21 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-63227 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCOR | CRITICAL | 9.9 | 25%ile | NVD | 2026-07-29 |
| CVE-2026-16610 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up | CRITICAL | 9.8 | 44%ile | NVD | 2026-07-30 |
| CVE-2026-63223 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i | CRITICAL | 9.8 | 40%ile | NVD | 2026-07-31 |
| CVE-2026-14483 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver | CRITICAL | 9.8 | 46%ile | NVD | 2026-07-31 |
| CVE-2026-14175 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS | CRITICAL | 9.8 | 32%ile | NVD | 2026-08-04 |
| CVE-2026-65885 | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows au | CRITICAL | 9.4 | 17%ile | NVD | 2026-07-29 |
| CVE-2026-14270 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl | HIGH | 8.8 | 43%ile | NVD | 2026-07-29 |
| CVE-2026-16236 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5 | HIGH | 8.8 | 47%ile | NVD | 2026-07-31 |
| CVE-2026-67206 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticat | HIGH | 8.7 | 36%ile | NVD | 2026-07-30 |
| CVE-2026-39931 | OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t | HIGH | 8.6 | 25%ile | NVD | 2026-08-03 |
| CVE-2026-61524 | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th | HIGH | 8.6 | 43%ile | NVD | 2026-08-03 |
| CVE-2026-67243 | freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig | HIGH | 8.6 | 22%ile | NVD | 2026-08-04 |
| CVE-2026-53599 | REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/s | HIGH | 7.5 | 24%ile | NVD | 2026-07-31 |
| CVE-2026-18607 | A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53 | HIGH | 7.4 | 36%ile | NVD | 2026-08-03 |
| CVE-2026-12476 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3 | HIGH | 7.2 | 47%ile | NVD | 2026-07-29 |
| CVE-2026-44103 | An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore | MEDIUM | 6.9 | 15%ile | NVD | 2026-07-30 |
| CVE-2026-16548 | The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be | MEDIUM | 5.4 | 6%ile | NVD | 2026-08-04 |
| CVE-2026-44097 | A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fi | MEDIUM | 5.3 | 16%ile | NVD | 2026-07-30 |
| CVE-2026-21662 | Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic | MEDIUM | 4.8 | 34%ile | NVD | 2026-07-31 |
| CVE-2026-63228 | An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content | LOW | 2.6 | 3%ile | NVD | 2026-07-29 |
| CVE-2026-18682 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api | LOW | 1.3 | 16%ile | NVD | 2026-08-03 |