17 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-18452 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att | CRITICAL | 10.0 | 36%ile | NVD | 2026-07-31 |
| CVE-2026-18072 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to | CRITICAL | 9.8 | 45%ile | NVD | 2026-07-29 |
| CVE-2026-16504 | Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw | CRITICAL | 9.8 | 19%ile | NVD | 2026-07-31 |
| CVE-2026-31478 | ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() | CRITICAL | 9.8 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-54363 | CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo | CRITICAL | 9.3 | 32%ile | NVD | 2026-07-30 |
| CVE-2026-41452 | Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated | CRITICAL | 9.3 | 48%ile | NVD | 2026-08-03 |
| CVE-2026-67595 | VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re | CRITICAL | 9.2 | 35%ile | NVD | 2026-07-29 |
| CVE-2026-52539 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not se | CRITICAL | 9.1 | 23%ile | NVD | 2026-07-30 |
| CVE-2026-48031 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202 | CRITICAL | 9.1 | 27%ile | NVD | 2026-08-03 |
| CVE-2025-15628 | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr | HIGH | 8.2 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-65313 | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c | HIGH | 8.1 | 7%ile | NVD | 2026-07-31 |
| CVE-2026-13463 | IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of creden | HIGH | 7.5 | 13%ile | NVD | 2026-07-28 |
| CVE-2026-40164 | jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed | HIGH | 7.5 | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-63239 | A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 bucke | MEDIUM | 5.4 | 2%ile | NVD | 2026-07-29 |
| CVE-2026-11870 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a | MEDIUM | 5.4 | 9%ile | NVD | 2026-07-30 |
| FG-IR-26-129 | Hardcoded Encryption Key Used for VPN Saved Passwords | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-107 | Hardcoded symmetric encryption key for Postgresql | UNKNOWN | — | — | Fortinet | 2026-04-14 |