--===============2652101280670941624==
Content-Type: multipart/alternative; boundary="===============2360347132490274785=="
MIME-Version: 1.0
--===============2360347132490274785==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Cybersecurity and Infrastructure Security Agency (CISA)
You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrast= ructure Security Agency. This information has recently been updated and is = now available.
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities t= hat have been recorded in the past week. In some cases, the vulnerabilities=
in the bulletin may not yet have assigned CVSS scores.
Vulnerabilities are based on the=C2=A0Common Vulnerabilities and Exposures =
[
https://www.cve.org/ ]=C2=A0(CVE) vulnerability naming standard and are o= rganized according to severity, determined by the=C2=A0Common Vulnerability=
Scoring System [
https://www.cve.org/about/relatedefforts ]=C2=A0(CVSS) st= andard. The division of high, medium, and low severities correspond to the = following scores:
* *High*: vulnerabilities with a CVSS base score of 7.0=E2=80=9310.0=20
* *Medium*: vulnerabilities with a CVSS base score of 4.0=E2=80=936.9=20
* *Low*: vulnerabilities with a CVSS base score of 0.0=E2=80=933.9=20
Entries may include additional information provided by organizations and ef= forts sponsored by CISA. This information may include identifying informati= on, values, definitions, and related links. Patch information is provided w= hen available. Please note that some of the information in the bulletin is = compiled from external, open-source reports and is not a direct result of C= ISA analysis.
=C2=A0
Vulnerability Summary for the Week of July 6, 2026 [
https://www.cisa.gov/n= ews-events/bulletins/sb26-194 ] 07/13/2026 12:15 PM EDT=20
High Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info 1Panel-dev--= MaxKB MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-= lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and = MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/= base_chat_step.py do not consistently validate MCP transport type, allowing=
an authenticated user to import a .tool file containing stdio transport wi=
th malicious commands and trigger the configuration through an AI Chat node=
so MultiServerMCPClient executes arbitrary system commands. This issue is = fixed in version 2.10.0-lts. 2026-07-10 8.8 CVE-2026-54149 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-54149 ] 389ds--389-ds-base A heap buffer over= flow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-b= ase). After a successful SASL bind with integrity protection (SSF > 0), an = authenticated attacker can send a specially crafted oversized LDAP UNBIND p= acket that is copied into a 512-byte heap receive buffer without a bounds c= heck in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 mega= bytes of attacker-controlled data to overflow the buffer, causing a denial =
of service (server crash). In FreeIPA and Red Hat Identity Management deplo= yments, any domain user with a valid Kerberos ticket, any enrolled host, or=
any service account can trigger this vulnerability over the network after = authenticating via GSSAPI. The vulnerable code path has existed since appro= ximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-149=
05 fix, which patched a separate heap overflow in schema.c only. 2026-07-07=
8.8 CVE-2026-11610 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11610 ] a= ctualbudget--actual Actual is a local-first personal finance app. Prior to = 26.6.0, in OpenID multi-user mode, disabling a user only blocks future Open=
ID login for that identity, while existing Actual session tokens for the di= sabled user remain valid. The shared session validation path accepts any ex= isting token row that has not expired without checking whether the associat=
ed user is still enabled, allowing a disabled user to continue calling auth= enticated server endpoints. This issue is fixed in version 26.6.0. 2026-07-=
07 8.3 CVE-2026-49229 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49229 ]=
Adam Retail Automation Ltd.--MobilMen 20T Improper neutralization of speci=
al elements used in an SQL command ('SQL injection') vulnerability in Adam = Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affect=
s MobilMen 20T: from v3 through 10072026.=C2=A0NOTE: The vendor was contact=
ed early about this disclosure but did not respond in any way. 2026-07-10 9=
.8 CVE-2026-2397 [
https://www.cve.org/CVERecord?id=3DCVE-2026-2397 ] Adam = Retail Automation Ltd.--MobilMen 20T Authorization bypass through User-Cont= rolled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows=
Privilege Escalation. This issue affects MobilMen 20T: from v3 through 100= 72026.=C2=A0NOTE: The vendor was contacted early about this disclosure but = did not respond in any way. 2026-07-10 8.8 CVE-2026-2398 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-2398 ] Adobe--ColdFusion ColdFusion versions 20= 25.9, 2023.20 and earlier are affected by an Improper Input Validation vuln= erability that could result in arbitrary code execution in the context of t=
he current user. Exploitation of this issue does not require user interacti= on. Scope is changed. 2026-07-06 10 CVE-2026-48316 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-48316 ] Allwinner--H616 Allwinner H616 TV Box TV98 ha=
s ADB enabled and exposed to the network on production. An attacker could r= equest for ADB authorization and gain root level privileges if the victim a= llows access. 2026-07-09 8.8 CVE-2026-58378 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-58378 ] appium--appium Appium is a cross-platform automation=
framework for all kinds of apps, built on top of the W3C WebDriver protoco=
l. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, = whose handler passes the user-supplied name value directly into path.join(s= torageRoot, name) and fs.rimraf() without path sanitization, allowing an un= authenticated remote client to escape the storage root with ../ sequences a=
nd recursively delete arbitrary writable files or directories. This issue i=
s fixed in version 1.1.6. 2026-07-08 8.6 CVE-2026-58192 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-58192 ] arikusi--deepseek-mcp-server DeepSeek MC=
P Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and pr= ior to version 1.7.0, the process-global `SessionStore` accepts caller-supp= lied `session_id` values without binding them to any authenticated principa=
l or transport session. An attacker can enumerate active session IDs via `d= eepseek_sessions`, then reuse a victim-controlled `session_id` in `deepseek= _chat` to retrieve and continue the victim's conversation context. Version = 1.7.0 contains a patch. 2026-07-09 8.6 CVE-2026-55604 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-55604 ] Armiya Information Technologies Ltd. Co.--= Access Control System (GKS) Missing Authorization vulnerability in Armiya I= nformation Technologies Ltd. Co. Access Control System (GKS) allows Collect=
Data from Common Resource Locations. This issue affects Access Control Sys= tem (GKS): before Version 2. 2026-07-07 8.2 CVE-2026-8377 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-8377 ] Aster Telecom--Azcall A weakness has be=
en identified in Aster Telecom Azcall 10/11. This issue affects some unknow=
n processing of the file /azcall/adm/gestao_loja/sis.php?t=3Dconsultar of t=
he component HTTP Handler. Executing a manipulation of the argument nome/pe= rfil/status can lead to sql injection. The attack may be performed from rem= ote. The exploit has been made available to the public and could be used fo=
r attacks. The vendor was contacted early about this disclosure but did not=
respond in any way. 2026-07-12 7.3 CVE-2026-15482 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-15482 ] AWS--MCP Gateway & Registry Improper Neutrali= zation of Special Elements in the metrics-service retention policy manageme=
nt component in Amazon mcp-gateway-registry before 1.0.13 might allow an au= thenticated remote user to execute arbitrary SQL queries via a crafted tabl= e_name value that is interpolated into SQL statements in identifier positio=
n. To remediate this issue, users should upgrade to version 1.0.13 or later=
. 2026-07-06 8.1 CVE-2026-14471 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-14471 ] B&R Industrial Automation GmbH--APROL Improper certificate valid= ation vulnerability in B&R Industrial Automation GmbH APROL. This issue aff= ects APROL: before R 4.4-01P5. 2026-07-06 7.4 CVE-2026-6900 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-6900 ] B&R Industrial Automation GmbH--APROL=
Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APRO=
L. This issue affects APROL: before R 4.4-01P5. 2026-07-06 7.7 CVE-2026-690=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6901 ] badhonrocks--Divi To= rque Lite Divi Modules for the Divi Builder & Theme The Divi Torque Lite - = Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable t=
o Cross-Site Request Forgery in all versions up to, and including, 4.2.3. T= his is due to the use of '__return_true' as the permission_callback for the=
/install_plugin and /activate_plugin REST API endpoints, which bypasses Wo= rdPress's built-in REST API nonce verification. Although the endpoint callb= acks contain internal current_user_can() checks, the absence of nonce verif= ication means that a forged cross-site request from a logged-in administrat= or's browser will pass the capability check via the admin's session cookies=
. This makes it possible for unauthenticated attackers to install arbitrary=
plugins from WordPress. 2026-07-09 8.8 CVE-2026-4275 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-4275 ] baptisteArno--typebot.io TypeBot is a chatb=
ot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packag= es/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspeci= fied address :: because validateIPAddress blocks local, metadata, and priva=
te ranges but does not block :: or its expanded form. A workspace editor or=
creator can configure a server-side HTTP Request block or guarded script f= etch to make the Typebot server connect to local HTTP services through safe= Ky, including flows triggered by POST /v1/typebots/{publicId}/startChat or = POST /v1/sessions/{sessionId}/continueChat. This issue is fixed in version = 3.17.2. 2026-07-10 8.1 CVE-2026-49213 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-49213 ] bitpressadmin--Bit Form Contact Form, Payment Forms, Multi=
Step Forms, Calculator & Custom Form Builder The Bit Form - Contact Form, = Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin fo=
r WordPress is vulnerable to arbitrary file deletion due to insufficient fi=
le path validation in the deleteFiles function in all versions up to, and i= ncluding, 3.1.1 This makes it possible for authenticated attackers, with su= bscriber-level access and above, to delete arbitrary files on the server, w= hich can easily lead to remote code execution when the right file is delete=
d (such as wp-config). 2026-07-09 7.1 CVE-2026-14372 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-14372 ] bitwarden--server Bitwarden Server before 2= 026.6.0 does not verify that the email in a POST /auth-requests/admin-reque=
st body belongs to the authenticated caller, allowing a low-privileged orga= nization member to obtain another user's vault key and a victim-scoped acce=
ss token by creating a Trusted Device Encryption authentication request, bo= und to an attacker-controlled public key, that is readable from an unauthen= ticated endpoint once approved resulting in disclosure of the victim's vaul=
t key and account takeover. 2026-07-08 8.7 CVE-2026-60104 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-60104 ] blakeblackshear--frigate Frigate is an=
open source network video recorder. In version 0.17.1, the GET /api/logs/{= service} endpoint allows any authenticated user including the viewer role t=
o download Frigate and nginx logs, exposing auto-generated admin passwords = and camera credentials logged in request query strings and enabling viewer-= to-admin privilege escalation. A fixed release has not been identified. 202= 6-07-08 8.1 CVE-2026-54652 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54= 652 ] blendmedia--WP CTA Call Now Button, Sticky Button & Call to Action Bu= ilder The WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin=
for WordPress is vulnerable to time-based blind SQL Injection via the 'fil= dname' parameter in all versions up to, and including, 2.2.2. This is due t=
o insufficient escaping of user-supplied column names in the ajaxCheck() me= thod and lack of preparation in the $wpdb->update() call. The vulnerability=
is compounded by the complete absence of authorization checks and the endp= oint being registered for unauthenticated users via wp_ajax_nopriv_. This m= akes it possible for unauthenticated attackers to inject arbitrary SQL quer= ies and extract sensitive information from the database via time-based blin=
d SQL injection techniques, including administrator password hashes. 2026-0= 7-11 7.5 CVE-2026-4661 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4661 ]=
boldgrid--W3 Total Cache The W3 Total Cache plugin for WordPress is vulner= able to Directory Traversal in all versions up to, and including, 2.9.4 via=
the setupSources function. This makes it possible for unauthenticated atta= ckers to read the contents of arbitrary files on the server, which can cont= ain sensitive information. Exploitation requires enabling manual minify mod=
e and supplying a manual-format minify filename so that the hash is empty a=
nd the f_array[] entries are not overwritten before reaching setupSources()=
. 2026-07-11 7.5 CVE-2026-9282 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-9282 ] brainstormforce--SureForms Drag & Drop Contact Form & Form Builder=
, Payment Form, Survey, Quiz & Calculator The SureForms - Drag and Drop For=
m Builder for WordPress plugin for WordPress is vulnerable to Improper Inpu=
t Validation in all versions up to, and including, 2.2.1. This is due to th=
e plugin accepting the payment amount directly from user-controlled POST da=
ta in the 'create_payment_intent' and 'create_subscription_intent' function=
s without validating it against the form's configured price. This makes it = possible for unauthenticated attackers to modify the payment amount to any = arbitrary value when submitting a Stripe payment form, potentially purchasi=
ng products or services at significantly reduced prices. 2026-07-10 7.5 CVE= -2026-15288 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15288 ] Canonical= --Ubuntu A sandbox escape vulnerability exists in the OpenJDK packages prov= ided in Ubuntu. The .jar MIME handlers installed by these packages execute = files marked as executable when the mailcap package is installed. A comprom= ised or malicious sandboxed application with access to the OpenURI portal v=
ia xdg-desktop-portal-gtk can write a malicious .jar file to the host file = system, set its executable bit, and trigger the handler to execute arbitrar=
y code outside of the sandbox environment. 2026-07-08 8.8 CVE-2026-10037 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-10037 ] Cap--Cap Cap's GET /api= /video/ai endpoint fails to validate user ownership or membership before re= turning private video AI metadata including titles, summaries, and chapters=
. Authenticated attackers can supply arbitrary video IDs to read sensitive = AI-generated content and trigger unauthorized AI generation that consumes t=
he video owner's credits without consent. 2026-07-07 7.1 CVE-2026-59704 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-59704 ] Cap-go--capgo Capgo (Cap= -go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function publ= ic.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the a= non role, allowing unauthenticated access. Because the function accepts a c= aller-supplied user UUID without verifying it matches the authenticated use=
r, an attacker using only the public publishable API key can query POST /re= st/v1/rpc/get_orgs_v6 with an arbitrary user UUID to retrieve that user's o= rganization membership, roles, subscription/trial metadata, and management_= email (PII). 2026-07-08 7.5 CVE-2026-56226 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-56226 ] capacitor-updater--capacitor-updater In @capgo/capaci= tor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption schem=
e distributes the private key to each device that downloads the app. Becaus=
e the public key can be derived from the private key, an attacker performin=
g a man-in-the-middle attack or compromising the Capgo server can create a = validly signed update bundle and cause devices to install an update not pro= duced by the original app maker. 2026-07-10 7 CVE-2026-56254 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-56254 ] Capgo--Capgo Capgo before 12.128.2 = contains a privilege escalation vulnerability where demoted super_admin use=
rs retain access to delete_non_compliant_bundles and count_non_compliant_bu= ndles RPCs due to stale org_users.user_right column not being cleared durin=
g role binding deletion. Attackers can exploit this by maintaining a previo= usly granted super_admin role to enumerate and bulk delete non-compliant bu= ndles across the entire organization indefinitely. 2026-07-12 8.3 CVE-2026-= 56241 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56241 ] Capgo--Capgo Ca= pgo before 12.128.2 contains a broken access control vulnerability in the o= rganization management API where a scoped API key (limited_to_orgs) inherit=
s its owner-user's permissions, allowing destructive cross-organization act= ions. When a user is an admin in two organizations and creates a write-mode=
API key restricted to one organization, that key can still perform destruc= tive operations (e.g., DELETE /organization, DELETE /organization/members) = against another organization. The root cause is route-level authorization (= rbac_check_permission_direct) that evaluates the key owner's user privilege=
s before enforcing the API key's limited_to_orgs scope. 2026-07-08 8.1 CVE-= 2026-56246 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56246 ] Capgo--Cap=
go Capgo before 12.128.2 contains an authentication bypass vulnerability in=
the password change endpoint that allows attackers to change user password=
s without requiring current password confirmation. Attackers with temporary=
session access can exploit this flaw to permanently lock out legitimate us= ers and achieve full account takeover. 2026-07-10 8.3 CVE-2026-56305 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-56305 ] Capgo--Capgo Capgo before 1= 2.128.2 contains a cross-organization account disruption vulnerability in t=
he SSO prelink endpoint that allows enterprise administrators to delete pas= sword identities of users in foreign organizations. Attackers with org.upda= te_settings permission and an active SSO provider can call the prelink-user=
s endpoint to permanently remove email-based authentication for any user ma= tching the provider's email domain, forcing victims to use the attacker's S=
SO provider or complete password reset recovery. 2026-07-12 8.1 CVE-2026-56= 313 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56313 ] Capgo--Capgo Capg=
o before 12.128.2 contains an information disclosure vulnerability in the S= upabase PostgREST global_stats endpoint that allows unauthenticated attacke=
rs to read sensitive financial and operational metrics using only the publi=
c apikey. Remote attackers can query the /rest/v1/global_stats endpoint to = expose MRR, total revenue, plan-tier revenue breakdown, customer counts, an=
d operational telemetry. 2026-07-12 7.5 CVE-2026-56238 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-56238 ] Capgo--Capgo Capgo before 12.128.2 allows=
upload-scoped API keys to modify the mutable app_versions.r2_path field th= rough PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attac= kers can patch r2_path to point to victim objects, soft-delete the attacker= -controlled version, and trigger the on_version_update cleanup function to = delete the victim R2 object, causing denial of service and bundle availabil= ity disruption. 2026-07-08 7.5 CVE-2026-56250 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-56250 ] Capgo--Capgo Capgo before 12.128.2 contains an inf= ormation disclosure vulnerability in the get_orgs_v7(userid) RPC function t= hat remains publicly invokable despite intended private access controls. Un= authenticated attackers can supply arbitrary user UUIDs to retrieve foreign=
users' organization membership, roles, management emails, and billing meta= data. 2026-07-10 7.5 CVE-2026-56279 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-56279 ] Capgo--Capgo Capgo before 12.128.2 contains an information d= isclosure vulnerability in the find_apikey_by_value PostgreSQL function mar= ked SECURITY DEFINER and executable by the anon role. Unauthenticated attac= kers can call this function via the /rest/v1/rpc/find_apikey_by_value endpo= int to retrieve sensitive API key metadata including user_id, mode, org sco= ping, and expiration details when supplied a valid key value. 2026-07-11 7.=
5 CVE-2026-56303 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56303 ] Capg= o--Capgo Capgo before 12.128.2 allows email address changes without requiri=
ng current password re-authentication or verification of the existing email=
address. An attacker with access to a valid session cookie or authenticate=
d browser can change the account email to gain control of account recovery = and bypass multi-factor authentication protections. 2026-07-12 7.3 CVE-2026= -56308 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56308 ] Cesanta--Mongo= ose Cesanta Mongoose before 7.22 contains an out-of-bounds read in the buil= t-in TLS server function mg_tls_server_recv_hello(), which uses an attacker= -controlled session_id_len byte from a TLS ClientHello as a buffer index wi= thout validating it against the length of received data. A remote, unauthen= ticated attacker can send a single crafted ClientHello with an oversized se= ssion id length to read past the receive buffer, crashing any HTTPS, MQTTS,=
or WSS service built on MG_TLS_BUILTIN. 2026-07-09 7.5 CVE-2026-11404 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-11404 ] choijun--LA-Studio Elemen=
t Kit for Elementor The LA-Studio Element Kit for Elementor plugin for Word= Press is vulnerable to Local File Inclusion in all versions up to, and incl= uding, 1.6.1 via the get_type_template function. This makes it possible for=
authenticated attackers, with contributor-level access and above, to inclu=
de and execute arbitrary .php files on the server, allowing the execution o=
f any PHP code in those files. This can be used to bypass access controls, = obtain sensitive data, or achieve code execution in cases where .php file t= ypes can be uploaded and included. The wp_normalize_path function used in g= et_template only normalizes directory separators and does not resolve or re= ject path traversal sequences, while the extension check is trivially bypas= sed because the caller already appends the required extension to the traver= sal payload. 2026-07-11 7.5 CVE-2026-15338 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-15338 ] cifi--GEO Plugin by Squirrly SEO The SEO Plugin by Sq= uirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation an=
d Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 = due to a leak of an API token and insufficient input sanitization and outpu=
t escaping. This makes it possible for unauthenticated attackers to create = arbitrary posts, and, if the Advanced Custom Fields plugin is installed and=
activated, inject arbitrary web scripts in pages that will execute wheneve=
r a user accesses an injected page. 2026-07-10 7.2 CVE-2026-1667 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-1667 ] cline--cline Cline is an autonom= ous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.3=
0, the Cline Hub dashboard server launched by the cline dashboard command a= ccepts WebSocket connections on the /browser endpoint without validating th=
e Origin header, and when ROOM_SECRET is unset for local 127.0.0.1 binds, i= sAuthorizedBrowserRequest() allows attacker-controlled websites to send des= ktopCommand frames that read workspace state, mutate MCP and provider setti= ngs, and trigger command execution when a provider or model is configured. = This issue is fixed in version 3.0.30. 2026-07-08 8.8 CVE-2026-59723 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-59723 ] CloudFoundry Foundation--UA=
A A network attacker positioned between UAA and its LDAP directory can impe= rsonate the directory using any certificate from any trusted CA, then harve=
st the LDAP bind password and every end-user password sent during simple-bi=
nd authentication, and return forged group memberships that grant themselve=
s admin scopes. This affects every deployment that authenticates users agai= nst LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; = Cf-deployment versions prior to v56.2.0. 2026-07-09 7.5 CVE-2026-47840 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-47840 ] code-projects--Interview = Management System A weakness has been identified in code-projects Interview=
Management System 1.0. This vulnerability affects unknown code of the file=
\inc\classes\View.php. This manipulation of the argument ID causes sql inj= ection. The attack can be initiated remotely. The exploit has been made ava= ilable to the public and could be used for attacks. 2026-07-09 7.3 CVE-2026= -15137 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15137 ] code-projects-= -Online Food Order System A security flaw has been discovered in code-proje= cts Online Food Order System 1.0. This affects an unknown part of the file = /edit_food_items.php. The manipulation of the argument update results in sq=
l injection. It is possible to launch the attack remotely. The exploit has = been released to the public and may be used for attacks. 2026-07-08 7.3 CVE= -2026-15135 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15135 ] CodeAstro= --Simple Online Leave Management System A vulnerability was determined in C= odeAstro Simple Online Leave Management System 1.0. Affected by this vulner= ability is an unknown functionality of the file /SimpleOnlineLeave/index.ph=
p. Executing a manipulation of the argument email can lead to sql injection=
. The attack may be performed from remote. The exploit has been publicly di= sclosed and may be utilized. 2026-07-08 7.3 CVE-2026-15134 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-15134 ] coder--coder Coder allows organizatio=
ns to provision remote development environments via Terraform. In versions = prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidenti= ty.Validate()` verifies that the PKCS#7 signer certificate chains to a trus= ted Azure CA but never verifies the PKCS#7 signature itself. An attacker ca=
n embed a legitimate Azure certificate alongside arbitrary content e.g. `{"= vmId":"<target>"}` and the forged `vmId` will be accepted returning the vic= tim workspace agent's session token. No authentication is required. The att= acker only needs to know a target VM's `vmId` which is a `UUIDv4`. That's a=
practical limitation which would typically require prior access to be expl= oited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch = the issue. As a workaround, reconfigure any Azure templates to use token au= thentication rather than `azure-instance-identity`. 2026-07-07 9.1 CVE-2026= -46354 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46354 ] coder--coder C= oder allows organizations to provision remote development environments via = Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry mod= ule passed unsanitized user input to shell commands, allowing arbitrary cod=
e execution inside a provisioned workspace. Any user who supplied a crafted=
`dotfiles_uri` value (for example, one containing shell command substituti=
on such as `$(...)`) could achieve command execution in their own workspace=
. The Create Workspace page's `mode=3Dauto` deep links amplified this into =
a one-click attack: an attacker could craft a URL that prefilled `param.dot= files_uri` and silently provisioned a workspace with the attacker-controlle=
d value, with no explicit user confirmation. In versions 2.29.7 and 2.30.2,=
input validation was added to the dotfiles module to reject URIs and usern= ames containing special characters, and the unsafe `eval`/`sh -c` usage was=
removed. This eliminated the command injection at its source. 2026-07-07 8=
.1 CVE-2026-44454 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44454 ] cod= er--coder Coder allows organizations to provision remote development enviro= nments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,=
`coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `= SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embed= ded newlines or restricting directives so a malicious or compromised Coder = server could inject arbitrary SSH configuration. Practical exploitation req= uires control of the server-supplied values through a malicious or compromi= sed deployment, a man-in-the-middle position or admin access to the `Hostna= meSuffix` and `SSHConfigOptions` settings. The fix in versions 2.29.7, 2.32= .7, 2.33.8, and 2.34.2 validates `HostnameSuffix` and `SSHConfigOptions` ag= ainst a strict character set that rejects newlines and other control charac= ters. As a workaround, inspect `coder config-ssh --dry-run` output before a= pplying changes. 2026-07-07 8.3 CVE-2026-55427 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-55427 ] coder--coder Coder allows organizations to provis= ion remote development environments via Terraform. Prior to versions 2.29.7=
, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an age= nt's `Addresses` derive from its authenticated UUID but applies no equivale=
nt check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedI= Ps` verbatim to tunnel peers which install them into the WireGuard peer con= figuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validate=
s each `AllowedIPs` prefix against the authenticating agent's UUID just lik=
e `Addresses`. As a workaround, monitor coordinator logs for agents adverti= sing unexpected `AllowedIPs` prefixes. 2026-07-07 8.2 CVE-2026-55428 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-55428 ] coder--coder Coder allows o= rganizations to provision remote development environments via Terraform. Pr= ior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` ov= erwrites an existing app's `agent_id` on a primary-key conflict and `insert= AgentApp` accepts the app ID from the provisioner's `CompleteJob` payload w= ithout verifying it belongs to the workspace being built. `CompleteJob` run=
s under `dbauthz.AsProvisionerd` so the authorization layer does not block = the cross-workspace upsert. Exploitation requires elevated access as a temp= late author or external provisioner operator. The fix in versions 2.29.7, 2= .32.7, 2.33.8, and 2.34.2 verifies that any existing `workspace_apps` row m= atching the supplied ID belongs to the workspace being built and rejects cr= oss-workspace agent reassignment. No known workarounds are available. 2026-= 07-08 8.7 CVE-2026-55429 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5542=
9 ] coder--coder Coder allows organizations to provision remote development=
environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and = 2.34.2, two flaws in Coder's OIDC login chained into account takeover. Emai= l-based user matching fell back to linking by email without checking for an=
existing link to a different IdP subject and the `email_verified` claim wa=
s only enforced when present as a boolean `false` so an absent or non-boole=
an claim was treated as verified. The fix in versions 2.29.7, 2.32.7, 2.33.=
8, and 2.34.2 restricts the email fallback to first-time and legacy linking=
and defaults `email_verified` to false when the claim is absent or of an u= nexpected type. As a workaround, configure the OIDC provider to disallow se= lf-registration or to require email verification before issuing tokens. 202= 6-07-07 7.4 CVE-2026-55075 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55= 075 ] coder--coder Coder allows organizations to provision remote developme=
nt environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, an=
d 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `= bool` type assertion. When an IdP returned the claim as a non-boolean (for = example the string `"false"`) or omitted it, the assertion failed open and = the email was treated as verified. Combined with an unconditional email-bas=
ed account fallback, this enabled account takeover. The fix in versions 2.2= 9.7, 2.32.7, 2.33.8, and 2.34.2 coerces `email_verified` across bool, strin=
g and numeric types (fail-closed) and blocks the email fallback when the ma= tched user already has a different linked IdP subject. As a workaround, ens= ure the IdP returns `email_verified` as a native JSON boolean. The email-fa= llback linking issue has no configuration workaround; upgrading is required=
. 2026-07-07 7.4 CVE-2026-55076 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-55076 ] coder--coder Coder allows organizations to provision remote deve= lopment environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.=
8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized = only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetti=
ng an `owner` account's password. It also did not require the current passw= ord when an admin reset another user's password. Exploitation requires the = privileged `user-admin` role so practical risk is limited to deployments th=
at grant `user-admin` to less trusted operators. The fix in versions 2.29.7=
, 2.32.7, 2.33.8, and 2.34.2 prevents non-owner users from resetting the pa= ssword of an account that holds the `owner` role. As a workaround, restrict=
the `user-admin` role to trusted administrators. 2026-07-07 7.2 CVE-2026-5= 5077 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55077 ] coder--coder Cod=
er allows organizations to provision remote development environments via Te= rraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open = app` opens external workspace-app URLs without validating the scheme or hos=
t. When an external app URL contains the `$SESSION_TOKEN` placeholder the C=
LI replaces it with the user's real session token before handing the URL to=
the OS open handler. Practical exploitation requires the victim to run `co= der open app` against a workspace whose external app definition the attacke=
r controls. Only a malicious template author can control external app URLs.=
The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-schem=
e allowlist in the CLI and limits `$SESSION_TOKEN` substitution to trusted = destinations like the web frontend. As a workaround, avoid running `coder o= pen app` for untrusted workspaces. 2026-07-08 7.7 CVE-2026-55431 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-55431 ] coder--coder Coder allows organ= izations to provision remote development environments via Terraform. Starti=
ng in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the =
AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default t= ransport set `InsecureSkipVerify: true` and only assigned a secure transpor=
t when an upstream proxy was configured. In the default configuration (no u= pstream proxy), outbound HTTPS to the Coder access URL accepted any TLS cer= tificate. Practical exploitation requires an on-path (man-in-the-middle) po= sition between the AI Bridge Proxy and the Coder server. Deployments where = they are co-located over loopback are effectively unaffected. The fix in ve= rsions 2.32.7, 2.33.8, and 2.34.2 applies the secure transport (TLS 1.2 or = higher using system root CAs) unconditionally. As a workaround, ensure the = Coder access URL uses a trusted certificate and secure the network path bet= ween the AI Bridge Proxy and the Coder server (for example, loopback or mTL= S). 2026-07-08 7.4 CVE-2026-55436 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-55436 ] Comfast--CF-WR631AX V3 A vulnerability was determined in Comfa=
st CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the funct= ion system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component=
FastCGI Backend. This manipulation of the argument filename causes os comm= and injection. It is possible to initiate the attack remotely. The exploit = has been publicly disclosed and may be utilized. The vendor was contacted e= arly about this disclosure but did not respond in any way. 2026-07-12 9.8 C= VE-2026-15511 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15511 ] compose= r--composer Composer is a dependency Manager for the PHP language. Prior to=
2.2.29 and 2.10.2, a maliciously crafted package from an untrusted reposit= ory other than Packagist.org or Private Packagist can cause Composer to wri=
te attacker-controlled files outside the vendor directory and outside the p= roject during install or update by using an invalid package name that is no=
t correctly validated before dependency-resolution results are written or i= nstalled. This issue is fixed in versions 2.2.29 and 2.10.2. 2026-07-08 7 C= VE-2026-59948 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59948 ] coollab= sio--coolify Coolify is an open-source and self-hostable tool for managing = servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo(=
) Livewire action in ResourceOperations.php authorizes the source resource = but resolves destination resources with unscoped Eloquent lookups, allowing=
an authenticated user to clone resources into destinations owned by other = teams and access cross-tenant resources. This issue is fixed in version 4.0= .0-beta.464. 2026-07-07 9.9 CVE-2026-34037 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-34037 ] coollabsio--coolify Coolify is an open-source and sel= f-hostable tool for managing servers, applications, and databases. Prior to=
4.0.0-beta.469, an authenticated remote command injection vulnerability in=
application deployment handling allows users with application write permis= sions to achieve remote code execution and exfiltrate sensitive environment=
variables through deployment logs via fields such as dockerfile_location a=
nd deployment commands. This issue is fixed in version 4.0.0-beta.469. 2026= -07-06 9.9 CVE-2026-34038 [
https://www.cve.org/CVERecord?id=3DCVE-2026-340=
38 ] coollabsio--coolify Coolify is an open-source and self-hostable tool f=
or managing servers, applications, and databases. Prior to 4.0.0-beta.471, = terminal WebSocket bootstrap routes did not enforce the expected authorizat= ion middleware, allowing an authenticated user to access terminal functiona= lity for resources outside the authorized scope and potentially execute com= mands. This issue is fixed in version 4.0.0-beta.471. 2026-07-07 9.9 CVE-20= 26-34047 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34047 ] coollabsio--= coolify Coolify is an open-source and self-hostable tool for managing serve= rs, applications, and databases. Prior to 4.0.0-beta.471, terminal websocke=
t bootstrap routes only check authentication and do not enforce terminal au= thorization, allowing a low-privileged team member to connect to terminal r= outes and execute commands on team servers. This issue is fixed in version = 4.0.0-beta.471. 2026-07-07 9.9 CVE-2026-34048 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-34048 ] coollabsio--coolify Coolify is an open-source and = self-hostable tool for managing servers, applications, and databases. Prior=
to 4.0.0-beta.466, the sentinel_token setting is used in shell commands wi= thout sufficient validation, allowing an authenticated user with access to = server Sentinel settings to inject shell syntax and execute commands on the=
host when Sentinel is restarted. This issue is fixed in version 4.0.0-beta= .466. 2026-07-07 8.8 CVE-2026-34034 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-34034 ] coollabsio--coolify Coolify is an open-source and self-hosta= ble tool for managing servers, applications, and databases. Prior to 4.0.0-= beta.466, log drain secret and environment values were interpolated into sh= ell commands without sufficient encoding, allowing an authenticated user to=
inject commands executed on the host. This issue is fixed in version 4.0.0= -beta.466. 2026-07-07 8.8 CVE-2026-34035 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-34035 ] coollabsio--coolify Coolify is an open-source and self-= hostable tool for managing servers, applications, and databases. Prior to 4= .0.0-beta.471, the database import Livewire component (app/Livewire/Project= /Database/Import.php) allows client-controlled container and server propert= ies to reach shell commands without locking or validation, allowing an auth= enticated user to inject commands through a database import container name.=
This issue is fixed in version 4.0.0-beta.471. 2026-07-07 8.8 CVE-2026-340=
57 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34057 ] coollabsio--coolif=
y Coolify is an open-source and self-hostable tool for managing servers, ap= plications, and databases. Prior to 4.0.0-beta.471, the Livewire component = Server\Resources exposes public methods (startUnmanaged, stopUnmanaged, res= tartUnmanaged) that accept a container ID parameter directly from the brows=
er without any sanitization or escaping. This parameter is interpolated dir= ectly into shell commands executed via SSH on managed servers, enabling any=
authenticated team member to execute arbitrary OS commands on remote serve= rs. This issue is fixed in version 4.0.0-beta.471. 2026-07-07 8.8 CVE-2026-= 34058 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34058 ] coollabsio--coo= lify Coolify is an open-source and self-hostable tool for managing servers,=
applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and p= ost-deployment commands are single-quote escaped but then sent through SSH = heredoc transport that preserves newlines, allowing an authenticated user t=
o inject additional shell statements that execute on the remote server duri=
ng deployment. This issue is fixed in version 4.0.0-beta.471. 2026-07-07 8.=
8 CVE-2026-34152 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34152 ] cool= labsio--coolify Coolify is an open-source and self-hostable tool for managi=
ng servers, applications, and databases. Prior to 4.0.0-beta.471, LocalFile= Volume::saveStorageOnServer builds shell commands using unescaped fs_path a=
nd parent_dir values before validation, and submitFileStorage does not vali= date the user-controlled file-mount path before creating a volume, allowing=
an authenticated user who can add file storage to execute commands when th=
e storage is saved. This issue is fixed in version 4.0.0-beta.471. 2026-07-=
06 8.8 CVE-2026-34153 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34153 ]=
coollabsio--coolify Coolify is an open-source and self-hostable tool for m= anaging servers, applications, and databases. Prior to 4.0.0-beta.469, the = executeInDocker() helper wraps user-controlled commands in single quotes wi= thout escaping embedded single quotes. Attackers who can edit application s= ettings can inject a single quote into docker_compose_custom_build_command =
or docker_compose_custom_start_command to break out of the quoted context a=
nd execute arbitrary commands on the managed server host during deployments=
, escaping the intended Docker container confinement. This issue is fixed i=
n version 4.0.0-beta.469. 2026-07-07 8.8 CVE-2026-34158 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-34158 ] coollabsio--coolify Coolify is an open-s= ource and self-hostable tool for managing servers, applications, and databa= ses. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is inter= polated directly into docker volume shell commands without shell argument e= scaping, allowing an authenticated user to set a storage name containing sh= ell metacharacters and execute commands on managed servers when the resourc=
e is deleted. This issue is fixed in version 4.0.0-beta.471. 2026-07-07 8.8=
CVE-2026-34168 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34168 ] cooll= absio--coolify Coolify is an open-source and self-hostable tool for managin=
g servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /i= nvitations/{uuid} endpoint can perform a state-changing password reset usin=
g an attacker-known invitation UUID, allowing an attacker who can cause a v= ictim to visit the crafted invitation URL to reset the victim account passw= ord to a predictable value. This issue is fixed in version 4.0.0-beta.471. = 2026-07-07 8 CVE-2026-34171 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3= 4171 ] coollabsio--coolify Coolify is an open-source and self-hostable tool=
for managing servers, applications, and databases. Prior to 4.0.0-beta.471=
, there is an authenticated command injection vulnerability in the GetLogs = Livewire component which allows users with team membership (lowest privileg=
e member role) to execute arbitrary commands as root on managed servers. Th=
e $container Livewire public property is interpolated directly into shell c= ommands (docker logs, docker service logs) without sanitization, and can be=
modified by any client via the Livewire wire protocol because it lacks the=
#[Locked] attribute. This issue is fixed in version 4.0.0-beta.471. 2026-0= 7-06 8.8 CVE-2026-34599 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34599=
] coollabsio--coolify Coolify is an open-source and self-hostable tool for=
managing servers, applications, and databases. Prior to 4.0.0-beta.471, us= er-controlled persistent volume names are interpolated into shell commands = executed on managed servers without escaping or validation, allowing an aut= henticated member to inject shell metacharacters and execute commands as ro=
ot when volume operations are triggered. This issue appears to be fixed in = version 4.0.0-beta.471. 2026-07-07 8.8 CVE-2026-42143 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-42143 ] coollabsio--coolify Coolify is an open-sou= rce and self-hostable tool for managing servers, applications, and database=
s. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used = attacker-controlled database settings (postgres_user and postgres_db) in sh= ell-form commands, allowing an authenticated user to inject commands execut=
ed in the database container. This issue is fixed in version 4.0.0-beta.474=
. 2026-07-06 8.8 CVE-2026-42153 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-42153 ] coollabsio--coolify Coolify is an open-source and self-hostable = tool for managing servers, applications, and databases. Prior to 4.0.0-beta= .474, PostgreSQL initialization script (generate_init_scripts() method in a= pp/Actions/Database/StartPostgresql.php) filename handling did not sufficie= ntly restrict paths, allowing an authenticated user to write files outside = the intended directory and achieve command execution through database initi= alization. This issue is fixed in version 4.0.0-beta.474. 2026-07-07 8.8 CV= E-2026-42200 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42200 ] coollabs= io--coolify Coolify is an open-source and self-hostable tool for managing s= ervers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta= .473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in cust=
om Docker Compose build, start, and pre/post-deployment command fields, all= owing an authenticated team member to inject shell commands that execute on=
the host. This issue is fixed in version 4.0.0-beta.474. 2026-07-06 8.8 CV= E-2026-42204 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42204 ] coollabs= io--coolify Coolify is an open-source and self-hostable tool for managing s= ervers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app= /Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function=
directly interpolated the health_check_host, health_check_method, and heal= th_check_path parameters into shell commands without proper sanitization, a= llowing authenticated users to execute arbitrary commands inside deployment=
containers. This issue is fixed in version 4.0.0-beta.469. 2026-07-09 8.8 = CVE-2026-59734 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59734 ] coolla= bsio--coolify Coolify is an open-source and self-hostable tool for managing=
servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::m= ount() component looks up resources by UUID without scoping the lookup to t=
he current team, allowing an authenticated user to access logs for applicat= ions owned by other teams by supplying a victim resource UUID. This issue i=
s fixed in version 4.0.0-beta.466. 2026-07-07 7.7 CVE-2026-34044 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-34044 ] CoreWCF--CoreWCF CoreWCF is a p= ort of the service side of Windows Communication Foundation (WCF) to .NET C= ore. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validati=
on does not correctly resolve the issuer signing key or require signed toke=
ns when IdentityConfiguration is used with federated bindings, allowing an = unauthenticated remote attacker to impersonate any principal the trusted ST=
S could issue. This issue is fixed in versions 1.8.1 and 1.9.1. 2026-07-08 =
10 CVE-2026-54782 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54782 ] Cor= eWCF--CoreWCF CoreWCF is a port of the service side of Windows Communicatio=
n Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticat=
ed remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or = UnixDomainSocketBinding endpoint can trigger premature EOF handling in the = CoreWCF net.tcp, net.pipe, or net.uds framing handshake and pin one server = thread-pool worker at full CPU per connection. This issue is fixed in versi= ons 1.8.1 and 1.9.1. 2026-07-08 7.5 CVE-2026-54772 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-54772 ] CoreWCF--CoreWCF CoreWCF is a port of the ser= vice side of Windows Communication Foundation (WCF) to .NET Core. Prior to = 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification whe=
n a CoreWCF service validates SAML tokens using a non-X.509 signing token, = allowing an attacker to reference a non-X.509 SecurityToken key identifier = and bypass assertion signature verification. This issue is fixed in version=
s 1.8.1 and 1.9.1. 2026-07-08 7.4 CVE-2026-54774 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-54774 ] CoreWCF--CoreWCF CoreWCF is a port of the servi=
ce side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.= 8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfir= mation method URIs or holder-of-key proof keys in SamlSecurityTokenHandler,=
allowing holder-of-key downgrade or custom confirmation method assertions =
to authenticate a subject without proving authority over the assertion. Thi=
s issue is fixed in versions 1.8.1 and 1.9.1. 2026-07-08 7.4 CVE-2026-54781=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-54781 ] CoreWCF--CoreWCF Cor= eWCF is a port of the service side of Windows Communication Foundation (WCF=
) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and=
supporting signature verification does not ensure the selected ds:Signatur=
e covers the expected Security header target, allowing an attacker with one=
captured signed SOAP envelope to replay arbitrary service operations as th=
e victim principal. This issue is fixed in versions 1.8.1 and 1.9.1. 2026-0= 7-08 7.4 CVE-2026-54783 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54783=
] CoreWCF--CoreWCF CoreWCF is a port of the service side of Windows Commun= ication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO Sec= urityContextToken negotiation can expose the proof key recovered from the R= STR when TransportWithMessageCredential with Windows client credentials and=
session establishment are used, allowing an observer to impersonate the au= thenticated Windows principal and decrypt or forge WS-SecureConversation tr= affic. This issue is fixed in version 1.9.1. 2026-07-08 7.4 CVE-2026-54784 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-54784 ] corvusinfo--CorvusPay=
WooCommerce Payment Gateway The CorvusPay WooCommerce Payment Gateway plug=
in for WordPress is vulnerable to Stored Cross-Site Scripting via the 'appr= oval_code' parameter in all versions up to, and including, 2.7.4 due to ins= ufficient input sanitization and output escaping. This makes it possible fo=
r unauthenticated attackers to inject arbitrary web scripts in pages that w= ill execute whenever a user accesses an injected page. The unauthenticated = REST endpoint POST /wp-json/corvuspay/success/ is registered with permissio= n_callback set to __return_true, and although a signature validation step e= xists it only logs the result without halting execution, meaning an attacke=
r can supply a completely arbitrary signature and have a malicious approval= _code stored in the database unchallenged. 2026-07-11 7.2 CVE-2026-6939 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-6939 ] Cotonti--Cotonti Cotonti = Siena 0.9.26 and earlier contains a cross-site request forgery vulnerabilit=
y that allows unauthenticated attackers to modify administrator configurati=
on by tricking a logged-in administrator into submitting a forged POST requ= est to the admin.php config update handler, which never invokes the applica= tion's CSRF validation function. Attackers can disable the PFS module's fil=
e extension whitelist by setting pfsfilecheck to 0, enabling any user with = PFS access to upload and execute arbitrary PHP files on the server. 2026-07= -09 8.8 CVE-2026-58143 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58143 =
] coturn--coturn Coturn is a free open source implementation of TURN and ST=
UN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query = parameters directly into SQL queries via snprintf string interpolation with= out sanitization. The is_secure_string filter that protects the STUN protoc=
ol path is not applied to the admin panel's delete-user, delete-secret, and=
delete-IP operations, so an authenticated admin can inject arbitrary SQL t= hrough the du, ds, and dip parameters, gaining full database control and po= tentially OS-level access via PostgreSQL COPY TO PROGRAM. This issue is fix=
ed in version 4.12.0. 2026-07-10 7.2 CVE-2026-53448 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-53448 ] coturn--coturn Coturn is a free open source = implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loo= pback peers by default unless allow-loopback-peers is enabled, but the defa= ult loopback guard can be bypassed by using the IPv4-mapped IPv6 peer addre=
ss ::ffff:127.0.0.1 in a TURN XOR-PEER-ADDRESS attribute. ioa_addr_is_loopb= ack checks for the literal IPv6 loopback shape before IPv4-mapped IPv6 hand= ling, so good_peer_addr does not apply the default loopback rejection and a=
n authenticated TURN client can expose services bound only to localhost on = the coturn host through TURN relay traffic. This issue is fixed in version = 4.13.0. 2026-07-10 7.4 CVE-2026-53450 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-53450 ] Crawl4AI--Crawl4AI Crawl4AI before 0.8.7 contains an arbit= rary file write vulnerability in the Docker API server's /screenshot and /p=
df endpoints. The output_path parameter accepts arbitrary filesystem paths = without validation, allowing an attacker to supply absolute or path-travers=
al values to write to any location writable by the application's user, over= writing server files and causing denial of service. 2026-07-12 9.1 CVE-2026= -56260 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56260 ] Crawl4AI--Craw= l4AI Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities=
in the Docker API server that allow attackers to redirect LLM API calls to=
attacker-controlled endpoints and read arbitrary environment variables. At= tackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints b=
y supplying a malicious base_url parameter and setting api_token to env:VAR= IABLE_NAME to exfiltrate provider API keys and server secrets including JWT=
SECRET_KEY for authentication bypass. 2026-07-12 8.2 CVE-2026-56259 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-56259 ] Crawl4AI--Crawl4AI Crawl4AI=
before 0.8.7 contains a server-side request forgery (SSRF) vulnerability i=
n the Docker API server's /crawl/job and /llm/job endpoints, which accept w= ebhook URLs without destination validation. An attacker can supply webhook = URLs pointing to private or internal IP ranges, Docker networks, or cloud m= etadata endpoints (e.g. 169.254.169.254), causing the server to make reques=
ts to internal services and potentially expose cloud metadata. 2026-07-10 8=
.6 CVE-2026-56261 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56261 ] Cre= ative Themes--Blocksy Companion Blocksy Companion Pro plugin for WordPress = before 2.1.47 contains an unauthenticated arbitrary file upload vulnerabili=
ty that allows attackers to upload executable files by bypassing extension = validation in the save_attachments function exposed through the Advanced Re= views feature. Attackers can exploit the Custom Fonts extension's flawed st= rpos() substring check by uploading double-extension filenames such as shel= l.woff2.php, causing the validation to pass on the substring match while th=
e web server executes the file as PHP, achieving remote code execution. 202= 6-07-08 9.8 CVE-2026-58480 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58= 480 ] creativethemeshq--Blocksy Companion The Blocksy Companion plugin for = WordPress is vulnerable to Arbitrary File Upload in all versions up to, and=
including, 2.1.46 via the save_attachments function. This is due to the Cu= stom Fonts extension registering a wp_check_filetype_and_ext filter that ap= proves any filename containing .woff2 or .ttf as a substring via strpos() r= ather than validating that those strings appear as the final extension via = PATHINFO_EXTENSION - allowing double-extension filenames such as shell.woff= 2.php to pass MIME validation and be handled as permitted font files. This = makes it possible for unauthenticated attackers to upload files that may be=
executable, which makes remote code execution possible. This vulnerability=
is only exploitable when the premium version of the plugin (blocksy-compan= ion-pro) is installed with both the WooCommerce Extra (Advanced Reviews) an=
d Custom Fonts extensions active; the free blocksy-companion plugin does no=
t contain the vulnerable code paths. 2026-07-09 9.8 CVE-2026-15158 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-15158 ] cyberlord92--miniOrange OTP L= ogin, Verification and SMS Notifications The miniOrange OTP Login, Verifica= tion and SMS Notifications plugin for WordPress is vulnerable to Authentica= tion Bypass leading to Administrator Account Takeover in all versions up to=
, and including, 5.5.1. This is due to the `um_reset_password_process_hook(=
)` function performing no server-side verification that the OTP validation = step was completed, and relying solely on a public `form_nonce` nonce that = the plugin itself emits to unauthenticated visitors via the `moumprvar` Jav= aScript object on the Ultimate Member password reset page, while still acce= pting the attacker-controlled `username_b` parameter to target any WordPres=
s user without role restriction or any binding to a previously validated OT=
P session. This makes it possible for unauthenticated attackers to obtain a=
freshly generated password-reset URL for an arbitrary Administrator accoun=
t - returned in a 302 `Location` header - and use it to take full control o=
f that account. Exploitation requires the Ultimate Member Password Reset Fo=
rm integration to be active and the plugin to not be configured for phone-o= nly reset. 2026-07-09 9.8 CVE-2026-14245 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-14245 ] cyberlord92--miniOrange Social Login and Register (Disc= ord, Google, Twitter, LinkedIn) The miniOrange Social Login and Register (D= iscord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to au= thentication bypass leading to account takeover in versions up to and inclu= ding 7.7.0. This is due to the Profile Completion flow accepting an arbitra=
ry email address via the 'email_field' POST parameter without verifying tha=
t the email belongs to the identity returned by the OAuth provider, combine=
d with send_otp_token() returning the SHA-512(customer_key || otp) transact= ion hash to the client where the OTP space is only 99,000 values (wp_rand(1= 000, 99999)) and the customer_key is a static option (empty on unregistered=
installs). This makes it possible for unauthenticated attackers to trigger=
an OTP email to an arbitrary admin's address, crack the OTP offline from t=
he leaked hash in under a second, and submit the cracked OTP to mo_openid_s= ocial_login_validate_otp(), which logs the attacker in as the user whose em= ail was supplied - granting full administrator access. 2026-07-10 9.8 CVE-2= 026-12761 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12761 ] D-link--DIR= -823G A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. = Affected by this vulnerability is an unknown functionality of the file /etc= /boa/boa.conf of the component Web Interface. Executing a manipulation can = lead to least privilege violation. The attack can be launched remotely. The=
attack requires a high level of complexity. The exploitation appears to be=
difficult. The exploit has been made available to the public and could be = used for attacks. 2026-07-09 7.5 CVE-2026-15270 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-15270 ] danieliser--Popup Maker Boost Sales, Conversions=
, Optins, Subscribers with the Ultimate WP Popup Builder The Popup Maker - = Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Bu= ilder plugin for WordPress is vulnerable to authorization bypass in all ver= sions up to, and including, 1.22.0. This is due to the plugin not properly = verifying that a user is authorized to perform an action. This makes it pos= sible for authenticated attackers, with editor-level access and above, to i= nstall and activate an arbitrary plugin from an attacker-controlled URL, le= ading to remote code execution. Exploitation requires that a valid Popup Ma= ker Pro license is active on the target site and that Popup Maker Pro is no=
t yet installed, as these conditions are necessary for the legacy v1/connec= t/info endpoint to issue the bearer token used to satisfy the install endpo= int's only non-spoofable validation check. 2026-07-09 7.2 CVE-2026-8848 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-8848 ] Dassault Systmes--DELMIA = Apriso An Improper Authentication vulnerability affecting DELMIA Apriso fro=
m Release 2020 through Release 2026 could allow an attacker to gain privile= ged access to the server. 2026-07-08 9.8 CVE-2026-9695 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-9695 ] decolua--9router 9Router is an AI router &=
token saver. Prior to 0.4.80, the /api/settings/database endpoint allows f= ull database export (containing all credentials, API keys, OAuth tokens, an=
d settings) and full database import (complete overwrite) without any authe= ntication requirement beyond the ALWAYS_PROTECTED middleware check, which o= nly validates JWT or CLI token. This issue is fixed in version 0.4.80. 2026= -07-10 9.9 CVE-2026-55500 [
https://www.cve.org/CVERecord?id=3DCVE-2026-555=
00 ] decolua--9router 9Router before 0.4.44 contains an OS command injectio=
n vulnerability in the unauthenticated POST /api/tunnel/tailscale-install e= ndpoint (this route is not covered by the dashboard middleware matcher, so =
no authorization check is applied). The sudoPassword field from the request=
body is written to the stdin of a 'sudo -S sh' child process. When sudo do=
es not prompt for a password (the process runs as root, NOPASSWD is configu= red, or a recent sudo timestamp cache exists), the sudoPassword value is in= terpreted by sh as a shell command, allowing a remote unauthenticated attac= ker to execute arbitrary OS commands. Exploitation evidence was first obser= ved by the Shadowserver Foundation on 2026-07-04 (UTC). 2026-07-07 9.8 CVE-= 2026-59800 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59800 ] decolua--9= router 9Router is an AI router & token saver. Prior to 0.5.2, 9router prote= cts /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omi=
ts /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A = remote unauthenticated attacker can send requests to /codex/* to bypass the=
API-key gate and cause the server to make upstream provider calls using op= erator-stored LLM provider credentials. This issue is fixed in version 0.5.=
2. 2026-07-10 8.6 CVE-2026-55638 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-55638 ] decolua--9router 9Router is an AI router & token saver. Prior t=
o 0.5.2, 9router determines whether a /v1 LLM proxy request is local by rea= ding the client-controlled Host header, allowing a remote unauthenticated a= ttacker to send Host: localhost and bypass API-key authentication. In the d= efault configuration, this exposes the /v1 proxy to upstream provider calls=
using stored provider credentials and allows /v1/search with the searxng p= rovider_options.baseUrl parameter to drive server-side requests to internal=
or cloud-metadata hosts. This issue is fixed in version 0.5.2. 2026-07-10 = 8.2 CVE-2026-55641 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55641 ] de= colua--9router 9Router is an AI router & token saver. Prior to 0.5.2, 9rout=
er treats loopback requests as trusted and allows /v1/* access without an A=
PI key, so a same-host reverse proxy that forwards public traffic to the ba= ckend through 127.0.0.1 causes src/dashboardGuard.js to misclassify externa=
l requests as local. A remote unauthenticated attacker can access /v1 APIs = such as /v1/models and may abuse configured upstream provider credentials t= hrough /v1 proxy endpoints depending on enabled providers. This issue is fi= xed in version 0.5.2. 2026-07-10 8.3 CVE-2026-56675 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-56675 ] decolua--9router 9Router is an AI router & t= oken saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/au= th/loginLimiter.js derives the client identity from the attacker-controlled=
X-Forwarded-For HTTP header, and src/app/api/auth/login/route.js uses that=
spoofable value for checkLock and recordFail. A remote attacker can rotate=
the X-Forwarded-For value on each login attempt to receive a fresh rate-li= mit bucket, bypass the 5-attempt threshold and progressive lockout duration=
s, and perform unlimited brute-force attempts against the dashboard passwor=
d. This issue is fixed in version 0.4.80. 2026-07-10 7.3 CVE-2026-55501 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-55501 ] decolua--9router 9Router=
is an AI router & token saver. Prior to 0.5.2, 9router validates image URL=
s by resolving the host before fetching, but open-sse/translator/concerns/i= mage.js performs the later server-side image fetch with a separate DNS reso= lution. An authenticated attacker with access to the LLM proxy can use a vi= sion-capable model and an attacker-controlled DNS name that first resolves =
to a public IP and then rebinds to an internal address, allowing server-sid=
e requests to internal-only HTTP services. This issue is fixed in version 0= .5.2. 2026-07-10 7.4 CVE-2026-56676 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-56676 ] Dell--PowerFlex Manager Dell PowerFlex Manager, Version prio=
r to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements use=
d in an OS Command ('OS Command Injection') vulnerability. A high privilege=
d attacker with remote access could potentially exploit this vulnerability = during OS Repository processing to achieve arbitrary command execution as r= oot, potentially leading to full appliance compromise and lateral movement = into managed infrastructure. 2026-07-10 9.1 CVE-2026-56688 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-56688 ] Dell--PowerFlex Manager Dell PowerFle=
x Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization =
of Special Elements used in an SQL Command ('SQL Injection') vulnerability.=
A low privileged attacker with remote access could potentially exploit thi=
s vulnerability, leading to Information disclosure, Information exposure, a=
nd Unauthorized access. 2026-07-10 8.5 CVE-2026-56690 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-56690 ] Dell--PowerFlex Manager Dell PowerFlex Man= ager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Sp= ecial Elements used in an SQL Command ('SQL Injection') vulnerability. A lo=
w privileged attacker with remote access could potentially exploit this vul= nerability, leading to Information exposure. 2026-07-10 7.7 CVE-2026-56689 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-56689 ] Dell--PowerProtect Da=
ta Domain Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2= 026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1=
.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 co= ntain an improper limitation of a pathname to a restricted directory ('Path=
Traversal') vulnerability. An unauthenticated attacker with remote access = could potentially exploit this vulnerability, leading to unauthorized acces=
s to the system. This is a critical severity vulnerability as it allows an = attacker to take complete control of system; so Dell recommends customers t=
o upgrade at the earliest opportunity. 2026-07-07 9.8 CVE-2026-53481 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-53481 ] Dell--PowerProtect Data Dom= ain Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 re= lease version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 thr= ough 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an impro= per authentication vulnerability. An unauthenticated attacker with remote a= ccess could potentially exploit this vulnerability, leading to unauthorized=
access. This is a critical severity vulnerability as it allows an attacker=
to take complete control of system; so Dell recommends customers to upgrad=
e at the earliest opportunity. 2026-07-07 9.8 CVE-2026-53483 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-53483 ] Dell--PowerProtect Data Domain Dell=
PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release ve= rsion 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3= .1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Incor= rect Authorization vulnerability. A low privileged attacker with remote acc= ess could potentially exploit this vulnerability, leading to unauthorized a= ccess. 2026-07-08 8.8 CVE-2026-56086 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-56086 ] Dell--PowerProtect Data Domain Dell PowerProtect Data Domai=
n, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.= 6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release v= ersions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vu= lnerability. An unauthenticated attacker with remote access could potential=
ly exploit this vulnerability. Exploitation may lead to information disclos= ure, session theft, or client-side request forgery. 2026-07-08 7.1 CVE-2026= -41122 [
https://www.cve.org/CVERecord?id=3DCVE-2026-41122 ] Dell--PowerPro= tect Data Domain Dell=C2=A0PowerProtect=C2=A0Data Domain, versions 7.7.1.0 = through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 rele= ase version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 thr= ough 7.13.1.70=C2=A0contain-an improper neutralization of special elements = used in an OS=C2=A0command ('OS=C2=A0command Injection') vulnerability.=C2= =A0A=C2=A0remote=C2=A0high=C2=A0privileged attacker could potentially explo=
it this vulnerability, leading to=C2=A0protection mechanism bypass.=C2=A0Th=
is is a Critical vulnerability as it allows an attacker=C2=A0to=C2=A0invoke=
arbitrary command execution with root privileges;=C2=A0so=C2=A0Dell recomm= ends customers to upgrade at the earliest opportunity. 2026-07-07 7.2 CVE-2= 026-53479 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53479 ] Dell--Power= Protect Data Domain Dell PowerProtect Data Domain, versions 7.7.1.0 through=
8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release ver= sion 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.= 13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthe= nticated attacker with remote access could potentially exploit this vulnera= bility, leading to denial of service. 2026-07-08 7.5 CVE-2026-53482 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-53482 ] Dell--Unisphere for PowerMax=
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a D= eserialization of Untrusted Data vulnerability. A low privileged attacker w= ith remote access could potentially exploit this vulnerability, leading to = arbitrary command execution with root privileges. 2026-07-10 8.8 CVE-2026-5= 4469 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54469 ] dgraph-io--dgrap=
h Dgraph is an open source distributed GraphQL database. Prior to version 2= 5.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on t=
he public gRPC port `:9080` without authentication or authorization. As a r= esult, an unauthenticated network client can open `StreamExtSnapshot` and s= end Badger stream data to the target group's store. In addition, the receiv=
er calls `Prepare()` before processing the stream. This operation deletes a=
nd replaces the existing DB data. Version 25.3.5 patches the issue. 2026-07= -08 9.1 CVE-2026-54061 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54061 =
] dgraph-io--dgraph Dgraph is an open source distributed GraphQL database. = Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is=
vulnerable to DQL (Dgraph Query Language) injection. User-supplied passwor=
d values are interpolated directly into a DQL `checkpwd()` query via `fmt.S= printf` without any escaping or parameterization. An attacker can inject a = password containing a double-quote character to break out of the DQL string=
literal and append arbitrary DQL query blocks. Version 25.3.4 patches the = issue. 2026-07-08 7.5 CVE-2026-44840 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-44840 ] discourse--discourse Discourse is an open-source discussion=
platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup = flow could allow newly registered users to set primary_group_id and gain wh= isper-group privileges without legitimate group membership on sites with wh= ispers_allowed_groups configured. This issue is fixed in versions 2026.6.0,=
2026.5.1, 2026.4.2, and 2026.1.5. 2026-07-09 8.2 CVE-2026-44787 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-44787 ] discourse--discourse Discourse =
is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.=
2, and 2026.1.5, a malicious second factor name on an attacker-controlled a= ccount was not escaped in the delete confirmation dialog, allowing stored c= ross-site scripting when an administrator impersonated that account. This i= ssue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. 2026-= 07-09 7.3 CVE-2026-53963 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5396=
3 ] discourse--discourse Discourse is an open-source discussion platform. P= rior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-defau=
lt configurations, processing of PDF uploads could be exploited to obtain R=
CE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, an=
d 2026.1.5. 2026-07-09 7.5 CVE-2026-55420 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-55420 ] Divi Engine--Divi Form Builder The Divi Form Builder p= lugin for WordPress is vulnerable to Missing Authorization in versions up t=
o, and including, 5.1.8. This is due to the update_user() function acceptin=
g a user ID parameter from form submissions without verifying that the auth= enticated user has permission to edit that specific user account, and the h= andle_register_submission() function only checking if any user is logged in=
rather than validating permissions for the target user. This makes it poss= ible for authenticated attackers, with subscriber-level access and above, t=
o change the email address and password of any user account, including admi= nistrators, resulting in complete account takeover. 2026-07-09 8.8 CVE-2026= -5523 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5523 ] e4jvikwp--VikBoo= king Hotel Booking Engine & PMS The VikBooking Hotel Booking Engine & PMS p= lugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's= pecial_requests' parameter in all versions up to, and including, 1.8.8 due =
to insufficient input sanitization and output escaping. This makes it possi= ble for unauthenticated attackers to inject arbitrary web scripts in pages = that will execute whenever a user accesses an injected page. 2026-07-08 7.2=
CVE-2026-6818 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6818 ] e4jvikw= p--VikBooking Hotel Booking Engine & PMS The VikBooking Hotel Booking Engin=
e & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting v=
ia the 'email' parameter in all versions up to, and including, 1.8.8 due to=
insufficient input sanitization and output escaping. This makes it possibl=
e for unauthenticated attackers to inject arbitrary web scripts in pages th=
at will execute whenever a user accesses an injected page. 2026-07-08 7.2 C= VE-2026-6820 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6820 ] elysiajs-= -elysia Elysia is a Typescript framework for request validation, type infer= ence, OpenAPI documentation, and client-server communication. Prior to 1.4.= 29, Elysia uses getAll in form data normalization for multipart/form-data e= ndpoints, causing the amount of work to grow quadratically with the number =
of unique key-value pairs and allowing CPU exhaustion. This issue is fixed =
in version 1.4.29. 2026-07-08 7.5 CVE-2026-56669 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-56669 ] espressif--esp-idf ESF-IDF is the Espressif Int= ernet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, = 5.3.5, and possibly prior contain an out-of-bounds write in jpeg_parse_dqt_= marker() in components/esp_driver_jpeg/jpeg_parse_marker.c because the atta= cker-controlled DQT marker Tq nibble is used as an index into the qt_tbl ar= ray without validating that it is in the range 0..3, allowing malformed JPE=
G input to corrupt stack memory and reliably trigger a denial of service. T= his issue is fixed in version 6.0.2 and is expected to be fixed in versions=
5.5.5, 5.4.5, and 5.3.6. 2026-07-10 7.5 CVE-2026-55687 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-55687 ] Esri--ArcGIS Server Esri ArcGIS Server c= ontains a directory traversal vulnerability. ArcGIS Enterprise on Kubernete=
s is not impacted. An unauthenticated attacker could exploit this issue by = sending crafted path parameters. Successful exploitation could allow overwr= iting sensitive files on the system. Abuse of this issue can allow full adm= inistrative access to ArcGIS Server, with high impact to confidentiality, i= ntegrity, and availability. This issue impacts all versions of ArcGIS Serve=
r on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS En= terprise for Kubernetes. 2026-07-06 9.8 CVE-2026-9181 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-9181 ] Esri--ArcGIS Server Esri ArcGIS Server cont= ains an unrestricted file upload vulnerability. An unauthenticated attacker=
could exploit this issue by uploading a crafted file to the affected endpo= int. Successful exploitation could allow arbitrary file upload, potentially=
allowing for other attacks. This issue impacts all versions of ArcGIS Serv=
er on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS E= nterprise for Kubernetes. 2026-07-06 9.8 CVE-2026-9182 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-9182 ] Esri--Portal for ArcGIS Esri Portal for Ar= cGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a miss= ing authentication for critical function vulnerability allows a remote, una= uthenticated attacker to access an unprotected API. 2026-07-07 9.8 CVE-2026= -13019 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13019 ] Esri--Portal f=
or ArcGIS A Weak Password Recovery Mechanism for Forgotten Password exists =
in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and K= ubernetes. A remote, unauthorized attacker may assume ownership of a user's=
account by manipulating this mechanism. ArcGIS Administrators should confi= gure an email server with ArcGIS Enterprise to facilitate user self-service=
password recovery. The ability for an administrator to reset a user's pass= word remains unchanged. 2026-07-07 8.1 CVE-2026-13020 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-13020 ] EverMind-AI--EverOS EverOS is a memory run= time for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in = the POST /api/v1/memory/add ingestion endpoint because the per-message send= er_id field was not validated as a path-safe identifier, unlike app_id and = project_id. During user-memory extraction, sender_id is used as owner_id an=
d joined into the filesystem path where the extracted episode is persisted =
as a Markdown file, so a sender_id containing ../ sequences could direct wr= ites outside the configured memory root and allow an unauthenticated caller=
to create or overwrite .md files at locations writable by the server proce=
ss with partially attacker-influenced content. This issue is fixed in versi=
on 1.0.1. 2026-07-10 8.2 CVE-2026-58499 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-58499 ] flaskbb--flaskbb FlaskBB through 2.2.0, fixed in commit=
acc88cf, contains an authorization bypass vulnerability that allows authen= ticated moderators to perform unauthorized actions on topics in forums they=
do not control by submitting crafted topic ID lists. Attackers can include=
a low-ID topic from a permitted forum as an anchor in a batch request, cau= sing the permission check applied only to the first result to pass, and the=
n execute lock, unlock, delete, or hide actions against topics in unmoderat=
ed forums. 2026-07-10 8.1 CVE-2026-22659 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-22659 ] flaskbb--flaskbb FlaskBB through 2.2.0, fixed in commit=
a5da9a5, contains a logic flaw vulnerability that allows authenticated adm= inistrators to delete all built-in authorization groups by exploiting a typ=
e mismatch in the bulk delete protection check. The bulk AJAX endpoint in t=
he management views compares received JSON integer group IDs against string=
literals, causing the protection check to always pass, which allows deleti=
on of all six built-in groups and destroys the forum's permission model, po= tentially rendering the site unusable. 2026-07-10 7.2 CVE-2026-22660 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-22660 ] Flowise--Flowise Flowise be= fore 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded defau=
lt JWT secrets ('auth_token', 'refresh_token') and default audience and iss= uer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication=
middleware (packages/server/src/enterprise/middleware/passport/index.ts). = When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_RE= FRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application = silently falls back to these publicly known defaults, allowing an attacker =
to forge valid JWTs and impersonate any user, including administrators, res= ulting in authentication bypass. 2026-07-12 9.8 CVE-2026-56271 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-56271 ] fluent--fluentd Fluentd collects = events from various data sources and writes them to files, RDBMS, NoSQL, Ia= aS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically con= structing file paths using the ${tag} placeholder, and insufficient validat= ion of ${tag} in file configurations such as the path parameter of the out_= file plugin allows attackers sending untrusted tags containing path travers=
