Security Database
All CVEs
Browse all security vulnerabilities from 1999 to present
CVEs published in 2026-08
| CVE ID | Published | Updated | Assigner | Description | |
|---|---|---|---|---|---|
| CVE-2026-54214 | 2026-08-07 09:47:55 | 2026-08-07 11:26:12 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable… | Details |
| CVE-2026-54215 | 2026-08-07 09:48:16 | 2026-08-07 11:25:12 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox contains an… | Details |
| CVE-2026-54216 | 2026-08-07 09:48:46 | 2026-08-07 11:24:31 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application contains a… | Details |
| CVE-2026-54217 | 2026-08-07 09:49:02 | 2026-08-07 11:23:53 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable… | Details |
| CVE-2026-54218 | 2026-08-07 09:49:24 | 2026-08-07 11:22:37 | NCSC.ch | Use of hard-coded cryptographic key vulnerability in Tobit… | Details |
| CVE-2026-54205 | 2026-08-07 10:02:28 | 2026-08-07 11:19:35 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox 's link storing… | Details |
| CVE-2026-19127 | 2026-08-06 17:02:44 | 2026-08-07 10:47:07 | postiz | An issue in the billing and license activation… | Details |
| CVE-2026-15816 | 2026-08-07 10:33:33 | 2026-08-07 10:33:33 | redhat | A flaw was found in dracut. The die()… | Details |
| CVE-2026-49004 | 2026-08-05 06:19:01 | 2026-08-07 10:24:54 | zte | The built-in PostgreSQL service on the mobile device… | Details |
| CVE-2026-54213 | 2026-08-07 09:47:34 | 2026-08-07 09:47:34 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application exposes a… | Details |
| CVE-2026-54212 | 2026-08-07 09:47:12 | 2026-08-07 09:47:12 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application implements an… | Details |
| CVE-2026-54211 | 2026-08-07 09:46:50 | 2026-08-07 09:46:50 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html”… | Details |
| CVE-2026-54210 | 2026-08-07 09:46:23 | 2026-08-07 09:46:23 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application implements various… | Details |
| CVE-2026-54209 | 2026-08-07 09:45:53 | 2026-08-07 09:45:53 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application handles password… | Details |
| CVE-2026-54208 | 2026-08-07 09:45:40 | 2026-08-07 09:45:40 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable… | Details |
| CVE-2026-54207 | 2026-08-07 09:45:18 | 2026-08-07 09:45:18 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox 's move archive… | Details |
| CVE-2026-54206 | 2026-08-07 09:44:58 | 2026-08-07 09:44:58 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox 's sending email,… | Details |
| CVE-2026-54204 | 2026-08-07 09:44:38 | 2026-08-07 09:44:38 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox 's search functionality… | Details |
| CVE-2026-54203 | 2026-08-07 09:44:13 | 2026-08-07 09:44:13 | NCSC.ch | Memory Leak to an Unauthorized Actor vulnerability in… | Details |
| CVE-2026-54202 | 2026-08-07 09:43:41 | 2026-08-07 09:43:41 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox is vulnerable… | Details |
| CVE-2026-54201 | 2026-08-07 09:43:18 | 2026-08-07 09:43:18 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox does not… | Details |
| CVE-2026-54200 | 2026-08-07 09:41:49 | 2026-08-07 09:41:49 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox is vulnerable… | Details |
| CVE-2026-54199 | 2026-08-07 09:41:22 | 2026-08-07 09:41:22 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox is vulnerable… | Details |
| CVE-2026-12071 | 2026-08-07 09:40:52 | 2026-08-07 09:40:52 | NCSC.ch | The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect… | Details |
| CVE-2026-12070 | 2026-08-07 09:40:02 | 2026-08-07 09:40:02 | NCSC.ch | Tobit Laboratories AG TeamDavid's Webbox is vulnerable… | Details |
| CVE-2026-0931 | 2026-08-05 09:42:23 | 2026-08-07 09:30:07 | M-Files Corporation | Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows… | Details |
| CVE-2026-71559 | 2026-08-07 08:56:09 | 2026-08-07 08:56:09 | apache | Deserialization of Untrusted Data vulnerability in the Go… | Details |
| CVE-2026-71558 | 2026-08-07 08:54:56 | 2026-08-07 08:54:56 | apache | Heap type confusion vulnerability in Apache Fory C++… | Details |
| CVE-2026-16027 | 2026-08-07 07:14:12 | 2026-08-07 08:54:04 | TR-CERT | Server-Side request forgery (SSRF) vulnerability in Revenue Administration… | Details |
| CVE-2026-71560 | 2026-08-07 08:53:36 | 2026-08-07 08:53:36 | apache | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This… | Details |
| CVE-2026-9169 | 2026-08-07 08:47:13 | 2026-08-07 08:47:13 | NCSC.ch | DLL Search Order Hijacking in LUCID Vision Labs… | Details |
| CVE-2026-18938 | 2026-08-07 08:19:08 | 2026-08-07 08:19:08 | redhat | A flaw was found in p11-kit. A local… | Details |
| CVE-2026-49006 | 2026-08-07 07:13:58 | 2026-08-07 08:10:07 | zte | By accessing unencrypted information in the device firmware,… | Details |
| CVE-2026-66491 | 2026-08-07 08:06:01 | 2026-08-07 08:06:01 | Joomla | Joomla Extension - phoca.cz - Arbitrary File Read… | Details |
| CVE-2026-66492 | 2026-08-07 08:03:50 | 2026-08-07 08:03:50 | Joomla | Joomla Extension - phoca.cz - Path Traversal vulnerability… | Details |
| CVE-2026-49008 | 2026-08-07 08:03:49 | 2026-08-07 08:03:49 | zte | By accessing unencrypted information in the device firmware,… | Details |
| CVE-2026-66493 | 2026-08-07 08:03:43 | 2026-08-07 08:03:43 | Joomla | Joomla Extension - phoca.cz - Path Traversal vulnerability… | Details |
| CVE-2026-49007 | 2026-08-07 07:39:03 | 2026-08-07 07:39:03 | zte | By accessing unencrypted information in the device firmware,… | Details |
| CVE-2026-15239 | 2026-08-07 07:25:36 | 2026-08-07 07:25:36 | WPScan | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin… | Details |
| CVE-2026-15211 | 2026-08-07 07:25:35 | 2026-08-07 07:25:35 | WPScan | The Subscriptions for WooCommerce WordPress plugin before 2.0.1… | Details |
| CVE-2026-15148 | 2026-08-07 07:25:34 | 2026-08-07 07:25:34 | WPScan | The WP Events Manager WordPress plugin before 2.2.5… | Details |
| CVE-2026-19079 | 2026-08-07 07:21:55 | 2026-08-07 07:21:55 | redhat | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found… | Details |
| CVE-2026-12261 | 2026-08-07 06:25:10 | 2026-08-07 06:25:10 | @huntr_ai | A vulnerability in `nltk.downloader` in nltk/nltk versions <=… | Details |
| CVE-2026-68480 | 2026-08-06 17:36:43 | 2026-08-07 06:17:28 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-16262 | 2026-08-07 06:00:14 | 2026-08-07 06:00:14 | WPScan | The Estatik Real Estate Plugin WordPress plugin before… | Details |
| CVE-2026-16265 | 2026-08-07 06:00:14 | 2026-08-07 06:00:14 | WPScan | The WP Maps WordPress plugin before 4.9.7… | Details |
| CVE-2026-16263 | 2026-08-07 06:00:14 | 2026-08-07 06:00:14 | WPScan | The WP Maps WordPress plugin before 4.9.7… | Details |
| CVE-2026-16038 | 2026-08-07 06:00:13 | 2026-08-07 06:00:13 | WPScan | The MStore API WordPress plugin before 4.21.0… | Details |
| CVE-2026-16030 | 2026-08-07 06:00:13 | 2026-08-07 06:00:13 | WPScan | The MStore API WordPress plugin before 4.21.0… | Details |
| CVE-2026-16041 | 2026-08-07 06:00:13 | 2026-08-07 06:00:13 | WPScan | The MStore API WordPress plugin before 4.21.0… | Details |
| CVE-2026-16258 | 2026-08-07 06:00:13 | 2026-08-07 06:00:13 | WPScan | The Ajax Search Lite WordPress plugin before… | Details |
| CVE-2026-16039 | 2026-08-07 06:00:13 | 2026-08-07 06:00:13 | WPScan | The MStore API WordPress plugin before 4.21.0… | Details |
| CVE-2026-15359 | 2026-08-07 06:00:12 | 2026-08-07 06:00:12 | WPScan | The Templately WordPress plugin before 3.7.1 does… | Details |
| CVE-2026-15245 | 2026-08-07 06:00:12 | 2026-08-07 06:00:12 | WPScan | The BNE Testimonials WordPress plugin before 2.0.8.2 does… | Details |
| CVE-2026-15361 | 2026-08-07 06:00:12 | 2026-08-07 06:00:12 | WPScan | The Content Views WordPress plugin before 4.5… | Details |
| CVE-2026-15386 | 2026-08-07 06:00:12 | 2026-08-07 06:00:12 | WPScan | The Meow Gallery WordPress plugin before 5.5.2 does… | Details |
| CVE-2026-15215 | 2026-08-07 06:00:11 | 2026-08-07 06:00:11 | WPScan | The Subscriptions for WooCommerce WordPress plugin before 2.0.1… | Details |
| CVE-2026-15214 | 2026-08-07 06:00:11 | 2026-08-07 06:00:11 | WPScan | The Subscriptions for WooCommerce WordPress plugin before 2.0.1… | Details |
| CVE-2026-14943 | 2026-08-07 06:00:10 | 2026-08-07 06:00:10 | WPScan | The Password Protected — Lock Entire Site, Pages,… | Details |
| CVE-2026-14205 | 2026-08-07 06:00:10 | 2026-08-07 06:00:10 | WPScan | The WP Events Manager WordPress plugin before 2.2.5… | Details |
| CVE-2026-14331 | 2026-08-07 06:00:10 | 2026-08-07 06:00:10 | WPScan | The Subscribe2 WordPress plugin before 10.46 does… | Details |
| CVE-2026-15032 | 2026-08-07 06:00:10 | 2026-08-07 06:00:10 | WPScan | The Comments WordPress plugin before 7.6.60 does… | Details |
| CVE-2026-64827 | 2026-08-03 13:26:10 | 2026-08-07 05:32:23 | VulnCheck | Telenia Software TVox 26.5.3 and prior 26.x versions,… | Details |
| CVE-2026-19196 | 2026-08-07 05:00:13 | 2026-08-07 05:00:13 | VulDB | A vulnerability was found in SourceCodester Photo Share… | Details |
| CVE-2026-19195 | 2026-08-07 04:45:09 | 2026-08-07 04:45:09 | VulDB | A vulnerability has been found in V-Secure Jingyun… | Details |
| CVE-2026-14364 | 2026-08-07 04:25:56 | 2026-08-07 04:25:56 | Wordfence | The TrueBooker – Appointment Booking and Scheduler System… | Details |
| CVE-2026-12801 | 2026-08-07 04:25:55 | 2026-08-07 04:25:55 | Wordfence | The Ultra Addons for Contact Form 7 plugin… | Details |
| CVE-2026-11907 | 2026-08-07 04:25:55 | 2026-08-07 04:25:55 | Wordfence | The Stream plugin for WordPress is vulnerable to… | Details |
| CVE-2026-14365 | 2026-08-07 04:25:54 | 2026-08-07 04:25:54 | Wordfence | The TrueBooker – Appointment Booking and Scheduler System… | Details |
| CVE-2026-19193 | 2026-08-07 04:15:10 | 2026-08-07 04:15:10 | VulDB | A flaw has been found in Jiangmin Antivirus… | Details |
| CVE-2026-64564 | 2026-08-04 06:23:23 | 2026-08-07 04:03:12 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-65668 | 2026-08-06 22:37:36 | 2026-08-07 03:56:09 | microsoft | Improper access control in Microsoft Purview eDiscovery allows… | Details |
| CVE-2026-59115 | 2026-08-06 22:37:40 | 2026-08-07 03:56:08 | microsoft | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows… | Details |
| CVE-2026-50481 | 2026-08-06 22:37:38 | 2026-08-07 03:56:07 | microsoft | Modification of assumed-immutable data (maid) in Azure Active… | Details |
| CVE-2026-59118 | 2026-08-06 22:37:37 | 2026-08-07 03:56:06 | microsoft | Improper authorization in Microsoft Power Apps allows an… | Details |
| CVE-2026-62896 | 2026-08-06 22:37:35 | 2026-08-07 03:56:05 | microsoft | Improper authentication in Microsoft Teams allows an authorized… | Details |
| CVE-2026-56162 | 2026-08-06 22:37:44 | 2026-08-07 03:56:03 | microsoft | Improper authentication in Azure SQL Database allows an… | Details |
| CVE-2026-62873 | 2026-08-06 22:37:47 | 2026-08-07 03:56:02 | microsoft | Improper verification of cryptographic signature in Microsoft 365… | Details |
| CVE-2026-19140 | 2026-08-06 20:33:43 | 2026-08-07 03:56:01 | Chrome | Use after free in GPU in Google Chrome… | Details |
| CVE-2026-19151 | 2026-08-06 20:33:48 | 2026-08-07 03:56:00 | Chrome | Use after free in V8 in Google Chrome… | Details |
| CVE-2026-19155 | 2026-08-06 20:33:49 | 2026-08-07 03:55:59 | Chrome | Use after free in Payments in Google Chrome… | Details |
| CVE-2026-19163 | 2026-08-06 20:33:52 | 2026-08-07 03:55:58 | Chrome | Use after free in Media in Google Chrome… | Details |
| CVE-2026-19177 | 2026-08-06 20:33:57 | 2026-08-07 03:55:57 | Chrome | Insufficient validation of untrusted input in UI in… | Details |
| CVE-2026-19165 | 2026-08-06 20:33:53 | 2026-08-07 03:55:55 | Chrome | Use after free in Extensions in Google Chrome… | Details |
| CVE-2026-19176 | 2026-08-06 20:33:56 | 2026-08-07 03:55:54 | Chrome | Use after free in Skia in Google Chrome… | Details |
| CVE-2026-19174 | 2026-08-06 20:33:55 | 2026-08-07 03:55:53 | Chrome | Integer overflow in V8 in Google Chrome prior… | Details |
| CVE-2026-19145 | 2026-08-06 20:33:45 | 2026-08-07 03:55:52 | Chrome | Use after free in Translate in Google Chrome… | Details |
| CVE-2026-19150 | 2026-08-06 20:33:47 | 2026-08-07 03:55:51 | Chrome | Inappropriate implementation in V8 in Google Chrome prior… | Details |
| CVE-2026-19162 | 2026-08-06 20:33:52 | 2026-08-07 03:55:50 | Chrome | Out of bounds write in V8 in Google… | Details |
| CVE-2026-19139 | 2026-08-06 20:33:42 | 2026-08-07 03:55:49 | Chrome | Race in CredentialProvider in Google Chrome on Windows… | Details |
| CVE-2026-19138 | 2026-08-06 20:33:42 | 2026-08-07 03:55:48 | Chrome | Heap buffer overflow in CrashReporting in Google Chrome… | Details |
| CVE-2026-19168 | 2026-08-06 20:33:42 | 2026-08-07 03:55:47 | Chrome | Inappropriate implementation in V8 in Google Chrome prior… | Details |
| CVE-2026-19169 | 2026-08-06 20:33:41 | 2026-08-07 03:55:45 | Chrome | Insufficient validation of untrusted input in Contextual Tasks… | Details |
| CVE-2026-19172 | 2026-08-06 20:33:41 | 2026-08-07 03:55:44 | Chrome | Use after free in Views in Google Chrome… | Details |
| CVE-2026-19170 | 2026-08-06 20:33:40 | 2026-08-07 03:55:43 | Chrome | Use after free in WebGL in Google Chrome… | Details |
| CVE-2026-19157 | 2026-08-06 20:33:40 | 2026-08-07 03:55:42 | Chrome | Out of bounds write in ANGLE in Google… | Details |
| CVE-2026-19154 | 2026-08-06 20:33:39 | 2026-08-07 03:55:41 | Chrome | Use after free in Skia in Google Chrome… | Details |
| CVE-2026-19149 | 2026-08-06 20:33:38 | 2026-08-07 03:55:40 | Chrome | Use after free in Aura in Google Chrome… | Details |
| CVE-2026-19137 | 2026-08-06 20:33:38 | 2026-08-07 03:55:39 | Chrome | Use after free in WebGL in Google Chrome… | Details |
| CVE-2026-64993 | 2026-08-06 13:38:42 | 2026-08-07 03:55:38 | dell | Dell RVTools versions prior to 4.8.1, contains an… | Details |
| CVE-2026-71320 | 2026-08-05 21:29:51 | 2026-08-07 03:55:36 | GitHub_M | Nuxt is an open-source web development framework for… | Details |
| CVE-2026-71319 | 2026-08-05 21:26:59 | 2026-08-07 03:55:35 | GitHub_M | Nuxt is an open-source web development framework for… | Details |
| CVE-2026-9203 | 2026-08-05 15:40:19 | 2026-08-07 03:55:33 | ProgressSoftware | A server-side request forgery vulnerability in Progress MarkLogic… | Details |
| CVE-2026-9193 | 2026-08-05 15:37:07 | 2026-08-07 03:55:32 | ProgressSoftware | An improper privilege management vulnerability in the Hadoop… | Details |
| CVE-2026-9192 | 2026-08-05 15:35:53 | 2026-08-07 03:55:30 | ProgressSoftware | An authentication bypass vulnerability in the ODBC App… | Details |
| CVE-2026-57817 | 2026-08-06 10:24:05 | 2026-08-07 03:55:29 | apache | The OpenID Connect Core 1.0 specification mandates that… | Details |
| CVE-2026-9190 | 2026-08-05 15:34:58 | 2026-08-07 03:55:28 | ProgressSoftware | An HTTP request smuggling vulnerability in the HTTP… | Details |
| CVE-2026-8709 | 2026-08-05 15:33:47 | 2026-08-07 03:55:27 | ProgressSoftware | An improper privilege management vulnerability in the REST… | Details |
| CVE-2026-7557 | 2026-08-05 15:33:05 | 2026-08-07 03:55:26 | ProgressSoftware | An improper verification of cryptographic signature vulnerability in… | Details |
| CVE-2026-7329 | 2026-08-05 15:32:21 | 2026-08-07 03:55:25 | ProgressSoftware | An improper privilege management vulnerability in the SQL,… | Details |
| CVE-2026-7327 | 2026-08-05 15:30:40 | 2026-08-07 03:55:24 | ProgressSoftware | An improper privilege management vulnerability in the REST… | Details |
| CVE-2026-7326 | 2026-08-05 15:29:54 | 2026-08-07 03:55:23 | ProgressSoftware | A cross-site request forgery vulnerability in the Admin… | Details |
| CVE-2026-71312 | 2026-08-05 20:37:49 | 2026-08-07 03:55:21 | GitHub_M | rclone is a command-line program to sync files… | Details |
| CVE-2026-19192 | 2026-08-07 03:45:08 | 2026-08-07 03:45:08 | VulDB | A vulnerability was detected in DeepCool DisplayService 1.2.12.… | Details |
| CVE-2026-49005 | 2026-08-07 03:36:08 | 2026-08-07 03:36:08 | zte | The root password hash of the device can… | Details |
| CVE-2026-19191 | 2026-08-07 03:30:09 | 2026-08-07 03:30:09 | VulDB | A security vulnerability has been detected in StableBit… | Details |
| CVE-2026-19190 | 2026-08-07 02:30:09 | 2026-08-07 02:30:09 | VulDB | A weakness has been identified in StableBit Scanner… | Details |
| CVE-2026-19189 | 2026-08-07 02:00:10 | 2026-08-07 02:00:10 | VulDB | A security flaw has been discovered in Power… | Details |
| CVE-2026-49746 | 2026-08-07 01:59:38 | 2026-08-07 01:59:38 | imaginationtech | Software installed and run as a non-privileged user… | Details |
| CVE-2026-45204 | 2026-08-07 01:53:10 | 2026-08-07 01:53:10 | imaginationtech | Software installed and run as a non-privileged user… | Details |
| CVE-2026-45198 | 2026-08-07 01:42:54 | 2026-08-07 01:42:54 | imaginationtech | Kernel software from a non-secure operating system on… | Details |
| CVE-2026-41861 | 2026-08-06 18:29:26 | 2026-08-07 01:09:37 | vmware | Path Traversal in BOSH-Ecosystem / BOSH allows an… | Details |
| CVE-2026-56161 | 2026-08-06 22:37:42 | 2026-08-07 01:04:10 | microsoft | Improper access control in Azure Logic Apps allows… | Details |
| CVE-2026-62918 | 2026-08-06 22:37:40 | 2026-08-07 01:00:10 | microsoft | Improper verification of cryptographic signature in Microsoft Teams… | Details |
| CVE-2026-65667 | 2026-08-06 22:37:43 | 2026-08-07 00:52:43 | microsoft | Missing authorization in Microsoft Teams allows an unauthorized… | Details |
| CVE-2026-19160 | 2026-08-06 20:33:51 | 2026-08-07 00:30:16 | Chrome | Uninitialized Use in Skia in Google Chrome prior… | Details |
| CVE-2026-19146 | 2026-08-06 20:33:46 | 2026-08-07 00:27:58 | Chrome | Uninitialized Use in GPU in Google Chrome on… | Details |
| CVE-2026-19161 | 2026-08-06 20:33:51 | 2026-08-07 00:25:17 | Chrome | Uninitialized Use in Skia in Google Chrome prior… | Details |
| CVE-2026-65400 | 2026-08-06 18:17:18 | 2026-08-07 00:16:10 | apple | An authentication issue was addressed with improved state… | Details |
| CVE-2026-68481 | 2026-08-06 11:22:37 | 2026-08-07 00:01:55 | apache | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still… | Details |
| CVE-2026-68079 | 2026-08-06 11:22:57 | 2026-08-07 00:01:53 | apache | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can… | Details |
| CVE-2026-66909 | 2026-08-06 10:23:23 | 2026-08-07 00:01:52 | apache | Apache CXF's JMS transport deserializes the body of… | Details |
| CVE-2026-65583 | 2026-08-06 11:23:17 | 2026-08-07 00:01:49 | apache | Apache CXF’s OIDC relying-party token validation could accept… | Details |
| CVE-2026-65432 | 2026-08-06 10:26:12 | 2026-08-07 00:01:48 | apache | Apache CXF reads a top-level WSDL through its… | Details |
| CVE-2026-63687 | 2026-08-06 11:23:45 | 2026-08-07 00:01:46 | apache | Apache CXF's JwtRequestCodeFilter copies all claims from a… | Details |
| CVE-2026-61466 | 2026-08-06 11:24:27 | 2026-08-07 00:01:45 | apache | In Apache CXF's OAuth2 Dynamic Client Registration endpoint,… | Details |
| CVE-2026-57819 | 2026-08-06 10:12:26 | 2026-08-07 00:01:43 | apache | Apache CXF allows to set a limit on… | Details |
| CVE-2026-57818 | 2026-08-06 11:24:53 | 2026-08-07 00:01:42 | apache | A race condition in JCacheCodeDataProvider allows an attacker… | Details |
| CVE-2026-54225 | 2026-08-06 10:11:41 | 2026-08-07 00:01:38 | apache | Apache CXF allows to control the maximum attachment… | Details |
| CVE-2026-63508 | 2026-08-06 22:37:46 | 2026-08-06 23:22:13 | microsoft | Missing authentication for critical function in Microsoft Planetary… | Details |
| CVE-2026-50515 | 2026-08-06 22:37:44 | 2026-08-06 23:22:12 | microsoft | Deserialization of untrusted data in Azure Service Bus… | Details |
| CVE-2026-62830 | 2026-08-06 22:37:43 | 2026-08-06 23:22:10 | microsoft | Missing authorization in Azure SRE Agent allows an… | Details |
| CVE-2026-68823 | 2026-08-06 22:37:41 | 2026-08-06 23:22:08 | microsoft | Exposed dangerous method or function in Azure Confidential… | Details |
| CVE-2026-70332 | 2026-08-06 23:22:08 | 2026-08-06 23:22:08 | microsoft | Server-side request forgery (ssrf) in Microsoft Office SharePoint… | Details |
| CVE-2026-49163 | 2026-08-06 22:37:41 | 2026-08-06 23:22:07 | microsoft | Improper limitation of a pathname to a restricted… | Details |
| CVE-2026-62836 | 2026-08-06 22:37:34 | 2026-08-06 23:22:01 | microsoft | Improper restriction of communication channel to intended endpoints… | Details |
| CVE-2026-17264 | 2026-08-06 22:13:03 | 2026-08-06 22:13:03 | icscert | Opening a crafted DICOM file containing malicious JPEG-compressed… | Details |
| CVE-2026-64640 | 2026-08-06 09:08:06 | 2026-08-06 21:56:16 | apache | Apache Polaris did not consistently validate storage locations… | Details |
| CVE-2026-34502 | 2026-08-06 14:31:07 | 2026-08-06 21:56:10 | apache | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime… | Details |
| CVE-2026-34501 | 2026-08-06 14:31:48 | 2026-08-06 21:56:09 | apache | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime… | Details |
| CVE-2026-34191 | 2026-08-06 14:32:24 | 2026-08-06 21:56:08 | apache | Improper Neutralization of Special Elements used in an… | Details |
| CVE-2026-32327 | 2026-08-06 14:32:43 | 2026-08-06 21:56:07 | apache | A bug in APR-util version 1.6.3 (and earlier)… | Details |
| CVE-2025-49506 | 2026-08-06 14:33:12 | 2026-08-06 21:56:06 | apache | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was… | Details |
| CVE-2026-71555 | 2026-08-06 21:51:55 | 2026-08-06 21:51:55 | GitHub_M | PILOS (Platform for Interactive Live-Online Seminars) is a… | Details |
| CVE-2026-71554 | 2026-08-06 21:46:43 | 2026-08-06 21:46:43 | GitHub_M | h2 is a pure-Python implementation of a HTTP/2… | Details |
| CVE-2026-48054 | 2026-08-06 21:37:54 | 2026-08-06 21:37:54 | GitHub_M | OpenZeppelin Contracts Wizardis a web application to interactively… | Details |
| CVE-2026-49391 | 2026-08-06 21:36:24 | 2026-08-06 21:36:24 | GitHub_M | Frappe is a full-stack web application framework. Prior… | Details |
| CVE-2026-48088 | 2026-08-06 21:34:32 | 2026-08-06 21:34:32 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-48087 | 2026-08-06 21:32:30 | 2026-08-06 21:32:30 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-70636 | 2026-08-06 21:31:55 | 2026-08-06 21:31:55 | VulnCheck | Flowise through 3.1.4 contains an authentication bypass vulnerability… | Details |
| CVE-2026-67622 | 2026-08-06 21:31:34 | 2026-08-06 21:31:34 | VulnCheck | Flowise through 3.1.4 contains an insecure direct object… | Details |
| CVE-2026-67434 | 2026-08-06 21:31:32 | 2026-08-06 21:31:32 | GitHub_M | PHP_CodeSniffer tokenizes PHP files and detects violations of… | Details |
| CVE-2026-67621 | 2026-08-06 21:31:13 | 2026-08-06 21:31:13 | VulnCheck | Flowise through 3.1.4 contains a missing authorization vulnerability… | Details |
| CVE-2026-48086 | 2026-08-06 21:30:32 | 2026-08-06 21:30:32 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-48085 | 2026-08-06 21:29:00 | 2026-08-06 21:29:00 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-70632 | 2026-08-06 21:26:17 | 2026-08-06 21:28:05 | VulnCheck | FFmpeg versions from 4.4 up to, but not… | Details |
| CVE-2026-70631 | 2026-08-06 21:25:53 | 2026-08-06 21:27:47 | VulnCheck | FFmpeg versions from 0.5 up to, but not… | Details |
| CVE-2026-70630 | 2026-08-06 21:25:31 | 2026-08-06 21:27:26 | VulnCheck | FFmpeg versions from 3.0 up to, but not… | Details |
| CVE-2026-70629 | 2026-08-06 21:25:08 | 2026-08-06 21:27:03 | VulnCheck | FFmpeg versions from 3.0 up to, but not… | Details |
| CVE-2026-70628 | 2026-08-06 21:24:15 | 2026-08-06 21:26:44 | VulnCheck | FFmpeg versions from 0.5 up to, but not… | Details |
| CVE-2026-71498 | 2026-08-06 21:26:00 | 2026-08-06 21:26:00 | GitHub_M | node-re2 provides RE2 regular expression bindings for Node.js.… | Details |
| CVE-2026-47765 | 2026-08-06 21:25:31 | 2026-08-06 21:25:31 | GitHub_M | Frappe is a full-stack web application framework. Prior… | Details |
| CVE-2026-71430 | 2026-08-06 21:19:32 | 2026-08-06 21:19:32 | GitHub_M | node-re2 provides RE2 regular expression bindings for Node.js.… | Details |
| CVE-2026-47194 | 2026-08-06 21:19:19 | 2026-08-06 21:19:19 | GitHub_M | Frappe is a full-stack web application framework. Prior… | Details |
| CVE-2026-48084 | 2026-08-06 21:18:12 | 2026-08-06 21:18:12 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-48083 | 2026-08-06 21:16:12 | 2026-08-06 21:16:12 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-48082 | 2026-08-06 21:14:16 | 2026-08-06 21:14:16 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-48081 | 2026-08-06 21:10:28 | 2026-08-06 21:10:28 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-71497 | 2026-08-06 21:09:31 | 2026-08-06 21:09:31 | GitHub_M | jsoup is a Java library for working with… | Details |
| CVE-2026-47185 | 2026-08-06 21:08:14 | 2026-08-06 21:08:14 | GitHub_M | Frappe is a full-stack web application framework. Prior… | Details |
| CVE-2026-62857 | 2026-08-06 21:04:23 | 2026-08-06 21:04:23 | GitHub_M | Fedify is a TypeScript library for building federated… | Details |
| CVE-2026-48079 | 2026-08-06 21:00:44 | 2026-08-06 21:00:44 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-61632 | 2026-08-06 20:59:20 | 2026-08-06 20:59:20 | GitHub_M | PyMdown Extensions is a set of extensions for… | Details |
| CVE-2026-48078 | 2026-08-06 20:56:24 | 2026-08-06 20:56:24 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-48077 | 2026-08-06 20:47:06 | 2026-08-06 20:47:06 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-19110 | 2026-08-06 20:45:08 | 2026-08-06 20:45:08 | VulDB | A vulnerability was determined in DataGear up to… | Details |
| CVE-2026-48076 | 2026-08-06 20:43:59 | 2026-08-06 20:43:59 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-62870 | 2026-08-03 22:58:03 | 2026-08-06 20:39:37 | microsoft | Use after free in Microsoft Office Excel allows… | Details |
| CVE-2026-66326 | 2026-08-03 22:58:02 | 2026-08-06 20:39:37 | microsoft | Missing authorization in Microsoft Edge (Chromium-based) allows an… | Details |
| CVE-2026-66325 | 2026-08-03 22:57:55 | 2026-08-06 20:39:36 | microsoft | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based)… | Details |
| CVE-2026-66322 | 2026-08-03 22:57:54 | 2026-08-06 20:39:36 | microsoft | Origin validation error in Microsoft Edge (Chromium-based) allows… | Details |
| CVE-2026-66317 | 2026-08-03 22:57:54 | 2026-08-06 20:39:35 | microsoft | Origin validation error in Microsoft Edge (Chromium-based) allows… | Details |
| CVE-2026-65804 | 2026-08-03 22:57:52 | 2026-08-06 20:39:34 | microsoft | Improper control of generation of code ('code injection')… | Details |
| CVE-2026-66311 | 2026-08-03 22:57:53 | 2026-08-06 20:39:34 | microsoft | Missing authorization in Microsoft Edge (Chromium-based) allows an… | Details |
| CVE-2026-48075 | 2026-08-06 20:39:34 | 2026-08-06 20:39:34 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-65802 | 2026-08-03 22:57:52 | 2026-08-06 20:39:33 | microsoft | External control of file name or path in… | Details |
| CVE-2026-71488 | 2026-08-06 20:37:17 | 2026-08-06 20:37:17 | GitHub_M | league/commonmark is a PHP library for parsing and… | Details |
| CVE-2026-18367 | 2026-08-06 20:30:39 | 2026-08-06 20:36:34 | Sophos | A privilege escalation vulnerability allows local users to… | Details |
| CVE-2026-66316 | 2026-08-03 22:53:13 | 2026-08-06 20:34:33 | microsoft | Origin validation error in Microsoft Edge (Chromium-based) allows… | Details |
| CVE-2026-66315 | 2026-08-03 22:53:12 | 2026-08-06 20:34:33 | microsoft | Use after free in Microsoft Edge (Chromium-based) allows… | Details |
| CVE-2026-66313 | 2026-08-03 22:53:11 | 2026-08-06 20:34:32 | microsoft | Origin validation error in Microsoft Edge (Chromium-based) allows… | Details |
| CVE-2026-66314 | 2026-08-03 22:53:12 | 2026-08-06 20:34:32 | microsoft | Time-of-check time-of-use (toctou) race condition in Microsoft Edge… | Details |
| CVE-2026-66312 | 2026-08-03 22:53:10 | 2026-08-06 20:34:31 | microsoft | Buffer over-read in Microsoft Edge (Chromium-based) allows an… | Details |
| CVE-2026-66310 | 2026-08-03 22:53:10 | 2026-08-06 20:34:31 | microsoft | External control of file name or path in… | Details |
| CVE-2026-19175 | 2026-08-06 20:33:56 | 2026-08-06 20:33:56 | Chrome | Use after free in Payments in Google Chrome… | Details |
| CVE-2026-19173 | 2026-08-06 20:33:55 | 2026-08-06 20:33:55 | Chrome | Out of bounds write in Skia in Google… | Details |
| CVE-2026-19171 | 2026-08-06 20:33:54 | 2026-08-06 20:33:54 | Chrome | Use after free in Media in Google Chrome… | Details |
| CVE-2026-19167 | 2026-08-06 20:33:54 | 2026-08-06 20:33:54 | Chrome | Integer overflow in GPU in Google Chrome prior… | Details |
| CVE-2026-19166 | 2026-08-06 20:33:53 | 2026-08-06 20:33:53 | Chrome | Use after free in Web Authentication in Google… | Details |
| CVE-2026-19164 | 2026-08-06 20:33:53 | 2026-08-06 20:33:53 | Chrome | Insufficient validation of untrusted input in Codecs in… | Details |
| CVE-2026-19158 | 2026-08-06 20:33:50 | 2026-08-06 20:33:50 | Chrome | Use after free in Views in Google Chrome… | Details |
| CVE-2026-19159 | 2026-08-06 20:33:50 | 2026-08-06 20:33:50 | Chrome | Use after free in Views in Google Chrome… | Details |
| CVE-2026-19153 | 2026-08-06 20:33:49 | 2026-08-06 20:33:49 | Chrome | Insufficient validation of untrusted input in Workers in… | Details |
| CVE-2026-19156 | 2026-08-06 20:33:49 | 2026-08-06 20:33:49 | Chrome | Heap buffer overflow in Base in Google Chrome… | Details |
| CVE-2026-19152 | 2026-08-06 20:33:48 | 2026-08-06 20:33:48 | Chrome | Insufficient policy enforcement in Navigation in Google Chrome… | Details |
| CVE-2026-19148 | 2026-08-06 20:33:47 | 2026-08-06 20:33:47 | Chrome | Out of bounds write in GPU in Google… | Details |
| CVE-2026-19147 | 2026-08-06 20:33:46 | 2026-08-06 20:33:46 | Chrome | Use after free in Aura in Google Chrome… | Details |
| CVE-2026-19144 | 2026-08-06 20:33:45 | 2026-08-06 20:33:45 | Chrome | Use after free in HTML in Google Chrome… | Details |
| CVE-2026-19142 | 2026-08-06 20:33:44 | 2026-08-06 20:33:44 | Chrome | Use after free in Views in Google Chrome… | Details |
| CVE-2026-19143 | 2026-08-06 20:33:44 | 2026-08-06 20:33:44 | Chrome | Insufficient validation of untrusted input in WebAPKs in… | Details |
| CVE-2026-19141 | 2026-08-06 20:33:43 | 2026-08-06 20:33:43 | Chrome | Use after free in Resources in Google Chrome… | Details |
| CVE-2026-66321 | 2026-08-03 22:51:44 | 2026-08-06 20:33:10 | microsoft | Access of resource using incompatible type ('type confusion')… | Details |
| CVE-2026-66318 | 2026-08-03 22:51:43 | 2026-08-06 20:33:09 | microsoft | Origin validation error in Microsoft Edge (Chromium-based) allows… | Details |
| CVE-2026-71478 | 2026-08-06 20:30:32 | 2026-08-06 20:30:32 | GitHub_M | league/commonmark is a PHP library for parsing and… | Details |
| CVE-2026-19108 | 2026-08-06 20:30:14 | 2026-08-06 20:30:14 | VulDB | A vulnerability was found in MZ Automation libiec61850… | Details |
| CVE-2026-71502 | 2026-08-06 20:30:04 | 2026-08-06 20:30:04 | CIRCL | CTI-Transmute contains a stored cross-site scripting vulnerability caused… | Details |
| CVE-2026-48074 | 2026-08-06 20:27:21 | 2026-08-06 20:27:21 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-54717 | 2026-08-06 20:27:17 | 2026-08-06 20:27:17 | GitHub_M | Silverstripe CMS is an open source content management… | Details |
| CVE-2026-67422 | 2026-08-06 20:26:31 | 2026-08-06 20:26:31 | GitHub_M | pymdown-extensions is a collection of extensions for the… | Details |
| CVE-2024-39024 | 2026-08-06 00:00:00 | 2026-08-06 20:21:31 | mitre | In Packetfence 13.2.0, the WebGui interface setting allows… | Details |
| CVE-2026-63637 | 2026-08-06 20:20:32 | 2026-08-06 20:20:32 | GitHub_M | Dgraph is an open source distributed GraphQL database.… | Details |
| CVE-2026-45378 | 2026-08-06 20:15:40 | 2026-08-06 20:15:40 | GitHub_M | Decidim is a participatory democracy framework. Prior to… | Details |
| CVE-2026-19071 | 2026-08-06 20:15:11 | 2026-08-06 20:15:11 | VulDB | A flaw has been found in itsourcecode Hospital… | Details |
| CVE-2026-45573 | 2026-08-06 20:14:07 | 2026-08-06 20:14:07 | GitHub_M | Decidim is a participatory democracy framework. Prior to… | Details |
| CVE-2026-45572 | 2026-08-06 20:10:54 | 2026-08-06 20:10:54 | GitHub_M | Decidim is a participatory democracy framework. Prior to… | Details |
| CVE-2026-71476 | 2026-08-06 20:07:09 | 2026-08-06 20:07:09 | GitHub_M | Nx is a monorepo solution for TypeScript and… | Details |
| CVE-2026-71439 | 2026-08-06 20:01:04 | 2026-08-06 20:01:04 | GitHub_M | Mermaid is a JavaScript tool that uses Markdown-inspired… | Details |
| CVE-2026-15734 | 2026-08-06 20:00:57 | 2026-08-06 20:00:57 | certcc | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard… | Details |
| CVE-2026-15732 | 2026-08-06 19:59:32 | 2026-08-06 20:00:44 | certcc | A Server-Side Request Forgery (SSFR) vulnerability exist in… | Details |
| CVE-2026-15733 | 2026-08-06 20:00:26 | 2026-08-06 20:00:26 | certcc | A Remote Code Execution (RCE) vulnerability exist in… | Details |
| CVE-2026-19070 | 2026-08-06 20:00:10 | 2026-08-06 20:00:10 | VulDB | A vulnerability was detected in itsourcecode Hospital Management… | Details |
| CVE-2026-71438 | 2026-08-06 19:59:07 | 2026-08-06 19:59:07 | GitHub_M | Mermaid is a JavaScript tool that uses Markdown-inspired… | Details |
| CVE-2026-67687 | 2026-08-06 00:00:00 | 2026-08-06 19:56:52 | mitre | Insecure Permissions vulnerability in ics-park v.2.0 allows a… | Details |
| CVE-2026-50159 | 2026-08-06 19:55:27 | 2026-08-06 19:55:27 | GitHub_M | Mermaid is a JavaScript tool that uses Markdown-inspired… | Details |
| CVE-2026-67689 | 2026-08-06 00:00:00 | 2026-08-06 19:52:59 | mitre | SQL Injection vulnerability in FineAdmin V1.0 allows a… | Details |
| CVE-2026-71437 | 2026-08-06 19:51:52 | 2026-08-06 19:51:52 | GitHub_M | Mermaid is a JavaScript tool that uses Markdown-inspired… | Details |
| CVE-2026-71436 | 2026-08-06 19:49:44 | 2026-08-06 19:49:44 | GitHub_M | Mermaid is a JavaScript tool that uses Markdown-inspired… | Details |
| CVE-2026-67688 | 2026-08-06 00:00:00 | 2026-08-06 19:49:39 | mitre | ICS-Park Smart Park Management System v2.0 contains an… | Details |
| CVE-2026-19069 | 2026-08-06 19:45:08 | 2026-08-06 19:45:08 | VulDB | A security vulnerability has been detected in itsourcecode… | Details |
| CVE-2026-65517 | 2026-08-06 14:27:27 | 2026-08-06 19:39:40 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal… | Details |
| CVE-2026-25403 | 2026-08-06 14:27:07 | 2026-08-06 19:38:05 | Patchstack | Unauthenticated Broken Access Control in Ultimate Store Kit… | Details |
| CVE-2026-71435 | 2026-08-06 19:37:54 | 2026-08-06 19:37:54 | GitHub_M | Statamic is a Laravel and Git powered content… | Details |
| CVE-2026-28140 | 2026-08-06 14:27:10 | 2026-08-06 19:36:56 | Patchstack | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1… | Details |
| CVE-2026-70559 | 2026-08-06 19:36:36 | 2026-08-06 19:36:36 | VulnCheck | Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a… | Details |
| CVE-2026-71434 | 2026-08-06 19:34:48 | 2026-08-06 19:34:48 | GitHub_M | Statamic is a Laravel and Git powered content… | Details |
| CVE-2026-28172 | 2026-08-06 14:27:13 | 2026-08-06 19:34:10 | Patchstack | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking… | Details |
| CVE-2026-45415 | 2026-08-06 19:33:31 | 2026-08-06 19:33:31 | GitHub_M | Decidim is a participatory democracy framework. Prior to… | Details |
| CVE-2026-70558 | 2026-08-06 19:30:55 | 2026-08-06 19:33:04 | VulnCheck | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path… | Details |
| CVE-2026-65575 | 2026-08-06 14:27:44 | 2026-08-06 19:30:36 | Patchstack | Unauthenticated PHP Object Injection in Accalia <= 1.5.3… | Details |
| CVE-2026-64662 | 2026-08-06 19:30:35 | 2026-08-06 19:30:35 | GitHub_M | Statamic is a Laravel and Git powered content… | Details |
| CVE-2026-65548 | 2026-08-06 14:27:34 | 2026-08-06 19:29:29 | Patchstack | Contributor Remote Code Execution (RCE) in Betheme <=… | Details |
| CVE-2026-65507 | 2026-08-06 14:27:24 | 2026-08-06 19:28:13 | Patchstack | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.… | Details |
| CVE-2026-64663 | 2026-08-06 19:28:06 | 2026-08-06 19:28:06 | GitHub_M | Statamic is a Laravel and Git powered content… | Details |
| CVE-2026-65543 | 2026-08-06 14:27:30 | 2026-08-06 19:26:32 | Patchstack | Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2… | Details |
| CVE-2026-61963 | 2026-08-06 14:27:20 | 2026-08-06 19:25:41 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary… | Details |
| CVE-2026-64665 | 2026-08-06 19:25:01 | 2026-08-06 19:25:01 | GitHub_M | Statamic is a Laravel and Git powered content… | Details |
| CVE-2026-64664 | 2026-08-06 19:22:29 | 2026-08-06 19:22:29 | GitHub_M | Statamic is a Laravel and Git powered content… | Details |
| CVE-2026-66451 | 2026-08-06 14:27:51 | 2026-08-06 19:22:10 | Patchstack | Unauthenticated Broken Authentication in WP Event SOlution <=… | Details |
| CVE-2026-66706 | 2026-08-06 14:28:08 | 2026-08-06 19:20:27 | Patchstack | Author Cross Site Scripting (XSS) in Subscribe to… | Details |
| CVE-2026-65570 | 2026-08-06 14:27:40 | 2026-08-06 19:19:36 | Patchstack | Unauthenticated Bypass Vulnerability in Login with phone number… | Details |
| CVE-2026-65556 | 2026-08-06 14:27:37 | 2026-08-06 19:18:37 | Patchstack | Unauthenticated PHP Object Injection in WPBruiser {no- Captcha… | Details |
| CVE-2026-65581 | 2026-08-06 14:27:47 | 2026-08-06 19:17:28 | Patchstack | Unauthenticated PHP Object Injection in AI ANN <=… | Details |
| CVE-2026-45414 | 2026-08-06 19:17:17 | 2026-08-06 19:17:17 | GitHub_M | Decidim is a participatory democracy framework. Prior to… | Details |
| CVE-2026-70557 | 2026-08-06 19:16:18 | 2026-08-06 19:16:18 | VulnCheck | diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names… | Details |
| CVE-2026-19068 | 2026-08-06 19:15:10 | 2026-08-06 19:15:10 | VulDB | A weakness has been identified in itsourcecode Hospital… | Details |
| CVE-2026-66663 | 2026-08-06 14:27:54 | 2026-08-06 19:09:26 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in WP Data… | Details |
| CVE-2026-66690 | 2026-08-06 14:28:01 | 2026-08-06 19:08:04 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in GiveWP <=… | Details |
| CVE-2026-66711 | 2026-08-06 14:28:11 | 2026-08-06 19:06:24 | Patchstack | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual… | Details |
| CVE-2026-66683 | 2026-08-06 14:27:58 | 2026-08-06 19:05:30 | Patchstack | Unauthenticated Sensitive Data Exposure in Custom CSS and… | Details |
| CVE-2026-66699 | 2026-08-06 14:28:04 | 2026-08-06 19:04:20 | Patchstack | Custom role Broken Access Control in Dokan <=… | Details |
| CVE-2026-71433 | 2026-08-06 19:03:09 | 2026-08-06 19:03:09 | GitHub_M | LangGraph Checkpoint Postgres and SQLite Checkpoint are the… | Details |
| CVE-2026-18501 | 2026-08-06 13:27:13 | 2026-08-06 18:53:30 | Wordfence | The UsersWP – Front-end login form, User Registration,… | Details |
| CVE-2026-18325 | 2026-08-06 03:26:08 | 2026-08-06 18:52:58 | Wordfence | The Forminator Forms – Contact Form, Payment Form… | Details |
| CVE-2026-5857 | 2026-08-06 18:52:40 | 2026-08-06 18:52:40 | VulnCheck | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1… | Details |
| CVE-2025-9266 | 2026-08-06 11:29:21 | 2026-08-06 18:50:43 | Wordfence | The Accelerate theme for WordPress is vulnerable to… | Details |
| CVE-2026-5856 | 2026-08-06 18:47:38 | 2026-08-06 18:47:38 | VulnCheck | Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS… | Details |
| CVE-2026-48071 | 2026-08-06 18:46:38 | 2026-08-06 18:46:38 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-19067 | 2026-08-06 18:45:10 | 2026-08-06 18:45:10 | VulDB | A security flaw has been discovered in itsourcecode… | Details |
| CVE-2026-55522 | 2026-08-05 19:01:43 | 2026-08-06 18:45:05 | GitHub_M | PraisonAI is a multi-agent teams system. In versions… | Details |
| CVE-2026-70616 | 2026-08-05 19:37:36 | 2026-08-06 18:44:57 | VulnCheck | boringproxy through 0.10.0 contains a resource exhaustion vulnerability… | Details |
| CVE-2026-71311 | 2026-08-05 20:33:32 | 2026-08-06 18:44:51 | GitHub_M | rclone is a command-line program to sync files… | Details |
| CVE-2026-71316 | 2026-08-05 21:14:31 | 2026-08-06 18:44:45 | GitHub_M | Nuxt is an open-source web development framework for… | Details |
| CVE-2026-67531 | 2026-08-05 22:54:36 | 2026-08-06 18:44:39 | GitHub_M | FrontMCP is a TypeScript-first framework for the Model… | Details |
| CVE-2026-18974 | 2026-08-06 00:45:08 | 2026-08-06 18:44:33 | VulDB | A vulnerability was found in heshengtao super-agent-party up… | Details |
| CVE-2026-66732 | 2026-08-06 12:53:54 | 2026-08-06 18:44:27 | VulnCheck | Sonic 3 A.I.R. before commit 2492d18 contains a… | Details |
| CVE-2026-43622 | 2026-08-06 15:27:07 | 2026-08-06 18:44:19 | VulnCheck | llama.cpp builds b1886 through b7445 contain a double… | Details |
| CVE-2026-64655 | 2026-08-06 18:41:54 | 2026-08-06 18:41:54 | GitHub_M | GitHub CLI (gh) is GitHub’s official command line… | Details |
| CVE-2026-5855 | 2026-08-06 18:39:06 | 2026-08-06 18:39:06 | VulnCheck | Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores… | Details |
| CVE-2026-19066 | 2026-08-06 18:30:09 | 2026-08-06 18:30:09 | VulDB | A vulnerability was identified in SourceCodester Online Examination… | Details |
| CVE-2026-64654 | 2026-08-06 18:27:38 | 2026-08-06 18:27:38 | GitHub_M | GitHub CLI (gh) is GitHub's official command line… | Details |
| CVE-2026-48080 | 2026-08-06 18:26:52 | 2026-08-06 18:26:52 | GitHub_M | OpenReception's appointment booking software provides an end-to-end encrypted… | Details |
| CVE-2026-65321 | 2026-08-02 14:56:28 | 2026-08-06 18:25:29 | VulnCheck | PyAthena prior to 3.35.4 contains a sql injection… | Details |
| CVE-2026-19065 | 2026-08-06 18:15:09 | 2026-08-06 18:15:09 | VulDB | A vulnerability was determined in SourceCodester Online Examination… | Details |
| CVE-2026-70617 | 2026-08-05 19:53:34 | 2026-08-06 18:07:53 | VulnCheck | Spacebar Server before commit dcfd910 contains a missing… | Details |
| CVE-2026-19111 | 2026-08-06 18:03:21 | 2026-08-06 18:05:05 | AMZN | Insecure direct object reference in the mongodb_memory, elasticsearch_memory,… | Details |
| CVE-2026-66733 | 2026-08-06 12:58:05 | 2026-08-06 17:54:02 | VulnCheck | Sonic 3 A.I.R. before commit 2492d18 contains an… | Details |
| CVE-2026-53977 | 2026-08-06 14:43:37 | 2026-08-06 17:53:21 | VulnCheck | OpenChamber 1.11.7 contains an authentication bypass vulnerability that… | Details |
| CVE-2026-64653 | 2026-08-06 17:51:54 | 2026-08-06 17:51:54 | GitHub_M | GitHub CLI (gh) is GitHub’s official command line… | Details |
| CVE-2026-60053 | 2026-08-05 15:13:10 | 2026-08-06 17:47:19 | apache | Insufficient Session Expiration vulnerability in Apache Answer. This issue… | Details |
| CVE-2026-64652 | 2026-08-06 17:45:35 | 2026-08-06 17:45:35 | GitHub_M | GitHub CLI (gh) is GitHub's official command line… | Details |
| CVE-2026-61483 | 2026-08-05 06:36:02 | 2026-08-06 17:44:10 | apache | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability… | Details |
| CVE-2026-65523 | 2026-08-06 14:27:28 | 2026-08-06 17:38:33 | Patchstack | Unauthenticated Insecure Direct Object References (IDOR) in Formidable… | Details |
| CVE-2026-64604 | 2026-08-06 07:13:55 | 2026-08-06 17:37:50 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-63725 | 2026-08-06 17:34:39 | 2026-08-06 17:36:11 | VulnCheck | sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds… | Details |
| CVE-2026-70615 | 2026-08-05 19:34:13 | 2026-08-06 17:33:41 | VulnCheck | boringproxy through 0.10.0 contains a newline injection vulnerability… | Details |
| CVE-2026-18959 | 2026-08-05 20:15:10 | 2026-08-06 17:32:18 | VulDB | A flaw has been found in yushine InnoShop… | Details |
| CVE-2026-28183 | 2026-08-06 14:27:17 | 2026-08-06 17:32:15 | Patchstack | This CVE ID has been rejected or withdrawn… | Details |
| CVE-2026-3418 | 2026-08-06 17:32:14 | 2026-08-06 17:32:14 | WSO2 | The System REST API accepts user-supplied file uploads… | Details |
| CVE-2026-18992 | 2026-08-06 03:30:10 | 2026-08-06 17:32:12 | VulDB | A vulnerability was detected in zhayujie CowAgent up… | Details |
| CVE-2026-3415 | 2026-08-06 17:32:10 | 2026-08-06 17:32:10 | WSO2 | The XML and schema validation functionalities within the… | Details |
| CVE-2026-18990 | 2026-08-06 02:15:08 | 2026-08-06 17:32:08 | VulDB | A vulnerability was detected in letta-ai LettaBot 0.2.0.… | Details |
| CVE-2025-14561 | 2026-08-06 17:32:07 | 2026-08-06 17:32:07 | WSO2 | In multi-tenant deployments, the Publisher REST APIs fail… | Details |
| CVE-2026-18998 | 2026-08-06 04:45:09 | 2026-08-06 17:32:05 | VulDB | A vulnerability was determined in cosmicstack-labs mercury-agent up… | Details |
| CVE-2025-12317 | 2026-08-06 17:32:05 | 2026-08-06 17:32:05 | WSO2 | When internal roles are removed from a user… | Details |
| CVE-2025-6508 | 2026-08-06 17:32:02 | 2026-08-06 17:32:02 | WSO2 | The Swagger UI Try-out console within the API… | Details |
| CVE-2024-6541 | 2026-08-06 17:31:59 | 2026-08-06 17:31:59 | WSO2 | The Class Mediator fails to correctly validate or… | Details |
| CVE-2026-18967 | 2026-08-06 05:33:17 | 2026-08-06 17:31:57 | redhat | A flaw was found in the SAML broker… | Details |
| CVE-2026-19008 | 2026-08-06 06:30:09 | 2026-08-06 17:31:50 | VulDB | A vulnerability was identified in mf-yang openclaw-cn up… | Details |
| CVE-2026-19020 | 2026-08-06 07:45:08 | 2026-08-06 17:31:42 | VulDB | A weakness has been identified in itsourcecode Hospital… | Details |
| CVE-2026-19036 | 2026-08-06 12:00:13 | 2026-08-06 17:31:36 | VulDB | A security flaw has been discovered in Shibby… | Details |
| CVE-2026-19041 | 2026-08-06 13:30:13 | 2026-08-06 17:31:30 | VulDB | A vulnerability has been found in MissionSquad mcp-api… | Details |
| CVE-2026-54489 | 2026-08-06 13:54:56 | 2026-08-06 17:31:24 | dell | Dell Virtual Storage Integrator for VMware vSphere Client,… | Details |
| CVE-2026-19064 | 2026-08-06 17:30:10 | 2026-08-06 17:30:10 | VulDB | A vulnerability was found in SourceCodester Online Examination… | Details |
| CVE-2026-67261 | 2026-08-06 13:50:11 | 2026-08-06 17:26:00 | dell | Dell Virtual Storage Integrator for VMware vSphere Client,… | Details |
| CVE-2026-70637 | 2026-08-06 14:15:09 | 2026-08-06 17:24:13 | VulnCheck | LightFTP through 2.4 contains multiple data race vulnerabilities… | Details |
| CVE-2026-28082 | 2026-08-06 14:27:08 | 2026-08-06 17:22:39 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in JetEngine <=… | Details |
| CVE-2026-64677 | 2026-08-06 17:21:43 | 2026-08-06 17:21:43 | GitHub_M | Anki is a program for creating and reviewing… | Details |
| CVE-2026-28143 | 2026-08-06 14:27:11 | 2026-08-06 17:20:23 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Forminator <=… | Details |
| CVE-2025-15674 | 2026-08-06 17:17:18 | 2026-08-06 17:17:18 | WPScan | The Passster WordPress plugin before 4.3.7 does not… | Details |
| CVE-2026-16620 | 2026-08-06 17:17:17 | 2026-08-06 17:17:17 | WPScan | The WPC Name Your Price for WooCommerce WordPress… | Details |
| CVE-2026-16619 | 2026-08-06 17:17:16 | 2026-08-06 17:17:16 | WPScan | The miniOrange 2FA WordPress plugin before 6.2.8 does… | Details |
| CVE-2026-28178 | 2026-08-06 14:27:15 | 2026-08-06 17:16:17 | Patchstack | Contributor Cross Site Scripting (XSS) in Powerkit <=… | Details |
| CVE-2026-19062 | 2026-08-06 17:15:08 | 2026-08-06 17:15:08 | VulDB | A vulnerability has been found in chiuwingyan house… | Details |
| CVE-2026-16067 | 2026-08-06 17:14:40 | 2026-08-06 17:14:40 | WPScan | The Event Booking Manager for WooCommerce (Pro) WordPress… | Details |
| CVE-2026-15256 | 2026-08-06 17:14:40 | 2026-08-06 17:14:40 | WPScan | The Ninja Forms WordPress plugin before 3.14.10 does… | Details |
| CVE-2026-17032 | 2026-08-06 17:14:39 | 2026-08-06 17:14:39 | WPScan | Multiple Supsystic Pro plugins were distributed with malicious… | Details |
| CVE-2026-32548 | 2026-08-06 14:27:18 | 2026-08-06 17:14:24 | Patchstack | Unauthenticated Broken Access Control in SureCart <= 4.6.2… | Details |
| CVE-2026-7406 | 2026-08-06 16:31:12 | 2026-08-06 17:14:14 | autodesk | A maliciously crafted BMP file, when parsed through… | Details |
| CVE-2026-7405 | 2026-08-06 16:17:54 | 2026-08-06 17:13:10 | autodesk | A maliciously crafted TIF file, when parsed through… | Details |
| CVE-2026-61982 | 2026-08-06 14:27:21 | 2026-08-06 17:12:23 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP… | Details |
| CVE-2026-71447 | 2026-08-06 17:04:53 | 2026-08-06 17:08:52 | CIRCL | AIL Project contains a stored cross-site scripting vulnerability… | Details |
| CVE-2026-13342 | 2026-08-06 17:07:33 | 2026-08-06 17:07:33 | WPScan | The Security Optimizer WordPress plugin from 1.5.8 to… | Details |
| CVE-2026-15149 | 2026-08-06 17:07:32 | 2026-08-06 17:07:32 | WPScan | The WP Hotel Booking WordPress plugin before 2.3.3… | Details |
| CVE-2026-15208 | 2026-08-06 17:07:32 | 2026-08-06 17:07:32 | WPScan | The RegistrationMagic WordPress plugin before 6.0.9.5 does not… | Details |
| CVE-2026-15147 | 2026-08-06 17:07:31 | 2026-08-06 17:07:31 | WPScan | The Five Star Restaurant Reservations WordPress plugin before… | Details |
| CVE-2026-10524 | 2026-08-06 17:07:30 | 2026-08-06 17:07:30 | WPScan | The CoCart WordPress plugin before 4.9.0 does not… | Details |
| CVE-2026-65509 | 2026-08-06 14:27:25 | 2026-08-06 17:07:01 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <=… | Details |
| CVE-2026-14831 | 2026-08-06 17:04:20 | 2026-08-06 17:04:20 | WPScan | The Easy Booking WordPress plugin before 3.5.0 does… | Details |
| CVE-2026-14936 | 2026-08-06 17:04:20 | 2026-08-06 17:04:20 | WPScan | The Simple Membership WordPress plugin before 4.7.7 does… | Details |
| CVE-2026-12501 | 2026-08-06 17:00:56 | 2026-08-06 17:00:56 | WPScan | The WP Travel Engine WordPress plugin before 6.8.2… | Details |
| CVE-2026-12901 | 2026-08-06 17:00:56 | 2026-08-06 17:00:56 | WPScan | The GetPaid WordPress plugin before 2.8.55 does not… | Details |
| CVE-2026-15152 | 2026-08-06 17:00:55 | 2026-08-06 17:00:55 | WPScan | The WP Hotel Booking WordPress plugin before 2.3.2… | Details |
| CVE-2026-14225 | 2026-08-06 17:00:54 | 2026-08-06 17:00:54 | WPScan | The Easy Appointments WordPress plugin through 3.12.26 does… | Details |
| CVE-2026-14842 | 2026-08-06 17:00:54 | 2026-08-06 17:00:54 | WPScan | The Events Made Easy WordPress plugin before 3.1.2… | Details |
| CVE-2026-19061 | 2026-08-06 17:00:09 | 2026-08-06 17:00:09 | VulDB | A flaw has been found in Insta InstaKNXServiceApp… | Details |
| CVE-2026-71446 | 2026-08-06 16:57:17 | 2026-08-06 16:57:17 | CIRCL | AIL Framework contains a stored cross-site scripting vulnerability… | Details |
| CVE-2026-65545 | 2026-08-06 14:27:32 | 2026-08-06 16:56:11 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in AI Engine… | Details |
| CVE-2026-65552 | 2026-08-06 14:27:35 | 2026-08-06 16:55:12 | Patchstack | Subscriber PHP Object Injection in Export User Data… | Details |
| CVE-2026-65560 | 2026-08-06 14:27:38 | 2026-08-06 16:54:41 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Houzez Property… | Details |
| CVE-2026-70635 | 2026-08-06 16:54:37 | 2026-08-06 16:54:37 | VulnCheck | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains… | Details |
| CVE-2026-65572 | 2026-08-06 14:27:42 | 2026-08-06 16:54:10 | Patchstack | Unauthenticated PHP Object Injection in A.Williams <= 1.3.1… | Details |
| CVE-2026-70634 | 2026-08-06 16:53:58 | 2026-08-06 16:53:58 | VulnCheck | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains… | Details |
| CVE-2026-65577 | 2026-08-06 14:27:45 | 2026-08-06 16:53:37 | Patchstack | Unauthenticated PHP Object Injection in Advice <= 1.18.0… | Details |
| CVE-2026-66439 | 2026-08-06 14:27:49 | 2026-08-06 16:52:46 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX… | Details |
| CVE-2026-14812 | 2026-08-06 16:52:36 | 2026-08-06 16:52:36 | WPScan | The Premium SEO WordPress plugin is malicious: it… | Details |
| CVE-2026-13399 | 2026-08-06 16:52:35 | 2026-08-06 16:52:35 | WPScan | The Payment Plugins for PayPal WooCommerce WordPress plugin… | Details |
| CVE-2026-70633 | 2026-08-06 16:51:26 | 2026-08-06 16:51:40 | VulnCheck | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains… | Details |
| CVE-2026-14306 | 2026-08-06 16:49:01 | 2026-08-06 16:49:01 | WPScan | The Tutor LMS WordPress plugin before 3.9.14 does… | Details |
| CVE-2026-71445 | 2026-08-06 16:48:50 | 2026-08-06 16:48:50 | CIRCL | AIL Framework contained a reflected cross-site scripting vulnerability… | Details |
| CVE-2026-12584 | 2026-08-06 16:48:24 | 2026-08-06 16:48:24 | WPScan | The Payment Gateway for Redsys & WooCommerce Lite… | Details |
| CVE-2026-66457 | 2026-08-06 14:27:52 | 2026-08-06 16:46:31 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Events Manager… | Details |
| CVE-2026-66665 | 2026-08-06 14:27:56 | 2026-08-06 16:45:26 | Patchstack | Unauthenticated Arbitrary File Upload in Type Hub <=… | Details |
| CVE-2026-11361 | 2026-08-06 16:45:22 | 2026-08-06 16:45:22 | WPScan | The Formidable Forms WordPress plugin before 6.32.1 does… | Details |
| CVE-2026-10599 | 2026-08-06 16:45:21 | 2026-08-06 16:45:21 | WPScan | The Integrate PhonePe with WooCommerce WordPress plugin through… | Details |
| CVE-2026-19060 | 2026-08-06 16:45:10 | 2026-08-06 16:45:10 | VulDB | A vulnerability was identified in FoundationAgents MetaGPT up… | Details |
| CVE-2026-66685 | 2026-08-06 14:27:59 | 2026-08-06 16:43:23 | Patchstack | Unauthenticated Sensitive Data Exposure in Featured Video Plus… | Details |
| CVE-2026-66694 | 2026-08-06 14:28:02 | 2026-08-06 16:42:53 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Thrive Architect… | Details |
| CVE-2026-11976 | 2026-08-06 16:40:18 | 2026-08-06 16:40:18 | WPScan | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`)… | Details |
| CVE-2026-71327 | 2026-08-06 16:38:11 | 2026-08-06 16:38:11 | GitHub_M | Traefik is an open source HTTP reverse proxy… | Details |
| CVE-2026-5336 | 2026-08-06 16:36:04 | 2026-08-06 16:36:04 | WPScan | The DataPress (Dataverse Integration) WordPress plugin before 2.91… | Details |
| CVE-2026-71326 | 2026-08-06 16:34:23 | 2026-08-06 16:34:23 | GitHub_M | Traefik is an open source HTTP reverse proxy… | Details |
| CVE-2026-18487 | 2026-08-06 16:32:39 | 2026-08-06 16:32:39 | fedora | A flaw was found in Epiphany. An issue… | Details |
| CVE-2026-19059 | 2026-08-06 16:30:09 | 2026-08-06 16:30:09 | VulDB | A vulnerability was determined in FoundationAgents MetaGPT up… | Details |
| CVE-2026-71325 | 2026-08-06 16:24:56 | 2026-08-06 16:24:56 | GitHub_M | Traefik is an open-source edge router that makes… | Details |
| CVE-2026-66702 | 2026-08-06 14:28:06 | 2026-08-06 16:14:24 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Rank Math… | Details |
| CVE-2026-66708 | 2026-08-06 14:28:09 | 2026-08-06 16:08:39 | Patchstack | Unauthenticated Broken Access Control in Total Upkeep <=… | Details |
| CVE-2026-19045 | 2026-08-06 14:30:10 | 2026-08-06 16:02:47 | VulDB | A weakness has been identified in NocteDefensor LudusMCP… | Details |
| CVE-2026-19046 | 2026-08-06 14:45:10 | 2026-08-06 15:59:13 | VulDB | A security vulnerability has been detected in NocteDefensor… | Details |
| CVE-2026-11803 | 2026-08-06 15:58:36 | 2026-08-06 15:58:36 | autodesk | A maliciously crafted PDF file, when parsed through… | Details |
| CVE-2026-8325 | 2026-08-06 15:58:02 | 2026-08-06 15:58:02 | autodesk | A maliciously crafted PDF file, when parsed through… | Details |
| CVE-2026-1289 | 2026-08-06 15:57:13 | 2026-08-06 15:57:13 | autodesk | A maliciously crafted PDF file, when parsed through… | Details |
| CVE-2026-71324 | 2026-08-06 15:56:33 | 2026-08-06 15:56:33 | GitHub_M | Traefik is an open source HTTP reverse proxy… | Details |
| CVE-2026-67870 | 2026-08-05 00:00:00 | 2026-08-06 15:54:03 | mitre | In open62541 v1.5.5, the server-side AddReferences implementation contains… | Details |
| CVE-2026-43632 | 2026-08-06 15:53:19 | 2026-08-06 15:53:19 | VulnCheck | llama.cpp builds b7492 through the latest b9060 contains… | Details |
| CVE-2026-43631 | 2026-08-06 15:52:09 | 2026-08-06 15:52:09 | VulnCheck | llama.cpp builds b7492 through the latest b9060 contains… | Details |
| CVE-2026-43630 | 2026-08-06 15:50:55 | 2026-08-06 15:50:55 | VulnCheck | llama.cpp builds b5702 through b7653 contain an out-of-bounds… | Details |
| CVE-2026-43629 | 2026-08-06 15:48:41 | 2026-08-06 15:48:41 | VulnCheck | llama.cpp builds b4882 through b9058 contain a heap… | Details |
| CVE-2026-3430 | 2026-08-06 15:09:23 | 2026-08-06 15:47:36 | WPScan | The Creative Mail WordPress plugin from 1.6.5 to… | Details |
| CVE-2026-70640 | 2026-08-06 15:38:22 | 2026-08-06 15:47:17 | VulnCheck | llama.cpp builds b1886 through b7445 contain a race… | Details |
| CVE-2026-70639 | 2026-08-06 15:37:30 | 2026-08-06 15:47:07 | VulnCheck | llama.cpp builds b1886 through b7445 contain a null… | Details |
| CVE-2026-18276 | 2026-08-06 15:11:03 | 2026-08-06 15:47:06 | GitLab | Missing authorization in the websocket consumer in Scripta… | Details |
| CVE-2026-70638 | 2026-08-06 15:35:08 | 2026-08-06 15:46:53 | VulnCheck | llama.cpp builds b1886 through b7445 contain an integer… | Details |
| CVE-2026-18275 | 2026-08-06 15:11:08 | 2026-08-06 15:46:45 | GitLab | Authorization bypass in the process and annotation taxonomy… | Details |
| CVE-2026-18359 | 2026-08-06 15:11:13 | 2026-08-06 15:46:28 | GitLab | Server-side request forgery in the METS and IIIF… | Details |
| CVE-2026-18277 | 2026-08-06 15:11:23 | 2026-08-06 15:46:08 | GitLab | Missing authorization in the OcrModelRight create and delete… | Details |
| CVE-2026-43628 | 2026-08-06 15:45:52 | 2026-08-06 15:45:52 | VulnCheck | llama.cpp builds b3978 through b9058 contain an integer… | Details |
| CVE-2026-18258 | 2026-08-06 15:11:28 | 2026-08-06 15:45:45 | GitLab | Authorization bypass in the Line, LineTranscription, VirtualCollection, tag… | Details |
| CVE-2026-5423 | 2026-08-06 15:15:29 | 2026-08-06 15:45:22 | Neo4j | @neo4j/graphql library versions prior to 7.5.6 fail to verify… | Details |
| CVE-2026-19058 | 2026-08-06 15:45:11 | 2026-08-06 15:45:11 | VulDB | A vulnerability was found in FoundationAgents MetaGPT up… | Details |
| CVE-2026-18427 | 2026-08-06 14:52:26 | 2026-08-06 15:44:54 | openjs | @fastify/static before version 10.1.3 contains an incomplete fix… | Details |
| CVE-2026-68749 | 2026-08-06 14:50:12 | 2026-08-06 15:44:22 | EEF | Inefficient Regular Expression Complexity vulnerability in the CSS… | Details |
| CVE-2026-68747 | 2026-08-06 14:50:03 | 2026-08-06 15:43:37 | EEF | Improper Neutralization of Special Elements in Output Used… | Details |
| CVE-2026-43627 | 2026-08-06 15:40:19 | 2026-08-06 15:43:06 | VulnCheck | llama.cpp builds b1283 through b9058 contain an integer… | Details |
| CVE-2026-66829 | 2026-08-06 14:49:23 | 2026-08-06 15:42:46 | EEF | URL Redirection to Untrusted Site ('Open Redirect') vulnerability… | Details |
| CVE-2026-66370 | 2026-08-06 14:49:15 | 2026-08-06 15:42:09 | EEF | URL Redirection to Untrusted Site ('Open Redirect') vulnerability… | Details |
| CVE-2026-68750 | 2026-08-06 14:50:20 | 2026-08-06 15:41:27 | EEF | Inefficient Algorithmic Complexity vulnerability in the traversal engine… | Details |
| CVE-2026-66843 | 2026-08-06 14:48:20 | 2026-08-06 15:40:50 | EEF | Inclusion of Functionality from Untrusted Control Sphere vulnerability… | Details |
| CVE-2026-51190 | 2026-08-03 00:00:00 | 2026-08-06 15:38:49 | mitre | The "s init" command in Serverless-Devs @serverless-devs/s <=… | Details |
| CVE-2026-67590 | 2026-08-05 05:33:39 | 2026-08-06 15:38:44 | apache | A pre-authentication attacker could leverage type nesting to… | Details |
| CVE-2026-51775 | 2026-08-03 00:00:00 | 2026-08-06 15:38:42 | mitre | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an… | Details |
| CVE-2026-52102 | 2026-08-03 00:00:00 | 2026-08-06 15:38:36 | mitre | An OS command injection vulnerability in the openmediavault-md… | Details |
| CVE-2026-67972 | 2026-08-03 00:00:00 | 2026-08-06 15:38:29 | mitre | An issue in the CF_CFDP_RecvMd() component of NASA… | Details |
| CVE-2026-67969 | 2026-08-03 00:00:00 | 2026-08-06 15:38:23 | mitre | An issue in the HS_MonitorApplications() component of NASA… | Details |
| CVE-2026-67970 | 2026-08-03 00:00:00 | 2026-08-06 15:38:17 | mitre | Incorrect access control in the DS_SetDestPathCmd() component of… | Details |
| CVE-2026-67974 | 2026-08-03 00:00:00 | 2026-08-06 15:38:10 | mitre | A parser boundary flaw in the Software Bus… | Details |
| CVE-2026-67975 | 2026-08-03 00:00:00 | 2026-08-06 15:38:05 | mitre | Incorrect access control in NASA cFS v7.0.1 allows… | Details |
| CVE-2026-53983 | 2026-08-06 15:38:02 | 2026-08-06 15:38:02 | VulnCheck | Ground Station prior to 0.6.0 contains an unauthenticated blind server-side… | Details |
| CVE-2026-68060 | 2026-08-05 05:26:27 | 2026-08-06 15:37:59 | apache | A pre-authentication attacker could leverage type size/count handling… | Details |
| CVE-2026-67551 | 2026-08-05 05:27:24 | 2026-08-06 15:37:53 | apache | pre-authentication attacker could leverage type size/count handling to… | Details |
| CVE-2026-67589 | 2026-08-05 05:28:15 | 2026-08-06 15:37:47 | apache | A pre-authentication attacker could leverage type size/count handling… | Details |
| CVE-2026-66274 | 2026-08-05 05:29:44 | 2026-08-06 15:37:40 | apache | A pre-authentication attacker could leverage type nesting to… | Details |
| CVE-2026-68073 | 2026-08-05 05:32:25 | 2026-08-06 15:37:34 | apache | A pre-authentication attacker could leverage type nesting to… | Details |
| CVE-2026-67552 | 2026-08-05 05:32:58 | 2026-08-06 15:37:28 | apache | A pre-authentication attacker could leverage type nesting to… | Details |
| CVE-2026-15991 | 2026-08-06 03:26:08 | 2026-08-06 15:37:22 | Wordfence | The File Manager plugin for WordPress is vulnerable… | Details |
| CVE-2026-18510 | 2026-08-06 05:29:25 | 2026-08-06 15:37:16 | Wordfence | The TranslatePress – Translate Multilingual sites with AI… | Details |
| CVE-2026-5391 | 2026-08-06 11:29:19 | 2026-08-06 15:37:10 | Wordfence | The LatePoint plugin for WordPress is vulnerable to… | Details |
| CVE-2026-28111 | 2026-08-06 14:27:09 | 2026-08-06 15:37:04 | Patchstack | Contributor Privilege Escalation in Forminator <= 1.56.0 versions.… | Details |
| CVE-2026-28146 | 2026-08-06 14:27:12 | 2026-08-06 15:36:57 | Patchstack | Contributor Arbitrary File Download in Unlimited Elements For… | Details |
| CVE-2026-28179 | 2026-08-06 14:27:15 | 2026-08-06 15:36:51 | Patchstack | Shop manager Cross Site Scripting (XSS) in FiboSearch… | Details |
| CVE-2026-61959 | 2026-08-06 14:27:19 | 2026-08-06 15:36:43 | Patchstack | Subscriber Cross Site Scripting (XSS) in Business Directory… | Details |
| CVE-2026-65502 | 2026-08-06 14:27:22 | 2026-08-06 15:36:38 | Patchstack | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons… | Details |
| CVE-2026-65513 | 2026-08-06 14:27:26 | 2026-08-06 15:36:29 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule… | Details |
| CVE-2026-65541 | 2026-08-06 14:27:29 | 2026-08-06 15:36:21 | Patchstack | Unauthenticated Broken Access Control in Staff Training <=… | Details |
| CVE-2026-53985 | 2026-08-06 15:19:44 | 2026-08-06 15:36:18 | VulnCheck | Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service… | Details |
| CVE-2026-65546 | 2026-08-06 14:27:32 | 2026-08-06 15:36:12 | Patchstack | Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1… | Details |
| CVE-2026-65553 | 2026-08-06 14:27:36 | 2026-08-06 15:36:06 | Patchstack | Unauthenticated Remote Code Execution (RCE) in Spider Analyser… | Details |
| CVE-2026-7867 | 2026-08-06 15:36:02 | 2026-08-06 15:36:02 | redhat | A flaw was found in udisks2. A local… | Details |
| CVE-2026-65565 | 2026-08-06 14:27:39 | 2026-08-06 15:35:59 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Survey Maker… | Details |
| CVE-2026-65573 | 2026-08-06 14:27:42 | 2026-08-06 15:35:53 | Patchstack | Unauthenticated PHP Object Injection in Abelle <= 1.22… | Details |
| CVE-2026-65578 | 2026-08-06 14:27:46 | 2026-08-06 15:35:48 | Patchstack | Unauthenticated PHP Object Injection in Agora <= 1.9… | Details |
| CVE-2026-66440 | 2026-08-06 14:27:49 | 2026-08-06 15:35:42 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in WPIDE –… | Details |
| CVE-2026-66470 | 2026-08-06 14:27:53 | 2026-08-06 15:35:36 | Patchstack | Subscriber Broken Access Control in Frontend Admin by… | Details |
| CVE-2026-66678 | 2026-08-06 14:27:56 | 2026-08-06 15:35:31 | Patchstack | Contributor Broken Access Control in Advanced Custom Fields:… | Details |
| CVE-2026-66686 | 2026-08-06 14:28:00 | 2026-08-06 15:35:25 | Patchstack | Unauthenticated Cross Site Request Forgery (CSRF) in Plugins… | Details |
| CVE-2026-66695 | 2026-08-06 14:28:03 | 2026-08-06 15:35:19 | Patchstack | Unauthenticated Path Traversal in W3 Total Cache <=… | Details |
| CVE-2026-66703 | 2026-08-06 14:28:06 | 2026-08-06 15:35:14 | Patchstack | Contributor Cross Site Scripting (XSS) in MailOptin <=… | Details |
| CVE-2026-66709 | 2026-08-06 14:28:10 | 2026-08-06 15:35:08 | Patchstack | Shop manager Remote Code Execution (RCE) in CTX… | Details |
| CVE-2026-16054 | 2026-08-06 06:00:09 | 2026-08-06 15:34:10 | WPScan | The Drag and Drop Multiple File Upload for… | Details |
| CVE-2026-53984 | 2026-08-06 15:33:49 | 2026-08-06 15:33:49 | VulnCheck | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction… | Details |
| CVE-2026-15246 | 2026-08-06 14:19:27 | 2026-08-06 15:33:06 | WPScan | The RealHomes Memberships WordPress plugin before 3.1.0 does… | Details |
| CVE-2026-13703 | 2026-08-06 06:00:13 | 2026-08-06 15:32:48 | WPScan | The SEO Redirection Plugin WordPress plugin before… | Details |
| CVE-2026-14204 | 2026-08-06 06:00:13 | 2026-08-06 15:31:31 | WPScan | The Google Authenticator WordPress plugin before 0.56 does… | Details |
| CVE-2026-66275 | 2026-08-05 05:34:48 | 2026-08-06 15:30:56 | apache | An authenticated attacker could exceed the session flow… | Details |
| CVE-2026-19024 | 2026-08-05 22:14:29 | 2026-08-06 15:30:56 | HDFG | NULL pointer dereference in H5Pget_fill_value in HDF5 before… | Details |
| CVE-2026-19023 | 2026-08-05 22:13:45 | 2026-08-06 15:30:38 | HDFG | Untrusted pointer dereference in the render_bin_output function in… | Details |
| CVE-2026-19054 | 2026-08-06 15:30:10 | 2026-08-06 15:30:10 | VulDB | A vulnerability was detected in Lspace-io lspace-server up… | Details |
| CVE-2026-50749 | 2026-08-05 15:11:05 | 2026-08-06 15:27:21 | apache | Improper Authorization vulnerability in Apache Answer. This issue affects… | Details |
| CVE-2026-68075 | 2026-08-05 05:36:02 | 2026-08-06 15:26:23 | apache | An authenticated attacker could exceed the session flow… | Details |
| CVE-2026-65576 | 2026-08-06 14:27:44 | 2026-08-06 15:24:09 | Patchstack | Unauthenticated PHP Object Injection in Adrena <= 1.2.14… | Details |
| CVE-2026-65571 | 2026-08-06 14:27:41 | 2026-08-06 15:23:11 | Patchstack | Unauthenticated PHP Object Injection in 69 Clothing <=… | Details |
| CVE-2026-65559 | 2026-08-06 14:27:38 | 2026-08-06 15:22:19 | Patchstack | Shop manager Privilege Escalation in Order Delivery Date… | Details |
| CVE-2026-65549 | 2026-08-06 14:27:34 | 2026-08-06 15:20:51 | Patchstack | Author PHP Object Injection in Jeg Kit for… | Details |
| CVE-2026-65544 | 2026-08-06 14:27:31 | 2026-08-06 15:20:11 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Super Socializer… | Details |
| CVE-2026-67553 | 2026-08-05 05:37:29 | 2026-08-06 15:19:37 | apache | An authenticated attacker could exceed the session flow… | Details |
| CVE-2026-65520 | 2026-08-06 14:27:28 | 2026-08-06 15:19:31 | Patchstack | Unauthenticated SQL Injection in WP OAuth Server <=… | Details |
| CVE-2026-65508 | 2026-08-06 14:27:24 | 2026-08-06 15:18:11 | Patchstack | Unauthenticated SQL Injection in Simply Schedule Appointments <=… | Details |
| CVE-2026-61964 | 2026-08-06 14:27:21 | 2026-08-06 15:17:11 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables… | Details |
| CVE-2026-32469 | 2026-08-06 14:27:17 | 2026-08-06 15:16:25 | Patchstack | Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0… | Details |
| CVE-2026-67591 | 2026-08-05 05:38:26 | 2026-08-06 15:16:01 | apache | An authenticated attacker could exceed the session flow… | Details |
| CVE-2026-28177 | 2026-08-06 14:27:14 | 2026-08-06 15:15:44 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Popup Maker… | Details |
| CVE-2026-66276 | 2026-08-05 05:39:30 | 2026-08-06 15:14:36 | apache | An authenticated attacker can craft a disposition frame… | Details |
| CVE-2026-68077 | 2026-08-05 05:41:07 | 2026-08-06 15:13:48 | apache | An authenticated attacker can craft a disposition frame… | Details |
| CVE-2026-16746 | 2026-08-05 06:00:10 | 2026-08-06 15:12:42 | WPScan | The MultiVendorX WordPress plugin before 5.0.11 does… | Details |
| CVE-2026-28141 | 2026-08-06 14:27:11 | 2026-08-06 15:11:39 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery… | Details |
| CVE-2026-16940 | 2026-08-05 06:00:10 | 2026-08-06 15:11:04 | WPScan | The Custom Fields WordPress plugin before 1.5.1 does… | Details |
| CVE-2026-64958 | 2026-08-06 10:13:04 | 2026-08-06 15:10:53 | apache | An incomplete fix for CVE-2026-50645 means that it is… | Details |
| CVE-2026-28005 | 2026-08-06 14:27:07 | 2026-08-06 15:10:51 | Patchstack | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer… | Details |
| CVE-2026-16981 | 2026-08-05 06:00:11 | 2026-08-06 15:09:49 | WPScan | The DHL Shipping Germany for WooCommerce WordPress plugin… | Details |
| CVE-2026-19038 | 2026-08-06 12:45:10 | 2026-08-06 15:09:44 | VulDB | A security vulnerability has been detected in MonomythDevelopment… | Details |
| CVE-2026-66712 | 2026-08-06 14:27:06 | 2026-08-06 15:08:41 | Patchstack | Unauthenticated Broken Access Control in Simple Membership <=… | Details |
| CVE-2026-70429 | 2026-08-05 17:40:29 | 2026-08-06 15:08:29 | jenkins | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier… | Details |
| CVE-2026-18969 | 2026-08-05 23:30:38 | 2026-08-06 15:08:09 | VulDB | A vulnerability was detected in Rongzhitong Visual Integrated… | Details |
| CVE-2026-53976 | 2026-08-06 14:24:32 | 2026-08-06 15:07:52 | VulnCheck | OpenChamber 1.11.7 contains a path traversal vulnerability in… | Details |
| CVE-2026-19005 | 2026-08-06 05:45:09 | 2026-08-06 15:06:38 | VulDB | A vulnerability was detected in nanocoai NanoClaw up… | Details |
| CVE-2026-66688 | 2026-08-06 14:28:00 | 2026-08-06 15:06:14 | Patchstack | Contributor Cross Site Scripting (XSS) in Ultimate Addons… | Details |
| CVE-2026-19040 | 2026-08-06 13:15:12 | 2026-08-06 15:05:57 | VulDB | A flaw has been found in MissionSquad mcp-api… | Details |
| CVE-2026-66696 | 2026-08-06 14:28:04 | 2026-08-06 15:05:54 | Patchstack | Contributor Sensitive Data Exposure in Gutenberg Blocks by… | Details |
| CVE-2026-70430 | 2026-08-05 17:40:29 | 2026-08-06 15:05:21 | jenkins | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier… | Details |
| CVE-2026-19022 | 2026-08-06 08:15:08 | 2026-08-06 15:04:51 | VulDB | A vulnerability was determined in OpenHands up to… | Details |
| CVE-2026-66705 | 2026-08-06 14:28:07 | 2026-08-06 15:04:00 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Facebook for… | Details |
| CVE-2026-66710 | 2026-08-06 14:28:10 | 2026-08-06 15:03:38 | Patchstack | Unauthenticated Local File Inclusion in e2pdf <= 1.32.40… | Details |
| CVE-2026-66681 | 2026-08-06 14:27:57 | 2026-08-06 15:03:00 | Patchstack | Unauthenticated Cross Site Request Forgery (CSRF) in Theme… | Details |
| CVE-2026-19035 | 2026-08-06 11:30:17 | 2026-08-06 15:02:49 | VulDB | A vulnerability was identified in Shibby Tomato 1.28.0000.… | Details |
| CVE-2026-70433 | 2026-08-05 17:40:31 | 2026-08-06 15:01:30 | jenkins | Missing permission checks in Jenkins HCL AppScan Plugin… | Details |
| CVE-2026-11983 | 2026-08-06 11:29:20 | 2026-08-06 15:00:43 | Wordfence | The Ad Inserter – Ad Manager & AdSense… | Details |
| CVE-2026-19047 | 2026-08-06 15:00:11 | 2026-08-06 15:00:11 | VulDB | A vulnerability was detected in NocteDefensor LudusMCP up… | Details |
| CVE-2026-70434 | 2026-08-05 17:40:32 | 2026-08-06 14:59:33 | jenkins | A cross-site request forgery (CSRF) vulnerability in Jenkins… | Details |
| CVE-2026-19019 | 2026-08-06 07:30:10 | 2026-08-06 14:58:31 | VulDB | A security flaw has been discovered in poco-ai… | Details |
| CVE-2026-70435 | 2026-08-05 17:40:33 | 2026-08-06 14:57:47 | jenkins | A missing permission check in Jenkins SCM-Manager Plugin… | Details |
| CVE-2026-18995 | 2026-08-06 04:00:11 | 2026-08-06 14:57:29 | VulDB | A flaw has been found in netease-youdao LobsterAI… | Details |
| CVE-2026-66662 | 2026-08-06 14:27:54 | 2026-08-06 14:57:28 | Patchstack | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps… | Details |
| CVE-2026-70436 | 2026-08-05 17:40:33 | 2026-08-06 14:56:37 | jenkins | Jenkins External Workspace Manager Plugin 1.4.1 and earlier… | Details |
| CVE-2026-19007 | 2026-08-06 06:15:08 | 2026-08-06 14:56:29 | VulDB | A vulnerability was determined in mf-yang openclaw-cn up… | Details |
| CVE-2026-66447 | 2026-08-06 14:27:50 | 2026-08-06 14:56:20 | Patchstack | Unauthenticated SQL Injection in WordPress File Upload <=… | Details |
| CVE-2026-65579 | 2026-08-06 14:27:46 | 2026-08-06 14:55:50 | Patchstack | Unauthenticated PHP Object Injection in Agricola <= 1.21.0… | Details |
| CVE-2026-18980 | 2026-08-06 02:00:16 | 2026-08-06 14:55:39 | VulDB | A vulnerability was identified in nearai ironclaw up… | Details |
| CVE-2026-65574 | 2026-08-06 14:27:43 | 2026-08-06 14:55:34 | Patchstack | Unauthenticated PHP Object Injection in Abogado <= 1.18… | Details |
| CVE-2026-70437 | 2026-08-05 17:40:34 | 2026-08-06 14:55:24 | jenkins | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and… | Details |
| CVE-2026-65569 | 2026-08-06 14:27:40 | 2026-08-06 14:55:15 | Patchstack | Subscriber SQL Injection in WP Job Portal <=… | Details |
| CVE-2026-18997 | 2026-08-06 04:30:10 | 2026-08-06 14:54:31 | VulDB | A vulnerability was found in cosmicstack-labs mercury-agent up… | Details |
| CVE-2026-65554 | 2026-08-06 14:27:36 | 2026-08-06 14:54:23 | Patchstack | Subscriber Broken Access Control in AnsPress – Question… | Details |
| CVE-2026-70438 | 2026-08-05 17:40:35 | 2026-08-06 14:54:04 | jenkins | A missing permission check in Jenkins Parameterized Remote… | Details |
| CVE-2026-65547 | 2026-08-06 14:27:33 | 2026-08-06 14:53:47 | Patchstack | Subscriber SQL Injection in Creative Mail <= 1.6.9… | Details |
| CVE-2026-65542 | 2026-08-06 14:27:30 | 2026-08-06 14:53:27 | Patchstack | Unauthenticated Broken Authentication in Super Socializer <= 7.14.5… | Details |
| CVE-2026-15459 | 2026-08-06 04:26:51 | 2026-08-06 14:53:08 | Wordfence | The WPMU DEV Dashboard plugin for WordPress is… | Details |
| CVE-2026-18991 | 2026-08-06 02:30:13 | 2026-08-06 14:52:17 | VulDB | A security vulnerability has been detected in nanocoai… | Details |
| CVE-2026-70445 | 2026-08-05 17:40:40 | 2026-08-06 14:52:13 | jenkins | Missing permission checks in Jenkins Sauce OnDemand Plugin… | Details |
| CVE-2026-18953 | 2026-08-05 19:33:10 | 2026-08-06 14:51:50 | AMZN | Improper limitation of a pathname to a restricted… | Details |
| CVE-2026-19010 | 2026-08-06 07:00:10 | 2026-08-06 14:51:42 | VulDB | A security vulnerability has been detected in TinyAGI… | Details |
| CVE-2026-65515 | 2026-08-06 14:27:26 | 2026-08-06 14:50:39 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <=… | Details |
| CVE-2026-18973 | 2026-08-06 00:30:12 | 2026-08-06 14:50:26 | VulDB | A vulnerability has been found in heshengtao super-agent-party… | Details |
| CVE-2026-71318 | 2026-08-05 21:21:30 | 2026-08-06 14:49:15 | GitHub_M | Nuxt is an open-source web development framework for… | Details |
| CVE-2026-68746 | 2026-08-05 19:43:38 | 2026-08-06 14:48:46 | EEF | Not Failing Securely ('Failing Open') vulnerability in livebook-dev… | Details |
| CVE-2026-61961 | 2026-08-06 14:27:19 | 2026-08-06 14:48:10 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <=… | Details |
| CVE-2026-65504 | 2026-08-06 14:27:23 | 2026-08-06 14:47:53 | Patchstack | Unauthenticated Broken Access Control in BOX NOW Delivery… | Details |
| CVE-2026-28180 | 2026-08-06 14:27:16 | 2026-08-06 14:47:32 | Patchstack | Unauthenticated Insecure Direct Object References (IDOR) in Mercado… | Details |
| CVE-2026-28169 | 2026-08-06 14:27:13 | 2026-08-06 14:47:12 | Patchstack | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom… | Details |
| CVE-2026-28139 | 2026-08-06 14:27:09 | 2026-08-06 14:46:49 | Patchstack | Unauthenticated PHP Object Injection in Ajax Search Lite… | Details |
| CVE-2026-19044 | 2026-08-06 14:15:10 | 2026-08-06 14:46:25 | VulDB | A flaw has been found in LeeSinLiang godot-mcp… | Details |
| CVE-2026-53975 | 2026-08-06 14:06:12 | 2026-08-06 14:45:26 | VulnCheck | OpenChamber 1.11.7 contains an unauthenticated remote code execution… | Details |
| CVE-2026-16315 | 2026-08-06 13:14:24 | 2026-08-06 14:44:35 | OMICRON | OMICRON StationGuard before version 4.10 contains a cryptographic… | Details |
| CVE-2026-16316 | 2026-08-06 13:14:25 | 2026-08-06 14:44:12 | OMICRON | OMICRON StationGuard 4.00 contains an improper input validation… | Details |
| CVE-2026-55524 | 2026-08-05 19:58:46 | 2026-08-06 14:43:50 | GitHub_M | PraisonAI is a multi-agent teams system. In versions… | Details |
| CVE-2026-16731 | 2026-08-06 13:14:25 | 2026-08-06 14:43:50 | OMICRON | OMICRON StationScout before version 3.05 contains a cryptographic… | Details |
| CVE-2026-12605 | 2026-08-06 13:18:05 | 2026-08-06 14:43:27 | eclipse | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF… | Details |
| CVE-2026-5134 | 2026-08-06 13:31:45 | 2026-08-06 14:42:41 | TR-CERT | Improper neutralization of special elements used in an… | Details |
| CVE-2026-15599 | 2026-08-06 12:37:22 | 2026-08-06 14:42:17 | TR-CERT | Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies… | Details |
| CVE-2026-13154 | 2026-08-06 06:00:12 | 2026-08-06 14:41:48 | WPScan | The Gutenberg Essential Blocks WordPress plugin before… | Details |
| CVE-2026-34966 | 2026-08-05 20:28:57 | 2026-08-06 14:41:17 | VulnCheck | Gitea prior to 1.27.0 contains a server-side request… | Details |
| CVE-2026-71313 | 2026-08-05 20:47:48 | 2026-08-06 14:40:45 | GitHub_M | rclone is a command-line program to sync files… | Details |
| CVE-2026-13153 | 2026-08-06 06:00:12 | 2026-08-06 14:40:32 | WPScan | The Gutenberg Essential Blocks WordPress plugin before… | Details |
| CVE-2026-18958 | 2026-08-05 20:00:10 | 2026-08-06 14:39:59 | VulDB | A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c.… | Details |
| CVE-2026-12713 | 2026-08-06 06:00:12 | 2026-08-06 14:39:54 | WPScan | The WPCargo Track & Trace WordPress plugin before… | Details |
| CVE-2025-15678 | 2026-08-06 06:00:12 | 2026-08-06 14:39:13 | WPScan | The Nexter Blocks WordPress plugin before 5.0.2… | Details |
| CVE-2026-70646 | 2026-08-06 14:38:52 | 2026-08-06 14:38:52 | GitHub_M | aiosend is a synchronous and asynchronous Crypto Pay… | Details |
| CVE-2026-60023 | 2026-08-05 15:12:08 | 2026-08-06 14:38:36 | apache | Exposure of Sensitive Information to an Unauthorized Actor… | Details |
| CVE-2026-55523 | 2026-08-05 19:26:22 | 2026-08-06 14:38:08 | GitHub_M | PraisonAI is a multi-agent teams system. In versions… | Details |
| CVE-2026-48912 | 2026-08-05 15:10:08 | 2026-08-06 14:37:55 | apache | Improper Input Validation vulnerability in Apache Answer. This issue… | Details |
| CVE-2026-48911 | 2026-08-05 15:09:14 | 2026-08-06 14:37:06 | apache | Insufficient Verification of Data Authenticity vulnerability in Apache… | Details |
| CVE-2026-48834 | 2026-08-05 15:07:35 | 2026-08-06 14:35:47 | apache | Improper Handling of Length Parameter Inconsistency vulnerability in… | Details |
| CVE-2026-69111 | 2026-08-05 19:18:23 | 2026-08-06 14:35:45 | VulnCheck | Milvus through 2.6.22 and 3.0.0 contains an unauthenticated… | Details |
| CVE-2026-19025 | 2026-08-05 22:35:11 | 2026-08-06 14:34:46 | HDFG | H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does… | Details |
| CVE-2026-7869 | 2026-08-05 18:13:15 | 2026-08-06 14:34:10 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable… | Details |
| CVE-2026-16734 | 2026-08-06 06:00:10 | 2026-08-06 14:33:15 | WPScan | The Stripe Payment Forms by WP Full Pay… | Details |
| CVE-2026-10128 | 2026-08-05 17:42:08 | 2026-08-06 14:32:28 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated… | Details |
| CVE-2026-19026 | 2026-08-05 22:47:58 | 2026-08-06 14:31:59 | HDFG | H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences… | Details |
| CVE-2026-70610 | 2026-08-05 17:41:03 | 2026-08-06 14:31:10 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-19027 | 2026-08-05 23:12:20 | 2026-08-06 14:30:48 | HDFG | The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c… | Details |
| CVE-2026-18531 | 2026-08-05 16:04:14 | 2026-08-06 14:29:40 | ibm | IBM Maximo Application Suite 9.2, 9.1, and 9.0… | Details |
| CVE-2026-16290 | 2026-08-06 06:00:09 | 2026-08-06 14:29:21 | WPScan | The ProfileGrid WordPress plugin before 6.0.0.0 does… | Details |
| CVE-2026-66707 | 2026-08-06 14:28:08 | 2026-08-06 14:28:08 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in Facebook for… | Details |
| CVE-2026-66701 | 2026-08-06 14:28:05 | 2026-08-06 14:28:05 | Patchstack | Unauthenticated Broken Access Control in Profile Builder <=… | Details |
| CVE-2026-66692 | 2026-08-06 14:28:02 | 2026-08-06 14:28:02 | Patchstack | Customer Insecure Direct Object References (IDOR) in Colissimo… | Details |
| CVE-2026-66684 | 2026-08-06 14:27:58 | 2026-08-06 14:27:58 | Patchstack | Unauthenticated Sensitive Data Exposure in Export Import Menus… | Details |
| CVE-2026-66664 | 2026-08-06 14:27:55 | 2026-08-06 14:27:55 | Patchstack | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin… | Details |
| CVE-2026-66452 | 2026-08-06 14:27:52 | 2026-08-06 14:27:52 | Patchstack | Unauthenticated Broken Access Control in Legal Text Connector… | Details |
| CVE-2026-66425 | 2026-08-06 14:27:48 | 2026-08-06 14:27:48 | Patchstack | Unauthenticated Broken Authentication in Gutena Forms – Contact… | Details |
| CVE-2026-16954 | 2026-08-06 06:00:10 | 2026-08-06 14:27:40 | WPScan | The AI Engine WordPress plugin before 3.6.4… | Details |
| CVE-2026-19028 | 2026-08-05 23:15:09 | 2026-08-06 14:25:52 | HDFG | H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes… | Details |
| CVE-2026-18050 | 2026-08-06 06:00:10 | 2026-08-06 14:24:54 | WPScan | The Events Manager WordPress plugin before 7.4… | Details |
| CVE-2026-14829 | 2026-08-06 06:00:11 | 2026-08-06 14:24:18 | WPScan | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery… | Details |
| CVE-2026-70605 | 2026-08-05 16:04:12 | 2026-08-06 14:24:06 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-10025 | 2026-08-05 16:03:19 | 2026-08-06 14:23:14 | ibm | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through… | Details |
| CVE-2026-70600 | 2026-08-05 15:40:27 | 2026-08-06 14:21:44 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-18970 | 2026-08-05 23:45:36 | 2026-08-06 14:21:24 | VulDB | A flaw has been found in Rongzhitong Visual… | Details |
| CVE-2026-49331 | 2026-08-05 14:40:45 | 2026-08-06 14:20:35 | redhat | A flaw was found in openshift/oauth-proxy. On paths… | Details |
| CVE-2026-18909 | 2026-08-06 03:46:00 | 2026-08-06 14:19:21 | ELAN | A stack-based buffer overflow vulnerability exists in ELAN… | Details |
| CVE-2026-70595 | 2026-08-05 14:37:21 | 2026-08-06 14:19:20 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-14313 | 2026-08-06 06:00:08 | 2026-08-06 14:18:21 | WPScan | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader… | Details |
| CVE-2026-16071 | 2026-08-05 13:50:54 | 2026-08-06 14:18:08 | redhat | A flaw was found in the LDAP storage… | Details |
| CVE-2026-14314 | 2026-08-06 06:00:08 | 2026-08-06 14:16:28 | WPScan | The PeproDev WooCommerce Receipt Uploader WordPress plugin through… | Details |
| CVE-2026-14240 | 2026-08-06 06:00:09 | 2026-08-06 14:14:10 | WPScan | The tourmaster WordPress plugin before 5.4.9 writes its… | Details |
| CVE-2026-14547 | 2026-08-06 06:00:09 | 2026-08-06 14:11:59 | WPScan | The Estatik Real Estate Plugin WordPress plugin before… | Details |
| CVE-2025-15028 | 2026-08-06 11:29:20 | 2026-08-06 14:09:26 | Wordfence | The FormGent – Next-Gen AI Form Builder for… | Details |
| CVE-2026-70556 | 2026-08-06 12:10:07 | 2026-08-06 14:08:50 | VulnCheck | Hubzilla 11.2.1 contains a cross-site request forgery vulnerability… | Details |
| CVE-2026-16268 | 2026-08-06 06:00:09 | 2026-08-06 14:08:39 | WPScan | The Newsletters WordPress plugin before 4.16 does not… | Details |
| CVE-2026-67864 | 2026-08-05 00:00:00 | 2026-08-06 14:07:36 | mitre | An issue in open62541 v.1.5.5 and before allows… | Details |
| CVE-2025-63823 | 2026-08-05 00:00:00 | 2026-08-06 14:06:02 | mitre | My Safetipin Android Application 5.2.1 contains Hardcoded credentials… | Details |
| CVE-2026-0673 | 2026-08-06 12:27:39 | 2026-08-06 14:05:57 | Wordfence | The Element Pack Addons for Elementor plugin for… | Details |
| CVE-2025-63822 | 2026-08-05 00:00:00 | 2026-08-06 14:04:30 | mitre | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect… | Details |
| CVE-2026-19039 | 2026-08-06 13:00:10 | 2026-08-06 13:59:05 | VulDB | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up… | Details |
| CVE-2026-18907 | 2026-08-05 01:47:16 | 2026-08-06 13:51:48 | TECNOMobile | Path Traversal in Download File Feature in com.talpa.hibrowser… | Details |
| CVE-2026-19037 | 2026-08-06 12:30:57 | 2026-08-06 13:50:39 | VulDB | A weakness has been identified in WonderTrader up… | Details |
| CVE-2026-65551 | 2026-08-06 12:47:56 | 2026-08-06 13:49:42 | Patchstack | Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting… | Details |
| CVE-2026-15996 | 2026-08-05 20:12:57 | 2026-08-06 13:48:59 | GitHub_P | A denial of service vulnerability was identified in… | Details |
| CVE-2026-66273 | 2026-08-05 05:23:31 | 2026-08-06 13:48:38 | apache | A pre-authentication attacker could leverage type size/count handling… | Details |
| CVE-2026-71310 | 2026-08-05 20:17:14 | 2026-08-06 13:47:34 | GitHub_M | rclone is a command-line program to sync files… | Details |
| CVE-2026-18411 | 2026-08-05 20:13:13 | 2026-08-06 13:46:47 | icscert | The KARR Security System and SWDS dealer-installed automotive… | Details |
| CVE-2026-71315 | 2026-08-05 21:05:15 | 2026-08-06 13:46:35 | GitHub_M | Nuxt is an open-source web development framework for… | Details |
| CVE-2026-71309 | 2026-08-05 20:13:30 | 2026-08-06 13:45:45 | GitHub_M | rclone is a command-line program to sync files… | Details |
| CVE-2026-71321 | 2026-08-05 21:42:48 | 2026-08-06 13:44:59 | GitHub_M | Nuxt is an open-source web development framework for… | Details |
| CVE-2026-67588 | 2026-08-05 05:21:44 | 2026-08-06 13:44:32 | apache | A pre-authentication attacker could leverage unbounded symbol value… | Details |
| CVE-2026-18649 | 2026-08-06 06:48:10 | 2026-08-06 13:42:09 | redhat | A flaw was found in the GStreamer gst-plugins-good… | Details |
| CVE-2026-17583 | 2026-08-05 20:23:32 | 2026-08-06 13:34:57 | icscert | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable… | Details |
| CVE-2026-18839 | 2026-08-05 20:45:17 | 2026-08-06 13:34:06 | redhat | An integer underflow was found in the popt… | Details |
| CVE-2026-71314 | 2026-08-05 20:58:50 | 2026-08-06 13:33:38 | GitHub_M | Nuxt is an open-source web development framework for… | Details |
| CVE-2026-18954 | 2026-08-05 20:07:35 | 2026-08-06 13:33:02 | AMZN | Incorrect authorization in the aggregation pipeline tool in… | Details |
| CVE-2026-18968 | 2026-08-05 23:00:10 | 2026-08-06 13:30:42 | VulDB | A security vulnerability has been detected in ttttonyhe… | Details |
| CVE-2026-18976 | 2026-08-06 01:45:12 | 2026-08-06 13:30:10 | VulDB | A vulnerability was determined in NousResearch hermes-agent up… | Details |
| CVE-2026-18993 | 2026-08-06 03:45:10 | 2026-08-06 13:27:35 | VulDB | A vulnerability was detected in NousResearch hermes-agent up… | Details |
| CVE-2026-67465 | 2026-08-05 05:21:04 | 2026-08-06 13:26:49 | apache | A pre-authentication attacker could leverage unbounded symbol value… | Details |
| CVE-2026-63457 | 2026-08-05 18:11:46 | 2026-08-06 13:19:37 | hpe | A potential denial of service vulnerability exists in… | Details |
| CVE-2026-68074 | 2026-08-05 05:19:55 | 2026-08-06 13:18:48 | apache | A pre-authentication attacker could leverage unbounded symbol value… | Details |
| CVE-2026-19000 | 2026-08-06 05:15:08 | 2026-08-06 13:16:06 | VulDB | A vulnerability was identified in JeecgBoot up to… | Details |
| CVE-2026-66257 | 2026-08-05 05:18:01 | 2026-08-06 13:13:32 | apache | A pre-authentication attacker could leverage unbounded symbol value… | Details |
| CVE-2026-18400 | 2026-08-06 05:29:25 | 2026-08-06 13:13:19 | Wordfence | The Slider, Gallery, and Carousel by MetaSlider –… | Details |
| CVE-2026-21766 | 2026-08-05 20:11:19 | 2026-08-06 13:12:46 | HCL | The default login portlet in HCL Digital Experience… | Details |
| CVE-2026-17556 | 2026-08-05 20:05:53 | 2026-08-06 13:11:06 | GitHub_P | A path traversal vulnerability was identified in GitHub… | Details |
| CVE-2026-71191 | 2026-08-05 05:01:20 | 2026-08-06 13:10:38 | mitre | In OpenStack Swift through 2.38.0, S3API middleware does… | Details |
| CVE-2026-70618 | 2026-08-05 19:57:35 | 2026-08-06 13:10:08 | VulnCheck | Spacebar Server before commit 51da17c contains a missing… | Details |
| CVE-2026-66885 | 2026-08-05 19:44:23 | 2026-08-06 13:09:29 | EEF | Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook… | Details |
| CVE-2026-71190 | 2026-08-05 04:54:03 | 2026-08-06 13:09:17 | mitre | In OpenStack Swift through 2.38.0, the proxy server… | Details |
| CVE-2026-66298 | 2026-08-05 19:44:11 | 2026-08-06 13:08:23 | EEF | Origin Validation Error vulnerability in livebook-dev livebook allows… | Details |
| CVE-2026-66297 | 2026-08-05 19:43:58 | 2026-08-06 13:04:30 | EEF | Improper Neutralization of Special Elements used in an… | Details |
| CVE-2026-66881 | 2026-08-05 19:43:48 | 2026-08-06 13:03:45 | EEF | Relative Path Traversal vulnerability in livebook-dev livebook allows… | Details |
| CVE-2026-55707 | 2026-08-05 04:44:16 | 2026-08-06 13:00:54 | mitre | In OpenStack Neutron before 28.0.2, the subnetpool onboarding… | Details |
| CVE-2026-67865 | 2026-08-05 00:00:00 | 2026-08-06 12:56:41 | mitre | S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse… | Details |
| CVE-2026-67863 | 2026-08-05 00:00:00 | 2026-08-06 12:45:48 | mitre | In open62541 1.5.5, a server-side use-after-free exists in… | Details |
| CVE-2026-67866 | 2026-08-05 00:00:00 | 2026-08-06 12:44:59 | mitre | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows… | Details |
| CVE-2026-11588 | 2026-08-06 06:00:11 | 2026-08-06 12:42:45 | WPScan | The EONSR AEO Agent WordPress plugin through 3.7.9… | Details |
| CVE-2026-16065 | 2026-08-06 06:00:11 | 2026-08-06 12:40:57 | WPScan | The Welcart e-Commerce WordPress plugin before 2.11.32 does… | Details |
