 2026 |
| CVE-2026-49223 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blo | HIGH | 7.6 | NVD | Aug 18, 2026 |
| CVE-2026-49222 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blo | HIGH | 7.6 | NVD | Aug 18, 2026 |
| CVE-2026-48744 | Saleor is an e-commerce platform | MEDIUM | 6.5 | NVD | Aug 18, 2026 |
| CVE-2026-30250 | Cross-site scripting vulnerability in the user documentation field in Beta Syste | MEDIUM | 6.1 | NVD | Aug 18, 2026 |
| CVE-2026-18963 | A flaw was found in the reset-credentials flow of the keycloak-services componen | CRITICAL | 9.1 | NVD | Aug 18, 2026 |
| CVE-2026-75829 | grav-plugin-api versions before 1 | HIGH | 8.1 | NVD | Aug 18, 2026 |
| CVE-2026-75828 | Grav before 2 | HIGH | 8.7 | NVD | Aug 18, 2026 |
| CVE-2026-75827 | Grav before 2 | HIGH | 8.8 | NVD | Aug 18, 2026 |
| CVE-2026-74906 | SiYuan before v3 | HIGH | 7.5 | NVD | Aug 18, 2026 |
| CVE-2026-74905 | SiYuan before v3 | HIGH | 7.1 | NVD | Aug 18, 2026 |
| CVE-2026-74904 | SiYuan before v3 | HIGH | 7.5 | NVD | Aug 18, 2026 |
| CVE-2026-74902 | SiYuan before v3 | HIGH | 8.6 | NVD | Aug 18, 2026 |
| CVE-2026-15585 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v | HIGH | 7.5 | NVD | Aug 18, 2026 |
| CVE-2026-75627 | Bastillion fails to properly validate request URI paths in its controller dispat | CRITICAL | 9.8 | NVD | Aug 18, 2026 |
| CVE-2026-75626 | SpiderFoot fails to HTML-escape correlation titles built from external scan data | CRITICAL | 9.3 | NVD | Aug 18, 2026 |
| CVE-2024-14046 | A security vulnerability has been detected in OpenBoxes up to 0 | MEDIUM | 6.3 | NVD | Aug 18, 2026 |
| CVE-2024-14045 | A weakness has been identified in OpenBoxes up to 0 | MEDIUM | 6.3 | NVD | Aug 18, 2026 |
| CVE-2026-34884 | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability | CRITICAL | 9.8 | NVD | Aug 18, 2026 |
| CVE-2026-15371 | Velociraptor's web GUI allows specifying a custom type for columns in tables | HIGH | 8.1 | NVD | Aug 18, 2026 |
| CVE-2026-75091 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for | HIGH | 7.2 | NVD | Aug 18, 2026 |
| CVE-2026-15748 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload | CRITICAL | 9.8 | NVD | Aug 18, 2026 |
| CVE-2026-11801 | The WPAdverts โ Classifieds Plugin plugin for WordPress is vulnerable to authori | HIGH | 7.5 | NVD | Aug 18, 2026 |
| CVE-2026-75094 | A flaw has been found in COMFAST CF-N1-S 2 | CRITICAL | 9.1 | NVD | Aug 18, 2026 |
| CVE-2026-75089 | A weakness has been identified in PHPGurukul Complaint Management System 1 | HIGH | 7.3 | NVD | Aug 18, 2026 |
| CVE-2026-75088 | A vulnerability was determined in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 18, 2026 |
| CVE-2026-75087 | A vulnerability was found in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 18, 2026 |
| CVE-2026-75086 | A vulnerability has been found in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 18, 2026 |
| CVE-2026-75080 | A security vulnerability has been detected in SourceCodester Class and Exam Time | HIGH | 7.3 | NVD | Aug 18, 2026 |
| CVE-2026-75079 | A weakness has been identified in SourceCodester Class and Exam Timetabling Syst | HIGH | 7.3 | NVD | Aug 18, 2026 |
| CVE-2026-65400 | Apple - macOS | CRITICAL | N/A | CISA | Aug 18, 2026 |
| CVE-2026-55040 | Microsoft - SharePoint | CRITICAL | N/A | CISA | Aug 18, 2026 |
| CVE-2026-59310 | Broadcom - VMware vCenter | CRITICAL | N/A | CISA | Aug 18, 2026 |
| CVE-2026-33824 | Microsoft - Internet Key Exchange (IKE) Service Extensions | CRITICAL | N/A | CISA | Aug 18, 2026 |
| EDB-52653 | [webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF | HIGH | N/A | EXPLOIT-DB | Aug 18, 2026 |
| EDB-52654 | [webapps] Nodemailer 9.0.0 - File Read/ SSRF | HIGH | N/A | EXPLOIT-DB | Aug 18, 2026 |
| EDB-52655 | [webapps] flyto-core 2.26.7 - Arbitrary File Write | HIGH | N/A | EXPLOIT-DB | Aug 18, 2026 |
| EDB-52656 | [dos] NanaZip 6.5 - DoS | HIGH | N/A | EXPLOIT-DB | Aug 18, 2026 |
| EDB-52657 | [remote] PCMan 2.0.7 - Buffer Overflow | HIGH | N/A | EXPLOIT-DB | Aug 18, 2026 |
| CVE-2025-62593 | Ray-Project - Ray | CRITICAL | N/A | CISA | Aug 18, 2026 |
| CVE-2026-67961 | An issue in O2OA v | HIGH | 7.8 | NVD | Aug 17, 2026 |
| CVE-2026-67919 | An issue in Halo 2 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-42164 | Mahara before 25 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-42162 | Mahara before 25 | CRITICAL | 9.1 | NVD | Aug 17, 2026 |
| CVE-2026-38165 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template e | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-59893 | sqlparse is a non-validating SQL parser module for Python | HIGH | 7.5 | NVD | Aug 17, 2026 |
| CVE-2026-51346 | SQL Injection vulnerability in StudIP 6 | CRITICAL | 9.1 | NVD | Aug 17, 2026 |
| CVE-2026-50772 | An issue in Squirro Cognitive Search < 3 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-50771 | Cross Site Scripting vulnerability in Squirro Cognitive Search < 3 | MEDIUM | 6.1 | NVD | Aug 17, 2026 |
| CVE-2026-50770 | An issue in Squirro Cognitive Search before v | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-50769 | The CRM+ application before and including version 2025 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-50768 | File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-46345 | compliance-trestle is a tooling platform for managing compliance as code | HIGH | 8.4 | NVD | Aug 17, 2026 |
| CVE-2026-33437 | Stirling-PDF is a locally hosted web application that facilitates various operat | HIGH | 8.1 | NVD | Aug 17, 2026 |
| CVE-2026-9771 | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash | HIGH | 8.8 | NVD | Aug 17, 2026 |
| CVE-2026-68517 | Glances is an open-source system cross-platform monitoring tool | MEDIUM | 6.5 | NVD | Aug 17, 2026 |
| CVE-2026-74880 | openssl_encrypt versions before 1 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-74879 | openssl_encrypt versions before 1 | HIGH | 7.5 | NVD | Aug 17, 2026 |
| CVE-2026-74878 | openssl_encrypt versions before 1 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-74877 | openssl_encrypt versions before 1 | HIGH | 8.8 | NVD | Aug 17, 2026 |
| CVE-2026-74876 | openssl_encrypt versions before 1 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-74875 | openssl_encrypt versions before 1 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-74874 | openssl_encrypt versions before 1 | HIGH | 7.5 | NVD | Aug 17, 2026 |
| CVE-2026-74872 | openssl_encrypt versions before 1 | CRITICAL | 9.8 | NVD | Aug 17, 2026 |
| CVE-2026-74871 | openssl_encrypt versions before 1 | MEDIUM | 6.2 | NVD | Aug 17, 2026 |
| CVE-2026-74869 | stoatchat before 0 | HIGH | 7.7 | NVD | Aug 17, 2026 |
| CVE-2026-74868 | SiYuan versions before 3 | HIGH | 7.5 | NVD | Aug 17, 2026 |
| CVE-2026-74842 | A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11 | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-74802 | SiYuan versions before 3 | HIGH | 8.2 | NVD | Aug 17, 2026 |
| CVE-2026-74801 | SiYuan before 3 | HIGH | 8.2 | NVD | Aug 17, 2026 |
| CVE-2026-74800 | SiYuan before v3 | CRITICAL | 9.0 | NVD | Aug 17, 2026 |
| CVE-2026-74799 | SiYuan before 3 | CRITICAL | 9.3 | NVD | Aug 17, 2026 |
| CVE-2026-74798 | SiYuan kernel before v3 | HIGH | 8.7 | NVD | Aug 17, 2026 |
| CVE-2026-20000 | A vulnerability was detected in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19999 | A security vulnerability has been detected in Open Asset Import Library Assimp A | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19994 | A vulnerability was found in Webkul Bagisto up to 2 | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19984 | A flaw has been found in jkawamoto mcp-florence2 up to 0 | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19983 | A vulnerability was detected in GL | HIGH | 8.3 | NVD | Aug 17, 2026 |
| CVE-2026-19982 | A security vulnerability has been detected in GL | HIGH | 7.4 | NVD | Aug 17, 2026 |
| CVE-2026-19977 | A vulnerability was detected in EFM ipTIME A3004T 14 | CRITICAL | 10.0 | NVD | Aug 17, 2026 |
| CVE-2026-19976 | A security vulnerability has been detected in COMFAST CF-N1-S 2 | MEDIUM | 6.6 | NVD | Aug 17, 2026 |
| CVE-2026-19973 | A vulnerability was found in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19972 | A vulnerability has been found in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19970 | A vulnerability was detected in Open Asset Import Library Assimp 17c12da | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19967 | A security flaw has been discovered in Open Asset Import Library Assimp 17c12da | MEDIUM | 6.3 | NVD | Aug 17, 2026 |
| CVE-2026-19963 | A vulnerability has been found in Edimax EW-7478APC 1 | HIGH | 7.4 | NVD | Aug 17, 2026 |
| CVE-2026-19962 | A flaw has been found in Edimax EW-7478APC 1 | HIGH | 7.4 | NVD | Aug 17, 2026 |
| EDB-52652 | [dos] NanaZip 6.5 - DoS | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52642 | [webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52643 | [remote] D-Link DNS_340L - OS Command Injection | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52644 | [remote] ipTIME A3004T - Remote Code Execution | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52645 | [webapps] Joomla JCE_2.9.15 - Remote Code Execution | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52646 | [webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52647 | [dos] Nmap 7.99 - Extension Header Integer Underflow | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52648 | [remote] phpSysInfo 3.4.5 - IP Allowlist Bypass | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52649 | [webapps] webpack_devserver 5.2.5 - CSRF | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52650 | [webapps] Probo 0.222.2 - IDOR | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| EDB-52651 | [webapps] flyto_core 2.26.7 - Server-Side Request Forgery | HIGH | N/A | EXPLOIT-DB | Aug 17, 2026 |
| CVE-2026-19961 | A vulnerability was detected in Edimax EW-7478APC 1 | CRITICAL | 9.9 | NVD | Aug 16, 2026 |
| CVE-2026-19960 | A security vulnerability has been detected in Edimax EW-7478APC 1 | HIGH | 7.4 | NVD | Aug 16, 2026 |
| CVE-2026-19959 | A weakness has been identified in Edimax EW-7478APC 1 | CRITICAL | 9.9 | NVD | Aug 16, 2026 |
| CVE-2026-19958 | A security flaw has been discovered in iatsiuk pptr-mcp up to 0 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19957 | A vulnerability was identified in graphlit graphlit-mcp-server 1 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19956 | A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-74790 | Scriban before 7 | CRITICAL | 9.1 | NVD | Aug 16, 2026 |
| CVE-2026-74789 | Scriban before 7 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-74788 | Scriban before 7 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-74787 | Scriban before 7 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-74786 | Scriban before 7 | MEDIUM | 6.5 | NVD | Aug 16, 2026 |
| CVE-2026-74785 | Scriban before 7 | MEDIUM | 6.5 | NVD | Aug 16, 2026 |
| CVE-2026-74783 | Scriban versions 6 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-73062 | Scriban versions 3 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-73061 | Scriban before 7 | CRITICAL | 9.8 | NVD | Aug 16, 2026 |
| CVE-2026-73060 | Scriban versions from 3 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-73059 | stoatchat before 0 | MEDIUM | 6.5 | NVD | Aug 16, 2026 |
| CVE-2026-73057 | stoatchat before 0 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-73056 | SiYuan kernel versions before 3 | CRITICAL | 9.8 | NVD | Aug 16, 2026 |
| CVE-2026-72888 | Net::OAuth versions before 0 | MEDIUM | 6.5 | NVD | Aug 16, 2026 |
| CVE-2026-72887 | Net::OAuth::Client versions before 0 | CRITICAL | 9.8 | NVD | Aug 16, 2026 |
| CVE-2026-19349 | Lemonldap::NG::Portal versions from 2 | CRITICAL | 9.8 | NVD | Aug 16, 2026 |
| CVE-2024-58375 | OpenTofu versions 1 | HIGH | 7.5 | NVD | Aug 16, 2026 |
| CVE-2026-17123 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req | HIGH | 8.8 | NVD | Aug 16, 2026 |
| CVE-2026-16099 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | HIGH | 8.8 | NVD | Aug 16, 2026 |
| CVE-2026-16098 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U | CRITICAL | 9.8 | NVD | Aug 16, 2026 |
| CVE-2026-16079 | The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Inject | MEDIUM | 6.5 | NVD | Aug 16, 2026 |
| CVE-2026-15963 | The Quiz and Survey Master (QSM) โ Easy Quiz and Survey Maker plugin for WordPre | MEDIUM | 6.5 | NVD | Aug 16, 2026 |
| CVE-2026-15726 | The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scrip | MEDIUM | 6.4 | NVD | Aug 16, 2026 |
| CVE-2026-15066 | The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scrip | MEDIUM | 6.4 | NVD | Aug 16, 2026 |
| CVE-2026-15009 | The Advanced File Manager โ Ultimate File Manager for WordPress And Document Lib | MEDIUM | 6.1 | NVD | Aug 16, 2026 |
| CVE-2026-15002 | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to | HIGH | 7.2 | NVD | Aug 16, 2026 |
| CVE-2026-14524 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d | CRITICAL | 9.1 | NVD | Aug 16, 2026 |
| CVE-2026-14498 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i | HIGH | 8.8 | NVD | Aug 16, 2026 |
| CVE-2026-13358 | The Appointment Booking Calendar โ Simply Schedule Appointments Booking Plugin p | MEDIUM | 6.5 | NVD | Aug 16, 2026 |
| CVE-2026-11780 | The Quiz and Survey Master (QSM) โ Easy Quiz and Survey Maker plugin for WordPre | MEDIUM | 6.4 | NVD | Aug 16, 2026 |
| CVE-2026-19930 | A security flaw has been discovered in Dolibarr up to 23 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19929 | A vulnerability was identified in OpenBoxes up to 0 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19928 | A vulnerability was determined in OpenBoxes up to 0 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19927 | A vulnerability was found in OpenBoxes up to 0 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19926 | A vulnerability has been found in Evergreen up to 3 | HIGH | 7.3 | NVD | Aug 16, 2026 |
| CVE-2026-19924 | A security vulnerability has been detected in Tenda AC10 16 | CRITICAL | 9.8 | NVD | Aug 16, 2026 |
| CVE-2026-19923 | A weakness has been identified in code-projects Online Shopping System 1 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19921 | A vulnerability was identified in code-projects Online Shopping System 1 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19920 | A vulnerability was determined in code-projects Online Shopping System 1 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19919 | A vulnerability was found in code-projects Online Shopping System 1 | HIGH | 7.3 | NVD | Aug 16, 2026 |
| CVE-2026-19918 | A vulnerability has been found in SpaceX Starlink Router Gen 3 2025 | MEDIUM | 6.3 | NVD | Aug 16, 2026 |
| CVE-2026-19917 | A flaw has been found in code-projects Online Food Order System 1 | MEDIUM | 6.3 | NVD | Aug 15, 2026 |
| CVE-2026-73053 | SiYuan versions before v3 | CRITICAL | 9.0 | NVD | Aug 15, 2026 |
| CVE-2026-73052 | SiYuan before v3 | CRITICAL | 9.0 | NVD | Aug 15, 2026 |
| CVE-2026-73050 | SiYuan versions before v3 | CRITICAL | 9.0 | NVD | Aug 15, 2026 |
| CVE-2026-73047 | siyuan versions <= 3 | MEDIUM | 6.2 | NVD | Aug 15, 2026 |
| CVE-2026-73046 | SiYuan before v3 | CRITICAL | 9.8 | NVD | Aug 15, 2026 |
| CVE-2026-73045 | SiYuan before 3 | HIGH | 7.5 | NVD | Aug 15, 2026 |
| CVE-2026-73044 | SiYuan versions before v3 | CRITICAL | 9.0 | NVD | Aug 15, 2026 |
| CVE-2026-73043 | SiYuan versions before v3 | CRITICAL | 9.0 | NVD | Aug 15, 2026 |
| CVE-2026-73042 | SiYuan before v3 | CRITICAL | 9.0 | NVD | Aug 15, 2026 |
| CVE-2026-73041 | SiYuan versions before v3 | CRITICAL | 9.0 | NVD | Aug 15, 2026 |
| CVE-2026-19905 | A weakness has been identified in Jinher OA 1 | HIGH | 7.3 | NVD | Aug 15, 2026 |
| CVE-2026-18855 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d | CRITICAL | 9.1 | NVD | Aug 15, 2026 |
| CVE-2026-19901 | A security flaw has been discovered in LB-LINK X-PRO 1 | HIGH | 8.1 | NVD | Aug 15, 2026 |
| CVE-2026-19598 | The Pods โ Custom Content Types and Fields plugin for WordPress is vulnerable to | CRITICAL | 9.8 | NVD | Aug 15, 2026 |
| CVE-2026-19900 | A vulnerability was identified in LB-LINK X-PRO 1 | HIGH | 8.1 | NVD | Aug 15, 2026 |
| CVE-2026-19899 | A vulnerability was determined in SourceCodester Class and Exam Timetabling Syst | HIGH | 7.3 | NVD | Aug 15, 2026 |
| CVE-2026-74449 | drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport | HIGH | 7.8 | NVD | Aug 15, 2026 |
| CVE-2026-74447 | drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment eop_ring_bu | HIGH | 7.8 | NVD | Aug 15, 2026 |
| CVE-2026-74446 | drm/amdkfd: hold event_mutex while checkpointing CRIU events kfd_criu_checkpoin | HIGH | 7.8 | NVD | Aug 15, 2026 |
| CVE-2026-74444 | drm/vmwgfx: validate DRAW_PRIMITIVES header size before division vmw_cmd_draw() | HIGH | 7.8 | NVD | Aug 15, 2026 |
| CVE-2026-74443 | drm/vmwgfx: bound DMA command body size against suffix pointer vmw_cmd_dma() lo | HIGH | 8.8 | NVD | Aug 15, 2026 |
| CVE-2026-74440 | drm/xe: Wait on external BO kernel fences in exec IOCTL Before arming a user jo | HIGH | 7.8 | NVD | Aug 15, 2026 |
| CVE-2026-19894 | A security flaw has been discovered in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 15, 2026 |
| CVE-2026-12248 | The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection vi | MEDIUM | 6.5 | NVD | Aug 15, 2026 |
| CVE-2026-15965 | The MaxUpload โ Big File Uploads โ Increase Maximum File Upload Size plugin for | HIGH | 8.8 | NVD | Aug 15, 2026 |
| CVE-2026-15341 | The User Session Synchronizer plugin for WordPress is vulnerable to Authenticati | CRITICAL | 9.8 | NVD | Aug 15, 2026 |
| CVE-2026-15312 | The Propovoice: All-in-One Client Management System plugin for WordPress is vuln | HIGH | 8.8 | NVD | Aug 15, 2026 |
| CVE-2026-15303 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass | CRITICAL | 9.8 | NVD | Aug 15, 2026 |
| CVE-2026-15162 | The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injec | HIGH | 7.5 | NVD | Aug 15, 2026 |
| CVE-2026-15001 | The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to | HIGH | 8.8 | NVD | Aug 15, 2026 |
| CVE-2026-14484 | The RapiSafe โ Secure Multi File Upload for Contact Form 7 plugin for WordPress | CRITICAL | 9.1 | NVD | Aug 15, 2026 |
| CVE-2026-14433 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordP | HIGH | 7.2 | NVD | Aug 15, 2026 |
| CVE-2026-74250 | In OpenStack Ironic before 38 | MEDIUM | 6.3 | NVD | Aug 14, 2026 |
| CVE-2026-74243 | A flaw was found in Red Hat Quay | MEDIUM | 6.5 | NVD | Aug 14, 2026 |
| CVE-2026-46603 | VP8L decoding in golang | HIGH | 7.5 | NVD | Aug 14, 2026 |
| CVE-2026-46439 | compliance-trestle is a tooling platform for managing compliance as code | HIGH | 7.8 | NVD | Aug 14, 2026 |
| CVE-2026-46380 | compliance-trestle is a tooling platform for managing compliance as code | MEDIUM | 6.7 | NVD | Aug 14, 2026 |
| CVE-2026-19845 | A vulnerability was determined in TOTOLINK A800R 4 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19844 | A vulnerability was found in TOTOLINK A800R 4 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19628 | A command injection vulnerability exists in Tenable Security Center | HIGH | 7.2 | NVD | Aug 14, 2026 |
| CVE-2026-19626 | A remote code execution vulnerability exists in Tenable Security Center's report | CRITICAL | 9.9 | NVD | Aug 14, 2026 |
| CVE-2026-72827 | Grav CMS before 2 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-72826 | The getgrav/grav-plugin-api plugin before 1 | CRITICAL | 9.8 | NVD | Aug 14, 2026 |
| CVE-2026-72825 | The getgrav/grav-plugin-api plugin before 1 | HIGH | 7.6 | NVD | Aug 14, 2026 |
| CVE-2026-72824 | The Grav API plugin (getgrav/grav-plugin-api) before 1 | CRITICAL | 9.8 | NVD | Aug 14, 2026 |
| CVE-2026-72822 | The getgrav/grav-plugin-api Composer package before 1 | CRITICAL | 9.8 | NVD | Aug 14, 2026 |
| CVE-2026-72819 | Grav CMS before 2 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-72817 | go-chi/chi versions 0 | MEDIUM | 6.5 | NVD | Aug 14, 2026 |
| CVE-2026-72816 | go-chi/chi through 5 | MEDIUM | 6.5 | NVD | Aug 14, 2026 |
| CVE-2026-72812 | SiYuan versions before v3 | MEDIUM | 6.5 | NVD | Aug 14, 2026 |
| CVE-2026-72811 | SiYuan versions <= v3 | CRITICAL | 10.0 | NVD | Aug 14, 2026 |
| CVE-2026-72810 | SiYuan versions before v3 | HIGH | 8.6 | NVD | Aug 14, 2026 |
| CVE-2026-19822 | A vulnerability was identified in Tenda W20E 15 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19821 | A vulnerability was determined in Tenda AC12 15 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19815 | A flaw has been found in TOTOLINK A800R 4 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19814 | A vulnerability was detected in TOTOLINK A800R 4 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19813 | A security vulnerability has been detected in TOTOLINK A800R 4 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19812 | A weakness has been identified in TOTOLINK A800R 4 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19794 | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting i | HIGH | 7.2 | NVD | Aug 14, 2026 |
| CVE-2026-19811 | A security flaw has been discovered in TOTOLINK A800R 4 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-18039 | The Essential Addons for Elementor WordPress plugin before 6 | HIGH | 8.1 | NVD | Aug 14, 2026 |
| CVE-2026-16810 | The Bit Form โ Contact Form, Payment Forms, Multi Step Forms, Calculator & Custo | MEDIUM | 6.5 | NVD | Aug 14, 2026 |
| CVE-2026-15205 | The Paymob for WooCommerce WordPress plugin before 4 | HIGH | 8.6 | NVD | Aug 14, 2026 |
| CVE-2026-14290 | The Embed Google Photos album WordPress plugin through 2 | MEDIUM | 6.8 | NVD | Aug 14, 2026 |
| CVE-2026-12949 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via I | CRITICAL | 9.8 | NVD | Aug 14, 2026 |
| CVE-2026-19792 | A security flaw has been discovered in Tenda G0 up to 20260625 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19791 | A weakness has been identified in Tenda G0 up to 20260625 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19788 | A vulnerability was found in Tenda AC1206 15 | HIGH | 8.8 | NVD | Aug 14, 2026 |
| CVE-2026-19785 | A vulnerability has been found in francoisjacquet RosarioSIS up to 12 | MEDIUM | 6.3 | NVD | Aug 14, 2026 |
| CVE-2026-18109 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scrip | HIGH | 7.2 | NVD | Aug 14, 2026 |
| CVE-2026-19771 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2 | HIGH | 7.2 | NVD | Aug 14, 2026 |
| CVE-2026-19767 | A weakness has been identified in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 14, 2026 |
| CVE-2026-19765 | A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951 | MEDIUM | 6.3 | NVD | Aug 14, 2026 |
| CVE-2026-19764 | A vulnerability was identified in Raisecom Communication Command and Dispatch Ma | HIGH | 7.3 | NVD | Aug 14, 2026 |
| CVE-2026-19762 | A vulnerability was found in DTStack Taier 1 | HIGH | 7.3 | NVD | Aug 14, 2026 |
| CVE-2026-19758 | A vulnerability was determined in dromara lamp-cloud up to 5 | HIGH | 7.3 | NVD | Aug 14, 2026 |
| CVE-2026-19757 | A vulnerability was found in Dromara lamp-cloud up to 5 | HIGH | 7.3 | NVD | Aug 14, 2026 |
| CVE-2026-19756 | A vulnerability has been found in Dromara lamp-cloud up to 5 | MEDIUM | 6.3 | NVD | Aug 13, 2026 |
| CVE-2026-19753 | A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1 | HIGH | 7.3 | NVD | Aug 13, 2026 |
| CVE-2026-24791 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` self r | HIGH | 8.1 | NVD | Aug 13, 2026 |
| CVE-2026-24059 | The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- | MEDIUM | 6.5 | NVD | Aug 13, 2026 |
| CVE-2026-13051 | Form::Processor::Field::HtmlArea versions from 0 | CRITICAL | 9.1 | NVD | Aug 13, 2026 |
| CVE-2026-13048 | Data::MuForm::Localizer versions through 0 | HIGH | 8.2 | NVD | Aug 13, 2026 |
| CVE-2022-4993 | HTML::FormHandler versions through 0 | CRITICAL | 9.1 | NVD | Aug 13, 2026 |
| CVE-2026-73671 | Saurus CMS Community Edition contains an unauthenticated open redirect vulnerabi | MEDIUM | 6.1 | NVD | Aug 13, 2026 |
| CVE-2026-73670 | A CMS contains a SQL injection vulnerability in admin/db_data | HIGH | 7.2 | NVD | Aug 13, 2026 |
| CVE-2026-73576 | In Zimbra Collaboration (ZCS) before 10 | MEDIUM | 6.3 | NVD | Aug 13, 2026 |
| CVE-2026-73572 | In Zimbra Collaboration (ZCS) before 10 | MEDIUM | 6.1 | NVD | Aug 13, 2026 |
| CVE-2026-73570 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor | HIGH | 8.9 | NVD | Aug 13, 2026 |
| CVE-2026-73559 | vLLM is an inference and serving engine for large language models | MEDIUM | 6.5 | NVD | Aug 13, 2026 |
| CVE-2026-73533 | Ninja Tables Pro 5 | CRITICAL | 9.8 | NVD | Aug 13, 2026 |
| CVE-2026-73532 | Fluent Forms Pro 6 | CRITICAL | 9.8 | NVD | Aug 13, 2026 |
| CVE-2026-73515 | PostGIS before 3 | HIGH | 8.1 | NVD | Aug 13, 2026 |
| CVE-2026-73514 | The address_standardizer extension for PostGIS through 3 | HIGH | 8.8 | NVD | Aug 13, 2026 |
| CVE-2026-73608 | SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not presen | HIGH | 8.6 | NVD | Aug 13, 2026 |
| CVE-2026-73604 | Flowise before 3 | MEDIUM | 6.5 | NVD | Aug 13, 2026 |
| CVE-2026-12263 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 vers | HIGH | 8.8 | NVD | Aug 13, 2026 |
| CVE-2026-19481 | @fastify/busboy is a multipart form-data parser | HIGH | 7.5 | NVD | Aug 13, 2026 |
| CVE-2026-15413 | The Link Factory WordPress plugin is a backdoor | CRITICAL | 10.0 | NVD | Aug 13, 2026 |
| CVE-2026-14298 | Mattermost versions 11 | MEDIUM | 6.5 | NVD | Aug 13, 2026 |
| CVE-2026-3639 | The PPWP โ Password Protect Pages plugin for WordPress is vulnerable to Stored C | MEDIUM | 6.4 | NVD | Aug 13, 2026 |
| CVE-2026-11840 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngin | HIGH | 8.8 | NVD | Aug 13, 2026 |
| CVE-2026-18146 | The Fluent Forms โ Customizable Contact Forms, Survey, Quiz, & Conversational Fo | HIGH | 7.2 | NVD | Aug 13, 2026 |
| CVE-2026-18945 | The WP Helper Premium WordPress plugin before 4 | HIGH | 8.2 | NVD | Aug 13, 2026 |
| CVE-2026-14182 | The Customer Email Verification for WooCommerce WordPress plugin before 3 | CRITICAL | 9.8 | NVD | Aug 13, 2026 |
| CVE-2026-13610 | The KiviCare WordPress plugin before 4 | HIGH | 7.5 | NVD | Aug 13, 2026 |
| CVE-2026-50544 | NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonligh | MEDIUM | 6.3 | NVD | Aug 13, 2026 |
| CVE-2026-49819 | UpSnap is a wake on lan web app | CRITICAL | 9.8 | NVD | Aug 13, 2026 |
| CVE-2026-49473 | @cedar-policy/authorization-for-expressjs is an open-source Express | HIGH | 8.8 | NVD | Aug 13, 2026 |
| CVE-2026-17431 | PDF::WebKit versions through 1 | MEDIUM | 6.1 | NVD | Aug 13, 2026 |
| CVE-2026-16770 | PDF::WebKit versions through 1 | CRITICAL | 9.8 | NVD | Aug 13, 2026 |
| CVE-2026-71194 | In OpenStack Designate before 22 | MEDIUM | 6.8 | NVD | Aug 12, 2026 |
| CVE-2026-71193 | In OpenStack Designate before 22 | CRITICAL | 9.6 | NVD | Aug 12, 2026 |
| CVE-2026-49481 | UpSnap is a wake on lan web app | CRITICAL | 9.6 | NVD | Aug 12, 2026 |
| CVE-2026-47717 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software | HIGH | 7.5 | NVD | Aug 12, 2026 |
| CVE-2026-73240 | Specifically crafted inputs may lead to git argument injection in Apache Allura | CRITICAL | 9.8 | NVD | Aug 12, 2026 |
| CVE-2026-73239 | Insecure Direct Object Reference (IDOR) due to missing permission checks for mul | MEDIUM | 6.5 | NVD | Aug 12, 2026 |
| CVE-2026-73238 | XSS vulnerability in code display in Apache Allura | MEDIUM | 6.1 | NVD | Aug 12, 2026 |
| CVE-2026-73237 | XSS vulnerability in Markdown handling in Apache Allura | MEDIUM | 6.1 | NVD | Aug 12, 2026 |
| CVE-2026-48554 | Nagios Core before 4 | HIGH | 7.5 | NVD | Aug 12, 2026 |
| CVE-2026-48553 | Nagios Core before 4 | HIGH | 7.5 | NVD | Aug 12, 2026 |
| CVE-2026-48551 | Nagios Core before 4 | HIGH | 7.4 | NVD | Aug 12, 2026 |
| CVE-2026-48550 | Nagios Core before 4 | MEDIUM | 6.1 | NVD | Aug 12, 2026 |
| CVE-2026-18847 | IBM i 7 | HIGH | 8.8 | NVD | Aug 12, 2026 |
| CVE-2026-18683 | IBM i 7 | HIGH | 8.8 | NVD | Aug 12, 2026 |
| CVE-2026-18499 | IBM WebSphere Application Server - Liberty 17 | HIGH | 8.1 | NVD | Aug 12, 2026 |
| CVE-2026-18098 | IBM i 7 | HIGH | 8.1 | NVD | Aug 12, 2026 |
