Edition of August 13, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-73608 | 9.2 | 15.5 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget |
| CVE-2026-17649 | 5.3 | 15.4 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-28148 | 9.8 | 15.2 | miniOrange | Headless Single Sign On | CWE-347 | WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulner… |
| CVE-2026-59763 | 4.3 | 15.1 | Gitea | Gitea Open Source Git Server | CWE-284 | Unbounded Arch package file metadata can cause resource amplification in Gite… |
| CVE-2026-66697 | 7.1 | 14.9 | Colissimo | Colissimo Officiel : Méthodes de livraison pour WooCommerce | CWE-79 | WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin … |
| CVE-2026-58507 | 5.3 | 14.9 | Gitea | Gitea Open Source Git Server | CWE-284 | Private Repository Existence Disclosure via go-get Meta Endpoint |
| CVE-2026-73840 | 5.3 | 14.9 | openchoreo | openchoreo | CWE-287 | OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion… |
| CVE-2026-14298 | 6.5 | 14.6 | Mattermost | Mattermost | CWE-409 | Denial of service via resource exhaustion in Mattermost |
| CVE-2026-72632 | 7.1 | 14.5 | Elastic | Kibana | CWE-203 | Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent… |
| CVE-2026-55986 | 5.4 | 14.5 | Gitea | Gitea Open Source Git Server | CWE-284 | Email Management API Bypasses ManageCredentials Feature Restrictions |
| CVE-2026-73651 | 5.7 | 14.4 | typeorm | typeorm | CWE-94 | TypeORM: migration:generate template-literal code injection |
| CVE-2026-18164 | 7.2 | 13.9 | Flow Neuroscience | FL-100 | CWE-798 | Flow Neuroscience FL-100 Use of Hard-coded Credentials |
| CVE-2026-23603 | 3.1 | 13.9 | Gitea | Gitea Open Source Git Server | CWE-918 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim |
| CVE-2026-55400 | 6.0 | 13.8 | Absolute Security | Secure Access | CWE-190 | CVE-2026-55400 is an integer underflow in Secure Access servers prior to vers… |
| CVE-2026-73353 | 5.3 | 13.7 | revolutbusiness | Revolut Gateway for WooCommerce | CWE-862 | WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Co… |
| CVE-2026-19292 | 8.8 | 13.6 | silabs.com | WiseConnect | CWE-305 | Bluetooth re-pairing with legitimate device can use lower security level |
| CVE-2026-73619 | 7.1 | 13.7 | gitpython-developers | GitPython | CWE-73 | GitPython before 3.1.57 Arbitrary File Read via Repo.archive() |
| CVE-2026-28173 | 7.1 | 13.5 | Arraytics | WP Event SOlution | CWE-862 | WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vul… |
| CVE-2026-58511 | 2.7 | 13.5 | Gitea | Gitea Open Source Git Server | CWE-200 | Webhook Authorization Header Returned in Plaintext via API |
| CVE-2026-73039 | 5.3 | 13.1 | streamaserver | streama | CWE-639 | streama Insecure Direct Object Reference via ViewingStatusController |
| CVE-2026-73671 | 5.1 | 13.2 | Saurus | Saurus CMS Community Edition | CWE-601 | Saurus CMS Unauthenticated Open Redirect via logout url parameter |
| CVE-2026-17074 | 3.1 | 13.1 | IBM | i | CWE-269 | IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
| CVE-2026-72669 | 7.6 | 13.1 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Cross-User Information Disclosure … |
| CVE-2026-58444 | 4.3 | 13.0 | Gitea | Gitea Open Source Git Server | CWE-863 | Personal access token scope enforcement bypass on the repository home page (`… |
| CVE-2026-28188 | 7.3 | 12.6 | themefic | Hydra Booking | CWE-862 | WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability |
| CVE-2026-72655 | 4.3 | 12.5 | Elastic | Kibana | CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attribute… |
| CVE-2026-72675 | 7.1 | 12.1 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Machine Learning Leading to Cross-Space Infor… |
| CVE-2026-18068 | 4.3 | 12.1 | IBM | i | CWE-200 | IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
| CVE-2026-21832 | 4.3 | 12.1 | HCL Software | AION | CWE-1427 | HCL AION is affected by multiple security vulnerabilities. |