| CVE-2026-67867 | 2026-08-05 00:00:00 | 2026-08-06 12:40:35 | mitre | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows… | Details |
| CVE-2026-18395 | 2026-08-06 06:00:11 | 2026-08-06 12:39:59 | WPScan | The Child Pages Card WordPress plugin before 1.09… | Details |
| CVE-2026-16537 | 2026-08-06 06:00:11 | 2026-08-06 12:39:16 | WPScan | The Slick Slider WordPress plugin before 0.5.3 does… | Details |
| CVE-2026-67869 | 2026-08-05 00:00:00 | 2026-08-06 12:37:55 | mitre | Buffer Overflow vulnerability in open62541 v1.5.5 allows a… | Details |
| CVE-2026-19009 | 2026-08-06 06:45:09 | 2026-08-06 12:37:47 | VulDB | A weakness has been identified in TinyAGI 0.0.20.… | Details |
| CVE-2025-11850 | 2026-08-06 07:33:07 | 2026-08-06 12:36:25 | WSO2 | When secondary user stores are configured, the implicit-association… | Details |
| CVE-2025-13736 | 2026-08-06 07:33:03 | 2026-08-06 12:35:37 | WSO2 | When Multi-Attribute Login is enabled, the login interface… | Details |
| CVE-2025-14779 | 2026-08-06 07:33:10 | 2026-08-06 12:35:21 | WSO2 | The Secret Type Management REST API does not… | Details |
| CVE-2026-67623 | 2026-08-05 13:27:27 | 2026-08-06 12:35:02 | VulnCheck | Mistral Vibe before 2.23.3 contains a remote code… | Details |
| CVE-2024-10302 | 2026-08-06 07:33:01 | 2026-08-06 12:34:59 | WSO2 | The user self-signup flow in multiple WSO2 products… | Details |
| CVE-2024-6832 | 2026-08-06 07:32:59 | 2026-08-06 12:34:29 | WSO2 | The account locking mechanism fails to trigger when… | Details |
| CVE-2024-8995 | 2026-08-06 07:32:56 | 2026-08-06 12:34:10 | WSO2 | Unused authorization codes issued to deleted users are… | Details |
| CVE-2026-67871 | 2026-08-05 00:00:00 | 2026-08-06 12:33:56 | mitre | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows… | Details |
| CVE-2025-12627 | 2026-08-06 07:33:12 | 2026-08-06 12:33:46 | WSO2 | The user impersonation flow in WSO2 Identity Server… | Details |
| CVE-2025-13909 | 2026-08-06 07:33:14 | 2026-08-06 12:33:19 | WSO2 | The system accepts authentication requests without sufficient validation… | Details |
| CVE-2026-18915 | 2026-08-06 07:33:16 | 2026-08-06 12:32:52 | TR-CERT | Invocation of process using visible sensitive information vulnerability… | Details |
| CVE-2025-13394 | 2026-08-06 07:33:17 | 2026-08-06 12:32:29 | WSO2 | The Ajax processor within the Carbon console fails… | Details |
| CVE-2026-0637 | 2026-08-06 07:33:20 | 2026-08-06 12:32:09 | WSO2 | When an Event Publisher output adapter is configured… | Details |
| CVE-2025-15039 | 2026-08-06 07:33:23 | 2026-08-06 12:31:43 | WSO2 | The Conditional Authentication (Adaptive Authentication) script does not… | Details |
| CVE-2026-1728 | 2026-08-06 07:33:25 | 2026-08-06 12:31:19 | WSO2 | Tokens issued to a low-privileged user are not… | Details |
| CVE-2026-5430 | 2026-08-06 07:33:28 | 2026-08-06 12:30:55 | WSO2 | The JWT authentication mechanism accepts tokens signed with… | Details |
| CVE-2026-18597 | 2026-08-06 07:37:34 | 2026-08-06 12:30:12 | Foxit | The PDF creation feature of Foxit PDF Services… | Details |
| CVE-2026-67872 | 2026-08-05 00:00:00 | 2026-08-06 12:28:47 | mitre | An issue in Systerel S2OPC 1.7.3 allows a… | Details |
| CVE-2026-19021 | 2026-08-06 08:00:09 | 2026-08-06 12:28:15 | VulDB | A security vulnerability has been detected in SourceCodester… | Details |
| CVE-2026-55978 | 2026-08-06 09:18:32 | 2026-08-06 12:25:17 | CSA | An improper access control vulnerability in CatchPulse could allow a… | Details |
| CVE-2026-55979 | 2026-08-06 09:20:55 | 2026-08-06 12:24:35 | CSA | An improper access control check in CatchPulse's named pipe communication… | Details |
| CVE-2026-67873 | 2026-08-05 00:00:00 | 2026-08-06 12:23:51 | mitre | A heap-based buffer overflow exists in lib60870-C 2.4.0… | Details |
| CVE-2026-55980 | 2026-08-06 09:23:50 | 2026-08-06 12:23:49 | CSA | A denial-of-service vulnerability in CatchPulse could allow an attacker to… | Details |
| CVE-2026-5158 | 2026-08-06 11:29:19 | 2026-08-06 12:22:22 | Wordfence | The Post Grid Gutenberg Blocks for News, Magazines,… | Details |
| CVE-2026-8166 | 2026-08-06 11:30:17 | 2026-08-06 12:21:42 | TR-CERT | Improper neutralization of input during web page generation… | Details |
| CVE-2026-52466 | 2026-08-05 00:00:00 | 2026-08-06 12:21:02 | mitre | Open Library Foundation VuFind v11.0.3 and v4.1 is… | Details |
| CVE-2026-16636 | 2026-08-06 03:26:07 | 2026-08-06 12:14:04 | Wordfence | The FluentSMTP – WP SMTP Plugin with Amazon… | Details |
| CVE-2026-18996 | 2026-08-06 04:15:09 | 2026-08-06 12:13:14 | VulDB | A vulnerability has been found in cosmicstack-labs mercury-agent… | Details |
| CVE-2026-19006 | 2026-08-06 06:00:11 | 2026-08-06 12:02:14 | VulDB | A vulnerability was found in mf-yang openclaw-cn 2026.2.5.… | Details |
| CVE-2026-19011 | 2026-08-06 07:15:08 | 2026-08-06 11:54:45 | VulDB | A vulnerability was detected in TinyAGI 0.0.20. The… | Details |
| CVE-2026-19034 | 2026-08-06 10:30:15 | 2026-08-06 11:43:55 | VulDB | A vulnerability was determined in Shibby Tomato 1.28.0000.… | Details |
| CVE-2026-70368 | 2026-08-04 13:52:25 | 2026-08-06 07:33:31 | redhat | A stack-based out-of-bounds read vulnerability exists in the… | Details |
| CVE-2026-70367 | 2026-08-04 13:52:20 | 2026-08-06 07:28:08 | redhat | A Server-Side Request Forgery (SSRF) bypass vulnerability exists… | Details |
| CVE-2026-64603 | 2026-08-06 07:13:55 | 2026-08-06 07:13:55 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64602 | 2026-08-06 07:13:54 | 2026-08-06 07:13:54 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64599 | 2026-08-06 07:13:53 | 2026-08-06 07:13:53 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64601 | 2026-08-06 07:13:53 | 2026-08-06 07:13:53 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64597 | 2026-08-06 07:13:52 | 2026-08-06 07:13:52 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64598 | 2026-08-06 07:13:52 | 2026-08-06 07:13:52 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64596 | 2026-08-06 07:13:51 | 2026-08-06 07:13:51 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64595 | 2026-08-06 07:13:50 | 2026-08-06 07:13:50 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64594 | 2026-08-06 07:13:50 | 2026-08-06 07:13:50 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64593 | 2026-08-06 07:13:49 | 2026-08-06 07:13:49 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64592 | 2026-08-06 07:13:49 | 2026-08-06 07:13:49 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64591 | 2026-08-06 07:13:48 | 2026-08-06 07:13:48 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64590 | 2026-08-06 07:13:47 | 2026-08-06 07:13:47 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64589 | 2026-08-06 07:13:47 | 2026-08-06 07:13:47 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64588 | 2026-08-06 07:13:46 | 2026-08-06 07:13:46 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64587 | 2026-08-06 07:06:27 | 2026-08-06 07:06:27 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64586 | 2026-08-06 07:06:27 | 2026-08-06 07:06:27 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64585 | 2026-08-06 07:06:26 | 2026-08-06 07:06:26 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64583 | 2026-08-06 07:06:25 | 2026-08-06 07:06:25 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64584 | 2026-08-06 07:06:25 | 2026-08-06 07:06:25 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-17624 | 2026-08-05 18:34:24 | 2026-08-06 03:56:00 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through… | Details |
| CVE-2026-17633 | 2026-08-05 18:33:51 | 2026-08-06 03:55:59 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 could allow… | Details |
| CVE-2026-17632 | 2026-08-05 18:33:26 | 2026-08-06 03:55:58 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 could allow… | Details |
| CVE-2026-9196 | 2026-08-05 18:27:39 | 2026-08-06 03:55:57 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 could allow… | Details |
| CVE-2026-8182 | 2026-08-05 18:26:29 | 2026-08-06 03:55:56 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow… | Details |
| CVE-2026-9201 | 2026-08-05 18:26:16 | 2026-08-06 03:55:54 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 could allow… | Details |
| CVE-2026-18485 | 2026-08-05 18:39:36 | 2026-08-06 03:55:53 | NI | There is a local privilege escalation vulnerability recently… | Details |
| CVE-2026-8478 | 2026-08-05 18:24:12 | 2026-08-06 03:55:52 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 could allow… | Details |
| CVE-2026-9205 | 2026-08-05 18:09:11 | 2026-08-06 03:55:51 | ibm | IBM Langflow OSS contains a weak cryptographic key… | Details |
| CVE-2026-70611 | 2026-08-05 17:49:09 | 2026-08-06 03:55:50 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-70609 | 2026-08-05 17:32:21 | 2026-08-06 03:55:49 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-20272 | 2026-08-05 16:19:26 | 2026-08-06 03:55:48 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-70431 | 2026-08-05 17:40:30 | 2026-08-06 03:55:47 | jenkins | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy… | Details |
| CVE-2026-70426 | 2026-08-05 17:40:27 | 2026-08-06 03:55:46 | jenkins | In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included… | Details |
| CVE-2026-20267 | 2026-08-05 16:18:50 | 2026-08-06 03:55:44 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20200 | 2026-08-05 16:18:32 | 2026-08-06 03:55:43 | cisco | A vulnerability in the web-based management interface of… | Details |
| CVE-2026-17625 | 2026-08-05 17:17:09 | 2026-08-06 03:55:42 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through… | Details |
| CVE-2026-17626 | 2026-08-05 16:31:13 | 2026-08-06 03:55:40 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could… | Details |
| CVE-2026-17623 | 2026-08-05 16:34:22 | 2026-08-06 03:55:39 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 could allow… | Details |
| CVE-2026-17630 | 2026-08-05 16:33:46 | 2026-08-06 03:55:38 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 could allow… | Details |
| CVE-2026-20304 | 2026-08-05 16:19:39 | 2026-08-06 03:55:37 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20312 | 2026-08-05 16:31:04 | 2026-08-06 03:55:36 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20310 | 2026-08-05 16:30:27 | 2026-08-06 03:55:34 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20303 | 2026-08-05 16:29:52 | 2026-08-06 03:55:33 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-13477 | 2026-08-05 15:59:05 | 2026-08-06 03:55:31 | ibm | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through… | Details |
| CVE-2026-20288 | 2026-08-05 16:27:53 | 2026-08-06 03:55:30 | cisco | A vulnerability in the web-based management interface of… | Details |
| CVE-2026-70597 | 2026-08-05 15:21:11 | 2026-08-06 03:55:28 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-70603 | 2026-08-05 15:56:50 | 2026-08-06 03:55:27 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-8400 | 2026-08-05 15:58:42 | 2026-08-06 03:55:25 | ibm | IBM WebSphere Application Server 8.5, and 9.0 and… | Details |
| CVE-2026-44945 | 2026-08-05 10:00:04 | 2026-08-06 03:55:24 | suse | A privilege escalation vulnerability exists in Rancher's impersonation… | Details |
| CVE-2026-55997 | 2026-08-05 07:53:00 | 2026-08-06 03:55:23 | suse | Rancher issues long-lived registration tokens to authenticate nodes… | Details |
| CVE-2026-70482 | 2026-08-04 19:51:58 | 2026-08-06 03:55:22 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-18739 | 2026-08-04 05:32:50 | 2026-08-05 21:49:04 | redhat | A flaw was found in popt, a command-line… | Details |
| CVE-2026-0516 | 2026-08-05 11:50:03 | 2026-08-05 19:57:27 | sonicwall | A improper neutralization of HTTP Headers for Scripting… | Details |
| CVE-2026-13158 | 2026-08-01 06:00:10 | 2026-08-05 19:49:08 | WPScan | The Everest Toolkit WordPress plugin through 1.2.3 does… | Details |
| CVE-2026-13157 | 2026-08-01 06:00:11 | 2026-08-05 19:48:45 | WPScan | The Demo Import WordPress plugin through 1.1.3… | Details |
| CVE-2026-12872 | 2026-08-03 06:00:11 | 2026-08-05 19:48:35 | WPScan | The Webinfos WordPress plugin through 1.2 does not… | Details |
| CVE-2026-69702 | 2026-08-04 17:45:32 | 2026-08-05 19:48:28 | VulnCheck | SnailJob 1.7.0 contains a denial of service vulnerability… | Details |
| CVE-2026-48154 | 2026-08-04 19:45:51 | 2026-08-05 19:48:20 | GitHub_M | GoRest is a Golang starter kit built with… | Details |
| CVE-2026-39923 | 2026-08-05 14:38:35 | 2026-08-05 19:48:08 | VulnCheck | Flarum before 1.8.16 contains a password reset token… | Details |
| CVE-2026-16613 | 2026-08-05 06:00:10 | 2026-08-05 19:48:03 | WPScan | The GDPR Cookie Compliance WordPress plugin before… | Details |
| CVE-2026-9130 | 2026-08-05 18:16:05 | 2026-08-05 19:42:47 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 contain an… | Details |
| CVE-2026-7658 | 2026-08-05 18:20:40 | 2026-08-05 19:42:27 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 does not… | Details |
| CVE-2026-16605 | 2026-08-05 06:00:09 | 2026-08-05 19:41:31 | WPScan | The MultiVendorX WordPress plugin before 5.0.11 does… | Details |
| CVE-2026-70439 | 2026-08-05 17:40:36 | 2026-08-05 19:40:18 | jenkins | Jenkins XML Job to Job DSL Plugin 0.1.13… | Details |
| CVE-2026-70442 | 2026-08-05 17:40:38 | 2026-08-05 19:38:47 | jenkins | Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier… | Details |
| CVE-2026-70446 | 2026-08-05 17:40:40 | 2026-08-05 19:38:39 | jenkins | Missing permission checks in Jenkins CodeSonar Plugin 3.6.0… | Details |
| CVE-2026-70443 | 2026-08-05 17:40:38 | 2026-08-05 19:37:23 | jenkins | Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not… | Details |
| CVE-2026-70444 | 2026-08-05 17:40:39 | 2026-08-05 19:36:10 | jenkins | A missing permission check in Jenkins Violation Comments… | Details |
| CVE-2026-15573 | 2026-08-05 13:50:03 | 2026-08-05 19:33:13 | redhat | A flaw was found in Keycloak's Authorization Services.… | Details |
| CVE-2026-54876 | 2026-08-05 13:59:36 | 2026-08-05 19:31:51 | openssl | Issue summary: A malicious TLS server can cause… | Details |
| CVE-2026-70447 | 2026-08-05 17:40:41 | 2026-08-05 19:31:22 | jenkins | Missing permission checks in Jenkins AWS CodeBuild Plugin… | Details |
| CVE-2025-70962 | 2026-08-05 00:00:00 | 2026-08-05 19:30:02 | mitre | Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access… | Details |
| CVE-2026-70448 | 2026-08-05 17:40:42 | 2026-08-05 19:28:50 | jenkins | Jenkins Ivy Report Plugin 1.2 and earlier does… | Details |
| CVE-2026-66902 | 2026-08-04 20:49:43 | 2026-08-05 19:27:48 | CPANSec | Google::Auth versions before 0.06 for Perl run a… | Details |
| CVE-2026-66901 | 2026-08-04 20:49:27 | 2026-08-05 19:26:51 | CPANSec | Google::Auth versions before 0.09 for Perl allow server… | Details |
| CVE-2026-48168 | 2026-08-05 18:29:38 | 2026-08-05 19:24:05 | GitHub_M | PraisonAI is a multi-agent teams system. In versions… | Details |
| CVE-2026-52520 | 2026-08-03 00:00:00 | 2026-08-05 19:21:16 | mitre | Emlog CMS <= 2.6.14 contains a stored cross-site… | Details |
| CVE-2026-52521 | 2026-08-03 00:00:00 | 2026-08-05 19:19:44 | mitre | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows… | Details |
| CVE-2026-67977 | 2026-08-03 00:00:00 | 2026-08-05 19:17:43 | mitre | An integer overflow in the Svc::FileDownlink::SendPartial component of… | Details |
| CVE-2026-67673 | 2026-08-03 00:00:00 | 2026-08-05 19:16:46 | mitre | A stack-based buffer overflow vulnerability exists in the… | Details |
| CVE-2026-70440 | 2026-08-05 17:40:36 | 2026-08-05 19:15:58 | jenkins | Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and… | Details |
| CVE-2026-70441 | 2026-08-05 17:40:37 | 2026-08-05 19:15:26 | jenkins | Jenkins Summary Display Plugin 1.15 and earlier does… | Details |
| CVE-2026-51401 | 2026-08-04 00:00:00 | 2026-08-05 19:14:26 | mitre | An issue in Vim Project v9.2.0389 and earlier… | Details |
| CVE-2026-67979 | 2026-08-04 00:00:00 | 2026-08-05 19:07:04 | mitre | Incorrect access control in the Executive Services dynamic… | Details |
| CVE-2026-8470 | 2026-08-05 18:11:52 | 2026-08-05 19:06:28 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through… | Details |
| CVE-2026-70478 | 2026-08-04 19:37:22 | 2026-08-05 19:05:33 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-55996 | 2026-08-05 07:46:43 | 2026-08-05 19:05:26 | suse | A denial-of-service vulnerability was identified in multiple TLS… | Details |
| CVE-2026-52370 | 2026-08-04 00:00:00 | 2026-08-05 19:05:07 | mitre | A reflected cross-site scripting (XSS) vulnerability in the… | Details |
| CVE-2026-70553 | 2026-08-04 19:37:43 | 2026-08-05 19:04:34 | VulnCheck | MaxSite CMS contains a remote code execution vulnerability… | Details |
| CVE-2026-70612 | 2026-08-05 17:56:41 | 2026-08-05 19:03:29 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-70483 | 2026-08-04 19:54:35 | 2026-08-05 19:03:01 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-10547 | 2026-08-05 18:14:29 | 2026-08-05 19:02:25 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 does not… | Details |
| CVE-2026-65986 | 2026-08-04 20:13:47 | 2026-08-05 18:54:56 | GitHub_M | CVAT is an open source interactive video and… | Details |
| CVE-2026-67855 | 2026-08-04 00:00:00 | 2026-08-05 18:54:07 | mitre | open62541 contains a heap use-after-free in the GDS… | Details |
| CVE-2026-8183 | 2026-08-05 18:23:21 | 2026-08-05 18:50:55 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through… | Details |
| CVE-2026-67856 | 2026-08-04 00:00:00 | 2026-08-05 18:50:49 | mitre | An issue in open62541 v.1.5.5 and before allows… | Details |
| CVE-2026-70608 | 2026-08-05 17:27:15 | 2026-08-05 18:46:49 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-16100 | 2026-08-05 13:50:57 | 2026-08-05 18:45:38 | redhat | A flaw was found in the user-event metrics… | Details |
| CVE-2026-44605 | 2026-08-05 17:29:27 | 2026-08-05 18:43:41 | redhat | A flaw was found in the RPM Package… | Details |
| CVE-2026-15572 | 2026-08-05 15:09:23 | 2026-08-05 18:42:39 | redhat | A flaw was found in Keycloak's Dynamic Client… | Details |
| CVE-2026-70599 | 2026-08-05 15:36:02 | 2026-08-05 18:41:57 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-9195 | 2026-08-05 15:38:11 | 2026-08-05 18:41:44 | ProgressSoftware | A cross-site scripting vulnerability in the Query Console… | Details |
| CVE-2026-70604 | 2026-08-05 15:59:24 | 2026-08-05 18:41:32 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-15656 | 2026-08-05 16:05:53 | 2026-08-05 18:41:26 | ibm | IBM Maximo Application Suite 9.2, 9.1, and 9.0… | Details |
| CVE-2026-14587 | 2026-08-05 16:10:47 | 2026-08-05 18:41:20 | Neo4j | Neo4j's Bolt modern handshake decoder treats an overlong… | Details |
| CVE-2026-9081 | 2026-08-05 17:38:52 | 2026-08-05 18:37:43 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0… | Details |
| CVE-2026-67860 | 2026-08-04 00:00:00 | 2026-08-05 18:34:12 | mitre | open62541 1.5.5 contains a heap-based buffer overflow in… | Details |
| CVE-2026-67862 | 2026-08-04 00:00:00 | 2026-08-05 18:29:29 | mitre | open62541 1.5.5 contains a buffer-overflow in the high-level… | Details |
| CVE-2026-70607 | 2026-08-05 16:24:11 | 2026-08-05 18:27:13 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-70432 | 2026-08-05 17:40:31 | 2026-08-05 18:27:00 | jenkins | A cross-site request forgery (CSRF) vulnerability in Jenkins… | Details |
| CVE-2026-70427 | 2026-08-05 17:40:27 | 2026-08-05 18:25:36 | jenkins | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier… | Details |
| CVE-2026-18812 | 2026-08-04 20:30:11 | 2026-08-05 18:22:50 | VulDB | A flaw has been found in H3C NX15… | Details |
| CVE-2026-70428 | 2026-08-05 17:40:28 | 2026-08-05 18:22:01 | jenkins | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier… | Details |
| CVE-2026-70598 | 2026-08-05 15:27:24 | 2026-08-05 18:15:50 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-16443 | 2026-08-05 13:44:09 | 2026-08-05 18:12:25 | redhat | A flaw was found in the SAML metadata… | Details |
| CVE-2026-16442 | 2026-08-05 15:00:39 | 2026-08-05 18:12:16 | redhat | A flaw was found in the SAML broker… | Details |
| CVE-2026-16102 | 2026-08-05 13:50:50 | 2026-08-05 18:11:59 | redhat | A flaw was found in the Dynamic Client… | Details |
| CVE-2026-9077 | 2026-08-05 16:24:43 | 2026-08-05 18:11:44 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows… | Details |
| CVE-2026-70490 | 2026-08-04 20:44:54 | 2026-08-05 18:07:10 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-7657 | 2026-08-05 17:37:58 | 2026-08-05 18:03:12 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could… | Details |
| CVE-2026-12730 | 2026-08-05 15:57:37 | 2026-08-05 17:59:18 | ibm | IBM Business Automation Workflow containers and traditional 26.0.0,… | Details |
| CVE-2026-7646 | 2026-08-05 16:25:39 | 2026-08-05 17:58:02 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 allows users… | Details |
| CVE-2026-70588 | 2026-08-04 21:03:42 | 2026-08-05 17:56:48 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-45103 | 2026-08-04 21:56:57 | 2026-08-05 17:55:45 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-18818 | 2026-08-04 22:30:08 | 2026-08-05 17:52:54 | VulDB | A weakness has been identified in Ehco1996 django-sspanel… | Details |
| CVE-2026-45537 | 2026-08-04 22:48:43 | 2026-08-05 17:48:44 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-15314 | 2026-08-04 16:59:45 | 2026-08-05 17:47:43 | TPLink | Tapo P110 v1 smart Wi-Fi Plug contains an improper… | Details |
| CVE-2026-20268 | 2026-08-05 16:18:54 | 2026-08-05 17:45:15 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20263 | 2026-08-05 16:18:33 | 2026-08-05 17:45:15 | cisco | A vulnerability in the Blocks Extensible Exchange Protocol… | Details |
| CVE-2026-20271 | 2026-08-05 16:19:22 | 2026-08-05 17:45:14 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20269 | 2026-08-05 16:19:04 | 2026-08-05 17:45:14 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20270 | 2026-08-05 16:19:09 | 2026-08-05 17:45:14 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20273 | 2026-08-05 16:19:38 | 2026-08-05 17:45:14 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-20294 | 2026-08-05 16:29:16 | 2026-08-05 17:45:13 | cisco | A vulnerability in the web-based management interface of… | Details |
| CVE-2026-20308 | 2026-08-05 16:19:49 | 2026-08-05 17:45:13 | cisco | A vulnerability in the web-based management interface of… | Details |
| CVE-2026-20301 | 2026-08-05 16:28:37 | 2026-08-05 17:45:13 | cisco | A vulnerability in the Extensible Messaging Client Protocol… | Details |
| CVE-2026-20311 | 2026-08-05 16:32:36 | 2026-08-05 17:45:12 | cisco | A vulnerability in the web-based management interface of… | Details |
| CVE-2026-20289 | 2026-08-05 16:31:56 | 2026-08-05 17:45:12 | cisco | A vulnerability in the logging subsystem of Cisco… | Details |
| CVE-2026-20313 | 2026-08-05 16:33:12 | 2026-08-05 17:45:11 | cisco | As part of Cisco's ongoing commitment to proactive… | Details |
| CVE-2026-10716 | 2026-08-05 16:50:49 | 2026-08-05 17:45:11 | Fluid Attacks | Directus contains an authenticated SQL injection vulnerability in… | Details |
| CVE-2026-67555 | 2026-08-05 05:43:57 | 2026-08-05 17:43:30 | apache | It was not possible to govern the maximum… | Details |
| CVE-2026-51400 | 2026-08-04 00:00:00 | 2026-08-05 17:42:08 | mitre | An issue in Vim Project v9.2.0389 and earlier… | Details |
| CVE-2026-70596 | 2026-08-05 14:40:12 | 2026-08-05 17:32:38 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-71201 | 2026-08-05 06:19:33 | 2026-08-05 17:32:05 | mitre | In OpenStack Ironic through 38.0.0, a project reader… | Details |
| CVE-2026-70601 | 2026-08-05 15:45:31 | 2026-08-05 17:30:28 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-12762 | 2026-08-05 15:52:56 | 2026-08-05 17:28:42 | ibm | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1,… | Details |
| CVE-2026-70606 | 2026-08-05 16:07:46 | 2026-08-05 17:23:30 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-20124 | 2026-08-05 16:18:21 | 2026-08-05 17:20:47 | cisco | A vulnerability in the Simple Network Management Protocol… | Details |
| CVE-2026-20198 | 2026-08-05 16:18:21 | 2026-08-05 17:20:19 | cisco | A vulnerability in the web-based management interface of… | Details |
| CVE-2026-20028 | 2026-08-05 16:18:08 | 2026-08-05 17:19:46 | cisco | A vulnerability in the network driver of Cisco… | Details |
| CVE-2026-17617 | 2026-08-05 16:18:22 | 2026-08-05 17:14:01 | ibm | IBM Application Gateway Operator 22.2 through 26.06 is… | Details |
| CVE-2026-8446 | 2026-08-05 16:27:46 | 2026-08-05 17:11:12 | ibm | IBM Langflow OSS 1.0.0 through 1.10.3 contain an… | Details |
| CVE-2026-18927 | 2026-08-05 16:30:08 | 2026-08-05 17:10:31 | VulDB | A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c.… | Details |
| CVE-2026-15932 | 2026-08-01 06:00:07 | 2026-08-05 16:20:11 | WPScan | The Support Genix WordPress plugin before 1.4.48… | Details |
| CVE-2026-14197 | 2026-08-01 06:00:08 | 2026-08-05 16:20:06 | WPScan | The Fluent Support WordPress plugin before 2.3.1… | Details |
| CVE-2026-14309 | 2026-08-01 06:00:08 | 2026-08-05 16:19:58 | WPScan | The Chat On Desk Order Notifications WordPress… | Details |
| CVE-2026-14596 | 2026-08-01 06:00:08 | 2026-08-05 16:19:52 | WPScan | The DynamicKit for Elementor WordPress plugin before 1.0.3… | Details |
| CVE-2026-14836 | 2026-08-01 06:00:09 | 2026-08-05 16:19:47 | WPScan | The Login & Register Forms WordPress plugin… | Details |
| CVE-2026-18856 | 2026-08-05 00:30:12 | 2026-08-05 16:19:40 | VulDB | A vulnerability was determined in Poesis Rhymix CMS… | Details |
| CVE-2026-8790 | 2026-08-05 04:25:26 | 2026-08-05 16:19:40 | Wordfence | The Football Pool plugin for WordPress is vulnerable… | Details |
| CVE-2026-15244 | 2026-08-01 06:00:09 | 2026-08-05 16:19:36 | WPScan | The HUSKY WordPress plugin before 1.4.1 does… | Details |
| CVE-2026-15368 | 2026-08-01 06:00:09 | 2026-08-05 16:19:28 | WPScan | The User Profile Builder WordPress plugin before… | Details |
| CVE-2026-10827 | 2026-08-01 06:00:11 | 2026-08-05 16:19:22 | WPScan | The Spectra Legacy WordPress plugin before 2.20.0… | Details |
| CVE-2026-11882 | 2026-08-01 06:00:11 | 2026-08-05 16:19:16 | WPScan | The Builderall for WordPress plugin before 3.0.2 does… | Details |
| CVE-2026-13604 | 2026-08-01 06:00:12 | 2026-08-05 16:19:10 | WPScan | The Pixelavo WordPress plugin before 1.5.4 registers… | Details |
| CVE-2026-13725 | 2026-08-01 06:00:12 | 2026-08-05 16:19:04 | WPScan | The Dynamic Pricing With Discount Rules for WooCommerce… | Details |
| CVE-2026-17506 | 2026-08-05 13:26:42 | 2026-08-05 16:18:55 | Wordfence | The Independent Analytics plugin for WordPress is vulnerable… | Details |
| CVE-2026-13729 | 2026-08-01 06:00:12 | 2026-08-05 16:18:54 | WPScan | The Podlove Podcast Publisher WordPress plugin before 4.5.3… | Details |
| CVE-2026-14195 | 2026-08-01 06:00:12 | 2026-08-05 16:18:45 | WPScan | The Brizy WordPress plugin before 2.8.18 does… | Details |
| CVE-2026-14214 | 2026-08-01 06:00:13 | 2026-08-05 16:18:39 | WPScan | The Booking for Appointments and Events Calendar … | Details |
| CVE-2026-14822 | 2026-08-01 06:00:13 | 2026-08-05 16:18:33 | WPScan | The Event Tickets and Registration WordPress plugin before… | Details |
| CVE-2026-14840 | 2026-08-01 06:00:14 | 2026-08-05 16:18:26 | WPScan | The YOP Poll WordPress plugin before 7.0.6 does… | Details |
| CVE-2026-14938 | 2026-08-02 06:00:08 | 2026-08-05 16:18:20 | WPScan | The FluentBoards WordPress plugin before 1.95.3 does… | Details |
| CVE-2026-18898 | 2026-08-05 03:00:09 | 2026-08-05 16:18:14 | VulDB | A security flaw has been discovered in UTT… | Details |
| CVE-2026-15248 | 2026-08-02 06:00:09 | 2026-08-05 16:18:13 | WPScan | The Meta Box WordPress plugin before 5.13.1 does… | Details |
| CVE-2026-15939 | 2026-08-02 06:00:10 | 2026-08-05 16:18:07 | WPScan | The Simple Restrict WordPress plugin before 1.2.9 does… | Details |
| CVE-2026-16256 | 2026-08-02 06:00:10 | 2026-08-05 16:17:57 | WPScan | The POUCO Import Users WordPress plugin through 1.0.0… | Details |
| CVE-2026-16143 | 2026-08-05 04:25:24 | 2026-08-05 16:17:57 | Wordfence | The VikRentItems – Flexible Rental Management System plugin… | Details |
| CVE-2026-11872 | 2026-08-02 06:00:10 | 2026-08-05 16:17:48 | WPScan | The Clever Mega Menu for Visual Composer WordPress… | Details |
| CVE-2026-11969 | 2026-08-05 07:39:22 | 2026-08-05 16:17:41 | Wordfence | The WP TripAdvisor Review Slider plugin for WordPress… | Details |
| CVE-2026-70602 | 2026-08-05 15:54:49 | 2026-08-05 16:13:06 | GitHub_M | Electron is a framework for writing cross-platform desktop… | Details |
| CVE-2026-8761 | 2026-08-05 04:25:24 | 2026-08-05 16:08:54 | Wordfence | The Dokan plugin for WordPress is vulnerable to… | Details |
| CVE-2026-66839 | 2026-08-05 04:26:13 | 2026-08-05 16:07:55 | jpcert | NetKids iMark, provided by Integrated Systems Technologies, Inc.,… | Details |
| CVE-2026-15587 | 2026-08-05 14:40:11 | 2026-08-05 16:07:31 | GoogleCloud | Improper Privilege Management in Google SecOps (Chronicle SOAR)… | Details |
| CVE-2026-14553 | 2026-08-05 06:00:11 | 2026-08-05 16:04:48 | WPScan | The zportals WordPress plugin before 6.3.4 does not… | Details |
| CVE-2026-17613 | 2026-08-05 14:12:03 | 2026-08-05 16:01:24 | certcc | Penpot’s ::import-binfile RPC command lacks authorization on the… | Details |
| CVE-2026-71273 | 2026-08-05 12:26:20 | 2026-08-05 15:59:42 | TuranSec | OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via… | Details |
| CVE-2026-7693 | 2026-08-05 06:37:59 | 2026-08-05 15:59:28 | Wordfence | The Backup Migration plugin for WordPress is vulnerable… | Details |
| CVE-2026-41447 | 2026-08-03 20:58:05 | 2026-08-05 15:58:21 | VulnCheck | FirmaCheck for Windows before 1.3.16 contains a DLL… | Details |
| CVE-2026-4431 | 2026-08-05 07:39:20 | 2026-08-05 15:58:19 | Wordfence | The Easy Post Submission plugin for WordPress is… | Details |
| CVE-2026-6639 | 2026-08-05 06:37:54 | 2026-08-05 15:57:25 | Wordfence | The AI Chatbot & Workflow Automation by AIWU… | Details |
| CVE-2026-71278 | 2026-08-05 12:26:24 | 2026-08-05 15:57:11 | TuranSec | rust-iot-platform allows creating a "calc rule" via POST… | Details |
| CVE-2026-71277 | 2026-08-05 12:26:23 | 2026-08-05 15:56:51 | TuranSec | rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether… | Details |
| CVE-2026-71275 | 2026-08-05 12:26:22 | 2026-08-05 15:56:22 | TuranSec | OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter… | Details |
| CVE-2026-71274 | 2026-08-05 12:26:21 | 2026-08-05 15:56:05 | TuranSec | OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via… | Details |
| CVE-2026-71276 | 2026-08-05 12:26:22 | 2026-08-05 15:55:40 | TuranSec | Magistrala (formerly Mainflux)'s message-readers API reads a `format`… | Details |
| CVE-2026-71279 | 2026-08-05 12:26:25 | 2026-08-05 15:55:11 | TuranSec | Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received… | Details |
| CVE-2026-17505 | 2026-08-05 06:37:57 | 2026-08-05 15:55:10 | Wordfence | The Translate Multilingual sites – TranslatePress plugin for… | Details |
| CVE-2026-71272 | 2026-08-05 12:26:19 | 2026-08-05 15:54:41 | TuranSec | Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the… | Details |
| CVE-2026-71267 | 2026-08-05 12:26:14 | 2026-08-05 15:54:12 | TuranSec | microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a… | Details |
| CVE-2026-5581 | 2026-08-05 06:37:53 | 2026-08-05 15:54:04 | Wordfence | The Multi Uploader for Gravity Forms plugin for… | Details |
| CVE-2026-71282 | 2026-08-05 12:26:28 | 2026-08-05 15:53:45 | TuranSec | ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both… | Details |
| CVE-2026-71283 | 2026-08-05 12:26:29 | 2026-08-05 15:53:15 | TuranSec | Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path)… | Details |
| CVE-2026-71284 | 2026-08-05 12:26:30 | 2026-08-05 15:52:42 | TuranSec | Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), takes the… | Details |
| CVE-2026-15941 | 2026-08-05 05:27:37 | 2026-08-05 15:52:33 | Wordfence | The plugin provides an Admin Search page that… | Details |
| CVE-2026-71285 | 2026-08-05 12:26:30 | 2026-08-05 15:52:11 | TuranSec | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the… | Details |
| CVE-2026-71281 | 2026-08-05 12:26:27 | 2026-08-05 15:51:29 | TuranSec | Hugging Face peft's LoRA-GA and CorDA initialization modules… | Details |
| CVE-2026-71280 | 2026-08-05 12:26:26 | 2026-08-05 15:50:53 | TuranSec | go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL… | Details |
| CVE-2026-71288 | 2026-08-05 12:26:34 | 2026-08-05 15:49:58 | TuranSec | Koha's guided report builder (reports/guided_reports.pl) reads the `order_by`… | Details |
| CVE-2026-71289 | 2026-08-05 12:26:34 | 2026-08-05 15:49:24 | TuranSec | The NASA-AMMOS Asynchronous Network Management System (ANMS) reference… | Details |
| CVE-2026-39924 | 2026-08-05 14:40:27 | 2026-08-05 15:49:01 | VulnCheck | Flarum before 1.8.16 contains an improper session invalidation… | Details |
| CVE-2026-71287 | 2026-08-05 12:26:33 | 2026-08-05 15:48:50 | TuranSec | Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column… | Details |
| CVE-2026-71291 | 2026-08-05 12:38:41 | 2026-08-05 15:47:35 | TuranSec | Bolt CMS renders content field values through Twig's… | Details |
| CVE-2026-71292 | 2026-08-05 12:38:43 | 2026-08-05 15:46:21 | TuranSec | Subrion CMS's admin grid sorting helper, _gridGetSorting() in… | Details |
| CVE-2026-71286 | 2026-08-05 12:26:31 | 2026-08-05 15:45:49 | TuranSec | The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its… | Details |
| CVE-2026-67554 | 2026-08-05 05:41:26 | 2026-08-05 15:44:38 | apache | An authenticated attacker can craft a disposition frame… | Details |
| CVE-2026-61486 | 2026-08-05 06:44:11 | 2026-08-05 15:44:15 | apache | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow… | Details |
| CVE-2026-61485 | 2026-08-05 06:43:27 | 2026-08-05 15:44:13 | apache | ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with… | Details |
| CVE-2026-61484 | 2026-08-05 06:42:06 | 2026-08-05 15:44:12 | apache | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted… | Details |
| CVE-2026-71270 | 2026-08-05 12:26:17 | 2026-08-05 15:43:06 | TuranSec | Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated… | Details |
| CVE-2026-71269 | 2026-08-05 12:26:16 | 2026-08-05 15:42:25 | TuranSec | Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry()… | Details |
| CVE-2026-71268 | 2026-08-05 12:26:15 | 2026-08-05 15:41:47 | TuranSec | OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path… | Details |
| CVE-2026-71266 | 2026-08-05 12:26:14 | 2026-08-05 15:40:58 | TuranSec | tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c.h) reads each line of a… | Details |
| CVE-2026-71264 | 2026-08-05 12:26:12 | 2026-08-05 15:40:22 | TuranSec | WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls… | Details |
| CVE-2026-71263 | 2026-08-05 12:26:11 | 2026-08-05 15:39:36 | TuranSec | The LINUXTCP port of FreeModbus contains an off-by-one… | Details |
| CVE-2026-66277 | 2026-08-05 05:42:30 | 2026-08-05 15:38:51 | apache | It was not possible to govern the maximum… | Details |
| CVE-2026-71262 | 2026-08-05 12:26:10 | 2026-08-05 15:38:42 | TuranSec | IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to… | Details |
| CVE-2026-71271 | 2026-08-05 12:26:18 | 2026-08-05 15:38:10 | TuranSec | Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a… | Details |
| CVE-2026-71261 | 2026-08-05 12:26:09 | 2026-08-05 15:37:07 | TuranSec | dr_libs dr_wav.h (all versions through current master) contains… | Details |
| CVE-2026-14823 | 2026-08-01 06:00:13 | 2026-08-05 15:36:45 | WPScan | The Event Tickets and Registration WordPress plugin before… | Details |
| CVE-2026-71293 | 2026-08-05 12:38:44 | 2026-08-05 15:36:07 | TuranSec | Statamic CMS's user-augmentation resolver, AugmentedUser::get() in src/Auth/AugmentedUser.php, contains… | Details |
| CVE-2026-71294 | 2026-08-05 12:38:48 | 2026-08-05 15:35:10 | TuranSec | Cotonti CMS's Comments plugin deserializes user-supplied data without… | Details |
| CVE-2026-53992 | 2026-08-05 14:54:41 | 2026-08-05 15:33:05 | VulnCheck | ProjectSend r2029 contains a reflected cross-site scripting vulnerability… | Details |
| CVE-2026-12410 | 2026-08-05 14:14:09 | 2026-08-05 15:32:26 | GEN | Link following vulnerability in the Uninstaller component in… | Details |
| CVE-2026-71260 | 2026-08-05 12:26:08 | 2026-08-05 15:31:34 | TuranSec | ESPHome through 2026.7.0-dev discloses plaintext passwords via its… | Details |
| CVE-2026-71265 | 2026-08-05 12:26:13 | 2026-08-05 15:30:10 | TuranSec | Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies… | Details |
| CVE-2026-68078 | 2026-08-05 05:43:35 | 2026-08-05 15:29:55 | apache | It was not possible to govern the maximum… | Details |
| CVE-2026-71259 | 2026-08-05 12:26:07 | 2026-08-05 15:29:29 | TuranSec | ESPHome through 2026.7.0-dev contains an operator-precedence bug in… | Details |
| CVE-2026-16022 | 2026-08-05 12:06:19 | 2026-08-05 15:28:35 | NCSC.ch | @oblique/cli 15.4.0 contains an OS command injection vulnerability… | Details |
| CVE-2026-16583 | 2026-08-05 06:00:09 | 2026-08-05 15:22:36 | WPScan | The Orbit Fox: Duplicate Page, Menu Icons, SVG… | Details |
| CVE-2026-42169 | 2026-08-04 03:15:25 | 2026-08-05 15:21:41 | redhat | A heap-buffer-overflow vulnerability exists in the APNG (Animated… | Details |
| CVE-2026-16602 | 2026-08-05 06:00:09 | 2026-08-05 15:20:52 | WPScan | The Passster WordPress plugin before 4.3.6 does… | Details |
| CVE-2026-16603 | 2026-08-05 06:00:09 | 2026-08-05 15:20:22 | WPScan | The Passster WordPress plugin before 4.3.6 does… | Details |
| CVE-2026-67592 | 2026-08-05 05:44:18 | 2026-08-05 15:20:13 | apache | It was not possible to govern the maximum… | Details |
| CVE-2026-16604 | 2026-08-05 06:00:09 | 2026-08-05 15:19:52 | WPScan | The Passster WordPress plugin before 4.3.6 outputs… | Details |
| CVE-2026-16736 | 2026-08-05 06:00:10 | 2026-08-05 15:18:10 | WPScan | The User Registration & Membership WordPress plugin… | Details |
| CVE-2026-16036 | 2026-08-05 06:00:12 | 2026-08-05 15:17:06 | WPScan | The miniOrange 2FA WordPress plugin before 6.2.7… | Details |
| CVE-2026-15372 | 2026-08-05 06:00:12 | 2026-08-05 15:15:35 | WPScan | The WP 2FA WordPress plugin before 4.1.0… | Details |
| CVE-2026-15360 | 2026-08-05 06:00:12 | 2026-08-05 15:13:01 | WPScan | The Ajax Load More WordPress plugin before… | Details |
| CVE-2026-15230 | 2026-08-05 06:00:11 | 2026-08-05 15:12:26 | WPScan | The YayPricing WordPress plugin before 3.5.7 does… | Details |
| CVE-2026-16968 | 2026-08-05 06:00:10 | 2026-08-05 15:11:45 | WPScan | The GeoDirectory WordPress plugin before 2.8.168 does… | Details |
| CVE-2026-16942 | 2026-08-05 06:00:10 | 2026-08-05 15:11:05 | WPScan | The WP Custom HTML Page WordPress plugin through… | Details |
| CVE-2026-70619 | 2026-08-04 21:21:30 | 2026-08-05 15:10:51 | VulnCheck | Odysseus before commit bf325f6 contains a missing authorization… | Details |
| CVE-2026-15210 | 2026-08-05 06:00:12 | 2026-08-05 15:10:18 | WPScan | The OTP Login With Phone Number, OTP Verification… | Details |
| CVE-2026-67973 | 2026-08-03 00:00:00 | 2026-08-05 15:09:00 | mitre | An issue in the CFDP receive path of… | Details |
| CVE-2026-16791 | 2026-08-04 19:47:55 | 2026-08-05 15:08:08 | lenovo | A temporary file creation vulnerability in the Linux… | Details |
| CVE-2026-70374 | 2026-08-05 05:46:19 | 2026-08-05 15:07:29 | TuranSec | HashBrown CMS through 1.4.6 contains an OS Command… | Details |
| CVE-2026-67976 | 2026-08-03 00:00:00 | 2026-08-05 15:05:43 | mitre | The Ref::SignalGen component of fprime framework v4.2.2 does… | Details |
| CVE-2026-70375 | 2026-08-05 05:46:26 | 2026-08-05 15:03:00 | TuranSec | HashBrown CMS through 1.4.6 contains an OS Command… | Details |
| CVE-2026-70472 | 2026-08-04 17:46:05 | 2026-08-05 15:01:55 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-18903 | 2026-08-05 04:45:08 | 2026-08-05 15:01:16 | VulDB | A vulnerability was determined in yeqifu warehouse up… | Details |
| CVE-2026-47763 | 2026-08-04 17:29:41 | 2026-08-05 15:00:39 | GitHub_M | pdm is a Python package and dependency manager… | Details |
| CVE-2026-69258 | 2026-08-04 15:56:06 | 2026-08-05 14:59:55 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-68080 | 2026-08-05 05:51:22 | 2026-08-05 14:58:48 | apache | It was not possible to govern the rate… | Details |
| CVE-2026-18811 | 2026-08-04 20:15:07 | 2026-08-05 14:58:27 | VulDB | A vulnerability was detected in H3C NX15 V100R017.… | Details |
| CVE-2026-18817 | 2026-08-04 22:00:12 | 2026-08-05 14:57:08 | VulDB | A security flaw has been discovered in Baserow… | Details |
| CVE-2026-18784 | 2026-08-04 16:30:09 | 2026-08-05 14:55:36 | VulDB | A vulnerability was found in o6 open62541 up… | Details |
| CVE-2026-18854 | 2026-08-05 00:00:40 | 2026-08-05 14:55:22 | VulDB | A vulnerability has been found in Shandong Hoteam… | Details |
| CVE-2026-69098 | 2026-08-04 15:15:06 | 2026-08-05 14:54:51 | VulnCheck | kotaemon through 0.12.0 contains an insecure deserialization vulnerability… | Details |
| CVE-2026-69243 | 2026-08-03 20:45:43 | 2026-08-05 14:54:06 | GitHub_M | AIOHTTP is an asynchronous HTTP client/server framework for… | Details |
| CVE-2026-18897 | 2026-08-05 02:00:12 | 2026-08-05 14:54:00 | VulDB | A vulnerability was identified in UTT HiPER 1250GW… | Details |
| CVE-2026-69704 | 2026-08-04 18:47:05 | 2026-08-05 14:53:20 | VulnCheck | Atals-Livre contains a SQL injection vulnerability that allows… | Details |
| CVE-2026-16561 | 2026-08-05 06:00:08 | 2026-08-05 14:51:36 | WPScan | The Sunshine Photo Cart WordPress plugin before… | Details |
| CVE-2026-70476 | 2026-08-04 19:23:57 | 2026-08-05 14:51:23 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-18656 | 2026-08-04 19:35:43 | 2026-08-05 14:50:43 | AMZN | An uncontrolled search path element in Kiro IDE… | Details |
| CVE-2026-70479 | 2026-08-04 19:40:12 | 2026-08-05 14:49:42 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-16792 | 2026-08-04 19:48:03 | 2026-08-05 14:48:58 | lenovo | An improper certificate validation vulnerability was reported in… | Details |
| CVE-2026-16793 | 2026-08-04 19:48:11 | 2026-08-05 14:48:38 | lenovo | An improper neutralization of special elements used in… | Details |
| CVE-2026-70484 | 2026-08-04 19:56:54 | 2026-08-05 14:48:18 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-18810 | 2026-08-04 20:00:09 | 2026-08-05 14:47:30 | VulDB | A security vulnerability has been detected in H3C… | Details |
| CVE-2026-70487 | 2026-08-04 20:16:11 | 2026-08-05 14:46:10 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-70491 | 2026-08-04 20:51:27 | 2026-08-05 14:45:34 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-13227 | 2026-08-04 20:53:53 | 2026-08-05 14:44:49 | Fluid Attacks | An Improper Authorization vulnerability exists in ERPNext version… | Details |
| CVE-2026-6627 | 2026-08-05 06:37:55 | 2026-08-05 14:44:48 | Wordfence | The WPFormify – Stripe Payments with Form and… | Details |
| CVE-2026-7529 | 2026-08-05 13:26:42 | 2026-08-05 14:43:46 | Wordfence | The wiseCampaign – WooCommerce Conversions Made Easy plugin… | Details |
| CVE-2026-69253 | 2026-08-04 15:13:39 | 2026-08-05 14:42:10 | GitHub_M | Flowise is a drag-and-drop user interface for building… | Details |
| CVE-2026-70492 | 2026-08-04 20:53:36 | 2026-08-05 14:41:30 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-15979 | 2026-08-05 13:26:43 | 2026-08-05 14:40:28 | Wordfence | The Content Egg – Affiliate Product Importer &… | Details |
| CVE-2026-18766 | 2026-08-04 14:15:10 | 2026-08-05 14:40:24 | VulDB | A flaw has been found in chetans9 core-php-admin-panel… | Details |
| CVE-2026-70485 | 2026-08-04 19:59:21 | 2026-08-05 14:40:22 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-67196 | 2026-08-04 14:03:41 | 2026-08-05 14:38:55 | VulnCheck | Perspective 5.0.0 contains a cross-site scripting vulnerability in… | Details |
| CVE-2026-46581 | 2026-08-05 11:09:41 | 2026-08-05 14:38:08 | eclipse | In Eclipse Mojarra versions 2.3 and following, URL… | Details |
| CVE-2026-18719 | 2026-08-04 01:15:09 | 2026-08-05 14:37:34 | VulDB | A vulnerability was detected in cemtan sar2html 4.0.0.… | Details |
| CVE-2026-67859 | 2026-08-04 00:00:00 | 2026-08-05 14:36:45 | mitre | Buffer Overflow vulnerability in open62541 v1.5.5 allows a… | Details |
| CVE-2026-67861 | 2026-08-04 00:00:00 | 2026-08-05 14:34:06 | mitre | An issue in open62541 v.1.5.5 and before allows… | Details |
| CVE-2026-67858 | 2026-08-04 00:00:00 | 2026-08-05 14:33:03 | mitre | Buffer Overflow vulnerability exists in open62541 1.5.5 when… | Details |
| CVE-2026-67857 | 2026-08-04 00:00:00 | 2026-08-05 14:31:49 | mitre | open62541 1.5.5 contains an out-of-bounds read in the… | Details |
| CVE-2026-51144 | 2026-08-04 00:00:00 | 2026-08-05 14:30:45 | mitre | Cross Site Scripting vulnerability in Soliton Systems MailZen… | Details |
| CVE-2026-70474 | 2026-08-04 18:01:01 | 2026-08-05 14:29:21 | GitHub_M | Flowise is a drag-and-drop user interface for building… | Details |
| CVE-2026-70481 | 2026-08-04 19:45:37 | 2026-08-05 14:29:13 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-70486 | 2026-08-04 20:01:55 | 2026-08-05 14:29:05 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-70554 | 2026-08-04 20:11:55 | 2026-08-05 14:28:55 | VulnCheck | MaxSite CMS contains a PHP object injection vulnerability… | Details |
| CVE-2026-45538 | 2026-08-04 20:47:10 | 2026-08-05 14:28:49 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-70493 | 2026-08-04 20:56:20 | 2026-08-05 14:28:42 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-18814 | 2026-08-04 21:15:09 | 2026-08-05 14:28:34 | VulDB | A vulnerability was found in H3C NX15 V100R017.… | Details |
| CVE-2026-70590 | 2026-08-04 21:27:22 | 2026-08-05 14:28:28 | GitHub_M | Ghost is a Node.js content management system. Prior… | Details |
| CVE-2026-70593 | 2026-08-04 21:49:49 | 2026-08-05 14:28:19 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-48330 | 2026-08-03 22:37:03 | 2026-08-05 14:28:18 | adobe | Adobe Campaign Classic (ACC) is affected by an… | Details |
| CVE-2026-18852 | 2026-08-04 23:15:10 | 2026-08-05 14:28:11 | VulDB | A vulnerability has been found in epsilla-cloud vectordb… | Details |
| CVE-2026-46334 | 2026-08-04 23:50:57 | 2026-08-05 14:28:03 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-18895 | 2026-08-05 01:30:09 | 2026-08-05 14:27:55 | VulDB | A vulnerability was found in UTT HiPER 1250GW… | Details |
| CVE-2026-18901 | 2026-08-05 04:00:10 | 2026-08-05 14:27:47 | VulDB | A security vulnerability has been detected in H3C… | Details |
| CVE-2026-46714 | 2026-08-03 21:58:36 | 2026-08-05 14:27:42 | GitHub_M | Misskey is an open source, federated social media… | Details |
| CVE-2026-15918 | 2026-08-05 04:25:25 | 2026-08-05 14:27:34 | Wordfence | VikAppointments Service Booking Calendar wordpress plugin is vulnerable… | Details |
| CVE-2026-7753 | 2026-08-05 05:27:37 | 2026-08-05 14:27:26 | Wordfence | The Cost Calculator Builder plugin for WordPress is… | Details |
| CVE-2026-5108 | 2026-08-05 06:37:53 | 2026-08-05 14:27:19 | Wordfence | The Super Progressive Web Apps plugin for WordPress… | Details |
| CVE-2026-6147 | 2026-08-05 06:37:59 | 2026-08-05 14:27:11 | Wordfence | The LightSync Pro plugin for WordPress is vulnerable… | Details |
| CVE-2026-7441 | 2026-08-05 06:38:01 | 2026-08-05 14:27:05 | Wordfence | The Simple Yearly Archive plugin for WordPress is… | Details |
| CVE-2026-12000 | 2026-08-05 06:38:02 | 2026-08-05 14:26:56 | Wordfence | The Page and Post Restriction plugin for WordPress… | Details |
| CVE-2026-10059 | 2026-08-05 08:54:51 | 2026-08-05 14:26:49 | redhat | A flaw was found in the Multicluster Engine… | Details |
| CVE-2026-15452 | 2026-08-05 09:26:25 | 2026-08-05 14:26:41 | Wordfence | The Smash Balloon Social Photo Feed – Easy… | Details |
| CVE-2026-67616 | 2026-08-03 21:40:49 | 2026-08-05 14:26:36 | VulnCheck | Camaleon CMS through 2.9.2, fixed in commit 88ab703,… | Details |
| CVE-2026-48115 | 2026-08-03 21:21:59 | 2026-08-05 14:24:48 | GitHub_M | Misskey is an open source, federated social media… | Details |
| CVE-2026-18648 | 2026-08-03 21:00:10 | 2026-08-05 14:23:54 | VulDB | A vulnerability was detected in Blix Email Blue… | Details |
| CVE-2026-18737 | 2026-08-03 20:40:28 | 2026-08-05 14:22:39 | VulnCheck | Shlink contains a blind SQL injection vulnerability that… | Details |
| CVE-2026-7456 | 2026-08-05 13:26:41 | 2026-08-05 14:22:26 | Wordfence | The Udimi Tools plugin for WordPress is vulnerable… | Details |
| CVE-2026-71225 | 2026-08-05 12:16:52 | 2026-08-05 14:21:01 | redhat | A flaw was found in libkcapi. When performing… | Details |
| CVE-2026-66065 | 2026-08-03 20:20:27 | 2026-08-05 14:20:51 | GitHub_M | Ouroboros is a local-first runtime for AI coding… | Details |
| CVE-2026-66747 | 2026-08-05 10:50:45 | 2026-08-05 14:20:12 | VulnCheck | Zbtlink router firmware ships an embedded remote-control implant,… | Details |
| CVE-2026-18641 | 2026-08-03 19:45:10 | 2026-08-05 14:20:11 | VulDB | A vulnerability was determined in Sangfor Operation and… | Details |
| CVE-2026-70480 | 2026-08-04 19:43:15 | 2026-08-05 14:18:27 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-6020 | 2026-08-05 07:39:20 | 2026-08-05 14:17:21 | Wordfence | The ShopLentor plugin for WordPress is vulnerable to… | Details |
| CVE-2026-70620 | 2026-08-04 21:16:32 | 2026-08-05 14:16:53 | VulnCheck | Odysseus before commit 87babb5 contains a server-side request… | Details |
| CVE-2026-70589 | 2026-08-04 21:11:03 | 2026-08-05 14:16:41 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-6972 | 2026-08-05 06:38:01 | 2026-08-05 14:16:31 | Wordfence | The SKT Skill Bar plugin for WordPress is… | Details |
| CVE-2026-45084 | 2026-08-04 21:23:21 | 2026-08-05 14:16:11 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-5651 | 2026-08-05 06:38:00 | 2026-08-05 14:15:49 | Wordfence | The Askeet plugin for WordPress is vulnerable to… | Details |
| CVE-2026-17532 | 2026-08-05 06:37:56 | 2026-08-05 14:15:11 | Wordfence | The Seraphinite Accelerator plugin for WordPress is vulnerable… | Details |
| CVE-2026-70591 | 2026-08-04 21:37:53 | 2026-08-05 14:15:07 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-18816 | 2026-08-04 21:45:08 | 2026-08-05 14:14:31 | VulDB | A vulnerability was identified in Baserow up to… | Details |
| CVE-2026-7726 | 2026-08-05 06:37:54 | 2026-08-05 14:13:46 | Wordfence | The Layouts for WPBakery plugin for WordPress is… | Details |
| CVE-2026-9273 | 2026-08-05 04:25:27 | 2026-08-05 14:13:10 | Wordfence | The Membership Plugin – Kadence Memberships plugin for… | Details |
| CVE-2026-18322 | 2026-08-05 04:25:25 | 2026-08-05 14:12:28 | Wordfence | The Smart Popup by Supsystic plugin for WordPress… | Details |
| CVE-2026-18900 | 2026-08-05 03:45:09 | 2026-08-05 14:11:46 | VulDB | A weakness has been identified in H3C NX15… | Details |
| CVE-2026-16573 | 2026-08-05 06:00:09 | 2026-08-05 14:11:30 | WPScan | The Bit Form WordPress plugin before 3.2.0… | Details |
| CVE-2026-16993 | 2026-08-05 06:00:11 | 2026-08-05 14:09:16 | WPScan | The DHL Shipping Germany for WooCommerce WordPress plugin… | Details |
| CVE-2026-18859 | 2026-08-05 00:45:35 | 2026-08-05 14:08:50 | VulDB | A vulnerability was identified in ESAFENET CDG up… | Details |
| CVE-2025-15677 | 2026-08-05 06:00:11 | 2026-08-05 14:07:56 | WPScan | The GeoDirectory WordPress plugin before 2.8.110 does… | Details |
| CVE-2026-18819 | 2026-08-04 22:45:11 | 2026-08-05 14:07:18 | VulDB | A security vulnerability has been detected in RackTables… | Details |
| CVE-2026-70594 | 2026-08-04 21:53:45 | 2026-08-05 14:05:02 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-16055 | 2026-08-05 06:00:12 | 2026-08-05 14:04:53 | WPScan | The Contest Gallery WordPress plugin before 30.0.7… | Details |
| CVE-2026-47682 | 2026-08-04 20:00:49 | 2026-08-05 14:04:05 | GitHub_M | CVAT is an open source interactive video and… | Details |
| CVE-2026-70488 | 2026-08-04 20:35:44 | 2026-08-05 14:02:29 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-45100 | 2026-08-04 21:41:54 | 2026-08-05 14:01:56 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-70592 | 2026-08-04 21:41:27 | 2026-08-05 14:01:28 | GitHub_M | Ghost is a Node.js content management system. From… | Details |
| CVE-2026-18813 | 2026-08-04 21:00:09 | 2026-08-05 14:00:44 | VulDB | A vulnerability has been found in H3C NX15… | Details |
| CVE-2026-70494 | 2026-08-04 20:58:05 | 2026-08-05 13:59:11 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-18103 | 2026-08-04 23:08:02 | 2026-08-05 13:58:53 | redhat | A flaw was found in dhcp-server. A remote… | Details |
| CVE-2026-45809 | 2026-08-04 23:30:03 | 2026-08-05 13:57:39 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-70489 | 2026-08-04 20:42:31 | 2026-08-05 13:57:00 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-54020 | 2026-08-04 20:38:27 | 2026-08-05 13:55:01 | GitHub_M | Open WebUI is an extensible, feature-rich, and user-friendly… | Details |
| CVE-2026-17515 | 2026-08-05 06:00:12 | 2026-08-05 13:54:29 | WPScan | The MLSImport: IDX Plugin & MLS Plugin for… | Details |
| CVE-2026-70477 | 2026-08-04 19:29:14 | 2026-08-05 13:51:57 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-5116 | 2026-08-05 06:37:56 | 2026-08-05 13:51:18 | Wordfence | The Contact Form 7 – Dynamic Text Extension… | Details |
| CVE-2026-10090 | 2026-08-05 08:54:55 | 2026-08-05 13:50:30 | redhat | A flaw was found in the Application Subscription… | Details |
| CVE-2026-70552 | 2026-08-04 19:28:27 | 2026-08-05 13:50:02 | VulnCheck | MaxSite CMS 109.5 and earlier contains an authentication… | Details |
| CVE-2026-47781 | 2026-08-04 18:42:23 | 2026-08-05 13:48:50 | GitHub_M | PDM is a Python package and dependency manager.… | Details |
| CVE-2026-47764 | 2026-08-04 17:57:15 | 2026-08-05 13:47:02 | GitHub_M | pdm is a Python package and dependency manager… | Details |
| CVE-2026-18788 | 2026-08-04 17:15:08 | 2026-08-05 13:45:13 | VulDB | A security flaw has been discovered in Trippo… | Details |
| CVE-2026-69262 | 2026-08-04 16:50:12 | 2026-08-05 13:43:57 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-15281 | 2026-08-05 06:37:57 | 2026-08-05 13:43:17 | Wordfence | The User Access Manager plugin for WordPress is… | Details |
| CVE-2026-7444 | 2026-08-05 06:38:01 | 2026-08-05 13:42:20 | Wordfence | The Search Analytics for WP plugin for WordPress… | Details |
| CVE-2026-18774 | 2026-08-04 16:00:11 | 2026-08-05 13:42:12 | VulDB | A flaw has been found in NousResearch hermes-agent… | Details |
| CVE-2026-11421 | 2026-08-05 04:25:26 | 2026-08-05 13:41:17 | Wordfence | The ERP: Complete HR, Accounting & CRM Suite… | Details |
| CVE-2026-69256 | 2026-08-04 15:45:55 | 2026-08-05 13:41:04 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-67305 | 2026-08-01 12:22:16 | 2026-08-05 13:40:54 | VulnCheck | FreeRDP Windows client before 3.29.0 contains a heap… | Details |
| CVE-2026-67293 | 2026-08-01 12:22:16 | 2026-08-05 13:40:21 | VulnCheck | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains… | Details |
| CVE-2026-67325 | 2026-08-01 12:22:16 | 2026-08-05 13:39:53 | VulnCheck | GitPython before 3.1.51 contains an incomplete command injection… | Details |
| CVE-2026-45705 | 2026-08-04 23:16:31 | 2026-08-05 13:39:43 | GitHub_M | OpenSIPS is a Session Initiation Protocol (SIP) server… | Details |
| CVE-2026-18853 | 2026-08-04 23:45:10 | 2026-08-05 13:38:27 | VulDB | A security vulnerability has been detected in ZomboDroid… | Details |
| CVE-2026-67289 | 2026-08-01 12:22:17 | 2026-08-05 13:38:18 | VulnCheck | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does… | Details |
| CVE-2026-71249 | 2026-08-05 10:57:05 | 2026-08-05 13:38:12 | TuranSec | 299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw… | Details |
| CVE-2026-67324 | 2026-08-01 12:22:18 | 2026-08-05 13:37:56 | VulnCheck | GitPython 3.1.50 fails to recognize joined short-option forms… | Details |
| CVE-2026-18896 | 2026-08-05 01:45:08 | 2026-08-05 13:37:54 | VulDB | A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0.… | Details |
| CVE-2026-24079 | 2026-08-04 15:07:17 | 2026-08-05 13:37:19 | qualcomm | Cryptographic Issue while processing registration requests with malformed… | Details |
| CVE-2026-68580 | 2026-08-02 12:15:27 | 2026-08-05 13:36:50 | VulnCheck | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in… | Details |
| CVE-2026-71226 | 2026-08-05 12:37:17 | 2026-08-05 13:36:23 | redhat | Memory Corruption via Uncanceled AIO Requests on Error:… | Details |
| CVE-2026-20486 | 2026-08-03 02:05:51 | 2026-08-05 13:36:02 | MediaTek | In imgsensor, there is a possible application crash… | Details |
| CVE-2026-20495 | 2026-08-03 02:06:03 | 2026-08-05 13:34:52 | MediaTek | In Bluetooth driver, there is a possible permission… | Details |
| CVE-2026-68979 | 2026-08-03 19:56:11 | 2026-08-05 13:33:59 | apache | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter… | Details |
| CVE-2026-40717 | 2026-08-03 17:30:44 | 2026-08-05 13:33:46 | dell | Dell Monitor driver, version 1.0.0.0, contains an Improper… | Details |
| CVE-2026-66344 | 2026-08-05 04:25:58 | 2026-08-05 13:33:27 | jpcert | NetKids iMark, provided by Integrated Systems Technologies, Inc.,… | Details |
| CVE-2026-58075 | 2026-08-04 15:56:03 | 2026-08-05 13:33:25 | hackerone | A vulnerability allowing an unauthenticated attacker to read… | Details |
| CVE-2026-18902 | 2026-08-05 04:30:08 | 2026-08-05 13:32:29 | VulDB | A vulnerability was detected in H3C NX15 V100R017.… | Details |
| CVE-2026-71192 | 2026-08-05 05:05:33 | 2026-08-05 13:31:30 | mitre | In OpenStack Swift through 2.38.0, the S3API middleware… | Details |
| CVE-2026-54416 | 2026-08-05 06:58:23 | 2026-08-05 13:31:13 | TuranSec | Pluck CMS through 4.7.21 restricts dangerous file uploads… | Details |
| CVE-2026-5062 | 2026-08-05 05:27:38 | 2026-08-05 13:30:37 | Wordfence | The PrettyLinks – Affiliate Links, Link Branding, Link… | Details |
| CVE-2026-11454 | 2026-08-05 06:37:56 | 2026-08-05 13:30:11 | Wordfence | The Groundhogg — CRM, Newsletters, and Marketing Automation… | Details |
| CVE-2026-18881 | 2026-08-05 06:37:59 | 2026-08-05 13:29:54 | Wordfence | The TableOn – WordPress Posts Table Filterable plugin… | Details |
| CVE-2026-6079 | 2026-08-05 06:37:55 | 2026-08-05 13:29:33 | Wordfence | The Material Dashboard plugin for WordPress is vulnerable… | Details |
| CVE-2026-7105 | 2026-08-05 06:38:02 | 2026-08-05 13:29:04 | Wordfence | The Xpro Addons plugin for WordPress is vulnerable… | Details |
| CVE-2026-71207 | 2026-08-05 06:59:10 | 2026-08-05 13:28:36 | TuranSec | The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password… | Details |
| CVE-2026-71214 | 2026-08-05 06:59:32 | 2026-08-05 13:28:04 | TuranSec | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the… | Details |
| CVE-2026-71213 | 2026-08-05 06:59:29 | 2026-08-05 13:27:30 | TuranSec | Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no… | Details |
| CVE-2026-71212 | 2026-08-05 06:59:26 | 2026-08-05 13:26:56 | TuranSec | xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp… | Details |
| CVE-2026-71211 | 2026-08-05 06:59:23 | 2026-08-05 13:26:34 | TuranSec | MLflow's AI Gateway accepts an auth_config.api_base value when… | Details |
| CVE-2026-71202 | 2026-08-05 06:58:53 | 2026-08-05 13:25:08 | TuranSec | The raster Rust crate's crop() function (src/editor.rs) clamps… | Details |
| CVE-2026-71210 | 2026-08-05 06:59:19 | 2026-08-05 13:22:45 | TuranSec | Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target… | Details |
| CVE-2026-71209 | 2026-08-05 06:59:16 | 2026-08-05 13:21:27 | TuranSec | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes… | Details |
| CVE-2026-71203 | 2026-08-05 06:58:56 | 2026-08-05 13:21:15 | TuranSec | changedetection.io's REST API resources are protected by an… | Details |
| CVE-2026-71208 | 2026-08-05 06:59:13 | 2026-08-05 13:20:20 | TuranSec | KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster… | Details |
| CVE-2026-71215 | 2026-08-05 06:59:35 | 2026-08-05 13:19:43 | TuranSec | art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both… | Details |
| CVE-2026-71206 | 2026-08-05 06:59:06 | 2026-08-05 13:19:03 | TuranSec | Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's… | Details |
| CVE-2026-71205 | 2026-08-05 06:59:03 | 2026-08-05 13:18:25 | TuranSec | changedetection.io's /login route checks the submitted password against… | Details |
| CVE-2026-11977 | 2026-08-05 07:39:24 | 2026-08-05 13:17:35 | Wordfence | The WP Post Author – Author Box, Multiple… | Details |
| CVE-2026-61515 | 2026-08-04 13:59:29 | 2026-08-05 13:16:27 | VulnCheck | Puwell IP Camera firmware versions 2.x through 4.x… | Details |
| CVE-2026-67200 | 2026-08-04 14:04:39 | 2026-08-05 13:16:22 | VulnCheck | Perspective 5.0.0 contains a path traversal vulnerability that… | Details |
| CVE-2026-71204 | 2026-08-05 06:59:00 | 2026-08-05 13:16:07 | TuranSec | changedetection.io's /settings save handler builds an update dict… | Details |
| CVE-2026-59675 | 2026-08-05 07:49:11 | 2026-08-05 13:15:22 | suse | When API audit logging is enabled, the middleware… | Details |
| CVE-2026-70378 | 2026-08-05 06:58:50 | 2026-08-05 13:15:02 | TuranSec | imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.rs)… | Details |
| CVE-2025-29296 | 2026-08-04 00:00:00 | 2026-08-05 13:15:00 | mitre | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C… | Details |
| CVE-2026-70377 | 2026-08-05 06:58:47 | 2026-08-05 13:14:14 | TuranSec | imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs)… | Details |
| CVE-2026-70376 | 2026-08-05 06:58:44 | 2026-08-05 13:13:12 | TuranSec | Pluck CMS's admin panel relies solely on a… | Details |
| CVE-2026-55998 | 2026-08-05 07:51:21 | 2026-08-05 13:13:02 | suse | The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before… | Details |
| CVE-2026-55747 | 2026-08-05 06:58:41 | 2026-08-05 13:12:39 | TuranSec | The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a… | Details |
| CVE-2026-55739 | 2026-08-05 06:58:38 | 2026-08-05 13:12:08 | TuranSec | Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense… | Details |
| CVE-2026-7520 | 2026-08-05 07:39:23 | 2026-08-05 13:11:29 | Wordfence | The MailChimp Forms by MailMunch plugin for WordPress… | Details |
| CVE-2026-11920 | 2026-08-05 07:39:24 | 2026-08-05 13:11:03 | Wordfence | The JoomSport – for Sports: Team & League,… | Details |
| CVE-2026-71227 | 2026-08-05 12:42:10 | 2026-08-05 13:10:21 | redhat | A flaw was found in libkcapi. A local… | Details |
| CVE-2026-25703 | 2026-08-05 09:48:19 | 2026-08-05 13:09:10 | suse | NeuVector through 5.4.9 is can potentially leak information… | Details |
| CVE-2026-17578 | 2026-08-05 10:20:55 | 2026-08-05 13:07:23 | Kong | Kong Event Gateway versions 1.0.0 through 1.1.1 and… | Details |
| CVE-2026-8029 | 2026-08-05 08:36:02 | 2026-08-05 13:06:32 | zte | The ZTE Smart Life app contains an SQL… | Details |
| CVE-2026-14574 | 2026-08-05 10:51:47 | 2026-08-05 13:05:29 | eclipse | In Eclipse Theia versions 0.7.0 and up until… | Details |
| CVE-2026-14304 | 2026-08-05 10:40:03 | 2026-08-05 13:03:57 | eclipse | In Eclipse Accessibility Tools Framework (ACTF) versions up… | Details |
| CVE-2026-12609 | 2026-08-05 10:55:42 | 2026-08-05 13:03:23 | eclipse | In Eclipse Theia versions 1.66.0 and up until… | Details |
| CVE-2026-71235 | 2026-08-05 10:56:25 | 2026-08-05 12:59:05 | TuranSec | Magistrala's Rules Engine allows authenticated users to create… | Details |
| CVE-2026-71241 | 2026-08-05 10:56:42 | 2026-08-05 12:58:25 | TuranSec | Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book,… | Details |
| CVE-2026-71240 | 2026-08-05 10:56:39 | 2026-08-05 12:57:46 | TuranSec | DjangoCRM's toggle_default_sorting view is the only route in… | Details |
| CVE-2026-71239 | 2026-08-05 10:56:36 | 2026-08-05 12:56:18 | TuranSec | DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject,… | Details |
| CVE-2026-71234 | 2026-08-05 10:56:21 | 2026-08-05 12:55:30 | TuranSec | Documize Community's attachment download route (domain/attachment/endpoint.go, Download function,… | Details |
| CVE-2026-71233 | 2026-08-05 10:56:18 | 2026-08-05 12:54:59 | TuranSec | InvoiceNinja v5-stable renders an invoice or quote's "terms"… | Details |
| CVE-2026-71232 | 2026-08-05 10:56:15 | 2026-08-05 12:53:53 | TuranSec | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP… | Details |
| CVE-2026-70373 | 2026-08-04 13:00:15 | 2026-08-05 12:53:11 | TuranSec | Koha's reports/issues_stats.pl (the circulation statistics report) builds its… | Details |
| CVE-2026-70372 | 2026-08-04 13:00:12 | 2026-08-05 12:53:09 | TuranSec | Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate… | Details |
| CVE-2026-70371 | 2026-08-04 13:00:10 | 2026-08-05 12:53:07 | TuranSec | Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate… | Details |
| CVE-2026-70370 | 2026-08-04 13:00:07 | 2026-08-05 12:53:06 | TuranSec | Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate… | Details |
| CVE-2026-70369 | 2026-08-04 12:59:55 | 2026-08-05 12:53:04 | TuranSec | Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in… | Details |
| CVE-2026-71231 | 2026-08-05 10:56:07 | 2026-08-05 12:52:53 | TuranSec | IOTSmartHome's gui/login.php checkCookie() function builds an authentication query… | Details |
| CVE-2026-71256 | 2026-08-05 11:44:21 | 2026-08-05 12:52:23 | TuranSec | nanoMODBUS through v1.23.0 contains an out-of-bounds stack read… | Details |
| CVE-2026-71255 | 2026-08-05 11:44:21 | 2026-08-05 12:52:21 | TuranSec | nanoMODBUS through v1.23.0 contains an out-of-bounds write in… | Details |
| CVE-2026-71242 | 2026-08-05 10:56:45 | 2026-08-05 12:52:20 | TuranSec | Crater's NotePolicy checks only a blanket Bouncer ability… | Details |
| CVE-2026-71246 | 2026-08-05 10:56:57 | 2026-08-05 12:52:19 | TuranSec | Pixelfed's SearchController (behind the auth middleware) accepts a… | Details |
| CVE-2026-71244 | 2026-08-05 10:56:51 | 2026-08-05 12:52:17 | TuranSec | Paperless-ngx's MailAccountViewSet.test() action, when called with an existing… | Details |
| CVE-2026-71236 | 2026-08-05 10:56:28 | 2026-08-05 12:52:14 | TuranSec | Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming… | Details |
| CVE-2026-71254 | 2026-08-05 11:44:20 | 2026-08-05 12:51:40 | TuranSec | nanoMODBUS through v1.23.0 contains an out-of-bounds write in… | Details |
| CVE-2026-71243 | 2026-08-05 10:56:48 | 2026-08-05 12:50:55 | TuranSec | The backmeup npm package assembles shell command strings… | Details |
| CVE-2026-71237 | 2026-08-05 10:56:31 | 2026-08-05 12:48:00 | TuranSec | Miantang/IoT-PHP's index.php implements a POST /userlogin route that… | Details |
| CVE-2026-71238 | 2026-08-05 10:56:33 | 2026-08-05 12:43:45 | TuranSec | DjangoCRM ships with its Django SECRET_KEY hardcoded directly… | Details |
| CVE-2026-71248 | 2026-08-05 10:57:02 | 2026-08-05 12:42:56 | TuranSec | Inventory-Management-System-PHP's login.php constructs its authentication query via direct… | Details |
| CVE-2026-71250 | 2026-08-05 10:57:08 | 2026-08-05 12:41:26 | TuranSec | Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most… | Details |
| CVE-2026-71251 | 2026-08-05 10:57:11 | 2026-08-05 12:40:32 | TuranSec | Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download(), reachable at uploads/{id}/download… | Details |
| CVE-2026-71252 | 2026-08-05 10:57:14 | 2026-08-05 12:39:13 | TuranSec | toner-management's admin state-changing handlers (add.php, edit.php, delete.php under… | Details |
| CVE-2026-60009 | 2026-08-05 10:59:24 | 2026-08-05 12:37:08 | eclipse | In Eclipse Theia versions up to and including… | Details |
| CVE-2026-61891 | 2026-08-05 11:03:01 | 2026-08-05 12:35:46 | eclipse | In Eclipse Theia versions up to and including… | Details |
| CVE-2026-71245 | 2026-08-05 10:56:54 | 2026-08-05 12:35:45 | TuranSec | Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from… | Details |
| CVE-2026-71247 | 2026-08-05 10:56:59 | 2026-08-05 12:32:16 | TuranSec | Documenso's sign-field-with-token.ts, used by the live document-signing UI,… | Details |
| CVE-2026-18933 | 2026-08-05 11:27:06 | 2026-08-05 12:30:56 | TuranSec | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also… | Details |
| CVE-2026-54418 | 2026-08-05 06:58:34 | 2026-08-05 12:20:15 | TuranSec | Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,… | Details |
| CVE-2026-64582 | 2026-08-05 11:25:29 | 2026-08-05 11:25:29 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-0392 | 2026-08-03 09:56:31 | 2026-08-05 09:29:36 | ENISA | eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and… | Details |
| CVE-2026-64581 | 2026-08-05 08:09:35 | 2026-08-05 08:09:35 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64580 | 2026-08-05 08:09:34 | 2026-08-05 08:09:34 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64579 | 2026-08-05 08:09:34 | 2026-08-05 08:09:34 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64578 | 2026-08-05 08:09:33 | 2026-08-05 08:09:33 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64577 | 2026-08-05 08:09:33 | 2026-08-05 08:09:33 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64576 | 2026-08-05 08:09:32 | 2026-08-05 08:09:32 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64575 | 2026-08-05 08:09:31 | 2026-08-05 08:09:31 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64574 | 2026-08-05 08:08:10 | 2026-08-05 08:08:10 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64573 | 2026-08-05 08:08:09 | 2026-08-05 08:08:09 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64572 | 2026-08-05 08:08:09 | 2026-08-05 08:08:09 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64571 | 2026-08-05 08:08:08 | 2026-08-05 08:08:08 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64570 | 2026-08-05 08:08:07 | 2026-08-05 08:08:07 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64569 | 2026-08-05 08:08:07 | 2026-08-05 08:08:07 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64567 | 2026-08-05 08:08:06 | 2026-08-05 08:08:06 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64568 | 2026-08-05 08:08:06 | 2026-08-05 08:08:06 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64566 | 2026-08-05 08:06:18 | 2026-08-05 08:06:18 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-18477 | 2026-08-03 15:34:36 | 2026-08-05 06:28:00 | redhat | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's… | Details |
| CVE-2026-18657 | 2026-08-04 19:38:23 | 2026-08-05 03:57:21 | AMZN | An uncontrolled search path element in Kiro CLI… | Details |
| CVE-2026-0163 | 2026-08-04 18:31:10 | 2026-08-05 03:57:20 | Google_Devices | In multiple functions of vpu_ioctl.c, there is a… | Details |
| CVE-2026-15307 | 2026-08-04 15:48:18 | 2026-08-05 03:57:15 | DSF | An issue was discovered in Django 5.2 before… | Details |
| CVE-2026-64634 | 2026-08-04 15:56:03 | 2026-08-05 03:57:14 | hackerone | A vulnerability allowing local privilege escalation to the… | Details |
| CVE-2026-64633 | 2026-08-04 15:56:03 | 2026-08-05 03:57:12 | hackerone | A vulnerability allowing remote unauthenticated code execution on… | Details |
| CVE-2026-62354 | 2026-08-03 19:57:44 | 2026-08-05 03:57:11 | apache | Authorization handling for Parameter Context validation requests in… | Details |
| CVE-2026-58073 | 2026-08-04 15:56:03 | 2026-08-05 03:57:08 | hackerone | A vulnerability in Veeam Service Provider Console allowing… | Details |
| CVE-2025-9291 | 2026-08-03 17:48:14 | 2026-08-05 03:57:07 | TPLink | A certification validation weakness exists in communication between affected Omada… | Details |
| CVE-2026-58074 | 2026-08-04 15:56:03 | 2026-08-05 03:57:06 | hackerone | A vulnerability allowing a high-privileged user to execute… | Details |
| CVE-2026-58072 | 2026-08-04 15:56:03 | 2026-08-05 03:57:05 | hackerone | A vulnerability in Veeam Service Provider Console allowing… | Details |
| CVE-2026-59913 | 2026-08-03 17:57:19 | 2026-08-05 03:57:04 | dell | Dell Display and Peripheral Manager (DDPM Mac), versions… | Details |
| CVE-2026-59912 | 2026-08-03 17:53:44 | 2026-08-05 03:57:03 | dell | Dell Display and Peripheral Manager (DDPM Mac), versions… | Details |
| CVE-2026-69097 | 2026-08-03 13:20:49 | 2026-08-05 03:57:01 | VulnCheck | GitPython before 3.1.53 fails to properly escape section… | Details |
| CVE-2026-69096 | 2026-08-03 13:20:48 | 2026-08-05 03:57:00 | VulnCheck | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing… | Details |
| CVE-2026-18574 | 2026-08-03 12:07:33 | 2026-08-05 03:56:59 | checkpoint | An authentication bypass vulnerability in Check Point Security… | Details |
| CVE-2026-20498 | 2026-08-03 02:06:06 | 2026-08-05 03:56:57 | MediaTek | In geniezone, there is a possible escalation of… | Details |
| CVE-2026-20485 | 2026-08-03 02:05:49 | 2026-08-05 03:56:54 | MediaTek | In HFRP, there is a possible out of… | Details |
| CVE-2026-20483 | 2026-08-03 02:05:45 | 2026-08-05 03:56:53 | MediaTek | In Telephony, there is a possible escalation of… | Details |
| CVE-2026-20481 | 2026-08-03 02:05:43 | 2026-08-05 03:56:52 | MediaTek | In geniezone, there is a possible out of… | Details |
| CVE-2026-24083 | 2026-08-04 15:07:19 | 2026-08-05 03:56:51 | qualcomm | Memory Corruption while processing IOCTL device driver requests… | Details |
| CVE-2026-20497 | 2026-08-03 02:05:41 | 2026-08-05 03:56:49 | MediaTek | In geniezone, there is a possible out of… | Details |
| CVE-2026-20477 | 2026-08-03 02:05:32 | 2026-08-05 03:56:48 | MediaTek | In display, there is a possible out of… | Details |
| CVE-2026-20475 | 2026-08-03 02:05:29 | 2026-08-05 03:56:47 | MediaTek | In display, there is a possible out of… | Details |
| CVE-2026-20474 | 2026-08-03 02:05:28 | 2026-08-05 03:56:46 | MediaTek | In display, there is a possible escalation of… | Details |
| CVE-2026-20473 | 2026-08-03 02:05:26 | 2026-08-05 03:56:45 | MediaTek | In display, there is a possible memory corruption… | Details |
| CVE-2026-18667 | 2026-08-03 22:27:29 | 2026-08-05 03:56:44 | tenable | A vulnerability in Tenable Sensor Proxy allows a… | Details |
| CVE-2026-20469 | 2026-08-03 02:05:21 | 2026-08-05 03:56:42 | MediaTek | In trusted_mem, there is a possible escalation of… | Details |
| CVE-2026-20468 | 2026-08-03 02:05:20 | 2026-08-05 03:56:41 | MediaTek | In apusys, there is a possible escalation of… | Details |
| CVE-2026-20467 | 2026-08-03 02:05:18 | 2026-08-05 03:56:40 | MediaTek | In apusys, there is a possible escalation of… | Details |
| CVE-2026-20465 | 2026-08-03 02:05:15 | 2026-08-05 03:56:39 | MediaTek | In wlan AP driver, there is a possible… | Details |
| CVE-2026-20464 | 2026-08-03 02:05:14 | 2026-08-05 03:56:38 | MediaTek | In hevc decoder, there is a possible out… | Details |
| CVE-2026-24076 | 2026-08-04 15:07:13 | 2026-08-05 03:56:31 | qualcomm | Memory Corruption when processing registry values with incorrect… | Details |
| CVE-2026-24080 | 2026-08-04 15:07:18 | 2026-08-05 03:56:28 | qualcomm | Memory Corruption when handling malformed request parameters in… | Details |
| CVE-2026-67326 | 2026-08-01 12:22:18 | 2026-08-05 03:56:26 | VulnCheck | GitPython before 3.1.50 fails to validate newline characters… | Details |
| CVE-2026-21366 | 2026-08-04 15:07:12 | 2026-08-05 03:56:25 | qualcomm | Memory corruption while processing a packet with a… | Details |
| CVE-2026-25289 | 2026-08-04 15:07:23 | 2026-08-05 03:56:23 | qualcomm | Memory Corruption when processing Device Capability Extended attributes… | Details |
| CVE-2026-67323 | 2026-08-01 12:22:18 | 2026-08-05 03:56:21 | VulnCheck | GitPython before 3.1.51 fails to guard against dangerous… | Details |
| CVE-2026-6837 | 2026-08-04 01:52:07 | 2026-08-05 03:56:19 | Zyxel | A post-authentication command injection vulnerability in the "export-cgi"… | Details |
| CVE-2026-66402 | 2026-08-01 12:22:17 | 2026-08-05 03:56:18 | VulnCheck | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains… | Details |
| CVE-2026-10709 | 2026-08-04 12:59:07 | 2026-08-05 03:56:14 | autodesk | A maliciously crafted FBX file, when parsed through… | Details |
| CVE-2026-10710 | 2026-08-04 12:59:51 | 2026-08-05 03:56:13 | autodesk | A maliciously crafted FBX file, when parsed through… | Details |
| CVE-2026-18556 | 2026-08-01 19:59:30 | 2026-08-05 03:56:07 | N-able | Authentication bypass using an alternate path or channel… | Details |
| CVE-2026-68494 | 2026-08-04 14:39:14 | 2026-08-05 01:39:56 | HeroDevs | The fix released in jackson-core 2.18.6 and 2.21.1… | Details |
| CVE-2026-11836 | 2026-08-04 00:02:34 | 2026-08-04 21:25:29 | Caliptra | Insufficient verification of data authenticity in Caliptra Core… | Details |
| CVE-2026-11835 | 2026-08-04 00:03:23 | 2026-08-04 21:25:26 | Caliptra | Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input… | Details |
| CVE-2026-13229 | 2026-08-04 18:12:04 | 2026-08-04 20:53:04 | Fluid Attacks | Zammad 7.1.0 contains an authenticated improper authorization vulnerability… | Details |
| CVE-2026-69250 | 2026-08-04 14:20:35 | 2026-08-04 19:52:53 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-69255 | 2026-08-04 15:39:39 | 2026-08-04 19:52:22 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-18775 | 2026-08-04 16:15:09 | 2026-08-04 19:51:57 | VulDB | A vulnerability has been found in NousResearch hermes-agent… | Details |
| CVE-2026-48121 | 2026-08-04 16:49:57 | 2026-08-04 19:51:50 | GitHub_M | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses… | Details |
| CVE-2026-18790 | 2026-08-04 17:30:09 | 2026-08-04 19:51:41 | VulDB | A weakness has been identified in Systerel S2OPC… | Details |
| CVE-2026-70470 | 2026-08-04 17:30:54 | 2026-08-04 19:51:28 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-18718 | 2026-08-03 16:54:17 | 2026-08-04 19:45:52 | VulnCheck | Ghidra contains an arbitrary code execution vulnerability in… | Details |
| CVE-2026-67978 | 2026-08-03 00:00:00 | 2026-08-04 19:42:48 | mitre | An issue in the SBN UDP interface of… | Details |
| CVE-2026-70475 | 2026-08-04 19:18:44 | 2026-08-04 19:37:54 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-14920 | 2026-08-02 06:00:08 | 2026-08-04 19:37:41 | WPScan | ## Summary… | Details |
| CVE-2026-18654 | 2026-08-03 19:38:51 | 2026-08-04 19:32:59 | AMZN | Key exchange without entity authentication in the EMR… | Details |
| CVE-2026-70473 | 2026-08-04 17:56:50 | 2026-08-04 19:32:09 | GitHub_M | Flowise is a drag-and-drop user interface for building… | Details |
| CVE-2026-18733 | 2026-08-03 20:33:24 | 2026-08-04 19:31:53 | AMZN | A prompt injection vulnerability in the shell tool… | Details |
| CVE-2026-69703 | 2026-08-04 18:41:26 | 2026-08-04 19:30:45 | VulnCheck | Atlas-Livre contains an improper access control vulnerability in… | Details |
| CVE-2026-10849 | 2026-08-03 21:21:32 | 2026-08-04 19:29:56 | zephyr | The hawkBit device management client in subsys/mgmt/hawkbit accumulates… | Details |
| CVE-2026-68980 | 2026-08-03 19:58:56 | 2026-08-04 19:20:56 | apache | Apache NiFi 2.0.0 through 2.10.0 support creating, reading,… | Details |
| CVE-2026-68981 | 2026-08-03 19:59:58 | 2026-08-04 19:19:50 | apache | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP… | Details |
| CVE-2026-70471 | 2026-08-04 17:43:29 | 2026-08-04 19:17:49 | GitHub_M | Flowise is a drag-and-drop user interface for building… | Details |
| CVE-2026-68743 | 2026-08-04 18:37:21 | 2026-08-04 19:10:51 | redhat | A flaw was found in SSSD. The extract_authtok_v1()… | Details |
| CVE-2026-49435 | 2026-08-04 18:52:30 | 2026-08-04 18:59:37 | cisa-cg | Keysight IxChariot Endpoint and associated products contain a… | Details |
| CVE-2017-20242 | 2026-08-04 18:52:14 | 2026-08-04 18:59:17 | cisa-cg | Keysight IxChariot Endpoint before 9.5.102 contains a stack-based… | Details |
| CVE-2017-20241 | 2026-08-04 18:51:59 | 2026-08-04 18:58:55 | cisa-cg | Keysight IxChariot Endpoint before 9.5.102 contains a heap-based… | Details |
| CVE-2026-66300 | 2026-08-04 18:51:27 | 2026-08-04 18:58:36 | cisa-cg | SNOMED International Snowstorm contains a reflected XSS vulnerability… | Details |
| CVE-2026-16881 | 2026-08-04 05:05:34 | 2026-08-04 18:57:11 | LY-Corporation | A code injection vulnerability exists in the LINE… | Details |
| CVE-2026-18830 | 2026-08-04 17:42:20 | 2026-08-04 18:52:52 | AMZN | Insufficient input validation in Amazon Bedrock AgentCore harness… | Details |
| CVE-2026-8508 | 2026-08-04 01:57:51 | 2026-08-04 18:46:57 | Zyxel | An improper authentication vulnerability in the "social_login.cgi" CGI… | Details |
| CVE-2026-14818 | 2026-08-04 02:28:53 | 2026-08-04 18:45:22 | Zyxel | A path traversal vulnerability in the CLI command… | Details |
| CVE-2026-47612 | 2026-08-04 17:24:16 | 2026-08-04 18:41:30 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability in… | Details |
| CVE-2026-47613 | 2026-08-04 17:25:52 | 2026-08-04 18:40:31 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-47614 | 2026-08-04 17:26:19 | 2026-08-04 18:39:43 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-47615 | 2026-08-04 17:30:18 | 2026-08-04 18:36:58 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-47616 | 2026-08-04 17:30:51 | 2026-08-04 18:35:54 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability in… | Details |
| CVE-2026-47617 | 2026-08-04 17:31:22 | 2026-08-04 18:34:55 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability in… | Details |
| CVE-2026-47618 | 2026-08-04 17:31:45 | 2026-08-04 18:29:22 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability in… | Details |
| CVE-2026-47619 | 2026-08-04 17:32:08 | 2026-08-04 18:27:44 | nvidia | NVIDIA Dynamo for Linux examples and recipes contain… | Details |
| CVE-2026-47620 | 2026-08-04 17:32:36 | 2026-08-04 18:26:46 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-47621 | 2026-08-04 17:33:00 | 2026-08-04 18:25:20 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-24255 | 2026-08-04 17:23:47 | 2026-08-04 18:24:18 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability in… | Details |
| CVE-2026-24254 | 2026-08-04 17:23:07 | 2026-08-04 18:23:35 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability in… | Details |
| CVE-2026-24253 | 2026-08-04 17:22:32 | 2026-08-04 18:22:24 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-47487 | 2026-08-04 17:20:27 | 2026-08-04 18:20:41 | nvidia | NVIDIA Triton Inference Server for Linux contains a… | Details |
| CVE-2026-47622 | 2026-08-04 17:33:27 | 2026-08-04 18:19:12 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-16060 | 2026-08-03 06:00:13 | 2026-08-04 18:02:30 | WPScan | The Insert or Embed Articulate Content into WordPress… | Details |
| CVE-2026-14337 | 2026-08-04 13:48:40 | 2026-08-04 18:00:09 | Pega | Pega Platform versions 23.1.0 through 25.1.3 are affected… | Details |
| CVE-2026-18401 | 2026-08-04 14:23:27 | 2026-08-04 17:59:07 | HeroDevs | The non-blocking (asynchronous) JSON parser in jackson-core does… | Details |
| CVE-2026-47623 | 2026-08-04 17:33:54 | 2026-08-04 17:58:07 | nvidia | NVIDIA Dynamo for Linux contains a vulnerability where… | Details |
| CVE-2026-11368 | 2026-08-04 14:23:28 | 2026-08-04 17:57:40 | zephyr | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each… | Details |
| CVE-2026-69264 | 2026-08-04 17:22:36 | 2026-08-04 17:53:00 | GitHub_M | Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled… | Details |
| CVE-2026-18801 | 2026-08-04 14:53:01 | 2026-08-04 17:45:57 | Kong | OpenMeter contains a stored, or second-order, SQL injection… | Details |
| CVE-2026-69254 | 2026-08-04 15:28:49 | 2026-08-04 17:45:10 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-69259 | 2026-08-04 16:05:19 | 2026-08-04 17:44:16 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-10032 | 2026-08-04 15:36:45 | 2026-08-04 17:43:20 | The openUrl function in @a2ui/web_core passes an agent-controlled… | Details | |
| CVE-2026-12586 | 2026-08-02 06:00:10 | 2026-08-04 17:42:45 | WPScan | The Lenxel WP WordPress theme through 1.0.31 does… | Details |
| CVE-2026-14817 | 2026-08-02 06:00:10 | 2026-08-04 17:42:39 | WPScan | The Element Pack Addons for Elementor WordPress… | Details |
| CVE-2026-16042 | 2026-08-02 06:00:11 | 2026-08-04 17:42:33 | WPScan | The LWS Optimize WordPress plugin before 3.4… | Details |
| CVE-2026-16291 | 2026-08-02 06:00:12 | 2026-08-04 17:42:27 | WPScan | The ProfileGrid WordPress plugin before 5.9.9.8 does… | Details |
| CVE-2026-16292 | 2026-08-02 06:00:12 | 2026-08-04 17:42:20 | WPScan | The Frontend File Manager Plugin WordPress plugin through… | Details |
| CVE-2026-16062 | 2026-08-02 06:00:12 | 2026-08-04 17:42:13 | WPScan | The Event Booking Manager for WooCommerce WordPress… | Details |
| CVE-2026-16057 | 2026-08-03 06:00:10 | 2026-08-04 17:42:06 | WPScan | The Contest Gallery WordPress plugin before 30.0.7… | Details |
| CVE-2026-16274 | 2026-08-03 06:00:10 | 2026-08-04 17:41:58 | WPScan | The Classified Listing WordPress plugin before 5.4.4… | Details |
| CVE-2026-16276 | 2026-08-03 06:00:10 | 2026-08-04 17:41:52 | WPScan | The Classified Listing WordPress plugin before 5.4.4… | Details |
| CVE-2025-15672 | 2026-08-03 06:00:11 | 2026-08-04 17:41:46 | WPScan | The ChamaWP WordPress plugin before 1.0.13 does… | Details |
| CVE-2025-15673 | 2026-08-03 06:00:11 | 2026-08-04 17:41:38 | WPScan | The Import and export users and customers WordPress… | Details |
| CVE-2026-14557 | 2026-08-03 06:00:12 | 2026-08-04 17:41:32 | WPScan | The SoftMarket — Digital Marketplace WordPress plugin through… | Details |
| CVE-2026-15231 | 2026-08-03 06:00:12 | 2026-08-04 17:41:26 | WPScan | The Tag, Category, and Taxonomy Manager WordPress… | Details |
| CVE-2026-16618 | 2026-08-04 06:00:08 | 2026-08-04 17:40:09 | WPScan | The Improve SEO WordPress plugin through 2.0.11 does… | Details |
| CVE-2026-16068 | 2026-08-04 06:00:11 | 2026-08-04 17:39:20 | WPScan | The Brizy WordPress plugin before 2.8.19 does… | Details |
| CVE-2026-16056 | 2026-08-04 06:00:11 | 2026-08-04 17:38:24 | WPScan | The Contest Gallery WordPress plugin before 30.0.7… | Details |
| CVE-2026-16035 | 2026-08-04 06:00:11 | 2026-08-04 17:37:08 | WPScan | The miniOrange 2FA WordPress plugin before 6.2.7… | Details |
| CVE-2026-15958 | 2026-08-04 06:00:11 | 2026-08-04 17:36:26 | WPScan | The Easy Integration for Dropbox WordPress plugin… | Details |
| CVE-2026-56848 | 2026-08-04 15:57:24 | 2026-08-04 17:36:14 | hackerone | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`… | Details |
| CVE-2026-18785 | 2026-08-04 16:45:08 | 2026-08-04 17:35:15 | VulDB | A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b.… | Details |
| CVE-2026-15233 | 2026-08-04 06:00:10 | 2026-08-04 17:34:29 | WPScan | The Nested Pages WordPress plugin before 3.2.15 does… | Details |
| CVE-2026-14939 | 2026-08-04 06:00:10 | 2026-08-04 17:33:45 | WPScan | The Visualizer WordPress plugin before 4.0.6 does… | Details |
| CVE-2026-14872 | 2026-08-04 06:00:10 | 2026-08-04 17:33:06 | WPScan | The Database for Contact Form 7, WPforms, Elementor… | Details |
| CVE-2026-63455 | 2026-08-04 16:40:50 | 2026-08-04 17:33:01 | hpe | Multiple vulnerabilities in the REST API interface of… | Details |
| CVE-2026-14824 | 2026-08-04 06:00:09 | 2026-08-04 17:32:29 | WPScan | The Quiz and Survey Master (QSM) WordPress… | Details |
| CVE-2026-14848 | 2026-08-04 06:00:10 | 2026-08-04 17:32:15 | WPScan | The Paid Membership Subscriptions WordPress plugin before… | Details |
| CVE-2026-16623 | 2026-08-04 06:00:08 | 2026-08-04 17:30:47 | WPScan | The Create Block WordPress plugin before 2.10.0… | Details |
| CVE-2026-63456 | 2026-08-04 16:41:00 | 2026-08-04 17:27:47 | hpe | Multiple vulnerabilities in the REST API interface of… | Details |
| CVE-2026-18809 | 2026-08-04 12:31:10 | 2026-08-04 17:24:56 | mozilla | Information disclosure in Firefox for Android and Firefox… | Details |
| CVE-2026-69198 | 2026-08-03 19:59:05 | 2026-08-04 17:21:59 | GitHub_M | ip-address is a library for parsing and manipulating… | Details |
| CVE-2026-15337 | 2026-08-04 15:48:25 | 2026-08-04 17:21:43 | DSF | An issue was discovered in Django 5.2 before… | Details |
| CVE-2026-15830 | 2026-08-04 15:48:34 | 2026-08-04 17:21:28 | DSF | An issue was discovered in Django 5.2 before… | Details |
| CVE-2026-15920 | 2026-08-04 15:48:40 | 2026-08-04 17:21:13 | DSF | An issue was discovered in Django 5.2 before… | Details |
| CVE-2026-58067 | 2026-08-04 15:56:03 | 2026-08-04 17:20:55 | hackerone | A vulnerability in Veeam Service Provider Console allowing… | Details |
| CVE-2026-58071 | 2026-08-04 15:56:03 | 2026-08-04 17:20:39 | hackerone | A vulnerability in Veeam Service Provider Console allowing… | Details |
| CVE-2026-69263 | 2026-08-04 16:54:36 | 2026-08-04 17:20:39 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-64631 | 2026-08-04 15:56:03 | 2026-08-04 17:19:37 | hackerone | A vulnerability allowing a low-privileged user to inject… | Details |
| CVE-2026-18787 | 2026-08-04 17:00:09 | 2026-08-04 17:19:14 | VulDB | A vulnerability was identified in GL.iNet AX1800 up… | Details |
| CVE-2026-64630 | 2026-08-04 15:56:03 | 2026-08-04 17:19:08 | hackerone | A vulnerability allowing a low-privileged user to retrieve… | Details |
| CVE-2026-16250 | 2026-08-03 06:00:13 | 2026-08-04 17:16:37 | WPScan | The Personal QR Message WordPress plugin through 1.0… | Details |
| CVE-2026-18616 | 2026-08-03 18:30:10 | 2026-08-04 17:13:28 | VulDB | A vulnerability was identified in GL-iNet GL-MT3000 up… | Details |
| CVE-2026-67599 | 2026-08-03 19:05:57 | 2026-08-04 17:12:40 | VulnCheck | ClearOS 7.9 contains an OS command injection vulnerability… | Details |
| CVE-2026-18645 | 2026-08-03 20:15:12 | 2026-08-04 17:11:27 | VulDB | A security flaw has been discovered in danpros… | Details |
| CVE-2026-49132 | 2026-08-03 20:35:05 | 2026-08-04 17:06:57 | VulnCheck | OPNsense before 26.1.9 contains a stored cross-site scripting… | Details |
| CVE-2026-48113 | 2026-08-03 21:05:14 | 2026-08-04 17:04:25 | GitHub_M | Chisel is a TCP/UDP tunnel, transported over HTTP… | Details |
| CVE-2026-48323 | 2026-08-03 22:37:07 | 2026-08-04 17:02:59 | adobe | Adobe Campaign Classic (ACC) is affected by an… | Details |
| CVE-2026-61514 | 2026-08-04 14:00:26 | 2026-08-04 16:56:48 | VulnCheck | Puwell IP Camera firmware versions 2.x through 4.x… | Details |
| CVE-2026-67199 | 2026-08-04 14:04:19 | 2026-08-04 16:46:11 | VulnCheck | Perspective 5.0.0 contains a denial of service vulnerability… | Details |
| CVE-2026-69252 | 2026-08-04 14:53:59 | 2026-08-04 16:43:11 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-18773 | 2026-08-04 15:00:09 | 2026-08-04 16:40:42 | VulDB | A vulnerability was detected in NousResearch hermes-agent up… | Details |
| CVE-2026-69110 | 2026-08-04 15:30:21 | 2026-08-04 16:39:02 | VulnCheck | OpenCode Studio before 2.4.4 contains a missing authentication… | Details |
| CVE-2026-69257 | 2026-08-04 15:51:47 | 2026-08-04 16:36:51 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-24077 | 2026-08-04 15:07:14 | 2026-08-04 16:04:02 | qualcomm | Information Disclosure when processing wireless network channel switch… | Details |
| CVE-2026-24078 | 2026-08-04 15:07:15 | 2026-08-04 16:02:55 | qualcomm | Information Disclosure when IPSec negotiation fails or is… | Details |
| CVE-2026-46712 | 2026-08-03 21:29:49 | 2026-08-04 15:55:04 | GitHub_M | Misskey is an open source, federated social media… | Details |
| CVE-2026-24084 | 2026-08-04 15:07:20 | 2026-08-04 15:52:44 | qualcomm | Weak configuration when UE does not verify the… | Details |
| CVE-2026-25292 | 2026-08-04 15:07:24 | 2026-08-04 15:51:32 | qualcomm | Memory Corruption when processing untrusted user input in… | Details |
| CVE-2026-69100 | 2026-08-04 15:20:02 | 2026-08-04 15:47:30 | VulnCheck | LAMP Rapid Development Platform through 5.6.2, fixed in… | Details |
| CVE-2026-25288 | 2026-08-04 15:07:21 | 2026-08-04 15:47:13 | qualcomm | Transient DOS when processing a short target wake… | Details |
| CVE-2026-67198 | 2026-08-04 14:04:00 | 2026-08-04 15:46:25 | VulnCheck | Perspective 5.0.0 contains a denial-of-service vulnerability in the… | Details |
| CVE-2026-46713 | 2026-08-03 21:37:45 | 2026-08-04 15:44:53 | GitHub_M | Misskey is an open source, federated social media… | Details |
| CVE-2026-48399 | 2026-08-03 22:37:03 | 2026-08-04 15:43:54 | adobe | Adobe Campaign Classic (ACC) is affected by a… | Details |
| CVE-2026-18684 | 2026-08-03 22:45:10 | 2026-08-04 15:41:00 | VulDB | A weakness has been identified in GL.iNet GL-MT3000… | Details |
| CVE-2026-18806 | 2026-08-04 12:38:14 | 2026-08-04 15:37:47 | TR-CERT | External control of file name or path vulnerability… | Details |
| CVE-2026-18650 | 2026-08-04 14:02:45 | 2026-08-04 15:37:01 | TR-CERT | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS… | Details |
| CVE-2026-69251 | 2026-08-04 14:27:55 | 2026-08-04 15:35:08 | GitHub_M | Flowise is a drag & drop user interface… | Details |
| CVE-2026-17070 | 2026-08-04 13:45:00 | 2026-08-04 15:34:21 | TR-CERT | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS… | Details |
| CVE-2026-67195 | 2026-08-04 14:03:17 | 2026-08-04 15:06:09 | VulnCheck | Perspective 5.0.0 contains a remote code execution vulnerability… | Details |
| CVE-2026-18647 | 2026-08-03 20:45:08 | 2026-08-04 15:05:17 | VulDB | A security vulnerability has been detected in jina-ai… | Details |
| CVE-2026-48061 | 2026-08-03 20:47:34 | 2026-08-04 15:05:11 | GitHub_M | Litestar is an Asynchronous Server Gateway Interface (ASGI)… | Details |
| CVE-2026-67618 | 2026-08-04 14:30:48 | 2026-08-04 15:05:08 | VulnCheck | marimo before 0.23.15 contains a configuration injection vulnerability… | Details |
| CVE-2026-18738 | 2026-08-03 20:53:57 | 2026-08-04 15:05:04 | VulnCheck | Shlink versions 5.0.0 through 5.1.5 contain a CSV… | Details |
| CVE-2026-69245 | 2026-08-03 21:05:08 | 2026-08-04 15:04:58 | GitHub_M | Guzzle is an extensible PHP HTTP client. Prior… | Details |
| CVE-2026-69248 | 2026-08-03 21:21:43 | 2026-08-04 15:04:51 | GitHub_M | cryptography is a package designed to expose cryptographic… | Details |
| CVE-2026-48326 | 2026-08-03 22:37:02 | 2026-08-04 15:04:45 | adobe | Adobe Campaign Classic (ACC) is affected by an… | Details |
| CVE-2026-18686 | 2026-08-04 00:00:12 | 2026-08-04 15:04:21 | VulDB | A vulnerability was detected in GL.iNet GL-MT3000 up… | Details |
| CVE-2026-56845 | 2026-08-04 00:43:48 | 2026-08-04 15:04:12 | hackerone | An unauthenticated path traversal (LFI) vulnerability exists under… | Details |
| CVE-2026-58041 | 2026-08-04 00:49:58 | 2026-08-04 15:04:06 | hackerone | A flaw in Node.js node:sqlite allows a stale… | Details |
| CVE-2026-58045 | 2026-08-04 00:49:58 | 2026-08-04 15:03:57 | hackerone | A flaw in Node.js allows a spoofed `TypedArray`… | Details |
| CVE-2026-58044 | 2026-08-04 00:49:58 | 2026-08-04 15:03:46 | hackerone | A flaw in Node.js HTTP client can cause… | Details |
| CVE-2026-56846 | 2026-08-04 00:49:58 | 2026-08-04 15:03:38 | hackerone | A flaw in Node.js HTTP/2 handling can cause… | Details |
| CVE-2026-58042 | 2026-08-04 00:49:58 | 2026-08-04 15:03:30 | hackerone | A flaw in Node.js can cause dns.resolveAny() Aborts… | Details |
| CVE-2026-18723 | 2026-08-04 03:15:07 | 2026-08-04 15:03:22 | VulDB | A vulnerability was determined in diaowen DWSurvey up… | Details |
| CVE-2026-68744 | 2026-08-04 05:28:30 | 2026-08-04 15:03:12 | redhat | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr()… | Details |
| CVE-2026-18754 | 2026-08-04 07:09:17 | 2026-08-04 15:03:03 | GV | The product firmware contains an embedded, static RSA private… | Details |
| CVE-2026-18755 | 2026-08-04 07:09:50 | 2026-08-04 15:02:57 | GV | A DLL hijacking vulnerability in GeoVision GV-ASManager allows… | Details |
| CVE-2026-61387 | 2026-08-04 11:52:38 | 2026-08-04 15:02:51 | eclipse | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item… | Details |
| CVE-2026-60007 | 2026-08-04 11:55:41 | 2026-08-04 15:02:43 | eclipse | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token… | Details |
| CVE-2026-62927 | 2026-08-04 11:57:59 | 2026-08-04 15:02:34 | eclipse | In Eclipse Milo versions 1.0.0 through 1.1.4, the… | Details |
| CVE-2026-63252 | 2026-08-04 12:03:18 | 2026-08-04 15:02:26 | eclipse | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC… | Details |
| CVE-2026-58080 | 2026-08-04 12:05:10 | 2026-08-04 15:02:18 | eclipse | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()`… | Details |
| CVE-2026-63248 | 2026-08-04 12:07:43 | 2026-08-04 15:02:13 | eclipse | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC… | Details |
| CVE-2026-18770 | 2026-08-04 14:45:09 | 2026-08-04 14:59:33 | VulDB | A vulnerability has been found in vibesurf-ai VibeSurf… | Details |
| CVE-2026-18721 | 2026-08-04 02:30:07 | 2026-08-04 14:51:19 | VulDB | A vulnerability has been found in kalcaddle kodbox… | Details |
| CVE-2026-17614 | 2026-08-04 02:12:04 | 2026-08-04 14:47:26 | redhat | A path traversal flaw was found in WildFly's… | Details |
| CVE-2026-18720 | 2026-08-04 01:45:10 | 2026-08-04 14:41:53 | VulDB | A flaw has been found in kalcaddle kodbox… | Details |
| CVE-2026-18682 | 2026-08-03 21:30:08 | 2026-08-04 14:40:37 | VulDB | A security flaw has been discovered in OpenAkita… | Details |
| CVE-2026-18569 | 2026-08-04 05:13:08 | 2026-08-04 14:40:25 | redhat | A flaw was found in the backchannel logout… | Details |
| CVE-2026-16536 | 2026-08-04 06:00:08 | 2026-08-04 14:37:05 | WPScan | The Simple Google Calendar Outlook Events Widget WordPress… | Details |
| CVE-2026-10526 | 2026-08-04 06:00:09 | 2026-08-04 14:35:05 | WPScan | The EmbedPress WordPress plugin before 4.6.1 does… | Details |
| CVE-2026-11366 | 2026-08-04 06:00:09 | 2026-08-04 14:33:12 | WPScan | The MonsterInsights WordPress plugin before 11.1.0 does… | Details |
| CVE-2026-12698 | 2026-08-04 06:00:09 | 2026-08-04 14:29:45 | WPScan | The wpForo Forum WordPress plugin before 3.1.3 does… | Details |
| CVE-2026-14816 | 2026-08-04 06:00:09 | 2026-08-04 14:26:26 | WPScan | The GDPR Framework By Data443 WordPress plugin before… | Details |
| CVE-2026-16069 | 2026-08-04 06:00:12 | 2026-08-04 14:23:39 | WPScan | The Brizy WordPress plugin before 2.8.19 does… | Details |
| CVE-2026-16070 | 2026-08-04 06:00:12 | 2026-08-04 14:21:23 | WPScan | The Brizy WordPress plugin before 2.8.19 does… | Details |
| CVE-2026-18722 | 2026-08-04 03:00:08 | 2026-08-04 14:20:14 | VulDB | A vulnerability was found in diaowen DWSurvey up… | Details |
| CVE-2026-18685 | 2026-08-03 23:15:08 | 2026-08-04 14:19:21 | VulDB | A security vulnerability has been detected in GL.iNet… | Details |
| CVE-2026-16293 | 2026-08-04 06:00:12 | 2026-08-04 14:18:32 | WPScan | The PowerPress Podcasting plugin by Blubrry WordPress plugin… | Details |
| CVE-2026-16295 | 2026-08-04 06:00:12 | 2026-08-04 14:16:50 | WPScan | The Clearfy Cache WordPress plugin before 2.4.3… | Details |
| CVE-2026-16296 | 2026-08-04 06:00:12 | 2026-08-04 14:15:34 | WPScan | The Clearfy Cache WordPress plugin before 2.4.3… | Details |
| CVE-2026-48333 | 2026-08-03 22:37:06 | 2026-08-04 14:14:45 | adobe | Adobe Campaign Classic (ACC) is affected by an… | Details |
| CVE-2026-69244 | 2026-08-03 20:50:59 | 2026-08-04 14:13:17 | GitHub_M | AIOHTTP is an asynchronous HTTP client/server framework for… | Details |
| CVE-2026-48317 | 2026-08-03 22:37:05 | 2026-08-04 14:12:45 | adobe | Adobe Campaign Classic (ACC) is affected by an… | Details |
| CVE-2026-69240 | 2026-08-03 20:28:28 | 2026-08-04 14:12:28 | GitHub_M | Sequelize is a Node.js ORM tool. Prior to… | Details |
| CVE-2026-47746 | 2026-08-03 21:56:40 | 2026-08-04 14:11:19 | GitHub_M | Misskey is an open source, federated social media… | Details |
| CVE-2026-67617 | 2026-08-03 21:53:26 | 2026-08-04 14:09:54 | VulnCheck | Microweber CMS through 2.0.20 contains a stored cross-site… | Details |
| CVE-2026-69247 | 2026-08-03 21:16:32 | 2026-08-04 14:09:24 | GitHub_M | cryptography is a package designed to expose cryptographic… | Details |
| CVE-2026-69249 | 2026-08-03 21:26:45 | 2026-08-04 14:08:58 | GitHub_M | python-cryptography is a package designed to expose cryptographic… | Details |
| CVE-2026-16546 | 2026-08-04 06:00:12 | 2026-08-04 14:08:58 | WPScan | The Wired Impact Volunteer Management WordPress plugin before… | Details |
| CVE-2026-69246 | 2026-08-03 21:07:04 | 2026-08-04 14:06:40 | GitHub_M | Guzzle is an extensible PHP HTTP client. Prior… | Details |
| CVE-2026-16547 | 2026-08-04 06:00:13 | 2026-08-04 14:05:07 | WPScan | The REST API Log WordPress plugin before 1.7.1… | Details |
| CVE-2026-48063 | 2026-08-03 20:55:08 | 2026-08-04 14:03:34 | GitHub_M | Baileys is a cocket-based TS/JavaScript API for WhatsApp… | Details |
| CVE-2026-18646 | 2026-08-03 20:30:11 | 2026-08-04 14:01:39 | VulDB | A weakness has been identified in danpros HTMLy… | Details |
| CVE-2026-49131 | 2026-08-03 20:29:48 | 2026-08-04 14:00:52 | VulnCheck | OPNsense before 26.1.9 contains a stored cross-site scripting… | Details |
| CVE-2026-69192 | 2026-08-03 19:56:13 | 2026-08-04 13:59:43 | GitHub_M | ip-address is a library for parsing and manipulating… | Details |
| CVE-2026-16548 | 2026-08-04 06:00:13 | 2026-08-04 13:58:06 | WPScan | The Chat Widget: Floating Customer Support Button for… | Details |
| CVE-2026-18631 | 2026-08-03 19:15:07 | 2026-08-04 13:57:10 | VulDB | A vulnerability was identified in jeequan jeepay up… | Details |
| CVE-2026-67598 | 2026-08-03 19:02:06 | 2026-08-04 13:54:45 | VulnCheck | Emlog Pro through 2.6.23 contains a disabled TLS… | Details |
| CVE-2026-48331 | 2026-08-03 22:37:04 | 2026-08-04 13:54:35 | adobe | Adobe Campaign Classic (ACC) is affected by a… | Details |
| CVE-2026-14175 | 2026-08-04 08:23:47 | 2026-08-04 13:46:16 | TR-CERT | Unrestricted upload of file with dangerous type vulnerability… | Details |
| CVE-2026-67243 | 2026-08-04 06:38:25 | 2026-08-04 13:45:29 | jpcert | freo2 provided by refirio contains an unrestricted upload… | Details |
| CVE-2026-18736 | 2026-08-03 20:15:22 | 2026-08-04 13:45:06 | VulnCheck | Shlink contains a server-side request forgery vulnerability that… | Details |
| CVE-2026-18753 | 2026-08-04 07:08:40 | 2026-08-04 13:36:24 | GV | The product firmware contains an embedded, static RSA private… | Details |
| CVE-2026-18759 | 2026-08-04 07:25:09 | 2026-08-04 13:33:51 | ASUSTOR1 | The background service of ABP or AES runs… | Details |
| CVE-2026-18577 | 2026-08-02 22:06:18 | 2026-08-04 13:32:51 | N-able | An incomplete patch for CVE-2026-18556 allows for authentication… | Details |
| CVE-2026-15721 | 2026-08-04 08:18:08 | 2026-08-04 13:20:58 | TR-CERT | Cleartext storage of sensitive information vulnerability in Bilin… | Details |
| CVE-2026-18772 | 2026-08-04 08:22:48 | 2026-08-04 13:16:37 | samsung.tv_appliance | Improper input validation vulnerability in Samsung Open Source… | Details |
| CVE-2026-14194 | 2026-08-04 08:28:49 | 2026-08-04 13:13:51 | TR-CERT | Improper Limitation of a Pathname to a Restricted… | Details |
| CVE-2026-14219 | 2026-08-04 08:33:44 | 2026-08-04 13:12:55 | TR-CERT | URL redirection to untrusted site ('open redirect') vulnerability… | Details |
| CVE-2026-14804 | 2026-08-04 08:37:37 | 2026-08-04 13:10:41 | TR-CERT | Use of hard-coded cryptographic key vulnerability in Bilin… | Details |
| CVE-2026-14838 | 2026-08-04 08:42:27 | 2026-08-04 13:09:50 | TR-CERT | Use of GET request method with sensitive query… | Details |
| CVE-2026-14192 | 2026-08-04 08:48:52 | 2026-08-04 13:07:00 | TR-CERT | Improper neutralization of input during web page generation… | Details |
| CVE-2026-14465 | 2026-08-04 08:58:53 | 2026-08-04 13:03:45 | TR-CERT | Insufficient session expiration vulnerability in Bilin Software and… | Details |
| CVE-2026-14202 | 2026-08-04 09:07:15 | 2026-08-04 12:52:33 | TR-CERT | Observable response discrepancy vulnerability in Bilin Software and… | Details |
| CVE-2026-10050 | 2026-08-04 11:02:40 | 2026-08-04 12:46:38 | eclipse | In Eclipse Jetty, the Digest authentication server-side component… | Details |
| CVE-2026-66884 | 2026-08-04 11:45:49 | 2026-08-04 12:40:41 | EEF | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation… | Details |
| CVE-2026-66883 | 2026-08-04 11:46:05 | 2026-08-04 12:27:58 | EEF | Improper Handling of Case Sensitivity vulnerability in Erlang… | Details |
| CVE-2026-14682 | 2026-08-03 02:44:13 | 2026-08-04 09:24:50 | bcorg | In Bouncy Castle for Java before 1.85, Possible… | Details |
| CVE-2026-64565 | 2026-08-04 06:23:24 | 2026-08-04 06:23:24 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64563 | 2026-08-04 06:23:22 | 2026-08-04 06:23:22 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64562 | 2026-08-04 06:23:21 | 2026-08-04 06:23:21 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-64561 | 2026-08-04 06:23:21 | 2026-08-04 06:23:21 | Linux | In the Linux kernel, the following vulnerability has… | Details |
| CVE-2026-12185 | 2026-08-03 00:38:01 | 2026-08-04 01:54:27 | bcorg | In Bouncy Castle for Java before 1.85, BKS/UBER… | Details |
| CVE-2026-69151 | 2026-08-03 16:23:34 | 2026-08-03 21:19:24 | GitHub_M | Angular is a development platform for building mobile… | Details |
| CVE-2026-18613 | 2026-08-03 17:45:09 | 2026-08-03 21:19:17 | VulDB | A vulnerability has been found in GL-iNet GL-MT3000… | Details |
| CVE-2026-18632 | 2026-08-03 19:30:08 | 2026-08-03 21:19:13 | VulDB | A security flaw has been discovered in langgenius… | Details |
| CVE-2026-58139 | 2026-08-03 19:45:31 | 2026-08-03 21:19:09 | VulnCheck | The DuckDB AWS extension for DuckDB contains a… | Details |
| CVE-2026-47211 | 2026-08-03 20:01:03 | 2026-08-03 21:19:05 | GitHub_M | Ouroboros is a local-first runtime for AI coding… | Details |
| CVE-2026-69149 | 2026-08-03 16:14:39 | 2026-08-03 20:33:46 | GitHub_M | Angular is a development platform for building mobile… | Details |
| CVE-2026-69185 | 2026-08-03 19:09:10 | 2026-08-03 20:31:54 | GitHub_M | Socket.IO enables bidirectional and low-latency communication for every… | Details |
| CVE-2026-18644 | 2026-08-03 20:00:10 | 2026-08-03 20:28:48 | VulDB | A vulnerability was identified in danpros HTMLy up… | Details |
| CVE-2026-18607 | 2026-08-03 16:45:09 | 2026-08-03 20:23:24 | VulDB | A security vulnerability has been detected in Wavlink… | Details |
| CVE-2026-18615 | 2026-08-03 18:15:08 | 2026-08-03 20:17:48 | VulDB | A vulnerability was determined in GL-iNet GL-MT3000 up… | Details |
| CVE-2026-18587 | 2026-08-03 05:45:11 | 2026-08-03 20:16:37 | VulDB | A flaw has been found in Wavlink WL-NU516U1… | Details |
| CVE-2026-18612 | 2026-08-03 17:30:09 | 2026-08-03 20:13:29 | VulDB | A flaw has been found in GL-iNet GL-MT3000… | Details |
| CVE-2026-69152 | 2026-08-03 16:33:36 | 2026-08-03 20:12:20 | GitHub_M | The brace-expansion library generates arbitrary strings containing a… | Details |
| CVE-2026-67611 | 2026-08-03 16:04:34 | 2026-08-03 20:11:18 | VulnCheck | OpenEMR through 8.2.0 contains an authentication bypass vulnerability… | Details |
| CVE-2026-39931 | 2026-08-03 15:54:13 | 2026-08-03 20:10:01 | VulnCheck | OpenEMR through 8.2.0 contains an authenticated SQL injection… | Details |
| CVE-2026-61372 | 2026-08-03 15:41:27 | 2026-08-03 20:07:09 | apache | Improper Limitation of a Pathname to a Restricted… | Details |
| CVE-2026-18604 | 2026-08-03 15:45:09 | 2026-08-03 20:06:55 | VulDB | A vulnerability was identified in textPlus Text Message… | Details |
| CVE-2026-69094 | 2026-08-03 13:20:47 | 2026-08-03 20:05:54 | VulnCheck | Admidio before 5.0.11 contains an insecure direct object… | Details |
| CVE-2026-18568 | 2026-08-03 14:38:52 | 2026-08-03 20:05:52 | CPANSec | XML::Sig versions from 0.29 before 0.72 for Perl… | Details |
| CVE-2026-69089 | 2026-08-03 13:20:43 | 2026-08-03 20:04:51 | VulnCheck | Grav CMS 2.0.10 contains a path traversal vulnerability… | Details |
| CVE-2026-69084 | 2026-08-03 13:20:39 | 2026-08-03 20:03:22 | VulnCheck | SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint,… | Details |
| CVE-2026-68584 | 2026-08-03 13:20:36 | 2026-08-03 20:02:21 | VulnCheck | SiYuan versions before v3.7.3 contain an authentication bypass… | Details |
| CVE-2026-18092 | 2026-08-03 13:24:52 | 2026-08-03 20:01:20 | CPANSec | Net::SAML2 versions before 0.86 for Perl allow SAML… | Details |
| CVE-2026-18598 | 2026-08-03 11:30:10 | 2026-08-03 20:01:16 | VulDB | A vulnerability was detected in GL.iNet GL-MT3000 up… | Details |
| CVE-2026-68742 | 2026-08-03 09:53:14 | 2026-08-03 20:00:25 | redhat | A flaw was found in SSSD. The sss_nss_protocol_parse_addr()… | Details |
| CVE-2026-9487 | 2026-08-03 13:14:43 | 2026-08-03 19:59:47 | CPANSec | XML::Sig versions before 0.71 for Perl allow signature… | Details |
| CVE-2026-18589 | 2026-08-03 06:30:10 | 2026-08-03 19:59:44 | VulDB | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628.… | Details |
| CVE-2026-9390 | 2026-08-03 13:09:40 | 2026-08-03 19:58:50 | CPANSec | XML::Sig versions before 0.71 for Perl allow XPath… | Details |
| CVE-2026-18583 | 2026-08-03 04:15:08 | 2026-08-03 19:58:41 | VulDB | A weakness has been identified in mz-automation libiec61850… | Details |
| CVE-2026-18601 | 2026-08-03 13:15:08 | 2026-08-03 19:58:12 | VulDB | A vulnerability was found in GL.iNet GL-MT3000 up… | Details |
| CVE-2026-18108 | 2026-08-03 13:00:23 | 2026-08-03 19:57:38 | CPANSec | Net::SAML2 versions before 0.86 for Perl allow authentication… | Details |
| CVE-2026-68582 | 2026-08-02 12:15:28 | 2026-08-03 19:57:08 | VulnCheck | Vikunja versions >= 0.24.0 and <= 2.3.0 contain… | Details |
| CVE-2026-18089 | 2026-08-03 12:42:08 | 2026-08-03 19:56:33 | CPANSec | Net::SAML2 versions before 0.86 for Perl allow SAML… | Details |
| CVE-2026-18536 | 2026-08-01 10:35:38 | 2026-08-03 19:55:35 | CPANSec | Data::Entropy versions before 0.010 for Perl read remote… | Details |
| CVE-2026-67357 | 2026-08-02 12:15:25 | 2026-08-03 19:55:16 | VulnCheck | ArcadeDB versions before 26.7.3 contain an information disclosure… | Details |
| CVE-2026-12231 | 2026-08-02 08:33:00 | 2026-08-03 19:53:13 | Wordfence | The Exclusive Addons for Elementor plugin for WordPress… | Details |
| CVE-2026-18655 | 2026-08-03 19:04:12 | 2026-08-03 19:52:25 | AMZN | Improper restriction of intended endpoints in the RabbitMQ… | Details |
| CVE-2026-18571 | 2026-08-02 05:18:50 | 2026-08-03 19:52:10 | redhat | A flaw was found in the user creation… | Details |
| CVE-2026-67298 | 2026-08-01 12:22:18 | 2026-08-03 19:50:59 | VulnCheck | FreeRDP versions 3.28.0 and earlier contain a heap… | Details |
| CVE-2026-66296 | 2026-08-03 19:04:30 | 2026-08-03 19:50:27 | EEF | Improper Neutralization of Input During Web Page Generation… | Details |
| CVE-2026-67288 | 2026-08-01 12:22:18 | 2026-08-03 19:49:39 | VulnCheck | FreeRDP before 3.29.0 contains a null pointer dereference… | Details |
| CVE-2026-48031 | 2026-08-03 19:05:50 | 2026-08-03 19:49:15 | GitHub_M | go-base is a Go RESTful API Boilerplate template… | Details |
| CVE-2026-18581 | 2026-08-03 00:30:08 | 2026-08-03 19:47:33 | VulDB | A vulnerability was determined in ggml-org llama.cpp e15efe0.… | Details |
| CVE-2026-20493 | 2026-08-03 02:06:00 | 2026-08-03 19:47:06 | MediaTek | In wifi, there is a possible out of… | Details |
| CVE-2026-20492 | 2026-08-03 02:05:59 | 2026-08-03 19:46:26 | MediaTek | In Audio HAL, there is a possible system… | Details |
| CVE-2026-67303 | 2026-08-01 12:22:18 | 2026-08-03 19:45:09 | VulnCheck | FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength… | Details |
| CVE-2026-20484 | 2026-08-03 02:05:48 | 2026-08-03 19:45:07 | MediaTek | In TFA, there is a possible information disclosure… | Details |
| CVE-2026-20482 | 2026-08-03 02:05:44 | 2026-08-03 19:43:53 | MediaTek | In wlan STA FW, there is a possible… | Details |
| CVE-2026-18592 | 2026-08-03 07:30:07 | 2026-08-03 19:43:39 | VulDB | A security flaw has been discovered in osCommerce… | Details |
| CVE-2026-67333 | 2026-08-01 12:22:18 | 2026-08-03 19:43:05 | VulnCheck | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through… | Details |
| CVE-2026-20470 | 2026-08-03 02:05:47 | 2026-08-03 19:41:08 | MediaTek | In Telephony, there is a possible information disclosure… | Details |
| CVE-2026-67318 | 2026-08-01 12:22:18 | 2026-08-03 19:40:31 | VulnCheck | axios versions >=1.13.0 (Node.js HTTP adapter) fail to… | Details |
| CVE-2026-67328 | 2026-08-01 12:22:17 | 2026-08-03 19:39:20 | VulnCheck | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass… | Details |
| CVE-2026-67343 | 2026-08-01 12:22:17 | 2026-08-03 19:38:25 | VulnCheck | ArcadeDB versions before 26.7.2 fail to properly redact… | Details |
| CVE-2026-20466 | 2026-08-03 02:05:17 | 2026-08-03 19:38:19 | MediaTek | In sec boot, there is a possible escalation… | Details |
| CVE-2026-67355 | 2026-08-01 12:22:17 | 2026-08-03 19:37:29 | VulnCheck | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only… | Details |
| CVE-2026-67338 | 2026-08-01 12:22:17 | 2026-08-03 19:36:40 | VulnCheck | JupyterLab before 4.5.9 contains a stored cross-site scripting… | Details |
| CVE-2026-67308 | 2026-08-01 12:22:17 | 2026-08-03 19:35:25 | VulnCheck | Wazuh workflows before 44bf114 contain a shell injection… | Details |
| CVE-2026-18248 | 2026-08-03 15:20:04 | 2026-08-03 19:35:15 | openjs | @fastify/aws-lambda version 6.4.0 decorates each Fastify request with… | Details |
| CVE-2026-18642 | 2026-08-03 13:31:04 | 2026-08-03 19:34:41 | TR-CERT | Deserialization of untrusted data vulnerability in TUBITAK BILGEM… | Details |
| CVE-2026-38447 | 2026-08-03 00:00:00 | 2026-08-03 19:34:16 | mitre | osTicket 1.18.3 generates API keys using a predictable… | Details |
| CVE-2026-38446 | 2026-08-03 00:00:00 | 2026-08-03 19:32:20 | mitre | A stored cross-site scripting (XSS) vulnerability exists in… | Details |
| CVE-2025-71402 | 2026-08-01 12:22:16 | 2026-08-03 19:32:01 | VulnCheck | better-auth versions greater than 1.3.34 and before 1.4.0… | Details |
| CVE-2026-38444 | 2026-08-03 00:00:00 | 2026-08-03 19:31:07 | mitre | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting… | Details |
| CVE-2026-67313 | 2026-08-01 12:22:16 | 2026-08-03 19:30:22 | VulnCheck | axios versions 0.28.0 and later contain uncontrolled recursion… | Details |
| CVE-2026-55735 | 2026-08-01 18:46:05 | 2026-08-03 19:30:07 | EEF | Improper Verification of Cryptographic Signature in ueberauth guardian… | Details |
| CVE-2026-18344 | 2026-08-01 08:32:29 | 2026-08-03 19:28:19 | Wordfence | The Wp Responsive Thumbnail Slider plugin for WordPress… | Details |
| CVE-2026-15644 | 2026-08-01 08:32:28 | 2026-08-03 19:27:23 | Wordfence | The Powerkit – Supercharge your WordPress Site plugin… | Details |
| CVE-2026-15950 | 2026-08-01 07:49:52 | 2026-08-03 19:26:55 | Wordfence | The Cozy Blocks – Page Builder for Gutenberg… | Details |
| CVE-2026-15450 | 2026-08-01 07:49:51 | 2026-08-03 19:25:59 | Wordfence | The Nex Forms – Ultimate Form Builder –… | Details |
| CVE-2026-17605 | 2026-08-01 07:49:51 | 2026-08-03 19:25:21 | Wordfence | The Payment forms, Buy now buttons, and Invoicing… | Details |
| CVE-2026-16144 | 2026-08-01 07:49:50 | 2026-08-03 19:22:40 | Wordfence | The Kali Forms — Contact Form & Drag-and-Drop… | Details |
| CVE-2026-10782 | 2026-08-01 07:49:45 | 2026-08-03 19:21:36 | Wordfence | The RealHomes Memberships plugin for WordPress is vulnerable… | Details |
| CVE-2026-7623 | 2026-08-01 01:29:55 | 2026-08-03 19:21:05 | Wordfence | The SureForms – Contact Form, Payment Form &… | Details |
| CVE-2026-15430 | 2026-08-03 14:45:57 | 2026-08-03 19:19:47 | certcc | Improper access control in the IRP_MJ_WRITE command interface… | Details |
| CVE-2026-18570 | 2026-08-02 05:18:42 | 2026-08-03 19:17:32 | redhat | A flaw was found in the full-scope-disabled client-policy… | Details |
| CVE-2026-6695 | 2026-08-03 04:05:30 | 2026-08-03 19:16:42 | redhat | A flaw was found in GIMP. A remote… | Details |
| CVE-2025-14073 | 2026-08-01 08:32:28 | 2026-08-03 19:12:08 | Wordfence | The WooCommerce PayPal Payments plugin for WordPress is… | Details |
| CVE-2026-15662 | 2026-08-01 07:49:46 | 2026-08-03 19:11:16 | Wordfence | The Advanced Woo Labels – Product Labels &… | Details |
| CVE-2026-67292 | 2026-08-01 12:22:18 | 2026-08-03 19:09:45 | VulnCheck | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability… | Details |
| CVE-2026-17580 | 2026-08-01 07:49:53 | 2026-08-03 19:09:40 | Wordfence | The Advanced Views – Display Custom Fields (ACF,… | Details |
| CVE-2026-15414 | 2026-08-01 01:29:56 | 2026-08-03 19:08:41 | Wordfence | The Subscriptions for WooCommerce plugin for WordPress is… | Details |
| CVE-2026-20478 | 2026-08-03 02:05:35 | 2026-08-03 19:08:03 | MediaTek | In Audio HAL, there is a possible out… | Details |
| CVE-2026-2916 | 2026-08-01 06:48:48 | 2026-08-03 19:07:33 | Wordfence | The Jeg Kit for Elementor plugin for WordPress… | Details |
| CVE-2026-20476 | 2026-08-03 02:05:31 | 2026-08-03 19:07:29 | MediaTek | In ccci, there is a possible out of… | Details |
| CVE-2026-20472 | 2026-08-03 02:05:24 | 2026-08-03 19:05:23 | MediaTek | In TFA, there is a possible out of… | Details |
| CVE-2026-20471 | 2026-08-03 02:05:23 | 2026-08-03 19:04:40 | MediaTek | In DA, there is a possible out of… | Details |
| CVE-2026-20480 | 2026-08-03 02:05:40 | 2026-08-03 19:02:18 | MediaTek | In Audio HAL, there is a possible out… | Details |
| CVE-2026-17571 | 2026-08-01 08:32:27 | 2026-08-03 19:02:11 | Wordfence | The Fluent Forms – Customizable Contact Forms, Survey,… | Details |
| CVE-2026-20488 | 2026-08-03 02:05:52 | 2026-08-03 19:00:49 | MediaTek | In display, there is a possible information disclosure… | Details |
| CVE-2026-20489 | 2026-08-03 02:05:54 | 2026-08-03 18:59:46 | MediaTek | In display, there is a possible information disclosure… | Details |
| CVE-2026-20479 | 2026-08-03 02:05:38 | 2026-08-03 18:59:07 | MediaTek | In Modem, there is a possible out of… | Details |
| CVE-2026-20491 | 2026-08-03 02:05:57 | 2026-08-03 18:58:11 | MediaTek | In med, there is a possible out of… | Details |
| CVE-2026-15052 | 2026-08-01 07:49:51 | 2026-08-03 18:58:05 | Wordfence | The MailChimp Subscribe Form, Optin Builder, PopUp Builder,… | Details |
| CVE-2026-20494 | 2026-08-03 02:06:01 | 2026-08-03 18:57:13 | MediaTek | In wifi, there is a possible out of… | Details |
| CVE-2026-20496 | 2026-08-03 02:06:04 | 2026-08-03 18:55:51 | MediaTek | In geniezone, there is a possible out of… | Details |
| CVE-2026-8457 | 2026-08-01 23:29:35 | 2026-08-03 18:55:40 | Wordfence | The WooCommerce - Social Login plugin for WordPress… | Details |
| CVE-2026-20490 | 2026-08-03 02:05:55 | 2026-08-03 18:55:15 | MediaTek | In ccci, there is a possible out of… | Details |
| CVE-2026-18614 | 2026-08-03 18:00:09 | 2026-08-03 18:53:45 | VulDB | A vulnerability was found in GL-iNet GL-MT3000 up… | Details |
| CVE-2026-12696 | 2026-08-01 06:00:11 | 2026-08-03 18:53:06 | WPScan | The wpForo Forum WordPress plugin before 3.1.2 does… | Details |
| CVE-2026-16091 | 2026-08-01 07:49:53 | 2026-08-03 18:52:22 | Wordfence | The GamiPress – Gamification plugin to reward points,… | Details |
| CVE-2026-13329 | 2026-08-01 06:00:11 | 2026-08-03 18:52:09 | WPScan | The Buckaroo Woocommerce Payments Plugin WordPress plugin before… | Details |
| CVE-2026-13596 | 2026-08-01 06:00:12 | 2026-08-03 18:51:16 | WPScan | The Participants Database WordPress plugin before 2.7.8.4 does… | Details |
| CVE-2026-15234 | 2026-08-01 06:00:10 | 2026-08-03 18:50:30 | WPScan | The Codeless Page Builder WordPress plugin through 1.1.4… | Details |
| CVE-2026-14292 | 2026-08-01 06:00:13 | 2026-08-03 18:49:47 | WPScan | The Download Manager WordPress plugin before 3.3.66 does… | Details |
| CVE-2026-12966 | 2026-08-01 06:00:08 | 2026-08-03 18:49:03 | WPScan | The Direct Payments for WooCommerce WordPress plugin… | Details |
| CVE-2026-15262 | 2026-08-01 06:00:10 | 2026-08-03 18:48:17 | WPScan | The Admin Columns for ACF Fields WordPress plugin… | Details |
| CVE-2025-15669 | 2026-08-01 06:00:08 | 2026-08-03 18:47:33 | WPScan | The Bit Form WordPress plugin before 3.1.4… | Details |
| CVE-2026-14315 | 2026-08-01 06:00:13 | 2026-08-03 18:46:42 | WPScan | The Pixel Tag Manager for WooCommerce WordPress… | Details |
| CVE-2026-14561 | 2026-08-01 06:00:13 | 2026-08-03 18:41:54 | WPScan | The Authora : Easy login with mobile number… | Details |
| CVE-2026-14839 | 2026-08-01 06:00:14 | 2026-08-03 18:41:02 | WPScan | The Mapster WP Maps WordPress plugin before 1.24.0… | Details |
| CVE-2026-6453 | 2026-08-01 08:32:28 | 2026-08-03 18:39:59 | Wordfence | The CubeWP Framework plugin for WordPress is vulnerable… | Details |
| CVE-2026-18243 | 2026-08-03 15:58:54 | 2026-08-03 18:39:46 | hp | Certain HP DesignJet products may be potentially vulnerable… | Details |
| CVE-2026-15964 | 2026-08-01 08:32:27 | 2026-08-03 18:39:30 | Wordfence | The Single Sign On For TNG plugin for… | Details |
| CVE-2026-18059 | 2026-08-01 07:49:52 | 2026-08-03 18:38:53 | Wordfence | The PixelYourSite – Your smart PIXEL (TAG) &… | Details |
| CVE-2026-15951 | 2026-08-01 07:49:50 | 2026-08-03 18:38:23 | Wordfence | The Icegram Mailer plugin for WordPress is vulnerable… | Details |
| CVE-2026-16614 | 2026-08-01 07:49:49 | 2026-08-03 18:37:54 | Wordfence | The GSheetConnector – CF7 Google Sheets Connector with… | Details |
| CVE-2026-11995 | 2026-08-01 07:49:49 | 2026-08-03 18:37:21 | Wordfence | The Gutena Forms – Contact Form, Survey Form,… | Details |
| CVE-2026-15601 | 2026-08-01 07:49:46 | 2026-08-03 18:36:23 | Wordfence | The Kirki – Freeform Page Builder, Website Builder… | Details |
| CVE-2026-67307 | 2026-08-01 12:22:18 | 2026-08-03 18:35:41 | VulnCheck | Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate… | Details |
| CVE-2025-15544 | 2026-08-03 17:49:13 | 2026-08-03 18:35:36 | TPLink | A cryptographic weakness exists in the Omada device adoption… | Details |
| CVE-2026-67312 | 2026-08-01 12:22:18 | 2026-08-03 18:34:07 | VulnCheck | axios versions from 0.28.0 before 0.33.0 and from… | Details |
| CVE-2025-15627 | 2026-08-03 17:49:46 | 2026-08-03 18:33:55 | TPLink | A cryptographic weakness exists in the Omada adoption protocol. The… | Details |
| CVE-2026-67302 | 2026-08-01 12:22:18 | 2026-08-03 18:33:16 | VulnCheck | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains… | Details |
| CVE-2025-15628 | 2026-08-03 17:50:12 | 2026-08-03 18:33:03 | TPLink | Affected Omada devices rely on embedded certificates that are… | Details |
| CVE-2025-15629 | 2026-08-03 17:50:44 | 2026-08-03 18:32:11 | TPLink | A cryptographic weakness exists in the Omada adoption protocol… | Details |
| CVE-2026-67332 | 2026-08-01 12:22:18 | 2026-08-03 18:32:02 | VulnCheck | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience… | Details |
| CVE-2026-67337 | 2026-08-01 12:22:18 | 2026-08-03 18:31:13 | VulnCheck | better-auth versions before 1.4.9 contain a two-factor authentication… | Details |
| CVE-2025-15630 | 2026-08-03 17:51:06 | 2026-08-03 18:30:42 | TPLink | A race condition exists in the cloud-based Omada device… | Details |
| CVE-2026-67327 | 2026-08-01 12:22:17 | 2026-08-03 18:29:37 | VulnCheck | better-auth versions >= 1.1.3 and < 1.6.22 (and… | Details |
| CVE-2025-15631 | 2026-08-03 17:51:52 | 2026-08-03 18:29:33 | TPLink | A cryptographic weakness exists in affected Omada devices where… | Details |
| CVE-2026-69153 | 2026-08-03 16:56:25 | 2026-08-03 18:28:59 | GitHub_M | PostCSS takes a CSS file and provides an… | Details |
| CVE-2026-67322 | 2026-08-01 12:22:17 | 2026-08-03 18:27:43 | VulnCheck | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration… | Details |
| CVE-2026-18610 | 2026-08-03 17:00:09 | 2026-08-03 18:27:37 | VulDB | A vulnerability was detected in NewType WebEIP up… | Details |
| CVE-2026-58062 | 2026-08-03 02:35:28 | 2026-08-03 18:27:07 | bcorg | In Bouncy Castle for Java before 1.85, Stapled… | Details |
| CVE-2026-67297 | 2026-08-01 12:22:16 | 2026-08-03 18:26:50 | VulnCheck | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT… | Details |
| CVE-2026-67319 | 2026-08-01 12:22:18 | 2026-08-03 18:26:40 | VulnCheck | axios before 0.33.0 (and 1.x before 1.18.0) can… | Details |
| CVE-2026-67342 | 2026-08-01 12:22:16 | 2026-08-03 18:26:03 | VulnCheck | ArcadeDB versions before 26.7.2 contain an authorization bypass… | Details |
| CVE-2026-67317 | 2026-08-01 12:22:16 | 2026-08-03 18:25:21 | VulnCheck | axios versions 1.7.0 before 1.18.0 fail to enforce… | Details |
| CVE-2026-67344 | 2026-08-01 12:22:18 | 2026-08-03 18:24:43 | VulnCheck | ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA… | Details |
| CVE-2026-67354 | 2026-08-01 12:22:18 | 2026-08-03 18:24:12 | VulnCheck | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure… | Details |
| CVE-2026-67301 | 2026-08-01 12:22:16 | 2026-08-03 18:23:49 | VulnCheck | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in… | Details |
| CVE-2026-61524 | 2026-08-03 17:19:51 | 2026-08-03 18:23:26 | VulnCheck | WebsiteBaker CMS before 2.13.10 contains an unrestricted file… | Details |
| CVE-2026-67329 | 2026-08-01 12:22:18 | 2026-08-03 18:23:06 | VulnCheck | @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and… | Details |
| CVE-2026-67341 | 2026-08-01 12:22:18 | 2026-08-03 18:22:32 | VulnCheck | ArcadeDB versions before 26.7.2 fail to enforce scripting… | Details |
| CVE-2026-67353 | 2026-08-01 12:22:17 | 2026-08-03 18:19:35 | VulnCheck | guzzlehttp/guzzle versions before 7.15.1 contain a denial of… | Details |
| CVE-2026-67334 | 2026-08-01 12:22:18 | 2026-08-03 18:19:22 | VulnCheck | better-auth versions before 1.6.11 fail to delete cached… | Details |
| CVE-2025-71403 | 2026-08-01 12:22:18 | 2026-08-03 18:18:54 | VulnCheck | better-auth versions before 1.1.20 contain a bypass vulnerability… | Details |
| CVE-2026-67294 | 2026-08-01 12:22:17 | 2026-08-03 18:15:35 | VulnCheck | FreeRDP before 3.29.0 improperly validates the Extended Key… | Details |
| CVE-2026-41453 | 2026-08-03 15:47:11 | 2026-08-03 18:11:42 | VulnCheck | Krayin CRM before 2.2.4 contains a blind SQL… | Details |
| CVE-2026-67304 | 2026-08-01 12:22:17 | 2026-08-03 18:11:18 | VulnCheck | FreeRDP before 3.29.0 contains a null pointer dereference… | Details |
| CVE-2026-61523 | 2026-08-03 17:18:45 | 2026-08-03 18:10:17 | VulnCheck | WebsiteBaker CMS before 2.13.10 contains a code injection… | Details |
| CVE-2026-67339 | 2026-08-01 12:22:17 | 2026-08-03 18:08:40 | VulnCheck | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate… | Details |
| CVE-2026-67314 | 2026-08-01 12:22:16 | 2026-08-03 18:06:09 | VulnCheck | axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side… | Details |
| CVE-2026-17555 | 2026-08-01 08:32:27 | 2026-08-03 18:01:35 | Wordfence | The WPvivid Backup & Migration plugin for WordPress… | Details |
| CVE-2026-15649 | 2026-08-01 07:49:53 | 2026-08-03 18:00:56 | Wordfence | The Powerkit – Supercharge your WordPress Site plugin… | Details |
| CVE-2026-15018 | 2026-08-01 07:49:49 | 2026-08-03 17:59:21 | Wordfence | The Database Collation Fix plugin for WordPress is… | Details |
| CVE-2026-2411 | 2026-08-01 12:06:41 | 2026-08-03 17:51:29 | zephyr | Zephyr's Bluetooth host declares a GATT characteristic as… | Details |
| CVE-2026-10773 | 2026-08-01 12:21:17 | 2026-08-03 17:50:55 | zephyr | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes… | Details |
| CVE-2026-54894 | 2026-08-01 18:46:05 | 2026-08-03 17:49:54 | EEF | Allocation of Resources Without Limits or Throttling in… | Details |
| CVE-2026-16540 | 2026-08-02 06:00:13 | 2026-08-03 17:49:00 | WPScan | The Simply Schedule Appointments WordPress plugin before 1.6.12.6… | Details |
| CVE-2026-16064 | 2026-08-02 06:00:12 | 2026-08-03 17:48:20 | WPScan | The Event Booking Manager for WooCommerce WordPress… | Details |
| CVE-2026-16063 | 2026-08-02 06:00:12 | 2026-08-03 17:47:42 | WPScan | The Event Booking Manager for WooCommerce WordPress… | Details |
| CVE-2025-15675 | 2026-08-02 06:00:13 | 2026-08-03 17:46:59 | WPScan | The Charitable WordPress plugin before 1.8.5.3 does… | Details |
| CVE-2026-67331 | 2026-08-01 12:22:17 | 2026-08-03 17:46:41 | VulnCheck | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail… | Details |
| CVE-2026-13389 | 2026-08-02 06:00:13 | 2026-08-03 17:46:19 | WPScan | The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not… | Details |
| CVE-2026-16285 | 2026-08-02 06:00:12 | 2026-08-03 17:45:32 | WPScan | The Product Attachment for WooCommerce WordPress plugin before… | Details |
| CVE-2026-67296 | 2026-08-01 12:22:17 | 2026-08-03 17:45:21 | VulnCheck | FreeRDP before 3.29.0 contains a denial of service… | Details |
| CVE-2026-16273 | 2026-08-02 06:00:11 | 2026-08-03 17:44:47 | WPScan | The Narrative Publisher WordPress plugin through 1.0.7 does… | Details |
| CVE-2026-16261 | 2026-08-02 06:00:11 | 2026-08-03 17:44:01 | WPScan | The login-social WordPress plugin through 1.0.4 does not… | Details |
| CVE-2026-15241 | 2026-08-02 06:00:09 | 2026-08-03 17:42:56 | WPScan | The AI ChatBot for WooCommerce WordPress plugin… | Details |
| CVE-2026-66401 | 2026-08-01 12:22:18 | 2026-08-03 17:42:01 | VulnCheck | FreeRDP before 3.29.0 contains an out-of-bounds heap read… | Details |
| CVE-2026-15206 | 2026-08-02 06:00:09 | 2026-08-03 17:41:55 | WPScan | The SMS Alert WordPress plugin before 3.9.8… | Details |
| CVE-2026-15151 | 2026-08-02 06:00:08 | 2026-08-03 17:41:05 | WPScan | The Five Star Restaurant Reservations WordPress plugin… | Details |
| CVE-2026-14864 | 2026-08-02 06:00:08 | 2026-08-03 17:40:16 | WPScan | The JetEngine WordPress plugin before 3.8.12 does not… | Details |
| CVE-2026-67306 | 2026-08-01 12:22:18 | 2026-08-03 17:40:02 | VulnCheck | FreeRDP versions 3.28.0 and earlier contain an out-of-bounds… | Details |
| CVE-2026-15385 | 2026-08-02 06:00:10 | 2026-08-03 17:39:34 | WPScan | The RT Mega Menu WordPress plugin before… | Details |
| CVE-2026-14841 | 2026-08-02 06:00:07 | 2026-08-03 17:38:47 | WPScan | The King Addons for Elementor WordPress plugin… | Details |
| CVE-2026-16685 | 2026-08-01 07:49:48 | 2026-08-03 17:38:14 | Wordfence | The Download Manager plugin for WordPress is vulnerable… | Details |
| CVE-2026-15236 | 2026-08-02 06:00:14 | 2026-08-03 17:37:55 | WPScan | The Gallery for Google Photos WordPress plugin… | Details |
| CVE-2026-16090 | 2026-08-01 07:49:48 | 2026-08-03 17:36:05 | Wordfence | The GamiPress – Gamification plugin to reward points,… | Details |
| CVE-2026-18435 | 2026-08-01 07:49:47 | 2026-08-03 17:35:46 | Wordfence | The Kadence Blocks — Page Builder Toolkit for… | Details |
| CVE-2026-15988 | 2026-08-01 06:48:48 | 2026-08-03 17:34:26 | Wordfence | The AI Engine – The Chatbot, AI Framework… | Details |
| CVE-2026-15403 | 2026-08-01 01:29:57 | 2026-08-03 17:31:27 | Wordfence | The Pinpoint Booking System – Version 2 plugin… | Details |
| CVE-2026-15260 | 2026-08-03 06:00:12 | 2026-08-03 17:31:14 | WPScan | The GEO my WP WordPress plugin before 4.5.5.3… | Details |
| CVE-2026-15930 | 2026-08-03 06:00:12 | 2026-08-03 17:30:59 | WPScan | The Simple Membership WordPress plugin before 4.7.8 does… | Details |
| CVE-2026-16564 | 2026-08-03 06:00:14 | 2026-08-03 17:30:48 | WPScan | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution… | Details |
| CVE-2026-16565 | 2026-08-03 06:00:14 | 2026-08-03 17:30:41 | WPScan | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution… | Details |
| CVE-2026-13362 | 2026-08-01 01:29:56 | 2026-08-03 17:11:53 | Wordfence | The SendPulse Email Marketing Newsletter plugin for WordPress… | Details |
| CVE-2026-3141 | 2026-08-01 05:33:54 | 2026-08-03 17:11:26 | Wordfence | The FormGent plugin for WordPress is vulnerable to… | Details |
| CVE-2026-15931 | 2026-08-03 06:00:13 | 2026-08-03 17:06:38 | WPScan | The Simple Membership WordPress plugin before 4.7.8 does… | Details |
| CVE-2026-16539 | 2026-08-03 06:00:14 | 2026-08-03 17:05:55 | WPScan | The sm page duplicator WordPress plugin through 1.0.0… | Details |
| CVE-2026-15383 | 2026-08-03 06:00:12 | 2026-08-03 17:05:08 | WPScan | The Blog Floating Button WordPress plugin through 1.4.20… | Details |
| CVE-2026-13340 | 2026-08-03 06:00:11 | 2026-08-03 17:04:22 | WPScan | The SVG Support WordPress plugin before 2.5.17 does… | Details |
| CVE-2026-12965 | 2026-08-03 06:00:11 | 2026-08-03 17:03:37 | WPScan | The Super Store Finder WordPress plugin through 7.8… | Details |
| CVE-2026-16534 | 2026-08-03 06:00:10 | 2026-08-03 17:02:38 | WPScan | The Import and export users and customers WordPress… | Details |
| CVE-2026-16532 | 2026-08-03 06:00:10 | 2026-08-03 17:01:28 | WPScan | The Link Library WordPress plugin before 7.9.3 does… | Details |
| CVE-2026-15254 | 2026-08-03 06:00:10 | 2026-08-03 17:00:35 | WPScan | The Simply Schedule Appointments WordPress plugin before 1.6.12.11… | Details |
| CVE-2026-16563 | 2026-08-03 06:00:14 | 2026-08-03 16:59:40 | WPScan | The Academy LMS WordPress plugin before 3.8.3 does… | Details |
| CVE-2026-18651 | 2026-08-03 14:55:33 | 2026-08-03 16:58:47 | redhat | A flaw was found in 389 Directory Server.… | Details |
| CVE-2026-68945 | 2026-08-03 15:58:02 | 2026-08-03 16:58:26 | GitHub_M | Angular is a development platform for building mobile… | Details |
| CVE-2026-67610 | 2026-08-03 16:02:47 | 2026-08-03 16:57:29 | VulnCheck | OpenEMR through 8.2.0 contains an improper authentication vulnerability… | Details |
| CVE-2026-18606 | 2026-08-03 16:15:07 | 2026-08-03 16:56:43 | VulDB | A weakness has been identified in Razer RzUpdateService… | Details |
| CVE-2026-55733 | 2026-08-01 18:46:12 | 2026-08-03 16:50:53 | EEF | Allocation of Resources Without Limits or Throttling in… | Details |
| CVE-2026-55734 | 2026-08-01 18:46:24 | 2026-08-03 16:49:59 | EEF | Allocation of Resources Without Limits or Throttling vulnerability… | Details |
| CVE-2026-18602 | 2026-08-03 15:30:08 | 2026-08-03 16:48:22 | VulDB | A vulnerability was determined in GL.iNet GL-MT3000 up… | Details |
| CVE-2026-9335 | 2026-08-02 03:49:25 | 2026-08-03 16:48:20 | @huntr_ai | A vulnerability in keras-team/keras versions <= 3.14.0 allows… | Details |
| CVE-2026-18573 | 2026-08-02 05:28:43 | 2026-08-03 16:47:32 | redhat | A flaw was found in the keycloak-services component… | Details |
| CVE-2026-67356 | 2026-08-02 12:15:24 | 2026-08-03 16:46:50 | VulnCheck | ArcadeDB before 26.7.3 binds the real LocalDatabase object… | Details |
| CVE-2026-68930 | 2026-08-03 15:34:41 | 2026-08-03 16:46:32 | GitHub_M | Russh is a Rust SSH client & server… | Details |
| CVE-2026-39932 | 2026-08-03 16:00:09 | 2026-08-03 16:37:11 | VulnCheck | OpenEMR through 8.2.0 contains a remote code execution… | Details |
| CVE-2026-67612 | 2026-08-03 16:06:15 | 2026-08-03 16:35:13 | VulnCheck | OpenEMR through 8.2.0 contains a stored cross-site scripting… | Details |
| CVE-2026-67609 | 2026-08-03 13:32:37 | 2026-08-03 16:31:57 | VulnCheck | Telenia Software TVox 26.5.3 and prior 26.x versions,… | Details |
| CVE-2026-67608 | 2026-08-03 13:30:35 | 2026-08-03 16:31:34 | VulnCheck | Telenia Software TVox 26.5.3 and prior 26.x versions,… | Details |
| CVE-2026-41452 | 2026-08-03 15:43:05 | 2026-08-03 16:26:45 | VulnCheck | Krayin CRM 2.2.4 contains a missing authentication vulnerability… | Details |
| CVE-2026-18605 | 2026-08-03 16:00:10 | 2026-08-03 16:26:41 | VulDB | A security flaw has been discovered in CheckMAL… | Details |
| CVE-2026-16289 | 2026-08-03 06:00:13 | 2026-08-03 16:19:22 | WPScan | The ProfileGrid WordPress plugin before 6.0.0.0 does… | Details |
| CVE-2026-16297 | 2026-08-03 06:00:13 | 2026-08-03 16:17:31 | WPScan | The Clearfy Cache WordPress plugin before 2.4.3… | Details |
| CVE-2026-16300 | 2026-08-03 06:00:13 | 2026-08-03 16:09:39 | WPScan | The ChamaWP WordPress plugin before 1.0.13 does… | Details |
| CVE-2026-16572 | 2026-08-03 06:00:14 | 2026-08-03 16:08:30 | WPScan | The LogMyTrip WordPress plugin through 1.9 does not… | Details |
| CVE-2026-18508 | 2026-08-03 14:51:41 | 2026-08-03 16:06:11 | redhat | A flaw was found in GNU tar. When… | Details |
| CVE-2026-67309 | 2026-08-01 12:22:18 | 2026-08-03 16:00:57 | VulnCheck | Traefik versions >= v3.7.0 and <= v3.7.7 contain… | Details |
| CVE-2026-67299 | 2026-08-01 12:22:18 | 2026-08-03 15:55:40 | VulnCheck | FreeRDP before 3.29.0 contains a client-side heap use-after-free… | Details |
| CVE-2026-18352 | 2026-08-01 23:29:34 | 2026-08-03 15:52:06 | Wordfence | The User Access Manager plugin for WordPress is… | Details |
| CVE-2026-18572 | 2026-08-02 05:18:58 | 2026-08-03 15:51:23 | redhat | Keycloak provides authorization services that allow administrators to… | Details |
| CVE-2025-71399 | 2026-08-02 12:15:22 | 2026-08-03 15:50:52 | VulnCheck | Better Auth relies on better-call, which uses the… | Details |
| CVE-2026-68578 | 2026-08-02 12:15:25 | 2026-08-03 15:44:10 | VulnCheck | ArcadeDB versions before 26.7.3 fail to bind the… | Details |
| CVE-2026-68583 | 2026-08-02 12:15:29 | 2026-08-03 15:41:14 | VulnCheck | luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting… | Details |
| CVE-2026-18582 | 2026-08-03 01:15:12 | 2026-08-03 15:39:59 | VulDB | A security flaw has been discovered in mz-automation… | Details |
| CVE-2026-15006 | 2026-08-01 01:29:56 | 2026-08-03 15:38:55 | Wordfence | The Bit integrations – Form Integration, Webhook, Spreadsheets,… | Details |
| CVE-2025-14469 | 2026-08-01 06:48:47 | 2026-08-03 15:38:52 | Wordfence | The Theme Editor plugin for WordPress is vulnerable… | Details |
| CVE-2026-16684 | 2026-08-01 07:49:44 | 2026-08-03 15:38:49 | Wordfence | The Easy Property Listings plugin for WordPress is… | Details |
| CVE-2026-16087 | 2026-08-01 07:49:45 | 2026-08-03 15:38:46 | Wordfence | The Icegram Engage – Popups, Optins, CTAs &… | Details |
| CVE-2026-13458 | 2026-08-01 07:49:45 | 2026-08-03 15:38:43 | Wordfence | The GenerateBlocks plugin for WordPress is vulnerable to… | Details |
| CVE-2026-15645 | 2026-08-01 07:49:47 | 2026-08-03 15:38:39 | Wordfence | The Powerkit – Supercharge your WordPress Site plugin… | Details |
| CVE-2026-18062 | 2026-08-01 07:49:47 | 2026-08-03 15:38:36 | Wordfence | The Kadence Blocks — Page Builder Toolkit for… | Details |
| CVE-2026-16635 | 2026-08-01 08:32:29 | 2026-08-03 15:38:33 | Wordfence | The Pronamic Pay plugin for WordPress is vulnerable… | Details |
| CVE-2026-67352 | 2026-08-01 12:22:16 | 2026-08-03 15:38:30 | VulnCheck | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in… | Details |
| CVE-2026-67290 | 2026-08-01 12:22:16 | 2026-08-03 15:38:23 | VulnCheck | FreeRDP before 3.29.0 contains a heap out-of-bounds read… | Details |
| CVE-2026-67330 | 2026-08-01 12:22:16 | 2026-08-03 15:38:15 | VulnCheck | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through… | Details |
| CVE-2026-67335 | 2026-08-01 12:22:17 | 2026-08-03 15:38:08 | VulnCheck | better-auth versions before 1.6.2 fail to validate the… | Details |
| CVE-2026-67320 | 2026-08-01 12:22:17 | 2026-08-03 15:38:04 | VulnCheck | axios in a Node.js deployment using the HTTP… | Details |
| CVE-2025-71404 | 2026-08-01 12:22:17 | 2026-08-03 15:38:00 | VulnCheck | better-auth versions after v0.0.2 and before 1.1.16 contain… | Details |
| CVE-2026-67310 | 2026-08-01 12:22:17 | 2026-08-03 15:37:56 | VulnCheck | OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure… | Details |
| CVE-2026-67315 | 2026-08-01 12:22:18 | 2026-08-03 15:37:53 | VulnCheck | axios versions 0.31.0 before 0.33.0 and 1.15.0 before… | Details |
| CVE-2026-67340 | 2026-08-01 12:22:18 | 2026-08-03 15:37:49 | VulnCheck | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to… | Details |
| CVE-2026-67295 | 2026-08-01 12:22:18 | 2026-08-03 15:37:43 | VulnCheck | FreeRDP before 3.29.0 fails to properly validate server-supplied… | Details |
| CVE-2026-67300 | 2026-08-01 12:22:18 | 2026-08-03 15:37:40 | VulnCheck | FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities… | Details |
| CVE-2026-13339 | 2026-08-01 23:29:35 | 2026-08-03 15:37:36 | Wordfence | The CubeWP Framework plugin for WordPress is vulnerable… | Details |
| CVE-2025-71400 | 2026-08-02 12:15:22 | 2026-08-03 15:37:32 | VulnCheck | better-auth passkey versions before 1.4.0 contain an insecure… | Details |
| CVE-2026-68579 | 2026-08-02 12:15:26 | 2026-08-03 15:37:29 | VulnCheck | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based… | Details |
| CVE-2026-6694 | 2026-08-03 04:05:27 | 2026-08-03 15:37:22 | redhat | A flaw was found in GIMP's file-png plugin.… | Details |
| CVE-2026-18584 | 2026-08-03 04:45:07 | 2026-08-03 15:37:18 | VulDB | A security vulnerability has been detected in GL.iNet… | Details |
| CVE-2026-18590 | 2026-08-03 06:45:10 | 2026-08-03 15:37:14 | VulDB | A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628.… | Details |
| CVE-2026-28147 | 2026-08-03 07:09:38 | 2026-08-03 15:37:10 | Patchstack | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements… | Details |
| CVE-2026-18599 | 2026-08-03 12:00:09 | 2026-08-03 15:37:07 | VulDB | A flaw has been found in GL.iNet GL-MT3000… | Details |
| CVE-2026-68586 | 2026-08-03 13:20:37 | 2026-08-03 15:37:03 | VulnCheck | SiYuan before v3.7.3 fails to apply publish-access filters… | Details |
| CVE-2026-69086 | 2026-08-03 13:20:41 | 2026-08-03 15:36:58 | VulnCheck | SiYuan versions before v3.7.3 fail to validate the… | Details |
| CVE-2026-69091 | 2026-08-03 13:20:44 | 2026-08-03 15:36:54 | VulnCheck | Admidio before 5.0.11 contains an authentication bypass vulnerability… | Details |
| CVE-2026-58063 | 2026-08-03 02:29:09 | 2026-08-03 15:36:41 | bcorg | In Bouncy Castle for Java before 1.85, BCFKS… | Details |
| CVE-2026-58061 | 2026-08-03 02:36:36 | 2026-08-03 15:35:41 | bcorg | In Bouncy Castle for Java before 1.85, CCM-family… | Details |
| CVE-2026-58060 | 2026-08-03 02:37:43 | 2026-08-03 15:34:42 | bcorg | In Bouncy Castle for Java before 1.85, HSS… | Details |
| CVE-2026-58059 | 2026-08-03 02:41:30 | 2026-08-03 15:32:46 | bcorg | In Bouncy Castle for Java before 1.85, Quadratic-time… | Details |
| CVE-2026-12802 | 2026-08-03 02:48:42 | 2026-08-03 15:28:12 | bcorg | In Bouncy Castle for Java before 1.85, CMS… | Details |
| CVE-2026-68587 | 2026-08-03 13:20:38 | 2026-08-03 15:26:26 | VulnCheck | SiYuan versions before v3.7.3 contain an information disclosure… | Details |
| CVE-2026-67336 | 2026-08-01 12:22:18 | 2026-08-03 15:23:44 | VulnCheck | better-auth versions before 1.6.11 contain insecure cryptographic defaults… | Details |
| CVE-2026-12803 | 2026-08-03 02:52:20 | 2026-08-03 15:22:55 | bcorg | In Bouncy Castle for Java before 1.85, KCCMBlockCipher… | Details |
| CVE-2026-12816 | 2026-08-03 02:53:32 | 2026-08-03 15:21:22 | bcorg | In Bouncy Castle for Java before 1.85, IESEngine… | Details |
| CVE-2026-67321 | 2026-08-01 12:22:18 | 2026-08-03 15:18:48 | VulnCheck | axios versions 0.31.1 before 0.33.0 and 1.15.1 before… | Details |
| CVE-2026-67316 | 2026-08-01 12:22:18 | 2026-08-03 15:17:16 | VulnCheck | axios is vulnerable to read-side prototype-pollution gadgets that… | Details |
| CVE-2026-67311 | 2026-08-01 12:22:18 | 2026-08-03 15:15:47 | VulnCheck | Budibase before 3.38.1 contains a server-side request forgery… | Details |
| CVE-2026-12817 | 2026-08-03 02:54:16 | 2026-08-03 15:15:27 | bcorg | In Bouncy Castle for Java before 1.85, OpenPGP… | Details |
| CVE-2026-12852 | 2026-08-03 02:55:02 | 2026-08-03 15:11:39 | bcorg | In Bouncy Castle for Java before 1.85, MLS… | Details |
| CVE-2026-12860 | 2026-08-03 02:55:58 | 2026-08-03 15:10:17 | bcorg | In Bouncy Castle for Java before 1.85, RSA… | Details |
| CVE-2026-13506 | 2026-08-03 02:56:49 | 2026-08-03 15:09:01 | bcorg | In Bouncy Castle for Java before 1.85, Lazy… | Details |
| CVE-2026-13586 | 2026-08-03 02:58:00 | 2026-08-03 15:03:49 | bcorg | In Bouncy Castle for Java before 1.85, PKCS#12… | Details |
| CVE-2026-18588 | 2026-08-03 06:00:11 | 2026-08-03 15:03:20 | VulDB | A vulnerability has been found in Wavlink WL-NU516U1… | Details |
| CVE-2026-68581 | 2026-08-02 12:15:27 | 2026-08-03 15:02:40 | VulnCheck | Vikunja versions 0.22.0 through 2.3.0 fail to validate… | Details |
| CVE-2026-12259 | 2026-08-03 07:09:35 | 2026-08-03 14:59:01 | @huntr_ai | In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes… | Details |
| CVE-2026-65875 | 2026-08-03 00:13:39 | 2026-08-03 14:58:59 | jpcert | BaserCMS provided by baserCMS Users Community contains a… | Details |
| CVE-2026-9856 | 2026-08-02 15:10:53 | 2026-08-03 14:57:43 | @huntr_ai | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an… | Details |
| CVE-2026-10774 | 2026-08-02 14:20:03 | 2026-08-03 14:57:06 | zephyr | Zephyr's Bluetooth Mesh subnet key management leaks one… | Details |
| CVE-2026-67291 | 2026-08-01 12:22:18 | 2026-08-03 14:56:19 | VulnCheck | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains… | Details |
| CVE-2026-10848 | 2026-08-02 16:12:18 | 2026-08-03 14:55:27 | zephyr | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound… | Details |
| CVE-2026-4793 | 2026-08-03 06:00:39 | 2026-08-03 14:54:10 | synology | An incorrect default permissions vulnerability in Synology Assistant… | Details |
| CVE-2026-3245 | 2026-08-02 23:32:44 | 2026-08-03 14:53:56 | Canon | A deserialization vulnerability in PRISMAproduction Version 6.5 or… | Details |
| CVE-2026-59646 | 2026-08-03 00:48:29 | 2026-08-03 14:53:11 | bcorg | In Bouncy Castle for Java before 1.85, DTLS… | Details |
| CVE-2026-18600 | 2026-08-03 13:00:10 | 2026-08-03 14:50:38 | VulDB | A vulnerability has been found in GL.iNet GL-MT3000… | Details |
| CVE-2026-69093 | 2026-08-03 13:20:46 | 2026-08-03 14:49:53 | VulnCheck | Admidio before 5.0.11 does not validate the adm_csrf_token… | Details |
| CVE-2026-69088 | 2026-08-03 13:20:42 | 2026-08-03 14:47:10 | VulnCheck | Grav CMS versions 2.0.7 through 2.0.10 fail to… | Details |
| CVE-2026-9593 | 2026-08-03 06:28:19 | 2026-08-03 14:44:52 | CERTVDE | A vulnerability in the iDTM FDI allows an… | Details |
| CVE-2026-69083 | 2026-08-03 13:20:39 | 2026-08-03 14:42:13 | VulnCheck | SiYuan versions before v3.7.3 contain SQL injection vulnerabilities… | Details |
| CVE-2026-8793 | 2026-08-03 06:58:00 | 2026-08-03 14:32:59 | PaperCut | PaperCut NG/MF does not properly restrict excessive authentication… | Details |
| CVE-2026-8794 | 2026-08-03 07:02:42 | 2026-08-03 14:30:36 | PaperCut | PaperCut NG/MF contains an observable timing discrepancy in… | Details |
| CVE-2025-71401 | 2026-08-02 12:15:23 | 2026-08-03 14:29:35 | VulnCheck | better-auth (npm) before 1.4.2 allows an external request… | Details |
| CVE-2026-21548 | 2026-08-03 07:18:17 | 2026-08-03 14:27:38 | Unisoc | In nr modem, there is a possible improper… | Details |
| CVE-2026-21549 | 2026-08-03 07:18:19 | 2026-08-03 14:25:44 | Unisoc | In modem, there is a possible improper input… | Details |
| CVE-2026-69087 | 2026-08-03 13:20:42 | 2026-08-03 14:25:42 | VulnCheck | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains… | Details |
| CVE-2026-21550 | 2026-08-03 07:18:21 | 2026-08-03 14:24:16 | Unisoc | In modem, there is a possible improper input… | Details |
| CVE-2026-69092 | 2026-08-03 13:20:45 | 2026-08-03 14:23:30 | VulnCheck | Admidio versions before 5.0.11 contain a reflected cross-site… | Details |
| CVE-2026-21551 | 2026-08-03 07:18:23 | 2026-08-03 14:20:56 | Unisoc | In modem, there is a possible improper input… | Details |
| CVE-2026-21552 | 2026-08-03 07:18:26 | 2026-08-03 14:20:00 | Unisoc | In modem, there is a possible improper input… | Details |
| CVE-2026-21553 | 2026-08-03 07:18:27 | 2026-08-03 14:19:08 | Unisoc | In modem, there is a possible improper input… | Details |
| CVE-2026-68585 | 2026-08-03 13:20:37 | 2026-08-03 14:17:52 | VulnCheck | SiYuan versions before v3.7.3 contain a metadata disclosure… | Details |
| CVE-2026-69085 | 2026-08-03 13:20:40 | 2026-08-03 14:15:43 | VulnCheck | SiYuan before v3.7.3 contains a SQL injection vulnerability… | Details |
| CVE-2026-69090 | 2026-08-03 13:20:44 | 2026-08-03 14:10:15 | VulnCheck | Admidio before 5.0.11 fails to validate target organization… | Details |
| CVE-2026-69095 | 2026-08-03 13:20:47 | 2026-08-03 14:09:30 | VulnCheck | OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path… | Details |
| CVE-2026-59644 | 2026-08-03 00:50:50 | 2026-08-03 13:36:10 | bcorg | In Bouncy Castle for Java before 1.85, MLS… | Details |
| CVE-2026-59645 | 2026-08-03 00:49:41 | 2026-08-03 13:35:36 | bcorg | In Bouncy Castle for Java before 1.85, OER… | Details |
| CVE-2026-59647 | 2026-08-03 00:46:57 | 2026-08-03 13:34:57 | bcorg | In Bouncy Castle for Java before 1.85, CRMF/CMP… | Details |
| CVE-2026-59648 | 2026-08-03 00:45:34 | 2026-08-03 13:34:16 | bcorg | In Bouncy Castle for Java before 1.85, OpenPGP… | Details |
| CVE-2026-59649 | 2026-08-03 00:44:24 | 2026-08-03 13:33:33 | bcorg | In Bouncy Castle for Java before 1.85, OpenPGP… | Details |
| CVE-2026-59650 | 2026-08-03 00:42:46 | 2026-08-03 13:32:53 | bcorg | In Bouncy Castle for Java before 1.85, MTI/A0… | Details |
| CVE-2026-59651 | 2026-08-03 00:41:23 | 2026-08-03 13:31:42 | bcorg | In Bouncy Castle for Java before 1.85, BKS… | Details |
| CVE-2026-59652 | 2026-08-03 00:39:23 | 2026-08-03 13:30:51 | bcorg | In Bouncy Castle for Java before 1.85, LDAP… | Details |
| CVE-2026-8763 | 2026-08-03 00:36:05 | 2026-08-03 13:29:24 | bcorg | In Bouncy Castle for Java before 1.85, Name… | Details |
| CVE-2026-15055 | 2026-08-03 00:32:51 | 2026-08-03 13:28:42 | bcorg | In Bouncy Castle for Java before 1.85, PKCS#8… | Details |
| CVE-2026-59643 | 2026-08-03 00:51:55 | 2026-08-03 13:28:03 | bcorg | In Bouncy Castle for Java before 1.85, OpenPGP… | Details |
| CVE-2026-59642 | 2026-08-03 00:53:28 | 2026-08-03 13:27:19 | bcorg | In Bouncy Castle for Java before 1.85, CMS… | Details |
| CVE-2026-59641 | 2026-08-03 00:54:21 | 2026-08-03 13:26:05 | bcorg | In Bouncy Castle for Java before 1.85, S/MIME… | Details |
| CVE-2026-59640 | 2026-08-03 00:55:19 | 2026-08-03 13:25:07 | bcorg | In Bouncy Castle for Java before 1.85, OpenPGP… | Details |
| CVE-2026-59639 | 2026-08-03 00:56:24 | 2026-08-03 13:24:16 | bcorg | In Bouncy Castle for Java before 1.85, CMS… | Details |
| CVE-2026-59638 | 2026-08-03 00:57:31 | 2026-08-03 13:23:06 | bcorg | In Bouncy Castle for Java before 1.85, JSSE… | Details |
| CVE-2026-18585 | 2026-08-03 05:15:07 | 2026-08-03 13:21:10 | VulDB | A vulnerability was detected in GL.iNet MT3000, MT6000,… | Details |
| CVE-2026-18591 | 2026-08-03 07:15:08 | 2026-08-03 13:19:02 | VulDB | A vulnerability was identified in Meesho Online Shopping… | Details |
| CVE-2026-56608 | 2026-08-03 11:25:35 | 2026-08-03 13:18:24 | HCL | HCL iControl is affected by Missing Access Control… | Details |
| CVE-2026-56609 | 2026-08-03 11:26:07 | 2026-08-03 13:17:58 | HCL | HCL iControl is affected by Weak SSL/TLS Version… | Details |
| CVE-2026-2346 | 2026-08-03 11:49:45 | 2026-08-03 13:17:35 | TR-CERT | Authorization bypass through User-Controlled key vulnerability in Menulux… | Details |
| CVE-2026-21554 | 2026-08-03 07:18:29 | 2026-08-03 11:25:46 | Unisoc | In modem, there is a possible improper input… | Details |
| CVE-2026-21555 | 2026-08-03 07:18:31 | 2026-08-03 11:25:18 | Unisoc | In modem, there is a possible improper input… | Details |
| CVE-2026-60011 | 2026-08-03 07:56:05 | 2026-08-03 11:16:54 | jpcert | Sharp and Toshiba Tec MFPs (multifunction printers) fail… | Details |
| CVE-2026-63545 | 2026-08-03 07:57:09 | 2026-08-03 11:12:38 | jpcert | Sharp and Toshiba Tec MFPs (multifunction printers) caches… | Details |
| CVE-2026-63563 | 2026-08-03 07:57:50 | 2026-08-03 11:11:35 | jpcert | Sharp and Toshiba Tec MFPs (multifunction printers) for… | Details |
| CVE-2026-62416 | 2026-08-03 07:58:56 | 2026-08-03 11:09:46 | jpcert | Network Scanner Tool and Network Scanner Tool Lite… | Details |
| CVE-2026-69075 | 2026-08-03 08:46:59 | 2026-08-03 11:00:05 | CIRCL | FlowIntel is affected by a stored cross-site scripting… | Details |
| CVE-2026-69078 | 2026-08-03 09:14:04 | 2026-08-03 10:56:06 | CIRCL | CTI-Transmute is affected by a server-side request forgery… | Details |
| CVE-2026-69079 | 2026-08-03 09:22:55 | 2026-08-03 10:52:28 | CIRCL | CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the… | Details |
| CVE-2026-33591 | 2026-08-03 09:35:40 | 2026-08-03 10:51:35 | ENISA | A vulnerability in Wapt Server before version 2.6.1.17813… | Details |
| CVE-2026-69082 | 2026-08-03 09:43:14 | 2026-08-03 10:45:04 | CIRCL | CTI-Transmute contained a cross-site request forgery vulnerability in… | Details |
| CVE-2026-18593 | 2026-08-03 07:45:09 | 2026-08-03 10:20:37 | VulDB | A weakness has been identified in vxcontrol PentAGI… | Details |