| CVE-2026-17095 | IBM i 7 | HIGH | 8.3 | NVD | Aug 12, 2026 |
| CVE-2026-16694 | IBM i 7 | MEDIUM | 6.4 | NVD | Aug 12, 2026 |
| CVE-2026-70468 | A authentication bypass using an alternate path or channel vulnerability in Fort | HIGH | 8.1 | NVD | Aug 12, 2026 |
| CVE-2026-57858 | Cal | HIGH | 8.9 | NVD | Aug 12, 2026 |
| CVE-2026-53996 | NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio | HIGH | 7.0 | NVD | Aug 12, 2026 |
| CVE-2026-47226 | Admidio is an open-source user management solution | MEDIUM | 6.5 | NVD | Aug 12, 2026 |
| CVE-2026-26035 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet For | CRITICAL | 9.8 | NVD | Aug 12, 2026 |
| CVE-2026-70465 | A buffer copy without checking size of input ('classic buffer overflow') vulnera | HIGH | 8.1 | NVD | Aug 12, 2026 |
| CVE-2026-16747 | The Kirki WordPress plugin before 6 | MEDIUM | 6.5 | NVD | Aug 12, 2026 |
| CVE-2026-15045 | The Wallet System for WooCommerce WordPress plugin before 2 | MEDIUM | 6.5 | NVD | Aug 12, 2026 |
| CVE-2026-11325 | Description Cloudflare was recently notified by external researchers of vulne | HIGH | 8.8 | NVD | Aug 12, 2026 |
| CVE-2026-68868 | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provi | MEDIUM | 6.5 | NVD | Aug 12, 2026 |
| CVE-2026-16051 | The wpmudev-updates WordPress plugin before 5 | CRITICAL | 9.8 | NVD | Aug 12, 2026 |
| CVE-2026-15039 | The giftware WordPress plugin before 4 | CRITICAL | 9.8 | NVD | Aug 12, 2026 |
| CVE-2026-14925 | The Import WP WordPress plugin before 2 | HIGH | 7.5 | NVD | Aug 12, 2026 |
| CVE-2026-13613 | The KiviCare WordPress plugin before 4 | HIGH | 8.8 | NVD | Aug 12, 2026 |
| CVE-2026-13171 | The Eventin WordPress plugin before 4 | HIGH | 8.2 | NVD | Aug 12, 2026 |
| CVE-2026-13168 | The Eventin WordPress plugin before 4 | MEDIUM | 6.5 | NVD | Aug 12, 2026 |
| CVE-2026-12976 | The LearnPress WordPress plugin before 4 | MEDIUM | 6.5 | NVD | Aug 12, 2026 |
| CVE-2026-64954 | Velociraptor allows scheduling new collections via VQL queries in notebooks | HIGH | 8.2 | NVD | Aug 12, 2026 |
| CVE-2026-12235 | The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocati | MEDIUM | 6.3 | NVD | Aug 12, 2026 |
| CVE-2026-12234 | The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg( | HIGH | 7.8 | NVD | Aug 12, 2026 |
| CVE-2026-12232 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() i | MEDIUM | 6.1 | NVD | Aug 12, 2026 |
| CVE-2024-14043 | A vulnerability was determined in Open5GS up to 2 | MEDIUM | 6.3 | NVD | Aug 12, 2026 |
| CVE-2026-73249 | calibre is an e-book manager | HIGH | 7.5 | NVD | Aug 11, 2026 |
| CVE-2026-73247 | Kestra is an open-source, event-driven orchestration platform | HIGH | 8.6 | NVD | Aug 11, 2026 |
| CVE-2026-73246 | Kestra is an open-source, event-driven orchestration platform | HIGH | 7.5 | NVD | Aug 11, 2026 |
| CVE-2026-73245 | Kestra is an open-source, event-driven orchestration platform | MEDIUM | 6.5 | NVD | Aug 11, 2026 |
| CVE-2026-12571 | An authentication bypass in ManageEngine DDI Central's password-reset workflow a | CRITICAL | 9.8 | NVD | Aug 11, 2026 |
| CVE-2026-72546 | An insecure direct object reference vulnerability in Attendize through commit 92 | HIGH | 7.1 | NVD | Aug 11, 2026 |
| CVE-2026-72545 | An insecure direct object reference vulnerability in OpenSignLabs OpenSign throu | HIGH | 7.5 | NVD | Aug 11, 2026 |
| CVE-2026-72544 | An integrity verification vulnerability in OpenSignLabs OpenSign through 2 | HIGH | 7.5 | NVD | Aug 11, 2026 |
| CVE-2026-72543 | An insecure direct object reference vulnerability in OpenSignLabs OpenSign throu | HIGH | 7.5 | NVD | Aug 11, 2026 |
| CVE-2026-72541 | A missing authorization vulnerability in Windmill Labs Windmill through 1 | MEDIUM | 6.5 | NVD | Aug 11, 2026 |
| CVE-2026-72539 | An information disclosure vulnerability in Windmill Labs Windmill through 1 | MEDIUM | 6.5 | NVD | Aug 11, 2026 |
| CVE-2026-72538 | An argument injection vulnerability in PrefectHQ Prefect through 3 | HIGH | 8.8 | NVD | Aug 11, 2026 |
| CVE-2026-72537 | A privilege escalation vulnerability in Authentik Security authentik through 202 | HIGH | 8.8 | NVD | Aug 11, 2026 |
| CVE-2026-72536 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows | HIGH | 8.6 | NVD | Aug 11, 2026 |
| CVE-2026-72535 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows | HIGH | 8.6 | NVD | Aug 11, 2026 |
| CVE-2026-72534 | A privilege escalation vulnerability in Authentik Security authentik through 202 | HIGH | 8.8 | NVD | Aug 11, 2026 |
| CVE-2026-72533 | An authentication bypass vulnerability in Portainer CE through 2 | HIGH | 8.8 | NVD | Aug 11, 2026 |
| CVE-2026-50237 | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift C | HIGH | 7.4 | NVD | Aug 11, 2026 |
| CVE-2026-50236 | An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhoo | HIGH | 7.4 | NVD | Aug 11, 2026 |
| CVE-2026-58231 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | CRITICAL | 10.0 | NVD | Aug 11, 2026 |
| CVE-2026-19391 | A flaw was found in insights-core where the password redaction layer fails to re | MEDIUM | 6.5 | NVD | Aug 11, 2026 |
| CVE-2026-16053 | Zohocorp ManageEngineย M365 Manager Plus and M365 Security Plus versions belowย 48 | HIGH | 8.5 | NVD | Aug 11, 2026 |
| CVE-2026-4757 | A VAPIX API parameter had improper input validation which could allow code execu | HIGH | 7.2 | NVD | Aug 11, 2026 |
| CVE-2026-19516 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-g | CRITICAL | 9.1 | NVD | Aug 11, 2026 |
| CVE-2026-14548 | The Ray Enterprise Translation WordPress plugin through 1 | MEDIUM | 6.5 | NVD | Aug 11, 2026 |
| CVE-2026-13716 | Path traversal in server import and admin file upload in Crafty Controller | CRITICAL | 9.1 | NVD | Aug 11, 2026 |
| CVE-2026-19425 | Travel Agency Management System developed by Win Men Intermational has a SQL Inj | CRITICAL | 9.8 | NVD | Aug 11, 2026 |
| CVE-2026-16974 | The Kirki โ Freeform Page Builder, Website Builder & Customizer plugin for WordP | MEDIUM | 6.4 | NVD | Aug 11, 2026 |
| CVE-2026-58235 | SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated ope | MEDIUM | 6.3 | NVD | Aug 11, 2026 |
| CVE-2026-58230 | SAP Approuter does not sufficiently validate certain token content under specifi | HIGH | 7.0 | NVD | Aug 11, 2026 |
| CVE-2026-44765 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integrat | HIGH | 7.3 | NVD | Aug 11, 2026 |
| CVE-2026-44764 | Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integrat | HIGH | 7.3 | NVD | Aug 11, 2026 |
| CVE-2026-44763 | SAP Manufacturing Integration and Intelligence allows a privileged attacker to e | HIGH | 7.6 | NVD | Aug 11, 2026 |
| CVE-2026-44758 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig | CRITICAL | 9.1 | NVD | Aug 11, 2026 |
| CVE-2026-34265 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl | CRITICAL | 9.8 | NVD | Aug 11, 2026 |
| CVE-2026-68820 | Microsoft - Windows Ancillary Function Driver for WinSock | CRITICAL | N/A | CISA | Aug 11, 2026 |
| EDB-52638 | [remote] mcp-server-kubernetes 3.8.x - Argument Injection | HIGH | N/A | EXPLOIT-DB | Aug 11, 2026 |
| EDB-52637 | [dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting | HIGH | N/A | EXPLOIT-DB | Aug 11, 2026 |
| EDB-52636 | [webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF | HIGH | N/A | EXPLOIT-DB | Aug 11, 2026 |
| EDB-52635 | [webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion | HIGH | N/A | EXPLOIT-DB | Aug 11, 2026 |
| CVE-2026-20349 | Cisco - Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | CRITICAL | N/A | CISA | Aug 11, 2026 |
| CVE-2026-72898 | Metabase - Metabase | CRITICAL | N/A | CISA | Aug 11, 2026 |
| EDB-52641 | [webapps] Apache Gravitino 1.2.1 - SSRF | HIGH | N/A | EXPLOIT-DB | Aug 11, 2026 |
| EDB-52640 | [webapps] Blocksy Companion 2.1.46 - RCE | HIGH | N/A | EXPLOIT-DB | Aug 11, 2026 |
| EDB-52639 | [remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution | HIGH | N/A | EXPLOIT-DB | Aug 11, 2026 |
| CVE-2026-8718 | tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tl | HIGH | 8.4 | NVD | Aug 10, 2026 |
| CVE-2026-72726 | Discourse is an open-source discussion platform | MEDIUM | 6.5 | NVD | Aug 10, 2026 |
| CVE-2026-72720 | Discourse is an open-source discussion platform | MEDIUM | 6.4 | NVD | Aug 10, 2026 |
| CVE-2026-72719 | Chatwoot is a customer engagement suite | MEDIUM | 6.7 | NVD | Aug 10, 2026 |
| CVE-2026-66738 | SPIP before 4 | HIGH | 8.8 | NVD | Aug 10, 2026 |
| CVE-2026-48048 | XWiki Platform is a generic wiki platform | HIGH | 7.5 | NVD | Aug 10, 2026 |
| CVE-2026-47754 | Metacat is data repository software that helps researchers preserve, share, and | CRITICAL | 9.3 | NVD | Aug 10, 2026 |
| CVE-2026-65948 | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2 | HIGH | 7.3 | NVD | Aug 10, 2026 |
| CVE-2026-65945 | Logs contain replayable JWT tokens in Apache Ranger versions <= 2 | MEDIUM | 6.5 | NVD | Aug 10, 2026 |
| CVE-2026-65942 | TLS hostname verification issue in Apache Ranger Client Code in versions <= 2 | HIGH | 7.5 | NVD | Aug 10, 2026 |
| CVE-2026-61899 | Vulnerability in tapestry-core in Apache Tapestry 5 | HIGH | 7.5 | NVD | Aug 10, 2026 |
| CVE-2026-59087 | A flaw was found in the GIMP image manipulation program, specifically within its | HIGH | 7.8 | NVD | Aug 10, 2026 |
| CVE-2026-55814 | Missing Authentication in Apache Ranger Download APIs on versions <= 2 | HIGH | 7.5 | NVD | Aug 10, 2026 |
| CVE-2026-16298 | The FoodBoxBooker WordPress plugin before 1 | CRITICAL | 9.8 | NVD | Aug 10, 2026 |
| CVE-2026-16257 | The Arvow AI SEO Writer WordPress plugin before 1 | HIGH | 8.2 | NVD | Aug 10, 2026 |
| CVE-2026-15047 | The s2Member WordPress plugin before 260805 does not escape several shortcode a | MEDIUM | 6.8 | NVD | Aug 10, 2026 |
| CVE-2026-14293 | The Autopay WordPress plugin before 5 | HIGH | 8.8 | NVD | Aug 10, 2026 |
| CVE-2026-14237 | The vitepos WordPress plugin before 3 | HIGH | 7.2 | NVD | Aug 10, 2026 |
| CVE-2026-14206 | The HT Contact Form WordPress plugin before 2 | HIGH | 7.5 | NVD | Aug 10, 2026 |
| CVE-2026-13600 | The AutoNetTV Relay WordPress plugin before 3 | HIGH | 8.1 | NVD | Aug 10, 2026 |
| CVE-2026-72522 | libexpat before 2 | MEDIUM | 6.2 | NVD | Aug 10, 2026 |
| CVE-2026-19389 | Multiple integer overflow and underflow vulnerabilities were found in the GStrea | HIGH | 7.1 | NVD | Aug 10, 2026 |
| CVE-2026-19387 | A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins- | HIGH | 7.6 | NVD | Aug 10, 2026 |
| CVE-2026-19384 | A weakness has been identified in SourceCodester Simple Doctors Appointment Syst | HIGH | 7.3 | NVD | Aug 10, 2026 |
| CVE-2026-19381 | A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2 | HIGH | 7.8 | NVD | Aug 10, 2026 |
| CVE-2026-19379 | A vulnerability was determined in EFM ipTIME AX8004M 15 | HIGH | 7.3 | NVD | Aug 10, 2026 |
| CVE-2026-19376 | A vulnerability has been found in Uasoft Badaso 3 | HIGH | 7.3 | NVD | Aug 10, 2026 |
| CVE-2026-19375 | A vulnerability was detected in dmitriiweb article-scraper-mcp 1 | MEDIUM | 6.3 | NVD | Aug 10, 2026 |
| EDB-52631 | [webapps] CorgetGpsDget 2_3.2 - OS Command Injection | HIGH | N/A | EXPLOIT-DB | Aug 10, 2026 |
| EDB-52633 | [webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution | HIGH | N/A | EXPLOIT-DB | Aug 10, 2026 |
| EDB-52632 | [local] Microsoft Edge 150.0.4078.48 - RCE | HIGH | N/A | EXPLOIT-DB | Aug 10, 2026 |
| EDB-52630 | [webapps] Joomla 2.9.99.4 - Unauthenticated Remote Code Execution | HIGH | N/A | EXPLOIT-DB | Aug 10, 2026 |
| CVE-2026-19374 | A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfe | HIGH | 7.3 | NVD | Aug 09, 2026 |
| CVE-2026-19367 | A vulnerability has been found in NocteDefensor LudusMCP 1 | MEDIUM | 6.3 | NVD | Aug 09, 2026 |
| CVE-2026-19364 | A vulnerability was determined in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 09, 2026 |
| CVE-2026-19358 | A weakness has been identified in 3CORESec Trapdoor up to 1 | MEDIUM | 6.3 | NVD | Aug 09, 2026 |
| CVE-2026-19355 | A vulnerability was determined in MingSoft MCMS up to 3 | HIGH | 7.3 | NVD | Aug 09, 2026 |
| CVE-2026-19354 | A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc | MEDIUM | 6.3 | NVD | Aug 09, 2026 |
| CVE-2026-19351 | A vulnerability was found in dresende node-sql-query 0 | HIGH | 7.3 | NVD | Aug 09, 2026 |
| CVE-2026-19350 | A vulnerability has been found in Dolibarr ERP up to 23 | MEDIUM | 6.3 | NVD | Aug 09, 2026 |
| CVE-2026-19348 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-19347 | A vulnerability was identified in itsourcecode Hospital Management System 1 | MEDIUM | 6.3 | NVD | Aug 09, 2026 |
| CVE-2026-18473 | The WP Directory Kit WordPress plugin before 1 | CRITICAL | 9.1 | NVD | Aug 09, 2026 |
| CVE-2026-18465 | The WP MAPS PRO WordPress plugin before 6 | MEDIUM | 6.5 | NVD | Aug 09, 2026 |
| CVE-2026-18464 | The WP MAPS PRO WordPress plugin before 6 | HIGH | 7.5 | NVD | Aug 09, 2026 |
| CVE-2026-18357 | The WPC Order Tip for WooCommerce WordPress plugin before 3 | HIGH | 7.5 | NVD | Aug 09, 2026 |
| CVE-2026-18032 | The WP Data Access WordPress plugin before 5 | HIGH | 7.5 | NVD | Aug 09, 2026 |
| CVE-2026-17017 | The CubeWP Framework WordPress plugin before 1 | HIGH | 8.1 | NVD | Aug 09, 2026 |
| CVE-2026-16988 | The GeoDirectory WordPress plugin before 2 | HIGH | 7.5 | NVD | Aug 09, 2026 |
| CVE-2026-16032 | The LWS Optimize WordPress plugin before 4 | MEDIUM | 6.1 | NVD | Aug 09, 2026 |
| CVE-2026-15038 | The InfiniteWP Client WordPress plugin before 1 | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71993 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71992 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71991 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71990 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71989 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71988 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71987 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71986 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71985 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71984 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 09, 2026 |