| CVE-2026-73349 | 5.3 | 12.0 | Nexcess | GiveWP | CWE-862 | WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability |
| CVE-2026-73401 | 5.3 | 12.0 | InstaWP | InstaWP Connect | CWE-862 | WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerabi… |
| CVE-2026-73403 | 5.3 | 12.0 | wpeverest | User Registration | CWE-862 | WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerabi… |
| CVE-2026-58445 | 2.7 | 12.0 | Gitea | Gitea Open Source Git Server | CWE-203 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API |
| CVE-2026-72631 | 6.5 | 11.8 | Elastic | Kibana | CWE-269 | Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic … |
| CVE-2026-72680 | 6.5 | 11.8 | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Lead… |
| CVE-2026-16101 | 8.8 | 11.6 | silabs.com | WiseConnect | CWE-290 | forced re-pairing with already bonded device |
| CVE-2026-19291 | 8.8 | 11.7 | silabs.com | WiseConnect | CWE-290 | Bluetooth re-pairing can use a lower security level than previous |
| CVE-2026-72630 | 7.1 | 11.6 | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation |
| CVE-2026-28182 | 6.5 | 11.7 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-79 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Cross Site Scripting… |
| CVE-2026-66456 | 6.5 | 11.7 | bestwebsoft | Profile Extra Fields by BestWebSoft | CWE-79 | WordPress Profile Extra Fields by BestWebSoft plugin <= 1.3.4 - Cross Site Sc… |
| CVE-2026-66460 | 6.5 | 11.7 | AfterShip & Automizely | AfterShip Tracking | CWE-79 | WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vu… |
| CVE-2026-66467 | 6.5 | 11.7 | WPManageNinja | FluentCommunity | CWE-79 | WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-66471 | 6.5 | 11.7 | Themepoints | Accordion | CWE-79 | WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-18671 | 5.3 | 11.7 | IBM | i | CWE-190 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-54481 | 7.5 | 11.3 | Gitea | Gitea Open Source Git Server | CWE-295 | Internal API HTTP client hardcodes InsecureSkipVerify:true with no config ove… |
| CVE-2026-72673 | 5.4 | 11.4 | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthet… |
| CVE-2026-49856 | 4.3 | 11.3 | vmoranv | jshookmcp | CWE-918 | @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authoriz… |
| CVE-2026-73652 | 7.1 | 11.1 | vantage6 | vantage6 | CWE-863 | vantage6: Algorithm developer can edit another developer's algorithm that is … |
| CVE-2026-73669 | 6.9 | 10.9 | Signify | Philips Hue Bridge Pro | CWE-306 | Signify Philips Hue Bridge Pro MQTT broker missing authentication |
| CVE-2026-73531 | 5.3 | 10.8 | django-helpdesk | django-helpdesk | CWE-79 | django-helpdesk < 2.3.3 Stored XSS via HTML Attachments |
| CVE-2026-14666 | 4.2 | 10.8 | n/a | PostgreSQL | CWE-1250 | PostgreSQL row security caching disregards role modifications |
| CVE-2026-73617 | 7.1 | 10.5 | budibase | server | CWE-943 | Budibase before 3.40.0 NoSQL Injection via MongoDB datasource |
| CVE-2026-73610 | 6.9 | 10.3 | siyuan-note | siyuan | CWE-639 | SiYuan before v3.7.4 Information Disclosure via Local Storage |
| CVE-2026-73563 | 4.7 | 10.4 | backstage | backstage | CWE-601 | Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlis… |
| CVE-2026-73574 | 3.1 | 10.4 | Zimbra | Collaboration | CWE-669 | In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerab… |
| CVE-2026-13328 | 5.3 | 10.0 | Unknown | Food Menu | CWE-284 | TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification |
| CVE-2026-73621 | 5.3 | 10.1 | gitpython-developers | GitPython | CWE-88 | GitPython before 3.1.56 Arbitrary File Truncation via Commit.count |
| CVE-2026-28185 | 9.8 | 10.0 | rtCamp | Log in with Google | CWE-345 | WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerab… |
| CVE-2026-18728 | 6.5 | 10.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-191 | Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing |
| CVE-2026-66455 | 6.0 | 9.7 | rockiger | ReactPress | CWE-862 | WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability |
| CVE-2026-66654 | 6.0 | 9.7 | TangibleWP | Vehica Core | CWE-918 | WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) … |
| CVE-2026-16455 | 6.9 | 9.7 | Teltonika Networks | RUTOS | CWE-93 | Local privilege escalation via improper input sanitization in execl() call |
| CVE-2026-66704 | 7.2 | 9.4 | Jegstudio | Gutenverse Companion | CWE-918 | WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery … |
| CVE-2026-73605 | 6.9 | 9.5 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.4 Path Traversal via getUniqueFilename |
| CVE-2026-73606 | 6.9 | 9.5 | siyuan-note | siyuan | CWE-639 | SiYuan before v3.7.4 Information Disclosure via getRefIDs |
| CVE-2026-73607 | 6.9 | 9.5 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.4 Information Disclosure via getOutlineStorage |
| CVE-2026-73609 | 6.9 | 9.5 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.4 Information Disclosure via getBookmarkLabels |
| CVE-2026-66464 | 6.5 | 9.4 | Toast Plugins | Internal Link Optimiser | CWE-862 | WordPress Internal Link Optimiser plugin <= 5.2.7 - Broken Access Control vul… |
| CVE-2026-73038 | 5.3 | 9.4 | NodeBB | NodeBB | CWE-79 | NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name |
| CVE-2026-18945 | 8.2 | 9.3 | Unknown | WP Helper Premium | CWE-639 | WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order M… |
| CVE-2026-58437 | 7.1 | 9.3 | Gitea | Gitea Open Source Git Server | CWE-284 | Repository Visibility Manipulation via Git Push Options |
| CVE-2026-0299 | 5.9 | 9.3 | Palo Alto Networks | GlobalProtect App | CWE-426 | GlobalProtect App: Local Privilege Escalation Vulnerabilities |
| CVE-2026-58431 | 4.3 | 9.3 | Gitea | Gitea Open Source Git Server | CWE-863 | Public-only API token restriction is not enforced on team API routes |
| CVE-2026-58510 | 4.3 | 9.3 | Gitea | Gitea Open Source Git Server | CWE-200 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — s… |
| CVE-2026-67986 | 8.4 | 9.2 | n/a | n/a | CWE-94 | amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c523… |
| CVE-2026-70454 | 7.6 | 8.9 | RsyncProject | rsync | CWE-295 | rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode |
| CVE-2026-72741 | 8.6 | 8.8 | goodrain | rainbond | CWE-639 | Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access |
| CVE-2026-73629 | 8.4 | 8.8 | s9y | Serendipity | CWE-918 | Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses |
| CVE-2026-66689 | 6.3 | 8.9 | AcyMailing Newsletter Team | Anti Spam and list cleaner – AcyChecker | CWE-862 | WordPress Anti Spam and list cleaner – AcyChecker plugin <= 2.0.0 - Broken Ac… |
| CVE-2026-73576 | 6.3 | 8.8 | Zimbra | Collaboration | CWE-1241 | In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generati… |
| CVE-2026-0298 | 5.2 | 8.7 | Palo Alto Networks | GlobalProtect App | CWE-94 | GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access P… |
| CVE-2026-28154 | 7.1 | 8.6 | snstheme | Samex - Clean, Minimal Shop WooCommerce WordPress Theme | CWE-79 | WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (… |
| CVE-2026-72671 | 4.3 | 8.4 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Modification of Machi… |
| CVE-2026-73616 | 7.1 | 8.0 | openremote | openremote | CWE-639 | OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference |
| CVE-2026-73626 | 0.0 | 8.0 | jupyterlab | jupyterlab | CWE-284 | JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager |
| CVE-2026-73842 | 9.0 | 7.8 | openchoreo | openchoreo | CWE-269 | OpenChoreo: cluster-gateway internal proxy performs no caller authentication … |
| CVE-2026-27536 | 7.1 | 7.8 | PluginOps | MailChimp Subscribe Forms | CWE-79 | WordPress MailChimp Subscribe Forms plugin <= 4.3.3 - Cross Site Scripting (X… |
| CVE-2026-27539 | 7.1 | 7.8 | Welcart | Welcart e-Commerce | CWE-79 | WordPress Welcart e-Commerce plugin <= 2.11.31 - Cross Site Scripting (XSS) v… |