al characters to write or overwrite arbitrary files and potentially achieve=
remote code execution. This issue is fixed in version 1.19.3. 2026-07-08 9=
.8 CVE-2026-44024 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44024 ] flu= ent--fluentd Fluentd collects events from various data sources and writes t= hem to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, = Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics an=
d plugin information via a REST API, and responses from /api/plugins.json a=
nd related endpoints unintentionally include internal instance variables th=
at may contain database passwords, API keys, or cloud credentials. This iss=
ue is fixed in version 1.19.3. 2026-07-08 7.5 CVE-2026-44025 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-44025 ] fluent--fluentd Fluentd collects ev= ents from various data sources and writes them to files, RDBMS, NoSQL, IaaS=
, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward=
plugins support gzip-compressed data but enforce limits only on compressed=
payloads through settings such as body_size_limit and chunk_size_limit, al= lowing crafted compressed payloads to decompress in memory to an excessive = size and cause denial of service through memory exhaustion. This issue is f= ixed in version 1.19.3. 2026-07-08 7.5 CVE-2026-44160 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-44160 ] fluent--fluentd Fluentd collects events fr=
om various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS,=
Hadoop and so on. Prior to 1.19.3, the Fluentd out_http output plugin allo=
ws placeholders such as ${tag} in the endpoint configuration parameter, and=
if a placeholder value is derived from untrusted input an attacker can con= trol the destination hostname of outbound HTTP requests and force requests =
to arbitrary internal services. This issue is fixed in version 1.19.3. 2026= -07-08 7.2 CVE-2026-44161 [
https://www.cve.org/CVERecord?id=3DCVE-2026-441=
61 ] Flux159--mcp-server-kubernetes MCP Server Kubernetes before 3.9.0 cont= ains an argument injection vulnerability in structured tools (kubectl_get, = kubectl_describe, kubectl_delete) that allows attackers to bypass the asser= tNoDangerousFlags security check by supplying resourceType and name paramet= ers with leading dashes. Attackers can inject the --server flag to redirect=
kubectl commands to an attacker-controlled API server, causing the operato= r's bearer token to be transmitted externally and enabling full cluster com= promise. 2026-07-10 9.8 CVE-2026-61459 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-61459 ] FluxInk--Color Management Driver FluxInk (formerly Suni=
a SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 all= ows local privilege escalation for a standard user account via arbitrary ph= ysical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. = The fixed driver is currently available in the Windows 11 25H2 HLK (Hardwar=
e Lab Kit). The fixed driver may be available through Windows Update or fro=
m Lenovo directly. 2026-07-07 7.1 CVE-2026-58583 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-58583 ] Foxit Software Inc.--Foxit PDF Editor The user-= controllable executable files will be directly executed by high-privilege p= rocesses, allowing low-privilege users to have the opportunity to elevate t= heir privileges to NT AUTHORITY\SYSTEM. 2026-07-08 8.2 CVE-2026-57239 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-57239 ] Foxit Software Inc.--Foxit=
PDF Editor The embedded JavaScript in the PDF deleted the pages, making th=
e object invalid. The application attempted to perform a write operation on=
the invalid pop-up annotations, resulting in the program crashing. 2026-07= -08 7.8 CVE-2026-13126 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13126 =
] Foxit Software Inc.--Foxit PDF Editor The application opens the PDF file.=
JavaScript then rewrites the document to modify the page structure, result= ing in the invalidation of the page objects. However, the thumbnails still = use the invalid page objects, ultimately causing the application to crash. = 2026-07-08 7.8 CVE-2026-13127 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -13127 ] Foxit Software Inc.--Foxit PDF Editor Embedding JavaScript within =
a PDF file will cause the page to be deleted. Subsequent scripts will conti= nue to access the relevant properties of the document view, eventually lead= ing to the crash of the application. 2026-07-08 7.8 CVE-2026-13128 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-13128 ] Foxit Software Inc.--Foxit PD=
F Editor When the application opens a PDF file, JavaScript uses the damaged=
field tree to trigger field traversal, resulting in the program holding an=
invalid form object when accessing the field property path. Eventually, th=
e application crashes due to reading an invalid pointer. 2026-07-08 7.8 CVE= -2026-13129 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13129 ] Foxit Sof= tware Inc.--Foxit PDF Editor When the application opens a PDF and JavaScrip=
t modifies the properties of form fields, it causes the state of the underl= ying objects referenced by the program to become invalid. Eventually, it re= ads an illegal memory address, which leads to the crash of the application.=
2026-07-08 7.8 CVE-2026-57237 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-57237 ] Foxit Software Inc.--Foxit PDF Editor After the application opene=
d the PDF, JavaScript deleted the form field object. Subsequently, it attem= pted to access the invalid object, which caused the application to crash. 2= 026-07-08 7.8 CVE-2026-57238 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 57238 ] Foxit Software Inc.--Foxit PDF Editor When the application opens a = PDF file and JavaScript deletes the PDF fields, the subsequent logic still = uses the old field pointers, resulting in invalid pointer references and ca= using the application to crash. 2026-07-08 7.8 CVE-2026-57240 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-57240 ] Foxit Software Inc.--Foxit PDF Edi= tor The application opens the PDF, and JavaScript modifies the form. Howeve=
r, the related objects on the page lack complete lifecycle management and n= ull value validation; when the page state changes, the application continuo= usly dereferences invalid objects, eventually leading to a crash. 2026-07-0=
8 7.8 CVE-2026-57242 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57242 ] = Foxit Software Inc.--Foxit PDF Editor After JavaScript resetting the form, = the synchronization process lacks re-entry protection and object lifecycle = verification, resulting in the failure of the control pointer during the tr= aversal process. After the pointer fails, it still continues to dereference=
, causing the application to crash. 2026-07-08 7.8 CVE-2026-57244 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-57244 ] Foxit Software Inc.--Foxit PDF=
Editor When the application opens a PDF, traverses and builds the annotati=
on elements related to hyperlinks, it fails to validate the abnormal annota= tion relationships and field combinations. This results in the internal obj= ects entering an invalid state. Eventually, during the destruction phase, a=
n invalid pointer write occurred, causing the application to crash. 2026-07= -08 7.8 CVE-2026-57245 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57245 =
] Foxit Software Inc.--Foxit PDF Editor When dealing with abnormally constr= ucted objects, there is a lack of argument validation; JavaScript triggers = signature verification, but the signature plugin does not perform validatio=
n when copying the abnormal string, causing the application to crash. 2026-= 07-08 7.8 CVE-2026-57246 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5724=
6 ] Foxit Software Inc.--Foxit PDF Editor The application re-enters the doc= ument structure via field processing and deletes the current page, and then=
continues using the field objects obtained before deletion, triggering an = illegal read and crashing. 2026-07-08 7.8 CVE-2026-57247 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-57247 ] Foxit Software Inc.--Foxit PDF Editor W= hen the application opens a PDF file and JavaScript writes annotation attri= butes, there is a lack of sufficient object type and argument checks. As a = result, due to the damage to the internal structure of the annotations, it = causes the application to crash during subsequent release. 2026-07-08 7.8 C= VE-2026-57248 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57248 ] Foxit S= oftware Inc.--Foxit PDF Editor After the application opened the PDF file, t=
he script first reset the annotation status, then triggered the reset form = event by additional action. During the re-entry process, the application ac= cess invalid objects and crashed. 2026-07-08 7.8 CVE-2026-57249 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-57249 ] Foxit Software Inc.--Foxit PDF E= ditor When the application opens a PDF and JavaScript resets the form field=
s, the script re-enters the interface. The underlying native object is dama= ged, but the application does not perform validation. The function call on = the damaged object leads to the application crashing. 2026-07-08 7.8 CVE-20= 26-57250 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57250 ] Foxit Softwa=
re Inc.--Foxit PDF Editor The application opens a PDF, but the cloud-like a= ppearance of the construction process lacks proper setting of an upper limi=
t and consistency checks. Out-of-bounds access to the underlying array is e= xposed, ultimately leading to a crash of the application. 2026-07-08 7.8 CV= E-2026-57251 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57251 ] Foxit So= ftware Inc.--Foxit PDF Editor When the application opens a PDF file, during=
the process of JavaScript deleting pages and removing attachment annotatio= ns, it will cause the attachment panel to continue accessing invalid pointe= rs, eventually leading to the application crashing. 2026-07-08 7.8 CVE-2026= -57252 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57252 ] Foxit Software=
Inc.--Foxit PDF Editor There is an abnormal annotation within the PDF that=
is referenced by other objects. When the application parses the PDF, it fa= ils to perform proper type checking, ultimately causing the application to = crash. 2026-07-08 7.8 CVE-2026-57254 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-57254 ] Foxit Software Inc.--Foxit PDF Editor When the application = opens a PDF and executes JavaScript, it performs abnormal operations on the=
list box field, and this operation is repeated after the form is reset. Du= ring this process, the application failed to adequately verify the validity=
of the form objects and their internal dictionary pointers, resulting in a= ccessing internal members of invalid or improperly initialized fields. This=
led to an illegal pointer read, ultimately causing the application to cras=
h. 2026-07-08 7.8 CVE-2026-57256 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-57256 ] Foxit Software Inc.--Foxit PDF Editor The application opened a = PDF file containing an abnormal Unity 3D object. During parsing, the applic= ation incorrectly resolved a portion of the abnormal object as a pointer an=
d used it as a valid address, ultimately causing the application to crash. = 2026-07-08 7.8 CVE-2026-57260 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -57260 ] FreeRDP--FreeRDP FreeRDP is a free implementation of the Remote De= sktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-defa= ult /cache:codec:rfx option pass desktop stride and height to RemoteFX deco= ding for Cache Bitmap V3 data while allocating bitmap->data only for the sm= aller DstWidth and DstHeight in gdi_Bitmap_Decompress, allowing a malicious=
RDP server to trigger a heap out-of-bounds write with attacker-controlled = offset and content. This issue is fixed in version 3.27.1. 2026-07-10 7.5 C= VE-2026-55827 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55827 ] FreeRDP= --FreeRDP FreeRDP before 3.22.0 contains a use-after-free vulnerability in = dvcman_channel_close and dvcman_call_on_receive due to improper synchroniza= tion of channel_callback access. A malicious RDP server can trigger a race = condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, caus= ing heap-use-after-free in the drdynvc client thread and potentially enabli=
ng remote code execution or denial of service. 2026-07-08 7 CVE-2026-56297 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-56297 ] Genetec Inc.--Genetec=
Security Center A flaw in the authentication mechanism for video stream re= quests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may a= llow an unauthenticated attacker to access live video streams. 2026-07-06 7=
.5 CVE-2026-55727 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55727 ] gen= olve--Genolve Genolve AI Business Graphics, AI Images The Genolve - AI imag=
e AI video generation plugin for WordPress is vulnerable to unauthorized mo= dification of data due to a missing capability check on the genolve_setOpt(=
) function in all versions up to, and including, 5.0.5. This makes it possi= ble for authenticated attackers, with Contributor-level access and above, t=
o update arbitrary WordPress options, including enabling user registration = and setting the default role to administrator, resulting in privilege escal= ation. 2026-07-11 8.8 CVE-2026-1359 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-1359 ] getgrav--grav Grav API plugin before v1.0.0-rc.16 accepts JWT=
tokens via the ?token=3D URL query parameter and responds with Access-Cont= rol-Allow-Origin: *, allowing unauthenticated attackers to make fully authe= nticated cross-origin API requests from any malicious website. Attackers wh=
o obtain a leaked JWT token from access logs, proxy logs, browser history, =
or Referrer headers can create persistent backdoor super-admin accounts and=
exfiltrate sensitive configuration and user data. 2026-07-08 7.5 CVE-2026-= 58656 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58656 ] getwpfunnels--W= PFunnels Funnel Builder for WooCommerce with Checkout & One Click Upsell Th=
e WPFunnels - Funnel Builder for WooCommerce with Checkout & One Click Upse=
ll plugin for WordPress is vulnerable to Remote Code Execution in all versi= ons up to, and including, 3.12.7 via the 'postData' parameter parameter. Th=
is is due to unsanitized write of attacker-controlled postData values into =
a PHP-includeable .log file combined with the use of include_once to render=
that file in wpfnl_show_log. This makes it possible for unauthenticated at= tackers to execute code on the server. Exploitation requires that the Log S= ettings "Enable Logs" toggle is on and that an administrator subsequently o= pens the polluted log file via the plugin's Log Settings View UI; however, = the nonce required to reach the optin endpoint is publicly emitted on every=
funnel step page, so the injection step itself is fully unauthenticated. 2= 026-07-07 9.8 CVE-2026-14345 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 14345 ] ghostfolio--ghostfolio The GET /api/v1/public/:accessId/portfolio e= ndpoint in ghostfolio accepts private access IDs without validating grantee= UserId filtering, allowing unauthenticated access to full portfolio data. A= ttackers with a private access ID can retrieve sensitive portfolio informat= ion including holdings, quantities, buy prices, and performance metrics wit= hout authentication. 2026-07-07 7.5 CVE-2026-59708 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-59708 ] GitLab--GitLab GitLab has remediated an issue=
in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before=
19.0.4, and 19.1 before 19.1.2 that under certain conditions could have al= lowed an authenticated user with developer-role permissions to execute arbi= trary scripts in another user's browser session due to improper sanitizatio=
n of user-supplied input. 2026-07-08 8.7 CVE-2026-6896 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-6896 ] GitLab--GitLab GitLab has remediated an is= sue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 b= efore 19.0.4, and 19.1 before 19.1.2 that under certain conditions could ha=
ve allowed an authenticated user to execute arbitrary scripts in another us= er's browser session due to improper sanitization of user-supplied input. 2= 026-07-08 7.3 CVE-2026-13320 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 13320 ] globalprogramming--WHMCS Bridge The WHMCS Bridge plugin for WordPre=
ss is vulnerable to arbitrary file uploads due to missing file type validat= ion in the connect() function in all versions up to, and including, 6.9. Th=
is makes it possible for authenticated attackers, with Custom-level access = and above, to upload arbitrary files on the affected site's server which ma=
y make remote code execution possible. 2026-07-08 8.8 CVE-2026-14489 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-14489 ] gnuwget--wget GNU Wget thro= ugh 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulne= rability in the clean_metalink_string() function within src/metalink.c that=
allows a malicious server to trigger memory corruption by serving a Metali=
nk document containing a whitespace-only URL. Attackers can cause the funct= ion to decrement a pointer past the start of the buffer when processing an = all-whitespace Metalink URL, potentially leading to abnormal program behavi= or. 2026-07-07 7.5 CVE-2026-58469 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-58469 ] gotenberg--gotenberg Gotenberg is a Docker-powered stateless A=
PI for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert e= ndpoint allows a specially crafted document to cause LibreOffice to automat= ically retrieve external HTTP(S) resources and local file resources during = document conversion, enabling blind SSRF and limited local file disclosure = via linked image resource loading. This issue is fixed in version 8.34.0. 2= 026-07-10 7.5 CVE-2026-55229 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 55229 ] gradio-app--gradio Gradio before 6.20.0 contains an open redirect a=
nd server-side request forgery vulnerability that allows attackers to redir= ect users to arbitrary URLs or perform client-side SSRF by supplying unvali= dated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file=
=3D endpoint. Attackers can craft a malicious FileData response targeting i= nternal endpoints such as cloud metadata services to retrieve sensitive cre= dentials including EC2 IAM role credentials. 2026-07-08 7.4 CVE-2026-59806 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-59806 ] Grafana--Grafana OSS = Several Grafana API endpoints, some of them unauthenticated, do not limit t=
he size of the request body before processing it. An attacker can send very=
large payloads that force excessive memory allocation, potentially exhaust= ing memory and causing a denial of service. 2026-07-10 7.5 CVE-2026-33382 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-33382 ] gristlabs--grist-core = Grist is spreadsheet software using Python as its formula language. Prior t=
o 1.7.15, several server-rendered Grist pages embedded user-controlled valu=
es into the page and into inline scripts without fully escaping them, allow= ing cross-site scripting. On the main application page, a document's name o=
r description, set by a document editor, is rendered into the page that oth=
er users load when opening the document. On the OAuth2 end-of-flow page, th=
e openerOrigin request parameter was reflected back into the served page. I= njected script runs in the victim's Grist origin and can act through the au= thenticated session, reading or modifying data and changing sharing setting=
s and access rules. A document editor could therefore escalate to owner-lev=
el access. This issue is fixed in version 1.7.15. 2026-07-10 7.7 CVE-2026-5= 5659 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55659 ] grokability--sni= pe-it Snipe-IT is an IT asset/license management system. Prior to 8.6.2, th=
e Accessories API create path mass-assigns request parameters to the Access= ory model while company_id is mass assignable, allowing a low-privileged au= thenticated user in one company to create accessory records under another c= ompany when Full Multiple Companies Support is enabled. This issue is fixed=
in version 8.6.2. 2026-07-10 8.5 CVE-2026-54329 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-54329 ] grokability--snipe-it Snipe-IT is an IT asset/l= icense management system. Prior to 8.6.2, an authenticated non-admin user w= ith users.view and users.edit but without users.delete can directly POST to=
/users/bulksave with delete_user=3D1 because BulkUsersController::destroy(=
) authorizes only update, allowing the user to soft-delete another non-admi=
n user. This issue is fixed in version 8.6.2. 2026-07-10 7.1 CVE-2026-55460=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-55460 ] grokability--snipe-i=
t Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH =
or PUT /api/v1/maintenances/{maintenance_id} checks access to the current m= aintenance record and asset but then fills attacker-controlled fields inclu= ding asset_id without re-authorizing the newly supplied asset, allowing an = authorized user to move a maintenance record onto an asset outside their co= mpany scope. This issue is fixed in version 8.6.2. 2026-07-10 7.7 CVE-2026-= 55516 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55516 ] h2o--h2o h2o is=
an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to comm=
it edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK ins= truction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate a=
n on-stack buffer as large as approximately 800 KB by calling alloca, which=
exceeds the default pthread stack size used by musl libc and causes the h2=
o server to crash with a segmentation fault while touching the guard page. = This issue is fixed in commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1. 202= 6-07-10 7.5 CVE-2026-55213 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55= 213 ] H3C--NX15 A vulnerability was found in H3C NX15 V100R017. Affected by=
this vulnerability is the function change_passwd of the file /api/login/mo= dify of the component Administrator Password Modification Endpoint. The man= ipulation of the argument newPass results in weak password recovery. The at= tack may be launched remotely. The exploit has been made public and could b=
e used. The vendor was contacted early about this disclosure. 2026-07-12 7.=
3 CVE-2026-15479 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15479 ] hapi= fhir--org.hl7.fhir.core HAPI FHIR is a complete implementation of the HL7 F= HIR standard for healthcare interoperability in Java. Prior to 6.9.10, the = fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRP= athEngine.matches() in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call=
raw String.matches(sw) without RegexTimeout protection while replaceMatche= s() was updated, allowing an unauthenticated attacker to trigger catastroph=
ic regex backtracking and exhaust server CPU. This issue is fixed in versio=
n 6.9.10. 2026-07-08 7.5 CVE-2026-55470 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55470 ] HashiCorp--Nomad HashiCorp Nomad and Nomad Enterprise a=
re vulnerable to a sandbox escape in the Docker task driver that may allow =
a job submitter to bind-mount a host path into a container even when volume=
bind mounts are disabled, potentially leading to reading and writing files=
on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Communi=
ty Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. 2026-07-0=
8 8.7 CVE-2026-14891 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14891 ] = HashiCorp--Nomad HashiCorp Nomad and Nomad Enterprise did not enforce the a= llow_privileged restriction for the Docker task driver's host namespace mod=
e options. This may allow an authenticated job submitter to run a container=
in a host namespace and access information belonging to the host or to oth=
er workloads on the same client. This vulnerability, CVE-2026-14373, is fix=
ed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and=
1.10.14. 2026-07-08 7.7 CVE-2026-14373 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-14373 ] HashiCorp--Terraform Enterprise HashiCorp Terraform Ent= erprise contained an issue in its version control system (VCS) ingestion of=
registry modules that did not correctly enforce the intended boundary on p= ackaged module content. This may allow an authenticated user to include fil=
es from outside the intended repository content in a module and then downlo=
ad them, potentially exposing sensitive files readable by the ingestion pro= cess. This vulnerability, CVE-2026-14468, is fixed in Terraform Enterprise = v2.0.4 and v1.2.4. 2026-07-06 7.7 CVE-2026-14468 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-14468 ] HAVELSAN Inc.--Liman MYS Missing Authorization = vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not=
Properly Constrained by ACLs. This issue affects Liman MYS: before release= .Master.1107. 2026-07-07 8.3 CVE-2026-11340 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-11340 ] HAVELSAN Inc.--Liman MYS Improper verification of cr= yptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake = the Source of Data. This issue affects Liman MYS: before release.Master.110=
7. 2026-07-07 8.1 CVE-2026-11348 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-11348 ] HAVELSAN Inc.--Liman MYS Improper neutralization of special ele= ments used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN In=
c. Liman MYS allows LDAP Injection. This issue affects Liman MYS: before re= lease.Master.1107. 2026-07-07 8.8 CVE-2026-13696 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-13696 ] hcr707305003--shiroiAdmin A vulnerability was d= etermined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function Fil= eController::upload of the file app/common/controller/FileController.php. E= xecuting a manipulation of the argument File can lead to unrestricted uploa=
d. The attack may be launched remotely. The exploit has been publicly discl= osed and may be utilized. Upgrading to version 1.4 is able to address this = issue. This patch is called 3ecde28ea8a20a3840dbfefd6d6863ee79a83e70. It is=
suggested to upgrade the affected component. The vendor was contacted earl=
y about this disclosure but did not respond in any way. 2026-07-12 7.3 CVE-= 2026-15488 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15488 ] hestiacp--= hestiacp HestiaCP before 1.9.5 contains an authenticated OS command injecti=
on vulnerability that allows low-privilege authenticated users to execute a= rbitrary commands as root by injecting a single-quote character into unvali= dated DNS record types. Attackers can exploit insufficient input validation=
in is_dns_record_format_valid() combined with unsafe eval-based parsing in=
update_domain_zone() to prematurely close a variable assignment string and=
achieve full root code execution on the underlying host in a single DNS re= cord creation step. 2026-07-10 8.8 CVE-2025-30007 [
https://www.cve.org/CVE= Record?id=3DCVE-2025-30007 ] hoppscotch--hoppscotch Hoppscotch is an open s= ource API development ecosystem. Prior to 2026.6.0, mock server creation in=
mock-server.service.ts does not persist the isPublic input field while sch= ema.prisma defaults isPublic to true, causing mock servers linked to privat=
e collections to be publicly accessible without authentication and potentia= lly expose sensitive API data. This issue is fixed in version 2026.6.0. 202= 6-07-09 7.5 CVE-2026-59720 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59= 720 ] hoppscotch--hoppscotch Hoppscotch is an open source API development e= cosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in adm= in/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, = and validateSMTPUrl in utils.ts permits path, query, or fragment content th=
at nodemailer parses into sendmail transport options, allowing an admin to = execute arbitrary commands as root in the backend container after restart a=
nd mail sending. This issue is fixed in version 2026.6.0. 2026-07-09 7.2 CV= E-2026-59721 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59721 ] horde--V=
fs Horde Virtual File System (VFS) API before 3.0.1 contains an OS command = injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellC= ommand() method fails to sanitize command substitution sequences, allowing = authenticated attackers to inject arbitrary shell commands through user-con= trolled filenames. Attackers can supply malicious filenames containing unes= caped command substitution payloads through operations such as file upload,=
folder creation, rename, or deletion, which are interpolated into a double= -quoted shell context and executed via proc_open() through /bin/sh -c befor=
e smbclient runs, resulting in arbitrary command execution on the underlyin=
g system. 2026-07-08 8.8 CVE-2026-60102 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-60102 ] httplib2--httplib2 httplib2 is a comprehensive HTTP cli= ent library for Python. Prior to 0.32.0, httplib2 performs unbounded decomp= ression of HTTP response bodies encoded with Content-Encoding: gzip or defl= ate in _decompressContent in httplib2/init.py, allowing a malicious or comp= romised HTTP server to return a small compressed payload that expands to an=
arbitrarily large size in memory and causes MemoryError or OOM-kill in the=
client process. This issue is fixed in version 0.32.0. 2026-07-08 7.5 CVE-= 2026-59939 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59939 ] Hydro-Qube= c--Le Circuit Electrique charging station backend The charging station webs= ocket endpoint accepts connections without proper authentication, which cou=
ld lead to privilege escalation. 2026-07-10 9.8 CVE-2026-20744 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-20744 ] Hydro-Qubec--Le Circuit Electriqu=
e charging station backend Previously, there was no throttling on repeated = authentication attempts to the charging station backend, which could allow =
an attacker to execute a denial-of-service attack. 2026-07-10 7.5 CVE-2026-= 42952 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42952 ] Hydro-Qubec--Le=
Circuit Electrique charging station backend Multiple connections to the ba= ckend using the same charging station ID are allowed, which could allow an = attacker to deploy multiple instances of malicious OCPP clients to overwhel=
m the backend. 2026-07-10 7.5 CVE-2026-44383 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-44383 ] IBM--API Connect IBM API Connect 10.0.8.0 through 1= 0.0.8.9 and=C2=A012.1.0.0 through 12.1.0.3=C2=A0contains an unauthenticated=
SQL injection vulnerability in the password reset functionality. 2026-07-0=
8 9.1 CVE-2026-9074 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9074 ] IB= M--API Connect IBM API Connect 12.1.0.0 through 12.1.0.3 uses default crede= ntials which could allow an attacker to gain unauthorized access to the app= lication before the system enforces a credential update. 2026-07-08 8.1 CVE= -2026-3144 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3144 ] Idvlabs Sof= tware and Consulting Services Inc.--Ontime Authorization bypass through Use= r-Controlled key vulnerability in Idvlabs Software and Consulting Services = Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects = Ontime: through 04052026. 2026-07-07 7.5 CVE-2026-5730 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-5730 ] Idvlabs Software and Consulting Services I= nc.--Ontime Authorization bypass through User-Controlled key vulnerability =
in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation=
of Trusted Identifiers. This issue affects Ontime: through 04052026. 2026-= 07-07 7.5 CVE-2026-5799 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5799 =
] Inrove Software and Internet Services--BiEticaret Improper neutralization=
of special elements used in an SQL command ('SQL injection') vulnerability=
in Inrove Software and Internet Services BiEticaret allows SQL Injection. = This issue affects BiEticaret: before v3.3.57. 2026-07-09 9.8 CVE-2026-5955=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-5955 ] JetBrains--IntelliJ I= DEA In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via p= ath traversal in project workspace ID handling was possible 2026-07-10 9.6 = CVE-2026-59792 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59792 ] JetBra= ins--TeamCity In JetBrains TeamCity before 2026.1.2 arbitrary file access w=
as possible via the Perforce VCS integration 2026-07-10 8.8 CVE-2026-59793 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-59793 ] JetBrains--TeamCity I=
n JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent r= egistration was possible 2026-07-10 8.1 CVE-2026-59795 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-59795 ] JetBrains--TeamCity In JetBrains TeamCity=
before 2026.1.2 pipeline modification was possible due to improper permiss= ion checks 2026-07-10 8.1 CVE-2026-59796 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-59796 ] JetBrains--TeamCity In JetBrains TeamCity before 2026.1=
.2 stored XSS on the cloud profile page was possible via agent-reported dat=
a 2026-07-10 7.3 CVE-2026-59794 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-59794 ] jknack--handlebars.java Handlebars.java provides logic-less and = semantic Mustache templates with Java. Prior to 4.5.2, applications that pa=
ss user-controlled input to Handlebars.compile() using FileTemplateLoader o=
r ClassPathTemplateLoader are vulnerable to path traversal, allowing arbitr= ary file read through template names derived from URL path parameters, requ= est parameters, or other user-controlled sources. This issue is fixed in ve= rsion 4.5.2. 2026-07-08 7.5 CVE-2026-55760 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-55760 ] joe007--Eventer The Eventer plugin for WordPress is v= ulnerable to an insecure password reset mechanism in all versions up to, an=
d including, 4.4.2. The plugin stores a plaintext copy of the password rese=
t key in the `eventer_verification_code` user meta field when a user reques=
ts a password reset. The plaintext key stored in `wp_usermeta` can be used = with the plugin's custom reset action to set a new password for any user. C= ombined with another vulnerability such as SQL Injection (CVE-2026-9700), t= his makes it possible for unauthenticated attackers to extract the plaintex=
t reset key and take over any user account, including administrators. Note:=
The password reset function only works up to PHP version 7.4. 2026-07-08 9=
.8 CVE-2026-9701 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9701 ] joe00= 7--Eventer The Eventer plugin for WordPress is vulnerable to time-based SQL=
Injection via the 'code' parameter in all versions up to, and including, 4= .4.2 due to insufficient escaping on the user supplied parameter and lack o=
f sufficient preparation on the existing SQL query. This makes it possible = for unauthenticated attackers to append additional SQL queries into already=
existing queries that can be used to extract sensitive information from th=
e database. 2026-07-08 7.5 CVE-2026-9700 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-9700 ] joedolson--My Calendar Accessible Event Manager The My C= alendar - Accessible Event Manager plugin for WordPress is vulnerable to ti= me-based blind SQL Injection via the 'mc_auth' parameter in all versions up=
to, and including, 3.7.8 due to insufficient escaping on the user supplied=
parameter and lack of sufficient preparation on the existing SQL query. Th=
is makes it possible for unauthenticated attackers to append additional SQL=
queries into already existing queries that can be used to extract sensitiv=
e information from the database. 2026-07-08 7.5 CVE-2026-6854 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-6854 ] joeyoungblood--WP Business Intellig= ence Lite The WP Business Intelligence Lite plugin for WordPress is vulnera= ble to authorization bypass in all versions up to, and including, 3.2.0. Th=
is is due to the plugin not properly verifying that a user is authorized to=
perform an action. This makes it possible for authenticated attackers, wit=
h Subscriber-level access and above, to modify stored SQL queries, which ca=
n lead to privilege escalation via arbitrary SQL execution when the modifie=
d query is viewed by an administrator. 2026-07-10 8 CVE-2026-15293 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-15293 ] jssor--Jssor Slider by jssor.= com The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Dir= ectory Traversal in all versions up to, and including, 3.1.24 via the 'url'=
parameter parameter. This makes it possible for unauthenticated attackers =
to read the contents of arbitrary files on the server, which can contain se= nsitive information. 2026-07-08 7.5 CVE-2026-14244 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-14244 ] Juniper Networks--Junos OS An Improper Valida= tion of Specified Quantity in Input vulnerability in the TCP proxy plugin o=
f Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows a=
n unauthenticated, network-based attacker to cause a complete Denial of Ser= vice (DoS). When TCP proxy is engaged in a flow session, to support ALGs,= =C2=A0Advanced Anti-Malware, ICAP=C2=A0or UTM, a TCP packet with specifical=
ly malformed TCP header will cause flow processing daemon (flowd) to crash = and restart. This causes a complete service outage until the system has aut= omatically recovered. This issue affects Junos OS on MX with SPC3, and SRX = Series:=C2=A0 * 23.4 versions before 23.4R2-S7,=C2=A0 * 24.2 versions befor=
e 24.2R2-S4,=C2=A0 * 24.4 versions before 24.4R2-S3, * 25.2 versions before=
25.2R2. This issue does not affect releases before 23.4R1. 2026-07-09 7.5 = CVE-2026-57023 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57023 ] Junipe=
r Networks--Junos OS An Improper Validation of Syntactic Correctness of Inp=
ut vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Serie=
s with SPC3 and SRX Series allows an unauthenticated, network-based attacke=
r to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affect=
ed device, the processing of a malformed SIP invite packet will cause a flo=
w processing daemon (flowd) crash and restart. This leads to a complete ser= vice outage until the system has automatically recovered. This issue affect=
s Junos OS on MX Series with SPC3 and SRX Series: * all versions before 23.= 2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5,=
* 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 ve= rsions before 25.4R1-S2. 2026-07-09 7.5 CVE-2026-57026 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-57026 ] Juniper Networks--Junos OS Evolved An Imp= roper Restriction of Communication Channel to Intended Endpoints vulnerabil= ity in Juniper Networks Junos OS Evolved allows an unauthenticated, network= -based attacker to cause license exhaustion. Due to an incorrect initializa= tion, a process which should only be able to communicate internally within = the device, can be reached over the network via an open port. This leads to=
unauthorized access to the license management. This issue affects all Juno=
s OS Evolved versions before 23.2R2-EVO. 2026-07-09 7.3 CVE-2026-57028 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-57028 ] jupyterlab--jupyterlab-gi=
t JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyte= rlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_g= it/handlers.py to enforce excluded_paths, allowing an authenticated user on=
a case-insensitive filesystem to vary URL path casing and read excluded di= rectories. This issue is fixed in version 0.54.0. 2026-07-08 7.1 CVE-2026-5= 4528 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54528 ] krayin--laravel-= crm Krayin CRM through 2.2.3 contains an insecure direct object reference v= ulnerability in LeadController, PersonController, OrganizationController, Q= uoteController, and ActivityController that allows authenticated users to e= dit, update, or delete records owned by other users. Attackers can modify C=
RM records and reassign ownership by exploiting missing record-level owners= hip validation in edit, update, and destroy methods. 2026-07-10 8.8 CVE-202= 6-61460 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61460 ] Labcenter--Pr= oteus The application contains a use-after-free vulnerability that can be e= xploited to cause memory corruption while parsing specially crafted files. = This could allow an attacker to execute arbitrary code in the context of th=
e current process. 2026-07-07 7.8 CVE-2026-42958 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-42958 ] Labcenter--Proteus The application contains a s= tack-based buffer overflow vulnerability that can be exploited by an attack=
er to execute arbitrary code. 2026-07-07 7.8 CVE-2026-49033 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-49033 ] labring--FastGPT FastGPT is an open = source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file=
handlers authorize an unrelated resource and then sign or read an S3 objec=
t using a key taken directly from the request, without checking that the ke=
y belongs to the caller's team. Because S3 object keys are global within th=
e bucket and carry the tenant id only as a path segment, an attacker can su= pply another team's key and obtain its file contents through the chat-file = presign endpoint or dataset preview endpoint. This issue is fixed in versio=