| CVE-2026-71983 | MSI Radix AXE6600 router firmware version v781521 contains a command injection v | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71958 | D-Link DWR-M961 devices with hardware version C1 and software version 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71957 | D-Link DWR-M961 devices with hardware version C1 and software version 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71956 | D-Link DWR-M961 devices with hardware version C1 and software version 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71955 | D-Link DWR-M961 devices with hardware version C1 and software version 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71954 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71953 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71952 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71951 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71950 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71949 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71948 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71947 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71946 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71945 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-71944 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1 | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-67620 | Flowise through 3 | HIGH | 7.7 | NVD | Aug 08, 2026 |
| CVE-2026-42170 | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Su | HIGH | 7.8 | NVD | Aug 08, 2026 |
| CVE-2026-14526 | The AI Copilot โ Content Generator plugin for WordPress is vulnerable to authori | CRITICAL | 9.8 | NVD | Aug 08, 2026 |
| CVE-2026-18988 | The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scrip | MEDIUM | 6.4 | NVD | Aug 08, 2026 |
| CVE-2026-52880 | Klever-Go is the Go implementation of the Klever blockchain protocol | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-52879 | Klever-Go is the Go implementation of the Klever blockchain protocol | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-52878 | Klever-Go is the Go implementation of the Klever blockchain protocol | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-48120 | Kakoune is a code editor | HIGH | 8.6 | NVD | Aug 07, 2026 |
| CVE-2026-48026 | lakeFS is an open-source tool that transforms object storage into a Git-like rep | HIGH | 8.7 | NVD | Aug 07, 2026 |
| CVE-2026-47249 | Klever-Go is the Go implementation of the Klever blockchain protocol | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-47127 | Ghostfolio is an open source wealth management software | MEDIUM | 6.5 | NVD | Aug 07, 2026 |
| CVE-2026-46409 | OpenYak is a local-first agent runtime for reliable tool-using models, with a de | CRITICAL | 9.6 | NVD | Aug 07, 2026 |
| CVE-2026-20348 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthent | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-20347 | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauth | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-20346 | A vulnerability in the PDF file format parser of ClamAV could allow an unauthent | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-20345 | A vulnerability in the GPT file format parser of ClamAV could allow an unauthent | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauth | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticat | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-19211 | A vulnerability was found in SourceCodester Photo Share Website 1 | HIGH | 7.3 | NVD | Aug 07, 2026 |
| CVE-2026-48093 | The Code Embed WordPress plugin prior to version 2 | MEDIUM | 6.5 | NVD | Aug 07, 2026 |
| CVE-2026-19210 | A vulnerability has been found in SourceCodester Photo Share Website 1 | MEDIUM | 6.3 | NVD | Aug 07, 2026 |
| CVE-2026-19264 | Postiz is an open-source social media scheduling tool | CRITICAL | 9.8 | NVD | Aug 07, 2026 |
| CVE-2022-4995 | Weaver (Fanwei) E-cology 9 | CRITICAL | 9.8 | NVD | Aug 07, 2026 |
| CVE-2026-56794 | Openmanage Server Administrator โ Dell OpenManage Server Administrator, versions prior to 11 | MEDIUM | 6.5 | NVD | Aug 07, 2026 |
| CVE-2026-56793 | Openmanage Server Administrator โ Dell OpenManage Server Administrator, versions prior to 11 | HIGH | 7.7 | NVD | Aug 07, 2026 |
| CVE-2026-15816 | A flaw was found in dracut | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-16030 | The MStore API WordPress plugin before 4 | HIGH | 8.1 | NVD | Aug 07, 2026 |
| CVE-2026-15361 | The Content Views WordPress plugin before 4 | HIGH | 8.1 | NVD | Aug 07, 2026 |
| CVE-2026-15359 | The Templately WordPress plugin before 3 | MEDIUM | 6.5 | NVD | Aug 07, 2026 |
| CVE-2026-15215 | The Subscriptions for WooCommerce WordPress plugin before 2 | HIGH | 8.8 | NVD | Aug 07, 2026 |
| CVE-2026-15032 | The Comments WordPress plugin before 7 | MEDIUM | 6.1 | NVD | Aug 07, 2026 |
| CVE-2026-14943 | The Password Protected โ Lock Entire Site, Pages, Posts, Categories, and Partial | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-14331 | The Subscribe2 WordPress plugin before 10 | MEDIUM | 6.1 | NVD | Aug 07, 2026 |
| CVE-2026-14205 | The WP Events Manager WordPress plugin before 2 | CRITICAL | 9.8 | NVD | Aug 07, 2026 |
| CVE-2026-19195 | A vulnerability has been found in V-Secure Jingyun Antivirus 2 | HIGH | 7.8 | NVD | Aug 07, 2026 |
| CVE-2026-19193 | A flaw has been found in Jiangmin Antivirus 21 | HIGH | 7.8 | NVD | Aug 07, 2026 |
| CVE-2026-19192 | A vulnerability was detected in DeepCool DisplayService 1 | HIGH | 7.8 | NVD | Aug 07, 2026 |
| CVE-2026-19191 | A security vulnerability has been detected in StableBit DrivePool 2 | HIGH | 7.8 | NVD | Aug 07, 2026 |
| CVE-2026-14365 | The TrueBooker โ Appointment Booking and Scheduler System plugin for WordPress i | CRITICAL | 9.8 | NVD | Aug 07, 2026 |
| CVE-2026-14364 | The TrueBooker โ Appointment Booking and Scheduler System plugin for WordPress i | CRITICAL | 9.8 | NVD | Aug 07, 2026 |
| CVE-2026-12801 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored | MEDIUM | 6.4 | NVD | Aug 07, 2026 |
| CVE-2026-11907 | The Stream plugin for WordPress is vulnerable to authorization bypass in all ver | MEDIUM | 6.5 | NVD | Aug 07, 2026 |
| CVE-2026-19189 | A security flaw has been discovered in Power Sofware PowerISO 9 | HIGH | 7.8 | NVD | Aug 07, 2026 |
| CVE-2026-70332 | Sharepoint Online โ Improper neutralization of input during web page generation | CRITICAL | 9.6 | NVD | Aug 07, 2026 |
| CVE-2026-68823 | Azure Confidential Ledger โ Exposed dangerous method or function in Azure Confidential L | CRITICAL | 9.1 | NVD | Aug 07, 2026 |
| CVE-2026-65668 | Purview Ediscovery โ Improper access control in Microsoft Purview eDiscovery allo | HIGH | 8.8 | NVD | Aug 07, 2026 |
| CVE-2026-65667 | Teams โ Missing authorization in Microsoft Teams allows an unauthori | CRITICAL | 10.0 | NVD | Aug 07, 2026 |
| CVE-2026-63508 | Planetary Computer โ Missing authentication for critical function in Microsoft Pl | CRITICAL | 10.0 | NVD | Aug 07, 2026 |
| CVE-2026-62918 | Teams โ Improper verification of cryptographic signature in Microsof | HIGH | 7.5 | NVD | Aug 07, 2026 |
| CVE-2026-62896 | Teams โ Improper authentication in Microsoft Teams allows an authori | CRITICAL | 9.6 | NVD | Aug 07, 2026 |
| CVE-2026-62873 | Windows Admin Center โ Improper verification of cryptographic signature in Microsof | CRITICAL | 9.8 | NVD | Aug 07, 2026 |
| CVE-2026-62836 | Azure Sql Managed Instance โ Improper restriction of communication channel to intended en | HIGH | 8.7 | NVD | Aug 07, 2026 |
| CVE-2026-62830 | Azure Sre Agent โ Missing authorization in Azure SRE Agent allows an authorize | CRITICAL | 9.9 | NVD | Aug 07, 2026 |
| CVE-2026-59118 | Power Apps โ Improper authorization in Microsoft Power Apps allows an una | CRITICAL | 9.3 | NVD | Aug 07, 2026 |
| CVE-2026-59115 | Entra Provisioning Service โ ' | CRITICAL | 9.9 | NVD | Aug 07, 2026 |
| CVE-2026-56162 | Azure Sql Database โ Improper authentication in Azure SQL Database allows an unau | CRITICAL | 10.0 | NVD | Aug 07, 2026 |
| CVE-2026-56161 | Azure Logic Apps โ Improper access control in Azure Logic Apps allows an author | CRITICAL | 9.6 | NVD | Aug 07, 2026 |
| CVE-2026-50515 | Azure Service Bus โ Deserialization of untrusted data in Azure Service Bus allow | CRITICAL | 9.9 | NVD | Aug 07, 2026 |
| CVE-2026-50481 | Azure Active Directory โ Modification of assumed-immutable data (maid) in Azure Activ | CRITICAL | 9.9 | NVD | Aug 07, 2026 |
| CVE-2026-49163 | Improper limitation of a pathname to a restricted directory ('path traversal') i | HIGH | 8.8 | NVD | Aug 07, 2026 |
| CVE-2026-8037 | Progress - LoadMaster | CRITICAL | N/A | CISA | Aug 07, 2026 |
| CVE-2026-14812 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backd | CRITICAL | 10.0 | NVD | Aug 06, 2026 |
| CVE-2026-13399 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2 | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-12584 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7 | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-11976 | The official MonsterInsights Pro update distribution bucket (`monster-insights | CRITICAL | 10.0 | NVD | Aug 06, 2026 |
| CVE-2026-11803 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an | HIGH | 7.8 | NVD | Aug 06, 2026 |
| CVE-2026-10599 | The Integrate PhonePe with WooCommerce WordPress plugin through 1 | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-10524 | The CoCart WordPress plugin before 4 | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2025-14561 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isol | CRITICAL | 9.0 | NVD | Aug 06, 2026 |
| CVE-2024-6541 | The Class Mediator fails to correctly validate or sanitize `messageContext` prop | MEDIUM | 6.8 | NVD | Aug 06, 2026 |
| CVE-2024-39024 | In Packetfence 13 | HIGH | 8.8 | NVD | Aug 06, 2026 |
| CVE-2026-68481 | Cxf โ In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-68079 | Cxf โ In Apache CXF's DefaultEncryptingCodeDataProvider,ย a capture | CRITICAL | 9.8 | NVD | Aug 06, 2026 |
| CVE-2026-65583 | Cxf โ Apache CXFโs OIDC relying-party token validation could accep | CRITICAL | 9.1 | NVD | Aug 06, 2026 |
| CVE-2026-63687 | Cxf โ Apache CXF's JwtRequestCodeFilter copies all claims from a s | CRITICAL | 9.1 | NVD | Aug 06, 2026 |
| CVE-2026-61466 | Cxf โ In Apache CXF's OAuth2 Dynamic Client Registration endpoint, | CRITICAL | 9.1 | NVD | Aug 06, 2026 |
| CVE-2026-5391 | The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting | MEDIUM | 6.4 | NVD | Aug 06, 2026 |
| CVE-2026-5158 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites โ PostX plugin | MEDIUM | 6.4 | NVD | Aug 06, 2026 |
| CVE-2026-57818 | Cxf โ A race condition in JCacheCodeDataProvider allows an attacke | HIGH | 8.1 | NVD | Aug 06, 2026 |
| CVE-2026-19035 | A vulnerability was identified in Shibby Tomato 1 | HIGH | 7.2 | NVD | Aug 06, 2026 |
| CVE-2025-15028 | The FormGent โ Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, | HIGH | 7.2 | NVD | Aug 06, 2026 |
| CVE-2026-66909 | Cxf โ Apache CXF's JMS transport deserializes the body of any inbo | CRITICAL | 9.8 | NVD | Aug 06, 2026 |
| CVE-2026-65432 | Cxf โ Apache CXF reads a top-level WSDL through its hardened StaxU | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-64958 | Cxf โ An incomplete fix forย CVE-2026-50645 means that it is still | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-57819 | Cxf โ Apache CXF allows to set a limit on the number of form param | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-57817 | Cxf โ The OpenID Connect Core 1 | HIGH | 8.1 | NVD | Aug 06, 2026 |
| CVE-2026-54225 | Cxf โ Apache CXF allows to control the maximum attachment size via | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-19034 | A vulnerability was determined in Shibby Tomato 1 | HIGH | 7.2 | NVD | Aug 06, 2026 |
| CVE-2026-14204 | The Google Authenticator WordPress plugin before 0 | MEDIUM | 6.5 | NVD | Aug 06, 2026 |
| CVE-2026-13154 | The Gutenberg Essential Blocks WordPress plugin before 6 | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-13153 | The Gutenberg Essential Blocks WordPress plugin before 6 | HIGH | 7.5 | NVD | Aug 06, 2026 |
| CVE-2026-12713 | The WPCargo Track & Trace WordPress plugin before 8 | CRITICAL | 9.1 | NVD | Aug 06, 2026 |
| CVE-2026-11588 | The EONSR AEO Agent WordPress plugin through 3 | MEDIUM | 6.1 | NVD | Aug 06, 2026 |
| CVE-2025-15678 | The Nexter Blocks WordPress plugin before 5 | MEDIUM | 6.1 | NVD | Aug 06, 2026 |
| CVE-2026-19000 | A vulnerability was identified in JeecgBoot up to 3 | HIGH | 7.3 | NVD | Aug 06, 2026 |
| CVE-2026-18998 | A vulnerability was determined in cosmicstack-labs mercury-agent up to 1 | MEDIUM | 6.3 | NVD | Aug 06, 2026 |
| CVE-2026-18997 | A vulnerability was found in cosmicstack-labs mercury-agent up to 1 | MEDIUM | 6.3 | NVD | Aug 06, 2026 |
| CVE-2026-15459 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypa | HIGH | 8.1 | NVD | Aug 06, 2026 |
| CVE-2026-18996 | A vulnerability has been found in cosmicstack-labs mercury-agent up to 1 | MEDIUM | 6.3 | NVD | Aug 06, 2026 |
| CVE-2026-18993 | A vulnerability was detected in NousResearch hermes-agent up to 0 | MEDIUM | 6.3 | NVD | Aug 06, 2026 |
| CVE-2026-18992 | A vulnerability was detected in zhayujie CowAgent up to 2 | MEDIUM | 6.3 | NVD | Aug 06, 2026 |
| CVE-2026-18325 | The Forminator Forms โ Contact Form, Payment Form & Custom Form Builder plugin f | HIGH | 7.2 | NVD | Aug 06, 2026 |
| CVE-2026-16636 | The FluentSMTP โ WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Go | HIGH | 7.2 | NVD | Aug 06, 2026 |
| CVE-2026-15991 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion d | HIGH | 8.8 | NVD | Aug 06, 2026 |
| CVE-2026-67867 | Buffer Overflow vulnerability in Systerel S2OPC 1 | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-67866 | Buffer Overflow vulnerability in Systerel S2OPC 1 | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-67863 | In open62541 1 | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-20288 | A vulnerability in the web-based management interface of Cisco IMC could allow a | MEDIUM | 6.5 | NVD | Aug 05, 2026 |
| CVE-2026-20273 | As part of Cisco's ongoing commitment to proactive security and product quality, | HIGH | 8.6 | NVD | Aug 05, 2026 |
| CVE-2026-20272 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 9.8 | NVD | Aug 05, 2026 |
| CVE-2026-20271 | As part of Cisco's ongoing commitment to proactive security and product quality, | HIGH | 8.6 | NVD | Aug 05, 2026 |
| CVE-2026-20270 | As part of Cisco's ongoing commitment to proactive security and product quality, | HIGH | 8.6 | NVD | Aug 05, 2026 |
| CVE-2026-20269 | As part of Cisco's ongoing commitment to proactive security and product quality, | HIGH | 8.6 | NVD | Aug 05, 2026 |
| CVE-2026-20268 | As part of Cisco's ongoing commitment to proactive security and product quality, | HIGH | 8.6 | NVD | Aug 05, 2026 |
| CVE-2026-20267 | As part of Cisco's ongoing commitment to proactive security and product quality, | CRITICAL | 9.0 | NVD | Aug 05, 2026 |
| CVE-2026-20263 | A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cis | HIGH | 8.6 | NVD | Aug 05, 2026 |
| CVE-2026-20200 | A vulnerability in the web-based management interface of Cisco IMC could allow a | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-20124 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Ci | HIGH | 7.7 | NVD | Aug 05, 2026 |
| CVE-2026-18927 | A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7 | MEDIUM | 6.3 | NVD | Aug 05, 2026 |
| CVE-2026-17630 | Langflow โ IBM Langflow OSS 1 | HIGH | 7.2 | NVD | Aug 05, 2026 |
| CVE-2026-17626 | Langflow โ IBM Langflow OSS 1 | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-17623 | Langflow โ IBM Langflow OSS 1 | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-17617 | IBM Application Gateway Operator 22 | HIGH | 8.5 | NVD | Aug 05, 2026 |
| CVE-2026-71244 | Paperless-ngx's MailAccountViewSet | MEDIUM | 6.5 | NVD | Aug 05, 2026 |
| CVE-2026-71243 | The backmeup npm package assembles shell command strings by directly concatenati | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-71242 | Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / vi | HIGH | 8.3 | NVD | Aug 05, 2026 |
| CVE-2026-71241 | Book-Management-System's Flask API endpoints /student, /record, /books, /find_st | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-71239 | DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, | HIGH | 8.1 | NVD | Aug 05, 2026 |
| CVE-2026-71238 | DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed w | CRITICAL | 9.1 | NVD | Aug 05, 2026 |
| CVE-2026-71237 | Miantang/IoT-PHP's index | CRITICAL | 9.8 | NVD | Aug 05, 2026 |
| CVE-2026-71236 | Grocy's API request-body parser (controllers/Api/BaseApiController | HIGH | 8.7 | NVD | Aug 05, 2026 |
| CVE-2026-71235 | Magistrala's Rules Engine allows authenticated users to create rules with embedd | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-71234 | Documize Community's attachment download route (domain/attachment/endpoint | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-71233 | InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client | HIGH | 8.7 | NVD | Aug 05, 2026 |
| CVE-2026-71232 | MacCMS10's admin template editor (application/admin/controller/Template | HIGH | 7.2 | NVD | Aug 05, 2026 |
| CVE-2026-71231 | IOTSmartHome's gui/login | CRITICAL | 9.8 | NVD | Aug 05, 2026 |
| CVE-2026-66747 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, | CRITICAL | 9.8 | NVD | Aug 05, 2026 |
| CVE-2026-60009 | In Eclipse Theia versions up to and including 1 | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-12609 | In Eclipse Theia versions 1 | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-68060 | A pre-authentication attacker could leverage type size/count handling to cause e | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-67589 | A pre-authentication attacker could leverage type size/count handling to cause e | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-67588 | A pre-authentication attacker could leverage unbounded symbol value caching to c | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-67551 | pre-authentication attacker could leverage type size/count handling to cause exc | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-67465 | A pre-authentication attacker could leverage unbounded symbol value caching to c | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-66273 | A pre-authentication attacker could leverage type size/count handling to cause e | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-66257 | A pre-authentication attacker could leverage unbounded symbol value caching to c | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-18902 | A vulnerability was detected in H3C NX15 V100R017 | HIGH | 7.2 | NVD | Aug 05, 2026 |
| CVE-2026-18322 | The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Esc | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-16143 | The VikRentItems โ Flexible Rental Management System plugin for WordPress is vul | HIGH | 7.2 | NVD | Aug 05, 2026 |
| CVE-2026-15941 | The plugin provides an Admin Search page that allows users with the `edit_posts` | MEDIUM | 6.5 | NVD | Aug 05, 2026 |
| CVE-2026-15918 | VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unaut | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-11421 | The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin | MEDIUM | 6.5 | NVD | Aug 05, 2026 |
| CVE-2026-18901 | A security vulnerability has been detected in H3C NX15 V100R017 | HIGH | 7.2 | NVD | Aug 05, 2026 |
| CVE-2026-18900 | A weakness has been identified in H3C NX15 V100R017 | HIGH | 7.2 | NVD | Aug 05, 2026 |
| CVE-2026-18898 | A security flaw has been discovered in UTT HiPER 1200GW up to v2 | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-18907 | Path Traversal in Download File Feature in com | HIGH | 7.5 | NVD | Aug 05, 2026 |
| CVE-2026-18897 | A vulnerability was identified in UTT HiPER 1250GW up to v3 | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-18896 | A vulnerability was determined in lavkush-maurya Student-Registration-System 1 | MEDIUM | 6.3 | NVD | Aug 05, 2026 |
| CVE-2026-18895 | A vulnerability was found in UTT HiPER 1250GW up to 3 | HIGH | 8.8 | NVD | Aug 05, 2026 |
| CVE-2026-18859 | A vulnerability was identified in ESAFENET CDG up to 20260615 | HIGH | 7.3 | NVD | Aug 05, 2026 |
| CVE-2026-18854 | A vulnerability has been found in Shandong Hoteam PDM Product Data Management Sy | HIGH | 7.3 | NVD | Aug 05, 2026 |
| CVE-2026-45537 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation | CRITICAL | 9.1 | NVD | Aug 04, 2026 |
| CVE-2026-18818 | A weakness has been identified in Ehco1996 django-sspanel up to 2023 | MEDIUM | 6.3 | NVD | Aug 04, 2026 |
| CVE-2026-63455 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orch | CRITICAL | 9.8 | NVD | Aug 04, 2026 |
| CVE-2026-48121 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph | MEDIUM | 6.7 | NVD | Aug 04, 2026 |
| CVE-2026-18787 | A vulnerability was identified in GL | HIGH | 8.8 | NVD | Aug 04, 2026 |
| CVE-2026-18775 | A vulnerability has been found in NousResearch hermes-agent up to 0 | MEDIUM | 6.3 | NVD | Aug 04, 2026 |
| CVE-2026-18774 | A flaw has been found in NousResearch hermes-agent up to 0 | MEDIUM | 6.3 | NVD | Aug 04, 2026 |
| CVE-2026-15920 | An issue was discovered in Django 5 | MEDIUM | 6.1 | NVD | Aug 04, 2026 |
| CVE-2026-15307 | An issue was discovered in Django 5 | HIGH | 8.8 | NVD | Aug 04, 2026 |
| CVE-2025-29296 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3 | CRITICAL | 9.8 | NVD | Aug 04, 2026 |
| CVE-2026-61387 | Milo โ In Eclipse Milo versions 1 | HIGH | 7.5 | NVD | Aug 04, 2026 |
| CVE-2026-60007 | Milo โ In Eclipse Milo versions 0 | HIGH | 7.4 | NVD | Aug 04, 2026 |
| CVE-2026-58080 | Milo โ In Eclipse Milo versions 1 | HIGH | 8.2 | NVD | Aug 04, 2026 |
| CVE-2026-18809 | Information disclosure in Firefox for Android and Firefox Focus for Android | MEDIUM | 6.5 | NVD | Aug 04, 2026 |
| CVE-2026-18806 | External control of file name or path vulnerability in TรBฤฐTAK BฤฐLGEM Software T | HIGH | 7.1 | NVD | Aug 04, 2026 |
| CVE-2026-10710 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigge | HIGH | 7.8 | NVD | Aug 04, 2026 |
| CVE-2026-10709 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigge | HIGH | 7.8 | NVD | Aug 04, 2026 |
| CVE-2026-15721 | Cleartext storage of sensitive information vulnerability in Bilin Software and I | CRITICAL | 9.8 | NVD | Aug 04, 2026 |
| CVE-2026-14838 | Use of GET request method with sensitive query strings vulnerability in Bilin So | HIGH | 7.4 | NVD | Aug 04, 2026 |
| CVE-2026-14804 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informat | CRITICAL | 9.1 | NVD | Aug 04, 2026 |
| CVE-2026-14465 | Insufficient session expiration vulnerability in Bilin Software and Informatics | MEDIUM | 6.5 | NVD | Aug 04, 2026 |
| CVE-2026-14194 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v | MEDIUM | 6.5 | NVD | Aug 04, 2026 |
| CVE-2026-14175 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software | CRITICAL | 9.8 | NVD | Aug 04, 2026 |
| CVE-2026-16293 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11 | MEDIUM | 6.8 | NVD | Aug 04, 2026 |
| CVE-2026-16069 | The Brizy WordPress plugin before 2 | MEDIUM | 6.8 | NVD | Aug 04, 2026 |
| CVE-2026-15958 | The Easy Integration for Dropbox WordPress plugin before 2 | CRITICAL | 9.3 | NVD | Aug 04, 2026 |
| CVE-2026-14939 | The Visualizer WordPress plugin before 4 | MEDIUM | 6.8 | NVD | Aug 04, 2026 |
| CVE-2026-14872 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin befor | MEDIUM | 6.8 | NVD | Aug 04, 2026 |
| CVE-2026-14816 | The GDPR Framework By Data443 WordPress plugin before 2 | MEDIUM | 6.5 | NVD | Aug 04, 2026 |
| CVE-2026-66311 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized | MEDIUM | 6.2 | NVD | Aug 04, 2026 |
| CVE-2026-66310 | External control of file name or path in Microsoft Edge for Android allows an un | HIGH | 7.7 | NVD | Aug 04, 2026 |
| CVE-2026-65804 | Improper control of generation of code ('code injection') in Microsoft Edge (Chr | MEDIUM | 6.1 | NVD | Aug 04, 2026 |
| CVE-2026-65802 | External control of file name or path in Microsoft Edge for Android allows an un | HIGH | 7.4 | NVD | Aug 04, 2026 |
| CVE-2026-62870 | Use after free in Microsoft Office Excel allows an unauthorized attacker to exec | HIGH | 8.8 | NVD | Aug 04, 2026 |
| CVE-2026-18686 | A vulnerability was detected in GL | CRITICAL | 9.8 | NVD | Aug 04, 2026 |
| CVE-2026-18685 | A security vulnerability has been detected in GL | CRITICAL | 9.8 | NVD | Aug 04, 2026 |
| CVE-2026-9198 | IBM - Langflow | CRITICAL | N/A | CISA | Aug 04, 2026 |
| CVE-2026-34486 | Apache - Tomcat | CRITICAL | N/A | CISA | Aug 04, 2026 |
| CVE-2026-18556 | N-able - N-central | CRITICAL | N/A | CISA | Aug 04, 2026 |
| CVE-2026-67978 | An issue in the SBN UDP interface of NASA cFS v7 | HIGH | 7.5 | NVD | Aug 03, 2026 |
| CVE-2026-48399 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Princip | HIGH | 7.5 | NVD | Aug 03, 2026 |
| CVE-2026-48333 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-48331 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) | CRITICAL | 10.0 | NVD | Aug 03, 2026 |
| CVE-2026-48330 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | CRITICAL | 10.0 | NVD | Aug 03, 2026 |
| CVE-2026-48326 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | CRITICAL | 9.9 | NVD | Aug 03, 2026 |
| CVE-2026-48323 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | CRITICAL | 10.0 | NVD | Aug 03, 2026 |
| CVE-2026-48317 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Direct | CRITICAL | 9.6 | NVD | Aug 03, 2026 |
| CVE-2026-18684 | A weakness has been identified in GL | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-18667 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code | CRITICAL | 9.6 | NVD | Aug 03, 2026 |
| CVE-2026-68930 | Russh is a Rust SSH client & server library | MEDIUM | 6.5 | NVD | Aug 03, 2026 |
| CVE-2026-67611 | OpenEMR through 8 | HIGH | 8.1 | NVD | Aug 03, 2026 |
| CVE-2026-67610 | OpenEMR through 8 | HIGH | 8.1 | NVD | Aug 03, 2026 |
| CVE-2026-61372 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v | HIGH | 7.5 | NVD | Aug 03, 2026 |
| CVE-2026-41453 | Krayin CRM before 2 | HIGH | 8.8 | NVD | Aug 03, 2026 |
| CVE-2026-41452 | Krayin CRM 2 | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-39932 | OpenEMR through 8 | CRITICAL | 9.1 | NVD | Aug 03, 2026 |
| CVE-2026-39931 | OpenEMR through 8 | HIGH | 7.2 | NVD | Aug 03, 2026 |
| CVE-2026-18718 | Ghidra contains an arbitrary code execution vulnerability in the Swift demangler | HIGH | 7.0 | NVD | Aug 03, 2026 |
| CVE-2026-18607 | A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN52 | HIGH | 8.8 | NVD | Aug 03, 2026 |
| CVE-2026-18606 | A weakness has been identified in Razer RzUpdateService 1 | HIGH | 7.8 | NVD | Aug 03, 2026 |
| CVE-2026-18605 | A security flaw has been discovered in CheckMAL AppCheck Pro 3 | HIGH | 7.0 | NVD | Aug 03, 2026 |
| CVE-2026-18602 | A vulnerability was determined in GL | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-69084 | SiYuan versions <= v3 | CRITICAL | 10.0 | NVD | Aug 03, 2026 |
| CVE-2026-69083 | SiYuan versions before v3 | CRITICAL | 10.0 | NVD | Aug 03, 2026 |
| CVE-2026-68587 | SiYuan versions before v3 | HIGH | 8.6 | NVD | Aug 03, 2026 |
| CVE-2026-68586 | SiYuan before v3 | HIGH | 8.6 | NVD | Aug 03, 2026 |
| CVE-2026-68584 | SiYuan versions before v3 | HIGH | 8.6 | NVD | Aug 03, 2026 |
| CVE-2026-67608 | Telenia Software TVox 26 | HIGH | 7.2 | NVD | Aug 03, 2026 |
| CVE-2026-64827 | Telenia Software TVox 26 | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-18642 | Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Techn | HIGH | 7.8 | NVD | Aug 03, 2026 |
| CVE-2026-18601 | A vulnerability was found in GL | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-18600 | A vulnerability has been found in GL | HIGH | 8.8 | NVD | Aug 03, 2026 |
| CVE-2026-18108 | Net::SAML2 versions before 0 | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-18092 | Net::SAML2 versions before 0 | HIGH | 8.1 | NVD | Aug 03, 2026 |
| CVE-2026-18089 | Net::SAML2 versions before 0 | HIGH | 7.5 | NVD | Aug 03, 2026 |
| CVE-2026-2346 | Authorization bypass through User-Controlled key vulnerability in Menulux Softwa | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-18599 | A flaw has been found in GL | HIGH | 8.0 | NVD | Aug 03, 2026 |
| CVE-2026-18598 | A vulnerability was detected in GL | HIGH | 8.8 | NVD | Aug 03, 2026 |
| CVE-2026-16250 | The Personal QR Message WordPress plugin through 1 | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-16060 | The Insert or Embed Articulate Content into WordPress plugin through 4 | CRITICAL | 9.8 | NVD | Aug 03, 2026 |
| CVE-2026-16057 | The Contest Gallery WordPress plugin before 30 | MEDIUM | 6.5 | NVD | Aug 03, 2026 |
| CVE-2026-15931 | The Simple Membership WordPress plugin before 4 | MEDIUM | 6.1 | NVD | Aug 03, 2026 |
| CVE-2026-15930 | The Simple Membership WordPress plugin before 4 | CRITICAL | 9.4 | NVD | Aug 03, 2026 |
| CVE-2026-15383 | The Blog Floating Button WordPress plugin through 1 | MEDIUM | 6.1 | NVD | Aug 03, 2026 |
| CVE-2026-15254 | The Simply Schedule Appointments WordPress plugin before 1 | MEDIUM | 6.5 | NVD | Aug 03, 2026 |
| CVE-2026-14557 | The SoftMarket โ Digital Marketplace WordPress plugin through 1 | CRITICAL | 9.1 | NVD | Aug 03, 2026 |
| CVE-2026-13340 | The SVG Support WordPress plugin before 2 | MEDIUM | 6.1 | NVD | Aug 03, 2026 |
| CVE-2026-12965 | The Super Store Finder WordPress plugin through 7 | CRITICAL | 9.1 | NVD | Aug 03, 2026 |
| CVE-2025-15672 | The ChamaWP WordPress plugin before 1 | HIGH | 8.1 | NVD | Aug 03, 2026 |
| CVE-2026-3245 | A deserialization vulnerability in PRISMAproduction Version 6 | HIGH | 7.5 | NVD | Aug 03, 2026 |
| CVE-2026-18577 | N-able - N-central | CRITICAL | N/A | CISA | Aug 03, 2026 |
| CVE-2026-10848 | The OCPP 1 | HIGH | 7.0 | NVD | Aug 02, 2026 |
| CVE-2026-65321 | PyAthena prior to 3 | CRITICAL | 9.8 | NVD | Aug 02, 2026 |
| CVE-2026-68582 | Vikunja versions >= 0 | MEDIUM | 6.5 | NVD | Aug 02, 2026 |
| CVE-2026-68581 | Vikunja versions 0 | HIGH | 8.1 | NVD | Aug 02, 2026 |
| CVE-2026-68580 | FreeRDP before 3 | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-68579 | FreeRDP before 3 | CRITICAL | 9.6 | NVD | Aug 02, 2026 |
| CVE-2026-68578 | ArcadeDB versions before 26 | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-67357 | ArcadeDB versions before 26 | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-67356 | ArcadeDB before 26 | HIGH | 8.8 | NVD | Aug 02, 2026 |
| CVE-2025-71400 | better-auth passkey versions before 1 | HIGH | 7.1 | NVD | Aug 02, 2026 |
| CVE-2025-71399 | Better Auth relies on better-call, which uses the rou3 router library | HIGH | 8.6 | NVD | Aug 02, 2026 |
| CVE-2026-15241 | The AI ChatBot for WooCommerce WordPress plugin before 4 | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-15236 | The Gallery for Google Photos WordPress plugin before 1 | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-15206 | The SMS Alert WordPress plugin before 3 | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-15151 | The Five Star Restaurant Reservations WordPress plugin before 2 | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-14841 | The King Addons for Elementor WordPress plugin before 51 | MEDIUM | 6.1 | NVD | Aug 02, 2026 |
| CVE-2026-13389 | The webtoffee-cookie-consent WordPress plugin before 3 | MEDIUM | 6.5 | NVD | Aug 02, 2026 |
| CVE-2026-8457 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat | CRITICAL | 9.8 | NVD | Aug 02, 2026 |
| CVE-2026-18352 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversa | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-13339 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i | HIGH | 7.5 | NVD | Aug 02, 2026 |
| CVE-2026-67298 | FreeRDP versions 3 | HIGH | 7.5 | NVD | Aug 01, 2026 |
| CVE-2026-67297 | FreeRDP before 3 | HIGH | 7.5 | NVD | Aug 01, 2026 |
| CVE-2026-67296 | FreeRDP before 3 | HIGH | 7.5 | NVD | Aug 01, 2026 |
| CVE-2026-67295 | FreeRDP before 3 | MEDIUM | 6.3 | NVD | Aug 01, 2026 |
| CVE-2026-67292 | FreeRDP before 3 | MEDIUM | 6.5 | NVD | Aug 01, 2026 |
| CVE-2026-67291 | FreeRDP before 3 | HIGH | 7.5 | NVD | Aug 01, 2026 |
| CVE-2026-67290 | FreeRDP before 3 | HIGH | 7.5 | NVD | Aug 01, 2026 |
| CVE-2026-67289 | FreeRDP before 3 | CRITICAL | 9.8 | NVD | Aug 01, 2026 |
| CVE-2026-67288 | FreeRDP before 3 | HIGH | 7.5 | NVD | Aug 01, 2026 |
| CVE-2026-66402 | FreeRDP before 3 | CRITICAL | 9.8 | NVD | Aug 01, 2026 |
| CVE-2026-2411 | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attrib | MEDIUM | 6.5 | NVD | Aug 01, 2026 |
| CVE-2025-71403 | better-auth versions before 1 | HIGH | 7.1 | NVD | Aug 01, 2026 |
| CVE-2026-3141 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d | CRITICAL | 9.1 | NVD | Aug 01, 2026 |
| CVE-2026-7623 | The SureForms โ Contact Form, Payment Form & Other Custom Form Builder plugin fo | MEDIUM | 6.4 | NVD | Aug 01, 2026 |
| CVE-2026-15414 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg | HIGH | 8.8 | NVD | Aug 01, 2026 |
| CVE-2026-15006 | The Bit integrations โ Form Integration, Webhook, Spreadsheets, CRM, LMS & Email | HIGH | 7.5 | NVD | Aug 01, 2026 |
| CVE-2026-13362 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to S | MEDIUM | 6.4 | NVD | Aug 01, 2026 |
| CVE-2026-54785 | gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini | MEDIUM | 6.2 | NVD | Jul 31, 2026 |
| CVE-2026-45377 | Decidim is a participatory democracy framework | MEDIUM | 6.5 | NVD | Jul 31, 2026 |
| CVE-2026-34641 | Premiere Pro is affected by an out-of-bounds write vulnerability that could resu | HIGH | 7.8 | NVD | Jul 31, 2026 |
| CVE-2026-53501 | Thumbor is an open-source photo thumbnail service by globo | HIGH | 8.2 | NVD | Jul 31, 2026 |
| CVE-2026-53500 | Thumbor is an open-source photo thumbnail service by globo | HIGH | 8.2 | NVD | Jul 31, 2026 |
| CVE-2026-18481 | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel be | HIGH | 7.3 | NVD | Jul 31, 2026 |
| CVE-2026-54737 | @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preserva | HIGH | 7.3 | NVD | Jul 31, 2026 |
| CVE-2026-54725 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret | CRITICAL | 9.6 | NVD | Jul 31, 2026 |
| CVE-2026-67822 | Tenda W6-S 1 | CRITICAL | 9.8 | NVD | Jul 31, 2026 |
| CVE-2026-52856 | Wings is the server control plane for Pterodactyl, a free, open-source game serv | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-52855 | Wings is the server control plane for Pterodactyl, a free, open-source game serv | CRITICAL | 9.9 | NVD | Jul 31, 2026 |
| CVE-2026-18358 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-17561 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innot | CRITICAL | 9.8 | NVD | Jul 31, 2026 |
| CVE-2026-62391 | The security fix for CVE-2025-66518 is incomplete | HIGH | 8.1 | NVD | Jul 31, 2026 |
| CVE-2026-44615 | Path traversal vulnerability in Apache Zeppelin | MEDIUM | 6.5 | NVD | Jul 31, 2026 |
| CVE-2026-16843 | Some Hikvision Wireless Access Points are vulnerable to authenticated command ex | HIGH | 7.2 | NVD | Jul 31, 2026 |
| CVE-2026-14483 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner | CRITICAL | 9.8 | NVD | Jul 31, 2026 |
| CVE-2026-14333 | The Demi WordPress plugin before 0 | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-14319 | The GiveWP WordPress plugin before 4 | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-13609 | The Frontend Admin by DynamiApps WordPress plugin before 3 | HIGH | 8.8 | NVD | Jul 31, 2026 |
| CVE-2026-13392 | The ElementsKit Elementor Addons WordPress plugin before 3 | HIGH | 7.2 | NVD | Jul 31, 2026 |
| CVE-2026-12721 | The Kirki WordPress plugin before 6 | HIGH | 8.6 | NVD | Jul 31, 2026 |
| CVE-2026-12720 | The Kirki WordPress plugin before 6 | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-12695 | The miniOrange 2FA WordPress plugin before 6 | HIGH | 8.1 | NVD | Jul 31, 2026 |
| CVE-2026-12251 | The Ultimate Member WordPress plugin before 2 | HIGH | 8.1 | NVD | Jul 31, 2026 |
| CVE-2026-63223 | CodeIgniter is a PHP full-stack web framework | CRITICAL | 9.8 | NVD | Jul 31, 2026 |
| CVE-2026-63222 | CodeIgniter is a PHP full-stack web framework | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-63221 | CodeIgniter is a PHP full-stack web framework | CRITICAL | 9.4 | NVD | Jul 31, 2026 |
| CVE-2026-56673 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-56672 | ComfyUI is a node-based diffusion model GUI, API, and backend | HIGH | 8.2 | NVD | Jul 31, 2026 |
| CVE-2026-56671 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes int | HIGH | 7.5 | NVD | Jul 31, 2026 |
| CVE-2026-56670 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes int | HIGH | 8.2 | NVD | Jul 31, 2026 |
| CVE-2026-66720 | The GOOSE subscriber component improperly validates the UTC timestamp field in | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-66421 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all | CRITICAL | 9.3 | NVD | Jul 30, 2026 |
| CVE-2026-66420 | MeshCentral 1 | HIGH | 8.8 | NVD | Jul 30, 2026 |
| CVE-2026-66369 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be trig | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-66364 | The GOOSE payload parser contains a boundary handling flaw that can be triggere | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-66360 | The ISO Presentation layer contains a flaw in the handling of specific paramete | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-66349 | The MMS server connection handler contains a flaw in its processing of BER-enco | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-65423 | An integer overflow in the UA_Variant arrayDimensions product computation in op | HIGH | 8.8 | NVD | Jul 30, 2026 |
| CVE-2026-65421 | The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-63550 | The MMS BER decoder contains a boundary-handling flaw in the processing of cert | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-63035 | A heap use-after-free vulnerability in the TransferSubscriptions service in ope | HIGH | 8.1 | NVD | Jul 30, 2026 |
| CVE-2026-63033 | A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what f | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-61893 | A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated o | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-56758 | The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connec | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2024-25039 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9 | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-9322 | IBM WebSphere Application Server 9 | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-66414 | Leantime 3 | MEDIUM | 6.1 | NVD | Jul 30, 2026 |
| CVE-2026-62663 | Banks generates meaningful LLM prompts using a simple template language | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-12945 | IBM Langflow OSS 1 | HIGH | 7.1 | NVD | Jul 30, 2026 |
| CVE-2026-12940 | IBM Langflow OSS 1 | CRITICAL | 9.8 | NVD | Jul 30, 2026 |
| CVE-2026-11885 | IBM PowerVM Hypervisor FW1110 | HIGH | 8.4 | NVD | Jul 30, 2026 |
| CVE-2026-54367 | CentreStack before 17 | HIGH | 8.6 | NVD | Jul 30, 2026 |
| CVE-2026-54366 | CentreStack before 17 | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-54365 | CentreStack before 17 | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-54364 | CentreStack before 17 | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-54363 | CentreStack before 17 | CRITICAL | 9.1 | NVD | Jul 30, 2026 |
| CVE-2026-47876 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | CRITICAL | 9.3 | NVD | Jul 30, 2026 |
| CVE-2026-41703 | VMware ESX,ย Workstation, and Fusionย contain an out-of-bounds read vulnerability | HIGH | 7.6 | NVD | Jul 30, 2026 |
| CVE-2026-18382 | A flaw was found in koku-metrics-operator | MEDIUM | 6.8 | NVD | Jul 30, 2026 |
| CVE-2026-18381 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift | HIGH | 7.6 | NVD | Jul 30, 2026 |
| CVE-2026-18378 | A flaw was found in koku-metrics-operator | HIGH | 7.6 | NVD | Jul 30, 2026 |
| CVE-2026-15397 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing | HIGH | 7.2 | NVD | Jul 30, 2026 |
| CVE-2026-22622 | Improper input validation in one of the session management interface of Eaton's | HIGH | 8.8 | NVD | Jul 30, 2026 |
| CVE-2026-22621 | Improper input validation in one of the session management interface of Eaton's | HIGH | 8.3 | NVD | Jul 30, 2026 |
| CVE-2026-22620 | Improper input validation in the authentication component ofย Eaton's Tripp Lite | HIGH | 8.6 | NVD | Jul 30, 2026 |
| CVE-2026-13395 | The Online Scheduling and Appointment Booking System WordPress plugin before 27 | HIGH | 8.6 | NVD | Jul 30, 2026 |
| CVE-2026-13330 | The Animation Addons for Elementor WordPress plugin before 2 | MEDIUM | 6.1 | NVD | Jul 30, 2026 |
| CVE-2026-13178 | The Eventin WordPress plugin before 4 | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-12687 | The ProfileGrid WordPress plugin before 5 | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-12500 | The WP Travel Engine WordPress plugin before 6 | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-11881 | The Fluent Forms WordPress plugin before 6 | MEDIUM | 6.1 | NVD | Jul 30, 2026 |
| CVE-2026-11867 | The Frontend Admin by DynamiApps WordPress plugin before 3 | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-1360 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste | HIGH | 7.5 | NVD | Jul 30, 2026 |
| CVE-2026-16610 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to | CRITICAL | 9.8 | NVD | Jul 30, 2026 |
| CVE-2026-14356 | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a | HIGH | 8.8 | NVD | Jul 30, 2026 |
| CVE-2026-17664 | Insufficient validation of untrusted input in Loader in Google Chrome prior to 1 | MEDIUM | 6.5 | NVD | Jul 30, 2026 |
| CVE-2026-17663 | Insufficient validation of untrusted input in GPU in Google Chrome on Android pr | HIGH | 8.3 | NVD | Jul 30, 2026 |
| CVE-2026-17661 | Use after free in Loader in Google Chrome prior to 151 | HIGH | 8.8 | NVD | Jul 30, 2026 |
| CVE-2026-17660 | Insufficient validation of untrusted input in Network in Google Chrome prior to | HIGH | 8.3 | NVD | Jul 30, 2026 |
| CVE-2026-17658 | Use after free in V8 in Google Chrome prior to 151 | HIGH | 8.8 | NVD | Jul 30, 2026 |
| CVE-2026-17657 | Use after free in Navigation in Google Chrome prior to 151 | HIGH | 8.3 | NVD | Jul 30, 2026 |
| CVE-2026-17656 | Use after free in Ozone in Google Chrome prior to 151 | CRITICAL | 9.6 | NVD | Jul 30, 2026 |
| CVE-2026-17655 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 15 | CRITICAL | 9.6 | NVD | Jul 30, 2026 |
| CVE-2026-17654 | Race in Updater in Google Chrome on Mac prior to 151 | HIGH | 7.8 | NVD | Jul 30, 2026 |
| CVE-2026-17653 | Use after free in Skia in Google Chrome prior to 151 | HIGH | 8.3 | NVD | Jul 30, 2026 |
| CVE-2026-17652 | Use after free in Views in Google Chrome prior to 151 | CRITICAL | 9.6 | NVD | Jul 30, 2026 |
| CVE-2026-17651 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android p | CRITICAL | 9.6 | NVD | Jul 30, 2026 |
| CVE-2026-17650 | Use after free in Compositing in Google Chrome prior to 151 | HIGH | 8.3 | NVD | Jul 30, 2026 |
| CVE-2026-13723 | A vulnerability in the `zipx | MEDIUM | 6.5 | NVD | Jul 29, 2026 |
| CVE-2026-67194 | Courier IMAP before 6 | MEDIUM | 6.5 | NVD | Jul 29, 2026 |
| CVE-2026-64560 | posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwo | HIGH | 7.8 | NVD | Jul 29, 2026 |
| CVE-2026-64559 | s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer l | HIGH | 7.8 | NVD | Jul 29, 2026 |
| CVE-2026-64558 | s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check t | HIGH | 7.8 | NVD | Jul 29, 2026 |
| CVE-2026-54727 | proot-distro is a utility for managing proot containers | HIGH | 8.2 | NVD | Jul 29, 2026 |
| CVE-2026-54680 | Logging operator automates the deployment and configuration of Kubernetes loggin | CRITICAL | 9.9 | NVD | Jul 29, 2026 |
| CVE-2026-54574 | proot-distro is a utility for managing proot containers | HIGH | 8.2 | NVD | Jul 29, 2026 |
| CVE-2026-51992 | SQL Injection vulnerability in ClickHouse Server Versions <= 26 | CRITICAL | 9.1 | NVD | Jul 29, 2026 |
| CVE-2026-18255 | A flaw was found in Quay | HIGH | 7.2 | NVD | Jul 29, 2026 |
| CVE-2026-15144 | @fastify/rate-limit before 11 | HIGH | 7.3 | NVD | Jul 29, 2026 |
| CVE-2026-13697 | undici's cache interceptor mishandles malformed Cache-Control private directives | HIGH | 7.4 | NVD | Jul 29, 2026 |
| CVE-2025-60931 | An Insecure Direct Object Reference (IDOR) in the Employee Compensation View fun | HIGH | 7.5 | NVD | Jul 29, 2026 |
| CVE-2026-14270 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom | HIGH | 8.8 | NVD | Jul 29, 2026 |
| CVE-2026-8791 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Sit | MEDIUM | 6.4 | NVD | Jul 29, 2026 |
| CVE-2026-7436 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to S | MEDIUM | 6.4 | NVD | Jul 29, 2026 |
| CVE-2026-5060 | The MasterStudy LMS WordPress Plugin โ for Online Courses and Education plugin f | MEDIUM | 6.5 | NVD | Jul 29, 2026 |
| CVE-2026-18220 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back | HIGH | 7.8 | NVD | Jul 29, 2026 |
| CVE-2026-16655 | The Fluent Forms โ Customizable Contact Forms, Survey, Quiz, & Conversational Fo | HIGH | 7.2 | NVD | Jul 29, 2026 |
| CVE-2026-16597 | The GTM4WP โ A Google Tag Manager (GTM) plugin for WordPress plugin for WordPres | HIGH | 7.2 | NVD | Jul 29, 2026 |
| CVE-2026-14900 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Cod | CRITICAL | 9.8 | NVD | Jul 29, 2026 |
| CVE-2026-14488 | The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via | CRITICAL | 9.1 | NVD | Jul 29, 2026 |
| CVE-2026-63234 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed | CRITICAL | 9.9 | NVD | Jul 29, 2026 |
| CVE-2026-63233 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed | CRITICAL | 9.9 | NVD | Jul 29, 2026 |
| CVE-2026-63232 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed | CRITICAL | 9.9 | NVD | Jul 29, 2026 |
| CVE-2026-63231 | A post-authentication SQL injection vulnerability in Koollab LMS allowed an auth | HIGH | 8.1 | NVD | Jul 29, 2026 |
| CVE-2026-63230 | A pre-authentication error-based SQL injection vulnerability in Koollab LMS allo | CRITICAL | 9.1 | NVD | Jul 29, 2026 |
| CVE-2026-63229 | A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an | CRITICAL | 9.1 | NVD | Jul 29, 2026 |
| CVE-2026-63227 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authen | CRITICAL | 9.9 | NVD | Jul 29, 2026 |
| CVE-2026-14300 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Wo | HIGH | 8.1 | NVD | Jul 29, 2026 |
| CVE-2026-14234 | The WOLF WordPress plugin before 1 | HIGH | 7.1 | NVD | Jul 29, 2026 |
| CVE-2026-13690 | The UsersWP WordPress plugin before 1 | HIGH | 7.4 | NVD | Jul 29, 2026 |
| CVE-2026-13605 | The PhotoSwipe WordPress plugin through 4 | MEDIUM | 6.8 | NVD | Jul 29, 2026 |
| CVE-2026-13423 | The Streamit WordPress theme through 4 | CRITICAL | 9.8 | NVD | Jul 29, 2026 |
| CVE-2026-11974 | The wp-media-folder-addon WordPress plugin through 4 | HIGH | 8.6 | NVD | Jul 29, 2026 |
| CVE-2026-18072 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick | CRITICAL | 9.8 | NVD | Jul 29, 2026 |
| CVE-2026-17162 | The WowStore โ Store Builder & Product Blocks for WooCommerce plugin for WordPre | MEDIUM | 6.4 | NVD | Jul 29, 2026 |
| CVE-2026-17161 | The WowStore โ Store Builder & Product Blocks for WooCommerce plugin for WordPre | MEDIUM | 6.4 | NVD | Jul 29, 2026 |
| CVE-2026-15735 | The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-S | MEDIUM | 6.4 | NVD | Jul 29, 2026 |
| CVE-2026-12939 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scr | MEDIUM | 6.4 | NVD | Jul 29, 2026 |
| CVE-2026-12938 | The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scr | MEDIUM | 6.4 | NVD | Jul 29, 2026 |
| CVE-2026-12144 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Es | HIGH | 8.8 | NVD | Jul 29, 2026 |
| CVE-2026-56822 | Netty is an asynchronous, event-driven network application framework | HIGH | 7.4 | NVD | Jul 29, 2026 |
| CVE-2026-56821 | Netty is an asynchronous, event-driven network application framework | HIGH | 7.4 | NVD | Jul 29, 2026 |
| CVE-2026-20316 | Cisco - Secure Firewall Management Center (FMC) | CRITICAL | N/A | CISA | Jul 29, 2026 |
| CVE-2026-66063 | goshs is a feature-rich single-binary file server for red teamers and developers | MEDIUM | 6.5 | NVD | Jul 28, 2026 |
| CVE-2026-64863 | goshs is a feature-rich single-binary file server for red teamers and developers | CRITICAL | 9.1 | NVD | Jul 28, 2026 |
| CVE-2026-62325 | goshs is a feature-rich single-binary file server for red teamers and developers | CRITICAL | 9.1 | NVD | Jul 28, 2026 |
| CVE-2026-54719 | goshs is a feature-rich single-binary file server for red teamers and developers | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-54658 | Hypequery is a TypeScript semantic layer for ClickHouse | CRITICAL | 9.8 | NVD | Jul 28, 2026 |
| CVE-2026-54650 | openhole exposes localhost to the internet in one command | HIGH | 8.6 | NVD | Jul 28, 2026 |
| CVE-2026-54638 | gotd/td is a T Telegram MTProto API client in Go | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-47219 | find-my-way is a framework-independent HTTP router that internally uses a Radix | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-51275 | In schreibfaul1 ESP32-audioI2S 3 | HIGH | 8.8 | NVD | Jul 28, 2026 |
| CVE-2026-51274 | In schreibfaul1 ESP32-audioI2S 3 | HIGH | 8.8 | NVD | Jul 28, 2026 |
| CVE-2026-51273 | In schreibfaul1 ESP32-audioI2S 3 | HIGH | 7.8 | NVD | Jul 28, 2026 |
| CVE-2026-16313 | A flaw was found in sg3_utils | HIGH | 7.6 | NVD | Jul 28, 2026 |
| CVE-2026-7868 | IBM OPENBMC FW1110 | MEDIUM | 6.5 | NVD | Jul 28, 2026 |
| CVE-2026-66749 | Let's Chat 0 | MEDIUM | 6.5 | NVD | Jul 28, 2026 |
| CVE-2026-66748 | Camaleon CMS versions 2 | HIGH | 8.8 | NVD | Jul 28, 2026 |
| CVE-2026-61609 | Pterodactyl is a free, open-source game server management panel | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-18047 | A flaw was found in Dogtag PKI's ACME responder where the web | MEDIUM | 6.5 | NVD | Jul 28, 2026 |
| CVE-2026-15393 | The Cozy Blocks โ Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 | MEDIUM | 6.4 | NVD | Jul 28, 2026 |
| CVE-2026-15016 | The Paid Memberships Pro โ Content Restriction, User Registration, & Paid Subscr | MEDIUM | 6.4 | NVD | Jul 28, 2026 |
| CVE-2026-15025 | The Uncanny Automator โ Easy Automation, Integration, Webhooks & Workflow Builde | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-13440 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Che | HIGH | 7.2 | NVD | Jul 28, 2026 |
| CVE-2026-12741 | The WP Fast Total Search โ The Power of Indexed Search plugin for WordPress is v | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-11756 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App | CRITICAL | 10.0 | NVD | Jul 28, 2026 |
| CVE-2026-6251 | The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Bli | MEDIUM | 6.5 | NVD | Jul 28, 2026 |
| CVE-2026-16585 | The Better Messages โ Chat Rooms, Group Chat, Private Messages & AI Chat Bots pl | HIGH | 7.2 | NVD | Jul 28, 2026 |
| CVE-2026-14924 | The Tablesome Table WordPress plugin before 1 | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-14870 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin befor | HIGH | 7.1 | NVD | Jul 28, 2026 |
| CVE-2026-14545 | The TrueBooker WordPress plugin before 1 | CRITICAL | 9.8 | NVD | Jul 28, 2026 |
| CVE-2026-14490 | The Demi โ One Click Demo Import, WP Backup & Site Migration plugin for WordPres | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-17528 | Versions of the package nice-select2 before 2 | MEDIUM | 6.1 | NVD | Jul 28, 2026 |
| CVE-2026-17524 | Versions of the package zip-lib before 1 | HIGH | 7.5 | NVD | Jul 28, 2026 |
| CVE-2026-66473 | Unauthenticated Broken Access Control in Xendit Payment <= 7 | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-65448 | Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – | MEDIUM | 6.5 | NVD | Jul 27, 2026 |
| CVE-2026-65447 | Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-65446 | Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-65445 | Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1 | MEDIUM | 6.5 | NVD | Jul 27, 2026 |
| CVE-2026-65443 | Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-65442 | Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3 | HIGH | 7.2 | NVD | Jul 27, 2026 |
| CVE-2026-65441 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-65440 | Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-65439 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-65438 | Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-65437 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWal | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-61957 | Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-61953 | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro | HIGH | 7.2 | NVD | Jul 27, 2026 |
| CVE-2026-51565 | Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController | MEDIUM | 6.1 | NVD | Jul 27, 2026 |
| CVE-2025-63913 | An issue was discovered in OpenSBI 1 | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-51235 | LibRaw 0 | HIGH | 8.8 | NVD | Jul 27, 2026 |
| CVE-2026-48030 | Pheditor is a single-file editor and file manager written in PHP | CRITICAL | 9.9 | NVD | Jul 27, 2026 |
| CVE-2026-45623 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-17568 | Improper access control in the role membership management endpoint in Devolution | HIGH | 8.8 | NVD | Jul 27, 2026 |
| CVE-2026-17552 | Plack::App::Prerender versions before 0 | CRITICAL | 9.1 | NVD | Jul 27, 2026 |
| CVE-2026-66731 | facil | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-66730 | facil | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-66729 | facil | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-66391 | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability | MEDIUM | 6.5 | NVD | Jul 27, 2026 |
| CVE-2026-66390 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti | MEDIUM | 6.1 | NVD | Jul 27, 2026 |
| CVE-2026-63077 | In JetBrains TeamCity before 2026 | CRITICAL | 9.8 | NVD | Jul 27, 2026 |
| CVE-2026-24252 | NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS co | HIGH | 7.8 | NVD | Jul 27, 2026 |
| CVE-2026-17192 | A VCO feature does not sufficiently validate caller-supplied input, allowing req | HIGH | 8.5 | NVD | Jul 27, 2026 |
| CVE-2026-17191 | An input validation vulnerability exists in an API component of the orchestrator | CRITICAL | 9.1 | NVD | Jul 27, 2026 |
| CVE-2026-58662 | Thrift โ Improper Validation of Specified Quantity in Input, Out-of-b | CRITICAL | 9.1 | NVD | Jul 27, 2026 |
| CVE-2026-58389 | Thrift โ Allocation of Resources Without Limits or Throttling vulnera | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-58023 | Thrift โ Out-of-bounds Read vulnerability in Apache Thrift c_glib bin | CRITICAL | 9.1 | NVD | Jul 27, 2026 |
| CVE-2026-55971 | Thrift โ Heap-based Buffer Overflow vulnerability in Apache Thrift C+ | CRITICAL | 9.8 | NVD | Jul 27, 2026 |
| CVE-2026-55970 | Thrift โ Buffer Over-read vulnerability in Apache Thrift C++ bindings | MEDIUM | 6.5 | NVD | Jul 27, 2026 |
| CVE-2026-55969 | Thrift โ Integer Overflow or Wraparound vulnerability in Apache Thrif | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-55968 | Thrift โ Inefficient Algorithmic Complexity, Allocation of Resources | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-49158 | Thrift โ Improper Handling of Highly Compressed Data (Data Amplificat | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-48586 | Thrift โ Improper Handling of Highly Compressed Data (Data Amplificat | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-48145 | Thrift โ Improper Validation of Certificate with Host Mismatch vulner | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-48144 | Thrift โ Improper Validation of Certificate with Host Mismatch vulner | CRITICAL | 9.1 | NVD | Jul 27, 2026 |
| CVE-2026-45112 | Thrift โ Allocation of Resources Without Limits or Throttling vulnera | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-43871 | Thrift โ Loop with Unreachable Exit Condition ('Infinite Loop') vulne | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-41608 | Thrift โ Improper Handling of Highly Compressed Data (Data Amplificat | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-14568 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Pro | MEDIUM | 6.5 | NVD | Jul 27, 2026 |
| CVE-2026-14289 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5 | CRITICAL | 9.0 | NVD | Jul 27, 2026 |
| CVE-2026-14235 | The Download Manager WordPress plugin before 3 | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-14190 | The Sina Extension for Elementor WordPress plugin before 3 | MEDIUM | 6.1 | NVD | Jul 27, 2026 |
| CVE-2026-13726 | The MPG WordPress plugin before 4 | HIGH | 7.1 | NVD | Jul 27, 2026 |
| CVE-2026-13714 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5 | CRITICAL | 9.8 | NVD | Jul 27, 2026 |
| CVE-2026-13597 | The ๅพฎไฟกไบ็ปด็ ็ป้ WordPress plugin through 1 | CRITICAL | 9.1 | NVD | Jul 27, 2026 |
| CVE-2026-13400 | Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site | MEDIUM | 6.1 | NVD | Jul 27, 2026 |
| CVE-2026-13332 | The Masteriyo LMS WordPress plugin before 2 | CRITICAL | 9.1 | NVD | Jul 27, 2026 |
| CVE-2026-13152 | The Custom Fields Account Registration For Woocommerce WordPress plugin before 1 | HIGH | 8.1 | NVD | Jul 27, 2026 |
| CVE-2026-12982 | The Document Gallery WordPress plugin before 5 | MEDIUM | 6.1 | NVD | Jul 27, 2026 |
| CVE-2026-12493 | The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1 | HIGH | 7.5 | NVD | Jul 27, 2026 |
| CVE-2026-12394 | The MemberGlut WordPress plugin before 1 | CRITICAL | 9.8 | NVD | Jul 27, 2026 |
| CVE-2026-12255 | The MainWP Child WordPress plugin before 6 | HIGH | 8.1 | NVD | Jul 27, 2026 |
| CVE-2026-10082 | The Advanced Ads WordPress plugin before 2 | MEDIUM | 6.1 | NVD | Jul 27, 2026 |
| CVE-2025-15662 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin bef | HIGH | 8.6 | NVD | Jul 27, 2026 |
| CVE-2025-68686 | Fortinet - FortiOS | CRITICAL | N/A | CISA | Jul 27, 2026 |
| CVE-2026-16812 | Arista - VeloCloud Orchestrator | CRITICAL | N/A | CISA | Jul 27, 2026 |
| CVE-2026-57990 | Files or directories accessible to external parties in Microsoft Edge (Chromium- | HIGH | 7.4 | NVD | Jul 26, 2026 |
| CVE-2026-57989 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize | HIGH | 7.4 | NVD | Jul 26, 2026 |
| CVE-2026-17497 | NoteGen before 0 | HIGH | 8.3 | NVD | Jul 26, 2026 |
| CVE-2026-17496 | NoteGen before 0 | HIGH | 8.1 | NVD | Jul 26, 2026 |
| CVE-2026-17458 | A vulnerability was found in mf-yang openclaw-cn up to 0 | MEDIUM | 6.3 | NVD | Jul 26, 2026 |
| CVE-2026-64530 | net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() | CRITICAL | 9.8 | NVD | Jul 26, 2026 |
| CVE-2024-14040 | net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur a | HIGH | 7.8 | NVD | Jul 26, 2026 |
| CVE-2026-63720 | datamodel-code-generator prior to version 0 | HIGH | 7.5 | NVD | Jul 26, 2026 |
| CVE-2026-17434 | A flaw has been found in nanocoai NanoClaw up to 2 | MEDIUM | 6.3 | NVD | Jul 26, 2026 |
| CVE-2026-15962 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Objec | HIGH | 8.8 | NVD | Jul 26, 2026 |
| CVE-2026-10681 | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/us | MEDIUM | 6.5 | NVD | Jul 25, 2026 |
| CVE-2026-66012 | SiYuan before v3 | CRITICAL | 10.0 | NVD | Jul 25, 2026 |
| CVE-2026-15425 | The Yoast SEO โ Advanced SEO with real-time guidance and built-in AI plugin for | MEDIUM | 6.4 | NVD | Jul 25, 2026 |
| CVE-2026-14955 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerab | MEDIUM | 6.5 | NVD | Jul 25, 2026 |
| CVE-2026-10818 | The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a | HIGH | 8.1 | NVD | Jul 25, 2026 |
| CVE-2026-66374 | Knot Resolver before 6 | HIGH | 8.1 | NVD | Jul 25, 2026 |
| CVE-2026-66373 | Redis before 8 | HIGH | 7.5 | NVD | Jul 25, 2026 |
| CVE-2026-54342 | In epa4all, prior to version 2026-05-20, an attacker on the network path between | HIGH | 8.1 | NVD | Jul 24, 2026 |
| CVE-2026-48021 | In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS c | CRITICAL | 9.1 | NVD | Jul 24, 2026 |
| CVE-2026-17107 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad | HIGH | 8.5 | NVD | Jul 24, 2026 |
| CVE-2026-66035 | libssh2 through 1 | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-66034 | libssh2 through 1 | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-66033 | libssh2 through 1 | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-66032 | libssh2 through 1 | HIGH | 8.8 | NVD | Jul 24, 2026 |
| CVE-2026-65711 | sysPass through version 3 | HIGH | 7.2 | NVD | Jul 24, 2026 |
| CVE-2026-65710 | sysPass through version 3 | HIGH | 7.1 | NVD | Jul 24, 2026 |
| CVE-2026-65709 | sysPass through version 3 | HIGH | 8.3 | NVD | Jul 24, 2026 |
| CVE-2026-65708 | sysPass through version 3 | HIGH | 8.1 | NVD | Jul 24, 2026 |
| CVE-2026-65707 | Likeshop through 3 | MEDIUM | 6.5 | NVD | Jul 24, 2026 |
| CVE-2026-9765 | Note: The CVE and blog post don't exist because we determined this is actually a | HIGH | 7.1 | NVD | Jul 24, 2026 |
| CVE-2026-66144 | Although remote policy references are not retrieved during policy normalization, | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-66143 | It is possible to bypass theย maximum number of normalized policy alternatives th | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-66142 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-66010 | DOMPurify before 3 | MEDIUM | 6.1 | NVD | Jul 24, 2026 |
| CVE-2026-45816 | NULL Pointer Dereference vulnerability in Apache NimBLE inย LE Long Term Key Requ | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-45815 | Reachable Assertion vulnerability in Apache NimBLE | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-45813 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apa | HIGH | 8.8 | NVD | Jul 24, 2026 |
| CVE-2026-45812 | Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when process | MEDIUM | 6.5 | NVD | Jul 24, 2026 |
| CVE-2026-45811 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerabi | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-15653 | The Visualizer โ Tables & Charts Manager with Built-in AI Generator plugin for W | MEDIUM | 6.4 | NVD | Jul 24, 2026 |
| CVE-2026-15648 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Si | MEDIUM | 6.4 | NVD | Jul 24, 2026 |
| CVE-2026-15464 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scr | MEDIUM | 6.4 | NVD | Jul 24, 2026 |
| CVE-2026-15334 | The Cozy Blocks โ Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 | MEDIUM | 6.4 | NVD | Jul 24, 2026 |
| CVE-2026-15333 | The Cozy Blocks โ Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 | MEDIUM | 6.4 | NVD | Jul 24, 2026 |
| CVE-2026-14603 | The WowOptin: Next-Gen Popup Maker WordPress plugin before 1 | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-14172 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables | HIGH | 7.8 | NVD | Jul 24, 2026 |
| CVE-2026-12981 | The CAFEHAUS API WordPress plugin through 1 | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-12877 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5 | CRITICAL | 9.1 | NVD | Jul 24, 2026 |
| CVE-2026-12688 | The ProfileGrid WordPress plugin before 5 | MEDIUM | 6.5 | NVD | Jul 24, 2026 |
| CVE-2026-12497 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User | HIGH | 7.5 | NVD | Jul 24, 2026 |
| CVE-2026-16870 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior | HIGH | 8.8 | NVD | Jul 24, 2026 |
| CVE-2026-66141 | Exim before 4 | HIGH | 7.4 | NVD | Jul 24, 2026 |
| CVE-2026-66140 | Exim before 4 | HIGH | 8.4 | NVD | Jul 24, 2026 |
| CVE-2026-66138 | In OpenStack Ironic Python Agent through 11 | HIGH | 7.2 | NVD | Jul 24, 2026 |
| CVE-2026-12736 | The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in vers | HIGH | 8.0 | NVD | Jul 24, 2026 |
| CVE-2025-9205 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in | MEDIUM | 6.4 | NVD | Jul 24, 2026 |
| CVE-2026-62825 | Improper authentication in Azure Key Vault allows an unauthorized attacker to el | CRITICAL | 10.0 | NVD | Jul 24, 2026 |
| CVE-2026-58275 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate pr | CRITICAL | 10.0 | NVD | Jul 24, 2026 |
| CVE-2026-56191 | Improper authentication in Microsoft Exchange Online allows an unauthorized atta | CRITICAL | 10.0 | NVD | Jul 24, 2026 |
| CVE-2026-56167 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attac | HIGH | 8.5 | NVD | Jul 24, 2026 |
| CVE-2026-56165 | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker | CRITICAL | 9.8 | NVD | Jul 24, 2026 |
| CVE-2026-56160 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att | CRITICAL | 9.1 | NVD | Jul 24, 2026 |
| CVE-2026-54120 | Improper input validation in Microsoft Surface allows an authorized attacker to | CRITICAL | 9.9 | NVD | Jul 24, 2026 |
| CVE-2026-50517 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker | CRITICAL | 9.9 | NVD | Jul 24, 2026 |
| CVE-2026-49159 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph al | MEDIUM | 6.5 | NVD | Jul 24, 2026 |
| CVE-2026-35425 | Improper access control in Azure API Management (APIM) allows an authorized atta | HIGH | 8.0 | NVD | Jul 24, 2026 |
| CVE-2026-50044 | Pronetiqs IntraVUE versions 3 | MEDIUM | 6.8 | NVD | Jul 23, 2026 |
| CVE-2026-42933 | Pronetiqs IntraVUE versions 3 | CRITICAL | 10.0 | NVD | Jul 23, 2026 |
| CVE-2026-40430 | Pronetiqs IntraVUE Versions 3 | HIGH | 7.5 | NVD | Jul 23, 2026 |
| CVE-2026-28698 | Pronetiqs IntraVUE versions 3 | HIGH | 8.6 | NVD | Jul 23, 2026 |
| CVE-2026-16767 | A vulnerability was detected in Ne-Lexa php-zip up to 4 | MEDIUM | 6.5 | NVD | Jul 23, 2026 |
| CVE-2026-65702 | Vanna through 2 | HIGH | 8.6 | NVD | Jul 23, 2026 |
| CVE-2026-65701 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path trav | CRITICAL | 9.1 | NVD | Jul 23, 2026 |
| CVE-2026-65700 | h2oGPT through 0 | CRITICAL | 9.8 | NVD | Jul 23, 2026 |
| CVE-2026-47755 | ITFlow provides an IT documentation, ticketing and accounting system for small m | MEDIUM | 6.5 | NVD | Jul 23, 2026 |
| CVE-2026-47752 | Tugtainer is a self-hosted app for automating updates of Docker containers | CRITICAL | 9.9 | NVD | Jul 23, 2026 |
| CVE-2026-47743 | Shopper is a Headless e-commerce Admin Panel | HIGH | 8.7 | NVD | Jul 23, 2026 |
| CVE-2026-47668 | DbGate is cross-platform database manager | CRITICAL | 10.0 | NVD | Jul 23, 2026 |
| CVE-2026-65697 | Fathom Lite through 1 | MEDIUM | 6.1 | NVD | Jul 23, 2026 |
| CVE-2026-65695 | Office-Word-MCP-Server through 1 | MEDIUM | 6.8 | NVD | Jul 23, 2026 |
| CVE-2026-44909 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP | HIGH | 7.5 | NVD | Jul 23, 2026 |
| CVE-2026-50522 | Microsoft - SharePoint | CRITICAL | N/A | CISA | Jul 22, 2026 |
| CVE-2026-16232 | Check Point - SmartConsole | CRITICAL | N/A | CISA | Jul 22, 2026 |
| CVE-2026-60137 | WordPress - Core | CRITICAL | N/A | CISA | Jul 21, 2026 |
| CVE-2026-0770 | Langflow - Langflow | CRITICAL | N/A | CISA | Jul 21, 2026 |
| CVE-2021-27137 | DD-WRT - DD-WRT | CRITICAL | N/A | CISA | Jul 21, 2026 |
| CVE-2026-63030 | WordPress - Core | CRITICAL | N/A | CISA | Jul 21, 2026 |
| CVE-2026-39808 | Fortinet - FortiSandbox | CRITICAL | N/A | CISA | Jul 16, 2026 |
| CVE-2026-25089 | Fortinet - FortiSandbox | CRITICAL | N/A | CISA | Jul 16, 2026 |
| CVE-2026-58644 | Microsoft - SharePoint | CRITICAL | N/A | CISA | Jul 16, 2026 |
| CVE-2023-4346 | KNX Association - KNX Protocol Connection Authorization Option 1 | CRITICAL | N/A | CISA | Jul 15, 2026 |
| CVE-2026-46817 | Oracle - E-Business Suite | CRITICAL | N/A | CISA | Jul 15, 2026 |
| CVE-2026-15409 | SonicWall - SMA1000 Appliances | CRITICAL | N/A | CISA | Jul 14, 2026 |
| CVE-2026-15410 | SonicWall - SMA1000 Appliances | CRITICAL | N/A | CISA | Jul 14, 2026 |
| CVE-2026-56155 | Microsoft - Active Directory Federation Services | CRITICAL | N/A | CISA | Jul 14, 2026 |
| CVE-2026-56164 | Microsoft - SharePoint Server | CRITICAL | N/A | CISA | Jul 14, 2026 |
| CVE-2008-4128 | Cisco - IOS | CRITICAL | N/A | CISA | Jul 13, 2026 |
| CVE-2026-48939 | iCagenda - iCagenda | CRITICAL | N/A | CISA | Jul 10, 2026 |
| CVE-2026-56291 | Balbooa - Forms | CRITICAL | N/A | CISA | Jul 10, 2026 |
| EDB-52629 | [webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution | HIGH | N/A | EXPLOIT-DB | Jul 08, 2026 |
| EDB-52627 | [webapps] Langflow 1.9.0 - RCE | HIGH | N/A | EXPLOIT-DB | Jul 08, 2026 |
| EDB-52626 | [webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload | HIGH | N/A | EXPLOIT-DB | Jul 08, 2026 |
| EDB-52628 | [webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure | HIGH | N/A | EXPLOIT-DB | Jul 08, 2026 |
| EDB-52622 | [remote] Hydra - Stack Buffer Overflow | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| EDB-52621 | [webapps] Discuz! X5.0 - Authentication Bypass | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| CVE-2026-48908 | JoomShaper - SP Page Builder | CRITICAL | N/A | CISA | Jul 07, 2026 |
| CVE-2026-55255 | Langflow - Langflow | CRITICAL | N/A | CISA | Jul 07, 2026 |
| EDB-52618 | [remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| EDB-52619 | [webapps] WordPress Bricks Builder Theme - RCE | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| EDB-52625 | [webapps] MCPJam Inspector - Remote Code Execution | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| EDB-52624 | [local] ProtonVPN v4.4.1 - Unquoted Service Path | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| EDB-52623 | [webapps] Flowise 3.1.3 - arbitrary code execution | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| EDB-52620 | [webapps] Tenable Nessus 10.12.1 - SQL Injection | HIGH | N/A | EXPLOIT-DB | Jul 07, 2026 |
| EDB-52617 | [webapps] Joomla Extension 4.1.4 - PHP Object injection | HIGH | N/A | EXPLOIT-DB | Jul 06, 2026 |
| EDB-52616 | [webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass | HIGH | N/A | EXPLOIT-DB | Jul 06, 2026 |
| EDB-52615 | [local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation | HIGH | N/A | EXPLOIT-DB | Jul 06, 2026 |
| EDB-52614 | [webapps] KeepInMind 0.8.4.2 - Stored XSS | HIGH | N/A | EXPLOIT-DB | Jul 06, 2026 |
| EDB-52613 | [webapps] KNX visualisering - Broken Access Control | HIGH | N/A | EXPLOIT-DB | Jul 06, 2026 |
| EDB-52612 | [local] Windows Defender (MsMpEng.exe) - Race Condition | HIGH | N/A | EXPLOIT-DB | Jul 06, 2026 |
| EDB-52611 | [webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS) | HIGH | N/A | EXPLOIT-DB | Jul 06, 2026 |
| EDB-52610 | [webapps] OpenEMR 7.0.2 - Arbitrary File Read | HIGH | N/A | EXPLOIT-DB | Jun 08, 2026 |
1440 results