| CVE-2026-28003 | 7.1 | 7.8 | yonifre | Maspik – Spam blacklist | CWE-79 | WordPress Maspik – Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS… |
| CVE-2026-28004 | 7.1 | 7.8 | Strategy11 Team | Business Directory | CWE-79 | WordPress Business Directory plugin <= 6.4.25 - Cross Site Scripting (XSS) vu… |
| CVE-2026-28158 | 7.1 | 7.8 | Lasso Analytics, Inc. | Do Lasso | CWE-79 | WordPress Do Lasso plugin <= 358 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-28170 | 7.1 | 7.8 | 1meril | Blog Floating Button | CWE-79 | WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) … |
| CVE-2026-28175 | 7.1 | 7.8 | wp-buy | Visitors Traffic Real Time Statistics | CWE-79 | WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site S… |
| CVE-2026-28187 | 7.1 | 7.8 | echoplugins | Knowledge Base for Documentation, FAQs with AI Assistance | CWE-79 | WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <=… |
| CVE-2026-61960 | 7.1 | 7.8 | Themeisle | WP Full Stripe Free | CWE-79 | WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vu… |
| CVE-2026-61965 | 7.1 | 7.8 | ahmadgb | GeekyBot | CWE-79 | WordPress GeekyBot plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-61974 | 7.1 | 7.8 | Kitae Park | Mang Board WP | CWE-79 | WordPress Mang Board WP plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-65580 | 7.1 | 7.8 | bracketweb | Agrion | CWE-79 | WordPress Agrion theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulner… |
| CVE-2026-66426 | 7.1 | 7.8 | Lester Chan | WP-Stats | CWE-79 | WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66429 | 7.1 | 7.8 | CODEPRESS | Visitor Traffic Real Time Statistics Pro | CWE-79 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - Cross Si… |
| CVE-2026-66449 | 7.1 | 7.8 | Dylan Kuhn | Geo Mashup | CWE-79 | WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-66468 | 7.1 | 7.8 | powerfulwp | Local Delivery Drivers for WooCommerce | CWE-79 | WordPress Local Delivery Drivers for WooCommerce plugin <= 3.0.0 - Cross Site… |
| CVE-2026-66655 | 7.1 | 7.8 | multiparcels | MultiParcels Shipping For WooCommerce | CWE-79 | WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected… |
| CVE-2026-66698 | 7.1 | 7.8 | Brainstorm Force | SureDash | CWE-79 | WordPress SureDash plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66700 | 7.1 | 7.8 | ZAYTECH | Smart Online Order for Clover | CWE-79 | WordPress Smart Online Order for Clover plugin <= 1.6.1 - Cross Site Scriptin… |
| CVE-2026-65935 | 7.6 | 7.8 | silabs.com | WiseConnect | CWE-305 | Bypassing passkey entry in legacy pairing |
| CVE-2026-65932 | 5.3 | 7.7 | silabs.com | BT122 | CWE-440 | BT122 stops advertising |
| CVE-2026-65933 | 5.3 | 7.7 | silabs.com | BT122 | CWE-126 | BT122 malformed packet with increased length field causes memory leak |
| CVE-2026-65936 | 5.3 | 7.7 | silabs.com | WiseConnect | CWE-126 | RS9116W/SiWx917 malformed packet with increased length field causes memory leak |
| CVE-2026-72506 | 5.1 | 7.5 | National Institute of Information and Communications Technology | "VoiceTra(Voice Translator)" for Android | CWE-941 | VoiceTra provided by National Institute of Information and Communications Tec… |
| CVE-2026-53784 | 8.4 | 7.3 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Path Traversal via Symlink Module Root |
| CVE-2026-18511 | 7.8 | 7.2 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
| CVE-2026-18368 | 6.0 | 7.2 | Teltonika Networks | RUTOS | CWE-122 | Heap buffer overflow in Modbusgwd |
| CVE-2026-19135 | 5.4 | 7.0 | The OpenNMS Group | Meridian | CWE-470 | OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load… |
| CVE-2026-73344 | 5.9 | 6.9 | Passionate Programmer Peter | WP Data Access | CWE-79 | WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-58435 | 5.4 | 6.9 | Gitea | Gitea Open Source Git Server | CWE-266 | Gitea LFS Deploy-Key Privilege Escalation |
