| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-15413 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator- | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-59500 | CWE-287: Improper Authentication | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-27544 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-61962 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-19188 | A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vul | CRITICAL | 10.0 | NVD | 2026-08-14 |
| CVE-2026-73678 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that a | CRITICAL | 10.0 | NVD | 2026-08-14 |
| CVE-2026-72407 | In the Linux kernel, the following vulnerability has been resolved:
geneve: validate inner network offset in geneve_gro | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-72408 | In the Linux kernel, the following vulnerability has been resolved:
geneve: gate GRO hint in geneve_gro_complete() on g | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-72421 | In the Linux kernel, the following vulnerability has been resolved:
ipv4: fib: Don't ignore error route in local/main t | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74279 | In the Linux kernel, the following vulnerability has been resolved:
crypto: cavium/cpt - fix DMA cleanup using wrong lo | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74280 | In the Linux kernel, the following vulnerability has been resolved:
crypto: marvell/octeontx - fix DMA cleanup using wr | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74309 | In the Linux kernel, the following vulnerability has been resolved:
vdpa/octeon_ep: fix IRQ-to-ring mapping in interrup | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74475 | In the Linux kernel, the following vulnerability has been resolved:
vxlan: use neigh_ha_snapshot() in route_shortcircui | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74764 | Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74253 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - | CRITICAL | 10.0 | NVD | 2026-08-17 |
| CVE-2026-75874 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. | CRITICAL | 10.0 | NVD | 2026-08-18 |
| CVE-2026-73343 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | CRITICAL | 10.0 | NVD | 2026-08-18 |
| CVE-2026-61241 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 10.0 | NVD | 2026-08-18 |
| CVE-2026-70880 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | CRITICAL | 10.0 | NVD | 2026-08-18 |
| CVE-2026-70921 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 10.0 | NVD | 2026-08-18 |
| CVE-2026-76008 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox- | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-18051 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-67364 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9. | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-74803 | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbi | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-75949 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - U | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-20030 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-20315 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-20317 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-20357 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-20358 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha | CRITICAL | 10.0 | NVD | 2026-08-19 |
| CVE-2026-22306 | Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
trans | CRITICAL | 10.0 | NVD | 2026-08-19 |
| GHSA-m5w8-4gq2-6f8x | vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host ( | CRITICAL | 10.0 | GitHub | 2026-08-17 |
| CVE-2026-55107 | kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) | CRITICAL | 10.0 | GitHub | 2026-08-18 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-27211 | Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse | CRITICAL | 10.0 | Microsoft | 2026-02-10 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |