20 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-65883 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo | CRITICAL | 10.0 | 40%ile | NVD | 2026-07-29 |
| CVE-2026-14512 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization whi | CRITICAL | 9.8 | 42%ile | NVD | 2026-07-28 |
| CVE-2026-12118 | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co | CRITICAL | 9.8 | 40%ile | NVD | 2026-07-30 |
| CVE-2026-15969 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl | CRITICAL | 9.8 | 59%ile | NVD | 2026-07-30 |
| CVE-2026-15976 | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi | CRITICAL | 9.8 | 26%ile | NVD | 2026-07-30 |
| CVE-2026-68771 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthentic | CRITICAL | 9.3 | 46%ile | NVD | 2026-07-31 |
| CVE-2026-69098 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows | CRITICAL | 9.3 | — | NVD | 2026-08-04 |
| CVE-2026-54365 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe | HIGH | 8.7 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-11536 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conne | HIGH | 8.5 | 26%ile | NVD | 2026-07-30 |
| CVE-2026-58163 | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue af | HIGH | 8.3 | 48%ile | NVD | 2026-07-29 |
| CVE-2026-14974 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused | HIGH | 8.1 | 29%ile | NVD | 2026-07-28 |
| CVE-2026-18642 | Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock | HIGH | 7.8 | 3%ile | NVD | 2026-08-03 |
| CVE-2026-57859 | e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a | HIGH | 7.7 | 33%ile | NVD | 2026-07-30 |
| CVE-2026-3245 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. | HIGH | 7.7 | 15%ile | NVD | 2026-08-03 |
| CVE-2026-1360 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ | HIGH | 7.5 | 44%ile | NVD | 2026-07-30 |
| CVE-2026-12720 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data | HIGH | 7.5 | 23%ile | NVD | 2026-07-31 |
| CVE-2026-15920 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field( | MEDIUM | 5.1 | — | NVD | 2026-08-04 |
| CVE-2026-16297 | The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-impor | MEDIUM | 4.1 | 14%ile | NVD | 2026-08-03 |
| CVE-2026-16062 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co | UNKNOWN | — | 11%ile | NVD | 2026-08-02 |
| CVE-2025-15672 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa | UNKNOWN | — | 13%ile | NVD | 2026-08-03 |