| CVE-2026-73428 | 4.6 | 6.9 | basecamp | trix | CWE-79 | Trix: Stored XSS via HTMLParser attribute injection on paste |
| CVE-2026-14332 | 5.4 | 6.7 | Unknown | Ecwid by Lightspeed Ecommerce Shopping Cart | CWE-862 | Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disco… |
| CVE-2026-73571 | 3.1 | 6.3 | Zimbra | Collaboration | CWE-863 | An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) be… |
| CVE-2026-56657 | 6.2 | 6.2 | Gitea | Gitea Open Source Git Server | CWE-284 | Gitea SSH Key Parser Denial of Service |
| CVE-2026-18509 | 7.1 | 6.1 | IBM | i | CWE-285 | IBM i is Affected By A Prvilege Escalation Vulnerability [] |
| CVE-2026-0297 | 5.2 | 6.1 | Palo Alto Networks | GlobalProtect App | CWE-787 | GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake |
| CVE-2026-17069 | 7.3 | 6.0 | IBM | i | CWE-352 | IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
| CVE-2026-14213 | 3.7 | 5.9 | Unknown | Booking for Appointments and Events Calendar | CWE-639 | Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR |
| CVE-2026-27537 | 6.5 | 5.8 | supsystic | Popup by Supsystic | CWE-79 | WordPress Popup by Supsystic plugin <= 1.11.2 - Cross Site Scripting (XSS) vu… |
| CVE-2026-66687 | 6.5 | 5.7 | magepeopleteam | WpBookingly | CWE-79 | WordPress WpBookingly plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73340 | 6.5 | 5.7 | fifu.app | Featured Image from URL | CWE-79 | WordPress Featured Image from URL plugin <= 5.3.3 - Cross Site Scripting (XSS… |
| CVE-2026-73357 | 6.5 | 5.7 | Nexcess | GiveWP | CWE-79 | WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73266 | 7.1 | 5.7 | Red Hat | Multicluster Engine for Kubernetes | CWE-441 | Clusterclaims-controller: clusterclaims-controller: tenant-controlled cluster… |
| CVE-2026-12036 | 6.9 | 5.7 | Lenovo | Vantage | CWE-59 | An improper link following vulnerability was reported in the VantageCoreAddin… |
| CVE-2026-73657 | 4.2 | 5.7 | triggerdotdev | trigger.dev | CWE-22 | Trigger.dev: Cross-tenant payload poisoning via packet write + replay |
| CVE-2026-0289 | 0.5 | 5.5 | Palo Alto Networks | Prisma Browser | CWE-522 | Prisma Browser: Inappropriate Implementation in Account Protection |
| CVE-2026-15994 | 7.3 | 5.3 | Lenovo | Commercial Vantage | CWE-59 | During an internal security assessment, an improper link following vulnerabil… |
| CVE-2026-73572 | 6.1 | 5.1 | Zimbra | Collaboration | CWE-79 | In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (… |
| CVE-2026-73628 | 5.3 | 5.1 | s9y | Serendipity | CWE-79 | Serendipity 2.3.5 Reflected XSS via search clean-URL route |
| CVE-2026-73037 | 5.1 | 5.1 | DayuanJiang | next-ai-draw-io | CWE-79 | Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter |
| CVE-2026-73505 | 7.8 | 5.0 | JanDeDobbeleer | oh-my-posh | CWE-94 | Oh My Posh: Arbitrary command execution via template injection in the path se… |
| CVE-2026-19182 | 4.3 | 4.9 | The OpenNMS Group | Meridian | CWE-863 | OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users a… |
| CVE-2026-63423 | 8.5 | 4.7 | Lenovo | Accessories and Display Manager | CWE-321 | During an internal security assessment, a potential vulnerability was discove… |
| CVE-2026-73481 | 5.3 | 4.7 | phplist | phplist3 | CWE-352 | phpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules |
| CVE-2026-18741 | 4.6 | 4.5 | Froiden | Worksuite SaaS | CWE-79 | Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Locati… |
| CVE-2026-0292 | 2.1 | 4.2 | Palo Alto Networks | Prisma Access Agent | CWE-290 | Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows |
| CVE-2025-62315 | 3.4 | 4.1 | HCL Software | AION | CWE-116 | HCL AION is affected by multiple security vulnerabilities. |
| CVE-2026-0290 | 0.5 | 4.0 | Palo Alto Networks | Prisma Browser | CWE-522 | Prisma Browser: Sensitive Information Disclosure Vulnerability |
| CVE-2026-67990 | 5.4 | 3.8 | n/a | n/a | CWE-352 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables … |
| CVE-2026-53802 | 8.4 | 3.6 | RsyncProject | rsync | CWE-61 | rsync < 3.5.0 Arbitrary File Read via Symlink Following |
| CVE-2026-53785 | 6.9 | 3.6 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Path Traversal Write Escape via --relative Mode |
| CVE-2026-19293 | 8.8 | 3.4 | silabs.com | WiseConnect | CWE-521 | SMP security request |
| CVE-2026-53803 | 8.5 | 3.3 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Symlink Following Arbitrary File Overwrite |
| CVE-2026-6387 | 7.3 | 3.3 | Lenovo | System Update | CWE-290 | A potential authentication bypass vulnerability was reported in Lenovo System… |
| CVE-2026-72658 | 7.3 | 3.3 | Elastic | Kibana | CWE-352 | Cross-Site Request Forgery in Kibana Leading to Privilege Escalation |
| CVE-2026-68451 | 7.8 | 3.2 | Linux | Linux | — | s390/zcrypt: Validate length for CCA ECC private key requests |
| CVE-2026-63426 | 6.9 | 3.0 | Lenovo | Dock Manager | CWE-59 | During an internal security assessment, a potential vulnerability was discove… |
| CVE-2026-56755 | 6.2 | 3.1 | Gitea | Gitea Open Source Git Server | CWE-284 | Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation i… |
| CVE-2026-68454 | 8.8 | 3.0 | Linux | Linux | — | KVM: s390: pci: Fix handling of AIF enable without AISB |
| CVE-2026-68452 | 7.8 | 2.9 | Linux | Linux | — | s390/zcrypt: Validate length for CCA AES cipher key requests |
| CVE-2026-73506 | 6.1 | 3.0 | JanDeDobbeleer | oh-my-posh | CWE-150 | Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment… |
| CVE-2026-68453 | 7.1 | 2.8 | Linux | Linux | — | s390/zcrypt: Fix buffer over-read in cca_cipher2protkey |
| CVE-2026-72849 | 8.7 | 2.6 | budibase | server | CWE-352 | Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF |
| CVE-2026-17029 | 8.8 | 2.3 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
| CVE-2026-18622 | 4.7 | 2.4 | Foxit Software Inc. | Foxit PDF Editor | CWE-451 | Foxit PDF Editor/Reader's signature-validation pop-up reports modified certif… |
| CVE-2026-0294 | 6.0 | 2.3 | Palo Alto Networks | Prisma Access Agent | CWE-427 | Prisma Access Agent: Local Privilege Escalation |
| CVE-2026-0291 | 1.1 | 2.2 | Palo Alto Networks | Prisma Access Agent | CWE-59 | Prisma Access Agent: Authenticated Limited File Deletion on Linux |
| CVE-2026-11970 | 4.8 | 2.1 | Forcepoint | F1E mac | CWE-754 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint… |
| CVE-2026-73480 | 4.8 | 2.1 | dundee | gdu | CWE-116 | gdu Terminal Injection via Unstripped Escape Sequences |
| CVE-2026-73479 | 4.8 | 2.0 | Byron | dua-cli | CWE-116 | dua-cli Terminal Escape Sequence Injection via Marked Paths |
| CVE-2026-58441 | 6.3 | 1.9 | Gitea | Gitea Open Source Git Server | CWE-918 | SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL |
| CVE-2026-14875 | 7.8 | 1.8 | IBM | i Access Client Solutions | CWE-426 | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-14663 | 6.5 | 1.7 | n/a | PostgreSQL | CWE-313 | PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and d… |
| CVE-2026-0293 | 5.6 | 1.6 | Palo Alto Networks | Prisma Access Agent | CWE-693 | Prisma Access Agent: Anti-Tamper Protection Bypass on Windows |
| CVE-2026-16898 | 7.8 | 1.6 | IBM | i | CWE-73 | IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service |
| CVE-2026-16987 | 7.8 | 1.6 | IBM | i | CWE-73 | IBM i is Affected By An Improper Validation Vulnerability in PASE [] |
| CVE-2026-13365 | 6.5 | 1.6 | IBM | Planning Analytics | CWE-352 | IBM Planning Analytics Local is affected by security vulnerabilities |
| CVE-2026-73575 | 3.1 | 1.6 | Zimbra | Collaboration | CWE-352 | In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (C… |
| CVE-2026-63425 | 8.5 | 1.4 | Lenovo | Dock Manager | CWE-276 | During an internal security assessment, a potential improper permissions vuln… |
| CVE-2026-19483 | 5.5 | 1.4 | IBM | Storage Scale | CWE-532 | The following vulnerabilities that can affect IBM Storage Scale and the Manag… |
| CVE-2026-56865 | 8.4 | 1.3 | Go toolchain | cmd/go | CWE-347 | Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog |
| CVE-2026-19696 | 6.6 | 1.3 | Wireshark Foundation | Wireshark | CWE-787 | Out-of-bounds Write in Wireshark |
| CVE-2026-19730 | 4.2 | 1.3 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-459 | Podman: podman: quadlet install --replace non-truncating write retains remove… |
| CVE-2026-65934 | 7.1 | 1.2 | silabs.com | BT122 | CWE-440 | BT122 plaintext pause encryption request causes DOS |
| CVE-2026-73585 | 6.3 | 1.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-377 | Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider… |
| CVE-2025-62314 | 5.6 | 1.1 | HCL Software | AION | CWE-307 | HCL AION is affected by multiple security vulnerabilities. |
| CVE-2026-12236 | 6.5 | 1.1 | zephyrproject | zephyr | CWE-835 | Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type response… |
| CVE-2026-18101 | 8.8 | 1.0 | IBM | i | CWE-269 | IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server… |
| CVE-2026-19088 | 5.4 | 0.9 | Unknown | ShopEngine Elementor WooCommerce Builder Addon | CWE-352 | ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication |
| CVE-2026-19694 | 4.7 | 0.9 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-19695 | 4.7 | 0.9 | Wireshark Foundation | Wireshark | CWE-121 | Stack-based Buffer Overflow in Wireshark |
| CVE-2026-63424 | 7.0 | 0.8 | Lenovo | Dock Manager | CWE-261 | During an internal security assessment, an improperly protected key was disco… |
| CVE-2026-73583 | 6.6 | 0.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows … |
| CVE-2026-53796 | 5.8 | 0.7 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling |
| CVE-2026-18071 | 7.8 | 0.7 | IBM | i | CWE-269 | IBM i is Affected By An Improper Management Vulnerability in HTTP Server [] |
| CVE-2026-0296 | 4.5 | 0.6 | Palo Alto Networks | GlobalProtect App | CWE-295 | GlobalProtect App: Improper Certificate Validation Bypass Vulnerability |
| CVE-2026-53797 | 5.7 | 0.6 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Symlink Race Condition Information Disclosure |
| CVE-2026-53800 | 5.7 | 0.6 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Symlink Race Condition via --remove-source-files |
| CVE-2026-53799 | 7.2 | 0.6 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application |
| CVE-2026-73584 | 6.3 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-377 | Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via … |
| CVE-2026-17438 | 4.4 | 0.6 | IBM | i | CWE-269 | IBM i is Affected By An Improper Privilege Management Vulnerability in LDAP [] |
| CVE-2026-14256 | 5.7 | 0.5 | Lenovo | E16 Gen 2 (Type 21M5, 21M6) Laptops (ThinkPad) ELAN TrackPoint Device Driver for Windows 11 (Version 23H2 or later) - ThinkPad | CWE-125 | ELAN reported a potential out-of-bounds write vulnerability in the ELAN Track… |
| CVE-2026-18086 | 4.5 | 0.4 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension |
| CVE-2025-52640 | 4.7 | 0.4 | HCL Software | AION | CWE-276 | HCL AION is affected by multiple security vulnerabilities. |
| CVE-2025-62318 | 3.7 | 0.3 | HCL Software | AION | CWE-352 | HCL AION is affected by multiple security vulnerabilities. |
| CVE-2026-0295 | 4.1 | 0.3 | Palo Alto Networks | GlobalProtect App | CWE-362 | GlobalProtect App: Local Privilege Escalation via Race Condition on macOS |
| CVE-2026-14681 | 4.2 | 0.2 | n/a | PostgreSQL | CWE-924 | PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL |
| CVE-2026-16896 | 4.7 | 0.1 | IBM | i | CWE-367 | IBM i is Affected By Multiple Vulnerabilities in Network Authentication Service |
| CVE-2026-16458 | 5.9 | 0.0 | Oberon microsystems AG | ocrypto | CWE-208 | Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto |
| CVE-2026-16459 | 5.9 | 0.0 | Oberon microsystems AG | Oberon PSA Crypto | CWE-208 | Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto |