← Back to feed Patch nowZero-days

📅 New This Week

Vulnerabilities published in the last 7 days (2026-07-28 → 2026-08-04). Updated every 4 hours.

2161
Total new CVEs
284
Critical
700
High
5
Actively exploited
1
Public PoC
CVE / IDTitleSeverityCVSSEPSSWhy urgentSourceDate
CVE-2026-38709TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2CRITICAL9.884%EPSS 84%ileNVD2026-07-30
CVE-2026-38711TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2CRITICAL9.884%EPSS 84%ileNVD2026-07-31
CVE-2026-38708TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2CRITICAL9.884%EPSS 84%ileNVD2026-07-31
CVE-2026-38713TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2CRITICAL9.884%EPSS 84%ileNVD2026-07-31
CVE-2026-66066Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.CRITICAL9.575%EPSS 75%ileNVD2026-07-30
CVE-2026-51785An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted reqCRITICAL9.864%EPSS 64%ileNVD2026-07-31
CVE-2026-59310VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access CRITICAL9.864%EPSS 64%ileNVD2026-07-30
CVE-2026-67208Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execCRITICAL9.362%EPSS 62%ileNVD2026-07-30
CVE-2026-14959IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to CRITICAL9.161%EPSS 61%ileNVD2026-07-28
CVE-2026-18574An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management SeCRITICAL9.359%EPSS 59%ileNVD2026-08-03
CVE-2026-15969SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylCRITICAL9.859%EPSS 59%ileNVD2026-07-30
CVE-2025-4318AWS Amplify Studio UI Component Properties Has an Input Validation IssueCRITICAL57%EPSS 57%ileGitHub2026-07-30
CVE-2026-12943IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power enCRITICAL9.857%EPSS 57%ileNVD2026-07-30
CVE-2026-41939Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final managCRITICAL9.353%EPSS 53%ileNVD2026-07-29
CVE-2026-52134An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass auCRITICAL9.853%EPSS 53%ileNVD2026-07-31
CVE-2026-39932OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/clCRITICAL9.452%EPSS 52%ileNVD2026-08-03
CVE-2026-59309VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with nCRITICAL9.851%EPSS 51%ileNVD2026-07-30
CVE-2026-15435IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to tCRITICAL9.851%EPSS 51%ileNVD2026-07-30
CVE-2026-14900The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and iCRITICAL9.849%EPSS 49%ileNVD2026-07-29
CVE-2026-48330Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL CRITICAL10.049%EPSS 49%ileNVD2026-08-03
CVE-2026-41452Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticatedCRITICAL9.348%EPSS 48%ileNVD2026-08-03
CVE-2026-28323SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2CRITICAL9.847%EPSS 47%ileNVD2026-07-30
CVE-2026-58161Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affeCRITICAL9.247%EPSS 47%ileNVD2026-07-29
CVE-2026-48323Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulCRITICAL10.046%EPSS 46%ileNVD2026-08-03
CVE-2026-68771ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticCRITICAL9.346%EPSS 46%ileNVD2026-07-31
CVE-2026-67192Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticCRITICAL9.246%EPSS 46%ileNVD2026-07-29
CVE-2026-14483The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all verCRITICAL9.846%EPSS 46%ileNVD2026-07-31
CVE-2026-18588A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgiCRITICAL9.346%EPSS 46%ileNVD2026-08-03
CVE-2026-52887NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCECRITICAL10.045%EPSS 45%ileGitHub2026-07-31
CVE-2026-18072The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to CRITICAL9.845%EPSS 45%ileNVD2026-07-29
CVE-2026-67191Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unautCRITICAL9.344%EPSS 44%ileNVD2026-07-29
CVE-2026-16610The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions upCRITICAL9.844%EPSS 44%ileNVD2026-07-30
CVE-2026-58179The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affecCRITICAL9.243%EPSS 43%ileNVD2026-07-29
CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporaryCRITICAL9.843%EPSS 43%ileNVD2026-07-30
CVE-2026-48449Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary codeCRITICAL10.042%EPSS 42%ileNVD2026-07-30
CVE-2026-14512IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization whiCRITICAL9.842%EPSS 42%ileNVD2026-07-28
CVE-2026-13423The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthCRITICAL9.842%EPSS 42%ileNVD2026-07-29
CVE-2026-59243The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attackeCRITICAL9.842%EPSS 42%ileNVD2026-07-29
CVE-2026-68502LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.CRITICAL9.842%EPSS 42%ileNVD2026-07-30
CVE-2026-33591A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security rCRITICAL10.042%EPSS 42%ileNVD2026-08-03
CVE-2026-67340ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) bCRITICAL9.342%EPSS 42%ileNVD2026-08-01
CVE-2026-14602The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, alCRITICAL9.042%EPSS 42%ileNVD2026-07-30
CVE-2026-68770sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code eCRITICAL9.341%EPSS 41%ileNVD2026-07-31
CVE-2026-14958IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to CRITICAL9.141%EPSS 41%ileNVD2026-07-28
CVE-2026-51992SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary codeCRITICAL9.141%EPSS 41%ileNVD2026-07-29
CVE-2026-58048Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.CRITICAL9.440%EPSS 40%ileNVD2026-07-31
CVE-2026-65883Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A foCRITICAL10.040%EPSS 40%ileNVD2026-07-29
CVE-2026-12118IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary coCRITICAL9.840%EPSS 40%ileNVD2026-07-30
CVE-2026-67429Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fiCRITICAL10.040%EPSS 40%ileNVD2026-07-29
CVE-2026-66803Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.CRITICAL10.040%EPSS 40%ileNVD2026-07-30
CVE-2026-63223CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not iCRITICAL9.840%EPSS 40%ileNVD2026-07-31
CVE-2025-10656The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing AuCRITICAL9.840%EPSS 40%ileNVD2026-07-29
CVE-2026-67305FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel whenCRITICAL9.440%EPSS 40%ileNVD2026-08-01
CVE-2026-15964The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reseCRITICAL9.839%EPSS 39%ileNVD2026-08-01
CVE-2026-12940IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable CRITICAL9.839%EPSS 39%ileNVD2026-07-30
CVE-2026-48326Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL CRITICAL9.939%EPSS 39%ileNVD2026-08-03
CVE-2026-48317Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('EvaCRITICAL9.639%EPSS 39%ileNVD2026-08-03
CVE-2026-48331Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privCRITICAL10.038%EPSS 38%ileNVD2026-08-03
CVE-2026-48333Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escaCRITICAL9.838%EPSS 38%ileNVD2026-08-03
CVE-2026-3141The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability checCRITICAL9.138%EPSS 38%ileNVD2026-08-01
CVE-2026-44108Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shCRITICAL9.338%EPSS 38%ileNVD2026-07-30
CVE-2026-38447osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with CRITICAL9.837%EPSS 37%ileNVD2026-08-03
CVE-2026-67594Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attacCRITICAL9.337%EPSS 37%ileNVD2026-07-30
CVE-2026-14973IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's sCRITICAL9.337%EPSS 37%ileNVD2026-07-28
CVE-2026-67308Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to executCRITICAL9.337%EPSS 37%ileNVD2026-08-01
CVE-2026-17351The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_quCRITICAL9.437%EPSS 37%ileNVD2026-07-31
CVE-2026-65321PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrarCRITICAL9.336%EPSS 36%ileNVD2026-08-02
CVE-2026-18452DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attCRITICAL10.036%EPSS 36%ileNVD2026-07-31
CVE-2026-54680Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the FluentdCRITICAL9.935%EPSS 35%ileNVD2026-07-29
CVE-2026-17566pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query inCRITICAL9.435%EPSS 35%ileNVD2026-07-31
CVE-2026-64827Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypCRITICAL9.335%EPSS 35%ileNVD2026-08-03
CVE-2026-67595VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template reCRITICAL9.235%EPSS 35%ileNVD2026-07-29
CVE-2026-17681Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 alloCRITICAL9.635%EPSS 35%ileNVD2026-07-30
CVE-2026-7849Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into CRITICAL9.334%EPSS 34%ileNVD2026-07-30
CVE-2026-17652Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.634%EPSS 34%ileNVD2026-07-30
CVE-2026-17655Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker toCRITICAL9.634%EPSS 34%ileNVD2026-07-30
CVE-2026-17656Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbCRITICAL9.634%EPSS 34%ileNVD2026-07-30
CVE-2026-53431Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previousCRITICAL9.134%EPSS 34%ileNVD2026-07-30
CVE-2026-60112AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenCRITICAL9.334%EPSS 34%ileNVD2026-07-29
CVE-2026-60113AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulneraCRITICAL9.334%EPSS 34%ileNVD2026-07-29
CVE-2026-15971SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DCRITICAL9.833%EPSS 33%ileNVD2026-07-30
CVE-2026-17687Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.633%EPSS 33%ileNVD2026-07-30
CVE-2026-17697Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbCRITICAL9.633%EPSS 33%ileNVD2026-07-30
CVE-2026-44090Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected frCRITICAL9.333%EPSS 33%ileNVD2026-07-30
CVE-2026-44101Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the CRITICAL9.333%EPSS 33%ileNVD2026-07-30
CVE-2026-8457The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and incCRITICAL9.833%EPSS 33%ileNVD2026-08-02
CVE-2026-17680Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compCRITICAL9.633%EPSS 33%ileNVD2026-07-30
CVE-2026-17651Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote aCRITICAL9.632%EPSS 32%ileNVD2026-07-30
CVE-2026-54658Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/uCRITICAL9.832%EPSS 32%ileNVD2026-07-28
CVE-2026-68503LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships defCRITICAL9.832%EPSS 32%ileNVD2026-07-30
CVE-2026-14175Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANISCRITICAL9.832%EPSS 32%ileNVD2026-08-04
CVE-2026-54363CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to foCRITICAL9.332%EPSS 32%ileNVD2026-07-30
CVE-2026-58155Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. CRITICAL9.231%EPSS 31%ileNVD2026-07-29
CVE-2026-18191VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers toCRITICAL9.331%EPSS 31%ileNVD2026-07-29
CVE-2026-67289FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controllCRITICAL9.331%EPSS 31%ileNVD2026-08-01
CVE-2026-67324GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>CRITICAL9.331%EPSS 31%ileNVD2026-08-01
CVE-2026-63221CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound vCRITICAL9.430%EPSS 30%ileNVD2026-07-31
CVE-2026-58154Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affeCRITICAL9.230%EPSS 30%ileNVD2026-07-29
CVE-2026-17669Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker CRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17670Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17671Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker whCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17672Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attackCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17673Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendeCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17676Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who hCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17682Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17684Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17688Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17691Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentiallyCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17692Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17695Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17704Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17708Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17710Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had cCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17713Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed aCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-17717Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sanCRITICAL9.630%EPSS 30%ileNVD2026-07-30
CVE-2026-0667CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, dCRITICAL9.330%EPSS 30%ileNVD2026-07-29
CVE-2026-35847An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the ChecCRITICAL9.829%EPSS 29%ileNVD2026-07-30
CVE-2026-18667A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing anCRITICAL9.329%EPSS 29%ileNVD2026-08-03
CVE-2026-65886Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unautCRITICAL9.229%EPSS 29%ileNVD2026-07-29
CVE-2026-17701Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attaCRITICAL9.628%EPSS 28%ileNVD2026-07-30
CVE-2026-67330@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.CRITICAL9.428%EPSS 28%ileNVD2026-08-01
CVE-2026-54735Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0CRITICAL10.028%EPSS 28%ileNVD2026-07-29
CVE-2026-69083SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachableCRITICAL9.928%EPSS 28%ileNVD2026-08-03
CVE-2026-48031go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202CRITICAL9.127%EPSS 27%ileNVD2026-08-03
CVE-2026-58046Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injectCRITICAL9.927%EPSS 27%ileNVD2026-07-30
CVE-2026-12946IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the iCRITICAL9.927%EPSS 27%ileNVD2026-07-30
CVE-2026-62325goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserverCRITICAL9.127%EPSS 27%ileNVD2026-07-28
CVE-2026-17758Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a CRITICAL9.627%EPSS 27%ileNVD2026-07-30
CVE-2026-66418OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackCRITICAL9.326%EPSS 26%ileNVD2026-07-30
CVE-2025-69946SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distrCRITICAL9.826%EPSS 26%ileNVD2026-07-31
CVE-2026-64863goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.CRITICAL9.126%EPSS 26%ileNVD2026-07-28
CVE-2026-14529IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 tCRITICAL9.426%EPSS 26%ileNVD2026-07-29
CVE-2026-15976SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wiCRITICAL9.826%EPSS 26%ileNVD2026-07-30
CVE-2026-8763In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also aCRITICAL9.326%EPSS 26%ileNVD2026-08-03
CVE-2026-16498The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HCRITICAL10.026%EPSS 26%ileNVD2026-07-28
CVE-2026-63227An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORCRITICAL9.925%EPSS 25%ileNVD2026-07-29
CVE-2026-12965The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befoCRITICAL9.125%EPSS 25%ileNVD2026-08-03
CVE-2026-65889Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allowCRITICAL9.225%EPSS 25%ileNVD2026-07-29
CVE-2025-65336Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.CRITICAL9.824%EPSS 24%ileNVD2026-07-30
CVE-2026-69240Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oraclCRITICAL9.824%EPSS 24%ileNVD2026-08-03
CVE-2026-54725vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1CRITICAL9.624%EPSS 24%ileNVD2026-07-31
CVE-2026-67341ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement withCRITICAL9.324%EPSS 24%ileNVD2026-08-01
CVE-2026-67342ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, PCRITICAL9.324%EPSS 24%ileNVD2026-08-01
CVE-2026-17675Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rCRITICAL9.624%EPSS 24%ileNVD2026-07-30
CVE-2026-17718Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbCRITICAL9.624%EPSS 24%ileNVD2026-07-30
CVE-2026-17721Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a CRITICAL9.624%EPSS 24%ileNVD2026-07-30
CVE-2026-17726Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially peCRITICAL9.624%EPSS 24%ileNVD2026-07-30
CVE-2026-17727Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentiallyCRITICAL9.624%EPSS 24%ileNVD2026-07-30
CVE-2026-17801Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially pCRITICAL9.624%EPSS 24%ileNVD2026-07-30
CVE-2026-17804Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.624%EPSS 24%ileNVD2026-07-30
CVE-2026-43830Full details and mitigation steps are currently restricted and will be published at a later date.CRITICAL9.824%EPSS 24%ileNVD2026-07-31
CVE-2026-17561Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and ConsCRITICAL9.824%EPSS 24%ileNVD2026-07-31
CVE-2026-18753The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatioCRITICAL9.124%EPSS 24%ileNVD2026-08-04
CVE-2026-18754The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatioCRITICAL9.124%EPSS 24%ileNVD2026-08-04
CVE-2026-28812UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate priCRITICAL9.824%EPSS 24%ileNVD2026-07-30
CVE-2026-68584SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endCRITICAL9.224%EPSS 24%ileNVD2026-08-03
CVE-2025-69948SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.CRITICAL9.823%EPSS 23%ileNVD2026-07-31
CVE-2026-14488The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in theCRITICAL9.123%EPSS 23%ileNVD2026-07-29
CVE-2026-14804Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital HuCRITICAL9.123%EPSS 23%ileNVD2026-08-04
CVE-2026-52539Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not seCRITICAL9.123%EPSS 23%ileNVD2026-07-30
CVE-2026-16300The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticateCRITICAL9.823%EPSS 23%ileNVD2026-08-03
CVE-2026-17349/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of CRITICAL9.322%EPSS 22%ileNVD2026-07-31
CVE-2026-8338A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.CRITICAL9.222%EPSS 22%ileNVD2026-07-29
CVE-2026-16326In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allCRITICAL10.022%EPSS 22%ileNVD2026-07-29
CVE-2026-18363A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.CRITICAL9.122%EPSS 22%ileNVD2026-07-30
CVE-2026-63229A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-CRITICAL9.122%EPSS 22%ileNVD2026-07-29
CVE-2026-63230A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read CRITICAL9.122%EPSS 22%ileNVD2026-07-29
CVE-2026-63232A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject throCRITICAL9.922%EPSS 22%ileNVD2026-07-29
CVE-2026-63233A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject throCRITICAL9.922%EPSS 22%ileNVD2026-07-29
CVE-2026-63234A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject throCRITICAL9.922%EPSS 22%ileNVD2026-07-29
CVE-2026-67822Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fuCRITICAL9.822%EPSS 22%ileNVD2026-07-31
CVE-2026-17709Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendeCRITICAL9.622%EPSS 22%ileNVD2026-07-30
CVE-2026-17711Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendeCRITICAL9.622%EPSS 22%ileNVD2026-07-30
CVE-2026-14446IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the adminisCRITICAL9.821%EPSS 21%ileNVD2026-07-28
CVE-2026-17803Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attCRITICAL9.621%EPSS 21%ileNVD2026-07-30
CVE-2026-67426Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verificaCRITICAL9.321%EPSS 21%ileNVD2026-07-29
CVE-2026-69084SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statementCRITICAL9.921%EPSS 21%ileNVD2026-08-03
CVE-2026-66402FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in CRITICAL9.321%EPSS 21%ileNVD2026-08-01
CVE-2026-9177A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SeCRITICAL9.421%EPSS 21%ileNVD2026-07-29
CVE-2026-13435IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implCRITICAL9.921%EPSS 21%ileNVD2026-07-30
CVE-2026-2346Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software IntegCRITICAL9.821%EPSS 21%ileNVD2026-08-03
CVE-2026-9390XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/SiCRITICAL9.120%EPSS 20%ileNVD2026-08-03
CVE-2026-47876VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with CRITICAL9.320%EPSS 20%ileNVD2026-07-30
CVE-2026-17738Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attackerCRITICAL9.620%EPSS 20%ileNVD2026-07-30
CVE-2026-17768Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attackCRITICAL9.620%EPSS 20%ileNVD2026-07-30
CVE-2026-14919The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it beCRITICAL9.820%EPSS 20%ileNVD2026-07-31
CVE-2025-69943kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and CRITICAL9.820%EPSS 20%ileNVD2026-07-29
CVE-2026-59638In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. CRITICAL9.320%EPSS 20%ileNVD2026-08-03
CVE-2026-17847Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker toCRITICAL9.620%EPSS 20%ileNVD2026-07-30
CVE-2026-17856Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who hadCRITICAL9.620%EPSS 20%ileNVD2026-07-30
CVE-2026-17865Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had CRITICAL9.620%EPSS 20%ileNVD2026-07-30
CVE-2026-52855Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{CRITICAL9.920%EPSS 20%ileNVD2026-07-31
CVE-2025-67649A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input CRITICAL9.320%EPSS 20%ileNVD2026-07-31
CVE-2026-67294FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-siCRITICAL9.319%EPSS 19%ileNVD2026-08-01
CVE-2026-16504Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passwCRITICAL9.819%EPSS 19%ileNVD2026-07-31
CVE-2026-67292FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/corCRITICAL9.318%EPSS 18%ileNVD2026-08-01
CVE-2026-59650In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affectsCRITICAL9.318%EPSS 18%ileNVD2026-08-03
CVE-2026-13596The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameteCRITICAL9.118%EPSS 18%ileNVD2026-08-01
CVE-2026-16532The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using CRITICAL9.118%EPSS 18%ileNVD2026-08-03
CVE-2025-65340kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.CRITICAL9.818%EPSS 18%ileNVD2026-07-29
CVE-2025-67403Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameteCRITICAL9.818%EPSS 18%ileNVD2026-07-29
CVE-2025-67404Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters CRITICAL9.818%EPSS 18%ileNVD2026-07-29
CVE-2025-69942kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-29
CVE-2026-4978Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision TraffiCRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69930CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69931CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69933CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69934CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69935CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via thCRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69936CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69937CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the ParameteCRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69938CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69941SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-69947SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.CRITICAL9.818%EPSS 18%ileNVD2026-07-30
CVE-2025-71401better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BCRITICAL9.318%EPSS 18%ileNVD2026-08-02
CVE-2026-17848Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a saCRITICAL9.617%EPSS 17%ileNVD2026-07-30
CVE-2026-17832Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.617%EPSS 17%ileNVD2026-07-30
CVE-2026-17834Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeCRITICAL9.617%EPSS 17%ileNVD2026-07-30
CVE-2026-17837Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerCRITICAL9.617%EPSS 17%ileNVD2026-07-30
CVE-2026-17924Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendererCRITICAL9.617%EPSS 17%ileNVD2026-07-30
CVE-2026-17940Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 alloCRITICAL9.617%EPSS 17%ileNVD2026-07-30
CVE-2026-17947Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a CRITICAL9.617%EPSS 17%ileNVD2026-07-30
CVE-2026-65885Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows auCRITICAL9.417%EPSS 17%ileNVD2026-07-29
CVE-2026-69085SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-sCRITICAL9.916%EPSS 16%ileNVD2026-08-03
CVE-2026-65884Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provideCRITICAL10.016%EPSS 16%ileNVD2026-07-29
CVE-2026-65887Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword methodCRITICAL10.016%EPSS 16%ileNVD2026-07-29
CVE-2026-65888Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actoCRITICAL10.016%EPSS 16%ileNVD2026-07-29
CVE-2026-16503Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces CRITICAL9.116%EPSS 16%ileNVD2026-07-31
CVE-2026-68587SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeaCRITICAL9.216%EPSS 16%ileNVD2026-08-03
CVE-2026-58066Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML CRITICAL9.816%EPSS 16%ileNVD2026-07-30
CVE-2026-17991Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who hCRITICAL9.616%EPSS 16%ileNVD2026-07-30
CVE-2026-44104The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without crypCRITICAL9.315%EPSS 15%ileNVD2026-07-30
CVE-2026-68586SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpointsCRITICAL9.215%EPSS 15%ileNVD2026-08-03
CVE-2026-48499Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the CodeCRITICAL9.315%EPSS 15%ileNVD2026-07-30
CVE-2026-65890Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unautheCRITICAL9.215%EPSS 15%ileNVD2026-07-29
CVE-2026-53609Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorizaCRITICAL9.115%EPSS 15%ileGitHub2026-07-31
CVE-2026-15930The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration befCRITICAL9.414%EPSS 14%ileNVD2026-08-03
CVE-2026-16534The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment andCRITICAL9.114%EPSS 14%ileNVD2026-08-03
CVE-2026-15721Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST DigCRITICAL9.814%EPSS 14%ileNVD2026-08-04
CVE-2026-17987Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attCRITICAL9.613%EPSS 13%ileNVD2026-07-30
CVE-2026-17990Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attackerCRITICAL9.613%EPSS 13%ileNVD2026-07-30
CVE-2026-18108Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncrCRITICAL9.813%EPSS 13%ileNVD2026-08-03
CVE-2026-17855Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderCRITICAL9.613%EPSS 13%ileNVD2026-07-30
CVE-2026-18248@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.contCRITICAL9.112%EPSS 12%ileNVD2026-08-03
CVE-2026-11707IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scCRITICAL9.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17749Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker whoCRITICAL9.612%EPSS 12%ileNVD2026-07-30
CVE-2026-68582Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-colCRITICAL9.311%EPSS 11%ileNVD2026-08-02
CVE-2026-6881A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated aCRITICAL9.410%EPSS 10%ileNVD2026-07-28
CVE-2026-58062In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This iCRITICAL9.310%EPSS 10%ileNVD2026-08-03
CVE-2026-18002Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacCRITICAL9.610%EPSS 10%ileNVD2026-07-30
CVE-2026-18236A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker whCRITICAL9.310%EPSS 10%ileNVD2026-07-29
CVE-2026-50736The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscribCRITICAL9.09%EPSS 9%ileNVD2026-07-28
CVE-2026-50737When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table'sCRITICAL9.09%EPSS 9%ileNVD2026-07-28
CVE-2026-46428lettre has TLS hostname verification disabled when using Boring TLS backendCRITICAL9%EPSS 9%ileGitHub2026-07-28
CVE-2026-17666Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network posCRITICAL9.19%EPSS 9%ileNVD2026-07-30
CVE-2026-18015Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentiCRITICAL9.68%EPSS 8%ileNVD2026-07-30
CVE-2026-46713Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain aCRITICAL9.27%EPSS 7%ileNVD2026-08-03
CVE-2026-9487XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, CRITICAL9.16%EPSS 6%ileNVD2026-08-03
CVE-2026-67293FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. CRITICAL9.36%EPSS 6%ileNVD2026-08-01
CVE-2026-67598Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allCRITICAL9.16%EPSS 6%ileNVD2026-08-03
CVE-2026-67336better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that adveCRITICAL9.46%EPSS 6%ileNVD2026-08-01
CVE-2026-48063Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any BaileCRITICAL9.35%EPSS 5%ileNVD2026-08-03
CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host.CRITICAL10.0NVD2026-08-04
CVE-2026-63455Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated CRITICAL9.8NVD2026-08-04
CVE-2026-63456Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated CRITICAL9.8NVD2026-08-04
USN-8615-2USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilitiesCRITICAL9.8Ubuntu2026-07-29
CVE-2026-25289Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invCRITICAL9.6NVD2026-08-04
DSA 6408-1[SECURITY] [DSA 6408-1] chromium security updateCRITICAL9.6Debian2026-08-01
CVE-2026-58073A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent anCRITICAL9.5NVD2026-08-04
CVE-2026-69254Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriCRITICAL9.4NVD2026-08-04
CVE-2026-69256Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent noCRITICAL9.4NVD2026-08-04
CVE-2026-69259Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite RecoCRITICAL9.4NVD2026-08-04
CVE-2026-61514Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthentCRITICAL9.3NVD2026-08-04
CVE-2026-61515Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that alloCRITICAL9.3NVD2026-08-04
CVE-2026-18801OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution CRITICAL9.3NVD2026-08-04
CVE-2026-69098kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows CRITICAL9.3NVD2026-08-04
CVE-2026-69110OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackerCRITICAL9.3NVD2026-08-04
CVE-2026-69255Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent inCRITICAL9.2NVD2026-08-04
CVE-2026-60007In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PCRITICAL9.1NVD2026-08-04
CVE-2026-69251Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record CRITICAL9.0NVD2026-08-04
CVE-2026-69253Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1CRITICAL9.0NVD2026-08-04
CVE-2026-58072A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can leadCRITICAL9.0NVD2026-08-04
CVE-2026-69264Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validationCRITICALGitHub2026-08-04
CVE-2026-70470Flowise: Pyodide validator Unicode homoglyph bypass leads to RCECRITICALGitHub2026-08-04
CVE-2026-34486Apache Tomcat Missing Encryption of Sensitive Data VulnerabilityHIGH99%KEV PoC EPSS 99%ileCISA-KEV2026-08-04
CVE-2026-18686A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of HIGH8.984%EPSS 84%ileNVD2026-08-04
CVE-2026-38710TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock inHIGH7.283%EPSS 83%ileNVD2026-07-31
CVE-2026-18577An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throuHIGH8.283%KEV EPSS 83%ileNVD2026-08-02
CVE-2026-18601A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fiHIGH8.982%EPSS 82%ileNVD2026-08-03
CVE-2026-18612A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/pHIGH8.980%EPSS 80%ileNVD2026-08-03
CVE-2026-18684A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the fHIGH8.979%EPSS 79%ileNVD2026-08-03
CVE-2026-18614A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file HIGH8.979%EPSS 79%ileNVD2026-08-03
CVE-2026-18602A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_confHIGH8.979%EPSS 79%ileNVD2026-08-03
CVE-2026-18615A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generateHIGH8.979%EPSS 79%ileNVD2026-08-03
CVE-2026-18616A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer ofHIGH8.979%EPSS 79%ileNVD2026-08-03
CVE-2026-18685A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of theHIGH8.979%EPSS 79%ileNVD2026-08-04
CVE-2026-18600A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.sHIGH7.478%EPSS 78%ileNVD2026-08-03
CVE-2026-67599ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackeHIGH8.678%EPSS 78%ileNVD2026-08-03
CVE-2026-32203Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service VulnerabilityHIGH7.578%EPSS 78%ileGitHub2026-07-28
CVE-2026-9198IBM Langflow Code Injection VulnerabilityHIGH78%KEV EPSS 78%ileCISA-KEV2026-08-04
CVE-2026-69096OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend afterHIGH8.774%EPSS 74%ileNVD2026-08-03
CVE-2026-18598A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_lHIGH7.474%EPSS 74%ileNVD2026-08-03
CVE-2026-5487DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloHIGH7.572%EPSS 72%ileNVD2026-07-29
CVE-2026-5491DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloHIGH7.572%EPSS 72%ileNVD2026-07-29
CVE-2026-63362An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cauHIGH8.272%EPSS 72%ileNVD2026-07-30
CVE-2026-67608Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injectiHIGH8.672%EPSS 72%ileNVD2026-08-03
CVE-2026-67325GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option pHIGH8.771%EPSS 71%ileNVD2026-08-01
CVE-2026-18599A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the fHIGH7.370%EPSS 70%ileNVD2026-08-03
CVE-2026-44098This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to pHIGH8.869%EPSS 69%ileNVD2026-07-30
CVE-2026-12357Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability HIGH7.262%EPSS 62%ileNVD2026-07-29
CVE-2026-16524A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filHIGH7.862%EPSS 62%ileNVD2026-07-30
CVE-2026-67323GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and gHIGH8.660%EPSS 60%ileNVD2026-08-01
CVE-2026-9044An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows anHIGH8.559%EPSS 59%ileNVD2026-07-31
CVE-2026-6837A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versionsHIGH7.258%EPSS 58%ileNVD2026-08-04
CVE-2026-65802External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informatHIGH7.458%EPSS 58%ileNVD2026-08-04
CVE-2026-66321Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized HIGH7.458%EPSS 58%ileNVD2026-08-04
CVE-2026-142667-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote HIGH7.057%EPSS 57%ileNVD2026-07-29
CVE-2026-16843Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatioHIGH7.256%EPSS 56%ileNVD2026-07-31
CVE-2026-58222A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory DoHIGH8.854%EPSS 54%ileNVD2026-07-30
CVE-2026-62870Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.HIGH8.854%EPSS 54%ileNVD2026-08-04
CVE-2026-15006The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnHIGH7.554%EPSS 54%ileNVD2026-08-01
CVE-2026-12935The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based bHIGH8.753%EPSS 53%ileNVD2026-07-29
CVE-2026-16526A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code executionHIGH8.852%EPSS 52%ileNVD2026-07-30
CVE-2026-59933PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 tHIGH7.549%EPSS 49%ileNVD2026-07-28
CVE-2026-59932PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 tHIGH7.549%EPSS 49%ileNVD2026-07-28
CVE-2026-16144The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in allHIGH8.149%EPSS 49%ileNVD2026-08-01
CVE-2026-18352The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, HIGH7.549%EPSS 49%ileNVD2026-08-02
CVE-2026-56671ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previHIGH7.548%EPSS 48%ileNVD2026-07-31
CVE-2026-58163Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue afHIGH8.348%EPSS 48%ileNVD2026-07-29
CVE-2026-61523WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticatedHIGH8.647%EPSS 47%ileNVD2026-08-03
CVE-2026-13339The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1HIGH7.547%EPSS 47%ileNVD2026-08-02
CVE-2026-58164Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This issHIGH8.347%EPSS 47%ileNVD2026-07-29
CVE-2026-58175Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0HIGH8.247%EPSS 47%ileNVD2026-07-29
CVE-2026-58178The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects AHIGH8.247%EPSS 47%ileNVD2026-07-29
CVE-2026-58180The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache HIGH8.247%EPSS 47%ileNVD2026-07-29
CVE-2026-16236The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5HIGH8.847%EPSS 47%ileNVD2026-07-31
CVE-2026-12476The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3HIGH7.247%EPSS 47%ileNVD2026-07-29
CVE-2026-14519IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to rHIGH7.546%EPSS 46%ileNVD2026-07-30
CVE-2026-66315Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.HIGH7.546%EPSS 46%ileNVD2026-08-04
CVE-2026-69095OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in HIGH8.746%EPSS 46%ileNVD2026-08-03
CVE-2026-18589A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file naHIGH8.946%EPSS 46%ileNVD2026-08-03
CVE-2026-65423An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to tHIGH8.746%EPSS 46%ileNVD2026-07-30
CVE-2026-58188Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects ApachHIGH8.445%EPSS 45%ileNVD2026-07-29
CVE-2026-22621Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could alHIGH8.345%EPSS 45%ileNVD2026-07-30
CVE-2026-63035A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attackHIGH7.244%EPSS 44%ileNVD2026-07-30
CVE-2026-1360The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includHIGH7.544%EPSS 44%ileNVD2026-07-30
CVE-2026-13308Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allHIGH8.144%EPSS 44%ileNVD2026-07-29
CVE-2026-58158Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects AHIGH8.243%EPSS 43%ileNVD2026-07-29
CVE-2026-61524WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature thHIGH8.643%EPSS 43%ileNVD2026-08-03
CVE-2026-41703VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment prHIGH7.643%EPSS 43%ileNVD2026-07-30
CVE-2026-16308IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remoHIGH7.543%EPSS 43%ileNVD2026-07-30
CVE-2026-18613A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of tHIGH8.943%EPSS 43%ileNVD2026-08-03
CVE-2026-14270The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerablHIGH8.843%EPSS 43%ileNVD2026-07-29
CVE-2026-58177The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This isHIGH8.343%EPSS 43%ileNVD2026-07-29
CVE-2026-56846A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memorHIGH7.543%EPSS 43%ileNVD2026-08-04
CVE-2026-58186The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issHIGH8.243%EPSS 43%ileNVD2026-07-29
CVE-2026-58182The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issuHIGH8.242%EPSS 42%ileNVD2026-07-29
CVE-2026-59931PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 tHIGH7.742%EPSS 42%ileNVD2026-07-28
CVE-2026-58159Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affectHIGH7.042%EPSS 42%ileNVD2026-07-29
CVE-2026-58183The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects ApachHIGH8.241%EPSS 41%ileNVD2026-07-29
CVE-2026-15722A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function HIGH7.541%EPSS 41%ileNVD2026-07-31
CVE-2026-11770A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleHIGH7.540%EPSS 40%ileNVD2026-07-31
CVE-2026-14522IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to eHIGH8.840%EPSS 40%ileNVD2026-07-30
CVE-2026-20479In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servHIGH7.540%EPSS 40%ileNVD2026-08-03
CVE-2026-66723MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. HIGH7.040%EPSS 40%ileNVD2026-07-29
CVE-2026-58181The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue HIGH8.240%EPSS 40%ileNVD2026-07-29
CVE-2026-67309Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX providerHIGH7.840%EPSS 40%ileNVD2026-08-01
CVE-2026-11974The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in HIGH8.639%EPSS 39%ileNVD2026-07-29
CVE-2026-58189Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. THIGH8.239%EPSS 39%ileNVD2026-07-29
CVE-2026-5057ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackeHIGH7.539%EPSS 39%ileNVD2026-07-29
CVE-2026-5490DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate priviHIGH8.839%EPSS 39%ileNVD2026-07-29
CVE-2026-48399Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in aHIGH7.539%EPSS 39%ileNVD2026-08-03
CVE-2026-58151Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This HIGH8.738%EPSS 38%ileNVD2026-07-29
CVE-2026-65324Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client HIGH8.238%EPSS 38%ileNVD2026-07-29
CVE-2026-17658Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside HIGH8.838%EPSS 38%ileNVD2026-07-30
CVE-2026-17661Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insHIGH8.838%EPSS 38%ileNVD2026-07-30
CVE-2026-50559Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization VulnerabilitiesHIGH7.538%EPSS 38%ileGitHub2026-07-29
CVE-2026-47219find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wHIGH7.538%EPSS 38%ileNVD2026-07-28
CVE-2026-58184The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition HIGH8.337%EPSS 37%ileNVD2026-07-29
CVE-2026-63222CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument usHIGH7.537%EPSS 37%ileNVD2026-07-31
CVE-2026-58185The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 tHIGH8.237%EPSS 37%ileNVD2026-07-29
CVE-2026-17665Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside HIGH8.836%EPSS 36%ileNVD2026-07-30
CVE-2026-17685Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code iHIGH8.836%EPSS 36%ileNVD2026-07-30
CVE-2026-17694Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insideHIGH8.836%EPSS 36%ileNVD2026-07-30
CVE-2026-17705Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code iHIGH8.836%EPSS 36%ileNVD2026-07-30
CVE-2026-67206Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticatHIGH8.736%EPSS 36%ileNVD2026-07-30
CVE-2026-18607A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53HIGH7.436%EPSS 36%ileNVD2026-08-03
CVE-2026-18140Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithyHIGH8.736%EPSS 36%ileNVD2026-07-30
CVE-2026-67432MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::TranHIGH7.536%EPSS 36%ileNVD2026-07-29
CVE-2026-63559An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to rHIGH8.736%EPSS 36%ileNVD2026-07-30
CVE-2026-17346The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatinHIGH8.736%EPSS 36%ileNVD2026-07-31
CVE-2026-67290FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEGHIGH8.736%EPSS 36%ileNVD2026-08-01
CVE-2026-56673ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_pathHIGH7.535%EPSS 35%ileNVD2026-07-31
CVE-2026-17544Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versionsHIGH8.135%EPSS 35%ileNVD2026-07-30
CVE-2026-18358A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system moHIGH7.535%EPSS 35%ileNVD2026-07-31
CVE-2026-5056GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attaHIGH7.835%EPSS 35%ileNVD2026-07-29
CVE-2026-54635pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.HIGH7.535%EPSS 35%ileNVD2026-07-28
CVE-2026-17881Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inHIGH8.834%EPSS 34%ileNVD2026-07-30
CVE-2026-53503Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, HIGH7.534%EPSS 34%ileNVD2026-07-31
CVE-2026-12942IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker cHIGH7.534%EPSS 34%ileNVD2026-07-30
CVE-2026-17725Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside HIGH8.834%EPSS 34%ileNVD2026-07-30
CVE-2026-21548In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execHIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-21549In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-21550In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-21551In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-21552In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-21553In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-21554In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-21555In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional HIGH7.533%EPSS 33%ileNVD2026-08-03
CVE-2026-66310External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informatHIGH7.733%EPSS 33%ileNVD2026-08-04
CVE-2026-62391The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontendHIGH8.133%EPSS 33%ileNVD2026-07-31
CVE-2026-17922Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute HIGH8.833%EPSS 33%ileNVD2026-07-30
CVE-2026-57859e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows aHIGH7.733%EPSS 33%ileNVD2026-07-30
CVE-2026-69079CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpHIGH8.732%EPSS 32%ileNVD2026-08-03
CVE-2026-53510Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDLHIGH8.132%EPSS 32%ileNVD2026-07-31
CVE-2026-12947IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive inforHIGH7.532%EPSS 32%ileNVD2026-07-30
CVE-2026-16527An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpHIGH7.332%EPSS 32%ileNVD2026-07-30
CVE-2026-15975GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 1HIGH7.532%EPSS 32%ileNVD2026-07-29
CVE-2026-47427GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete HandlerHIGH7.532%EPSS 32%ileGitHub2026-07-28
CVE-2026-54368CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allowsHIGH8.732%EPSS 32%ileNVD2026-07-30
CVE-2026-67201V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allowsHIGH7.732%EPSS 32%ileNVD2026-07-29
CVE-2026-60074Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ranHIGH7.532%EPSS 32%ileNVD2026-07-30
CVE-2026-60075Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substiHIGH7.532%EPSS 32%ileNVD2026-07-30
CVE-2026-17650Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the HIGH8.331%EPSS 31%ileNVD2026-07-30
CVE-2026-17653Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendereHIGH8.331%EPSS 31%ileNVD2026-07-30
CVE-2026-17543Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions fHIGH8.131%EPSS 31%ileNVD2026-07-30
CVE-2026-17660Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker HIGH8.331%EPSS 31%ileNVD2026-07-30
CVE-2026-62959Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started wHIGH8.231%EPSS 31%ileNVD2026-07-31
CVE-2026-55100hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenatHIGH8.731%EPSS 31%ileNVD2026-07-31
CVE-2026-61372Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. ThiHIGH7.531%EPSS 31%ileNVD2026-08-03
CVE-2026-68500Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, SyliHIGH7.531%EPSS 31%ileNVD2026-07-30
CVE-2026-67298FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_HIGH8.731%EPSS 31%ileNVD2026-08-01
CVE-2026-18192VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to eHIGH7.131%EPSS 31%ileNVD2026-07-29
CVE-2026-44092An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not valiHIGH8.831%EPSS 31%ileNVD2026-07-30
CVE-2026-17719Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insiHIGH8.831%EPSS 31%ileNVD2026-07-30
CVE-2026-15450The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path travHIGH8.130%EPSS 30%ileNVD2026-08-01
CVE-2026-69089Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $imageHIGH8.730%EPSS 30%ileNVD2026-08-03
CVE-2026-17677Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to poHIGH8.830%EPSS 30%ileNVD2026-07-30
CVE-2026-17678Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the reHIGH8.830%EPSS 30%ileNVD2026-07-30
CVE-2026-67351Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and sessioHIGH8.730%EPSS 30%ileNVD2026-07-30
CVE-2026-48448Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL HIGH8.630%EPSS 30%ileNVD2026-07-30
CVE-2026-13392The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by aHIGH7.230%EPSS 30%ileNVD2026-07-31
CVE-2026-12144The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclHIGH8.830%EPSS 30%ileNVD2026-07-29
CVE-2026-66318Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over HIGH8.130%EPSS 30%ileNVD2026-08-04
CVE-2026-6540Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URHIGH7.930%EPSS 30%ileNVD2026-07-30
CVE-2026-69152The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3HIGH7.530%EPSS 30%ileNVD2026-08-03
CVE-2026-14974IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code causedHIGH8.129%EPSS 29%ileNVD2026-07-28
CVE-2026-17751Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arHIGH8.829%EPSS 29%ileNVD2026-07-30
CVE-2026-58060In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This isHIGH8.729%EPSS 29%ileNVD2026-08-03
CVE-2026-56819Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memoryHIGH7.529%EPSS 29%ileGitHub2026-07-31
CVE-2026-66421OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to HIGH8.829%EPSS 29%ileNVD2026-07-30
CVE-2026-41695Spring Data: Unbounded property-path cache keyed by externally-supplied path stringHIGH7.529%EPSS 29%ileGitHub2026-07-31
CVE-2026-22620Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauHIGH8.629%EPSS 29%ileNVD2026-07-30
CVE-2026-55389datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.529%EPSS 29%ileNVD2026-07-28
CVE-2026-17896Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code iHIGH7.529%EPSS 29%ileNVD2026-07-30
CVE-2026-54650openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publHIGH8.629%EPSS 29%ileNVD2026-07-28
CVE-2026-55390datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsHIGH7.529%EPSS 29%ileNVD2026-07-28
CVE-2026-56845An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configurHIGH7.529%EPSS 29%ileNVD2026-08-04
CVE-2026-17657Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rHIGH8.329%EPSS 29%ileNVD2026-07-30
CVE-2026-14818A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versiHIGH7.229%EPSS 29%ileNVD2026-08-04
CVE-2026-16540The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operatiHIGH7.528%EPSS 28%ileNVD2026-08-02
CVE-2026-53502Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded pathHIGH8.728%EPSS 28%ileNVD2026-07-31
CVE-2026-69091Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only HIGH8.728%EPSS 28%ileNVD2026-08-03
CVE-2026-54593Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissionsHIGH8.128%EPSS 28%ileGitHub2026-07-28
CVE-2026-67304FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup whenHIGH8.728%EPSS 28%ileNVD2026-08-01
CVE-2026-67437OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/inteHIGH7.528%EPSS 28%ileNVD2026-07-29
CVE-2026-17712Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside aHIGH8.828%EPSS 28%ileNVD2026-07-30
CVE-2026-12932A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allHIGH7.128%EPSS 28%ileNVD2026-07-30
CVE-2026-17686Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeHIGH8.128%EPSS 28%ileNVD2026-07-30
CVE-2026-67288FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept HIGH8.728%EPSS 28%ileNVD2026-08-01
CVE-2026-41453Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated useHIGH8.728%EPSS 28%ileNVD2026-08-03
CVE-2026-69086SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,HIGH8.328%EPSS 28%ileNVD2026-08-03
CVE-2026-54653datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH8.828%EPSS 28%ileNVD2026-07-28
CVE-2026-50622Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoiHIGH8.828%EPSS 28%ileNVD2026-07-29
CVE-2026-17778Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary codeHIGH8.828%EPSS 28%ileNVD2026-07-30
CVE-2026-50782Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manageHIGH7.528%EPSS 28%ileNVD2026-07-29
CVE-2026-17663Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote atHIGH8.327%EPSS 27%ileNVD2026-07-30
CVE-2026-67215cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSONHIGH8.727%EPSS 27%ileNVD2026-07-29
CVE-2026-54638gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencryptedHIGH7.527%EPSS 27%ileNVD2026-07-28
CVE-2026-69185Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a spHIGH7.527%EPSS 27%ileNVD2026-08-03
CVE-2026-55771Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilitiesHIGH8.827%EPSS 27%ileGitHub2026-07-28
CVE-2026-67296FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validHIGH8.727%EPSS 27%ileNVD2026-08-01
CVE-2026-67297FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responsesHIGH8.727%EPSS 27%ileNVD2026-08-01
CVE-2026-18022Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, wHIGH8.827%EPSS 27%ileNVD2026-07-29
CVE-2026-54693ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4HIGH8.227%EPSS 27%ileNVD2026-07-29
CVE-2026-11771OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in theHIGH7.027%EPSS 27%ileNVD2026-07-30
CVE-2026-69149Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and otherHIGH8.627%EPSS 27%ileNVD2026-08-03
CVE-2026-17935Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary coHIGH8.826%EPSS 26%ileNVD2026-07-30
CVE-2026-67291FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragmentsHIGH8.726%EPSS 26%ileNVD2026-08-01
CVE-2026-67301FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC anHIGH8.726%EPSS 26%ileNVD2026-08-01
CVE-2026-67427Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable HIGH8.626%EPSS 26%ileNVD2026-07-29
CVE-2026-18064An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a sHIGH8.226%EPSS 26%ileNVD2026-07-30
CVE-2026-53505Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) fiHIGH7.526%EPSS 26%ileNVD2026-07-31
CVE-2026-57834Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic SerHIGH7.026%EPSS 26%ileNVD2026-07-29
CVE-2026-57510SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers tHIGH8.726%EPSS 26%ileNVD2026-07-28
CVE-2026-13395The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a HIGH8.626%EPSS 26%ileNVD2026-07-30
CVE-2026-55502Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin rHIGH7.126%EPSS 26%ileNVD2026-07-31
CVE-2026-11536IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conneHIGH8.526%EPSS 26%ileNVD2026-07-30
CVE-2026-67428Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includiHIGH8.526%EPSS 26%ileNVD2026-07-29
CVE-2026-15414The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and inclHIGH8.826%EPSS 26%ileNVD2026-08-01
CVE-2026-15280IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segmHIGH7.526%EPSS 26%ileNVD2026-07-28
CVE-2026-62663Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filtHIGH7.526%EPSS 26%ileNVD2026-07-30
CVE-2026-52856Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a HIGH7.526%EPSS 26%ileNVD2026-07-31
CVE-2026-53504Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expressioHIGH7.526%EPSS 26%ileNVD2026-07-31
CVE-2026-14893IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core HIGH7.326%EPSS 26%ileNVD2026-07-28
CVE-2026-16261The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the reqHIGH7.526%EPSS 26%ileNVD2026-08-02
CVE-2026-17868Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privHIGH8.826%EPSS 26%ileNVD2026-07-30
CVE-2026-6267GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, andHIGH8.526%EPSS 26%ileNVD2026-07-29
CVE-2026-58162The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue aHIGH8.426%EPSS 26%ileNVD2026-07-29
CVE-2026-67299FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDERHIGH8.726%EPSS 26%ileNVD2026-08-01
CVE-2026-67300FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIHIGH8.726%EPSS 26%ileNVD2026-08-01
CVE-2026-58059In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue aHIGH8.725%EPSS 25%ileNVD2026-08-03
CVE-2026-67611OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ciHIGH8.625%EPSS 25%ileNVD2026-08-03
CVE-2026-69151Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and otherHIGH7.625%EPSS 25%ileNVD2026-08-03
CVE-2026-44091An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuraHIGH8.825%EPSS 25%ileNVD2026-07-30
CVE-2026-54722DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_HIGH8.725%EPSS 25%ileNVD2026-07-30
CVE-2026-28814Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sHIGH7.525%EPSS 25%ileNVD2026-07-30
CVE-2026-39931OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature tHIGH8.625%EPSS 25%ileNVD2026-08-03
CVE-2026-10842IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 THIGH7.525%EPSS 25%ileNVD2026-07-30
CVE-2026-67610OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoiHIGH8.625%EPSS 25%ileNVD2026-08-03
CVE-2026-33930Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handlHIGH8.225%EPSS 25%ileNVD2026-07-29
CVE-2026-18733A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actorsHIGH7.525%EPSS 25%ileNVD2026-08-03
CVE-2026-16184IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafteHIGH7.025%EPSS 25%ileNVD2026-07-28
CVE-2026-11393AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote EscapingHIGH9.025%EPSS 25%ileGitHub2026-07-29
CVE-2026-68581Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and HIGH8.625%EPSS 25%ileNVD2026-08-02
CVE-2026-54078veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veHIGH8.724%EPSS 24%ileNVD2026-07-29
CVE-2026-54079veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30HIGH8.724%EPSS 24%ileNVD2026-07-29
CVE-2026-67425Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys HIGH8.624%EPSS 24%ileNVD2026-07-29
CVE-2026-68981Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encodingHIGH8.824%EPSS 24%ileNVD2026-08-03
CVE-2026-67213nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these funHIGH8.224%EPSS 24%ileNVD2026-07-29
CVE-2026-67214nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure moHIGH8.224%EPSS 24%ileNVD2026-07-29
CVE-2026-67216cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, theHIGH8.224%EPSS 24%ileNVD2026-07-29
CVE-2026-65310ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuHIGH7.524%EPSS 24%ileNVD2026-07-31
CVE-2026-17989Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside HIGH8.824%EPSS 24%ileNVD2026-07-30
CVE-2026-17752Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit HIGH8.824%EPSS 24%ileNVD2026-07-30
CVE-2026-17967Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentiallyHIGH8.824%EPSS 24%ileNVD2026-07-30
CVE-2026-58150Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This HIGH7.824%EPSS 24%ileNVD2026-07-29
CVE-2026-66745Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability tHIGH7.524%EPSS 24%ileNVD2026-07-28
CVE-2026-14319The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurriHIGH7.524%EPSS 24%ileNVD2026-07-31
CVE-2026-53599REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/sHIGH7.524%EPSS 24%ileNVD2026-07-31
CVE-2026-15397The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, andHIGH7.224%EPSS 24%ileNVD2026-07-30
CVE-2026-12733IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.HIGH7.524%EPSS 24%ileNVD2026-07-30
CVE-2026-13697undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 anHIGH7.424%EPSS 24%ileNVD2026-07-29
CVE-2026-67345MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaulHIGH8.523%EPSS 23%ileNVD2026-07-30
CVE-2026-44107A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus fHIGH8.723%EPSS 23%ileNVD2026-07-30
CVE-2026-12436GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 1HIGH8.423%EPSS 23%ileNVD2026-07-29
CVE-2026-28811Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to verHIGH7.523%EPSS 23%ileNVD2026-07-30
CVE-2026-16635The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0HIGH8.823%EPSS 23%ileNVD2026-08-01
CVE-2026-23904Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A reHIGH7.323%EPSS 23%ileNVD2026-07-29
CVE-2026-54910FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesHIGH7.723%EPSS 23%ileGitHub2026-07-31
CVE-2025-71399Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalizeHIGH8.823%EPSS 23%ileNVD2026-08-02
CVE-2026-67194Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd processHIGH7.123%EPSS 23%ileNVD2026-07-29
CVE-2026-17875Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insHIGH8.823%EPSS 23%ileNVD2026-07-30
CVE-2026-22622Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could alHIGH8.823%EPSS 23%ileNVD2026-07-30
CVE-2026-67320axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardHIGH8.323%EPSS 23%ileNVD2026-08-01
CVE-2026-9322IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 aHIGH7.523%EPSS 23%ileNVD2026-07-30
CVE-2026-12720The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data HIGH7.523%EPSS 23%ileNVD2026-07-31
CVE-2026-17887Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engHIGH7.523%EPSS 23%ileNVD2026-07-30
CVE-2026-16655The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulneHIGH7.223%EPSS 23%ileNVD2026-07-29
CVE-2026-17807Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside HIGH8.823%EPSS 23%ileNVD2026-07-30
CVE-2026-17836Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside HIGH8.823%EPSS 23%ileNVD2026-07-30
CVE-2026-17918Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insidHIGH8.823%EPSS 23%ileNVD2026-07-30
CVE-2026-69078CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functioHIGH8.822%EPSS 22%ileNVD2026-08-03
CVE-2026-17698Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local attaHIGH7.522%EPSS 22%ileNVD2026-07-30
CVE-2026-67243freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the higHIGH8.622%EPSS 22%ileNVD2026-08-04
CVE-2026-65635Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackHIGH8.322%EPSS 22%ileNVD2026-07-30
CVE-2026-50738A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aftHIGH7.722%EPSS 22%ileNVD2026-07-28
CVE-2026-50567 Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directoryHIGH7.722%EPSS 22%ileGitHub2026-07-28
CVE-2026-61536Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JHIGH7.522%EPSS 22%ileNVD2026-07-30
CVE-2026-67207Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticHIGH8.722%EPSS 22%ileNVD2026-07-30
CVE-2026-11897IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by senHIGH7.522%EPSS 22%ileNVD2026-07-30
CVE-2026-69244AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap rHIGH7.122%EPSS 22%ileNVD2026-08-03
CVE-2026-67343ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing aHIGH8.722%EPSS 22%ileNVD2026-08-01
CVE-2026-66065Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to HIGH8.422%EPSS 22%ileNVD2026-08-03
CVE-2026-46593A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of inputHIGH8.622%EPSS 22%ileNVD2026-07-31
CVE-2026-12687The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into thHIGH7.522%EPSS 22%ileNVD2026-07-30
CVE-2026-14333The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a pHIGH7.522%EPSS 22%ileNVD2026-07-31
CVE-2026-41920Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 thHIGH7.022%EPSS 22%ileNVD2026-07-29
CVE-2026-17729Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer HIGH8.822%EPSS 22%ileNVD2026-07-30
CVE-2026-67607LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thrHIGH8.222%EPSS 22%ileNVD2026-07-31
CVE-2026-9856A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes viHIGH7.122%EPSS 22%ileNVD2026-08-02
CVE-2026-62999Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-direcHIGH7.522%EPSS 22%ileNVD2026-07-31
CVE-2026-57862Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypassHIGH8.422%EPSS 22%ileNVD2026-07-30
CVE-2026-15978SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endHIGH7.522%EPSS 22%ileNVD2026-07-30
CVE-2026-54729DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_HIGH8.722%EPSS 22%ileNVD2026-07-31
CVE-2026-14869The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTHIGH8.622%EPSS 22%ileNVD2026-07-28
CVE-2026-69192ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 acHIGH7.722%EPSS 22%ileNVD2026-08-03
CVE-2026-17956Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute HIGH8.821%EPSS 21%ileNVD2026-07-30
CVE-2026-17969Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute aHIGH8.821%EPSS 21%ileNVD2026-07-30
CVE-2026-59646In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This isHIGH8.721%EPSS 21%ileNVD2026-08-03
CVE-2026-12695The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targetedHIGH8.121%EPSS 21%ileNVD2026-07-31
CVE-2026-67247A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlleHIGH7.121%EPSS 21%ileNVD2026-07-30
CVE-2026-67346Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url HIGH7.721%EPSS 21%ileNVD2026-07-30
CVE-2026-16529A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU proceHIGH7.521%EPSS 21%ileNVD2026-07-30
CVE-2026-54366CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackHIGH8.721%EPSS 21%ileNVD2026-07-30
CVE-2026-53500Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passesHIGH8.221%EPSS 21%ileNVD2026-07-31
CVE-2026-67349OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environmHIGH8.721%EPSS 21%ileNVD2026-07-30
CVE-2026-54666swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schHIGH8.321%EPSS 21%ileNVD2026-07-29
CVE-2026-66415Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated aHIGH8.421%EPSS 21%ileNVD2026-07-30
CVE-2026-48060Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances whichHIGH8.121%EPSS 21%ileNVD2026-07-28
CVE-2026-56428The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperlyHIGH8.121%EPSS 21%ileNVD2026-07-30
CVE-2026-54719goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.HIGH7.521%EPSS 21%ileNVD2026-07-28
CVE-2026-49258Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*HIGH8.820%EPSS 20%ileNVD2026-07-28
CVE-2026-16572The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in aHIGH8.620%EPSS 20%ileNVD2026-08-03
CVE-2026-17784Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised theHIGH8.820%EPSS 20%ileNVD2026-07-30
CVE-2025-67650An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatioHIGH8.620%EPSS 20%ileNVD2026-07-31
CVE-2026-15236The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-partyHIGH7.520%EPSS 20%ileNVD2026-08-02
CVE-2026-17951Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of boHIGH8.820%EPSS 20%ileNVD2026-07-30
CVE-2026-55768GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the bHIGH8.720%EPSS 20%ileNVD2026-07-30
CVE-2026-12562The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting fullHIGH8.720%EPSS 20%ileNVD2026-07-30
CVE-2026-66360The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A misHIGH8.720%EPSS 20%ileNVD2026-07-30
CVE-2026-17722Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had cHIGH8.320%EPSS 20%ileNVD2026-07-30
CVE-2026-67328@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling HIGH8.620%EPSS 20%ileNVD2026-08-01
CVE-2026-44100The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to diHIGH8.820%EPSS 20%ileNVD2026-07-30
CVE-2026-67431MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::TranHIGH8.320%EPSS 20%ileNVD2026-07-29
CVE-2026-55415datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.520%EPSS 20%ileNVD2026-07-28
CVE-2026-51953An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authenticationHIGH7.420%EPSS 20%ileNVD2026-07-31
CVE-2026-17884Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploiHIGH8.820%EPSS 20%ileNVD2026-07-30
CVE-2026-17886Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heHIGH8.820%EPSS 20%ileNVD2026-07-30
CVE-2026-7769IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM HIGH8.120%EPSS 20%ileNVD2026-07-28
CVE-2026-15992The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.HIGH8.820%EPSS 20%ileNVD2026-07-28
CVE-2026-50570Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and HIGH8.520%EPSS 20%ileGitHub2026-07-28
CVE-2026-16496The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful tHIGH8.919%EPSS 19%ileNVD2026-07-28
CVE-2026-18255A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repoHIGH7.219%EPSS 19%ileNVD2026-07-29
CVE-2026-17971Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially pHIGH8.819%EPSS 19%ileNVD2026-07-30
CVE-2026-18556Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.HIGH8.219%KEV EPSS 19%ileNVD2026-08-01
CVE-2026-54661swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templatHIGH8.319%EPSS 19%ileNVD2026-07-29
CVE-2026-54662swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-HIGH8.319%EPSS 19%ileNVD2026-07-29
CVE-2026-54664swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schHIGH8.319%EPSS 19%ileNVD2026-07-29
CVE-2026-14541An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcHIGH8.019%EPSS 19%ileNVD2026-07-31
CVE-2026-17950Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker toHIGH8.819%EPSS 19%ileNVD2026-07-30
CVE-2026-14356The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.HIGH8.819%EPSS 19%ileNVD2026-07-30
CVE-2026-62246Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datHIGH8.519%EPSS 19%ileNVD2026-07-30
CVE-2026-67337better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is eHIGH7.119%EPSS 19%ileNVD2026-08-01
CVE-2026-68579FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_HIGH8.719%EPSS 19%ileNVD2026-08-02
CVE-2026-54603OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attackeHIGH8.619%EPSS 19%ileGitHub2026-07-28
CVE-2026-18360The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in theHIGH7.619%EPSS 19%ileNVD2026-07-30
CVE-2026-18361The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in theHIGH7.619%EPSS 19%ileNVD2026-07-30
CVE-2026-17816Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker wHIGH7.519%EPSS 19%ileNVD2026-07-30
CVE-2026-17347The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that HIGH7.719%EPSS 19%ileNVD2026-07-31
CVE-2026-64816RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proceHIGH7.119%EPSS 19%ileNVD2026-07-30
CVE-2026-67322GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remHIGH8.718%EPSS 18%ileNVD2026-08-01
CVE-2026-10849The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update serHIGH8.218%EPSS 18%ileNVD2026-08-03
CVE-2026-66322Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a neHIGH7.118%EPSS 18%ileNVD2026-08-04
CVE-2026-54609QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwardingHIGH8.618%EPSS 18%ileGitHub2026-07-28
CVE-2026-14981IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 aHIGH7.518%EPSS 18%ileNVD2026-07-28
CVE-2026-15057IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrHIGH7.518%EPSS 18%ileNVD2026-07-28
CVE-2024-25039IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1HIGH7.518%EPSS 18%ileNVD2026-07-30
CVE-2026-16192IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability whHIGH7.118%EPSS 18%ileNVD2026-07-28
CVE-2026-59640In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue HIGH8.718%EPSS 18%ileNVD2026-08-03
CVE-2026-59644In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.HIGH8.718%EPSS 18%ileNVD2026-08-03
CVE-2026-59645In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. THIGH8.718%EPSS 18%ileNVD2026-08-03
CVE-2026-59649In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issuHIGH8.718%EPSS 18%ileNVD2026-08-03
CVE-2026-12852In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.HIGH8.718%EPSS 18%ileNVD2026-08-03
CVE-2026-13506In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects BHIGH8.718%EPSS 18%ileNVD2026-08-03
CVE-2026-14682In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This iHIGH8.718%EPSS 18%ileNVD2026-08-03
CVE-2026-16881A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering componentHIGH8.718%EPSS 18%ileNVD2026-08-04
CVE-2026-12721The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before usHIGH8.618%EPSS 18%ileNVD2026-07-31
CVE-2026-15206The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that wHIGH7.518%EPSS 18%ileNVD2026-08-02
CVE-2026-15241The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one oHIGH7.518%EPSS 18%ileNVD2026-08-02
CVE-2026-16285The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before strHIGH7.518%EPSS 18%ileNVD2026-08-02
CVE-2026-54737@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to HIGH7.318%EPSS 18%ileNVD2026-07-31
CVE-2026-54715GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the bHIGH7.118%EPSS 18%ileNVD2026-07-30
CVE-2026-12185In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This iHIGH7.118%EPSS 18%ileNVD2026-08-03
CVE-2026-17869Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of boundHIGH8.118%EPSS 18%ileNVD2026-07-30
CVE-2026-62354Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients witHIGH7.718%EPSS 18%ileNVD2026-08-03
CVE-2026-17723Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromisedHIGH8.318%EPSS 18%ileNVD2026-07-30
CVE-2026-44094An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configurHIGH8.317%EPSS 17%ileNVD2026-07-30
CVE-2026-14528IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.HIGH7.417%EPSS 17%ileNVD2026-07-28
CVE-2026-14838Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HIGH7.417%EPSS 17%ileNVD2026-08-04
CVE-2026-67311Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that failHIGH8.217%EPSS 17%ileNVD2026-08-01
CVE-2026-15048The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowinHIGH7.517%EPSS 17%ileNVD2026-07-31
CVE-2026-14839The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status check on a public RHIGH7.517%EPSS 17%ileNVD2026-08-01
CVE-2026-12722Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel aHIGH8.217%EPSS 17%ileNVD2026-07-30
CVE-2026-13690The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor logHIGH7.417%EPSS 17%ileNVD2026-07-29
CVE-2026-67348Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows autheHIGH8.617%EPSS 17%ileNVD2026-07-30
CVE-2026-12500The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates aHIGH7.517%EPSS 17%ileNVD2026-07-30
CVE-2026-13178The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied HIGH7.517%EPSS 17%ileNVD2026-07-30
CVE-2026-63231A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-basedHIGH8.117%EPSS 17%ileNVD2026-07-29
CVE-2026-18655Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.HIGH7.117%EPSS 17%ileNVD2026-08-03
CVE-2026-55995A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affectsHIGH8.717%EPSS 17%ileNVD2026-07-29
CVE-2026-18141A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticHIGH8.217%EPSS 17%ileNVD2026-07-31
CVE-2026-67354guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When theHIGH8.217%EPSS 17%ileNVD2026-08-01
CVE-2026-15144@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. BecHIGH7.317%EPSS 17%ileNVD2026-07-29
CVE-2026-16771In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on HIGH8.816%EPSS 16%ileNVD2026-07-28
CVE-2026-67357ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool thatHIGH7.716%EPSS 16%ileNVD2026-08-02
CVE-2026-65981Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authentiHIGH7.116%EPSS 16%ileNVD2026-07-31
CVE-2026-67436Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. InHIGH8.316%EPSS 16%ileNVD2026-07-29
CVE-2026-63550The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messHIGH7.116%EPSS 16%ileNVD2026-07-30
CVE-2026-13425The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in alHIGH7.216%EPSS 16%ileNVD2026-07-29
CVE-2026-43983Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictionsHIGH16%EPSS 16%ileGitHub2026-07-28
CVE-2026-13609The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value afHIGH8.816%EPSS 16%ileNVD2026-07-31
CVE-2026-59901Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HIGH8.716%EPSS 16%ileNVD2026-07-29
CVE-2026-67356ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowinHIGH8.716%EPSS 16%ileNVD2026-08-02
CVE-2026-33267Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 HIGH7.716%EPSS 16%ileNVD2026-07-29
CVE-2026-43829Full details and mitigation steps are currently restricted and will be published at a later date.HIGH7.516%EPSS 16%ileNVD2026-07-31
CVE-2026-43831Full details and mitigation steps are currently restricted and will be published at a later date.HIGH7.516%EPSS 16%ileNVD2026-07-31
CVE-2026-43832Full details and mitigation steps are currently restricted and will be published at a later date.HIGH7.516%EPSS 16%ileNVD2026-07-31
CVE-2026-17894Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploiHIGH8.816%EPSS 16%ileNVD2026-07-30
CVE-2026-54660swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolHIGH7.416%EPSS 16%ileNVD2026-07-29
CVE-2026-18017Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insidHIGH8.816%EPSS 16%ileNVD2026-07-30
CVE-2026-67244A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because userHIGH8.615%EPSS 15%ileNVD2026-07-30
CVE-2026-67527OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accHIGH7.615%EPSS 15%ileNVD2026-07-30
CVE-2026-18157A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit HIGH7.815%EPSS 15%ileNVD2026-07-31
CVE-2026-3245A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.HIGH7.715%EPSS 15%ileNVD2026-08-03
CVE-2026-15977SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfHIGH7.515%EPSS 15%ileNVD2026-07-30
CVE-2026-16597The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site ScrHIGH7.215%EPSS 15%ileNVD2026-07-29
CVE-2026-15052The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored CrHIGH7.215%EPSS 15%ileNVD2026-08-01
CVE-2026-18737Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQLHIGH7.115%EPSS 15%ileNVD2026-08-03
CVE-2026-18353PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim against an issuer aHIGH8.815%EPSS 15%ileNVD2026-07-30
CVE-2026-67331better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator bHIGH8.715%EPSS 15%ileNVD2026-08-01
CVE-2026-14300The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not binHIGH8.115%EPSS 15%ileNVD2026-07-29
CVE-2026-14930The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a frontHIGH7.515%EPSS 15%ileNVD2026-07-31
CVE-2026-18378A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able tHIGH7.615%EPSS 15%ileNVD2026-07-30
CVE-2026-68580FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALHIGH7.715%EPSS 15%ileNVD2026-08-02
CVE-2026-47726nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internHIGH7.115%EPSS 15%ileNVD2026-07-28
CVE-2025-71403better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute HIGH7.115%EPSS 15%ileNVD2026-08-01
CVE-2026-56672ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlHIGH8.215%EPSS 15%ileNVD2026-07-31
CVE-2026-17930Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attackHIGH7.515%EPSS 15%ileNVD2026-07-30
CVE-2026-64557In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_HIGH8.815%EPSS 15%ileNVD2026-07-29
CVE-2026-67424Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, htHIGH8.515%EPSS 15%ileNVD2026-07-29
CVE-2026-17995Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of boundsHIGH8.115%EPSS 15%ileNVD2026-07-30
CVE-2026-43910java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorHIGH8.215%EPSS 15%ileGitHub2026-07-28
CVE-2026-69088Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprintHIGH8.614%EPSS 14%ileNVD2026-08-03
CVE-2026-12703TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authentiHIGH8.014%EPSS 14%ileNVD2026-07-29
CVE-2026-16347MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessiHIGH8.714%EPSS 14%ileNVD2026-07-28
CVE-2026-16328In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing HIGH8.614%EPSS 14%ileNVD2026-07-29
CVE-2026-65943Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0HIGH7.514%EPSS 14%ileNVD2026-07-29
CVE-2025-60931An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33HIGH7.514%EPSS 14%ileNVD2026-07-29
CVE-2026-15151The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its HIGH7.514%EPSS 14%ileNVD2026-08-02
CVE-2026-44093A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user tHIGH8.514%EPSS 14%ileNVD2026-07-30
CVE-2026-44095A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to exHIGH8.514%EPSS 14%ileNVD2026-07-30
CVE-2026-44096A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, reHIGH8.514%EPSS 14%ileNVD2026-07-30
CVE-2026-44099A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitraryHIGH8.514%EPSS 14%ileNVD2026-07-30
CVE-2026-44106A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execHIGH8.514%EPSS 14%ileNVD2026-07-30
CVE-2026-67327better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerableHIGH8.714%EPSS 14%ileNVD2026-08-01
CVE-2026-67248A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because HIGH8.714%EPSS 14%ileNVD2026-07-30
CVE-2026-67355guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the DomainHIGH8.214%EPSS 14%ileNVD2026-08-01
CVE-2026-48113Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clientHIGH8.514%EPSS 14%ileNVD2026-08-03
CVE-2026-12251The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it mHIGH8.113%EPSS 13%ileNVD2026-07-31
CVE-2026-18186A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contrHIGH7.113%EPSS 13%ileNVD2026-07-30
CVE-2026-18187A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlHIGH7.113%EPSS 13%ileNVD2026-07-30
CVE-2026-18188A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlledHIGH7.113%EPSS 13%ileNVD2026-07-30
CVE-2026-14996IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.HIGH8.213%EPSS 13%ileNVD2026-07-28
CVE-2026-13463IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credenHIGH7.513%EPSS 13%ileNVD2026-07-28
CVE-2026-18012Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insHIGH8.813%EPSS 13%ileNVD2026-07-30
CVE-2026-56670ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoHIGH8.213%EPSS 13%ileNVD2026-07-31
CVE-2026-17920Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicHIGH8.813%EPSS 13%ileNVD2026-07-30
CVE-2026-15258The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feHIGH8.113%EPSS 13%ileNVD2026-07-31
CVE-2026-16539The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SHIGH8.113%EPSS 13%ileNVD2026-08-03
CVE-2026-10545IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect HIGH7.513%EPSS 13%ileNVD2026-07-30
CVE-2026-18446fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a referHIGH7.513%EPSS 13%ileNVD2026-07-31
CVE-2026-14980IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which cHIGH8.313%EPSS 13%ileNVD2026-07-30
CVE-2026-55735Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a viHIGH8.213%EPSS 13%ileNVD2026-08-01
CVE-2026-15064IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 iHIGH8.713%EPSS 13%ileNVD2026-07-28
CVE-2026-15988The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request FHIGH8.812%EPSS 12%ileNVD2026-08-01
CVE-2026-54365CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unautheHIGH8.712%EPSS 12%ileNVD2026-07-30
CVE-2026-12895SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queriesHIGH7.112%EPSS 12%ileNVD2026-07-29
CVE-2026-12945IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs througHIGH7.112%EPSS 12%ileNVD2026-07-30
CVE-2026-68578ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine pHIGH7.712%EPSS 12%ileNVD2026-08-02
CVE-2026-69087The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, thHIGH7.112%EPSS 12%ileNVD2026-08-03
CVE-2026-17786Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who cHIGH8.812%EPSS 12%ileNVD2026-07-30
CVE-2026-69246Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text andHIGH7.212%EPSS 12%ileNVD2026-08-03
CVE-2026-69082CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. ThHIGH8.812%EPSS 12%ileNVD2026-08-03
CVE-2026-58061In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue alHIGH8.712%EPSS 12%ileNVD2026-08-03
CVE-2026-13444IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatinHIGH8.112%EPSS 12%ileNVD2026-07-30
CVE-2026-53608@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script TagHIGH8.711%EPSS 11%ileGitHub2026-07-31
CVE-2026-54690datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH8.211%EPSS 11%ileNVD2026-07-28
CVE-2026-54691datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_coHIGH8.211%EPSS 11%ileNVD2026-07-28
CVE-2026-15325IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 iHIGH8.711%EPSS 11%ileNVD2026-07-28
CVE-2026-53501Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypasseHIGH8.211%EPSS 11%ileNVD2026-07-31
CVE-2026-14830The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actuallyHIGH7.511%EPSS 11%ileNVD2026-07-31
CVE-2026-15328IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 iHIGH7.411%EPSS 11%ileNVD2026-07-28
CVE-2026-67245A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlledHIGH7.011%EPSS 11%ileNVD2026-07-30
CVE-2026-14537Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0HIGH8.111%EPSS 11%ileNVD2026-07-31
CVE-2026-18718Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exeHIGH7.111%EPSS 11%ileNVD2026-08-03
CVE-2026-15240The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operHIGH7.511%EPSS 11%ileNVD2026-07-30
CVE-2026-17741Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remotHIGH7.111%EPSS 11%ileNVD2026-07-30
CVE-2026-17750Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbHIGH7.111%EPSS 11%ileNVD2026-07-30
CVE-2026-8339A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusHIGH8.710%EPSS 10%ileNVD2026-07-29
CVE-2026-20465In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proHIGH8.110%EPSS 10%ileNVD2026-08-03
CVE-2026-17979Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox HIGH7.510%EPSS 10%ileNVD2026-07-30
CVE-2025-67406https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execuHIGH7.310%EPSS 10%ileNVD2026-07-29
CVE-2025-71400better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletHIGH7.110%EPSS 10%ileNVD2026-08-02
CVE-2026-12927CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code executHIGH8.410%EPSS 10%ileNVD2026-07-29
CVE-2026-15658A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint tHIGH8.110%EPSS 10%ileNVD2026-07-30
CVE-2026-14540A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-tHIGH8.010%EPSS 10%ileNVD2026-07-31
CVE-2026-47858Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicatiHIGH8.010%EPSS 10%ileNVD2026-07-30
CVE-2026-18381A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom rHIGH7.610%EPSS 10%ileNVD2026-07-30
CVE-2026-55391datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.510%EPSS 10%ileNVD2026-07-28
CVE-2026-17744Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker toHIGH7.110%EPSS 10%ileNVD2026-07-30
CVE-2026-18092Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xmHIGH8.110%EPSS 10%ileNVD2026-08-03
CVE-2026-67329@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bHIGH7.110%EPSS 10%ileNVD2026-08-01
CVE-2026-10848The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_jHIGH7.010%EPSS 10%ileNVD2026-08-02
CVE-2026-17898Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install aHIGH7.59%EPSS 9%ileNVD2026-07-30
CVE-2026-17948Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicHIGH7.59%EPSS 9%ileNVD2026-07-30
CVE-2026-68945Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and otherHIGH8.89%EPSS 9%ileNVD2026-08-03
CVE-2026-17899Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a HIGH8.89%EPSS 9%ileNVD2026-07-30
CVE-2026-69249python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to HIGH8.79%EPSS 9%ileNVD2026-08-03
CVE-2026-18568XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when evHIGH7.59%EPSS 9%ileNVD2026-08-03
CVE-2026-67326GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attacHIGH7.39%EPSS 9%ileNVD2026-08-01
CVE-2026-48374Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability thHIGH7.89%EPSS 9%ileNVD2026-07-28
CVE-2026-14976IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the colleHIGH7.19%EPSS 9%ileNVD2026-07-28
CVE-2026-54367CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, wHIGH8.89%EPSS 9%ileNVD2026-07-30
CVE-2026-17952Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to iHIGH7.59%EPSS 9%ileNVD2026-07-30
CVE-2026-69097GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitraHIGH7.39%EPSS 9%ileNVD2026-08-03
CVE-2026-48372Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution iHIGH7.88%EPSS 8%ileNVD2026-07-28
CVE-2026-18220An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. THIGH7.88%EPSS 8%ileNVD2026-07-29
CVE-2026-47873The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network intHIGH8.08%EPSS 8%ileNVD2026-07-30
CVE-2026-16969The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in theHIGH7.68%EPSS 8%ileNVD2026-07-30
CVE-2026-47746Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulneHIGH8.98%EPSS 8%ileNVD2026-08-03
CVE-2025-9291A certification validation weakness exists in communication between affected Omada devices and cloud controllers. CertifHIGH7.78%EPSS 8%ileNVD2026-08-03
CVE-2026-10685The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invokedHIGH7.68%EPSS 8%ileNVD2026-07-31
CVE-2026-58263Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrierHIGH7.28%EPSS 8%ileGitHub2026-07-31
CVE-2026-17867Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to HIGH7.18%EPSS 8%ileNVD2026-07-30
CVE-2026-65313A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-cHIGH8.17%EPSS 7%ileNVD2026-07-31
CVE-2025-69949kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emHIGH7.37%EPSS 7%ileNVD2026-07-29
CVE-2026-69247cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 untiHIGH8.27%EPSS 7%ileNVD2026-08-03
CVE-2026-18089Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-emHIGH7.57%EPSS 7%ileNVD2026-08-03
CVE-2026-59639In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue alHIGH8.77%EPSS 7%ileNVD2026-08-03
CVE-2026-59643In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affectHIGH8.77%EPSS 7%ileNVD2026-08-03
CVE-2026-12860In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issuHIGH8.77%EPSS 7%ileNVD2026-08-03
CVE-2026-47882When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud FounHIGH8.37%EPSS 7%ileNVD2026-07-30
CVE-2026-13442IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-onlyHIGH7.17%EPSS 7%ileNVD2026-07-28
CVE-2026-15929Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmaHIGH7.17%EPSS 7%ileNVD2026-07-30
CVE-2026-65421The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length vHIGH7.17%EPSS 7%ileNVD2026-07-30
CVE-2026-66364The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 muHIGH7.17%EPSS 7%ileNVD2026-07-30
CVE-2026-66369The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-HIGH7.17%EPSS 7%ileNVD2026-07-30
CVE-2026-66720The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTyHIGH7.17%EPSS 7%ileNVD2026-07-30
CVE-2026-59651In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue alsHIGH7.17%EPSS 7%ileNVD2026-08-03
CVE-2026-59641In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issHIGH8.77%EPSS 7%ileNVD2026-08-03
CVE-2026-12803In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgHIGH8.77%EPSS 7%ileNVD2026-08-03
CVE-2026-47211Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to HIGH8.47%EPSS 7%ileNVD2026-08-03
CVE-2026-48388Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in HIGH8.67%EPSS 7%ileNVD2026-07-28
CVE-2026-12802In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also HIGH8.77%EPSS 7%ileNVD2026-08-03
CVE-2026-35226An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same nHIGH7.17%EPSS 7%ileNVD2026-07-29
CVE-2026-11980IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.HIGH7.37%EPSS 7%ileNVD2026-07-30
CVE-2026-48395Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contexHIGH8.67%EPSS 7%ileNVD2026-07-28
CVE-2025-67405Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the paramHIGH7.37%EPSS 7%ileNVD2026-07-29
CVE-2025-67407Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parametersHIGH7.37%EPSS 7%ileNVD2026-07-29
CVE-2025-67408Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter HIGH7.37%EPSS 7%ileNVD2026-07-29
CVE-2025-69945kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.HIGH7.37%EPSS 7%ileNVD2026-07-29
CVE-2026-17811Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perfHIGH7.16%EPSS 6%ileNVD2026-07-30
CVE-2026-67307Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in invenHIGH7.06%EPSS 6%ileNVD2026-08-01
CVE-2026-10079A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACHIGH8.56%EPSS 6%ileNVD2026-07-31
CVE-2026-17916Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had coHIGH7.56%EPSS 6%ileNVD2026-07-30
CVE-2026-66420MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticatedHIGH8.66%EPSS 6%ileNVD2026-07-30
CVE-2026-66416Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform statHIGH8.66%EPSS 6%ileNVD2026-07-30
CVE-2026-5846The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certHIGH7.66%EPSS 6%ileNVD2026-07-30
CVE-2026-48396Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the contHIGH8.66%EPSS 6%ileNVD2026-07-28
CVE-2026-50641Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed inHIGH7.16%EPSS 6%ileNVD2026-07-29
CVE-2026-59642In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issueHIGH8.75%EPSS 5%ileNVD2026-08-03
CVE-2026-12816In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue alsoHIGH8.75%EPSS 5%ileNVD2026-08-03
CVE-2026-12817In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also afHIGH8.75%EPSS 5%ileNVD2026-08-03
CVE-2026-16463A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A mHIGH7.85%EPSS 5%ileNVD2026-07-29
CVE-2026-17888Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker toHIGH7.15%EPSS 5%ileNVD2026-07-30
CVE-2026-48391Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contexHIGH8.25%EPSS 5%ileNVD2026-07-28
CVE-2026-18536Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:HIGH7.55%EPSS 5%ileNVD2026-08-01
CVE-2026-65309ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible formHIGH7.55%EPSS 5%ileNVD2026-07-31
CVE-2026-13268G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows HIGH7.85%EPSS 5%ileNVD2026-07-29
CVE-2026-54656datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.85%EPSS 5%ileNVD2026-07-28
CVE-2026-17699Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandboHIGH8.65%EPSS 5%ileNVD2026-07-30
CVE-2026-54545@wakaru/cli arbitrary file write during bundle unpackHIGH7.15%EPSS 5%ileGitHub2026-07-28
CVE-2026-28813Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommendeHIGH8.84%EPSS 4%ileNVD2026-07-30
CVE-2026-48392Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context HIGH7.84%EPSS 4%ileNVD2026-07-28
CVE-2026-48393Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context HIGH7.84%EPSS 4%ileNVD2026-07-28
CVE-2026-48394Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context HIGH7.84%EPSS 4%ileNVD2026-07-28
CVE-2026-54574proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain taHIGH8.24%EPSS 4%ileNVD2026-07-29
CVE-2026-54655datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type vHIGH7.84%EPSS 4%ileNVD2026-07-28
CVE-2026-67344ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPHIGH8.54%EPSS 4%ileNVD2026-08-01
CVE-2026-48390Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker coHIGH8.24%EPSS 4%ileNVD2026-07-28
CVE-2026-54621datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptioHIGH7.84%EPSS 4%ileNVD2026-07-28
CVE-2026-54654datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-temHIGH7.84%EPSS 4%ileNVD2026-07-28
CVE-2026-67609Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatioHIGH8.54%EPSS 4%ileNVD2026-08-03
CVE-2026-17774Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in HIGH7.54%EPSS 4%ileNVD2026-07-30
CVE-2026-58043A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. HIGH7.54%EPSS 4%ileNVD2026-07-30
CVE-2026-56821Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HIGH7.44%EPSS 4%ileNVD2026-07-29
CVE-2026-15228Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clustHIGH7.14%EPSS 4%ileNVD2026-07-29
CVE-2026-16543Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation prHIGH7.14%EPSS 4%ileNVD2026-07-29
CVE-2026-34641Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the coHIGH7.84%EPSS 4%ileNVD2026-07-31
CVE-2026-17716Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege eHIGH8.44%EPSS 4%ileNVD2026-07-30
CVE-2026-50986PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validHIGH8.83%EPSS 3%ileNVD2026-07-31
CVE-2026-5219Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows CHIGH8.33%EPSS 3%ileNVD2026-07-30
CVE-2026-18642Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock HIGH7.83%EPSS 3%ileNVD2026-08-03
CVE-2026-4793An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or wrHIGH7.33%EPSS 3%ileNVD2026-08-03
CVE-2026-54605OAuth: Cross-origin token-request redirects can expose signed request metadataHIGH7.23%EPSS 3%ileGitHub2026-07-28
CVE-2026-65944Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0HIGH8.83%EPSS 3%ileNVD2026-07-29
CVE-2026-54639Style Dictionary - Prototype Pollution in convertTokenData utility functionHIGH8.83%EPSS 3%ileGitHub2026-07-28
CVE-2026-59247Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute foHIGH7.63%EPSS 3%ileNVD2026-07-29
CVE-2026-42169A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fHIGH7.33%EPSS 3%ileNVD2026-08-04
CVE-2026-18755A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search diHIGH7.33%EPSS 3%ileNVD2026-08-04
CVE-2026-13584Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi EleHIGH7.13%EPSS 3%ileNVD2026-07-30
CVE-2026-65947Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2HIGH7.33%EPSS 3%ileNVD2026-07-29
CVE-2026-20483In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local esHIGH7.72%EPSS 2%ileNVD2026-08-03
CVE-2026-10535IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.HIGH8.42%EPSS 2%ileNVD2026-07-30
CVE-2026-54727proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink HIGH8.22%EPSS 2%ileNVD2026-07-29
CVE-2026-64556In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exeHIGH7.82%EPSS 2%ileNVD2026-07-29
CVE-2026-64560In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader HIGH7.82%EPSS 2%ileNVD2026-07-29
CVE-2026-64558In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler impleHIGH7.82%EPSS 2%ileNVD2026-07-29
CVE-2026-64559In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl HIGH7.82%EPSS 2%ileNVD2026-07-29
CVE-2026-14354CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorizeHIGH8.72%EPSS 2%ileNVD2026-07-29
CVE-2026-18759The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communicationHIGH8.52%EPSS 2%ileNVD2026-08-04
CVE-2026-9593A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the HIGH8.42%EPSS 2%ileNVD2026-08-03
CVE-2026-17654Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege esHIGH7.82%EPSS 2%ileNVD2026-07-30
CVE-2026-41447FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitHIGH8.52%EPSS 2%ileNVD2026-08-03
CVE-2026-18107A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insidHIGH7.82%EPSS 2%ileNVD2026-07-28
CVE-2026-17862Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-leveHIGH7.82%EPSS 2%ileNVD2026-07-30
CVE-2026-59913Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for CritiHIGH7.82%EPSS 2%ileNVD2026-08-03
CVE-2026-56822Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HIGH7.42%EPSS 2%ileNVD2026-07-29
CVE-2026-40272Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kHIGH7.02%EPSS 2%ileNVD2026-07-29
CVE-2026-69093Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs peHIGH7.12%EPSS 2%ileNVD2026-08-03
CVE-2026-18606A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionHIGH7.12%EPSS 2%ileNVD2026-08-03
CVE-2026-17861Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker tHIGH7.81%EPSS 1%ileNVD2026-07-30
CVE-2026-17863Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to pHIGH7.81%EPSS 1%ileNVD2026-07-30
CVE-2025-15628Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contrHIGH8.21%EPSS 1%ileNVD2026-08-03
CVE-2026-17877Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to HIGH8.41%EPSS 1%ileNVD2026-07-30
CVE-2026-17864Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perfoHIGH7.81%EPSS 1%ileNVD2026-07-30
CVE-2026-59912Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulneraHIGH7.81%EPSS 1%ileNVD2026-08-03
CVE-2026-11885IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefulHIGH8.41%EPSS 1%ileNVD2026-07-30
CVE-2026-14234The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowinHIGH7.11%EPSS 1%ileNVD2026-07-29
CVE-2026-44944An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socHIGH8.51%EPSS 1%ileNVD2026-07-29
CVE-2026-6102MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows localHIGH7.80%EPSS 0%ileNVD2026-07-29
CVE-2026-16727Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allowsHIGH7.30%EPSS 0%ileNVD2026-07-30
CVE-2026-8497Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0HIGH7.40%EPSS 0%ileNVD2026-07-29
CVE-2026-17993Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalatHIGH7.00%EPSS 0%ileNVD2026-07-30
CVE-2026-58080In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. OnHIGH8.8NVD2026-08-04
CVE-2026-17070Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained bHIGH8.8NVD2026-08-04
CVE-2026-18650Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYHIGH8.8NVD2026-08-04
CVE-2026-69258Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticHIGH8.8NVD2026-08-04
CVE-2026-10050In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. ThHIGH8.7NVD2026-08-04
CVE-2026-62927In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handHIGH8.7NVD2026-08-04
CVE-2026-63252In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chHIGH8.7NVD2026-08-04
CVE-2026-67195Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrHIGH8.7NVD2026-08-04
CVE-2026-67198Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthHIGH8.7NVD2026-08-04
CVE-2026-67200Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitraryHIGH8.7NVD2026-08-04
CVE-2026-68494The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypHIGH8.7NVD2026-08-04
CVE-2026-69100LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability iHIGH8.7NVD2026-08-04
CVE-2026-15307An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parseHIGH8.7NVD2026-08-04
CVE-2026-58067A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause HIGH8.7NVD2026-08-04
CVE-2026-58075A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveragHIGH8.7NVD2026-08-04
CVE-2026-69263Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation HIGH8.7NVD2026-08-04
CVE-2026-58074A vulnerability allowing a high-privileged user to execute arbitrary code on the server.HIGH8.6NVD2026-08-04
CVE-2026-12075Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.loaHIGH8.6GitHub2026-07-31
CVE-2026-69250Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 tokeHIGH8.5NVD2026-08-04
CVE-2026-64631A vulnerability allowing a low-privileged user to inject SQL and extract database contents.HIGH8.5NVD2026-08-04
CVE-2026-64634A vulnerability allowing local privilege escalation to the Reporter service context.HIGH8.4NVD2026-08-04
CVE-2026-58071A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance AHIGH8.2NVD2026-08-04
CVE-2026-24079Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.HIGH8.1NVD2026-08-04
GHSA-3f7w-8rr8-f37fGitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overHIGH8.1GitHub2026-08-03
DSA 6406-1[SECURITY] [DSA 6406-1] php8.4 security updateHIGH8.1Debian2026-07-31
CVE-2026-10709A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerabHIGH7.8NVD2026-08-04
CVE-2026-10710A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerabHIGH7.8NVD2026-08-04
CVE-2026-21366Memory corruption while processing a packet with a size close to the maximum allowed value.HIGH7.8NVD2026-08-04
CVE-2026-24080Memory Corruption when handling malformed request parameters in the fingerprint TA.HIGH7.8NVD2026-08-04
CVE-2026-24083Memory Corruption while processing IOCTL device driver requests with invalid arguments.HIGH7.8NVD2026-08-04
DSA 6405-1[SECURITY] [DSA 6405-1] linux security updateHIGH7.8Debian2026-07-31
FG-IR-26-144Linux Kernel vulnerability Dirty FragHIGH7.8Fortinet2026-06-03
CVE-2026-25292Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configurationHIGH7.6NVD2026-08-04
CVE-2026-69257Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP HIGH7.6NVD2026-08-04
CVE-2026-24084Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capHIGH7.5NVD2026-08-04
CVE-2026-56848A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mHIGH7.5NVD2026-08-04
CVE-2026-12061Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexHIGH7.5GitHub2026-07-31
CVE-2026-12072Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pHIGH7.5GitHub2026-07-31
CVE-2026-12074Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, HIGH7.5GitHub2026-07-31
CVE-2026-54632SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)HIGH7.5GitHub2026-07-28
GHSA-p7w7-4929-vpj5`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool InvocationHIGH7.5GitHub2026-07-31
DSA 6404-1[SECURITY] [DSA 6404-1] expat security updateHIGH7.5Debian2026-07-30
CVE-2026-25288Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.HIGH7.4NVD2026-08-04
CVE-2026-18787A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fiHIGH7.4NVD2026-08-04
CVE-2026-0392eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is HIGH7.30%EPSS 0%ileNVD2026-08-03
CVE-2026-69252Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/filHIGH7.2NVD2026-08-04
CVE-2026-18806External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-imHIGH7.1NVD2026-08-04
CVE-2026-11368The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channHIGH7.1NVD2026-08-04
CVE-2026-67199Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loopHIGH7.1NVD2026-08-04
CVE-2026-67618marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operatHIGH7.1NVD2026-08-04
CVE-2026-15314Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTHIGH7.1NVD2026-08-04
CVE-2026-69262Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1HIGH7.1NVD2026-08-04
USN-8623-1USN-8623-1: Linux kernel (NVIDIA) vulnerabilitiesHIGH7.1Ubuntu2026-07-29
USN-8622-1USN-8622-1: Linux kernel (NVIDIA) vulnerabilitiesHIGH7.1Ubuntu2026-07-29
CVE-2026-70472Flowise: Cross-workspace credential IDOR in openai-assistants-vector-storeHIGHGitHub2026-08-04
CVE-2026-70471Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables DisclosureHIGHGitHub2026-08-04
CVE-2026-42170CVE-2026-42170HIGHRed Hat2026-08-04
GHSA-xvg2-cgv6-6h7vnetfoil: Incorrect block responses could lead to localhost trafficHIGHGitHub2026-07-29
GHSA-88pr-878c-24wfFlowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys HIGHGitHub2026-08-04
CVE-2026-18641A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected byMEDIUM5.575%EPSS 75%ileNVD2026-08-03
CVE-2026-5492DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloMEDIUM6.573%EPSS 73%ileNVD2026-07-29
CVE-2026-5489DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discloMEDIUM5.367%EPSS 67%ileNVD2026-07-29
CVE-2026-18587A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the componentMEDIUM6.867%EPSS 67%ileNVD2026-08-03
CVE-2026-58218A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY MEDIUM5.362%EPSS 62%ileNVD2026-07-30
CVE-2026-67438OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/inteMEDIUM6.659%EPSS 59%ileNVD2026-07-29
CVE-2026-66312Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.MEDIUM6.559%EPSS 59%ileNVD2026-08-04
CVE-2026-17614A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getCoMEDIUM4.455%EPSS 55%ileNVD2026-08-04
CVE-2026-54753`nx graph` dev server permissive CORS policyMEDIUM5.954%EPSS 54%ileGitHub2026-07-31
CVE-2026-20316A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthentiMEDIUM5.353%KEV EPSS 53%ileNVD2026-07-29
CVE-2026-15601The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (ZiMEDIUM4.952%EPSS 52%ileNVD2026-08-01
CVE-2026-66314Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to MEDIUM6.550%EPSS 50%ileNVD2026-08-04
CVE-2026-17605The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File InclMEDIUM6.650%EPSS 50%ileNVD2026-08-01
CVE-2026-8793PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticatMEDIUM6.949%EPSS 49%ileNVD2026-08-03
CVE-2026-8794PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attaMEDIUM6.949%EPSS 49%ileNVD2026-08-03
CVE-2026-66326Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.MEDIUM6.548%EPSS 48%ileNVD2026-08-04
CVE-2026-9335A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to impropMEDIUM6.547%EPSS 47%ileNVD2026-08-02
CVE-2026-56722Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypMEDIUM6.343%EPSS 43%ileNVD2026-07-28
CVE-2026-58160Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0MEDIUM6.343%EPSS 43%ileNVD2026-07-29
CVE-2026-8508An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions througMEDIUM6.543%EPSS 43%ileNVD2026-08-04
CVE-2026-18646A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /systemMEDIUM5.542%EPSS 42%ileNVD2026-08-03
CVE-2026-55497Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image MEDIUM6.542%EPSS 42%ileNVD2026-07-31
CVE-2026-59952Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper whMEDIUM6.942%EPSS 42%ileNVD2026-07-30
CVE-2026-18245Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticMEDIUM6.441%EPSS 41%ileNVD2026-07-30
CVE-2026-58216An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) serviMEDIUM5.341%EPSS 41%ileNVD2026-07-30
CVE-2026-59941Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNMEDIUM6.340%EPSS 40%ileNVD2026-07-28
CVE-2026-44615Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wiMEDIUM6.540%EPSS 40%ileNVD2026-07-31
CVE-2026-18582A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function ReMEDIUM5.540%EPSS 40%ileNVD2026-08-03
CVE-2026-18583A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccMEDIUM5.540%EPSS 40%ileNVD2026-08-03
CVE-2026-58153Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HMEDIUM6.338%EPSS 38%ileNVD2026-07-29
CVE-2026-58157Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This iMEDIUM6.937%EPSS 37%ileNVD2026-07-29
CVE-2026-58187The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of servMEDIUM6.337%EPSS 37%ileNVD2026-07-29
CVE-2026-65100Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, soMEDIUM6.337%EPSS 37%ileNVD2026-07-29
CVE-2026-58047HTTP Smuggling in cPanel allows potential leak of credentials.MEDIUM5.636%EPSS 36%ileNVD2026-07-31
CVE-2026-14194Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and InforMEDIUM6.536%EPSS 36%ileNVD2026-08-04
CVE-2026-46678Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, whenMEDIUM6.836%EPSS 36%ileNVD2026-07-29
CVE-2026-63563Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication MEDIUM6.935%EPSS 35%ileNVD2026-08-03
CVE-2026-53551free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication ServerMEDIUM6.935%EPSS 35%ileNVD2026-07-31
CVE-2026-65804Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attaMEDIUM6.135%EPSS 35%ileNVD2026-08-04
CVE-2026-34495Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FMEDIUM4.834%EPSS 34%ileNVD2026-07-31
CVE-2026-34497Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM SysteMEDIUM4.834%EPSS 34%ileNVD2026-07-31
CVE-2026-66311Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.MEDIUM6.234%EPSS 34%ileNVD2026-08-04
CVE-2026-10700IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API thMEDIUM6.534%EPSS 34%ileNVD2026-07-30
CVE-2026-21662Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using MalicMEDIUM4.834%EPSS 34%ileNVD2026-07-31
CVE-2026-58042A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A RecMEDIUM5.933%EPSS 33%ileNVD2026-08-04
CVE-2026-66325Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofinMEDIUM6.133%EPSS 33%ileNVD2026-08-04
CVE-2025-71404better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the MEDIUM5.133%EPSS 33%ileNVD2026-08-01
CVE-2026-12996A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potenMEDIUM6.032%EPSS 32%ileNVD2026-07-30
CVE-2026-18610A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspMEDIUM5.532%EPSS 32%ileNVD2026-08-03
CVE-2026-59942Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack vMEDIUM6.332%EPSS 32%ileNVD2026-07-28
CVE-2026-17674Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass contentMEDIUM6.532%EPSS 32%ileNVD2026-07-30
CVE-2026-54345GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthentiMEDIUM32%EPSS 32%ileGitHub2026-07-28
CVE-2026-17667Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data vMEDIUM6.531%EPSS 31%ileNVD2026-07-30
CVE-2026-17668Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data vMEDIUM6.531%EPSS 31%ileNVD2026-07-30
CVE-2026-17707Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromiMEDIUM6.531%EPSS 31%ileNVD2026-07-30
CVE-2026-17714Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensiMEDIUM6.531%EPSS 31%ileNVD2026-07-30
CVE-2026-18738Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attMEDIUM5.131%EPSS 31%ileNVD2026-08-03
CVE-2026-17567The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulneMEDIUM5.330%EPSS 30%ileNVD2026-07-31
CVE-2026-53573GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafMEDIUM4.830%EPSS 30%ileNVD2026-07-31
CVE-2026-55495Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WMEDIUM4.330%EPSS 30%ileNVD2026-07-31
CVE-2026-54885Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuMEDIUM6.930%EPSS 30%ileNVD2026-07-30
CVE-2026-54909pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformedMEDIUM5.330%EPSS 30%ileNVD2026-07-31
CVE-2026-54659Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18MEDIUM6.930%EPSS 30%ileNVD2026-07-28
CVE-2026-17664Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker wMEDIUM6.529%EPSS 29%ileNVD2026-07-30
CVE-2026-54332GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 1MEDIUM29%EPSS 29%ileGitHub2026-07-28
CVE-2026-13117An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trMEDIUM6.029%EPSS 29%ileNVD2026-07-30
CVE-2026-67314axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/aMEDIUM6.329%EPSS 29%ileNVD2026-08-01
CVE-2026-55496Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActiMEDIUM4.329%EPSS 29%ileNVD2026-07-31
CVE-2026-44617LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when construMEDIUM6.529%EPSS 29%ileNVD2026-07-30
CVE-2026-67317axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch aMEDIUM6.329%EPSS 29%ileNVD2026-08-01
CVE-2026-69153PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract MEDIUM6.328%EPSS 28%ileNVD2026-08-03
CVE-2026-18362The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-foMEDIUM5.928%EPSS 28%ileNVD2026-07-30
CVE-2026-16531An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a MEDIUM5.328%EPSS 28%ileNVD2026-07-30
CVE-2026-62416Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requirMEDIUM6.928%EPSS 28%ileNVD2026-08-03
CVE-2026-67318axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request boMEDIUM6.328%EPSS 28%ileNVD2026-08-01
CVE-2026-15344The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all verMEDIUM4.928%EPSS 28%ileNVD2026-07-29
CVE-2026-18647A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue MEDIUM5.528%EPSS 28%ileNVD2026-08-03
CVE-2026-20464In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatioMEDIUM6.528%EPSS 28%ileNVD2026-08-03
CVE-2026-68979Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorizationMEDIUM5.928%EPSS 28%ileNVD2026-08-03
CVE-2026-17679Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attMEDIUM6.528%EPSS 28%ileNVD2026-07-30
CVE-2026-17683Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentMEDIUM6.528%EPSS 28%ileNVD2026-07-30
CVE-2026-46594A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicioMEDIUM5.128%EPSS 28%ileNVD2026-07-31
CVE-2026-13346pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary loMEDIUM5.627%EPSS 27%ileNVD2026-07-29
CVE-2026-13307Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabilitMEDIUM6.827%EPSS 27%ileNVD2026-07-29
CVE-2026-44616LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escapMEDIUM6.527%EPSS 27%ileNVD2026-07-30
CVE-2026-45376Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3MEDIUM5.527%EPSS 27%ileNVD2026-07-31
CVE-2026-59652In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.MEDIUM6.927%EPSS 27%ileNVD2026-08-03
CVE-2026-68501Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, SyliMEDIUM6.527%EPSS 27%ileNVD2026-07-30
CVE-2026-5114The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and MEDIUM4.927%EPSS 27%ileNVD2026-07-28
CVE-2026-67312axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (MEDIUM6.326%EPSS 26%ileNVD2026-08-01
CVE-2026-67313axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names wiMEDIUM6.326%EPSS 26%ileNVD2026-08-01
CVE-2026-18059The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information ExpMEDIUM5.326%EPSS 26%ileNVD2026-08-01
CVE-2026-55499Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscriMEDIUM4.326%EPSS 26%ileNVD2026-07-31
CVE-2026-44943An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remMEDIUM6.926%EPSS 26%ileNVD2026-07-29
CVE-2026-14202Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human MEDIUM5.326%EPSS 26%ileNVD2026-08-04
CVE-2026-58063In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue alMEDIUM5.325%EPSS 25%ileNVD2026-08-03
CVE-2026-13723A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrarMEDIUM6.525%EPSS 25%ileNVD2026-07-29
CVE-2026-17759Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensMEDIUM6.525%EPSS 25%ileNVD2026-07-30
CVE-2026-14341GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1MEDIUM4.925%EPSS 25%ileNVD2026-07-29
CVE-2026-58152Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects ApaMEDIUM6.925%EPSS 25%ileNVD2026-07-29
CVE-2026-11995The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress MEDIUM5.325%EPSS 25%ileNVD2026-08-01
CVE-2026-54908Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messageMEDIUM24%EPSS 24%ileGitHub2026-07-31
CVE-2026-17703Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attackMEDIUM6.524%EPSS 24%ileNVD2026-07-30
CVE-2026-16971The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force aMEDIUM5.924%EPSS 24%ileNVD2026-07-30
CVE-2026-14318The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HMEDIUM6.824%EPSS 24%ileNVD2026-07-30
CVE-2026-67302FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redireMEDIUM5.324%EPSS 24%ileNVD2026-08-01
CVE-2026-66756Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 MEDIUM6.924%EPSS 24%ileNVD2026-07-30
CVE-2026-67246A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controMEDIUM6.924%EPSS 24%ileNVD2026-07-30
CVE-2026-17580The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, ElemMEDIUM6.524%EPSS 24%ileNVD2026-08-01
CVE-2026-18207A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group mMEDIUM6.524%EPSS 24%ileNVD2026-07-29
CVE-2026-17689Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data vMEDIUM4.323%EPSS 23%ileNVD2026-07-30
CVE-2026-66296Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sitMEDIUM5.123%EPSS 23%ileNVD2026-08-03
CVE-2026-59943Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted conMEDIUM6.323%EPSS 23%ileNVD2026-07-28
CVE-2026-66064goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handlerMEDIUM5.323%EPSS 23%ileNVD2026-07-28
CVE-2026-13458The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML AMEDIUM6.423%EPSS 23%ileNVD2026-08-01
CVE-2026-62323Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the seMEDIUM6.323%EPSS 23%ileNVD2026-07-31
CVE-2026-38444osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value isMEDIUM6.123%EPSS 23%ileNVD2026-08-03
CVE-2026-59232Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding MEDIUM5.323%EPSS 23%ileNVD2026-07-31
CVE-2026-54080veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-serviceMEDIUM6.922%EPSS 22%ileNVD2026-07-29
CVE-2026-54081veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-serviceMEDIUM6.922%EPSS 22%ileNVD2026-07-29
CVE-2026-59881AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client acMEDIUM6.922%EPSS 22%ileNVD2026-07-30
CVE-2026-65841Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTaMEDIUM5.322%EPSS 22%ileNVD2026-07-31
CVE-2026-50642diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The applicationMEDIUM4.822%EPSS 22%ileNVD2026-07-29
CVE-2026-17796Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain poMEDIUM6.522%EPSS 22%ileNVD2026-07-30
CVE-2026-17800Inappropriate implementation in MediaRecording in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtaMEDIUM6.522%EPSS 22%ileNVD2026-07-30
CVE-2026-16530A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in tMEDIUM6.522%EPSS 22%ileNVD2026-07-30
CVE-2026-18585A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 aMEDIUM5.322%EPSS 22%ileNVD2026-08-03
CVE-2026-17706Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote MEDIUM4.322%EPSS 22%ileNVD2026-07-30
CVE-2026-15153The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative MEDIUM6.822%EPSS 22%ileNVD2026-07-30
CVE-2026-18201Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovMEDIUM5.522%EPSS 22%ileNVD2026-07-29
CVE-2026-18437The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access MEDIUM5.322%EPSS 22%ileNVD2026-07-31
CVE-2026-16751Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authMEDIUM6.522%EPSS 22%ileNVD2026-07-29
CVE-2026-10782The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includinMEDIUM4.322%EPSS 22%ileNVD2026-08-01
CVE-2026-18394Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obMEDIUM6.922%EPSS 22%ileNVD2026-07-31
CVE-2026-13389The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST MEDIUM6.522%EPSS 22%ileNVD2026-08-02
CVE-2026-11973The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in aMEDIUM4.922%EPSS 22%ileNVD2026-07-29
CVE-2026-13586In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also aMEDIUM5.322%EPSS 22%ileNVD2026-08-03
CVE-2026-58139The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SMEDIUM6.022%EPSS 22%ileNVD2026-08-03
CVE-2026-11904IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify IdentMEDIUM5.322%EPSS 22%ileNVD2026-07-30
CVE-2026-48025nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internMEDIUM6.921%EPSS 21%ileNVD2026-07-28
CVE-2026-59899Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, MEDIUM6.921%EPSS 21%ileNVD2026-07-29
CVE-2026-59900Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, MEDIUM6.921%EPSS 21%ileNVD2026-07-29
CVE-2026-67430MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::TranMEDIUM5.321%EPSS 21%ileNVD2026-07-29
CVE-2026-67315axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldByMEDIUM6.921%EPSS 21%ileNVD2026-08-01
CVE-2026-67321axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js wMEDIUM6.921%EPSS 21%ileNVD2026-08-01
CVE-2026-69075FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-cMEDIUM6.921%EPSS 21%ileNVD2026-08-03
CVE-2026-18654Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI vMEDIUM6.921%EPSS 21%ileNVD2026-08-03
CVE-2026-1918IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM MEDIUM4.921%EPSS 21%ileNVD2026-07-28
CVE-2026-18720A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?MEDIUM5.521%EPSS 21%ileNVD2026-08-04
CVE-2026-58041A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to contMEDIUM5.321%EPSS 21%ileNVD2026-08-04
CVE-2026-67435linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to veMEDIUM6.021%EPSS 21%ileNVD2026-07-29
CVE-2026-13379The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS statMEDIUM5.121%EPSS 21%ileNVD2026-07-30
CVE-2026-4672GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 1MEDIUM4.321%EPSS 21%ileNVD2026-07-29
CVE-2026-17696Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crosMEDIUM4.321%EPSS 21%ileNVD2026-07-30
CVE-2026-17700Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker whMEDIUM4.321%EPSS 21%ileNVD2026-07-30
CVE-2026-48061Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypaMEDIUM5.920%EPSS 20%ileNVD2026-08-03
CVE-2026-17756Insufficient policy enforcement in Presentation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypMEDIUM6.520%EPSS 20%ileNVD2026-07-30
CVE-2026-17764Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same oMEDIUM6.520%EPSS 20%ileNVD2026-07-30
CVE-2026-6453The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. ThiMEDIUM6.520%EPSS 20%ileNVD2026-08-01
CVE-2026-18481Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticateMEDIUM6.220%EPSS 20%ileNVD2026-07-31
CVE-2026-59921Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, MEDIUM5.720%EPSS 20%ileNVD2026-07-28
CVE-2026-18382A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user ableMEDIUM6.820%EPSS 20%ileNVD2026-07-30
CVE-2026-45330Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3MEDIUM4.920%EPSS 20%ileNVD2026-07-31
CVE-2026-54768WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordMEDIUM6.920%EPSS 20%ileNVD2026-07-31
CVE-2026-6089The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imporMEDIUM4.920%EPSS 20%ileNVD2026-07-29
CVE-2026-69198ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, evMEDIUM6.920%EPSS 20%ileNVD2026-08-03
CVE-2026-67347Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-locMEDIUM6.120%EPSS 20%ileNVD2026-07-30
CVE-2026-67306FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fuMEDIUM5.320%EPSS 20%ileNVD2026-08-01
CVE-2026-69243AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vMEDIUM6.320%EPSS 20%ileNVD2026-08-03
CVE-2026-45377Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3MEDIUM6.520%EPSS 20%ileNVD2026-07-31
CVE-2026-54756Jodit has prototype pollution via Jodit.configure() / ConfigMergeMEDIUM20%EPSS 20%ileGitHub2026-07-31
CVE-2026-17690Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local attMEDIUM6.519%EPSS 19%ileNVD2026-07-30
CVE-2026-17814Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reMEDIUM6.519%EPSS 19%ileNVD2026-07-30
CVE-2026-41187Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the DeleMEDIUM6.219%EPSS 19%ileNVD2026-07-30
CVE-2026-58040An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identMEDIUM6.319%EPSS 19%ileNVD2026-07-30
CVE-2026-14465Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human MEDIUM6.519%EPSS 19%ileNVD2026-08-04
CVE-2026-52888NocoBase: Sensitive Data Exposure via SQL Blacklist BypassMEDIUM6.819%EPSS 19%ileGitHub2026-07-28
CVE-2026-17946Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendMEDIUM6.519%EPSS 19%ileNVD2026-07-30
CVE-2026-17968Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to obtain potentMEDIUM6.519%EPSS 19%ileNVD2026-07-30
CVE-2026-16087The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL InjecMEDIUM6.519%EPSS 19%ileNVD2026-08-01
CVE-2026-18197Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allowMEDIUM6.419%EPSS 19%ileNVD2026-07-29
CVE-2026-66724MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob uMEDIUM5.319%EPSS 19%ileNVD2026-07-29
CVE-2026-65311The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoiMEDIUM5.319%EPSS 19%ileNVD2026-07-31
CVE-2026-65834Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetMEDIUM6.819%EPSS 19%ileNVD2026-07-30
CVE-2026-15403The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameMEDIUM4.919%EPSS 19%ileNVD2026-08-01
CVE-2026-15951The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, andMEDIUM4.919%EPSS 19%ileNVD2026-08-01
CVE-2026-16614The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL MEDIUM4.919%EPSS 19%ileNVD2026-08-01
CVE-2026-17555The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versMEDIUM4.919%EPSS 19%ileNVD2026-08-01
CVE-2026-59898Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,MEDIUM6.318%EPSS 18%ileNVD2026-07-29
CVE-2026-15018The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorMEDIUM5.318%EPSS 18%ileNVD2026-08-01
CVE-2026-17740Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data vMEDIUM4.318%EPSS 18%ileNVD2026-07-30
CVE-2026-17757Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data viMEDIUM4.318%EPSS 18%ileNVD2026-07-30
CVE-2026-17790Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentMEDIUM4.318%EPSS 18%ileNVD2026-07-30
CVE-2026-17808Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-orMEDIUM4.318%EPSS 18%ileNVD2026-07-30
CVE-2026-17810Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data viMEDIUM4.318%EPSS 18%ileNVD2026-07-30
CVE-2026-17793Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker toMEDIUM6.518%EPSS 18%ileNVD2026-07-30
CVE-2026-17831Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM6.518%EPSS 18%ileNVD2026-07-30
CVE-2026-67193Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers toMEDIUM6.918%EPSS 18%ileNVD2026-07-29
CVE-2026-61893A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuMEDIUM6.918%EPSS 18%ileNVD2026-07-30
CVE-2026-63033A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationOMEDIUM6.918%EPSS 18%ileNVD2026-07-30
CVE-2026-54712OpenTelemetry Javaagent RMI context propagation allows resource exhaustionMEDIUM5.318%EPSS 18%ileGitHub2026-07-29
CVE-2026-59647In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects MEDIUM6.918%EPSS 18%ileNVD2026-08-03
CVE-2026-59648In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affMEDIUM6.918%EPSS 18%ileNVD2026-08-03
CVE-2026-17830Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM6.518%EPSS 18%ileNVD2026-07-30
CVE-2026-17892Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentMEDIUM6.518%EPSS 18%ileNVD2026-07-30
CVE-2026-23981An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to updMEDIUM5.318%EPSS 18%ileNVD2026-07-30
CVE-2026-55777GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the bMEDIUM5.318%EPSS 18%ileNVD2026-07-30
CVE-2026-15055In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also aMEDIUM5.318%EPSS 18%ileNVD2026-08-03
CVE-2026-46714Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain aMEDIUM5.118%EPSS 18%ileNVD2026-08-03
CVE-2026-17659Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had MEDIUM4.218%EPSS 18%ileNVD2026-07-30
CVE-2026-17992Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentiMEDIUM6.518%EPSS 18%ileNVD2026-07-30
CVE-2026-14923The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a MEDIUM6.518%EPSS 18%ileNVD2026-07-30
CVE-2026-59231Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users toMEDIUM5.318%EPSS 18%ileNVD2026-07-31
CVE-2026-17851Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had cMEDIUM4.318%EPSS 18%ileNVD2026-07-30
CVE-2026-17859Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crossMEDIUM4.318%EPSS 18%ileNVD2026-07-30
CVE-2026-67316axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype hMEDIUM6.317%EPSS 17%ileNVD2026-08-01
CVE-2026-67319axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when theMEDIUM6.317%EPSS 17%ileNVD2026-08-01
CVE-2026-23985A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. TheMEDIUM5.317%EPSS 17%ileNVD2026-07-30
CVE-2026-12231The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infoMEDIUM6.417%EPSS 17%ileNVD2026-08-02
CVE-2026-6336GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 1MEDIUM5.317%EPSS 17%ileNVD2026-07-29
CVE-2026-16553GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2MEDIUM5.417%EPSS 17%ileNVD2026-07-29
CVE-2026-54272ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checksMEDIUM17%EPSS 17%ileGitHub2026-08-03
CVE-2026-67616Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoiMEDIUM5.317%EPSS 17%ileNVD2026-08-03
CVE-2026-48910A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the marMEDIUM6.517%EPSS 17%ileNVD2026-07-30
CVE-2026-67439OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the serviceMEDIUM4.317%EPSS 17%ileNVD2026-07-29
CVE-2026-54364CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to injMEDIUM6.917%EPSS 17%ileNVD2026-07-30
CVE-2026-14351GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19MEDIUM4.316%EPSS 16%ileNVD2026-07-29
CVE-2026-15077GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that uMEDIUM4.316%EPSS 16%ileNVD2026-07-29
CVE-2026-59920Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.FinaMEDIUM6.516%EPSS 16%ileNVD2026-07-29
CVE-2026-50558Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix dMEDIUM5.916%EPSS 16%ileNVD2026-07-29
CVE-2026-17348In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's befMEDIUM6.916%EPSS 16%ileNVD2026-07-31
CVE-2026-15304The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions MEDIUM6.516%EPSS 16%ileNVD2026-07-28
CVE-2026-16092The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field viMEDIUM6.516%EPSS 16%ileNVD2026-07-30
CVE-2026-48115Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, butMEDIUM6.316%EPSS 16%ileNVD2026-08-03
CVE-2026-67303FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proceMEDIUM5.316%EPSS 16%ileNVD2026-08-01
CVE-2026-38446A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread eMEDIUM6.116%EPSS 16%ileNVD2026-08-03
CVE-2026-67353guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimitMEDIUM6.916%EPSS 16%ileNVD2026-08-01
CVE-2026-10686Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing MEDIUM5.816%EPSS 16%ileNVD2026-07-31
CVE-2026-18573A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorizaMEDIUM6.516%EPSS 16%ileNVD2026-08-02
CVE-2026-13345The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibilityMEDIUM5.316%EPSS 16%ileNVD2026-07-30
CVE-2026-44097A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fiMEDIUM5.316%EPSS 16%ileNVD2026-07-30
CVE-2026-67295FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers toMEDIUM5.316%EPSS 16%ileNVD2026-08-01
CVE-2026-18266Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose MEDIUM5.416%EPSS 16%ileNVD2026-07-29
CVE-2026-54706OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frienMEDIUM4.816%EPSS 16%ileNVD2026-07-31
CVE-2026-17730Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who conviMEDIUM4.316%EPSS 16%ileNVD2026-07-30
CVE-2026-17760Side-channel information leakage in NoStatePrefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker toMEDIUM4.316%EPSS 16%ileNVD2026-07-30
CVE-2026-18736Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serveMEDIUM5.316%EPSS 16%ileNVD2026-08-03
CVE-2026-8791The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` MEDIUM6.415%EPSS 15%ileNVD2026-07-29
CVE-2026-16685The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute inMEDIUM6.415%EPSS 15%ileNVD2026-08-01
CVE-2025-36374IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileMEDIUM5.515%EPSS 15%ileNVD2026-07-30
CVE-2026-33385A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a higMEDIUM5.115%EPSS 15%ileNVD2026-07-29
CVE-2026-4912The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versioMEDIUM4.115%EPSS 15%ileNVD2026-07-28
CVE-2026-66313Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.MEDIUM6.815%EPSS 15%ileNVD2026-08-04
CVE-2026-17840Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain sMEDIUM6.515%EPSS 15%ileNVD2026-07-30
CVE-2026-3093GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 1MEDIUM4.715%EPSS 15%ileNVD2026-07-29
CVE-2026-17850Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass MEDIUM6.515%EPSS 15%ileNVD2026-07-30
CVE-2026-17852Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypassMEDIUM6.515%EPSS 15%ileNVD2026-07-30
CVE-2026-64607HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection maMEDIUM5.315%EPSS 15%ileNVD2026-07-31
CVE-2026-17693Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak MEDIUM4.315%EPSS 15%ileNVD2026-07-30
CVE-2026-17934Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM4.315%EPSS 15%ileNVD2026-07-30
CVE-2026-18571A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.MEDIUM6.615%EPSS 15%ileNVD2026-08-02
CVE-2026-17824Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to byMEDIUM6.515%EPSS 15%ileNVD2026-07-30
CVE-2026-17873Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attackMEDIUM6.515%EPSS 15%ileNVD2026-07-30
CVE-2026-17975Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain pMEDIUM6.515%EPSS 15%ileNVD2026-07-30
CVE-2026-67529OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /apMEDIUM4.315%EPSS 15%ileNVD2026-07-30
CVE-2026-44103An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore MEDIUM6.915%EPSS 15%ileNVD2026-07-30
CVE-2026-13605The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caMEDIUM6.815%EPSS 15%ileNVD2026-07-29
CVE-2026-14833The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendMEDIUM6.815%EPSS 15%ileNVD2026-07-31
CVE-2026-57511SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to injectMEDIUM6.315%EPSS 15%ileNVD2026-07-28
CVE-2026-17771Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data viMEDIUM4.315%EPSS 15%ileNVD2026-07-30
CVE-2026-17785Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data vMEDIUM4.315%EPSS 15%ileNVD2026-07-30
CVE-2026-15662The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-SitMEDIUM6.414%EPSS 14%ileNVD2026-08-01
CVE-2026-4604The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missingMEDIUM5.314%EPSS 14%ileNVD2026-07-29
CVE-2026-17791Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.514%EPSS 14%ileNVD2026-07-30
CVE-2026-17792Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker MEDIUM6.514%EPSS 14%ileNVD2026-07-30
CVE-2026-41186When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components MEDIUM6.014%EPSS 14%ileNVD2026-07-30
CVE-2026-17858Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-orMEDIUM4.314%EPSS 14%ileNVD2026-07-30
CVE-2026-17889Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data vMEDIUM4.314%EPSS 14%ileNVD2026-07-30
CVE-2026-67217cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replMEDIUM6.914%EPSS 14%ileNVD2026-07-29
CVE-2026-67339guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURMEDIUM6.914%EPSS 14%ileNVD2026-08-01
CVE-2026-66063goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.MEDIUM6.514%EPSS 14%ileNVD2026-07-28
CVE-2026-17166The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPressMEDIUM4.314%EPSS 14%ileNVD2026-07-29
CVE-2026-60011Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain imageMEDIUM6.914%EPSS 14%ileNVD2026-08-03
CVE-2026-17350The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforceMEDIUM5.314%EPSS 14%ileNVD2026-07-31
CVE-2025-14073The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an InsecurMEDIUM5.314%EPSS 14%ileNVD2026-08-01
CVE-2026-54082veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veMEDIUM6.514%EPSS 14%ileNVD2026-07-29
CVE-2026-14554The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using themMEDIUM6.514%EPSS 14%ileNVD2026-07-31
CVE-2026-14305The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allMEDIUM5.314%EPSS 14%ileNVD2026-07-30
CVE-2026-17794Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a remoteMEDIUM4.314%EPSS 14%ileNVD2026-07-30
CVE-2026-17938Inappropriate implementation in FullScreen in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.314%EPSS 14%ileNVD2026-07-30
CVE-2026-17941Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.314%EPSS 14%ileNVD2026-07-30
CVE-2026-54707OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frienMEDIUM5.414%EPSS 14%ileNVD2026-07-31
CVE-2026-18584A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. ImpactMEDIUM5.314%EPSS 14%ileNVD2026-08-03
CVE-2026-16297The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-imporMEDIUM4.114%EPSS 14%ileNVD2026-08-03
CVE-2026-14643undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or privaMEDIUM5.914%EPSS 14%ileNVD2026-07-29
CVE-2026-13309Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabiliMEDIUM6.814%EPSS 14%ileNVD2026-07-29
CVE-2026-18436The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the MEDIUM5.314%EPSS 14%ileNVD2026-07-31
CVE-2026-50569Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checksMEDIUM4.314%EPSS 14%ileGitHub2026-07-28
CVE-2026-15382The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce checMEDIUM6.513%EPSS 13%ileNVD2026-07-30
CVE-2026-17849Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.313%EPSS 13%ileNVD2026-07-30
CVE-2026-16581In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerMEDIUM6.913%EPSS 13%ileNVD2026-07-28
CVE-2026-17805Insufficient policy enforcement in Glic in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to MEDIUM6.513%EPSS 13%ileNVD2026-07-30
CVE-2026-17813Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attackMEDIUM6.513%EPSS 13%ileNVD2026-07-30
CVE-2026-17921Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM6.513%EPSS 13%ileNVD2026-07-30
CVE-2026-17926Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.513%EPSS 13%ileNVD2026-07-30
CVE-2026-17931Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navMEDIUM6.513%EPSS 13%ileNVD2026-07-30
CVE-2026-17953Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker MEDIUM6.513%EPSS 13%ileNVD2026-07-30
CVE-2026-17779Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypaMEDIUM5.413%EPSS 13%ileNVD2026-07-30
CVE-2026-69092Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoMEDIUM6.913%EPSS 13%ileNVD2026-08-03
CVE-2026-52371A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticatMEDIUM6.513%EPSS 13%ileNVD2026-07-31
CVE-2026-54704OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text PasswordsMEDIUM6.513%EPSS 13%ileGitHub2026-07-29
CVE-2026-49447Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as MEDIUM5.313%EPSS 13%ileNVD2026-07-28
CVE-2026-14226The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability on one of its appointmenMEDIUM4.313%EPSS 13%ileNVD2026-07-30
CVE-2026-14231The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handMEDIUM4.313%EPSS 13%ileNVD2026-07-30
CVE-2026-15235The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a bookingMEDIUM4.313%EPSS 13%ileNVD2026-07-30
CVE-2026-14227An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient SessiMEDIUM6.913%EPSS 13%ileNVD2026-07-30
CVE-2026-18208A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-sourceMEDIUM6.513%EPSS 13%ileNVD2026-07-31
CVE-2026-58156Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affeMEDIUM6.313%EPSS 13%ileNVD2026-07-29
CVE-2026-15831GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that uMEDIUM4.313%EPSS 13%ileNVD2026-07-29
CVE-2026-5060The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure DMEDIUM6.513%EPSS 13%ileNVD2026-07-29
CVE-2026-53466ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflowMEDIUM6.513%EPSS 13%ileGitHub2026-07-31
CVE-2026-11782The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wMEDIUM5.913%EPSS 13%ileNVD2026-07-30
CVE-2026-13143The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal poMEDIUM5.313%EPSS 13%ileNVD2026-07-30
CVE-2026-14317The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by tMEDIUM5.313%EPSS 13%ileNVD2026-07-31
CVE-2026-12966The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted MEDIUM5.313%EPSS 13%ileNVD2026-08-01
CVE-2026-17914Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potMEDIUM5.313%EPSS 13%ileNVD2026-07-30
CVE-2026-68562A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp MEDIUM6.212%EPSS 12%ileNVD2026-07-30
CVE-2026-3157IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM MEDIUM4.312%EPSS 12%ileNVD2026-07-28
CVE-2026-17949Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origMEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17819Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perfMEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-17828Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-17835Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-17838Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perfMEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-17839Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-14928The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning suppMEDIUM6.512%EPSS 12%ileNVD2026-07-31
CVE-2026-14931The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation MEDIUM6.512%EPSS 12%ileNVD2026-07-31
CVE-2026-2916The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, anMEDIUM4.312%EPSS 12%ileNVD2026-08-01
CVE-2026-17825Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attackeMEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-17917Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attackMEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2025-51684CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data MEDIUM6.112%EPSS 12%ileNVD2026-07-30
CVE-2026-66316Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a neMEDIUM5.412%EPSS 12%ileNVD2026-08-04
CVE-2026-66317Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a nMEDIUM5.412%EPSS 12%ileNVD2026-08-04
CVE-2026-63238An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, inclMEDIUM6.512%EPSS 12%ileNVD2026-07-29
CVE-2026-17985Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass siMEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-17988Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-17767Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remotMEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17769Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17772Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of boundMEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17773Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17795Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had cMEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17747Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remoMEDIUM4.212%EPSS 12%ileNVD2026-07-30
CVE-2026-14539An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up MEDIUM6.612%EPSS 12%ileNVD2026-07-31
CVE-2026-17789Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reMEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-18344The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parMEDIUM6.112%EPSS 12%ileNVD2026-08-01
CVE-2026-64870MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool pMEDIUM5.312%EPSS 12%ileNVD2026-07-30
CVE-2026-67352luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows MEDIUM6.812%EPSS 12%ileNVD2026-08-01
CVE-2026-17909Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remoteMEDIUM5.312%EPSS 12%ileNVD2026-07-30
CVE-2026-68930Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reciMEDIUM6.512%EPSS 12%ileNVD2026-08-03
CVE-2026-17879Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crossMEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17880Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crossMEDIUM4.312%EPSS 12%ileNVD2026-07-30
CVE-2025-15627A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys toMEDIUM6.912%EPSS 12%ileNVD2026-08-03
CVE-2026-11867The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term MEDIUM6.512%EPSS 12%ileNVD2026-07-30
CVE-2026-12938The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of theMEDIUM6.412%EPSS 12%ileNVD2026-07-29
CVE-2026-12939The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the pMEDIUM6.412%EPSS 12%ileNVD2026-07-29
CVE-2026-15250The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated MEDIUM5.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17978Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtaiMEDIUM5.312%EPSS 12%ileNVD2026-07-30
CVE-2026-17571The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulneMEDIUM6.111%EPSS 11%ileNVD2026-08-01
CVE-2026-17874Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM5.411%EPSS 11%ileNVD2026-07-30
CVE-2026-67528OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resolMEDIUM4.311%EPSS 11%ileNVD2026-07-30
CVE-2026-44102An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid fMEDIUM6.911%EPSS 11%ileNVD2026-07-30
CVE-2026-14592The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks beforMEDIUM6.111%EPSS 11%ileNVD2026-07-30
CVE-2026-22068Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: frMEDIUM6.911%EPSS 11%ileNVD2026-07-29
CVE-2026-17986Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had cMEDIUM6.511%EPSS 11%ileNVD2026-07-30
CVE-2026-15974SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitizeMEDIUM6.511%EPSS 11%ileNVD2026-07-30
CVE-2026-54705MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode contenMEDIUM6.311%EPSS 11%ileNVD2026-07-29
CVE-2026-65975Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 uMEDIUM6.511%EPSS 11%ileNVD2026-07-29
CVE-2026-17923Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrMEDIUM6.511%EPSS 11%ileNVD2026-07-30
CVE-2026-17929Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.511%EPSS 11%ileNVD2026-07-30
CVE-2026-15227Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking tMEDIUM5.311%EPSS 11%ileNVD2026-07-31
CVE-2026-7623The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored CrosMEDIUM6.411%EPSS 11%ileNVD2026-08-01
CVE-2026-15644The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'stMEDIUM6.411%EPSS 11%ileNVD2026-08-01
CVE-2026-15645The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'naMEDIUM6.411%EPSS 11%ileNVD2026-08-01
CVE-2026-18062The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site SMEDIUM6.411%EPSS 11%ileNVD2026-08-01
CVE-2026-11351The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API eMEDIUM5.311%EPSS 11%ileNVD2026-07-29
CVE-2026-66489Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2MEDIUM5.311%EPSS 11%ileNVD2026-07-29
CVE-2026-17662Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crMEDIUM4.311%EPSS 11%ileNVD2026-07-30
CVE-2026-14223The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored cusMEDIUM4.311%EPSS 11%ileNVD2026-07-30
CVE-2026-66488Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2MEDIUM5.311%EPSS 11%ileNVD2026-07-29
CVE-2026-17782Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spooMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-18203A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a grMEDIUM6.510%EPSS 10%ileNVD2026-07-31
CVE-2026-18572Keycloak provides authorization services that allow administrators to restrict access to resources based on time policieMEDIUM6.510%EPSS 10%ileNVD2026-08-02
CVE-2026-13362The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_MEDIUM6.410%EPSS 10%ileNVD2026-08-01
CVE-2026-14538An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of GooglMEDIUM5.710%EPSS 10%ileNVD2026-07-31
CVE-2026-15255The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in MEDIUM5.310%EPSS 10%ileNVD2026-07-30
CVE-2026-15649The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ShoMEDIUM6.410%EPSS 10%ileNVD2026-08-01
CVE-2026-16091The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is MEDIUM6.410%EPSS 10%ileNVD2026-08-01
CVE-2026-17731Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker toMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17733Inappropriate implementation in QUIC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leaMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17742Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17753Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crossMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17763Inappropriate implementation in GPU in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromiseMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17765Inappropriate implementation in WebProtect in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17815Insufficient policy enforcement in GuestView in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17820Insufficient policy enforcement in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17829Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17928Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17942Side-channel information leakage in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-MEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-69090Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role admMEDIUM6.910%EPSS 10%ileNVD2026-08-03
CVE-2026-13113GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2MEDIUM6.510%EPSS 10%ileNVD2026-07-29
CVE-2026-15657A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchaMEDIUM6.510%EPSS 10%ileNVD2026-07-30
CVE-2026-15209The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: aMEDIUM6.510%EPSS 10%ileNVD2026-07-31
CVE-2026-15254The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administratMEDIUM6.510%EPSS 10%ileNVD2026-08-03
CVE-2026-16563The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returnMEDIUM6.510%EPSS 10%ileNVD2026-08-03
CVE-2026-16105A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoinMEDIUM4.910%EPSS 10%ileNVD2026-07-31
CVE-2026-5626The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checMEDIUM4.310%EPSS 10%ileNVD2026-07-29
CVE-2026-18214Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google WorMEDIUM6.810%EPSS 10%ileNVD2026-07-31
CVE-2026-67334better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpMEDIUM5.110%EPSS 10%ileNVD2026-08-01
CVE-2026-63118MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::TranMEDIUM6.910%EPSS 10%ileNVD2026-07-29
CVE-2026-17799Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote attMEDIUM5.410%EPSS 10%ileNVD2026-07-30
CVE-2026-17812Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM5.410%EPSS 10%ileNVD2026-07-30
CVE-2026-17915Inappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to MEDIUM5.410%EPSS 10%ileNVD2026-07-30
CVE-2026-54249Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, andMEDIUM6.810%EPSS 10%ileNVD2026-07-29
CVE-2026-18001Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentMEDIUM6.510%EPSS 10%ileNVD2026-07-30
CVE-2026-18005Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentMEDIUM6.510%EPSS 10%ileNVD2026-07-30
CVE-2026-64685ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.MEDIUM5.310%EPSS 10%ileNVD2026-07-30
CVE-2026-43833Full details and mitigation steps are currently restricted and will be published at a later date.MEDIUM5.310%EPSS 10%ileNVD2026-07-31
CVE-2026-66414Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to MEDIUM5.110%EPSS 10%ileNVD2026-07-30
CVE-2026-17937Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17943Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass conteMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-17960Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attackMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-13145The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboaMEDIUM4.310%EPSS 10%ileNVD2026-07-30
CVE-2026-65891Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function MEDIUM6.510%EPSS 10%ileNVD2026-07-29
CVE-2026-1982The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, anMEDIUM5.310%EPSS 10%ileNVD2026-07-30
CVE-2026-62845Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivMEDIUM4.710%EPSS 10%ileNVD2026-07-30
CVE-2026-68585SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that rMEDIUM6.99%EPSS 9%ileNVD2026-08-03
CVE-2026-17780Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bMEDIUM6.39%EPSS 9%ileNVD2026-07-30
CVE-2026-50735pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol meMEDIUM6.19%EPSS 9%ileNVD2026-07-28
CVE-2026-18369A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dnsMEDIUM5.89%EPSS 9%ileNVD2026-07-30
CVE-2026-17842Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM6.59%EPSS 9%ileNVD2026-07-30
CVE-2026-17846Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who hMEDIUM6.59%EPSS 9%ileNVD2026-07-30
CVE-2026-17854Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass saMEDIUM6.59%EPSS 9%ileNVD2026-07-30
CVE-2026-17883Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass samMEDIUM6.59%EPSS 9%ileNVD2026-07-30
CVE-2026-61526AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 throughMEDIUM6.19%EPSS 9%ileNVD2026-07-30
CVE-2026-48058nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internMEDIUM4.69%EPSS 9%ileNVD2026-07-28
CVE-2026-17907Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crMEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-15735The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field'MEDIUM6.49%EPSS 9%ileNVD2026-07-29
CVE-2026-17161The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site ScMEDIUM6.49%EPSS 9%ileNVD2026-07-29
CVE-2026-17162The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site ScMEDIUM6.49%EPSS 9%ileNVD2026-07-29
CVE-2026-7436The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'textMEDIUM6.49%EPSS 9%ileNVD2026-07-29
CVE-2026-15950The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPressMEDIUM6.49%EPSS 9%ileNVD2026-08-01
CVE-2026-16090The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is MEDIUM6.49%EPSS 9%ileNVD2026-08-01
CVE-2026-16684The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User ContactMEDIUM6.49%EPSS 9%ileNVD2026-08-01
CVE-2026-18435The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site SMEDIUM6.49%EPSS 9%ileNVD2026-08-01
CVE-2026-18174@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header MEDIUM5.39%EPSS 9%ileNVD2026-07-29
CVE-2026-65835Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVEMEDIUM6.69%EPSS 9%ileNVD2026-07-30
CVE-2026-14207The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field beforMEDIUM6.19%EPSS 9%ileNVD2026-07-30
CVE-2026-17736Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remotMEDIUM5.89%EPSS 9%ileNVD2026-07-30
CVE-2026-64635Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows anMEDIUM5.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17945Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17955Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17958Inappropriate implementation in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spMEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17964Incorrect security UI in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domaMEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17965Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perfMEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17972Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-18211A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respoMEDIUM4.29%EPSS 9%ileNVD2026-07-31
CVE-2026-58045A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zMEDIUM6.29%EPSS 9%ileNVD2026-08-04
CVE-2026-15257The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a frMEDIUM5.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17912Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17944Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-17961Inappropriate implementation in Session in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2025-15630A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with tMEDIUM5.89%EPSS 9%ileNVD2026-08-03
CVE-2026-17982Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.39%EPSS 9%ileNVD2026-07-30
CVE-2026-18215Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organizationMEDIUM6.89%EPSS 9%ileNVD2026-07-31
CVE-2026-17882Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install MEDIUM6.59%EPSS 9%ileNVD2026-07-30
CVE-2026-11870The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a MEDIUM5.49%EPSS 9%ileNVD2026-07-30
CVE-2026-18003Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.38%EPSS 8%ileNVD2026-07-30
CVE-2026-17743Insufficient policy enforcement in ControlledFrame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to MEDIUM6.58%EPSS 8%ileNVD2026-07-30
CVE-2026-17748Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comMEDIUM6.58%EPSS 8%ileNVD2026-07-30
CVE-2026-17754Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same oMEDIUM6.58%EPSS 8%ileNVD2026-07-30
CVE-2026-17787Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass samMEDIUM6.58%EPSS 8%ileNVD2026-07-30
CVE-2026-11391Tanium addressed a SQL injection vulnerability in Patch.MEDIUM6.38%EPSS 8%ileNVD2026-07-28
CVE-2025-62347HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior andMEDIUM4.38%EPSS 8%ileNVD2026-07-31
CVE-2026-69248cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,MEDIUM6.98%EPSS 8%ileNVD2026-08-03
CVE-2026-17797Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.18%EPSS 8%ileNVD2026-07-30
CVE-2026-17728Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject aMEDIUM5.48%EPSS 8%ileNVD2026-07-30
CVE-2026-17734Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbMEDIUM5.48%EPSS 8%ileNVD2026-07-30
CVE-2026-13306Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present atMEDIUM4.38%EPSS 8%ileNVD2026-07-29
CVE-2026-17983Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.38%EPSS 8%ileNVD2026-07-30
CVE-2026-18243Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticatMEDIUM6.98%EPSS 8%ileNVD2026-08-03
CVE-2026-17845Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.18%EPSS 8%ileNVD2026-07-30
CVE-2026-13692The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applyingMEDIUM5.38%EPSS 8%ileNVD2026-07-29
CVE-2026-14843The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targetMEDIUM5.38%EPSS 8%ileNVD2026-07-31
CVE-2026-67310OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in tMEDIUM5.38%EPSS 8%ileNVD2026-08-01
CVE-2026-16970The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. StoMEDIUM4.28%EPSS 8%ileNVD2026-07-30
CVE-2026-56758The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certainMEDIUM6.98%EPSS 8%ileNVD2026-07-30
CVE-2026-66349The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed MEDIUM6.98%EPSS 8%ileNVD2026-07-30
CVE-2026-20482In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjMEDIUM6.58%EPSS 8%ileNVD2026-08-03
CVE-2026-54663swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolMEDIUM6.18%EPSS 8%ileNVD2026-07-29
CVE-2026-11881The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settingMEDIUM6.18%EPSS 8%ileNVD2026-07-30
CVE-2026-13330The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adMEDIUM6.18%EPSS 8%ileNVD2026-07-30
CVE-2026-14841The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refleMEDIUM6.18%EPSS 8%ileNVD2026-08-02
CVE-2026-13340The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extMEDIUM6.18%EPSS 8%ileNVD2026-08-03
CVE-2026-17901Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0.7922.72 allowed a remotMEDIUM4.38%EPSS 8%ileNVD2026-07-30
CVE-2026-17994Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to byMEDIUM4.38%EPSS 8%ileNVD2026-07-30
CVE-2026-3158IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM MEDIUM4.38%EPSS 8%ileNVD2026-07-28
CVE-2026-17745Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renMEDIUM5.88%EPSS 8%ileNVD2026-07-30
CVE-2026-17746Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the rMEDIUM5.88%EPSS 8%ileNVD2026-07-30
CVE-2026-62324Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElemMEDIUM5.48%EPSS 8%ileNVD2026-07-31
CVE-2026-17737Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromMEDIUM5.08%EPSS 8%ileNVD2026-07-30
CVE-2026-17781Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a uMEDIUM4.38%EPSS 8%ileNVD2026-07-30
CVE-2026-17802Side-channel information leakage in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to MEDIUM4.38%EPSS 8%ileNVD2026-07-30
CVE-2026-17823Insufficient policy enforcement in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass samMEDIUM6.58%EPSS 8%ileNVD2026-07-30
CVE-2026-17936Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convincedMEDIUM6.58%EPSS 8%ileNVD2026-07-30
CVE-2026-14515IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scriptinMEDIUM6.18%EPSS 8%ileNVD2026-07-28
CVE-2026-17776Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendMEDIUM5.88%EPSS 8%ileNVD2026-07-30
CVE-2026-15252The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX hanMEDIUM5.48%EPSS 8%ileNVD2026-07-30
CVE-2026-7362IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1MEDIUM4.38%EPSS 8%ileNVD2026-07-28
CVE-2026-16547The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log enMEDIUM5.97%EPSS 7%ileNVD2026-08-04
CVE-2026-16729undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before MEDIUM4.87%EPSS 7%ileNVD2026-07-29
CVE-2026-10773The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const cMEDIUM5.47%EPSS 7%ileNVD2026-08-01
CVE-2026-16728undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to MEDIUM4.87%EPSS 7%ileNVD2026-07-29
CVE-2026-63240An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers fMEDIUM4.37%EPSS 7%ileNVD2026-07-29
CVE-2026-17939Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-10569IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 througMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-28144Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded SensitiMEDIUM4.37%EPSS 7%ileNVD2026-07-31
CVE-2026-17853Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comprMEDIUM6.17%EPSS 7%ileNVD2026-07-30
CVE-2026-17878Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.17%EPSS 7%ileNVD2026-07-30
CVE-2026-14310The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread MEDIUM5.47%EPSS 7%ileNVD2026-07-30
CVE-2026-14192Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software andMEDIUM5.47%EPSS 7%ileNVD2026-08-04
CVE-2026-17822Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing vMEDIUM6.57%EPSS 7%ileNVD2026-07-30
CVE-2026-17841Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing vMEDIUM6.57%EPSS 7%ileNVD2026-07-30
CVE-2026-13329The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce vaMEDIUM6.57%EPSS 7%ileNVD2026-08-01
CVE-2026-18651A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind crMEDIUM5.47%EPSS 7%ileNVD2026-08-03
CVE-2026-67338JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to valiMEDIUM5.17%EPSS 7%ileNVD2026-08-01
CVE-2026-17843Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-17857Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-MEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-17871Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinceMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-17876Inappropriate implementation in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crossMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-17885Inappropriate implementation in Paint in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-orMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-17895Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who conviMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-17897Inappropriate implementation in ORB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origMEDIUM4.37%EPSS 7%ileNVD2026-07-30
CVE-2026-13344The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing TaMEDIUM4.87%EPSS 7%ileNVD2026-07-30
CVE-2025-15669The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before renMEDIUM4.87%EPSS 7%ileNVD2026-08-01
CVE-2025-15675The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields beforMEDIUM4.87%EPSS 7%ileNVD2026-08-02
CVE-2026-25552Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass ratMEDIUM6.37%EPSS 7%ileNVD2026-07-31
CVE-2026-17821Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced MEDIUM6.57%EPSS 7%ileNVD2026-07-30
CVE-2026-17974Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed a local attacker to bypass nMEDIUM6.57%EPSS 7%ileNVD2026-07-30
CVE-2026-17818Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbiMEDIUM6.17%EPSS 7%ileNVD2026-07-30
CVE-2026-17827Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrarMEDIUM6.17%EPSS 7%ileNVD2026-07-30
CVE-2026-17962Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrMEDIUM6.17%EPSS 7%ileNVD2026-07-30
CVE-2026-44613Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin MEDIUM6.17%EPSS 7%ileNVD2026-07-30
CVE-2026-67335better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-MEDIUM6.07%EPSS 7%ileNVD2026-08-01
CVE-2026-17866Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised tMEDIUM5.87%EPSS 7%ileNVD2026-07-30
CVE-2026-45086Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a particiMEDIUM5.47%EPSS 7%ileNVD2026-07-31
CVE-2026-17761Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a reMEDIUM5.47%EPSS 7%ileNVD2026-07-30
CVE-2026-12697The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting usMEDIUM5.47%EPSS 7%ileNVD2026-07-31
CVE-2026-28147Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, TemplaMEDIUM5.47%EPSS 7%ileNVD2026-08-03
CVE-2026-24033Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server.MEDIUM6.96%EPSS 6%ileNVD2026-07-29
CVE-2026-18014Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM6.56%EPSS 6%ileNVD2026-07-30
CVE-2026-17890Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attackerMEDIUM5.86%EPSS 6%ileNVD2026-07-30
CVE-2026-17893Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote atMEDIUM5.86%EPSS 6%ileNVD2026-07-30
CVE-2026-7260Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP MEDIUM5.46%EPSS 6%ileNVD2026-07-30
CVE-2026-17770Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromisedMEDIUM5.86%EPSS 6%ileNVD2026-07-30
CVE-2025-67651A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF MEDIUM6.96%EPSS 6%ileNVD2026-07-31
CVE-2026-65325Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the nMEDIUM6.36%EPSS 6%ileNVD2026-07-29
CVE-2026-49131OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firMEDIUM5.16%EPSS 6%ileNVD2026-08-03
CVE-2026-14834The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX MEDIUM6.56%EPSS 6%ileNVD2026-07-31
CVE-2026-14315The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of iMEDIUM6.56%EPSS 6%ileNVD2026-08-01
CVE-2026-14561The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confidenMEDIUM6.56%EPSS 6%ileNVD2026-08-01
CVE-2026-20471In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of serviceMEDIUM4.66%EPSS 6%ileNVD2026-08-03
CVE-2026-20466In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalatMEDIUM6.16%EPSS 6%ileNVD2026-08-03
CVE-2026-17817Inappropriate implementation in ReportingAndNEL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leaMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17833Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crosMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17904Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to lMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17905Inappropriate implementation in SurfaceCapture in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leakMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17910Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to lMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17911Insufficient policy enforcement in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-oMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17933Inappropriate implementation in DOMStorage in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak croMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17959Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-MEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-17963Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-18019Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crosMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2025-0152IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1MEDIUM6.16%EPSS 6%ileNVD2026-07-30
CVE-2026-14845The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor reMEDIUM6.16%EPSS 6%ileNVD2026-07-31
CVE-2026-15383The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, whicMEDIUM6.16%EPSS 6%ileNVD2026-08-03
CVE-2026-15931The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthentMEDIUM6.16%EPSS 6%ileNVD2026-08-03
CVE-2026-67332@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowingMEDIUM5.36%EPSS 6%ileNVD2026-08-01
CVE-2026-17977Policy bypass in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a cMEDIUM4.36%EPSS 6%ileNVD2026-07-30
CVE-2026-59328Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT BrowseMEDIUM4.26%EPSS 6%ileNVD2026-07-30
CVE-2025-36298IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0MEDIUM5.46%EPSS 6%ileNVD2026-07-30
CVE-2025-36431IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulneraMEDIUM5.46%EPSS 6%ileNVD2026-07-30
CVE-2026-11383IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scriMEDIUM5.46%EPSS 6%ileNVD2026-07-30
CVE-2026-12376The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowingMEDIUM4.36%EPSS 6%ileNVD2026-07-31
CVE-2026-14847The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of iMEDIUM4.36%EPSS 6%ileNVD2026-07-31
CVE-2026-16289The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending meMEDIUM4.36%EPSS 6%ileNVD2026-08-03
CVE-2026-66755Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.MEDIUM5.96%EPSS 6%ileNVD2026-07-30
CVE-2026-14219URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMMEDIUM5.46%EPSS 6%ileNVD2026-08-04
CVE-2026-67617Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that alMEDIUM4.86%EPSS 6%ileNVD2026-08-03
CVE-2026-14292The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in tMEDIUM5.46%EPSS 6%ileNVD2026-08-01
CVE-2026-16548The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin beMEDIUM5.46%EPSS 6%ileNVD2026-08-04
CVE-2026-16107IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validatMEDIUM5.96%EPSS 6%ileNVD2026-07-28
CVE-2026-17806Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM5.86%EPSS 6%ileNVD2026-07-30
CVE-2026-17809Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attackMEDIUM5.86%EPSS 6%ileNVD2026-07-30
CVE-2026-17906Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM5.86%EPSS 6%ileNVD2026-07-30
CVE-2026-17908Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remoMEDIUM5.86%EPSS 6%ileNVD2026-07-30
CVE-2026-17891Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromisedMEDIUM5.85%EPSS 5%ileNVD2026-07-30
CVE-2026-69094Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fuMEDIUM5.35%EPSS 5%ileNVD2026-08-03
CVE-2026-67333better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of rediMEDIUM5.15%EPSS 5%ileNVD2026-08-01
CVE-2026-17981Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-orMEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-18004Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compMEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-67530WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/MEDIUM6.45%EPSS 5%ileNVD2026-07-30
CVE-2026-18570A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componenMEDIUM5.45%EPSS 5%ileNVD2026-08-02
CVE-2026-17755Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to MEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-17925Inappropriate implementation in Cast in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypMEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-17954Policy bypass in MHTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via aMEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-47725nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every MEDIUM6.95%EPSS 5%ileNVD2026-07-28
CVE-2026-56389GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gramMEDIUM6.85%EPSS 5%ileNVD2026-07-29
CVE-2026-66490Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2MEDIUM6.15%EPSS 5%ileNVD2026-07-29
CVE-2025-65337Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address MEDIUM6.15%EPSS 5%ileNVD2026-07-29
CVE-2026-18006Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had coMEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-18007Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to peMEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-18013Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2024-40683IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,MEDIUM6.35%EPSS 5%ileNVD2026-07-30
CVE-2026-15157undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type heMEDIUM4.25%EPSS 5%ileNVD2026-07-29
CVE-2026-16069The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted tMEDIUM6.85%EPSS 5%ileNVD2026-08-04
CVE-2026-16293The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its PoMEDIUM6.85%EPSS 5%ileNVD2026-08-04
CVE-2026-66400Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php whMEDIUM6.35%EPSS 5%ileNVD2026-07-29
CVE-2026-63242A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to MEDIUM4.35%EPSS 5%ileNVD2026-07-29
CVE-2026-14929The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, alloMEDIUM4.35%EPSS 5%ileNVD2026-07-31
CVE-2026-15260The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-inMEDIUM4.35%EPSS 5%ileNVD2026-08-03
CVE-2026-16564The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order MEDIUM4.35%EPSS 5%ileNVD2026-08-03
CVE-2026-16565The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify producMEDIUM4.35%EPSS 5%ileNVD2026-08-03
CVE-2026-17724Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scriMEDIUM4.25%EPSS 5%ileNVD2026-07-30
CVE-2026-54785gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 untiMEDIUM6.25%EPSS 5%ileNVD2026-07-31
CVE-2026-6695A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (MEDIUM5.55%EPSS 5%ileNVD2026-08-03
CVE-2026-65875BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opensMEDIUM5.15%EPSS 5%ileNVD2026-08-03
CVE-2026-17900Inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.35%EPSS 5%ileNVD2026-07-30
CVE-2026-65946Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0MEDIUM6.15%EPSS 5%ileNVD2026-07-29
CVE-2025-65341Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.MEDIUM6.15%EPSS 5%ileNVD2026-07-30
CVE-2025-65342code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.MEDIUM6.15%EPSS 5%ileNVD2026-07-30
CVE-2026-14921The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_MEDIUM6.15%EPSS 5%ileNVD2026-07-31
CVE-2026-14922WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 througMEDIUM6.15%EPSS 5%ileNVD2026-07-31
CVE-2026-52232A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D BuildMEDIUM6.15%EPSS 5%ileNVD2026-07-31
CVE-2026-6694A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated PortableMEDIUM5.55%EPSS 5%ileNVD2026-08-03
CVE-2026-67612OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that alMEDIUM4.84%EPSS 4%ileNVD2026-08-03
CVE-2026-14816The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of thMEDIUM6.54%EPSS 4%ileNVD2026-08-04
CVE-2026-17762Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker MEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-17775Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leaMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-17777Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak crossMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-17788Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-orMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-17798Inappropriate implementation in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-oriMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-17999Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain MEDIUM6.54%EPSS 4%ileNVD2026-07-30
CVE-2026-17550A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabiliMEDIUM5.54%EPSS 4%ileNVD2026-07-29
CVE-2026-14224The Easy Appointments WordPress plugin through 3.12.26 does not verify that the appointment targeted by its customer-datMEDIUM5.44%EPSS 4%ileNVD2026-07-29
CVE-2026-17970Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in aMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-16465A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabiliMEDIUM6.14%EPSS 4%ileNVD2026-07-29
CVE-2026-10526The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests thMEDIUM5.84%EPSS 4%ileNVD2026-08-04
CVE-2026-18008Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UIMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-18009Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attackeMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-18010Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UMEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-12698The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing theiMEDIUM4.34%EPSS 4%ileNVD2026-08-04
CVE-2026-17739Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced MEDIUM4.24%EPSS 4%ileNVD2026-07-30
CVE-2026-17976Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced MEDIUM4.34%EPSS 4%ileNVD2026-07-30
CVE-2026-8155The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpointsMEDIUM5.44%EPSS 4%ileNVD2026-07-31
CVE-2026-16064The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the oMEDIUM5.44%EPSS 4%ileNVD2026-08-02
CVE-2026-68583luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field thMEDIUM5.14%EPSS 4%ileNVD2026-08-02
CVE-2026-69245Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of MEDIUM6.54%EPSS 4%ileNVD2026-08-03
CVE-2026-68742A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen MEDIUM5.54%EPSS 4%ileNVD2026-08-03
CVE-2026-53606sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, posMEDIUM5.44%EPSS 4%ileGitHub2026-07-31
CVE-2026-16536The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL befMEDIUM5.34%EPSS 4%ileNVD2026-08-04
CVE-2026-16296The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirectMEDIUM4.74%EPSS 4%ileNVD2026-08-04
CVE-2026-63220CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-ForMEDIUM4.83%EPSS 3%ileNVD2026-07-31
CVE-2026-18772Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.MEDIUM5.53%EPSS 3%ileNVD2026-08-04
CVE-2026-12696The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inMEDIUM5.43%EPSS 3%ileNVD2026-08-01
CVE-2026-15234The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usinMEDIUM5.43%EPSS 3%ileNVD2026-08-01
CVE-2026-15262The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outMEDIUM5.43%EPSS 3%ileNVD2026-08-01
CVE-2026-14864The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its sMEDIUM5.43%EPSS 3%ileNVD2026-08-02
CVE-2026-15385The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-mMEDIUM5.43%EPSS 3%ileNVD2026-08-02
CVE-2026-16063The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline contMEDIUM5.43%EPSS 3%ileNVD2026-08-02
CVE-2026-62363ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.MEDIUM5.03%EPSS 3%ileNVD2026-07-30
CVE-2026-56390GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyiMEDIUM4.63%EPSS 3%ileNVD2026-07-29
CVE-2026-16273The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field MEDIUM4.63%EPSS 3%ileNVD2026-08-02
CVE-2026-18016Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attackMEDIUM4.33%EPSS 3%ileNVD2026-07-30
CVE-2026-5582The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24MEDIUM4.33%EPSS 3%ileNVD2026-07-30
CVE-2026-16295The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch pMEDIUM4.33%EPSS 3%ileNVD2026-08-04
CVE-2026-16546The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAMEDIUM4.33%EPSS 3%ileNVD2026-08-04
CVE-2026-18508A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confinMEDIUM4.43%EPSS 3%ileNVD2026-08-03
CVE-2026-18218A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempMEDIUM4.23%EPSS 3%ileNVD2026-07-31
CVE-2026-55734Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) aMEDIUM6.93%EPSS 3%ileNVD2026-08-01
CVE-2025-15544A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials assocMEDIUM6.93%EPSS 3%ileNVD2026-08-03
CVE-2026-63119MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::TranMEDIUM6.23%EPSS 3%ileNVD2026-07-29
CVE-2026-68499re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match MEDIUM6.23%EPSS 3%ileNVD2026-07-30
CVE-2026-20470In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local infMEDIUM6.23%EPSS 3%ileNVD2026-08-03
CVE-2026-9720The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions MEDIUM4.33%EPSS 3%ileNVD2026-07-29
CVE-2025-14469The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, MEDIUM4.33%EPSS 3%ileNVD2026-08-01
CVE-2026-54894Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom cMEDIUM6.93%EPSS 3%ileNVD2026-08-01
CVE-2026-55733Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom cMEDIUM6.93%EPSS 3%ileNVD2026-08-01
CVE-2026-2411Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whoseMEDIUM6.53%EPSS 3%ileNVD2026-08-01
CVE-2026-17927Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a MEDIUM4.33%EPSS 3%ileNVD2026-07-30
CVE-2026-62946ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to bothMEDIUM5.12%EPSS 2%ileNVD2026-07-30
CVE-2026-62343ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.MEDIUM4.72%EPSS 2%ileNVD2026-07-30
CVE-2026-13305Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code ExecutioMEDIUM6.42%EPSS 2%ileNVD2026-07-29
CVE-2026-63239A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckeMEDIUM5.42%EPSS 2%ileNVD2026-07-29
CVE-2026-67550re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex againMEDIUM5.72%EPSS 2%ileNVD2026-07-30
CVE-2026-17919Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker toMEDIUM6.82%EPSS 2%ileNVD2026-07-30
CVE-2026-17783Inappropriate implementation in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-oMEDIUM4.32%EPSS 2%ileNVD2026-07-30
CVE-2026-10695IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated quMEDIUM6.22%EPSS 2%ileNVD2026-07-30
CVE-2026-17903Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local nMEDIUM5.42%EPSS 2%ileNVD2026-07-30
CVE-2026-20484In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local informatiMEDIUM4.42%EPSS 2%ileNVD2026-08-03
CVE-2026-20488In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informatiMEDIUM4.42%EPSS 2%ileNVD2026-08-03
CVE-2026-20489In display, there is a possible information disclosure due to an integer overflow. This could lead to local information MEDIUM4.42%EPSS 2%ileNVD2026-08-03
CVE-2026-17998Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to MEDIUM4.32%EPSS 2%ileNVD2026-07-30
CVE-2026-18605A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AMEDIUM6.42%EPSS 2%ileNVD2026-08-03
CVE-2026-63237A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled sMEDIUM4.82%EPSS 2%ileNVD2026-07-29
CVE-2026-17844Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the loMEDIUM4.32%EPSS 2%ileNVD2026-07-30
CVE-2026-17870Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the loMEDIUM4.32%EPSS 2%ileNVD2026-07-30
CVE-2026-20467In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalatioMEDIUM6.02%EPSS 2%ileNVD2026-08-03
CVE-2026-20468In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of MEDIUM6.02%EPSS 2%ileNVD2026-08-03
CVE-2026-20469In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local eMEDIUM6.02%EPSS 2%ileNVD2026-08-03
CVE-2026-20473In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilegMEDIUM6.02%EPSS 2%ileNVD2026-08-03
CVE-2026-20475In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation oMEDIUM6.02%EPSS 2%ileNVD2026-08-03
CVE-2026-20477In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation oMEDIUM6.02%EPSS 2%ileNVD2026-08-03
CVE-2026-40717Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulneraMEDIUM6.62%EPSS 2%ileNVD2026-08-03
CVE-2026-52857Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unMEDIUM5.52%EPSS 2%ileNVD2026-07-31
CVE-2026-56567HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internMEDIUM5.12%EPSS 2%ileNVD2026-07-31
CVE-2026-56569HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configMEDIUM4.02%EPSS 2%ileNVD2026-07-31
CVE-2026-20476In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servicMEDIUM5.52%EPSS 2%ileNVD2026-08-03
CVE-2026-28145Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User MEDIUM5.32%EPSS 2%ileNVD2026-07-31
CVE-2026-49132OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injecMEDIUM5.12%EPSS 2%ileNVD2026-08-03
CVE-2026-67596CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticateMEDIUM6.91%EPSS 1%ileNVD2026-07-30
CVE-2026-20481In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalationMEDIUM6.01%EPSS 1%ileNVD2026-08-03
CVE-2026-20485In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pMEDIUM6.01%EPSS 1%ileNVD2026-08-03
CVE-2026-20497In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalationMEDIUM6.01%EPSS 1%ileNVD2026-08-03
CVE-2026-20498In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local esMEDIUM6.01%EPSS 1%ileNVD2026-08-03
CVE-2026-47768nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-MEDIUM5.51%EPSS 1%ileNVD2026-07-28
CVE-2026-59919Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.FinaMEDIUM5.51%EPSS 1%ileNVD2026-07-29
CVE-2026-15430Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, MEDIUM6.21%EPSS 1%ileNVD2026-08-03
CVE-2026-17932Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potMEDIUM5.51%EPSS 1%ileNVD2026-07-30
CVE-2026-20472In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servicMEDIUM4.41%EPSS 1%ileNVD2026-08-03
CVE-2026-20496In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local informationMEDIUM4.41%EPSS 1%ileNVD2026-08-03
CVE-2026-17966Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain MEDIUM6.21%EPSS 1%ileNVD2026-07-30
CVE-2025-15631A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing alMEDIUM5.71%EPSS 1%ileNVD2026-08-03
CVE-2026-20478In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of MEDIUM5.51%EPSS 1%ileNVD2026-08-03
CVE-2026-20480In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of MEDIUM5.51%EPSS 1%ileNVD2026-08-03
CVE-2026-20491In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of serMEDIUM5.51%EPSS 1%ileNVD2026-08-03
CVE-2026-20494In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discMEDIUM5.51%EPSS 1%ileNVD2026-08-03
CVE-2026-34490Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacMEDIUM4.81%EPSS 1%ileNVD2026-07-31
CVE-2025-15629A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicatiMEDIUM6.91%EPSS 1%ileNVD2026-08-03
CVE-2026-18257Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certMEDIUM5.61%EPSS 1%ileNVD2026-07-29
CVE-2026-17973Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain MEDIUM5.51%EPSS 1%ileNVD2026-07-30
CVE-2026-68563A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and thMEDIUM5.51%EPSS 1%ileNVD2026-07-30
CVE-2026-12259In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to MEDIUM5.31%EPSS 1%ileNVD2026-08-03
CVE-2026-20486In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalationMEDIUM4.41%EPSS 1%ileNVD2026-08-03
CVE-2026-20490In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servicMEDIUM4.41%EPSS 1%ileNVD2026-08-03
CVE-2026-20493In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of serviMEDIUM4.41%EPSS 1%ileNVD2026-08-03
CVE-2026-20495In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local eMEDIUM4.41%EPSS 1%ileNVD2026-08-03
CVE-2026-56609HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was usingMEDIUM4.81%EPSS 1%ileNVD2026-08-03
CVE-2026-18477A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local aMEDIUM4.41%EPSS 1%ileNVD2026-08-03
CVE-2026-44105The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local aMEDIUM5.81%EPSS 1%ileNVD2026-07-30
CVE-2026-20474In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of MEDIUM6.00%EPSS 0%ileNVD2026-08-03
CVE-2026-17996Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypasMEDIUM6.20%EPSS 0%ileNVD2026-07-30
CVE-2026-59327Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain stringMEDIUM4.40%EPSS 0%ileNVD2026-07-30
CVE-2026-11835Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateReseMEDIUM5.60%EPSS 0%ileNVD2026-08-04
CVE-2026-20492In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial MEDIUM5.50%EPSS 0%ileNVD2026-08-03
CVE-2026-18321Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpdMEDIUM4.70%EPSS 0%ileNVD2026-07-31
CVE-2026-4932IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physicaMEDIUM4.20%EPSS 0%ileNVD2026-07-28
CVE-2026-56850A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cliMEDIUM4.10%EPSS 0%ileNVD2026-07-30
CVE-2026-67433Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. InMEDIUM5.80%EPSS 0%ileNVD2026-07-29
CVE-2026-61387In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation faMEDIUM6.9NVD2026-08-04
CVE-2026-63248In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anMEDIUM6.9NVD2026-08-04
CVE-2026-18401The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in SMEDIUM6.9NVD2026-08-04
CVE-2026-15337An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()MEDIUM6.9NVD2026-08-04
CVE-2026-15830An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeomeMEDIUM6.9NVD2026-08-04
GHSA-vg6v-j97m-h5xq@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request MEDIUM6.8GitHub2026-07-28
CVE-2026-24076Memory Corruption when processing registry values with incorrect types using a direct query method.MEDIUM6.7NVD2026-08-04
CVE-2026-48121@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for stoMEDIUM6.7NVD2026-08-04
GHSA-hc4m-q9jh-xw4jnono-cli'scregistry pack verification can fail open when provenance metadata is absentMEDIUM6.6GitHub2026-07-28
CVE-2026-70368A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log mMEDIUM6.5NVD2026-08-04
CVE-2026-24077Information Disclosure when processing wireless network channel switch information with improperly formatted length fielMEDIUM6.5NVD2026-08-04
CVE-2026-24078Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.MEDIUM6.5NVD2026-08-04
GHSA-539m-9xh6-q6rrGitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary fileMEDIUM6.5GitHub2026-08-03
GHSA-6xx4-9wp6-65p7skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill sourceMEDIUM6.5GitHub2026-07-28
DSA 6410-1[SECURITY] [DSA 6410-1] libssh security updateMEDIUM6.5Debian2026-08-02
CVE-2026-66883Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize moduMEDIUM6.3NVD2026-08-04
CVE-2026-17872Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to poteMEDIUM6.10%EPSS 0%ileNVD2026-07-30
CVE-2026-10032The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the UMEDIUM6.1NVD2026-08-04
CVE-2026-49446Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnelMEDIUM6.1GitHub2026-07-28
CVE-2026-18770A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unMEDIUM5.5NVD2026-08-04
USN-8620-4USN-8620-4: Linux kernel (Intel IoTG) vulnerabilitiesMEDIUM5.5Ubuntu2026-07-31
USN-8620-3USN-8620-3: Linux kernel (Intel IoTG) vulnerabilitiesMEDIUM5.5Ubuntu2026-07-31
USN-8620-2USN-8620-2: Linux kernel (Azure FIPS) vulnerabilitiesMEDIUM5.5Ubuntu2026-07-29
FG-IR-26-139Linux Kernel Vulnerability copy.fail - CVE-2026-31431MEDIUM5.5Fortinet2026-05-13
CVE-2026-70367A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS prMEDIUM5.4NVD2026-08-04
GHSA-p538-c434-8v24GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countMEDIUM5.4GitHub2026-08-03
CVE-2026-64630A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.MEDIUM5.3NVD2026-08-04
CVE-2026-69207Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersMEDIUM5.3GitHub2026-08-03
CVE-2026-67196Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inMEDIUM5.1NVD2026-08-04
CVE-2026-15920An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(MEDIUM5.1NVD2026-08-04
CVE-2026-14337Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a useMEDIUM4.6NVD2026-08-04
GHSA-pqh8-p93p-2rx7@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQLMEDIUM4.3GitHub2026-07-31
GHSA-xrmj-5g4g-8987@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notificationMEDIUM4.2GitHub2026-07-31
CVE-2026-18018Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to pMEDIUM4.00%EPSS 0%ileNVD2026-07-30
CVE-2016-1000305guard-livereload has a directory traversal vulnerabilityMEDIUMGitHub2026-07-31
CVE-2026-68743CVE-2026-68743MEDIUMRed Hat2026-08-03
GHSA-hp74-gm6m-2qm5Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT frMEDIUMGitHub2026-07-28
GHSA-wchh-9x6h-7f6polm dependency deprecation: CVE-2022-39255 and CVE-2024-45193MEDIUMGitHub2026-07-29
GHSA-2364-jh4q-m9vmFlowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpointMEDIUMGitHub2026-08-04
GHSA-3whf-vgf2-9w6gzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth LimitMEDIUMGitHub2026-07-31
CVE-2026-18590A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adLOW2.162%EPSS 62%ileNVD2026-08-03
CVE-2026-55555Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack thrLOW2.340%EPSS 40%ileNVD2026-07-28
CVE-2026-18645A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sysLOW2.135%EPSS 35%ileNVD2026-08-03
CVE-2026-41709VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to performLOW2.731%EPSS 31%ileNVD2026-07-30
CVE-2026-18631A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig LOW2.131%EPSS 31%ileNVD2026-08-03
CVE-2026-18632A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of LOW2.130%EPSS 30%ileNVD2026-08-03
CVE-2026-18644A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /LOW2.130%EPSS 30%ileNVD2026-08-03
CVE-2026-58044A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ouLOW3.720%EPSS 20%ileNVD2026-08-04
CVE-2026-55554Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boLOW2.320%EPSS 20%ileNVD2026-07-28
CVE-2026-18593A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/teLOW2.918%EPSS 18%ileNVD2026-08-03
CVE-2026-68980Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throuLOW2.318%EPSS 18%ileNVD2026-08-03
CVE-2026-18721A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the fileLOW2.116%EPSS 16%ileNVD2026-08-04
CVE-2026-18682A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /apiLOW1.316%EPSS 16%ileNVD2026-08-03
CVE-2026-14222The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connLOW3.815%EPSS 15%ileNVD2026-07-30
CVE-2026-14188The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one oLOW2.715%EPSS 15%ileNVD2026-07-30
CVE-2026-53607@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host headerLOW3.713%EPSS 13%ileGitHub2026-07-31
CVE-2025-14562GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1LOW3.113%EPSS 13%ileNVD2026-07-29
CVE-2026-18206A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.LOW3.712%EPSS 12%ileNVD2026-07-31
CVE-2026-46712Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain LOW2.312%EPSS 12%ileNVD2026-08-03
CVE-2026-55403datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generLOW3.712%EPSS 12%ileNVD2026-07-28
CVE-2026-18722A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvLOW2.112%EPSS 12%ileNVD2026-08-04
CVE-2026-55825Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can LOW3.111%EPSS 11%ileNVD2026-07-31
CVE-2025-71402better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ouLOW2.011%EPSS 11%ileNVD2026-08-01
CVE-2026-17702Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisLOW3.111%EPSS 11%ileNVD2026-07-30
CVE-2026-17715Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinceLOW3.111%EPSS 11%ileNVD2026-07-30
CVE-2026-67350Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to reLOW2.111%EPSS 11%ileNVD2026-07-31
CVE-2026-18592A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of LOW2.010%EPSS 10%ileNVD2026-08-03
CVE-2026-15054The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submissLOW3.710%EPSS 10%ileNVD2026-07-30
CVE-2026-18723A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the fileLOW2.110%EPSS 10%ileNVD2026-08-04
CVE-2026-63235An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the seLOW3.710%EPSS 10%ileNVD2026-07-29
CVE-2026-56568HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It invLOW3.79%EPSS 9%ileNVD2026-07-31
CVE-2026-14221The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-LOW3.89%EPSS 9%ileNVD2026-07-30
CVE-2026-18209A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flowLOW3.49%EPSS 9%ileNVD2026-07-31
CVE-2026-18217A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solutionLOW3.49%EPSS 9%ileNVD2026-07-31
CVE-2026-18719A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compoLOW2.19%EPSS 9%ileNVD2026-08-04
CVE-2026-17902Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leLOW3.59%EPSS 9%ileNVD2026-07-30
CVE-2026-57232Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end modLOW3.18%EPSS 8%ileNVD2026-07-31
CVE-2026-10031SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-direcLOW2.38%EPSS 8%ileNVD2026-07-30
CVE-2026-15381The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SLOW3.78%EPSS 8%ileNVD2026-07-31
CVE-2026-14849The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files itLOW3.78%EPSS 8%ileNVD2026-07-31
CVE-2026-56570HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: VaLOW3.77%EPSS 7%ileNVD2026-07-31
CVE-2026-17720Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had cLOW3.17%EPSS 7%ileNVD2026-07-30
CVE-2026-17732Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origLOW3.17%EPSS 7%ileNVD2026-07-30
CVE-2026-17826Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker LOW3.17%EPSS 7%ileNVD2026-07-30
CVE-2026-17980Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convLOW3.17%EPSS 7%ileNVD2026-07-30
CVE-2026-56571HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptionsLOW3.77%EPSS 7%ileNVD2026-07-31
CVE-2026-18648A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDatLOW1.97%EPSS 7%ileNVD2026-08-03
CVE-2026-58039A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wrLOW3.37%EPSS 7%ileNVD2026-07-31
CVE-2026-63236An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,LOW3.76%EPSS 6%ileNVD2026-07-29
CVE-2026-14862The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloLOW3.76%EPSS 6%ileNVD2026-07-31
CVE-2026-14927The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership cheLOW3.76%EPSS 6%ileNVD2026-07-31
CVE-2026-56608HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acceLOW3.76%EPSS 6%ileNVD2026-08-03
CVE-2026-18569A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat BuiLOW3.76%EPSS 6%ileNVD2026-08-04
CVE-2026-56847A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside LOW3.36%EPSS 6%ileNVD2026-07-30
CVE-2026-55824Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth creLOW2.65%EPSS 5%ileNVD2026-07-31
CVE-2026-18000Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who LOW3.15%EPSS 5%ileNVD2026-07-30
CVE-2026-66401FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that failLOW2.45%EPSS 5%ileNVD2026-08-01
CVE-2026-10774Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/blueLOW2.45%EPSS 5%ileNVD2026-08-02
CVE-2026-63545Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. TheyLOW2.45%EPSS 5%ileNVD2026-08-03
CVE-2026-11366The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticaLOW3.74%EPSS 4%ileNVD2026-08-04
CVE-2026-17957Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisLOW3.14%EPSS 4%ileNVD2026-07-30
CVE-2026-13393The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-itemLOW3.54%EPSS 4%ileNVD2026-07-31
CVE-2026-65636Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to injLOW2.14%EPSS 4%ileNVD2026-07-31
CVE-2026-63241An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course complLOW3.14%EPSS 4%ileNVD2026-07-29
CVE-2026-16070The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updLOW2.73%EPSS 3%ileNVD2026-08-04
CVE-2026-63228An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content LOW2.63%EPSS 3%ileNVD2026-07-29
CVE-2026-17997Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compLOW3.13%EPSS 3%ileNVD2026-07-30
CVE-2026-17766Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a locLOW3.32%EPSS 2%ileNVD2026-07-30
CVE-2026-54522MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::BLOW2.12%EPSS 2%ileNVD2026-07-30
CVE-2026-50568Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escapeLOW3.62%EPSS 2%ileGitHub2026-07-28
CVE-2026-18581A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of thLOW1.92%EPSS 2%ileNVD2026-08-03
CVE-2026-62995joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standarLOW2.31%EPSS 1%ileNVD2026-07-29
CVE-2026-54620sqlite3-ruby has Use-After-Free in SQLite Aggregate Function CallbacksLOW1%EPSS 1%ileGitHub2026-07-28
CVE-2026-54619sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different ArityLOW1%EPSS 1%ileGitHub2026-07-28
CVE-2026-52791fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C brancLOW2.01%EPSS 1%ileNVD2026-07-29
CVE-2026-18604A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DLOW1.91%EPSS 1%ileNVD2026-08-03
CVE-2026-10684In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coreduLOW3.01%EPSS 1%ileNVD2026-07-29
CVE-2026-68744A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space forLOW3.31%EPSS 1%ileNVD2026-08-04
CVE-2026-59326The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variLOW3.31%EPSS 1%ileNVD2026-07-30
CVE-2026-17860Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local LOW3.31%EPSS 1%ileNVD2026-07-30
CVE-2026-18739A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, whenLOW2.51%EPSS 1%ileNVD2026-08-04
CVE-2026-17984Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to lLOW3.31%EPSS 1%ileNVD2026-07-30
CVE-2026-54787sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle sLOW3.11%EPSS 1%ileNVD2026-07-31
CVE-2026-18011Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker tLOW2.41%EPSS 1%ileNVD2026-07-30
CVE-2026-2482IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which cLOW3.10%EPSS 0%ileNVD2026-07-29
CVE-2026-11836Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) inLOW1.80%EPSS 0%ileNVD2026-08-04
CVE-2026-18591A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability iLOW0.90%EPSS 0%ileNVD2026-08-03
GHSA-pc2w-4mq8-32qw@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gateLOW3.7GitHub2026-07-29
CVE-2026-66884Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback modLOW2.1NVD2026-08-04
CVE-2026-18766A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affectLOW2.1NVD2026-08-04
CVE-2026-18773A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_LOW2.1NVD2026-08-04
CVE-2026-18774A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agLOW2.1NVD2026-08-04
CVE-2026-18775A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browseLOW2.1NVD2026-08-04
CVE-2026-18784A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute LOW1.9NVD2026-08-04
CVE-2026-18785A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_CliLOW1.9NVD2026-08-04
GHSA-pmwx-rm49-xv39ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversalLOWGitHub2026-07-29
CVE-2026-52102An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exeUNKNOWN46%EPSS 46%ileNVD2026-08-03
CVE-2026-15244The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before conUNKNOWN40%EPSS 40%ileNVD2026-08-01
CVE-2026-51190The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawUNKNOWN39%EPSS 39%ileNVD2026-08-03
CVE-2026-12872The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload UNKNOWN20%EPSS 20%ileNVD2026-08-03
CVE-2026-15932The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment downloadUNKNOWN17%EPSS 17%ileNVD2026-08-01
CVE-2025-15672The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializaUNKNOWN13%EPSS 13%ileNVD2026-08-03
CVE-2026-16250The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unUNKNOWN13%EPSS 13%ileNVD2026-08-03
CVE-2026-16062The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-coUNKNOWN11%EPSS 11%ileNVD2026-08-02
CVE-2026-17735Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker UNKNOWN11%EPSS 11%ileNVD2026-07-30
CVE-2026-17913Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker UNKNOWN11%EPSS 11%ileNVD2026-07-30
CVE-2026-16060The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contenUNKNOWN11%EPSS 11%ileNVD2026-08-03
CVE-2026-16618The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file contenUNKNOWN10%EPSS 10%ileNVD2026-08-04
CVE-2026-52520Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/UNKNOWN10%EPSS 10%ileNVD2026-08-03
CVE-2026-14557The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token iUNKNOWN8%EPSS 8%ileNVD2026-08-03
CVE-2026-14920## SummaryUNKNOWN8%EPSS 8%ileNVD2026-08-02
CVE-2022-4994In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __UNKNOWN8%EPSS 8%ileNVD2026-07-30
CVE-2026-11882The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routesUNKNOWN7%EPSS 7%ileNVD2026-08-01
CVE-2026-13725The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not validate a nonce or user UNKNOWN7%EPSS 7%ileNVD2026-08-01
CVE-2026-64565In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcUNKNOWN7%EPSS 7%ileNVD2026-08-04
CVE-2026-15248The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment UNKNOWN6%EPSS 6%ileNVD2026-08-02
CVE-2026-14817The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cerUNKNOWN6%EPSS 6%ileNVD2026-08-02
CVE-2026-14824The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outpUNKNOWN6%EPSS 6%ileNVD2026-08-04
CVE-2025-15673The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads anUNKNOWN6%EPSS 6%ileNVD2026-08-03
CVE-2026-16068The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and doesUNKNOWN6%EPSS 6%ileNVD2026-08-04
CVE-2026-67974A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7UNKNOWN5%EPSS 5%ileNVD2026-08-03
CVE-2026-14872The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and eUNKNOWN5%EPSS 5%ileNVD2026-08-04
CVE-2026-64561In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* mUNKNOWN5%EPSS 5%ileNVD2026-08-04
CVE-2026-64562In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR frUNKNOWN5%EPSS 5%ileNVD2026-08-04
CVE-2026-64564In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-UNKNOWN5%EPSS 5%ileNVD2026-08-04
CVE-2026-64563In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rUNKNOWN5%EPSS 5%ileNVD2026-08-04
CVE-2026-15233The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML atUNKNOWN5%EPSS 5%ileNVD2026-08-04
CVE-2026-16623The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a gUNKNOWN5%EPSS 5%ileNVD2026-08-04
CVE-2026-16256The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions avUNKNOWN5%EPSS 5%ileNVD2026-08-02
CVE-2026-52521A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via thUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-67969An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset vUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-67973An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying fUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-67975Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new sUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-67977An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to causeUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-14840The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clienUNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-67972An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and dataUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-67976The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, alloUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-67673A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability isUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2025-69944kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vieUNKNOWN4%EPSS 4%ileNVD2026-07-29
CVE-2026-11872The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in UNKNOWN4%EPSS 4%ileNVD2026-08-02
CVE-2026-51775SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicatiUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-15231The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to accUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-13157The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import UNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-13158The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content impoUNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-67970Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive coUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-67978An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittinUNKNOWN4%EPSS 4%ileNVD2026-08-03
CVE-2026-14309The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been UNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-14596The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as theUNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-14822The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of iUNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-14836The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-resetUNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-15368The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after useUNKNOWN4%EPSS 4%ileNVD2026-08-01
CVE-2026-15958The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its UNKNOWN4%EPSS 4%ileNVD2026-08-04
CVE-2026-14939The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchiUNKNOWN3%EPSS 3%ileNVD2026-08-04
CVE-2026-13604The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emitUNKNOWN3%EPSS 3%ileNVD2026-08-01
CVE-2026-14195The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning pUNKNOWN3%EPSS 3%ileNVD2026-08-01
CVE-2026-14197The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticketUNKNOWN3%EPSS 3%ileNVD2026-08-01
CVE-2026-14214The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wrUNKNOWN3%EPSS 3%ileNVD2026-08-01
CVE-2026-14823The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of itUNKNOWN3%EPSS 3%ileNVD2026-08-01
CVE-2026-14938The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation beUNKNOWN3%EPSS 3%ileNVD2026-08-02
CVE-2026-15939The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST UNKNOWN3%EPSS 3%ileNVD2026-08-02
CVE-2026-16042The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowinUNKNOWN3%EPSS 3%ileNVD2026-08-02
CVE-2026-16291The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befoUNKNOWN3%EPSS 3%ileNVD2026-08-02
CVE-2026-16057The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of itsUNKNOWN3%EPSS 3%ileNVD2026-08-03
CVE-2026-16274The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX actionUNKNOWN3%EPSS 3%ileNVD2026-08-03
CVE-2026-16276The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returnsUNKNOWN3%EPSS 3%ileNVD2026-08-03
CVE-2026-14848The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified thUNKNOWN3%EPSS 3%ileNVD2026-08-04
CVE-2026-16035The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP UNKNOWN3%EPSS 3%ileNVD2026-08-04
CVE-2026-16056The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlerUNKNOWN3%EPSS 3%ileNVD2026-08-04
CVE-2026-64531RE: OVSwrap (CVE-2026-64531): Linux kernel/OVS local root vulnerabilityUNKNOWN3%EPSS 3%ileOSS-Security2026-08-01
CVE-2026-14239The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken froUNKNOWN3%EPSS 3%ileNVD2026-07-30
CVE-2026-10827The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usiUNKNOWN2%EPSS 2%ileNVD2026-08-01
CVE-2026-12586The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-resetUNKNOWN2%EPSS 2%ileNVD2026-08-02
CVE-2026-0011[NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial ofUNKNOWN2%EPSS 2%ileOSS-Security2026-07-29
CVE-2026-16292The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metaUNKNOWN1%EPSS 1%ileNVD2026-08-02
CVE-2026-13729The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administratUNKNOWN1%EPSS 1%ileNVD2026-08-01
CVE-2026-66051Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-07-29
CVE-2026-67188Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-07-29
CVE-2026-66737Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-07-29
CVE-2026-18060Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All rUNKNOWNNVD2026-07-29
CVE-2026-16339Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-07-29
CVE-2026-51290Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-30
CVE-2026-51291Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-30
CVE-2026-51292Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-30
CVE-2026-51293Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-30
CVE-2026-51294Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-30
CVE-2026-51295Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-30
CVE-2026-51272Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-30
CVE-2026-6889Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-07-31
CVE-2026-6890Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-07-31
CVE-2026-17592Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All rUNKNOWNNVD2026-07-31
CVE-2026-68574Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly resUNKNOWNNVD2026-07-31
CVE-2026-68575Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly resUNKNOWNNVD2026-07-31
CVE-2026-68576Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly resUNKNOWNNVD2026-07-31
CVE-2026-68577Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly resUNKNOWNNVD2026-07-31
CVE-2026-9611Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All rUNKNOWNNVD2026-07-31
CVE-2026-51229Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51230Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51231Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51232Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51233Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51234Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51236Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51237Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51238Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51239Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51240Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51241Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51242Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51243Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51245Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51246Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51247Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51248Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51249Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51250Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51253Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51255Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51256Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51257Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51258Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51262Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51264Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51265Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51276Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51277Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51278Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51279Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51280Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51281Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51282Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51283Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51284Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51285Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51286Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51287Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51288Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51289Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51299Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-51301Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further invUNKNOWNNVD2026-07-31
CVE-2026-10772Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigneUNKNOWNNVD2026-08-01
CVE-2026-17002Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-08-01
CVE-2026-68869Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a securitUNKNOWNNVD2026-08-03
CVE-2026-18809Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153UNKNOWNNVD2026-08-04
CVE-2026-70369Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-conUNKNOWNNVD2026-08-04
CVE-2026-70370Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and ColuUNKNOWNNVD2026-08-04
CVE-2026-70371Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request UNKNOWNNVD2026-08-04
CVE-2026-70372Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request paUNKNOWNNVD2026-08-04
CVE-2026-70373Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concUNKNOWNNVD2026-08-04
CVE-2025-29296H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 VUNKNOWNNVD2026-08-04
CVE-2026-55707[OSSA-2026-032] OpenStack Neutron: Subnetpool onboarding cross-project subnet mutation (CVE-2026-55707)UNKNOWNOSS-Security2026-07-29
USN-8625-1USN-8625-1: OpenSSL vulnerabilityUNKNOWNUbuntu2026-07-30
USN-8624-1USN-8624-1: Sinatra vulnerabilityUNKNOWNUbuntu2026-07-29
USN-8561-2USN-8561-2: FreeRDP regressionUNKNOWNUbuntu2026-07-28
DSA 6403-1[SECURITY] [DSA 6403-1] nss security updateUNKNOWNDebian2026-07-29
DSA 6407-1[SECURITY] [DSA 6407-1] incus security updateUNKNOWNDebian2026-07-31
DSA 6409-1[SECURITY] [DSA 6409-1] libgd2 security updateUNKNOWNDebian2026-08-01
OSS-20260804-1Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-04
OSS-20260804-2Bouncy Castle 1.85 release fixes 32 CVEsUNKNOWNOSS-Security2026-08-04
OSS-20260804-3Re: Bouncy Castle 1.85 release fixes 32 CVEsUNKNOWNOSS-Security2026-08-04
OSS-20260804-4Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-04
OSS-20260804-5Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-04
OSS-20260804-7Re: Bouncy Castle 1.85 release fixes 32 CVEsUNKNOWNOSS-Security2026-08-04
OSS-20260803-1Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-03
OSS-20260803-2mpg123 release 1.33.7 with lots of security-relevant fixesUNKNOWNOSS-Security2026-08-03
OSS-20260803-3Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-03
OSS-20260803-6Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-03
OSS-20260803-7Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-03
OSS-20260803-9Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-03
OSS-20260802-2[CVE requested] iwd &lt;= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validatioUNKNOWNOSS-Security2026-08-02
OSS-20260802-3Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-02
OSS-20260802-4Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-02
OSS-20260802-5Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-02
OSS-20260802-6Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-02
OSS-20260801-2Rejected CVE reports against SQLite, libraw, ESP32-audioI2SUNKNOWNOSS-Security2026-08-01
OSS-20260801-4Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-01
OSS-20260801-5Re: 33 Vulnerabilities in cJSONUNKNOWNOSS-Security2026-08-01
OSS-20260801-7Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-08-01
OSS-20260801-9Re: 33 Vulnerabilities in cJSONUNKNOWNOSS-Security2026-08-01
OSS-20260731-1Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-4Re: 33 Vulnerabilities in cJSONUNKNOWNOSS-Security2026-07-31
OSS-20260731-5Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-6Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-7Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-8Re: 33 Vulnerabilities in cJSONUNKNOWNOSS-Security2026-07-31
OSS-20260731-9Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-10Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-11Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-12Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-13Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-14Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-15Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260731-16Re: Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-31
OSS-20260730-2233 Vulnerabilities in cJSONUNKNOWNOSS-Security2026-07-30
OSS-20260730-25o6 Automation open62541: multiple CISA-coordinated OPC UA vulnerabilitiesUNKNOWNOSS-Security2026-07-30
OSS-20260730-26Re: 33 Vulnerabilities in cJSONUNKNOWNOSS-Security2026-07-30
OSS-20260730-27Some Changes to GNOME Security TrackingUNKNOWNOSS-Security2026-07-30
OSS-20260730-29PHP 30 July 2026 security releasesUNKNOWNOSS-Security2026-07-30
OSS-20260729-2Re: Fwd: Heads-up: Upcoming important Samba security releases on 2026-07-28UNKNOWNOSS-Security2026-07-29
OSS-20260729-6Fwd: Node.js security updates for all active release lines, June 2026UNKNOWNOSS-Security2026-07-29
OSS-20260729-10Re: Fwd: Node.js security updates for all active release lines, June 2026UNKNOWNOSS-Security2026-07-29
GHSA-g6cj-pr64-35w5GHSA-g6cj-pr64-35w5UNKNOWNOSV2026-08-04
GHSA-jwv3-5hgf-82wwGHSA-jwv3-5hgf-82wwUNKNOWNOSV2026-08-04
GHSA-m2h6-j472-rp4cGHSA-m2h6-j472-rp4cUNKNOWNOSV2026-08-04
PYSEC-2026-3552PYSEC-2026-3552UNKNOWNOSV2026-08-04
PYSEC-2026-3553PYSEC-2026-3553UNKNOWNOSV2026-08-04
PYSEC-2026-3554PYSEC-2026-3554UNKNOWNOSV2026-08-04
GHSA-993g-76c3-p5m4GHSA-993g-76c3-p5m4UNKNOWNOSV2026-07-31
GHSA-fhv5-28vv-h8m8GHSA-fhv5-28vv-h8m8UNKNOWNOSV2026-07-31
GHSA-42h9-826w-cgv3GHSA-42h9-826w-cgv3UNKNOWNOSV2026-08-02
GHSA-7q8q-rj6j-mhjqGHSA-7q8q-rj6j-mhjqUNKNOWNOSV2026-08-02
GHSA-f4gw-2p7v-4548GHSA-f4gw-2p7v-4548UNKNOWNOSV2026-08-02
GHSA-gcfj-64vw-6mp9GHSA-gcfj-64vw-6mp9UNKNOWNOSV2026-08-02
GHSA-hcpx-6fm6-wx23GHSA-hcpx-6fm6-wx23UNKNOWNOSV2026-08-02
GHSA-jqh4-m9w3-8hp9GHSA-jqh4-m9w3-8hp9UNKNOWNOSV2026-08-02
GHSA-mmx7-hfxf-jppxGHSA-mmx7-hfxf-jppxUNKNOWNOSV2026-08-02
GHSA-mwf2-3pr3-8698GHSA-mwf2-3pr3-8698UNKNOWNOSV2026-08-02
GHSA-pmv8-rq9r-6j72GHSA-pmv8-rq9r-6j72UNKNOWNOSV2026-08-02
GHSA-xj6q-8x83-jv6gGHSA-xj6q-8x83-jv6gUNKNOWNOSV2026-08-02
GHSA-659m-px2c-25wjGHSA-659m-px2c-25wjUNKNOWNOSV2026-07-31
GHSA-5gvw-p9qm-jgwhGHSA-5gvw-p9qm-jgwhUNKNOWNOSV2026-08-03
GHSA-rmj7-2vxq-3g9fGHSA-rmj7-2vxq-3g9fUNKNOWNOSV2026-07-30
FG-IR-26-154Buffer overread in authd and wad daemonUNKNOWNFortinet2026-07-14
FG-IR-26-149Cross-Site Scripting in Domain parameterUNKNOWNFortinet2026-07-14
FG-IR-26-152Header injection in Web Filter warning pageUNKNOWNFortinet2026-07-14
FG-IR-26-153Header injection in captive portal authentication formUNKNOWNFortinet2026-07-14
FG-IR-26-147Missed certificate verification in AD Connector communication with FortiClient EMSUNKNOWNFortinet2026-07-14
FG-IR-26-146Out of bounds read in GUIUNKNOWNFortinet2026-07-14
FG-IR-26-151Path traversal in CLI command allows deletion of root file systemUNKNOWNFortinet2026-07-14
FG-IR-26-150SSL-VPN Reflected XSSUNKNOWNFortinet2026-07-14
FG-IR-26-148Stack Buffer Overflow in Log ReportUNKNOWNFortinet2026-07-14
FG-IR-26-155Supers override fails to properly override supervisor addressUNKNOWNFortinet2026-07-14
FG-IR-26-145Unauthenticated VNC access exposed on all interfacesUNKNOWNFortinet2026-07-14
FG-IR-25-1052LDAP authentication bypass in Agentless VPN and FSSOUNKNOWNFortinet2026-02-10
FG-IR-26-140Improper access control in API endpointsUNKNOWNFortinet2026-06-09
FG-IR-26-143Restricted CLI escape using LuaUNKNOWNFortinet2026-06-09
FG-IR-26-141Second-Order OS Command Injection via JSON Input on start vnc featureUNKNOWNFortinet2026-06-09
FG-IR-24-452Insertion of Sensitive 2FA Information in logs and debug commandUNKNOWNFortinet2025-10-14
FG-IR-25-545Trusted hosts bypass via SSHUNKNOWNFortinet2025-11-18
FG-IR-26-138Arbitrary log file read in administrative interfaceUNKNOWNFortinet2026-05-12
FG-IR-26-131Command injection in CLIUNKNOWNFortinet2026-05-12
FG-IR-26-137DoS due to unsafe function in signal handlerUNKNOWNFortinet2026-05-12
FG-IR-26-129Hardcoded Encryption Key Used for VPN Saved PasswordsUNKNOWNFortinet2026-05-12
FG-IR-26-128Improper access control on API endpointsUNKNOWNFortinet2026-05-12
FG-IR-26-136Incorrect global authorizationUNKNOWNFortinet2026-05-12
FG-IR-26-133OS command injection in CLIUNKNOWNFortinet2026-05-12
FG-IR-26-130OTP Disclosure via Exported TokenContentProviderUNKNOWNFortinet2026-05-12
FG-IR-26-123Out-of-bounds access in CAPWAP daemonUNKNOWNFortinet2026-05-12
FG-IR-26-132SQL command injection in administrative portalUNKNOWNFortinet2026-05-12
FG-IR-26-134User controlled SQL commandsUNKNOWNFortinet2026-05-12
FG-IR-26-127Out-Of-Bounds Write in administrative interfaceUNKNOWNFortinet2026-04-15
FG-IR-26-1012FA request can be replayed without a valid token after one successful requestUNKNOWNFortinet2026-04-14
FG-IR-26-115Arbitrary directory delete on vmimages delete featureUNKNOWNFortinet2026-04-14
FG-IR-26-126Axios npm Package CompromisedUNKNOWNFortinet2026-04-14
FG-IR-26-105Clear-text credentials retrievable with IP modification for LDAPUNKNOWNFortinet2026-04-14
FG-IR-26-104Clear-text credentials retrievable with IP modification for connectorsUNKNOWNFortinet2026-04-14
FG-IR-26-106Cleartext Credentials in response for API endpointsUNKNOWNFortinet2026-04-14
FG-IR-26-113Credential disclosure in LDAP configuration web page.UNKNOWNFortinet2026-04-14
FG-IR-26-107Hardcoded symmetric encryption key for PostgresqlUNKNOWNFortinet2026-04-14
FG-IR-26-121Heap-based buffer overflow in oftpd daemonUNKNOWNFortinet2026-04-14
FG-IR-26-108Integer Overflow Denial of Service in administrative interfaceUNKNOWNFortinet2026-04-14
FG-IR-26-125Missing Authentication for critical function in CAPWAP daemonUNKNOWNFortinet2026-04-14
FG-IR-26-114Multiple Path traversals in CLIUNKNOWNFortinet2026-04-14
FG-IR-26-102Multiple SQL InjectionsUNKNOWNFortinet2026-04-14
FG-IR-26-110Multiple Stored XSSUNKNOWNFortinet2026-04-14
FG-IR-26-100OS Command Injection through API endpointUNKNOWNFortinet2026-04-14
FG-IR-26-118Open Redirection via Import CSV optionUNKNOWNFortinet2026-04-14
FG-IR-26-122Path Traversal in CLIUNKNOWNFortinet2026-04-14
OSSA-2026-031OSSA-2026-031: Swift proxy denial of service via Accept headerUNKNOWNOpenStack2026-07-28
OSSA-2026-030OSSA-2026-030: Swift S3API header authorization bypassUNKNOWNOpenStack2026-07-28
OSSN-0103OSSN-0103: Manila resource-lock list trusts a foreign project_id filterUNKNOWNOpenStack2026-08-03

Updated 2026-08-04. Sources: NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB and more. JSON API available for automation.