n v4.15.0-beta5. 2026-07-07 8.6 CVE-2026-55418 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-55418 ] labring--FastGPT FastGPT is a knowledge-based AI = application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema i= mporter validates only the top-level URL before passing it to SwaggerParser= .bundle, whose remote reference resolver fetches $ref URLs without FastGPT'=
s internal-address guard and returns fetched content inline, allowing an au= thenticated team member to read internal services or cloud metadata. This i= ssue is fixed in version 4.15.0-beta4. 2026-07-07 7.7 CVE-2026-54607 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-54607 ] langchain4j--langchain4j La= ngChain4j is a Java library for building LLM-powered applications on the JV=
M. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, th=
e MariaDB and pgvector embedding stores build metadata-filter SQL by string= -concatenating filter keys, and in MariaDB string values, directly into the=
query without adequate escaping. A crafted metadata key in EmbeddingSearch= Request.filter() can break out of its SQL context and inject arbitrary SQL = into the statements executed by the stores' search and removeAll(Filter) op= erations, enabling blind data exfiltration, denial of service via sleep fun= ctions, and deletion of arbitrary rows through removeAll(Filter). This issu=
e is fixed in langchain4j-mariadb and langchain4j-pgvector versions 1.2.1-b= eta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26. 2026-07-10 7.6 CVE-20= 26-55405 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55405 ] langgenius--= dify Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the M= yScale vector store backend that allows attackers to execute arbitrary SQL =
by supplying unsanitized search parameters to the search_by_full_text metho=
d without escaping or parameterization. Attackers can inject malicious SQL = through the search parameters to read, modify, or delete data in the underl= ying ClickHouse database. 2026-07-10 8.8 CVE-2026-61461 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-61461 ] langroid--langroid Langroid is a framewo=
rk for building large-language-model-powered applications. Versions prior t=
o 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code=
Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. Wh=
en these agents evaluate LLM-generated tool messages with `full_eval=3DTrue=
`, they attempt to sandbox the execution by explicitly setting `locals` to =
an empty dictionary `{}` inside Python's `eval()` function. However, this r= elies on an incomplete understanding of Python's execution model. Because `= __builtins__` is not explicitly scrubbed from the `globals` dictionary mapp= ing, Python implicitly injects all built-ins during execution, granting ful=
l access to functions like `__import__('os').system()`. Since `TableChatAge= nt.pandas_eval()` executes external LLM outputs natively, this bypass permi=
ts any attacker providing prompt payload to achieve unauthenticated RCE on = the host system. Version 0.65.2 patches the issue. 2026-07-09 10 CVE-2026-5= 4769 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54769 ] langroid--langro=
id Langroid is a framework for building large-language-model-powered applic= ations. Prior to version 0.65.3, a Langroid application exposing a chat int= erface to untrusted users may allow direct tool invocation via raw JSON pay= loads, even when tools are registered with `use=3DFalse, handle=3DTrue`. Ve= rsion 0.65.3 fixes the issue. 2026-07-09 8.1 CVE-2026-54771 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-54771 ] langroid--langroid Langroid is a fra= mework for building large-language-model-powered applications. Prior to ver= sion 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat = `curr_dir` as the intended working-directory boundary for file operations. = However, the tools only change the process working directory to `curr_dir` = and then operate on the user-supplied `file_path` without resolving and enf= orcing that the final path remains inside `curr_dir`. As a result, a tool c= aller can supply path traversal sequences such as `../secret.txt` to read f= iles outside the configured current directory, or `../written_by_tool.txt` =
to write files outside that directory. This can impact applications that ex= pose Langroid file tools to an LLM agent, user-controlled tool call, or del= egated coding/documentation agent while relying on `curr_dir` to restrict f= ile access to a project/workspace directory. Version 0.64.0 patches the iss= ue. 2026-07-09 7.1 CVE-2026-50181 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-50181 ] latepoint--LatePoint Calendar Booking Plugin for Appointments = and Events The LatePoint - Calendar Booking Plugin for Appointments and Eve= nts plugin for WordPress is vulnerable to Improper Input Validation in all = versions up to, and including, 5.4.0. This is due to the plugin's Stripe Co= nnect payment processor accepting a client-supplied PaymentIntent ID. This = makes it possible for unauthenticated attackers to pay an arbitrary amount =
by supplying a previously succeeded PaymentIntent token. 2026-07-08 7.5 CVE= -2026-5356 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5356 ] Leantime--L= eantime Leantime's Users::getUser method in the JSON-RPC API lacks proper a= uthorization checks, allowing authenticated users to retrieve full user cre= dential rows including password hashes, TOTP secrets, and session tokens. A= ttackers can exploit this by calling users.getUser with arbitrary user IDs =
to enumerate all accounts and obtain credentials for offline password crack= ing, 2FA bypass, and session hijacking. 2026-07-06 8.1 CVE-2026-59712 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-59712 ] Leantime--Leantime Leantim=
e contains an OIDC login CSRF vulnerability in the verifyState() method tha=
t unconditionally returns true without validating state parameters. Attacke=
rs can craft malicious callback URLs with attacker-controlled authorization=
codes to perform session fixation, logging victims in as the attacker. 202= 6-07-06 8.1 CVE-2026-59713 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59= 713 ] lepture--mistune Mistune is a Python Markdown parser with renderers a=
nd plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret ma= rker pairs around a character causes quadratic work in src/mistune/plugins/= formatting.py when the strikethrough, mark, or insert plugin scans for matc= hing markers from each possible start position, allowing denial of service = through CPU exhaustion. This issue is fixed in version 3.3.0. 2026-07-08 7.=
5 CVE-2026-59922 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59922 ] lept= ure--mistune Mistune is a Python Markdown parser with renderers and plugins=
. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-a= sterisk emphasis pairs around a character cause quadratic work in src/mistu= ne/inline_parser.py because the parser scans forward for matching close mar= kers from every potential opening run, allowing denial of service in defaul=
t Mistune parsing. This issue is fixed in version 3.3.0. 2026-07-08 7.5 CVE= -2026-59925 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59925 ] lepture--= mistune Mistune is a Python Markdown parser with renderers and plugins. Pri=
or to 3.3.0, a Markdown document containing many repeated or distinct refer= ence-link definitions causes quadratic work in src/mistune/block_parser.py = and the ref_links environment dictionary handling, allowing denial of servi=
ce through CPU exhaustion. This issue is fixed in version 3.3.0. 2026-07-08=
7.5 CVE-2026-59928 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59928 ] l= ibp2p--js-libp2p libp2p is a JavaScript Implementation of libp2p networking=
stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIh= aveMessageIDs and maxIwantMessageIDs to Infinity, allowing oversized IHAVE = and IWANT control message arrays in message/decodeRpc.ts and gossipsub.ts t=
o synchronously iterate roughly 180,000 message IDs per 4 MB frame and bloc=
k the Node.js event loop. This issue is fixed in version 16.0.0. 2026-07-08=
7.5 CVE-2026-49866 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49866 ] L= ibreBooking--LibreBooking LibreBooking's email template editor save action = passes the submitted template name directly into the destination file path,=
allowing a remote attacker with administrator credentials to write an arbi= trary file outside the template directory and execute code. Fixed in 5.1.0.=
2026-07-09 7.2 CVE-2026-61343 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-61343 ] lima-vm--lima Lima launches Linux virtual machines, typically on = macOS, for running containerd. Prior to 2.1.3, on an instance of Lima runni=
ng with the qemu driver, an arbitrary user in the VM could access /run/lima= -guestagent.sock when the guest agent is enabled, which could result in run= ning arbitrary commands with root privileges in the VM because the guest ag= ent socket provides tunneling for arbitrary addresses, including Unix socke=
t addresses for privileged daemons like D-Bus. This issue is fixed in versi=
on 2.1.3. 2026-07-10 8.2 CVE-2026-53657 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-53657 ] LocalAI--LocalAI LocalAI contains an unauthenticated se= rver-side request forgery vulnerability in the POST /models/apply endpoint = that allows attackers to fetch arbitrary internal URLs. The endpoint passes=
unsanitized gallery URL fields directly to gallery.GetGalleryConfigFromURL= WithContext without proper validation, enabling attackers to force the serv=
er to issue HTTP GET requests to private and loopback ranges with partial r= esponse content leaked through error messages. 2026-07-07 8.6 CVE-2026-5970=
7 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59707 ] LoginPress--LoginPr= ess Pro The LoginPress Pro plugin for WordPress is vulnerable to Authentica= tion Bypass via Unverified OAuth Email in all versions up to and including = 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discor=
d OAuth callback handler, which accepts the email field returned by Discord=
's /users/@me endpoint without ever checking that the profile's verified fl=
ag is true, then directly maps that email to a local WordPress account via = get_user_by('email', $profile['email']) and issues an authenticated session=
cookie via wp_set_auth_cookie(). This makes it possible for unauthenticate=
d attackers to take over any existing WordPress account - including adminis= trator accounts - by registering a Discord account configured with an unver= ified email address that matches the target user's registered WordPress ema=
il and completing the standard Discord OAuth flow. 2026-07-09 8.1 CVE-2026-= 12595 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12595 ] LoginPress--Log= inPress Pro The LoginPress Pro plugin for WordPress is vulnerable to Authen= tication Bypass via the GitHub OAuth callback in versions up to, and includ= ing, 6.2.3. The vulnerability exists in the loginpress_on_github_login() fu= nction, which blindly trusts the first element (profile[0]['email']) of the=
array returned by GitHub's /user/emails endpoint as an account-binding ide= ntifier without verifying that the email carries a verified =3D=3D=3D true = status. This makes it possible for unauthenticated attackers to log in as a=
ny existing WordPress user, including administrators, by adding an unverifi=
ed email address matching a local account to their GitHub profile and trigg= ering the OAuth callback via a crafted code parameter - causing the plugin =
to call get_user_by('email', ...) and establish an authenticated session fo=
r the matched account. Practical exploitation is conditional on GitHub retu= rning the attacker-added unverified email at index 0 of the /user/emails re= sponse, as GitHub typically prioritizes the primary verified address first;=
nonetheless, the absence of any email verification check in the plugin con= stitutes a fundamental authentication bypass flaw. 2026-07-09 8.1 CVE-2026-= 12597 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12597 ] LoginPress--Log= inPress Pro The LoginPress Pro plugin for WordPress is vulnerable to authen= tication bypass in versions up to and including 6.2.3 via the Spotify Socia=
l Login addon. This is due to the loginpress_on_spotify_login() function tr= usting the unverified 'email' field returned by Spotify's /v1/me endpoint a=
nd using it directly with get_user_by('email', $profile['email']) to identi=
fy and log in an existing WordPress account, without confirming that the Sp= otify user actually owns the email address (Spotify documents that the prof= ile email is unverified) and without requiring the user to prove ownership =
of the matching WordPress account. This makes it possible for unauthenticat=
ed attackers to log in as any existing WordPress user, including Administra= tors, by registering a Spotify account using the targeted user's email addr= ess and authenticating via the Spotify provider. 2026-07-09 8.1 CVE-2026-12= 598 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12598 ] logto-io--logto L= ogto is the modern, open-source auth infrastructure for SaaS and AI apps. P= rior to 1.41.0, Logto's Account Center step-up check accepted any active ve= rification record that belonged to the current user and had isVerified =3D= =3D=3D true. A WebAuthn registration verification record for binding a new = passkey could be created and verified with only an existing Account API bea= rer token, then sent in the logto-verification-id header and treated as ide= ntityVerified=3Dtrue by Account Center routes, allowing MFA factor manageme=
nt without proving possession of an existing password, identifier, or MFA f= actor. This issue is fixed in version 1.41.0. 2026-07-10 8.1 CVE-2026-55377=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-55377 ] logto-io--logto Logt=
o is the modern, open-source auth infrastructure for SaaS and AI apps. Prio=
r to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML=
response and assertion by string-substituting user-controlled profile attr= ibutes such as name, email, and custom attribute-mapping values into elemen= t-text placeholders of a SAML XML template using samlify 2.10.0, which left=
those placeholders unescaped. An authenticated low-privilege user could pl= ace XML markup in a profile attribute so Logto signed a forged SAML attribu= te, such as an arbitrary role, allowing privilege escalation at relying Ser= vice Providers that authorize on SAML attributes. This issue is fixed in ve= rsion 1.41.0. 2026-07-10 8.5 CVE-2026-55789 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-55789 ] loopus--WP Cost Estimation & Payment Forms Builder T=
he WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPr= ess is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' pa= rameter in all versions up to, and including, 10.5.97 due to insufficient i= nput sanitization and output escaping. This makes it possible for unauthent= icated attackers to inject arbitrary web scripts in pages that will execute=
whenever a user accesses an injected page. 2026-07-09 7.2 CVE-2026-9253 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-9253 ] lucee--Lucee Lucee CFML = Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines con= tain a reflected cross-site scripting vulnerability in URL path parsing tha=
t allows unauthenticated remote attackers to execute arbitrary JavaScript i=
n a victim's browser by embedding HTML or JavaScript payloads within the re= quest path. Attackers can craft a malicious URL containing injected script = content that is reflected in the server's response without proper output en= coding, enabling session hijacking or unauthorized actions against the Luce=
e administrative interface when a victim visits the crafted link. 2026-07-1=
0 8.2 CVE-2026-29519 [
https://www.cve.org/CVERecord?id=3DCVE-2026-29519 ] = markdown-it--linkify-it linkify-it is a links recognition library with full=
Unicode support. Prior to 5.0.2, the mailto: schema validator used by .tes= t() and .match() can be invoked at every mailto: occurrence and scan the re= maining input through src_email_name in lib/re.mjs, causing O(n^2) CPU cons= umption on crafted user text. This issue is fixed in version 5.0.2. 2026-07= -08 7.5 CVE-2026-59887 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59887 =
] masaakitanaka--Booking Package The Booking Package plugin for WordPress i=
s vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) =
in all versions up to, and including, 1.7.20 due to insufficient escaping o=
n the user supplied parameter and lack of sufficient preparation on the exi= sting SQL query. This makes it possible for unauthenticated attackers to ap= pend additional SQL queries into already existing queries that can be used =
to extract sensitive information from the database. The vulnerable REST API=
endpoint /wp-json/booking-package/v1/request is registered with permission= _callback: __return_true and wp_magic_quotes does not apply to REST-sourced=
$_POST values, meaning single quotes in the payload reach the SQL sink int= act without any authentication requirement. The impact of this is severely = limited as the vulnerable parameter goes through is_email. 2026-07-11 7.5 C= VE-2026-15335 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15335 ] mem0--m= em0 mem0's openmemory/api component contains an unauthenticated access vuln= erability that allows unauthenticated attackers to read, write, and delete = arbitrary user memories by accessing API routers registered without authent= ication middleware. Attackers can supply arbitrary user_id parameters or di= rectly access memory retrieval endpoints to expose private memory content, =
or invoke pause endpoints with global_pause=3Dtrue to cause denial-of-servi=
ce across all users. 2026-07-07 9.8 CVE-2026-59705 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-59705 ] mem0--mem0 mem0 contains unauthenticated conf=
ig API endpoints that expose LLM API keys in plaintext and allow server-sid=
e request forgery via attacker-controlled ollama_base_url parameter. Unauth= enticated attackers can retrieve stored secrets like OpenAI API keys via GE=
T /api/v1/config/ or trigger SSRF attacks by setting ollama_base_url to int= ernal addresses like cloud IMDS via PUT /api/v1/config/mem0/llm endpoint. 2= 026-07-07 9.3 CVE-2026-59706 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 59706 ] MervinPraison--PraisonAI PraisonAI before 1.6.78 contains a remote = code execution vulnerability in CodeAgent._execute_python() that executes L= LM-generated Python code without AST validation, import restrictions, or sa= ndbox enforcement. Attackers can influence LLM output through prompt inject= ion to exfiltrate all environment secrets and execute arbitrary code on the=
host system. 2026-07-11 10 CVE-2026-61447 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-61447 ] MervinPraison--PraisonAI PraisonAI before 4.6.78 fail=
s to validate the caller-controlled dimension argument in the PGVector and = Cassandra knowledge-store create_collection() backends. Although schema, ke= yspace, and collection-name identifiers are validated, the dimension value = (declared as int but not enforced at runtime) is interpolated directly into=
the vector column of the generated CREATE TABLE DDL. A caller able to infl= uence collection-creation dimensions can pass a string such as '3); DROP TA= BLE tenant_secrets; --' to inject SQL/CQL tokens into the statement execute=
d by the database driver. 2026-07-11 9.8 CVE-2026-60090 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-60090 ] MervinPraison--PraisonAI PraisonAI versi= ons before 4.6.78 contain a code injection vulnerability in deploy/api.py w= here the agents_file parameter is directly interpolated into an f-string wi= thout sanitization. Attackers can inject arbitrary Python code that execute=
s when the generated server code runs via subprocess.Popen(). 2026-07-10 9.=
1 CVE-2026-61444 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61444 ] Merv= inPraison--PraisonAI PraisonAI before 4.6.78 contains arbitrary file write = and command execution vulnerabilities in the AICoder component due to missi=
ng path validation and command sanitization in LLM tool calls. Attackers ca=
n inject malicious prompts through the chat interface to write files to arb= itrary filesystem locations and execute arbitrary shell commands with root = privileges. 2026-07-11 9.9 CVE-2026-61445 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-61445 ] MervinPraison--PraisonAI PraisonAI before 1.7.3 contai=
ns an insecure default configuration that binds to all interfaces with no A=
PI key requirement and wildcard CORS. Unauthenticated attackers can call GE=
T /api/agents to read agent instructions and system prompts, or POST /api/c= hat to invoke agents without authentication. 2026-07-11 8.6 CVE-2026-61426 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-61426 ] MervinPraison--Praiso= nAI PraisonAI versions before 1.6.78 contain a server-side request forgery = vulnerability in the Crawl4AI/Chromium backend that allows attackers to byp= ass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attacke=
rs can craft URLs that resolve to internal services after the initial valid= ation check, enabling the headless browser to follow redirects and read int= ernal responses including sensitive canary values. 2026-07-11 8.5 CVE-2026-= 61429 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61429 ] MervinPraison--= PraisonAI PraisonAI versions before 4.6.78 contain an allowlist bypass vuln= erability in shell command execution that allows attackers to execute restr= icted commands via find's built-in -exec, -execdir, and -delete actions. At= tackers can craft find commands with these built-in actions to read blocked=
files, delete files, or execute non-allowlisted binaries without triggerin=
g shell metacharacter filters. 2026-07-10 8.8 CVE-2026-61434 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-61434 ] MervinPraison--PraisonAI PraisonAI = before 4.6.78 contains an unauthenticated server-side request forgery vulne= rability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter i=
s validated at request time but re-resolved at connection time, allowing at= tackers to use DNS rebinding to reach internal services with a blind SSRF a= ttack. 2026-07-10 7.2 CVE-2026-60091 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-60091 ] MervinPraison--PraisonAI PraisonAI AgentMail versions befor=
e 4.6.78 lack signature verification in webhook mode, allowing unauthentica= ted attackers to inject messages with spoofed sender addresses. Attackers c=
an POST crafted message.received events to the webhook endpoint to inject a= rbitrary content into the agent and trigger replies to attacker-controlled = addresses, bypassing sender allow/block lists. 2026-07-11 7.3 CVE-2026-6142=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61428 ] MervinPraison--Prai= sonAI PraisonAI (pip package praisonaiagents) before 1.6.78 contains an uns= afe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_cla=
ss (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a wo= rkflow step uses a string output_pydantic reference, the framework locates = and imports a sibling tools.py from the workflow file's directory via impor= tlib exec_module without sandboxing, ignoring the PRAISONAI_ALLOW_*_TOOLS e= nvironment variables. An attacker who controls a workflow file and its sibl= ing tools.py can execute arbitrary Python code with the workflow runner's p= rivileges when the workflow is executed via WorkflowManager or after load_y= aml. 2026-07-10 7.8 CVE-2026-61437 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-61437 ] MervinPraison--PraisonAI PraisonAI versions before 4.6.78 con= tain a prompt injection defense misconfiguration where the block threshold = defaults to CRITICAL severity, allowing HIGH-level threats to pass through = unblocked. Attackers can submit single-vector prompt injection attacks such=
as instruction overrides or financial manipulation that trigger HIGH sever= ity detection but are logged without blocking, enabling system prompt extra= ction and unauthorized tool invocations. 2026-07-11 7.5 CVE-2026-61439 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-61439 ] MervinPraison--PraisonAI = PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner= /admin authorization on the PATCH routes for projects, issues, and agents, = which only require workspace-member role. A workspace member can modify own= er-created records; for projects, a member can reassign lead_id to their ow=
n user id and then delete the owner-created project, bypassing the delete r= oute's owner/admin permission check. 2026-07-11 7.1 CVE-2026-61442 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-61442 ] metabase--metabase Metabase i=
s an open-source business intelligence and embedded analytics tool. From 1.= 55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not valid= ate unsafe H2 connection properties on one database-creation code path, all= owing an authenticated administrator to register a crafted H2 database conn= ection and execute arbitrary Java code on the Metabase server. This issue i=
s fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2. 2026-07-09 9.=
1 CVE-2026-59826 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59826 ] meta= base--metabase Metabase is an open-source business intelligence and embedde=
d analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metaba=
se instances with an H2 database connection, including the default sample d= atabase, deserialize arbitrary Java objects returned in H2 native query res= ult columns of type OTHER without validation, allowing an authenticated use=
r who can run native H2 queries to execute code on the Metabase server. Thi=
s issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4. 2026= -07-09 9.9 CVE-2026-59827 [
https://www.cve.org/CVERecord?id=3DCVE-2026-598=
27 ] metagauss--EventPrime Events Calendar, Bookings and Tickets The EventP= rime - Events Calendar, Bookings and Tickets plugin for WordPress is vulner= able to Stored Cross-Site Scripting via the 'new_event_type_background_colo=
r' parameter in all versions up to, and including, 4.3.4.2 due to insuffici= ent input sanitization and output escaping. This makes it possible for auth= enticated attackers, with custom-level access and above, to inject arbitrar=
y web scripts in pages that will execute whenever a user accesses an inject=
ed page. This requires the plugin's Guest Submissions setting (allow_submis= sion_by_anonymous_user) to be enabled, which allows unauthenticated attacke=
rs to submit event types via the frontend form; when that setting is disabl= ed, exploitation requires at minimum a subscriber-level authenticated accou= nt. 2026-07-09 7.2 CVE-2026-13441 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-13441 ] Metasoft --MetaCRM A weakness has been identified in Metasoft = =C3=A7=C2=BE=C5=BD=C3=A7=E2=80=B0=C2=B9=C3=A8=C2=BD=C2=AF=C3=A4=C2=BB=C2=B6=
MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCSer= vice.query of the file /customizemt/xkq/rpc.jsp of the component PHPRPC Rem= ote Call Interface. Executing a manipulation of the argument phprpc_args ca=
n lead to sql injection. The attack can be launched remotely. The exploit h=
as been made available to the public and could be used for attacks. The ven= dor was contacted early about this disclosure but did not respond in any wa=
y. 2026-07-12 7.3 CVE-2026-15514 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-15514 ] Micro-Star International (MSI)--KernCoreLib64.sys MSI Feature M= anager contains a local privilege escalation vulnerability in the KernCoreL= ib64.sys kernel driver that allows any locally logged-on user to perform ar= bitrary physical memory read/write and unrestricted I/O port operations by = accessing exposed IOCTL handlers without administrator privileges. Attacker=
s can exploit the accessible device object through IOCTL handlers to manipu= late kernel objects, tamper with kernel-mode callbacks, bypass Protected Pr= ocess Light protections, and disable security software. 2026-07-07 7.8 CVE-= 2026-57851 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57851 ] Microsoft-= -Dynamics 365 Customer Voice Improper neutralization of input during web pa=
ge generation ('cross-site scripting') in Dynamics 365 Customer Voice allow=
s an unauthorized attacker to perform spoofing over a network. 2026-07-08 9=
.3 CVE-2026-47646 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47646 ] Mic= rosoft--Microsoft Edge (Chromium-based) Deserialization of untrusted data i=
n Microsoft Edge (Chromium-based) allows an unauthorized attacker to execut=
e code over a network. 2026-07-11 8.3 CVE-2026-58281 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-58281 ] Microsoft--Microsoft Edge (Chromium-based) = Improper access control in Microsoft Edge (Chromium-based) allows an unauth= orized attacker to bypass a security feature over a network. 2026-07-08 8.2=
CVE-2026-58525 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58525 ] Micro= soft--Microsoft Edge (Chromium-based) Untrusted pointer dereference in Micr= osoft Edge (Chromium-based) allows an unauthorized attacker to elevate priv= ileges over a network. 2026-07-12 8.3 CVE-2026-58596 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-58596 ] miniOrange Security Software Pvt Ltd.--OAut=
h Single Sign On - SSO (OAuth Client) Authentication Bypass Using an Altern= ate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. = OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploita= tion. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/=
a through 38.5.8. 2026-07-10 9.8 CVE-2026-57807 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-57807 ] mockoon--mockoon Mockoon provides way to design = and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/sr= c/libs/server/admin-api.ts is mounted on the same Express listener as user-= defined mock routes, enabled by default in shipped runtimes, serves Access-= Control-Allow-Origin: * with write methods allowed, and has no authenticati= on. Any unauthenticated caller who can reach the mock server port can read = MOCKOON_* environment variables, write arbitrary process environment variab= les through /mockoon-admin/env-vars, rewrite mock route bodies, statuses, a=
nd headers through PUT /mockoon-admin/environment, read transaction logs an=
d SSE streams, and purge state. This issue is fixed in version 9.7.0. 2026-= 07-09 8.8 CVE-2026-59148 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5914=
8 ] mohammed_kaludi--AMP for WP Accelerated Mobile Pages The AMP for WP - A= ccelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary Fil=
e Write in versions up to and including 1.1.12. This is due to unsafe ZIP f= ile extraction in the ampforwp_save_local_font() function combined with ina= dequate cleanup that fails to remove nested directories and files. This mak=
es it possible for authenticated attackers, with Author-level access and ab= ove, and permissions granted by an Administrator, to write arbitrary files =
to the server in a web-accessible location, potentially leading to remote c= ode execution on hosts that execute PHP files in the uploads directory. 202= 6-07-07 7.5 CVE-2026-6101 [
https://www.cve.org/CVERecord?id=3DCVE-2026-610=
1 ] Monsta Limited of New Zealand--Monsta FTP Monsta FTP before 2.14.5 cont= ains a server-side request forgery vulnerability in the fetchRemoteFile act= ion caused by an incomplete IP blocklist check in the isBlockedIP() functio=
n, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 ad= dresses. An unauthenticated attacker can obtain a CSRF token from the publi=
c getSystemVars endpoint and submit a fetchRemoteFile request with a source=
URL resolving to an IPv4-mapped address, causing the server to issue HTTP = requests to internal services and write responses to an attacker-controlled=
FTP destination, enabling retrieval of cloud instance metadata credentials=
. 2026-07-08 8.6 CVE-2026-60105 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-60105 ] n8n--n8n n8n before 1.123.55, 2.25.7, and 2.26.2 contains an aut= horization bypass in the POST /workflows/{workflowId}/test-runs/new endpoin=
t, which authorizes access using the workflow:read scope instead of workflo= w:execute. An authenticated user with read-only access to a workflow can tr= igger a real evaluation test run, causing the workflow to execute via the i= nternal workflow runner and resulting in unintended outbound API calls, dat=
a mutations, or other side effects in connected downstream systems. The iss=
ue primarily affects instances using the Evaluations feature where RBAC pro= ject roles grant workflow:read without workflow:execute. 2026-07-08 7.4 CVE= -2026-56776 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56776 ] nats-io--= nats-server NATS Server is a high-performance server for NATS.io, the cloud=
and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, wh=
en no_auth_user was configured, a parser fast path intended for ordinary cl= ient connections could also apply to route or leafnode listeners, allowing =
an unauthenticated peer to bypass inter-server CONNECT authentication and o= perate with the privileges associated with that connection type. This issue=
is fixed in versions 2.14.0, 2.12.7, and 2.11.16. 2026-07-08 8.8 CVE-2026-= 58253 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58253 ] nats-io--nats-s= erver NATS Server is a high-performance server for NATS.io, the cloud and e= dge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to = send account-scoped connection monitoring requests could crash the server b=
y supplying Connz pagination Offset and Limit values that overflowed intern=
al arithmetic before the response window was safely bounded. This issue is = fixed in versions 2.14.3 and 2.12.12. 2026-07-08 7.7 CVE-2026-58207 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-58207 ] nats-io--nats-server NATS Se= rver is a high-performance server for NATS.io, the cloud and edge native me= ssaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client=
could cause the server to retain large incomplete MQTT CONNECT packets bef= ore authentication completed, consuming server memory while the parser wait=
ed for the advertised MQTT packet length. This issue is fixed in versions 2= .14.3 and 2.12.12. 2026-07-08 7.5 CVE-2026-58210 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-58210 ] nats-io--nats-server NATS Server is a high-perf= ormance server for NATS.io, the cloud and edge native messaging system. Pri=
or to 2.14.1 and 2.12.9, an MQTT client could include protocol control char= acters in subscription filters that were later forwarded as NATS protocol d= ata to route or leafnode connections, corrupting the forwarded protocol str= eam and allowing injection of unintended NATS protocol operations. This iss=
ue is fixed in versions 2.14.1 and 2.12.9. 2026-07-08 7.1 CVE-2026-58213 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-58213 ] nats-io--nats-server NA=
TS Server is a high-performance server for NATS.io, the cloud and edge nati=
ve messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer w= ith network access to a leafnode listener with compression enabled could cr= ash the server during the pre-authentication leafnode handshake by sending = repeated leafnode INFO protocol messages before authentication and account = setup completed. This issue is fixed in versions 2.12.8 and 2.11.17. 2026-0= 7-08 7.5 CVE-2026-58250 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58250=
] nesquena--hermes-webui Hermes WebUI before 0.51.307 contains an authenti= cation bypass vulnerability that allows unauthenticated remote attackers to=
circumvent local-origin IP restrictions on onboarding endpoints by supplyi=
ng a spoofed X-Forwarded-For header with a loopback address. Attackers can = exploit this bypass to perform server-side request forgery against internal=
services including cloud metadata endpoints, overwrite LLM provider config= uration and API keys with attacker-controlled values, or initiate OAuth dev= ice-code flows to obtain persistent access tokens stored in auth.json. 2026= -07-09 9.1 CVE-2026-58122 [
https://www.cve.org/CVERecord?id=3DCVE-2026-581=
22 ] nesquena--hermes-webui Hermes WebUI before 0.51.788 contains an unauth= enticated remote code execution vulnerability that allows remote attackers =
to execute arbitrary shell commands by accessing the embedded terminal API = endpoints without credentials. Attackers can create a session, attach a PTY=
shell, and write arbitrary commands through the terminal input endpoint to=
achieve full command execution as the server process user via four sequent= ial unauthenticated HTTP requests. 2026-07-09 9.8 CVE-2026-58123 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-58123 ] nicu_m--Simple JWT Login Allows=
you to use JWT on REST endpoints. The Simple JWT Login - Allows you to use=
JWT on REST endpoints. plugin for WordPress is vulnerable to Authenticatio=
n Bypass to Privilege Escalation in all versions up to, and including, 3.6.=
6 via the `payload` parameter. The vulnerability exists because `Authentica= teService::generatePayload()` only overwrites JWT payload keys whose names = appear in the admin-configured `jwt_payload` list - leaving any attacker-su= pplied identity claims such as `email`, `id`, or `username` intact and sign=
ed into the JWT with the site's HS256 secret. This makes it possible for au= thenticated attackers, with subscriber-level access and above, to escalate = their privileges to that of an Administrator by injecting a target administ= rator's email address into the `payload` parameter at the `/wp-json/simple-= jwt-login/v1/auth` endpoint, then redeeming the resulting JWT at the `/auto= login` endpoint to obtain a fully authenticated session as that administrat= or. 2026-07-11 8.8 CVE-2026-14262 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-14262 ] ninjew--GEO my WP The GEO my WP plugin for WordPress was vulne= rable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in v= ersions up to, and including, 4.5.4. The values were read from $_SERVER['QU= ERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cov=
er $_SERVER), then passed through bare esc_sql() before being interpolated = into unquoted numeric positions in the proximity-search query (HAVING/SELEC=
T clause distance math, BETWEEN bounding-box pre-filter) built by gmw_locat= ions_query() in plugins/posts-locator/includes/class-gmw-wp-query.php. Beca= use esc_sql() only escapes string delimiters and these positions are numeri=
c, payloads such as `1 OR SLEEP(3)` survived sanitization. Fixed in 4.5.5 b=
y adding an upstream is_numeric() guard that short-circuits the WHERE claus=
e to `AND 1 =3D 0` when either coordinate is non-numeric, and by replacing = the three esc_sql() calls with (float) casts. 2026-07-10 9.1 CVE-2026-15300=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-15300 ] nodeca--js-yaml js-y= aml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and fr=
om 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a docum= ent whose size grows only linearly when a chain of mappings uses merge keys=
where each mapping merges the previous one. This issue is fixed in version=
s 3.15.0 and 4.3.0. 2026-07-08 7.5 CVE-2026-59869 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-59869 ] Nozomi Networks--Guardian An Incorrect Privile=
ge Assignment vulnerability was discovered in the synchronization functiona= lity due to Arc sensors receiving CLI permissions. An authenticated user wi=
th limited privileges can push administrative CLI commands through the sync=
, altering the device configuration, and/or affecting its availability. 202= 6-07-09 8.1 CVE-2026-33390 [
https://www.cve.org/CVERecord?id=3DCVE-2026-33= 390 ] Nozomi Networks--Guardian An Open Redirect vulnerability was discover=
ed in the SAML Single Sign-On functionality due to insufficient validation =
of a user-controlled redirection parameter. An unauthenticated attacker can=
craft a request to the SAML sign-in endpoint and poison the cached SAML re= direction for other users who subsequently initiate SAML Single Sign-On, en= abling phishing and credential-theft attacks, as well as disrupting SAML au= thentication for all affected users. 2026-07-09 7.1 CVE-2026-31982 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-31982 ] Nozomi Networks--Guardian A d= enial-of-service vulnerability caused by unbounded resource allocation was = discovered in the audit logging functionality, due to a missing size limit =
on input recorded into audit entries. An unauthenticated attacker can submi=
t requests containing excessively large input that is recorded into audit e= ntries, possibly exhausting the available disk space and rendering the syst=
em inoperable. 2026-07-09 7.5 CVE-2026-31984 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-31984 ] Nozomi Networks--Remote Collector When the upstream=
Guardian or CMC was configured in the Remote Collector via n2os-tui, the g= enerated configuration disabled TLS certificate verification, and no option=
was provided to enable it. A malicious actor could perform a man-in-the-mi= ddle attack and intercept the communication between the Remote Collector an=
d the Guardian or CMC. This could result in theft of the sync token, impers= onation of the server, injection of spoofed data (such as false asset infor= mation or vulnerabilities) into the Guardian or CMC, or disruption of the d= ata flow between the Remote Collector and the Guardian or CMC. 2026-07-09 8=
.1 CVE-2026-31985 [
https://www.cve.org/CVERecord?id=3DCVE-2026-31985 ] ntp= sec--gpsd gpsd through release-3.27.5, fixed at commit 4c06658, contains a = command injection vulnerability in gpsprof that allows attackers who contro=
l the GPS device subtype value to execute arbitrary shell commands by embed= ding backtick payloads in the gnuplot plot title without proper escaping. T=
he subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT senten=
ce is written into a generated gnuplot program via a set title statement wi=
th only double-quote characters escaped, enabling arbitrary shell command e= xecution as the user running gnuplot when the victim renders the generated = plot through the gpsprof and gnuplot workflow. 2026-07-09 7.8 CVE-2026-5845=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58459 ] OceanicSoft Informa= tics Systems Ltd.--ValeApp Improper neutralization of input during web page=
generation ('cross-site scripting') vulnerability in OceanicSoft Informati=
cs Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: thro= ugh 09072026.=C2=A0NOTE: The vendor was contacted early about this disclosu=
re but did not respond in any way. 2026-07-09 9.3 CVE-2026-2342 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-2342 ] Omnissa--Omnissa Workspace ONE Tu= nnel for Windows Omnissa Workspace ONE=C3=82=C2=AE Tunnel for Windows addre= sses a Local Privilege Escalation Vulnerability. 2026-07-08 7.8 CVE-2026-22= 927 [
https://www.cve.org/CVERecord?id=3DCVE-2026-22927 ] open-telemetry--o= pentelemetry-js OpenTelemetry JavaScript is the OpenTelemetry JavaScript cl= ient. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming ube= r-trace-id and uberctx-* HTTP header values with decodeURIComponent() witho=
ut handling decode errors, allowing an unauthenticated remote attacker to s= end a malformed percent-encoded value that throws an uncaught URIError and = terminates a Node.js process using JaegerPropagator as the active propagato=
r. This issue is fixed in version 2.9.0. 2026-07-08 7.5 CVE-2026-59892 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-59892 ] open-webui--open-webui Op=
en WebUI is an extensible, feature-rich, and user-friendly self-hosted AI p= latform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the=
ws_terminal upstream URL from an unencoded session_id and appended user_id=
as a query parameter, allowing query injection to make the terminal backen=
d resolve another user identity; the HTTP proxy path also forwarded X-User-=
Id as an integrity-unbound identity claim. This issue is fixed in version 0= .10.0. 2026-07-09 8 CVE-2026-59224 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-59224 ] open-webui--open-webui Open WebUI is an extensible, feature-r= ich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI=
runs client-side Python with Pyodide in a same-origin web worker, allowing=
stored chat payloads that use pyodide.http.pyfetch or the js module fetch = and XMLHttpRequest APIs to issue authenticated same-origin requests when a = victim clicks Run, which can reach admin-only endpoints and execute server-= side code through configured tools. This issue is fixed in version 0.10.0. = 2026-07-09 7.3 CVE-2026-59214 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -59214 ] open-webui--open-webui Open WebUI is an extensible, feature-rich, = and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call = delivered execute:python and execute:tool Socket.IO events to a client-supp= lied session_id after checking only that the session was connected, allowin=
g authenticated users who learned another socket ID through ydoc:document:j= oin to run code interpreter Python or tools in that user session. This issu=
e is fixed in version 0.10.0. 2026-07-09 7.7 CVE-2026-59216 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-59216 ] open-webui--open-webui Open WebUI is=
an extensible, feature-rich, and user-friendly self-hosted AI platform. Fr=
om 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join,=
join-channels, join-note, and the terminal websocket first-message authent= ication used decode_token without the Redis-backed is_valid_token revocatio=
n check, allowing revoked JWTs to continue authenticating realtime connecti= ons. This issue is fixed in version 0.10.0. 2026-07-09 7.1 CVE-2026-59219 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-59219 ] open-webui--open-webui=
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted A=
I platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_= webui/routers/terminals.py decoded proxy paths only eight times, allowing a=
nine-times percent-encoded ../ traversal value to pass normalization check=
s and be decoded by the upstream terminal server. This issue is fixed in ve= rsion 0.10.0. 2026-07-09 7.7 CVE-2026-59221 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-59221 ] OpenBSD--OpenSSH ssh in OpenSSH before 10.4 can have=
a use-after-free when a server changes its host key during a key re-exchan= ge. (This outcome occurs only on the client side.) 2026-07-08 7.7 CVE-2026-= 60002 [
https://www.cve.org/CVERecord?id=3DCVE-2026-60002 ] OpenClaw--OpenC= law OpenClaw before 2026.5.28 contains a credential exposure vulnerability = where workspace dotenv files can override provider credentials. Attackers w= ith lower-trust access to configured input paths can expose sensitive data = and credentials that should remain within trusted boundaries. 2026-07-08 7.=
1 CVE-2026-59261 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59261 ] Open= CTI-Platform--opencti OpenCTI is an open source platform for managing cyber=
threat intelligence knowledge and observables. Prior to 7.260326.0, an aut= horization bypass vulnerability in OpenCTI allows any authenticated user wi=
th KNOWLEDGE_KNUPDATE permission to bypass Confidence Level validation and = Object Marking restrictions by injecting the synchronized-upsert: true HTTP=
header, enabling attackers to downgrade confidence levels, remove security=
markings such as TLP:RED, manipulate relationships, and affect STIX object=
types including Indicators, ThreatActors, Malware, and Reports. This issue=
is fixed in version 7.260326.0. 2026-07-08 7.1 CVE-2026-35210 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-35210 ] OpenPLC--OpenPLC OpenPLC Runtime =
v3 contains an authenticated arbitrary file write vulnerability in the lega=
cy web UI program-upload workflow. The application stores an attacker-suppl= ied filename (prog_file) directly into the Programs.File database field and=
later uses this value as the destination path for an uploaded file without=
validating or restricting the path. Because Python os.path.join() honors a= ttacker-controlled absolute paths, an authenticated user can write arbitrar=
y files anywhere writable by the OpenPLC webserver process. In the default = build pipeline, all C++ source files within the OpenPLC runtime core direct= ory are automatically compiled into the executable runtime binary. By writi=
ng a malicious .cpp file into this directory, an authenticated attacker can=
escalate the arbitrary file write into arbitrary native code execution whe=
n the operator triggers a normal program compilation and runtime start. 202= 6-07-10 9.9 CVE-2026-14480 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14= 480 ] openreplay--openreplay OpenReplay is a self-hosted session replay sui= te. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom e= vent names and captured page URLs from any visitor using a public project k= ey, stores them in ClickHouse without output encoding, and later renders th=
em in the authenticated dashboard through TextEllipsis and the event-detail=
s modal, allowing an unauthenticated attacker to store script that executes=
in the dashboard origin, reads the session JWT from localStorage, and take=
s over a dashboard account. This issue is fixed in version 1.25.0. 2026-07-=
10 9.3 CVE-2026-55879 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55879 ]=
openreplay--openreplay OpenReplay is a self-hosted session replay suite. I=
n 1.27.0 and earlier, three dashboard and note mutation functions ran their=
SQL without the ownership predicate that their sibling read and edit funct= ions use: notes.delete filtered only on note id and project id, while dashb= oards.update_widget and dashboards.remove_widget filtered only on dashboard=
id and widget id, allowing any authenticated member to delete another user=
's private session notes and remove or rewrite widgets on another user's pr= ivate dashboards. 2026-07-10 7.1 CVE-2026-55880 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-55880 ] openresty--openresty OpenResty is a high perform= ance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write=
vulnerability exists in the upstream PROXY protocol v2 implementation. Whe=
n OpenResty is configured to send PROXY protocol version 2 headers to upstr= eam servers, constructing the header in the stream proxy protocol v2 patch = can write beyond the bounds of the allocated buffer, causing the worker pro= cess to crash and resulting in a denial of service. Only configurations tha=
t explicitly enable PROXY protocol v2 for upstream connections are impacted=
. This issue is fixed in version 1.29.2.5. 2026-07-10 7.5 CVE-2026-55233 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-55233 ] OpenStack--Ironic In Op= enStack Ironic before 37.0.1, an Ironic user with the ability to deploy nod=
es using the IPMI management interface can maliciously use the send_raw ste=
p to send arbitrary IPMI commands to a node, bypassing Ironic's access cont= rol. 2026-07-10 8.2 CVE-2026-54423 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-54423 ] openwrt--luci OpenWrt luci-app-samba4 read ACL grants file.ex=
ec permission on /usr/sbin/smbd, allowing authenticated delegated users to = execute the Samba daemon with caller-controlled command-line arguments. Att= ackers can pass arbitrary Samba global options such as message command to a=
root smbd process, triggering command execution when SMB protocol messages=
are processed. 2026-07-12 8.8 CVE-2026-59260 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-59260 ] openwrt--luci luci-app-upnp contains a stored cros= s-site scripting vulnerability that allows unauthenticated LAN clients to i= nject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can s= end malicious HTML in the NewPortMappingDescription field, which miniupnpd = stores and luci-app-upnp renders without output encoding, executing the pay= load when administrators view the UPnP or Status pages. 2026-07-12 8.8 CVE-= 2026-61875 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61875 ] openwrt--l= uci LuCI versions fail to properly encode DHCPv6 lease hostnames before ren= dering in status tables, allowing adjacent network attackers to inject HTML=
markup. Attackers can send a DHCPv6 Client FQDN containing script tags tha=
t execute in the administrator's browser when viewing DHCP lease pages. 202= 6-07-12 8.8 CVE-2026-61876 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61= 876 ] oraios--serena Serena is a powerful MCP toolkit for coding that provi= des semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's = built-in web dashboard exposes an unauthenticated Flask API on a fixed, pre= dictable port, with no authentication, no CSRF protection, and no Host head=
er validation. A DNS rebinding attack allows a malicious webpage to reach t= his API from any browser and write arbitrary content to the agent's persist= ent memory store, which the agent reads and acts on autonomously. Combined = with execute_shell_command using shell=3DTrue, this creates a remote code e= xecution chain requiring only that the victim visit a malicious webpage whi=
le Serena is running. This issue is fixed in version v1.5.2. 2026-07-07 8.3=
CVE-2026-49471 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49471 ] owasp= -modsecurity--ModSecurity ModSecurity is an open source, cross platform web=
application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.= 16, the multipart/form-data request body parser in libmodsecurity silently = removes embedded line breaks from non-file form-field values before exporti=
ng them to ARGS and ARGS_POST because src/request_body_processor/multipart.=
cc overwrites reserved bytes in m_reserve instead of appending the current = buffer. This creates a parser differential between ModSecurity and backend = applications that preserve line breaks in form fields, allowing rules that = inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends o=
n a line break. This issue is fixed in version 3.0.16. 2026-07-10 8.6 CVE-2= 026-52747 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52747 ] owncloud--A= nti-Virus for ownCloud Anti-Virus for ownCloud is an anti-virus application=
for file storage, synchronization, and sharing application ownCloud. Versi= ons of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side R= equest Forgery (SSRF). This corresponds to versions of ownCloud 10 prior to=
10.15.3. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade Anti-V= irus for ownCloud 10 to version 1.2.3 or later to receive a fix. 2026-07-06=
9.1 CVE-2025-53830 [
https://www.cve.org/CVERecord?id=3DCVE-2025-53830 ] o= wncloud--DrawIO for ownCloud DrawIO for ownCloud is an application for usin=
g DrawIO with the file storage, synchronization, and sharing application ow= nCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corres= ponds to ownCloud 10 prior to version 10.15.3, attackers with access to the=
DrawIO app can leverage improper neutralization of input during web page g= eneration to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or = later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or later to receiv=
e a patch. 2026-07-06 8.2 CVE-2025-53831 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-53831 ] owncloud--ownCloud 10 ownCloud is a file storage, synch= ronization, and sharing application. In ownCloud 10 prior to version 10.15.=
3, an attacker with administrative privileges can exploit a path traversal = vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 =
to version 10.15.3 or later to receive a patch. 2026-07-06 8 CVE-2025-53829=
[
https://www.cve.org/CVERecord?id=3DCVE-2025-53829 ] owncloud--ownCloud C= ore ownCloud Core is the server-side component of the file storage, synchro= nization, and sharing application ownCloud Classic. In versions prior to 10= .15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous m= ethod or function. Attackers with administrative privileges may leverage fu= nctionality to execute arbitrary code. This issue has been fixed in version=
10.15.3. 2026-07-06 9.1 CVE-2025-53827 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-53827 ] owncloud--SharePoint SharePoint for ownCloud is an appl= ication for using SharePoint with the file storage, synchronization, and sh= aring application ownCloud Classic. In SharePoint for ownCloud prior to ver= sion 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker = with administrative privileges can use a SSRF vulnerability in the SharePoi=
nt app to execute arbitrary code on the system. Upgrade ownCloud 10 to vers= ion 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixed ve= rsion. 2026-07-06 8.5 CVE-2025-53828 [
https://www.cve.org/CVERecord?id=3DC= VE-2025-53828 ] PasswordPusher--PasswordPusher PasswordPusher before 2.8.1 = accepts data URI schemes in URL push payloads due to insufficient validatio=
n in the valid_url function. Attackers can create malicious pushes containi=
ng data:text/html URIs that execute arbitrary JavaScript in victims' browse=
rs when clicked, enabling phishing and credential theft under the trusted P= asswordPusher domain. 2026-07-08 8.2 CVE-2026-59802 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-59802 ] PAVO Financial Technology Solutions Inc.--PA=
VO Pay Authorization bypass through User-Controlled key vulnerability in PA=
VO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trus= ted Identifiers. This issue affects PAVO Pay: through 09072026.=C2=A0NOTE: = The vendor was contacted early about this disclosure but did not respond in=
any way. 2026-07-09 7.5 CVE-2026-1989 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-1989 ] PEAKUP Technology Inc.--PassGate Improper neutralization=
of special elements used in an LDAP query ('LDAP injection') vulnerability=
in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affec=
ts PassGate: through 30042026. 2026-07-09 8.2 CVE-2026-4256 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-4256 ] pechenki--TelSender ontact form 7, Ev= ents, Wpforms, ninja forms and woocommerce to telegram bot The TelSender pl= ugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all v= ersions up to, and including, 1.14.14. This is due to insufficient input sa= nitization when processing Telegram API responses containing attacker-contr= olled chat titles. This makes it possible for unauthenticated attackers to = inject malicious scripts via Telegram chat titles that execute when an admi= nistrator opens the TelSender settings page and clicks the "Tested" button.=
2026-07-10 7.2 CVE-2026-15298 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-15298 ] pimcore--pimcore Pimcore is an Open Source Data & Experience Mana= gement Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacke=
r who knows a valid admin username can take over any Pimcore admin account =
by sending a password reset request with an attacker-controlled resetPasswo= rdUrl. The server generates a real cryptographic recovery token, appends it=
to the supplied URL, and emails the link to the victim; when the victim cl= icks the link, the token is sent to the attacker and can be used with POST = /pimcore-studio/api/login/token to authenticate with full admin privileges = while bypassing two-factor authentication. This issue is fixed in versions = 2025.4.6 and 2026.1.6. 2026-07-09 8.8 CVE-2026-55207 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-55207 ] pimcore--pimcore Pimcore Studio Backend Bun= dle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.=
6, an authenticated user can extract the admin password hash and other data= base content through time-based blind SQL injection in the DateFilter colum=
n key parameter. The POST /pimcore-studio/api/website-settings endpoint and=
other listing endpoints accept a columnFilters array where the key field i=
s interpolated directly into SQL with manual backtick wrapping, allowing a = backtick character to break out of quoting and append arbitrary SQL such as=
SLEEP() and IF() subqueries. This issue is fixed in versions 2025.4.6 and = 2026.1.6. 2026-07-09 7.7 CVE-2026-55208 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55208 ] pimcore--pimcore Pimcore is an Open Source Data & Exper= ience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API c= lass definition creation endpoint POST /pimcore-studio/api/class/definition= /configuration-view/detail/create is guarded by the objects permission inst= ead of the classes permission, allowing a standard editor-level user to cre= ate class definitions without admin privileges. Class definition creation g= enerates new database tables and PHP class files on the server, and missing=
API-layer UID format validation allows malformed UIDs to reach model-layer=
validation and return internal exceptions. This issue is fixed in versions=
2025.4.6 and 2026.1.6. 2026-07-09 7.1 CVE-2026-55212 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-55212 ] pipecat-ai--pipecat Pipecat is an open-sou= rce Python framework for building real-time voice and multimodal conversati= onal agents. Prior to 1.4.0, the pipecat development runner registers a /ws=
WebSocket endpoint for telephony testing that accepts connections without = authentication, reads an attacker-supplied callSid from a Twilio stream-sta=
rt handshake in src/pipecat/runner/utils.py, and passes it to TwilioFrameSe= rializer so the server can issue an authenticated Twilio REST API hang-up r= equest with the server operator's credentials; equivalent unauthenticated c= all-control sinks exist for Telnyx and Plivo. This issue is fixed in versio=
n 1.4.0. 2026-07-09 7.5 CVE-2026-54695 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-54695 ] pixelgrade--Backstage Customizer Demo Access The Backst= age - Customizer Demo Access plugin for WordPress is vulnerable to Privileg=
e Escalation in all versions up to, and including, 1.4.2. This is due to th=
e plugin assigning the `manage_options` capability to the `backstage_custom= izer_user` demo role, which is more permissive than necessary for Customize= r-only demo access. This makes it possible for unauthenticated attackers to=
navigate beyond the Customizer and update arbitrary WordPress options such=
as `default_role`, leading to privilege escalation. 2026-07-08 7.5 CVE-202= 6-9842 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9842 ] pnpm--pnpm pnpm=
is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package na= mes from the env lockfile configDependencies section and uses those names d= irectly when creating config dependency symlinks under node_modules/.pnpm-c= onfig. A malicious repository can commit a crafted pnpm-lock.yaml whose env= -lockfile document contains a traversal-shaped config dependency name. Duri=
ng pnpm install, pnpm installs the config dependency and creates a symlink =
at a path derived from that name. This vulnerability is fixed in 10.34.4 an=
d 11.8.0. 2026-07-06 8.2 CVE-2026-59195 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-59195 ] pnpm--pnpm pnpm is a package manager. Prior to 10.34.4 = and 11.7.0, a crafted patch entry could resolve outside the configured patc= hes directory and cause pnpm patch-remove to delete an arbitrary reachable = file. This vulnerability is fixed in 10.34.4 and 11.7.0. 2026-07-06 7.1 CVE= -2026-59194 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59194 ] pnpm--pnp=
m pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfil=
e alias could be joined directly under a hoisted node_modules directory. Tr= aversal aliases could escape that directory, while reserved aliases such as=
.bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fix=
ed in 10.34.4 and 11.7.0. 2026-07-06 7.1 CVE-2026-59196 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-59196 ] PROG MIS--ERP App ERP App developed by P= ROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthe= nticated remote attackers to log in to view application code and obtain the=
database account and password. 2026-07-06 9.8 CVE-2026-14807 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-14807 ] PROG MIS--Prog Management System P= rog Management System developed by PROG MIS has a Exposure of Sensitive Inf= ormation vulnerability, allowing unauthenticated remote attackers to view a=
specific page and obtain the database account and password. 2026-07-06 9.8=
CVE-2026-14808 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14808 ] PROG = MIS--Prog Management System Prog Management System developed by PROG MIS ha=
s a SQL Injection vulnerability, allowing unauthenticated remote attackers =
to inject arbitrary SQL commands to read database contents. 2026-07-06 7.5 = CVE-2026-14809 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14809 ] Progre= ss--MOVEit Transfer Improper neutralization of input during web page genera= tion ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad=
Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026= .0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. 2026-07= -08 8 CVE-2026-11903 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11903 ] = Progress--MOVEit Transfer Improper Neutralization of Special Elements in Da=
ta Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports mo= dules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, = from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. 2026-07-08 7.=
2 CVE-2026-10698 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10698 ] Prog= ress--MOVEit Transfer Missing release of memory after effective lifetime vu= lnerability in Progress MOVEit Transfer (Custom Reports modules). This issu=
e affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 bef= ore 2025.1.4, from 2026.0.0 before 2026.0.1. 2026-07-08 7.5 CVE-2026-10699 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-10699 ] prowler-cloud--prowle=
r Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML aut= hentication flow trusted the email domain asserted in a SAMLResponse when d= eciding which tenant should receive the final token, and the ACS finish log=
ic in api/src/backend/api/v1/views.py recalculated the tenant from user.ema=
il instead of binding token issuance to the validated SAML configuration. A=
n authenticated attacker with a controlled SAML IdP could complete a valid = SAML flow for an attacker-controlled domain while asserting an email addres=
s from another configured domain, causing a SAMLToken and tenant-scoped JWT=
to be issued for the wrong tenant and enabling cross-tenant account takeov= er. This issue is fixed in version 5.30.3. 2026-07-10 9.6 CVE-2026-59151 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-59151 ] python-pillow--Pillow P= illow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _loa= d_bitmaps() read glyph dimensions from the PCF METRICS section and passed t= hem directly to Image.frombytes() without calling Image._decompression_bomb= _check(), allowing crafted PCF font data to cause excessive memory allocati= on. This issue is fixed in version 12.3.0. 2026-07-06 7.5 CVE-2026-54059 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-54059 ] python-pillow--Pillow P= illow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFil= e.compile() assembled per-glyph images into a combined bitmap with Image.ne= w("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), a= llowing a font to trigger excessive allocation during conversion or saving.=
This issue is fixed in version 12.3.0. 2026-07-06 7.5 CVE-2026-54060 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-54060 ] python-pillow--Pillow Pill=
ow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_cha= r() read the BBX width and height field from a BDF font file and passed att= acker-controlled dimensions to Image.new() without calling Image._decompres= sion_bomb_check(), bypassing Pillow's documented decompression bomb protect= ion and allowing excessive memory allocation. This issue is fixed in versio=
n 12.3.0. 2026-07-06 7.5 CVE-2026-55379 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55379 ] python-pillow--Pillow Pillow is a Python imaging librar=
y. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimen= sions from the GD 2.x header and stored them in self._size without calling = Image._decompression_bomb_check(), allowing a crafted .gd file to trigger e= xcessive C-heap allocation when loaded. This issue is fixed in version 12.3= .0. 2026-07-06 7.5 CVE-2026-55380 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-55380 ] qax-os--excelize Excelize is a Go language library for reading=
and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet(=
) function in github.com/xuri/excelize/v2 uses an attacker-controlled <row = r=3D"N"> XML attribute value directly as the length argument to make([]xlsx= Row, row) without validating it against the Excel row limit (TotalRows =3D = 1,048,576). A specially crafted XLSX file can trigger two denial-of-service=
variants: (A) an out-of-memory process kill when r=3D2147483647 forces a ~=
16 GB allocation attempt, and (B) a runtime panic via out-of-bounds slice i= ndexing when r=3D-1. Any service that opens attacker-supplied XLSX files an=
d calls GetCellValue is affected. No authentication is required. This issue=
is fixed in version 2.11.0. 2026-07-10 7.5 CVE-2026-54063 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-54063 ] Qualcomm, Inc.--Snapdragon Memory Cor= ruption when processing invalid HT40 channel layouts during dynamic channel=
switching operations. 2026-07-06 8.8 CVE-2026-25268 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-25268 ] Qualcomm, Inc.--Snapdragon Memory Corruptio=
n when allocating memory with sizes that exceed the maximum allowed value. = 2026-07-06 7.8 CVE-2026-21379 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -21379 ] Qualcomm, Inc.--Snapdragon Cryptographic Issue when using a static=
initialization vector for AES-GCM key wrapping, which requires a unique va= lue for each call to ensure security. 2026-07-06 7.1 CVE-2026-21383 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-21383 ] Qualcomm, Inc.--Snapdragon M= emory Corruption when processing asynchronous input parameters due to impro= per handling of modified values between check and use. 2026-07-06 7.8 CVE-2= 026-25271 [
https://www.cve.org/CVERecord?id=3DCVE-2026-25271 ] QuantumNous= --new-api New API is a large language mode (LLM) gateway and artificial int= elligence (AI) asset management system. Prior to 0.12.0-alpha.1, the defaul=
t SSRF protection configuration did not apply IP filtering to hostnames; wi=
th ApplyIPFilterForDomain disabled by default, URL validation checked domai=
n allow/block rules but did not resolve a hostname and validate the resolve=
d IP address, allowing authenticated users to configure Webhook, Bark, or G= otify notification URLs that point at an internal or metadata IP address. T= his issue is fixed in version 0.12.0-alpha.1. 2026-07-09 7.7 CVE-2026-33655=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-33655 ] rabbitmq--rabbitmq-s= erver RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the Rab= bitMQ stream listener does not enforce the configured stream frame-size lim=
it while assembling frames during authentication and before Tune negotiatio=
n, allowing an unauthenticated remote client to declare oversized frame len= gths and consume broker memory in rabbit_stream_core. This issue is fixed i=
n version 4.2.6. 2026-07-10 7.5 CVE-2026-57220 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-57220 ] rabilal--WP Learn Manager The WP Learn Manager pl= ugin for WordPress is vulnerable to authorization bypass in all versions up=
to, and including, 1.1.8. This is due to the plugin not properly verifying=
that a user is authorized to perform an action. This makes it possible for=
unauthenticated attackers to install and activate arbitrary plugins from t=
he WordPress.org repository on the vulnerable site. 2026-07-08 9.8 CVE-2026= -12153 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12153 ] RafyMrX--TOKO-= ONLINE-ROTI A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up t=
o ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability =
is an unknown functionality of the file proses/login.php. The manipulation =
of the argument Username leads to sql injection. Remote exploitation of the=
attack is possible. The exploit is publicly available and might be used. T= his product follows a rolling release approach for continuous delivery, so = version details for affected or updated releases are not provided. The vend=
or was contacted early about this disclosure but did not respond in any way=
. 2026-07-12 7.3 CVE-2026-15489 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-15489 ] RafyMrX--TOKO-ONLINE-ROTI A security flaw has been discovered in=
RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. A= ffected by this issue is some unknown functionality of the file proses/add.= php. The manipulation of the argument kode_produk/kd_cs results in sql inje= ction. The attack can be executed remotely. The exploit has been released t=
o the public and may be used for attacks. This product implements a rolling=
release for ongoing delivery, which means version information for affected=
or updated releases is unavailable. The vendor was contacted early about t= his disclosure but did not respond in any way. 2026-07-12 7.3 CVE-2026-1549=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15490 ] RafyMrX--TOKO-ONLIN= E-ROTI A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddf= e1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This m= anipulation causes missing authentication. The attack is possible to be car= ried out remotely. This product adopts a rolling release strategy to mainta=
in continuous delivery. Therefore, version details for affected or updated = releases cannot be specified. The vendor was contacted early about this dis= closure but did not respond in any way. 2026-07-12 7.3 CVE-2026-15491 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-15491 ] react--create-react-app A = vulnerability was detected in react create-react-app up to 5.0.1 on macOS. = This affects the function startBrowserProcess of the file openBrowser.js of=
the component react-dev-utils. Performing a manipulation results in os com= mand injection. Remote exploitation of the attack is possible. The exploit =
is now public and may be used. The project was informed of the problem earl=
y through an issue report but has not responded yet. 2026-07-06 7.3 CVE-202= 6-14802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14802 ] Red Hat--Red = Hat Advanced Cluster Security for Kubernetes 4.10 A flaw was found in Red H=
at Advanced Cluster Security for Kubernetes (RHACS). Central does not limit=
the depth of GraphQL queries served on the authenticated GraphQL API. An a= uthenticated user with a valid API token can send deeply nested queries tha=
t cause excessive resource consumption in Central, resulting in a denial of=
service for the management plane. 2026-07-06 7.7 CVE-2026-9165 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-9165 ] Red Hat--Red Hat Enterprise Linux=
10 A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_searc= h_base option is not explicitly configured, SSSD searches the entire LDAP d= irectory tree for sudoRole objects. An authenticated attacker with write ac= cess to any subtree can inject a sudoRole object granting root-level sudo p= rivileges on all SSSD-enrolled hosts. 2026-07-07 8.8 CVE-2026-14474 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-14474 ] Red Hat--Red Hat Enterprise = Linux 10 A path traversal flaw was found in SSSD's AD GPO provider. The ad_= gpo_extract_smb_components() function does not sanitize .. sequences in the=
gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management=
access to write files outside the GPO cache directory as root. On default = RHEL configurations with SELinux enforcing, this can be used to inject Kerb= eros configuration leading to authentication bypass. 2026-07-07 8 CVE-2026-= 14476 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14476 ] Red Hat--Red Ha=
t Enterprise Linux 10 A heap buffer overflow vulnerability was found in GSt= reamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC serve=
r that advertises a 16bpp framebuffer and sends Hextile-encoded updates, th=
e Hextile background fill path writes 32-bit pixel values into a buffer all= ocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap w= rite that can lead to denial of service (process crash) and potential memor=
y corruption. 2026-07-09 7.1 CVE-2026-59691 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-59691 ] Red Hat--Red Hat Enterprise Linux 10 A stack buffer = overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS = handshake, the peer certificate Subject Distinguished Name is printed into =
a fixed-size 2048-byte stack buffer without bounds checking. A remote unaut= henticated attacker can send a certificate with an oversized Subject DN tha=
t exceeds the buffer, causing a stack buffer overflow and process crash, re= sulting in denial of service. 2026-07-09 7.5 CVE-2026-59692 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-59692 ] Red Hat--Red Hat Enterprise Linux 6 =
A flaw was found in GIMP's PNM file format parser. When parsing a specially=
crafted PNM file, the pnmscanner_gettoken() function writes a null termina= tor one byte past the end of a stack-allocated buffer due to an off-by-one = error in the loop boundary check. This could lead to memory corruption, pot= entially resulting in denial of service or arbitrary code execution. 2026-0= 7-06 7.3 CVE-2026-58380 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58380=
] Red Hat--Red Hat Enterprise Linux 6 A flaw was found in GIMP's PSD parse=
r. An integer overflow in read_RLE_channel() can cause an undersized heap a= llocation for the RLE row-length table, after which subsequent per-row writ=
es corrupt heap memory. This could lead to memory corruption, potentially r= esulting in denial of service or arbitrary code execution. 2026-07-07 7.3 C= VE-2026-58384 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58384 ] Red Hat= --Red Hat OpenShift AI (RHOAI) A flaw was found in the file_type content de= tector of guardrails-detectors. This vulnerability allows a remote attacker=
to supply an arbitrary XML Schema Definition (XSD) string, which is proces= sed without proper restrictions. This can lead to server-side requests to a= rbitrary URLs or local file reads, potentially resulting in sensitive infor= mation disclosure, such as cloud provider credentials or access to internal=
network services. 2026-07-10 9.3 CVE-2026-15143 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-15143 ] Red Hat--Red Hat OpenShift AI (RHOAI) A flaw wa=
s found in the `guardrails-detectors` component. This vulnerability allows =
a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by = submitting a specially crafted XML Schema Definition (XSD) string. This can=
lead to unauthorized access to sensitive information, including credential=
s from cloud metadata services, Kubernetes API, internal MinIO, and other i= nternal network endpoints. Additionally, it enables local file reads of cri= tical data such as service account tokens and pod secrets. 2026-07-10 9.3 C= VE-2026-15378 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15378 ] repomix= --repomix repomix contains a server-side request forgery vulnerability in t=
he POST /api/pack endpoint that allows unauthenticated attackers to make ar= bitrary outbound requests. The endpoint fails to properly validate
http://,=
https://, and file:// URLs before passing them to git clone, enabling atta= ckers to access private network addresses, GCP metadata services, or local = filesystem paths. 2026-07-08 9.3 CVE-2026-59702 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-59702 ] repomix--repomix repomix contains a local file i= nclusion vulnerability in the git clone endpoint that allows unauthenticate=
d attackers to read arbitrary local git repositories. The isValidRemoteValu=
e function in src/core/git/gitRemoteParse.ts fails to block file:// URLs, p= ermitting attackers to supply file:// scheme URLs that bypass validation an=
d are passed directly to git clone, enabling unauthorized access to all tra= cked file contents on the server filesystem. 2026-07-08 7.5 CVE-2026-59703 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-59703 ] rnzo--Connect Contact=
Form 7 and Mailchimp The Connect Contact Form 7 and Mailchimp plugin for W= ordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge F= ield Values in all versions up to, and including, 0.9.78.06 due to insuffic= ient input sanitization and output escaping. This makes it possible for una= uthenticated attackers to inject arbitrary web scripts in pages that will e= xecute whenever a user accesses an injected page. The injected payload is o= nly triggered when a privileged user (Administrator) performs a Contact Loo= kup for the email address submitted via the CF7 form, meaning execution is = deferred until an administrator interacts with the affected entry. 2026-07-=
09 7.2 CVE-2026-15000 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15000 ]=
ronf--asyncssh AsyncSSH is a Python package which provides an asynchronous=
client and server implementation of the SSHv2 protocol on top of the Pytho=
n asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbi= trary files on the asyncssh SCP client's filesystem by sending filenames co= ntaining ../ traversal sequences because _parse_cd_args in scp.py returns s= erver-provided names verbatim and _recv_files joins them to the destination=
path without enforcing the target directory boundary. This issue is fixed =
in version 2.23.1. 2026-07-08 8.1 CVE-2026-54591 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-54591 ] RustDesk--RustDesk RustDesk before 1.4.9 does n=
ot enforce a session's authorized connection scope on the server side, so a=
peer granted a limited session type (FileTransfer, PortForward, ViewCamera=
, or Terminal) can send control messages and login options reserved for a f= ull Remote session. An authenticated remote peer can exploit this missing s= cope check to act outside its granted scope, injecting out-of-scope control=
messages to observe and control the host beyond the permissions it was giv= en. 2026-07-10 8.3 CVE-2026-57850 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-57850 ] ruvnet--ruflo Ruflo is an agent meta-harness for Claude Code a=
nd Codex. Prior to 3.16.3, ruflo's default docker-compose deployment expose=
d the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentic= ation, allowing an unauthenticated network attacker to invoke tools/call to=
terminal_execute, obtain a shell in the bridge container, read provider AP=
I keys, and poison AgentDB learning-store patterns. This issue is fixed in = version 3.16.3. 2026-07-09 10 CVE-2026-59726 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-59726 ] seaweedfs--seaweedfs SeaweedFS is a distributed sto= rage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path=
segments in the X-Amz-Copy-Source header used by CopyObject and UploadPart= Copy, allowing an authenticated identity scoped to one bucket to read objec=
ts from other buckets through server-side copy. This issue is fixed in vers= ion 4.34. 2026-07-08 7.7 CVE-2026-55874 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55874 ] SecureAge--CatchPulse A security vulnerability has been=
detected in SecureAge CatchPulse up to 10.9.3. The affected element is an = unknown function in the library saappctl.sys of the component Driver. Such = manipulation leads to heap-based buffer overflow. An attack has to be appro= ached locally. The exploit has been disclosed publicly and may be used. The=
vendor was contacted early about this disclosure. 2026-07-12 7.8 CVE-2026-= 15506 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15506 ] Semtek Informat= ics Software Consulting Trade Ltd. Co.--SEM-PMP Improper neutralization of = special elements used in an SQL command ('SQL injection') vulnerability in = Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Comman=
d Line Execution through SQL Injection. This issue affects SEM-PMP: through=
23042026. 2026-07-10 9.8 CVE-2026-5801 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-5801 ] sergomanov--SmartHomeAdatum A vulnerability was identifi=
ed in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45c= e12c. This impacts an unknown function of the file users.php of the compone=
nt Login. Such manipulation of the argument Login leads to sql injection. T=
he attack may be launched remotely. This product operates on a rolling rele= ase basis, ensuring continuous delivery. Consequently, there are no version=
details for either affected or updated releases. The vendor was contacted = early about this disclosure but did not respond in any way. 2026-07-12 7.3 = CVE-2026-15498 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15498 ] shen2-=
- The =C3=A5=C2=A4=C5=A1=C3=A8=C2=AF=C2=B4=C3=A7=C2=A4=C2=BE=C3=A4=C2=BC=C5= =A1=C3=A5=C5=92=E2=80=93=C3=A8=C2=AF=E2=80=9E=C3=A8=C2=AE=C2=BA=C3=A6=C2=A1= =E2=80=A0 plugin for WordPress is vulnerable to Privilege Escalation in all=
versions up to, and including, 1.2. The vulnerability exists due to a miss= ing capability and nonce check on a directly web-accessible API endpoint, c= ombined with a trivially forgeable HMAC-SHA1 signature keyed on an always-e= mpty WordPress option, which allows the endpoint's `update_option` handler =
to pass attacker-controlled `option` and `value` parameters directly to Wor= dPress's `update_option` function without any allowlist or sanitization. Th=
is makes it possible for unauthenticated attackers to update arbitrary Word= Press options - such as setting `default_role` to `administrator` and enabl= ing open registration - and subsequently register an account with full admi= nistrator privileges. 2026-07-08 8.8 CVE-2026-14482 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-14482 ] Siemens--CPCI85 Central Processing/Communica= tion A vulnerability has been identified in CPCI85 Central Processing/Commu= nication (All versions < V26.20), SICORE Base system (All versions < V26.20= .0). The affected application contains insufficient validation of authentic= ation credentials when processing administrative account modifications thro= ugh the web API. This could allow an authenticated attacker to bypass secur= ity controls and gain unauthorized elevated privileges. 2026-07-09 7.2 CVE-= 2026-54801 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54801 ] SimpleMach= ines--SMF Simple Machines Forum 2.1 prior to 2.1.8 and 3.0 prior to 3.0 Alp=
ha 5 contains an authorization bypass vulnerability in Sources/Actions/Atta= chmentApprove.php where a single-character operator error causes the permis= sion check to always pass regardless of user permissions. An authenticated = low-privileged user can approve, reject, or delete any pending attachments =
on any board without holding the required approve_posts permission, bypass = moderation queues for their own uploads, and enumerate and delete other use= rs' pending attachments. 2026-07-10 7.1 CVE-2026-39903 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-39903 ] Sipeed--PicoClaw A security vulnerability=
has been detected in Sipeed PicoClaw up to 0.2.9. This affects the functio=
n IPAllowlist of the file web/backend/middleware/access_control.go of the c= omponent Launcher. Such manipulation leads to improper access controls. The=
attack may be performed from remote. The exploit has been disclosed public=
ly and may be used. The name of the patch is 3126. A patch should be applie=
d to remediate this issue. 2026-07-10 7.3 CVE-2026-15319 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-15319 ] siyuan-note--siyuan SiYuan is an open-s= ource personal knowledge management system. Prior to 3.7.1, the /snippets/*= filepath route handler serveSnippets in kernel/server/serve.go joins a sing= le-decoded request path with the snippets directory without subpath contain= ment or sensitive-path checks, allowing an authenticated request such as /s= nippets/%2e%2e/%2e%2e/conf/conf.json to read workspace secrets and the docu= ment database. This issue is fixed in versions 3.7.1. 2026-07-09 7.7 CVE-20= 26-59832 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59832 ] siyuan-note-= -siyuan SiYuan is an open-source personal knowledge management system. Prio=
r to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock = concatenates attacker-controlled paths values into SQL predicates used by n= on-SQL search modes, allowing an unauthenticated publish visitor to inject =
a UNION SELECT and return rows from hidden documents by projecting an allow=
ed visible box and path. This issue is fixed in versions 3.7.1. 2026-07-09 = 7.5 CVE-2026-59834 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59834 ] sm= ackcoders--WP Ultimate CSV Importer WordPress Import & Export for CSV, XML =
& Excel The WP Ultimate CSV Importer - WordPress Import & Export for CSV, X=
ML & Excel plugin for WordPress is vulnerable to Remote Code Execution in a=
ll versions up to, and including, 8.0.1 via the 'MappedFields' parameter. T= his is due to missing capability checks on the AJAX handlers for install_ad= don, saveMappedFields, and StartImport, combined with the plugin nonce bein=
g exposed to any authenticated user who can load an admin page, allowing a = Subscriber to install the Import WooCommerce add-on, persist attacker-contr= olled PHP expressions in the MappedFields parameter, and trigger evaluation=
via eval() in ImportHelpers::get_meta_values(). This makes it possible for=
authenticated attackers, with subscriber-level access and above, to execut=
e code on the server. 2026-07-11 8.8 CVE-2026-13353 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-13353 ] smallnest--rpcx rpcx through 1.9.3, fixed in=
commit 047aec1, contains a denial-of-service vulnerability in protocol.Mes= sage.Decode (protocol/message.go). When a message has the compression flag = set, the payload is gzip-decompressed via util.Unzip with no limit on the d= ecompressed output size. The only built-in size guard, protocol.MaxMessageL= ength, is checked against the compressed on-the-wire frame length, not the = decompressed size, so it provides no protection. Because decoding (and deco= mpression) occurs in readRequest before authentication, a single unauthenti= cated connection can send a small (under 2 MB) gzip-compressed message that=
expands to gigabytes of heap allocation, leading to out-of-memory conditio=
ns and service unavailability. 2026-07-08 7.5 CVE-2026-59803 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-59803 ] Snowflake--Snowpark Python SDK SQL = injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-py= thon) versions prior to 1.53.0 could allow authenticated low-privilege user=
s to execute SQL beyond their authorization scope. An attacker could exploi=
t these vulnerabilities by embedding SQL payloads in source database column=
names to escalate privileges via the DataFrameReader.dbapi() API by supply= ing a specially crafted location parameter to DataFrameWriter write methods=
to redirect a COPY INTO to an arbitrary source query, or by including a ba= ckslash-single-quote sequence in an export path to defeat the normalize_pat= h() sanitizer and inject SQL via DataFrame.to_csv(). Successful exploitatio=
n may result in source database compromise, unauthorized cross-tenant data = exfiltration, or unauthorized read of Snowflake account data. 2026-07-08 9.=
6 CVE-2026-15062 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15062 ] Snow= flake--Terraform Provider for Snowflake Snowflake Terraform Provider versio=
ns prior to 2.18.0 contain several security vulnerabilities, including SQL = injection via an unsanitized data source input could result in arbitrary SQ=
L execution under the provider's privileged Snowflake session, potentially = enabling sensitive data exfiltration and minting of long-lived access crede= ntials. Exploitation requires the ability for an attacker to influence a wo= rkspace variable in a pipeline where this data source was enabled. Improper=
neutralization of identifier content in user resource inputs could allow D=
DL injection into user management statements, potentially causing accounts =
to be created with attacker-controlled credentials and without the security=
controls configured by the operator. The fix is available in Snowflake Ter= raform Provider version 2.18.0. Users must manually upgrade. 2026-07-08 8.8=
CVE-2026-15067 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15067 ] socke= tio--socket.io Socket.IO enables bidirectional and low-latency communicatio=
n for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTr= ansport enabled can resolve a crafted session ID such as __proto__ through =
an inherited property of the clients object during WebTransport upgrade han= dling, causing a TypeError and denial of service. This issue is fixed in ve= rsion 6.6.7. 2026-07-08 7.5 CVE-2026-59724 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-59724 ] socketio--socket.io Socket.IO enables bidirectional a=
nd low-latency communication for every platform. From 4.1.0 before 6.6.7, E= ngine.IO protocol v4 polling transport does not properly close the HTTP res= ponse for invalid binary POST requests with Content-Type: application/octet= -stream, allowing an unauthenticated attacker to exhaust server-side connec= tions and sockets. This issue is fixed in version 6.6.7. 2026-07-08 7.5 CVE= -2026-59725 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59725 ] SonicClou= dOrg--sonic-agent A vulnerability was determined in SonicCloudOrg sonic-age=
nt up to 2.7.2. This affects an unknown function of the file sonic-server-c= ontroller/src/main/java/org/cloud/sonic/controller/controller/ExchangeContr= oller.java of the component JWT Authentication Filter. This manipulation ca= uses code injection. The attack may be initiated remotely. The exploit has = been publicly disclosed and may be utilized. The vendor was contacted early=
about this disclosure but did not respond in any way. This vulnerability o= nly affects products that are no longer supported by the maintainer. 2026-0= 7-12 7.3 CVE-2026-15497 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15497=
] SourceCodester--Simple and Nice Shopping Cart Script A vulnerability was=
detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This = affects an unknown part of the file /login.php. Performing a manipulation o=
f the argument Username results in sql injection. Remote exploitation of th=
e attack is possible. The exploit is now public and may be used. 2026-07-09=
7.3 CVE-2026-15190 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15190 ] s= pinnaker--spinnaker Spinnaker is an open source, multi-cloud continuous del= ivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe=
YAML processing bypasses safe deserialization when using CloudFormation de= ployments or CloudFoundry baking. The use of a non-safe constructor allows = arbitrary loading of Java classes, leading to remote code execution. This i= ssue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3. 2026-= 07-10 8.8 CVE-2026-44795 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4479=
5 ] spinnaker--spinnaker Spinnaker is an open source, multi-cloud continuou=
s delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 20= 25.3.4 on their respective release lines, Kustomize bake operations allow u= nsafe YAML tag processing in rosco manifests. This can lead to remote code = execution on rosco pods when performing Kustomize bakes. This issue is fixe=
d in versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4. 2026-07-10 7.5 CV= E-2026-55175 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55175 ] ST Engin= eering iDirect--Evolution iQSeries terminals The iDirect iQ200 does not val= idate CSRF tokens on state-changing API endpoints after authentication. The=
/api/reboot endpoint accepts POST requests authenticated solely by a sessi=
on cookie that lacks the SameSite attribute. A remote attacker can host a m= alicious web page that, when visited by an authenticated administrator, aut= omatically submits a cross-site POST request causing an immediate device re= boot and satellite link loss. Repeated attacks can sustain a denial-of-serv= ice condition. 2026-07-10 8.1 CVE-2026-38057 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-38057 ] ST Engineering iDirect--Evolution iQSeries terminal=
s The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints = without authentication. An unauthenticated attacker with network access can=
retrieve sensitive device information including the serial number, Device =
ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact fir= mware version. The DID and TPK are used for satellite network authenticatio=
n in the iDirect platform, potentially enabling terminal impersonation and = network reconnaissance. 2026-07-10 7.5 CVE-2026-38059 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-38059 ] stanfordnlp--stanza Stanza is a Stanford N=
LP Python library for tokenization, sentence segmentation, NER, and parsing=
of many human languages. Prior to 1.12.2, Stanza model loaders such as sta= nza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_= only=3DTrue) but fall back to torch.load(..., weights_only=3DFalse) on atta= cker-controllable pickle.UnpicklingError, allowing a malicious .pt pretrain=
or model file to execute arbitrary pickle code when a Stanza NLP pipeline = loads it. This issue is fixed in version 1.12.2. 2026-07-08 7.5 CVE-2026-54= 499 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54499 ] stiofansisland--U= sersWP Front-end login form, User Registration, User Profile & Members Dire= ctory plugin for WP The UsersWP plugin for WordPress is vulnerable to Arbit= rary File Deletion in versions up to, and including, 1.2.65. This is due to=
insufficient validation of file-field values in the UsersWP_Validation::va= lidate_fields() function (which falls through to sanitize_text_field() for = fields of type 'file', leaving directory-traversal sequences intact) combin=
ed with the UsersWP_Forms::upload_file_remove() AJAX handler building the d= eletion target from the uploads basedir concatenated with the attacker-cont= rolled metadata value without any realpath canonicalization or uploads-dire= ctory boundary check before calling unlink(). This makes it possible for au= thenticated attackers, with Subscriber-level access and above, to delete ar= bitrary files on the affected site's server, including wp-config. 2026-07-0=
9 8.8 CVE-2026-13492 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13492 ] = stylemix--Motors Car Dealership & Classified Listings Plugin The Motors - C=
ar Dealership & Classified Listings Plugin plugin for WordPress is vulnerab=
le to Stored Cross-Site Scripting via Comment Content and User Biographical=
Info in all versions up to, and including, 1.4.112 due to insufficient inp=
ut sanitization and output escaping. This makes it possible for unauthentic= ated attackers to inject arbitrary web scripts in pages that will execute w= henever a user accesses an injected page. 2026-07-11 7.2 CVE-2026-13114 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-13114 ] surecart--SureCart Ecomm= erce Made Easy For Selling Physical Products, Digital Downloads, Subscripti= ons, Donations, & Payments The SureCart plugin for WordPress is vulnerable =
to privilege escalation via account takeover in versions up to, and includi= ng, 4.2.3. This is due to the plugin not properly validating a user's ident= ity prior to updating their details like email during customer profile sync= hronization from webhook events. This makes it possible for unauthenticated=
attackers to change linked user's email addresses, including administrator=
s if the administrator account is linked to a SureCart customer record, and=
leverage that to reset the user's password and gain access to their accoun=
t if the customer ID is known. 2026-07-11 8.1 CVE-2026-7655 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-7655 ] SUSE--Rancher A vulnerability has bee=
n identified in Fleet's agent-side deployer, which did not filter security-= sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec= .options.namespaceLabels) when applying them to the target namespace. An at= tacker with git push access to a Fleet-monitored repository could overwrite=
Pod Security Standards (PSS) enforcement labels on a target namespace. Thi=
s allows the attacker to weaken admission controls and deploy workloads tha=
t PSS policies would otherwise block. 2026-07-07 8.8 CVE-2026-44938 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-44938 ] symfony--ux Symfony UX is a = JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 = before 3.2.0, the ux:install console command installs files from a recipe k=
it by copying paths listed in a copy-files map, and because Path::isRelativ= e() accepts paths like ../../../etc, a crafted or compromised kit can write=
attacker-controlled content to arbitrary locations or read local files out= side the recipe directory. This issue is fixed in versions 2.36.1 and 3.2.0=
. 2026-07-08 7.8 CVE-2026-55878 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-55878 ] tainacan--Tainacan The Tainacan plugin for WordPress is vulnerab=
le to time-based blind SQL Injection via the 'geoquery' parameter in all ve= rsions up to and including 1.0.3 due to insufficient escaping on the user s= upplied parameter and lack of sufficient preparation on the existing SQL qu= ery. This makes it possible for unauthenticated attackers to append additio= nal SQL queries into already existing queries that can be used to extract s= ensitive information from the database. 2026-07-08 7.5 CVE-2026-6230 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-6230 ] Tanium--Tanium Server Tanium=
addressed a denial of service vulnerability in Tanium Server. 2026-07-08 7=
.5 CVE-2026-15053 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15053 ] tem= platic1--Hide My WP Lite The Hide My WP Lite plugin for WordPress is vulner= able to Arbitrary File Read in versions up to and including 1.3 via the he_= wrapper_js and he_wrapper_css query parameters processed by the elementor_a= ssets_filter() function. This is due to the function concatenating user-sup= plied input directly onto ABSPATH and passing the result to file_get_conten= ts() without any path traversal validation, allow-list, realpath containmen=
t, or extension check; the result is then echoed in the HTTP response. Alth= ough the output is passed through wp_kses_post(), that function only filter=
s HTML tags and does not prevent disclosure of arbitrary file contents. Thi=
s makes it possible for unauthenticated attackers to read the contents of a= rbitrary files on the affected site's server (such as wp-config). Note: The=
exploit requires the Elementor plugin and the 'Hide Elementor' feature to =
be enabled. 2026-07-10 7.5 CVE-2026-13347 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-13347 ] tenteeglobal--Instant Appointment The Instant Appointm= ent plugin for WordPress is vulnerable to arbitrary file uploads due to mis= sing file type validation in the 'insapp_upload_image_as_attachment' functi=
on in all versions up to, and including, 1.2. This makes it possible for un= authenticated attackers to upload arbitrary files on the affected site's se= rver which may make remote code execution possible. 2026-07-10 9.8 CVE-2026= -15282 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15282 ] Teracity Softw= are Technologies Inc.--TeraMIS Authorization bypass through User-Controlled=
key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pr= ivilege Abuse. This issue affects TeraMIS: from V03.26.01.14 through 30.04.= 2026. 2026-07-10 8.8 CVE-2026-6212 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-6212 ] themeatelier--ChatHelp Click to Chat Button, WooCommerce Chat =
to Order & Floating Chat Form The Chat Help - Click to Chat Button & Form p= lugin for WordPress is vulnerable to Sensitive Information Exposure in all = versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/ch= at-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the p= lugin not performing any authentication and authorization checks. This make=
s it possible for unauthenticated attackers to extract sensitive data inclu= ding customer names, email addresses, phone numbers, WhatsApp messages, com= plete geolocation data (IP addresses, city, country, ISP, coordinates), dev= ice fingerprinting information (browser, OS, screen resolution), and WordPr= ess account credentials (user IDs, usernames, emails, names) for logged-in = users who submit forms. 2026-07-10 7.5 CVE-2026-15291 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-15291 ] tigroumeow--Code Engine PHP Snippets, AI F= unctions & Automation for WordPress The Code Engine plugin for WordPress is=
vulnerable to Remote Code Execution in all versions up to, and including, = 0.3.5 via the 'code-engine' shortcode. This is due to the plugin not restri= cting access to the code injecting functionality of the plugin. This makes =
it possible for authenticated attackers, with Contributor-level access and = above, to execute code on the server. 2026-07-11 8.8 CVE-2025-6784 [ https:= //www.cve.org/CVERecord?id=3DCVE-2025-6784 ] tombgtn--Simple Coherent Form = The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary fi=
le deletion due to insufficient file path validation in the removeUploadDir=
function in all versions up to, and including, 2.4.13. This makes it possi= ble for unauthenticated attackers to delete arbitrary files on the server, = which can easily lead to remote code execution when the right file is delet=
ed (such as wp-config.php). The scf_get_id_upload endpoint freely issues a = valid scf_upload_file_removal nonce to any unauthenticated visitor, and the=
removal endpoint's secondary hash check is forgeable offline because it re= lies on a hardcoded salt embedded in the plugin source, meaning neither con= trol presents a real authorization boundary. 2026-07-08 9.1 CVE-2026-14487 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-14487 ] topoteretes--cognee C= ognee before 1.2.0 contains an improper access control vulnerability that a= llows unauthenticated attackers to overwrite the global LLM provider config= uration by self-registering an account and calling the settings endpoint, w= hich performs no admin or superuser check. Attackers can redirect all LLM o= perations instance-wide to an attacker-controlled endpoint by exploiting th=
e process-wide singleton configuration cache, enabling exfiltration of prom= pts, uploaded documents, extracted entities, and knowledge graph content fr=
om all users. 2026-07-07 9.1 CVE-2026-58473 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-58473 ] totalbounty--Widget Logic Visual The Widget Logic Vi= sual plugin for WordPress is vulnerable to Remote Code Execution in all ver= sions up to, and including, 1.52 via the widget_logic_visual_check_visibili=
ty function. This is due to missing capability check and nonce verification=
on the widget-logic-update-conditional-tags AJAX action combined with insu= fficient sanitization of the 'nwlv[cod-tag]' parameter before storage and s= ubsequent use in an eval() call. This makes it possible for authenticated a= ttackers, with subscriber-level access and above, to execute code on the se= rver. 2026-07-08 8.8 CVE-2026-14158 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-14158 ] TOTOLINK--A3000RU A security vulnerability has been detected=
in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX20=
0 up to 20260906. Affected by this issue is some unknown functionality of t=
he file /etc/boa/boa.conf of the component Web Interface. The manipulation = leads to least privilege violation. The attack may be initiated remotely. T=
he attack's complexity is rated as high. The exploitation is known to be di= fficult. 2026-07-09 7.5 CVE-2026-15271 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15271 ] Trendnet--TEW-635BRM A vulnerability was identified in = Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of=
the file /sbin/rc of the component Web Service. Such manipulation of the a= rgument device_name leads to stack-based buffer overflow. The attack can be=
executed remotely. The exploit is publicly available and might be used. Th=
e vendor explains: "We are unable to confirm if the vulnerability exists. T= his item has been EOL since 2011. We will make an official announcement of = possible vulnerabilities, and recommend users to switch devices." This vuln= erability only affects products that are no longer supported by the maintai= ner. 2026-07-12 8.8 CVE-2026-15480 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-15480 ] Trendnet--TEW-635BRM A security flaw has been discovered in T= rendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function i= poa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. P= erforming a manipulation of the argument ipoa_ipaddr results in command inj= ection. The attack is possible to be carried out remotely. The exploit has = been released to the public and may be used for attacks. The vendor explain=
s: "We are unable to confirm if the vulnerability exists. This item has bee=
n EOL since 2011. We will make an official announcement of possible vulnera= bilities, and recommend users to switch devices." This vulnerability only a= ffects products that are no longer supported by the maintainer. 2026-07-12 = 8.8 CVE-2026-15481 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15481 ] TR= ENDnet--TEW-821DAP A security vulnerability has been detected in TRENDnet T= EW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/= tools_nslookup of the component ssi. The manipulation of the argument nsloo= kup_target leads to buffer overflow. It is possible to initiate the attack = remotely. The vendor explains: "We are unable to confirm the existence of t=
he vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EO=
L. " This vulnerability only affects products that are no longer supported =
by the maintainer. 2026-07-12 8.8 CVE-2026-15483 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-15483 ] TRENDnet--TEW-821DAP A vulnerability was detect=
ed in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub= _41EC14 of the file /goform/tools_nslookup of the component ssi. The manipu= lation results in buffer overflow. It is possible to launch the attack remo= tely. The vendor explains: "We are unable to confirm the existence of the v= ulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "=
This vulnerability only affects products that are no longer supported by t=
he maintainer. 2026-07-12 8.8 CVE-2026-15484 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-15484 ] u-boot--u-boot U-Boot through 2026.04-rc3 contains =
a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) = when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS ser= ver to overflow the 2048-byte nfs_path_buff buffer by returning multiple re= lative symlink targets that are appended without cumulative length validati= on. Attackers can send two or more READLINK responses containing relative s= ymlink targets of approximately 1100 bytes each to corrupt adjacent BSS var= iables including nfs_server_ip, nfs_server_mount_port, nfs_server_port, nfs= _our_port, nfs_state, and rpc_id, potentially achieving memory corruption a=
nd control over the NFS client state machine. 2026-07-08 8.2 CVE-2026-29009=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-29009 ] u-boot--u-boot U-Boo=
t through 2026.04-rc3 contains an integer underflow vulnerability in the tc= p_rx_state_machine() function (net/tcp.c) that allows a network-adjacent at= tacker to crash the bootloader by sending a malformed TCP SYN+ACK packet wi=
th a manipulated data offset field causing payload_len to become negative. = When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp= _seg_in_wnd() validation, the negative payload_len is implicitly converted =
to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in st= ore_block(), causing an immediate crash that prevents device boot and may e= nable memory corruption when CONFIG_LMB is disabled. 2026-07-08 7.5 CVE-202= 6-29008 [
https://www.cve.org/CVERecord?id=3DCVE-2026-29008 ] udecode--plat=
e Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1= .4, the media embed renderer trusts serialized provider or sourceUrl metada=
ta in useMediaState and skips parseMediaUrl protocol validation, allowing a=
crafted Plate document to set a known video provider while keeping url as =
a javascript: iframe source that the registry MediaEmbedElement renders dir= ectly as an iframe src when a victim opens the document. This issue is fixe=
d in version 53.1.4. 2026-07-08 8.7 CVE-2026-55596 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-55596 ] ultimatemember--Ultimate Member User Profile,=
Registration, Login, Member Directory, Content Restriction & Membership Pl= ugin The Ultimate Member - User Profile, Registration, Login, Member Direct= ory, Content Restriction & Membership Plugin plugin for WordPress is vulner= able to blind SQL Injection via the search parameter in all versions up to,=
and including, 2.10.1 due to insufficient escaping on the user supplied pa= rameter and lack of sufficient preparation on the existing SQL query. This = makes it possible for unauthenticated attackers to append additional SQL qu= eries into already existing queries that can be used to extract sensitive i= nformation from the database. This vulnerability was partially patched in v= ersion 2.9.2 when initially addressing CVE-2025-0308. 2026-07-10 7.5 CVE-20= 26-15290 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15290 ] unclecode--c= rawl4ai Crawl4AI is an open-source LLM-friendly web crawler and scraper. Pr= ior to 0.9.0, the Docker API server accepted request-supplied browser_confi= g.extra_args, which flowed into Chromium's launch arguments. An attacker co= uld inject Chromium switches that replace a child-process launch command to= gether with --no-zygote, causing Chromium to fork or exec an attacker-contr= olled command as the container's runtime user. The Docker API is unauthenti= cated by default, so a single request yields arbitrary command execution. T= his issue is fixed in version 0.9.0. 2026-07-06 10 CVE-2026-57572 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-57572 ] unclecode--crawl4ai Crawl4AI i=
s an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when=
the crawler saves a downloaded file, the destination filename was taken fr=
om attacker-influenced input and joined to the downloads directory with no = confinement. A filename containing an absolute path or traversal escaped th=
e downloads directory, giving an arbitrary file write with attacker-control= led contents; the HTTP crawler path uses the response Content-Disposition f= ilename and the browser crawler path uses the download's suggested filename=
. Because the written bytes are attacker-controlled, this can escalate to r= emote code execution. This issue is fixed in version 0.9.0. 2026-07-06 9.6 = CVE-2026-57571 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57571 ] unclec= ode--crawl4ai Crawl4AI is an open-source LLM-friendly web crawler and scrap= er. Prior to 0.9.0, the Docker API server applied its SSRF destination chec=
k on the non-streaming /crawl path but not on the streaming path. handle_st= ream_crawl_request passed seed URLs straight to the crawler with no destina= tion validation, allowing a remote unauthenticated client to call POST /cra= wl/stream or POST /crawl with crawler_config.stream=3Dtrue with a URL point= ing at an internal, private, or link-local address; the server fetched it a=
nd streamed the response body back. This issue is fixed in version 0.9.0. 2= 026-07-06 8.6 CVE-2026-57573 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 57573 ] Vikunja--Vikunja Vikunja before 2.2.1 contains an authorization fla=
w where the LinkSharing.ReadAll endpoint exposes share hashes to users with=
read access, enabling permission escalation to admin-level shares. The Get= TaskAttachment endpoint performs permission checks against user-supplied ta=
sk IDs but fetches attachments by sequential ID without verifying ownership=
, allowing attackers to download and delete all file attachments across all=
projects instance-wide. 2026-07-10 9.8 CVE-2026-56765 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-56765 ] vllm-project--vllm vLLM is a high-through= put and memory-efficient inference and serving engine for LLMs. Prior to 0.= 24.0, a frontend-legal multi-request speculative decoding workload can caus=
e the rejection sampler to produce a recovered token equal to the model voc= abulary size boundary value, which is then converted to negative one when t=
he engine selects the next live token for a request and is written back int=
o the drafter's input ids; that out-of-vocabulary value is later consumed b=
y the model's embedding and attention path and crashes the engine worker wi=
th a GPU device-side assertion. The same triggering request sequence is rea= chable through the public gRPC Generate and Abort endpoints, so a remote cl= ient that can send generation requests can crash the shared engine worker, = aborting concurrent requests and causing a service-wide denial of service f=
or other clients of the deployment until the worker is restarted. This issu=
e is fixed in version 0.24.0. 2026-07-06 7.5 CVE-2026-54234 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-54234 ] Vtiger--Vtiger CRM Vtiger CRM before=
8.4.0 contains an authenticated file upload vulnerability that allows low-= privileged users to achieve remote code execution by uploading a .phar file=
containing arbitrary PHP code through the Documents module, bypassing the = extension denylist in config.inc.php which omits the .phar extension. The u= ploaded file is stored with its original .phar extension under the web-acce= ssible storage directory, and a misconfigured .htaccess using Apache 2.2 sy= ntax is silently ignored on Apache 2.4 deployments, allowing unauthenticate=
d HTTP requests to directly execute the uploaded PHP payload. 2026-07-07 8.=
8 CVE-2026-23697 [
https://www.cve.org/CVERecord?id=3DCVE-2026-23697 ] Vtig= er--Vtiger CRM Vtiger CRM through 8.4.0 contains an authenticated remote co=
de execution vulnerability in the admin module import feature that allows a= dministrator-level attackers to upload arbitrary PHP files by submitting a = crafted zip archive through the ModuleManager import function, which extrac=
ts contents directly into the modules/ directory under the web root without=
validating file types beyond the manifest.xml descriptor. Attackers can pl= ace executable PHP files in the modules/ directory that become directly acc= essible via HTTP, bypassing Vtiger's authentication and authorization layer=
entirely since Apache resolves the path and invokes the PHP interpreter be= fore the application routing layer is involved, resulting in a persistent w=
eb shell independent of the originating session. 2026-07-07 7.2 CVE-2026-23= 698 [
https://www.cve.org/CVERecord?id=3DCVE-2026-23698 ] wclovers--WCFM Me= mbership WooCommerce Memberships for Multivendor Marketplace The WCFM Membe= rship - WooCommerce Memberships for Multivendor Marketplace plugin for Word= Press is vulnerable to Insecure Direct Object Reference in all versions up = to, and including, 2.11.10. This is due to the 'wcfmvm_membership_change' A= JAX action not validating user permission to modify other users. This makes=
it possible for authenticated attackers, with vendor level access and abov=
e, to change any user's role to 'wcfm_vendor' by changing their membership = plan. 2026-07-08 8.1 CVE-2026-3688 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-3688 ] Webbeyaz Web Design--Medikm Web Improper neutralization of spe= cial elements used in an SQL command ('SQL injection') vulnerability in Web= beyaz Web Design Medik=C3=83=C2=BCm Web allows SQL Injection. This issue af= fects Medik=C3=83=C2=BCm Web: through 08072026.=C2=A0NOTE: The vendor was c= ontacted and it was learned that the product is not supported. 2026-07-08 9=
.8 CVE-2026-8307 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8307 ] WebPr= os--Plesk An improper authorization vulnerability in the Plesk XML API allo=
ws an authenticated user to inject arbitrary configuration directives, resu= lting in arbitrary file write as root and full privilege escalation on the = underlying server. 2026-07-06 9.9 CVE-2026-48614 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-48614 ] Webpros--Plesk Incorrect authorization in the X= ML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authen= ticated customer to look up domains they do not own, because ownership is e= nforced only for certain lookup filters and schema validation is bypassed f=
or legacy protocol versions. This results in cross-tenant disclosure of oth=
er tenants' FTP credentials stored in cleartext, which can be leveraged to = execute code as another tenant's system user. 2026-07-08 9.9 CVE-2026-56843=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-56843 ] WebRehab--Super Form=
s Drag & Drop Form Builder The Super Forms - Drag & Drop Form Builder plugi=
n for WordPress is vulnerable to Arbitrary File Upload in all versions up t=
o, and including, 6.3.313 via the submit_form function. This is due to miss= ing file type validation and the absence of any capability check on the sub= mit_form nopriv AJAX handler, whose only barrier is a session nonce freely = obtainable by unauthenticated visitors via a separate nopriv endpoint. This=
makes it possible for unauthenticated attackers to upload files that may b=
e executable, which makes remote code execution possible. The nonce require= ment is trivially bypassed because the super_create_nonce nopriv AJAX actio=
n allows any unauthenticated visitor to mint a valid sf_nonce and session c= ookie in a single prior request, reducing exploitation to two unauthenticat=
ed HTTP requests. 2026-07-10 9.8 CVE-2026-14894 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-14894 ] Wireshark Foundation--Wireshark DBS Etherwatch f= ile parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows den= ial of service 2026-07-08 7.5 CVE-2026-15167 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-15167 ] withastro--astro Astro is a web framework for conte= nt-driven websites. Version 6.4.7 performs authorization decisions on a par= tially decoded pathname after reaching the iterative URL decoder limit, whi=
le later rewrite route matching performs an additional decodeURI() operatio=
n and can resolve the request to a protected route. This issue is fixed in = version 6.4.8. 2026-07-08 8.2 CVE-2026-59731 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-59731 ] wordpresschef--Salon Booking System Free Version Th=
e Salon Booking System - Free Version plugin for WordPress is vulnerable to=
Cross-Site Request Forgery in all versions up to, and including, 10.30.32.=
This is due to missing or incorrect nonce validation on the setCustomText = function. This makes it possible for unauthenticated attackers to inject ar= bitrary PHP code into the web-accessible translate-constants.php file withi=
n the plugin directory, enabling remote code execution on the server via a = forged request granted they can trick a site administrator into performing =
an action such as clicking on a link. sanitize_text_field() is applied to t=
he POST 'value' parameter but does not neutralize the characters - single q= uotes, parentheses, semicolons, $, and [] - required to break out of the PH=
P string literal into which the value is interpolated before being written =
to disk via file_put_contents(). 2026-07-10 8.8 CVE-2026-15070 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-15070 ] WP Grid Builder--WP Grid Builder = The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalat= ion in all versions up to, and including, 2.3.3. This is due to missing aut= horization and meta key validation in the `update()` handler for the `/wp-j= son/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticat=
ed attackers, with Subscriber-level access and above, to elevate their priv= ileges to Administrator by updating their own `wp_capabilities` user meta w= ith a crafted nested array payload. 2026-07-11 8.8 CVE-2026-13756 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-13756 ] wpazleen--Post Export Import w= ith Media The Post Export Import with Media plugin for WordPress is vulnera= ble to Arbitrary File Upload in all versions up to, and including, 1.13.1 v=
ia the import_media_file_secure function. This is due to insufficient file = extension validation caused by a trailing-dot filename bypass, where the ex= tension allow-list check in ajax_import_media_start() uses pathinfo() on th=
e raw ZIP entry name (e.g., 'shell.php.'), which returns an empty string fo=
r the extension, causing the allow-list guard to be skipped and the file to=
be extracted to a temporary location, after which import_media_file_secure=
() copies it into the WordPress uploads directory without re-validating the=
extension. This makes it possible for authenticated attackers, with admini= strator-level access and above, to upload files that may be executable, whi=
ch makes remote code execution possible. 2026-07-10 7.2 CVE-2026-13430 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-13430 ] wpdevteam--Essential Addo=
ns for Elementor Popular Elementor Templates & Widgets The Essential Addons=
for Elementor - Popular Elementor Templates & Widgets plugin for WordPress=
is vulnerable to Authenticated Account Takeover via Email Header Injection=
in all versions up to, and including, 6.6.10 This is due to insufficient s= erver-side validation of a Login/Register widget setting used to construct = outgoing email headers - the allowed-values restriction is enforced only in=
the client-side editor UI and not on the server, and the applied sanitizat= ion does not strip or encode CR/LF characters, allowing CRLF sequences stor=
ed in that setting to survive into raw mail headers. This makes it possible=
for authenticated attackers, with Contributor-level access and above, to i= nject an additional Bcc header into the WordPress administrator's password-= reset notification email, receive a copy of a valid administrator password-= reset link, and achieve full administrator account takeover. 2026-07-11 8.8=
CVE-2026-15155 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15155 ] wpdo5= ea--DoLogin Security The DoLogin Security plugin for WordPress is vulnerabl=
e to Authentication Bypass via Insufficient Randomness in all versions up t=
o, and including, 4.3. The vulnerability exists because `dologin\s::rrand()=
` seeds the Mersenne Twister with `mt_srand((double) microtime() * 1000000)=
` - discarding the integer-seconds component of `microtime()` and constrain= ing the seed to a range of approximately 10^6 values (~20 bits of entropy) =
- after which every character of the 32-character magic-link token is drawn=
sequentially with `mt_rand()`, making the entire token a deterministic fun= ction of that seed. Because `Pswdless::try_login()` is registered on the un= authenticated `init` hook, resolves the target account by the auto-incremen=
t numeric ID embedded in the `?dologin=3D<id>.<hash>` parameter, performs t=
he hash comparison using a non-constant-time `!=3D` operator, and then call=
s `wp_set_auth_cookie()` directly - never passing through `wp_authenticate(=
)` and therefore never triggering the plugin's own `Auth::_has_login_err()`=
lockout - an unauthenticated attacker can brute-force the ~10^6-candidate = seed space to reconstruct an active passwordless login token and authentica=
te as any targeted user, including administrators, without a password. Expl= oitation requires that a valid, unexpired passwordless login link (active f=
or up to 7 days) exists for the target account at the time of the attack, a=
nd that the numeric link ID is known or guessable from the auto-increment p= rimary key. 2026-07-08 8.8 CVE-2026-14495 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-14495 ] wpmessiah--Swiss Toolkit For WP The Swiss Toolkit For =
WP plugin for WordPress is vulnerable to arbitrary file upload due to a fla= wed file type validation bypass in the `upload_extension_files()` function =
in all versions up to, and including, 1.4.6. The `upload_extension_files()`=
function hooks into WordPress's `wp_check_filetype_and_ext` filter and use=
s `strpos()` to check if a filename contains a configured extension string,=
rather than verifying the actual file extension. This makes it possible fo=
r authenticated attackers, with Author-level access and above, to upload ar= bitrary files (including PHP) on the affected site's server which may make = remote code execution possible, granted the "Enhanced Multi-Format Image Su= pport" feature is enabled with at least one extension (e.g., avif) in the a= llowed formats. 2026-07-11 8.8 CVE-2026-2354 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-2354 ] wpvibes--Form Vibes Save Contact Form 7 & Elementor = Form Entries to Database The Form Vibes - Database Manager for Forms plugin=
for WordPress is vulnerable to Stored Cross-Site Scripting via Contact For=
m 7 Form Field in all versions up to, and including, 1.5.2 due to insuffici= ent input sanitization and output escaping. This makes it possible for unau= thenticated attackers to inject arbitrary web scripts in pages that will ex= ecute whenever a user accesses an injected page. 2026-07-11 7.2 CVE-2026-13= 378 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13378 ] WSO2--WSO2 Univer= sal Gateway The throttling event handling mechanism in multiple WSO2 produc=
ts accepts user-supplied JSON payloads without sufficient validation of the=
ir structure and content. This allows an unauthenticated remote attacker to=
inject malicious JSON data that can lead to a persistent denial of service=
condition. Successful exploitation of this vulnerability can disrupt the A=
PI Gateway, preventing legitimate API traffic from being processed and impa= cting complete service availability. The denial of service is persistent, r= equiring manual intervention to restore normal operations. 2026-07-06 8.6 C= VE-2026-4249 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4249 ] X.Org--li= bXfont2 A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.= 0.8 due to an overflowing 32bit size could be used by attackers able to acc= ess the X Server to execute code within the X server cont 2026-07-08 8.5 CV= E-2026-56001 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56001 ] X.Org--l= ibXfont2 A heap bufferflow in pcfReadFont() due to missing glyph bounds che= cking=C2=A0in libXfont2 before 2.0.8=C2=A0 allows attackers authenticated a=
s X client to execute code within the X server. 2026-07-08 8.5 CVE-2026-560=
02 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56002 ] X.Org--libXfont2 A=
heap buffer overflow due to missing size checking in the property buffer w= hen parsing PCF files in libXfont2 ComputeScaledProperties() before libXfon=
t2 before 2.0.8 could be used by attackers using authenticated X clients to=
execute code within the X server. 2026-07-08 8.5 CVE-2026-56003 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-56003 ] X.Org--xorg-server Local attack= ers with a X connection able to provide PCX fonts to the X server xorg-serv=
er before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer ove= rflow via SetFont due to missing glyph boundary checks. 2026-07-08 8.5 CVE-= 2026-55999 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55999 ] xtreeme--P= lanyo online reservation system The Planyo Online Reservation System plugin=
for WordPress is vulnerable to Server-Side Request Forgery leading to Loca=
l File Inclusion in all versions up to, and including, 3.0. The ulap.php fi=
le acts as an AJAX proxy and is directly accessible without WordPress boots= trapping or any authentication. The send_http_post() function validates the=
host of the provided URL against an allowlist that includes 'localhost', b=
ut critically fails to validate the URL scheme/protocol. This makes it poss= ible for unauthenticated attackers to supply a file:// URL (e.g., file://lo= calhost/etc/passwd) which bypasses the host allowlist check because parse_u= rl() returns 'localhost' as the host. The URL is then passed to curl_init()=
or fopen(), both of which support the file:// protocol, allowing the attac= ker to read arbitrary local files on the server and have their contents ret= urned in the HTTP response. This can lead to disclosure of sensitive files = such as /etc/passwd, wp-config.php (containing database credentials and aut= hentication keys), and other server-side files. 2026-07-11 7.2 CVE-2026-357=
6 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3576 ] yhirose--cpp-httplib=
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS l= ibrary. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 an=
d wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is = built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a c= lient connects to an IP-literal host with server certificate verification e= nabled, SSLClient and Client in HTTPS mode skip certificate chain validatio=
n and WebSocketClient on the Mbed TLS backend skips verification altogether=
, allowing a man-in-the-middle attacker positioned to intercept traffic to = present a crafted certificate and read or modify the traffic. This issue is=
fixed in version 0.47.0. 2026-07-10 7.4 CVE-2026-54919 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-54919 ] yt-dlp--yt-dlp yt-dlp and youtube-dl are=
command-line audio/video downloaders. Prior to 2026.7.4, the --write-link,=
--write-url-link, and --write-desktop-link options can write .url or .desk= top shortcut files using attacker-controlled webpage_url or filename metada=
ta without sufficient validation or escaping, allowing malicious file:// UR=
I injection on Windows or newline-based desktop entry key injection on Linu=
x that can execute commands if the generated shortcut is opened. This issue=
is fixed in version 2026.7.4. 2026-07-08 7.5 CVE-2026-55404 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-55404 ] zeek--zeek Zeek before 8.0.9 contai=
ns an uncontrolled memory consumption vulnerability in the FTP analyzer tha=
t allows unauthenticated remote attackers to cause process termination by s= ending a crafted FTP control session negotiating AUTH GSSAPI followed by a = large ADAT control line. Attackers can exploit the NVT_Analyzer component's=
lack of a maximum line length check, causing it to continuously double its=
internal buffer without bounds during base64 decoding of an attacker-contr= olled ADAT token, resulting in denial of service of the Zeek sensor. 2026-0= 7-09 7.5 CVE-2026-60108 [
https://www.cve.org/CVERecord?id=3DCVE-2026-60108=
] zeek--zeek Zeek before 8.0.9 contains a null pointer dereference vulnera= bility in its Kerberos protocol analyzer that allows unauthenticated remote=
attackers to crash the sensor by sending a crafted KRB_ERROR message with = error-code 25 (KDC_ERR_PREAUTH_REQUIRED) containing a PA-DATA element with = padata-type 2, 3, 11, or 19. Attackers can exploit a parser and analyzer st= ate mismatch where proc_padata() dereferences an uninitialized pa_data_elem= ent field selected by the wrong parsing arm, triggering a crash via a singl=
e UDP or TCP packet to port 88 without any credentials or prior authenticat= ion. 2026-07-09 7.5 CVE-2026-60109 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-60109 ] zephyrproject--zephyr parse_ipv4() in subsys/net/ip/utils.c (= reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copi=
es the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IP= V4_ADDR_LEN + 1]) using a length of str_len - end - 1, where str_len is the=
full, unbounded input length and end is only the (<=3D15-byte) offset of t=
he ':' delimiter. Because the destination size is never consulted, a crafte=
d address string with a long suffix after the colon (e.g. "1.2.3.4:" follow=
ed by hundreds of bytes) causes an out-of-bounds stack write whose length a=
nd contents are fully attacker-controlled (memcpy of the suffix plus a trai= ling NUL), enabling memory corruption and at minimum a denial of service, a=
nd potentially control-flow hijack. The parser is reached from the standard=
socket API (zsock_getaddrinfo / literal-address resolution), DNS server-st= ring configuration, and the eswifi Wi-Fi co-processor DNS-response path, so=
an application that resolves a network-influenced address string is expose=
d. The bug was introduced when the parser was added (Zephyr v1.9.0) and shi= pped in all releases through v4.4.0. The fix removes the unbounded copy and=
validates the port length before copying into a small dedicated buffer. No= te: the equivalent IPv6 "[addr]:port" path in parse_ipv6() retains the same=
unbounded copy at this commit and remains a separate, still-reachable inst= ance of the defect. 2026-07-12 8.1 CVE-2026-10666 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-10666 ] zephyrproject--zephyr In Zephyr's WireGuard su= bsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.=
c linearizes an inbound transport-data payload into a fixed pool buffer of = CONFIG_WIREGUARD_BUF_LEN bytes before decryption. The call net_buf_lineariz= e(buf->data, data_len, pkt->buffer, ..., data_len) passed the attacker-deri= ved data_len as both the destination capacity and the copy length, defeatin=
g the function's internal len =3D min(len, dst_len) bound. data_len is deri= ved from the received UDP datagram length and is only lower-bounded by wg_c= trl_recv() (no upper bound). When data_len exceeds CONFIG_WIREGUARD_BUF_LEN=
- e.g. when the buffer length is lowered below the link MTU, on links with=
MTU above the buffer size, or via reassembled IPv4/IPv6 fragments that exc= eed it - the underlying memcpy writes past the end of the pool buffer, an o= ut-of-bounds write (CWE-787). The overflow occurs before the Poly1305 authe= ntication check, so it requires only a valid receiver session index rather = than a valid authenticator, and is reachable by a malicious or compromised = peer (or an on-path attacker driving an established session) over the netwo= rk, yielding remote memory corruption and at minimum a reliable denial of s= ervice. The defect was present in the WireGuard implementation shipped in Z= ephyr 4.4.0. The fix adds an explicit data_len > CONFIG_WIREGUARD_BUF_LEN r= ejection and corrects the linearize call to pass net_buf_max_len(buf) as th=
e destination capacity. 2026-07-12 7.4 CVE-2026-10665 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-10665 ] zephyrproject--zephyr Zephyr's dynamic ker= nel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspac= e.c) maintains a doubly-linked list (obj_list) of dynamically allocated ker= nel objects. Iteration over this list in k_object_wordlist_foreach() was pe= rformed under lists_lock using the SAFE iterator (which caches the next nod= e), but list removal and freeing of nodes was performed under different, di= sjoint spinlocks: objfree_lock in k_object_free() and obj_lock in unref_che= ck(). On an SMP system, while one CPU iterated obj_list under lists_lock, a= nother CPU could unlink and k_free() the dyn_obj node that the iterator had=
cached as its next pointer, causing the iterator to dereference freed kern=
el memory (use-after-free / dangling list traversal). All of the racing ope= rations are reachable from unprivileged user-mode threads via system calls:=
k_object_alloc/k_object_alloc_size and k_object_release drive removals thr= ough unref_check() (under obj_lock), while k_thread_abort and thread creati=
on drive the iteration through k_thread_perms_all_clear()/k_thread_perms_in= herit() (under lists_lock). A deprivileged user thread on a CONFIG_SMP + CO= NFIG_USERSPACE build can therefore corrupt the kernel's object-tracking str= uctures across the userspace security boundary, yielding kernel memory corr= uption (potential privilege escalation) or a kernel crash (denial of servic= e). The fix removes objfree_lock and serializes every obj_list modification=
under lists_lock, including holding it across find+remove in k_object_free=
() and around unref_check() in k_thread_perms_clear(). Affects CONFIG_SMP+C= ONFIG_USERSPACE+CONFIG_DYNAMIC_OBJECTS configurations; the defect dates to = the 2019 spinlockification (commit 8a3d57b6cc6, first released in v1.14.0) = and shipped through v4.4.0. 2026-07-12 7.8 CVE-2026-10667 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-10667 ] zhayujie--CowAgent A vulnerability was=
determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _bui= ld_image_content/_download_to_data_url of the file agent/tools/vision/visio= n.py of the component Vision Tool. Executing a manipulation of the argument=
image can lead to server-side request forgery. The attack can be launched = remotely. The exploit has been publicly disclosed and may be utilized. Upgr= ading to version 2.1.2 is recommended to address this issue. This patch is = called e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. Upgrading the affected com= ponent is advised. 2026-07-10 7.3 CVE-2026-15330 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-15330 ] zitadel--zitadel ZITADEL is an open source iden= tity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange = endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verif=
y that the subject token belongs to the requesting client or that requested=
scopes remain within the original token's scopes, allowing a low-privilege=
token to be exchanged for elevated permissions at another application. Thi=
s issue is fixed in version 4.15.3. 2026-07-10 8.1 CVE-2026-56668 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-56668 ] zitadel--zitadel ZITADEL is an=
open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITA= DEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fa=
il to verify that the requesting client matches the client that initiated t=
he authorization flow, allowing intercepted grants or refresh tokens to be = exchanged under a different client. This issue is fixed in versions 3.4.12 = and 4.15.2. 2026-07-10 7.4 CVE-2026-55672 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-55672 ] zitadel--zitadel ZITADEL is an open source identity ma= nagement platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPr= econdition error paths return loginSettings.defaultRedirectUri to router.pu=
sh without applying the isSafeRedirectUri check, allowing an organization o=
r instance administrator to store a javascript or data URI that can execute=
in a user's browser when an affected login error path is reached. This iss=
ue is fixed in version 4.15.3. 2026-07-10 7.3 CVE-2026-56667 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-56667 ] zopefoundation--RestrictedPython Re= strictedPython is a tool that helps to define a subset of the Python langua=
ge which allows to provide a program input into a trusted environment. Prio=
r to 8.3, check_function_argument_names() rejected protected guard hook nam=
es for regular, variadic, and keyword-only arguments but omitted positional= -only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be=
shadowed by a local parameter and bypass the embedding application's acces=
s policy. This issue is fixed in version 8.3. 2026-07-08 8.3 CVE-2026-55830=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-55830 ]=20
Back to top [ #top ]
Medium Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info 2coders--Mux=
Video Uploader The Mux Video Uploader plugin for WordPress is vulnerable t=
o Sensitive Information Exposure in all versions up to, and including, 1.1.=
4 via the muxvideo_enqueue_settings_script. This makes it possible for auth= enticated attackers, with subscriber-level access and above, to extract sen= sitive data including Mux API credentials. 2026-07-11 4.3 CVE-2026-7544 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-7544 ] actualbudget--actual Actu=
al is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli = ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whene= ver the global --format csv option is passed, whose escapeCsv helper only h= andles RFC 4180 delimiter, quote, and newline escaping and does not neutral= ize standard CSV formula-injection prefixes. Any CLI command that streams a=
n object array containing user-controlled strings, including transactions l= ist, accounts list, payees list, categories list, tags list, category-group=
s list, rules list, schedules list, and query, can emit cells that auto-eva= luate when the resulting CSV is opened in Excel, LibreOffice Calc, or Googl=
e Sheets, enabling data exfiltration and arbitrary formula execution. This = issue is fixed in version 26.6.0. 2026-07-07 4.6 CVE-2026-46672 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-46672 ] actualbudget--actual Actual is a=
local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name = endpoint in @actual-app/sync-server checks only that the caller has a valid=
session and does not verify the caller is an admin, while the sibling POST=
/secret/ handler enforces an admin check in OpenID mode. Any authenticated=
non-admin BASIC user in OpenID multi-user deployments can probe the secret=
s store and learn which admin-managed bank-sync integrations have been conf= igured, including simplefin_accessKey, pluggyai_clientSecret, pluggyai_item= Ids, and the gocardless secrets. This issue is fixed in version 26.6.0. 202= 6-07-07 4.3 CVE-2026-46700 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46= 700 ] actualbudget--actual Actual is a local-first personal finance tool. P= rior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/= server/transactions/export/export-to-csv.ts pass user-controlled Payee, Not= es, Account, and Category strings to csv-stringify with no cast callback an=
d no formula-prefix neutralization. Strings that begin with equals sign, pl= us, minus, at sign, tab, or carriage return survive verbatim into the expor= ted CSV, and when a recipient opens the file in Excel, LibreOffice Calc, or=
Google Sheets, the strings are interpreted as formulas, enabling transacti=
on data exfiltration and attacker-chosen spreadsheet display values. This i= ssue is fixed in version 26.6.0. 2026-07-07 4.2 CVE-2026-50179 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-50179 ] acyba--AcyMailing An Ultimate New= sletter Plugin and Marketing Automation Solution for WordPress The AcyMaili=
ng - An Ultimate Newsletter Plugin and Marketing Automation Solution for Wo= rdPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting v=
ia the 'alignment' attribute in all versions up to, and including, 10.10.2 = due to insufficient input sanitization and output escaping. This makes it p= ossible for authenticated attackers, with contributor-level access and abov=
e, to inject arbitrary web scripts in pages that will execute whenever a us=
er accesses an injected page. 2026-07-09 6.4 CVE-2026-12170 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-12170 ] Adobe--DNG SDK DNG SDK versions 1.7.=
1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability=
that could result in an application denial-of-service. An attacker could e= xploit this vulnerability to crash the application, leading to a denial-of-= service condition. Exploitation of this issue requires user interaction in = that a victim must open a malicious file. 2026-07-06 5.5 CVE-2026-48267 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-48267 ] aerostackdev--aerostack-= mcp A security vulnerability has been detected in aerostackdev aerostack-mc=
p up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is=
the function upload_media of the component mcp-whatsapp. Such manipulation=
of the argument media_url leads to server-side request forgery. The attack=
may be launched remotely. This product operates on a rolling release basis=
, ensuring continuous delivery. Consequently, there are no version details = for either affected or updated releases. The project was informed of the pr= oblem early through an issue report but has not responded yet. 2026-07-09 6=
.3 CVE-2026-15189 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15189 ] aff= ine--monorepo AFFiNE's histories GraphQL field fails to validate Doc.Read p= ermission before exposing document edit history, allowing authenticated wor= kspace members to retrieve restricted content timelines. Attackers can supp=
ly arbitrary document GUIDs to access full edit histories including user na= mes, emails, and timestamps of private pages they lack access to. 2026-07-0=
8 6.5 CVE-2026-59262 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59262 ] = ahmadmj--Majestic Support The Leading-Edge Help Desk & Customer Support Plu= gin The Majestic Support - The Leading-Edge Help Desk & Customer Support Pl= ugin plugin for WordPress is vulnerable to generic SQL Injection via the 'v= al' parameter in all versions up to, and including, 1.1.9 due to insufficie=
nt escaping on the user supplied parameter and lack of sufficient preparati=
on on the existing SQL query. This makes it possible for unauthenticated at= tackers to append additional SQL queries into already existing queries that=
can be used to extract sensitive information from the database. Exploitati=
on requires a valid 'get-smart-reply' nonce, which any Subscriber-level use=
r can obtain by creating a ticket via the public frontend and visiting the = resulting ticket detail page, making this effectively exploitable by any au= thenticated user. 2026-07-11 6.5 CVE-2026-13262 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-13262 ] AidanPark--openclaw-android A vulnerability was = determined in AidanPark openclaw-android up to 0.4.0. The affected element =
is an unknown function of the file android/app/src/main/java/com/openclaw/a= ndroid/JsBridge.kt of the component Android WebView Bridge. This manipulati=
on causes os command injection. The attack can only be executed locally. Th=
e exploit has been publicly disclosed and may be utilized. The pull request=
to fix this issue awaits acceptance. 2026-07-09 5.3 CVE-2026-15193 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-15193 ] AMTT--Hotel Broadband Operat= ion System A flaw has been found in AMTT Hotel Broadband Operation System 1= .0. Impacted is an unknown function of the file manager/network/switch_stat= us.php. Executing a manipulation of the argument ID can lead to sql injecti= on. It is possible to launch the attack remotely. The exploit has been publ= ished and may be used. The vendor was contacted early about this disclosure=
but did not respond in any way. 2026-07-12 4.7 CVE-2026-15494 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-15494 ] ankitects--anki Anki is a program=
for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-ba= sed pages communicate with the Rust backend using an internal localhost API=
, and user scripts included via iframes in the editor can access this API d= espite protections intended to block reviewer and editor scripts. A malicio=
us imported card package with an embedded iframe can use exposed API method=
s such as getImageForOcclusion to read arbitrary files accessible to the An=
ki process and exfiltrate them over the network. This issue is fixed in ver= sion 25.09.4. 2026-07-07 6.5 CVE-2026-58266 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-58266 ] antiwork--gumroad Gumroad before 2026.07.06.2 contai=
ns a broken access control vulnerability in the PurchasesController that al= lows authenticated sellers to manipulate purchase access for other sellers'=
products by sending PUT requests to the revoke_access and undo_revoke_acce=
ss actions without seller ownership validation. Attackers can modify the is= _access_revoked status on arbitrary purchases to unauthorized revoke or res= tore buyer access to products they do not own. 2026-07-08 6.5 CVE-2026-5980=
5 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59805 ] AojiaoZero--Antaris=
A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the f= unction _rewardPurchase of the file /ipn.php of the component PayPal IPN Pa= yment Handler. The manipulation of the argument item_number results in sql = injection. The attack may be performed from remote. The vendor was contacte=
d early about this disclosure but did not respond in any way. 2026-07-12 6.=
3 CVE-2026-15502 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15502 ] apid= evtools--json-schema-ref-parser A weakness has been identified in apidevtoo=
ls json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/= Pointer.set in the library lib/pointer.ts. Executing a manipulation can lea=
d to improperly controlled modification of object prototype attributes. The=
attack can be launched remotely. Upgrading to version 15.3.6 will fix this=
issue. This patch is called a786bc6afc3674f650496472ee93d5cf74c4bd84. It i=
s suggested to upgrade the affected component. 2026-07-09 6.3 CVE-2026-1519=
5 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15195 ] appium--appium Appi=
um is a cross-platform automation framework for all kinds of apps, built on=
top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver u= nconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, an=
d /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects th=
e throwError query parameter, comments POST field, and User-Agent request h= eader into HTML without escaping, allowing reflected cross-site scripting a=
nd arbitrary JavaScript execution on the server origin. This issue is fixed=
in version 10.7.0. 2026-07-08 6.5 CVE-2026-58191 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-58191 ] arikusi--deepseek-mcp-server DeepSeek MCP Serv=
er is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to=
version 1.8.0, the self-hosted HTTP transport of `@arikusi/deepseek-mcp-se= rver` exposes `POST /mcp` without any authentication: `createMcpExpressApp`=
is called without an `authProvider` and no middleware guards the route, so=
any network-reachable client can issue an unauthenticated `initialize` req= uest and obtain a valid MCP session identifier. In reproduced testing again=
st commit `5e1302171e99`, an unauthenticated client was able to initialize =
a session, enumerate tools, and invoke the local `deepseek_sessions` tool w= ith no credentials. The same unauthenticated session also exposes `deepseek= _chat`, whose handler uses the server-side `DEEPSEEK_API_KEY` when self-hos= ted deployments configure one. This issue applies to self-hosted HTTP mode,=
not the separately documented hosted BYOK endpoint in `README.md`, which e= xpects an `Authorization: Bearer ...` header. Upstream self-hosted containe=
r assets enable HTTP mode by default (`Dockerfile`) and publish port `3000`=
(`docker-compose.yml`). Version 1.8.0 contains a patch for this issue. 202= 6-07-09 5.3 CVE-2026-55605 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55= 605 ] Armiya Information Technologies Ltd. Co.--Access Control System (GKS)=
Improper neutralization of Script-Related HTML tags in a web page (basic X= SS) vulnerability in Armiya Information Technologies Ltd. Co. Access Contro=
l System (GKS) allows XSS Targeting HTML Attributes. This issue affects Acc= ess Control System (GKS): before Version 2. 2026-07-07 6.1 CVE-2026-7380 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-7380 ] Armiya Information Techn= ologies Ltd. Co.--Access Control System (GKS) Improper neutralization of in= put during web page generation ('cross-site scripting') vulnerability in Ar= miya Information Technologies Ltd. Co. Access Control System (GKS) allows S= tored XSS. This issue affects Access Control System (GKS): before Version 2=
. 2026-07-07 6.1 CVE-2026-8306 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-8306 ] Armiya Information Technologies Ltd. Co.--Access Control System (G= KS) Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Armiya Information Technologies Ltd. Co. Acc= ess Control System (GKS) allows Reflected XSS. This issue affects Access Co= ntrol System (GKS): before Version 2. 2026-07-07 5.4 CVE-2026-8309 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-8309 ] arraytics--Eventin Event Calen= dar, Event Registration, Tickets & Booking (AI Powered) The Eventin - Event=
Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for Wo= rdPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_conte= nt' parameter in all versions up to, and including, 4.1.15 due to insuffici= ent input sanitization and output escaping. This makes it possible for auth= enticated attackers, with contributor-level access and above, to inject arb= itrary web scripts in pages that will execute whenever a user accesses an i= njected page. 2026-07-10 6.4 CVE-2026-12924 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-12924 ] arraytics--Eventin Event Calendar, Event Registratio=
n, Tickets & Booking (AI Powered) The Eventin - Event Calendar, Event Regis= tration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable =
to authorization bypass due to a regression in versions from 4.0.26 up to a=
nd including 4.1.15. This is due to the plugin not properly verifying that =
a user is authorized to perform an action in the payment_complete() functio=
n of PaymentController.php. This makes it possible for unauthenticated atta= ckers to mark unpaid ticket orders as completed by submitting a fabricated = SureCart checkout ID or FluentCart cart hash, granting themselves paid even=
t access, QR-code attendee tickets, and order confirmation emails without m= aking any real payment. The wp_rest nonce required to reach the vulnerable = endpoint is embedded in every public event page, meaning no WordPress sessi=
on or credentials are needed to obtain it. This vulnerability represents a = regression - the same function and endpoint were previously patched but the=
fix did not persist through subsequent releases. 2026-07-10 5.3 CVE-2026-1= 3039 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13039 ] arraytics--WPCaf=
e Restaurant Menu, Online Food Ordering & Table Booking System The WPCafe -=
Restaurant Menu, Online Food Ordering & Table Booking System plugin for Wo= rdPress is vulnerable to authorization bypass in all versions up to, and in= cluding, 3.0.14. This is due to the plugin not properly verifying that a us=
er is authorized to perform an action. This makes it possible for authentic= ated attackers, with subscriber-level access and above, to list, create, up= date, delete, clone, and bulk-delete notification flow workflows that are i= ntended to be managed only by administrators. The only protection on these = endpoints is a wp_rest nonce check, which is obtainable by any logged-in us=
er from the frontend page source. 2026-07-10 5.4 CVE-2026-11818 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-11818 ] AstrBotDevs--AstrBot A security = flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is t=
he function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.p=
y of the component Scheduled Task Handler. Performing a manipulation of the=
argument payload["note"] results in improper authorization. Remote exploit= ation of the attack is possible. The exploit has been released to the publi=
c and may be used for attacks. The vendor was contacted early about this di= sclosure but did not respond in any way. 2026-07-12 6.3 CVE-2026-15499 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-15499 ] AstrBotDevs--AstrBot A we= akness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by=
this vulnerability is the function get_online_plugins of the file astrbot/= dashboard/routes/plugin.py of the component market_list Endpoint. Executing=
a manipulation of the argument custom_registry can lead to server-side req= uest forgery. The attack can be executed remotely. The exploit has been mad=
e available to the public and could be used for attacks. The vendor was con= tacted early about this disclosure but did not respond in any way. 2026-07-=
12 6.3 CVE-2026-15500 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15500 ]=
AstrBotDevs--AstrBot A security vulnerability has been detected in AstrBot= Devs AstrBot up to 4.25.2. Affected by this issue is the function ToolsRout= e.test_mcp_connection of the file astrbot/dashboard/routes/tools.py of the = component MCP Test Endpoint. The manipulation of the argument mcp_server_co= nfig.url leads to server-side request forgery. The attack is possible to be=
carried out remotely. The exploit has been disclosed publicly and may be u= sed. The vendor was contacted early about this disclosure but did not respo=
nd in any way. 2026-07-12 6.3 CVE-2026-15501 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-15501 ] AVideo--AVideo AVideo (Meet plugin) through commit = e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scrip= ting vulnerability in the Meet plugin's getMeetInfo.json.php endpoint. When=
a participant joins a public meeting, the raw HTTP User-Agent header is st= ored (meet_join_log.user_agent) without sanitization (bypassing AVideo's se= tter-level xss_esc() layer) and later echoed without output encoding (no ht= mlspecialchars()) in the Participants management panel, which is accessible=
to the meeting host and site administrators. An anonymous, unauthenticated=
attacker can join any public meeting while supplying a User-Agent header c= ontaining an HTML/JavaScript payload; the payload is persisted and executes=
in the privileged, authenticated browser session of the meeting host or a = site administrator when they open the participant list. The issue was unpat= ched at the time of the report. 2026-07-08 6.1 CVE-2026-60092 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-60092 ] AWS--res AWS Research and Engineer= ing Studio (RES) is an open-source solution that enables researchers and en= gineers to create and manage secure virtual desktops and computing resource=
s on AWS. Improper link resolution before file access issue (CWE-59) in the=
Auth.GetUserPrivateKey API. An authenticated remote user could read arbitr= ary files on the cluster-manager EC2 instance by replacing their SSH privat=
e key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the h= ost. Because the cluster-manager process runs as root, any file readable by=
root is exposed, including other users' SSH private keys and application c= onfiguration secrets. It's recommended to upgrade to RES version 2026.06. 2= 026-07-07 6.5 CVE-2026-14904 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 14904 ] axllent--mailpit Mailpit is an email testing tool and API for devel= opers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incom= plete because the tools.IsInternalIP deny-list in internal/tools/net.go rel= ies on Go's standard library classification helpers and does not block IPv6=
transition mechanisms or prefixes such as NAT64, 6to4, IPv4-compatible IPv=
6, ISATAP, fec0::/10, and 2001:db8::/32. An attacker who can deliver email = and invoke POST /api/v1/message/{ID}/link-check can coerce the Link Check A= PI's safeDialContext path into dialing internal destinations and can use st= atus-code and error feedback to map internal service reachability, includin=
g cloud metadata endpoints. This issue is fixed in version 1.30.2. 2026-07-=
10 5.8 CVE-2026-55187 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55187 ]=
Bahmni--bahmnicore A vulnerability was detected in Bahmni bahmnicore up to=
0.93. This affects the function additionalParams of the file /openmrs/ws/r= est/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipu= lation of the argument test results in sql injection. The attack can be ini= tiated remotely. The exploit is now public and may be used. Upgrading to ve= rsion 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1 and 2.0.1 mitigates this issue. Up= grading the affected component is recommended. 2026-07-12 6.3 CVE-2026-1547=
7 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15477 ] beardev--JoomSport = for Sports: Team & League, Football, Hockey & more The JoomSport - for Spor= ts: Team & League, Football, Hockey & more plugin for WordPress is vulnerab=
le to time-based SQL Injection via 'event' Shortcode Attribute in all versi= ons up to, and including, 5.7.9 due to insufficient escaping on the user su= pplied parameter and lack of sufficient preparation on the existing SQL que= ry. This makes it possible for authenticated attackers, with contributor-le= vel access and above, to append additional SQL queries into already existin=
g queries that can be used to extract sensitive information from the databa= se. The shortcode can be embedded in posts or pages by Contributor-level us= ers, making this exploitable by any authenticated user with at least that r= ole. 2026-07-10 6.5 CVE-2026-13010 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-13010 ] bentoml--OpenLLM A vulnerability was found in bentoml OpenLLM=
0.6.30. This affects the function async_run_command of the file src/openll= m/common.py of the component Model Repository Directory Name Handler. Perfo= rming a manipulation of the argument cmd results in command injection. Atta= cking locally is a requirement. The exploit has been made public and could =
be used. The project was informed of the problem early through an issue rep= ort but has not responded yet. 2026-07-08 5.3 CVE-2026-15035 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-15035 ] Bixilon--Minosoft Minosoft is an op= en-source, multi-version Minecraft Java Edition client written in Kotlin. S= tarting in commit f1ae30e2b046a490026a8413b075685deb795122, the CryptManage= r=C2=A0 encryption routine (=C2=A0CryptManager.kt=C2=A0) initializes its AE=
S cipher using an initialization vector (IV) that is set equal to the secre=
t key rather than to a sufficiently random value. Because the IV is not ran= dom and is derived directly from the key, the encryption is vulnerable to c= hosen-ciphertext/chosen-plaintext attacks: an attacker who can submit speci= fic messages for encryption can recover the secret key. This affects all ve= rsions supporting Minecraft protocol 1.7 and later. No patched version is a= vailable, and no known workarounds are available. 2026-07-06 5 CVE-2024-561=
41 [
https://www.cve.org/CVERecord?id=3DCVE-2024-56141 ] bouncingsprout--Bl= ock, Suspend, Report for BuddyPress The Block, Suspend, Report for BuddyPre=
ss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th=
e 'link' parameter in versions up to and including 3.6.4. This is due to in= sufficient input sanitization and output escaping. This makes it possible f=
or authenticated attackers with subscriber-level access and above to inject=
arbitrary web scripts in pages that will execute whenever a user accesses =
an injected page. 2026-07-09 6.4 CVE-2026-4653 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-4653 ] bytecodealliance--wasmtime Wasmtime is a runtime f=
or WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-was=
i hard-link creation and renaming check directory permissions but not match= ing FilePerms on source and destination preopens, allowing a WASI guest wit=
h a read-only source file capability to overwrite host files exposed as Fil= ePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This = issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1. 2026-07-08=
6.5 CVE-2026-58494 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58494 ] C= ap-go--capgo Capgo (Cap-go/capgo) before 12.128.2 contains an information d= isclosure vulnerability in the Supabase PostgREST RPC function public.get_t= otal_metrics(org_id), which is callable by the anon role using only the pub= lic sb_publishable_* key. An unauthenticated attacker can probe organizatio=
n existence and leak sensitive usage metrics including MAU, bandwidth, and = install counts by sending POST requests to /rest/v1/rpc/get_total_metrics w= ith valid organization UUIDs. 2026-07-08 5.3 CVE-2026-56284 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-56284 ] Cap-go--capgo Cap-go before 12.128.2=
contains an information disclosure vulnerability in the public.transfer_ap=
p RPC function that returns distinct error messages for existing versus non= -existing app IDs. Unauthenticated attackers can enumerate valid app IDs by=
observing error message differences when calling transfer_app with only th=
e publishable API key. 2026-07-11 5.3 CVE-2026-56296 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-56296 ] Capgo--Capgo Capgo before 12.128.2 contains=
an authorization bypass vulnerability in the public.manifest INSERT policy=
that allows read-only org members to insert OTA manifest rows. Attackers w= ith read-only org access can inject malicious manifest entries with arbitra=
ry s3_path values that are served to devices via the unauthenticated /updat=
es endpoint, enabling OTA metadata poisoning and potential malicious asset = delivery. 2026-07-08 6.5 CVE-2026-56220 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56220 ] Capgo--Capgo Capgo before 12.128.2 contains an improper=
validation vulnerability in the accept_invitation endpoint that creates us=
er accounts before captcha validation is enforced. Attackers can bypass cap= tcha protection by sending POST requests with invalid captcha tokens to cre= ate unwanted accounts and burn invite links. 2026-07-10 6.5 CVE-2026-56312 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-56312 ] Capgo--Capgo Capgo be= fore 12.128.2 contains a cross-tenant preview namespace collision vulnerabi= lity caused by non-bijective decoding of double underscores to dots in prev= iew hostname parsing. Attackers can register app IDs with underscores that = collide with other tenants' dotted app IDs, causing preview misrouting and = denial of preview access for victim applications. 2026-07-10 6.4 CVE-2026-5= 6329 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56329 ] Capgo--Capgo Cap=
go before 12.128.2 contains an authorization bypass vulnerability where wri= te-scoped API keys can directly mutate protected channel configuration fiel=
ds through PostgREST by exploiting a null authentication check in the immut= ability trigger. Attackers with write API keys can modify sensitive channel=
attributes such as public, allow_emulator, and security-related flags outs= ide intended application routes. 2026-07-10 6.5 CVE-2026-56335 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-56335 ] Capgo--Capgo Capgo before 12.128.=
2 contains a scope isolation vulnerability in the POST /webhooks/test endpo= int that allows app-scoped API keys to invoke org-scoped webhook operations=
. Attackers with app-scoped credentials can trigger signed outbound webhook=
deliveries for arbitrary organization webhooks outside their declared app = boundary, bypassing the limited_to_apps authorization check. 2026-07-12 5.4=
CVE-2026-56252 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56252 ] Capgo= --Capgo Capgo before 12.128.2 contains an html injection vulnerability in t=
he organization settings endpoint that allows attackers to inject malicious=
HTML content. Attackers can craft payloads in the organization name field =
to redirect users to untrusted websites, enabling phishing attacks and repu= tational damage. 2026-07-08 5.4 CVE-2026-56283 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-56283 ] Capgo--Capgo Capgo before 12.128.2 contains an au= thorization flaw in transfer_app() that fails to update deploy_history.owne= r_org when transferring applications between organizations. Attackers can e= xploit this omission to retain unauthorized access to deployment history re= cords in the source organization or cause the destination organization to l= ose access to transferred application deployment records. 2026-07-08 5.4 CV= E-2026-56293 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56293 ] Capgo--C= apgo Capgo before 12.128.2 fails to enforce plan/quota restrictions on the = /files/upload/attachments endpoint, allowing plan-blocked apps to create pu= blicly readable R2 objects. Attackers can upload arbitrary attachments usin=
g upload-scoped API keys that bypass plan checks, persist outside normal bu= ndle metadata, and survive app deletion, enabling storage and bandwidth abu= se. 2026-07-10 5.4 CVE-2026-56309 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-56309 ] Capgo--Capgo Capgo before 12.128.2 contains an information dis= closure vulnerability in the unauthenticated /private/sso/check-domain endp= oint that returns internal org_id and provider_id values. Attackers can enu= merate email domains to build mappings of domains to organization UUIDs and=
SSO provider identifiers, enabling reconnaissance against Capgo tenants. 2= 026-07-12 5.3 CVE-2026-56336 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 56336 ] Capgo--Capgo Capgo before 12.128.2 contains a policy bypass vulnera= bility in app_versions update enforcement that allows app-scoped API keys t=
o downgrade encrypted bundles to non-encrypted state. Attackers with app-sc= oped all API keys can directly update the app_versions table via PostgREST =
to clear session_key and key_id fields, bypassing organization-enforced enc= rypted-bundle policies and weakening OTA security controls. 2026-07-08 4.3 = CVE-2026-56217 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56217 ] Capgo-= -Capgo Capgo before 12.128.12 contains a billing authorization bypass vulne= rability in the plan_valid calculation that allows organizations with exhau= sted or expired usage credit grants to bypass billing gates. Attackers can = exploit the divergence between the plugin hot-path plan_valid expression an=
d the authoritative billing gate to gain continued access to /updates, /sta= ts, /channel_self, and attachment upload endpoints after credit depletion. = 2026-07-11 4.3 CVE-2026-56240 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -56240 ] Capgo--Capgo Capgo before 12.128.2 fails to strip EXIF metadata fr=
om images uploaded via the app information endpoint, exposing sensitive geo= location data. Attackers can upload images containing EXIF metadata to extr= act geographic location information and other embedded metadata from upload=
ed files. 2026-07-08 4.3 CVE-2026-56298 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56298 ] carazo--Import and export users and customers The Impor=
t and export users and customers plugin for WordPress is vulnerable to Sens= itive Information Exposure in all versions up to, and including, 2.4.0 via = the email_template_selected. This makes it possible for authenticated attac= kers, with subscriber-level access and above, to extract the post_title and=
raw post_content of arbitrary posts regardless of status (draft, private, = future, trash, password-protected) or post type (including non-public CPTs = such as WooCommerce orders and internal CRM records) by enumerating post ID=
s. The required codection-security nonce is exposed as inline JavaScript on=
any wp-admin page when ?post_type=3Dacui_email_template is appended to the=
URL, which is reachable by any authenticated user including Subscribers. 2= 026-07-10 4.3 CVE-2026-15026 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 15026 ] catalyst2020--Catalyst Connect Zoho CRM Client Portal The Catalyst = Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-b= ased SQL Injection via the 'uid' parameter in all versions up to, and inclu= ding, 2.2.0 due to insufficient escaping on the user supplied parameter and=
lack of sufficient preparation on the existing SQL query. This makes it po= ssible for authenticated attackers, with Administrator-level access and abo= ve, to append additional SQL queries into already existing queries that can=
be used to extract sensitive information from the database. 2026-07-11 4.9=
CVE-2025-5017 [
https://www.cve.org/CVERecord?id=3DCVE-2025-5017 ] chatra-= -Chatra Live Chat + ChatBot + Cart Saver The Chatra Live Chat + ChatBot + C= art Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting=
via admin settings in all versions up to, and including, 1.0.12 due to ins= ufficient input sanitization and output escaping. This makes it possible fo=
r authenticated attackers, with administrator-level permissions and above, =
to inject arbitrary web scripts in pages that will execute whenever a user = accesses an injected page. This only affects multi-site installations and i= nstallations where unfiltered_html has been disabled. 2026-07-08 4.4 CVE-20= 26-12041 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12041 ] christophert= hielen--check-peer-dependencies A flaw has been found in christopherthielen=
check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the=
function shelljs.exec of the file dist/packageUtils.js of the component pe= erDependencies. This manipulation causes os command injection. The attack m=
ay be initiated remotely. The project was informed of the problem early thr= ough an issue report but has not responded yet. 2026-07-08 6.3 CVE-2026-150=
33 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15033 ] cilium--cilium Cil= ium is a networking, observability, and security solution. Prior to 1.17.16=
, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability =
to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via = addressMatcher, enabling hijacking traffic to Services in any namespace and=
bypassing namespace scoping enforced by serviceMatcher; deleting such a po= licy can also corrupt Cilium internal service state and stop service transl= ation for the affected Service. This issue is fixed in versions 1.17.16, 1.= 18.10, and 1.19.4. 2026-07-07 6.9 CVE-2026-53935 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-53935 ] cli--cli GitHub CLI (gh) is GitHub's official c= ommand line tool. From 2.10.0 through 2.95.0, connecting to a malicious Cod= espace with gh codespace jupyter can allow command execution because the co= mmand opens a JupyterLab URL supplied by a process inside the Codespace wit= hout validating that it is a loopback HTTP or HTTPS address, allowing a cra= fted vscode:// or vscode-insiders:// URL to be handed to VS Code. This issu=
e is fixed in version 2.96.0. 2026-07-09 4.4 CVE-2026-59831 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-59831 ] CodeAstro--Apartment Visitor Managem= ent System A vulnerability has been found in CodeAstro Apartment Visitor Ma= nagement System 1.0. Affected by this issue is some unknown functionality o=
f the file /apartment-visitor/action-visitor.php. Such manipulation of the = argument remark leads to sql injection. The attack may be performed from re= mote. The exploit has been disclosed to the public and may be used. 2026-07= -06 6.3 CVE-2026-14795 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14795 =
] CodeAstro--Apartment Visitor Management System A vulnerability was found =
in CodeAstro Apartment Visitor Management System 1.0. This affects an unkno=
wn part of the file /apartment-visitor/report.php. Performing a manipulatio=
n of the argument fromdate results in sql injection. It is possible to init= iate the attack remotely. The exploit has been made public and could be use=
d. 2026-07-06 6.3 CVE-2026-14796 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-14796 ] CodeAstro--Apartment Visitor Management System A vulnerability = was determined in CodeAstro Apartment Visitor Management System 1.0. This v= ulnerability affects unknown code of the file /apartment-visitor/edit-apart= ment.php. Executing a manipulation of the argument editid can lead to sql i= njection. It is possible to launch the attack remotely. The exploit has bee=
n publicly disclosed and may be utilized. 2026-07-06 6.3 CVE-2026-14797 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-14797 ] CodeAstro--Apartment Vis= itor Management System A vulnerability was identified in CodeAstro Apartmen=
t Visitor Management System 1.0. This issue affects some unknown processing=
of the file /apartment-visitor/visitor-entry.php. The manipulation of the = argument visname leads to sql injection. The attack can be initiated remote= ly. The exploit is publicly available and might be used. 2026-07-06 6.3 CVE= -2026-14798 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14798 ] CodeAstro= --Ecommerce Website A security flaw has been discovered in CodeAstro Ecomme= rce Website 1.0. Impacted is an unknown function of the file /customer/my_a= ccount.php?my_wishlist. The manipulation of the argument delete_wishlist re= sults in sql injection. The attack can be launched remotely. The exploit ha=
s been released to the public and may be used for attacks. 2026-07-06 6.3 C= VE-2026-14799 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14799 ] codenam= e065--Download Manager The Download Manager plugin for WordPress is vulnera= ble to Stored Cross-Site Scripting via 'note_before' and 'note_after' Short= code Attributes in all versions up to, and including, 3.3.61 due to insuffi= cient input sanitization and output escaping. This makes it possible for au= thenticated attackers, with contributor-level access and above, to inject a= rbitrary web scripts in pages that will execute whenever a user accesses an=
injected page. Because wp_kses_post filters post content on save for users=
without unfiltered_html, only kses-allowed tag and attribute payloads that=
survive save-time filtering will reach the unescaped sink; however, the si=
nk itself remains unsafe and such payloads can still execute in the browser=
when a user renders the shortcode. 2026-07-09 6.4 CVE-2026-14343 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-14343 ] coder--coder Coder allows orga= nizations to provision remote development environments via Terraform. Versi= ons prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulne= rable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via = the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-i= nstance-identity`). An external attacker can force the Coder server to issu=
e HTTP GET requests to arbitrary internal or external hosts by submitting a=
crafted PKCS#7 signature. The server does not return the target's response=
body, but error messages in the API response reveal whether the target is = reachable and what type of failure occurred. Versions 2.24.5, 2.29.13, 2.30= .8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, if the Az= ure identity-auth mechanism is not being used then restrict access to the c= orresponding endpoint (`/api/v2/workspaceagents/azure-instance-identity`) u= sing ingress firewall and/or proxy ACLs. 2026-07-07 6.5 CVE-2026-45796 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-45796 ] coder--coder Coder allows=
organizations to provision remote development environments via Terraform. = Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, an=
d 2.34.2, `POST /api/v2/files` converts zip uploads to tar in memory via `C= reateTarFromZip`, which enforced a per-entry size limit but no aggregate li= mit on total decompressed output, writing to an unbounded in-memory buffer.=
Exploitation requires authenticated file-upload access and the impact is l= imited to availability (denial of service). The fix in versions 2.29.7, 2.3= 2.7, 2.33.8, and 2.34.2 adds a metadata preflight check that sums projected=
entry sizes and a streaming writer that enforces the aggregate limit durin=
g decompression. As a workaround, restrict file-upload permissions to trust=
ed users or place a reverse proxy with request-body size limits in front of=
`coderd`. 2026-07-07 6.5 CVE-2026-55078 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55078 ] coder--coder Coder allows organizations to provision re= mote development environments via Terraform. Starting in version 2.33.0 and=
prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers read requ= est bodies with `io.ReadAll` without a maximum size so an authenticated use=
r with AI Bridge access could send an arbitrarily large body and exhaust me= mory. Exploitation requires authenticated access to the AI Bridge endpoints=
and the impact is limited to availability (denial of service). Versions 2.= 33.8 and 2.34.2 patch the issue. No known workarounds are available. 2026-0= 7-07 6.5 CVE-2026-55434 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55434=
] coder--coder Coder allows organizations to provision remote development = environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2= .34.2, the workspace app proxy resolves the target app from `httpapi.Reques= tHost()` which prefers the `X-Forwarded-Host` header over the real `Host` h= eader. No middleware strips `X-Forwarded-Host` before routing and the heade=
r is not browser-forbidden so client-side JavaScript can set it on `fetch()=
` calls. Practical exploitation requires subdomain app routing (wildcard ho= stname) enabled, a victim who visits the attacker's shared app and a deploy= ment whose upstream proxy does not strip `X-Forwarded-Host`. The fix in ver= sions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 trusts `X-Forwarded-Host` only fro=
m configured trusted proxies and otherwise resolves the routing host from t=
he verified request host. As a workaround, place an upstream reverse proxy = that strips or overwrites `X-Forwarded-Host` on untrusted requests. 2026-07= -08 5.8 CVE-2026-55430 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55430 =
] coder--coder Coder allows organizations to provision remote development e= nvironments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.= 34.2, the `CreateSubAgent` RPC did not validate a requested app sharing lev=
el against the template's `MaxPortSharingLevel` before persisting workspace=
apps, letting a workspace owner exceed the administrator's configured maxi= mum. Exploitation requires the ability to register sub-agent apps in a work= space the attacker controls. The fix in versions 2.29.7, 2.32.7, 2.33.8, an=
d 2.34.2clamps the sub-agent app sharing level to the template's `MaxPortSh= aringLevel`. As a workaround, disable wildcard app hostnames (`CODER_WILDCA= RD_ACCESS_URL`) to block subdomain-based app routing. 2026-07-08 5.4 CVE-20= 26-55432 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55432 ] coder--coder=
Coder allows organizations to provision remote development environments vi=
a Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devc= ontainer recreate endpoint relied on route middleware that checked only `Ac= tionRead` on the workspace and, unlike the sibling delete endpoint, perform=
ed no `ActionUpdate` check before triggering the destructive rebuild. Explo= itation requires an existing low-privilege role with access to the target w= orkspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an ex= plicit `ActionUpdate` authorization check before the agent is dialed like t=
he delete endpoint. No known workarounds are available. 2026-07-08 5.4 CVE-= 2026-55433 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55433 ] coder--cod=
er Coder allows organizations to provision remote development environments = via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.3= 3.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAutho= rized` in `coderd/aibridgedserver`, which validates key format, expiry, sec= ret and deleted or system users but does not check whether the account is s= uspended. Because suspension does not revoke existing API keys, a suspended=
user's unexpired token keeps working. Practical impact is limited to alrea= dy-issued API keys of suspended users until those keys are deleted. Version=
s 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspensio=
n, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`. 2026-= 07-07 5.4 CVE-2026-55435 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5543=
5 ] coder--coder Coder allows organizations to provision remote development=
environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and=
2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html`=
without `escapeXML: true` and inserted the result via `dangerouslySetInner= HTML` so HTML embedded in workspace agent log lines was rendered as live ma= rkup. Server-side sanitization did not neutralize HTML metacharacters. Expl= oitation requires a victim to view attacker-controlled agent logs in the da= shboard. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 enables `e= scapeXML: true` so HTML metacharacters are escaped before DOM insertion. No=
known workarounds are available. 2026-07-08 5.4 CVE-2026-55437 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-55437 ] coder--coder Coder allows organi= zations to provision remote development environments via Terraform. Prior t=
o versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based wor= kspace app proxy allowed the same-owner CORS check to be bypassed. When a w= orkspace-name subdomain segment parsed as a UUID, the workspace was resolve=
d by ID without confirming the URL's username matched the real owner, while=
the CORS middleware trusted the unverified username in the hostname. Pract= ical exploitation requires subdomain app routing (wildcard hostname) enable=
d and a victim who visits the attacker's crafted app URL while authenticate=
d. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 validates the su= bdomain username against the resolved workspace's actual owner and bases th=
e same-owner CORS decision on the authoritative owner identity. No known wo= rkarounds are available. 2026-07-08 5.8 CVE-2026-55438 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-55438 ] coder--coder Coder allows organizations t=
o provision remote development environments via Terraform. Starting in vers= ion 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDa= taBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice u= sing the client-supplied `FileSize` from a `DataUpload` message without an = upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` va= lue itself was unconstrained. The fix in versions 2.29.7, 2.32.7, 2.33.8, a=
nd 2.34.2 validates `FileSize` against an upper bound (`MaxFileSize =3D 100=
MiB`) before allocation. As a workaround, restrict access to the provision=
er daemon serve endpoint to trusted provisioner daemon service accounts. 20= 26-07-07 4.9 CVE-2026-55079 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 5079 ] composer--composer Composer is a dependency Manager for the PHP lang= uage. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .=
. path segments can resolve outside the package install directory and cause=
Composer's binary installation flow to chmod an existing host file to a wo= rld-readable and world-executable mode during composer install, update, or = require. This issue is fixed in versions 2.2.29 and 2.10.2. 2026-07-08 6.1 = CVE-2026-59946 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59946 ] compos= er--composer Composer is a dependency Manager for the PHP language. Prior t=
o 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it cou=
ld print a credential embedded in the username slot of a repository or pack= age URL, such as a GitHub Personal Access Token in
https://TOKEN@host/, to = debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not=
sanitize username-only URL credentials. This issue is fixed in versions 2.= 2.29 and 2.10.2. 2026-07-08 4.7 CVE-2026-59947 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-59947 ] ComposioHQ--composio Composio SDK before 0.2.32-b= eta.283 contains a path validation bypass vulnerability that allows attacke=
rs to read and exfiltrate sensitive files by exploiting a missing assertSaf= eFileUploadPath check in the readFileFromDisk function within tool-file-upl= oads.ts. Attackers can exploit prompt injection to manipulate file_uploadab=
le parameters to reference sensitive paths such as SSH private keys, causin=
g the CLI to upload credential files to attacker-controlled storage. 2026-0= 7-08 6.8 CVE-2026-59807 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59807=
] coollabsio--Coolify A vulnerability was detected in coollabsio Coolify u=
p to 4.1.1. The impacted element is an unknown function of the file /app/Po= licies/ of the component Policy Handler. Performing a manipulation results =
in missing authorization. Remote exploitation of the attack is possible. Th=
e exploit is now public and may be used. 2026-07-12 6.3 CVE-2026-15507 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-15507 ] coollabsio--coolify Cooli=
fy is an open-source and self-hostable tool for managing servers, applicati= ons, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoi= nts are guarded by read ability, allowing read-scoped API tokens to perform=
state-changing operations such as validating cloud tokens and servers. Thi=
s issue is fixed in version 4.0.0-beta.466. 2026-07-06 6.5 CVE-2026-32718 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-32718 ] coollabsio--coolify Co= olify is an open-source and self-hostable tool for managing servers, applic= ations, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewi=
re component does not check isInstanceAdmin in its mount method, allowing n= on-admin users to access the Updates settings page and potentially modify a= uto-update settings or trigger update checks. This issue is fixed in versio=
n 4.0.0-beta.471. 2026-07-06 6.5 CVE-2026-34050 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-34050 ] coollabsio--coolify Coolify is an open-source an=
d self-hostable tool for managing servers, applications, and databases. Pri=
or to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate lim= iting, and no input validation, allowing arbitrary content to be forwarded = directly to a Discord webhook and enabling spam, content injection, and web= hook abuse. This issue is fixed in version 4.0.0-beta.474. 2026-07-06 6.5 C= VE-2026-41899 [
https://www.cve.org/CVERecord?id=3DCVE-2026-41899 ] coollab= sio--coolify Coolify is an open-source and self-hostable tool for managing = servers, applications, and databases. Prior to 4.0.0-beta.471, the Activity= Monitor Livewire component exposes a public $activityId property without Li= vewire's #[Locked] attribute. It loads activities via Activity::find($this-= >activityId) with no authorization or team scoping. Activity IDs are auto-i= ncrementing integers. Any authenticated user can enumerate activity records=
across all teams and read the full command output from remote SSH processe=
s, which may include secrets, configuration files, and infrastructure detai= ls. This issue is fixed in version 4.0.0-beta.471. 2026-07-06 5 CVE-2026-34= 167 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34167 ] coollabsio--cooli=
fy Coolify is an open-source and self-hostable tool for managing servers, a= pplications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middl= eware trusts all proxies ($proxies =3D '*'), accepting X-Forwarded-Host fro=
m any source. The TrustHosts middleware, intended to prevent host header at= tacks, has a circular caching dependency that prevents it from ever validat= ing hosts. When a password reset is requested, the ResetPassword notificati=
on generates the reset URL using url(route(..., false)), which derives the = host from the (spoofable) request. An unauthenticated attacker can trigger =
a password reset email containing a link pointing to an attacker-controlled=
domain, enabling token theft and account takeover. This issue is fixed in = version 4.0.0-beta.471. 2026-07-07 5.3 CVE-2026-34198 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-34198 ] coollabsio--coolify Coolify is an open-sou= rce and self-hostable tool for managing servers, applications, and database=
s. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base=
URL for server-side HTTP requests without allowlisting or private IP block= ing, allowing an authenticated user to configure a GitHub App source that c= auses Coolify to request internal services or cloud metadata endpoints. Thi=
s issue is reported as fixed in version 4.0.0-beta.471. 2026-07-07 4.3 CVE-= 2026-34170 [
https://www.cve.org/CVERecord?id=3DCVE-2026-34170 ] coollabsio= --coolify Coolify is an open-source and self-hostable tool for managing ser= vers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endp= oint validation only checks URL format and testConnection() sends a server-= side request to the configured endpoint, allowing an authenticated user wit=
h storage management permissions to make Coolify request internal or metada= ta-service URLs. This issue is fixed in version 4.0.0-beta.474. 2026-07-07 = 4.9 CVE-2026-42147 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42147 ] Co= reWCF--CoreWCF CoreWCF is a port of the service side of Windows Communicati=
on Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF servi=
ce listening on a Kafka topic stops processing new records from that topic = when KafkaTransportPump receives a null-value tombstone record, causing a p= ersistent endpoint denial of service for attackers with produce permission.=
This issue is fixed in versions 1.8.1 and 1.9.1. 2026-07-08 6.5 CVE-2026-5= 4775 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54775 ] CoreWCF--CoreWCF=
CoreWCF is a port of the service side of Windows Communication Foundation = (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transpor=
t accepts attachment to a pre-existing named pipe instance, allowing local = interception of NetNamedPipe traffic when an attacker races NamedPipeListen=
er startup between shared memory GUID publication and service named pipe cr= eation. This issue is fixed in versions 1.8.1 and 1.9.1. 2026-07-08 6.5 CVE= -2026-54777 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54777 ] CoreWCF--= CoreWCF CoreWCF is a port of the service side of Windows Communication Foun= dation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSock=
et POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid = calls, allowing concurrent connections to attribute one connection's identi=
ty to another or crash the host process under contention. This issue is fix=
ed in versions 1.8.1 and 1.9.1. 2026-07-08 6.2 CVE-2026-54778 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-54778 ] CoreWCF--CoreWCF CoreWCF is a port=
of the service side of Windows Communication Foundation (WCF) to .NET Core=
. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification perf= orms a document-wide ds:Signature lookup, allowing an unauthenticated remot=
e attacker to place a SOAP header before wsse:Security and cause WSSecurity= OneDotZeroReceiveSecurityHeader to verify an attacker-supplied signature in= stead of the security header signature. This issue is fixed in versions 1.8=
.1 and 1.9.1. 2026-07-08 5.9 CVE-2026-54773 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-54773 ] CoreWCF--CoreWCF CoreWCF is a port of the service si=
de of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 a=
nd 1.9.1, CoreWCF SAML token replay protection is inoperative because Defau= ltTokenReplayCache.TryAdd does not reject duplicate tokens when DetectRepla= yedTokens is enabled, allowing a captured token to be reused. This issue is=
fixed in versions 1.8.1 and 1.9.1. 2026-07-08 5.9 CVE-2026-54779 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-54779 ] CoreWCF--CoreWCF CoreWCF is a = port of the service side of Windows Communication Foundation (WCF) to .NET = Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Soc= kets with PosixIdentity client credentials can accept connections that skip=
the application/unixposix stream upgrade before dispatching messages, bypa= ssing framing-layer identity checks in UnixPosixIdentitySecurityUpgradeProv= ider. This issue is fixed in versions 1.8.1 and 1.9.1. 2026-07-08 4.4 CVE-2= 026-54776 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54776 ] corvusinfo-= -CorvusPay WooCommerce Payment Gateway The CorvusPay WooCommerce Payment Ga= teway plugin for WordPress is vulnerable to Payment Bypass via Improper Ver= ification of Cryptographic Signature in all versions up to, and including, = 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint=
`POST /wp-json/corvuspay/success/` with `'permission_callback' =3D> '__ret= urn_true'`, and while it calls `$this->client->validate->signature()` and s= tores the boolean result in `$res`, the result is never evaluated in a cond= itional - it is only written to the debug log - causing execution to uncond= itionally reach `$order->payment_complete()` regardless of whether the cryp= tographic signature is valid. This makes it possible for unauthenticated at= tackers to mark any pending WooCommerce order as fully paid by sending a PO=
ST request to the success endpoint containing an arbitrary or forged signat= ure value, allowing them to obtain goods or services without payment. Becau=
se WooCommerce order IDs are sequential integers, target orders are trivial=
ly enumerable via the `order_number` POST parameter, requiring no prior kno= wledge of the victim order. 2026-07-09 5.3 CVE-2026-9027 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-9027 ] corvusinfo--CorvusPay WooCommerce Paymen=
t Gateway The CorvusPay WooCommerce Payment Gateway plugin for WordPress is=
vulnerable to authorization bypass in all versions up to, and including, 2= .7.4. This is due to the plugin not properly verifying that a user is autho= rized to perform an action. This makes it possible for unauthenticated atta= ckers to cancel any WooCommerce order placed via the CorvusPay payment meth=
od by supplying an arbitrary order number to the /wp-json/corvuspay/cancel/=
REST endpoint. 2026-07-09 5.3 CVE-2026-9028 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-9028 ] Cotonti--Cotonti Cotonti Siena 0.9.26 and earlier co= ntains a stored cross-site scripting vulnerability that allows authenticate=
d users with PFS access to inject arbitrary script payloads by supplying ma= licious HTML in the ntitle parameter processed through the TXT filter in pf= s.main.php. Attackers can create a folder with a crafted title containing s= cript tags that are stored unescaped in the database and execute in the bro= wser of any user who views the folder listing, including administrators. 20= 26-07-09 5.4 CVE-2026-58144 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 8144 ] coturn--coturn Coturn is a free open source implementation of TURN a=
nd STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in=
coturn takes a filename argument and directly passes it to fopen with no p= ath validation. An authenticated admin with CLI access can overwrite arbitr= ary files writable by the coturn process because the command string is used=
as-is after stripping the psd prefix and leading spaces, allowing truncati=
on and overwrite with session dump data. This issue is fixed in version 4.1= 3.0. 2026-07-10 6 CVE-2026-53449 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-53449 ] Craft--CMS A vulnerability was detected in Craft CMS up to 4.18= .0.1. Affected is the function actionReorderSets of the file src/controller= s/GlobalsController.php of the component reorder-sets Endpoint. The manipul= ation results in authorization bypass. The attack can be executed remotely.=
Upgrading to version 4.18.1 is able to address this issue. The patch is id= entified as 9bd05c91e6a7e6da5e949ec41a31c220c059aa04. The affected componen=
t should be upgraded. 2026-07-06 4.3 CVE-2026-14793 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-14793 ] Craft--CMS A flaw has been found in Craft CM=
S up to 4.18.0.1. Affected by this vulnerability is the function actionGetN= ewUsersData of the file src/controllers/ChartsController.php of the compone=
nt Charts Endpoint. This manipulation of the argument userGroupId causes im= proper authorization. The attack is possible to be carried out remotely. Up= grading to version 4.18.1 addresses this issue. Patch name: 9ee53efc1314e6a= ba32771c66a13e072a246f4ce. It is suggested to upgrade the affected componen=
t. 2026-07-06 4.3 CVE-2026-14794 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-14794 ] crewhrm--Employee, Leave and Recruitment Management System Crew=
HRM The Employee, Leave and Recruitment Management System - Crew HRM plugi=
n for WordPress is vulnerable to authorization bypass in all versions up to=
, and including, 1.2.2. This is due to the plugin not properly verifying th=
at a user is authorized to perform an action. This makes it possible for au= thenticated attackers, with subscriber-level access and above, to delete, a= rchive, unarchive, and duplicate arbitrary job listings - along with their = associated stages, meta, addresses, and applications - by supplying an arbi= trary integer job_id. The nonce verified by Dispatcher::dispatch() is expos=
ed to all authenticated front-end visitors via wp_head script localization,=
meaning subscribers can trivially obtain it and satisfy the nonce check wi= thout possessing any elevated privilege. 2026-07-09 4.3 CVE-2026-9237 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-9237 ] cservit--affiliate-toolkit = Multi-Network Affiliate & Amazon Product Display The affiliate-toolkit - WP=
Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored = Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versi= ons up to, and including, 3.7.0 due to insufficient input sanitization and = output escaping on user supplied attributes. This makes it possible for aut= henticated attackers, with contributor-level access and above, to inject ar= bitrary web scripts in pages that will execute whenever a user accesses an = injected page. This is a bypass to CVE-2024-10227. 2026-07-10 6.4 CVE-2026-= 15296 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15296 ] davenardella--s= nap7 A flaw has been found in davenardella snap7 up to 1.4.3. This affects = the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.= cpp of the component ReadVar Request Handler. This manipulation causes dese= rialization. The attack requires access to the local network. The exploit h=
as been published and may be used. The project was informed of the problem = early through an issue report but has not responded yet. 2026-07-08 6.3 CVE= -2026-15105 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15105 ] dcooney--= Ajax Load More Infinite Scroll, Load More, & Lazy Load The WordPress Infini=
te Scroll - Ajax Load More plugin for WordPress is vulnerable to Stored Cro= ss-Site Scripting via admin settings in all versions up to, and including, = 7.0.1 due to insufficient input sanitization and output escaping. This make=
s it possible for authenticated attackers, with administrator-level permiss= ions and above, to inject arbitrary web scripts in pages that will execute = whenever a user accesses an injected page. This only affects multi-site ins= tallations and installations where unfiltered_html has been disabled. 2026-= 07-10 4.4 CVE-2026-15295 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1529=
5 ] Dell--Unisphere for PowerMax Dell Unisphere for PowerMax, version(s) 10= .3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileg=
ed attacker with remote access could potentially exploit this vulnerability=
to read arbitrary files. 2026-07-10 6.5 CVE-2026-54468 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-54468 ] Dell--Unisphere for PowerMax Dell Unisph= ere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Rest= riction of XML External Entity Reference vulnerability. A low privileged at= tacker with remote access could potentially exploit this vulnerability, lea= ding to Unauthorized access. 2026-07-10 5.3 CVE-2026-54470 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-54470 ] Deloitte--AI Assist for Customer Delo= itte AI Assist for Customer disclosed some configuration information throug=
h public-facing API endpoints that accepted unauthenticated requests. This = information could reduce an attacker's reconnaissance effort. On 2026-03-25=
, AI Assist for Customer restricted network access and enforced authenticat= ion for the previously exposed endpoints. 2026-07-10 5.3 CVE-2026-57474 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-57474 ] Deloitte--AI Assist for = Customer Deloitte AI Assist for Customer accepted unauthenticated POST requ= ests through public-facing API endpoints that allowed a remote attacker to = make limited additions to the configuration. These additions were not used =
by the system. On 2026-03-25, AI Assist for Customer restricted network acc= ess and enforced authentication for the previously exposed endpoints. 2026-= 07-10 5.3 CVE-2026-57475 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5747=
5 ] Deloitte--AI Assist for Customer Deloitte AI Assist for Customer expose=
d unauthenticated API endpoints that allowed an attacker with knowledge of = additional parameters to read from or inject content into the retrieval-aug= mented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restr= icted network access and enforced authentication for the previously exposed=
endpoints. 2026-07-10 4.8 CVE-2026-57476 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-57476 ] devitemsllc--Recurio Ultimate Subscription for WooComm= erce The Recurio - Ultimate Subscription for WooCommerce plugin for WordPre=
ss is vulnerable to generic SQL Injection via the 'data' parameter in all v= ersions up to, and including, 1.1.3 due to insufficient escaping on the use=
r supplied parameter and lack of sufficient preparation on the existing SQL=
query. This makes it possible for authenticated attackers, with shop manag= er-level access and above, to append additional SQL queries into already ex= isting queries that can be used to extract sensitive information from the d= atabase. 2026-07-08 4.9 CVE-2026-12936 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-12936 ] dhlparcel--DHL eCommerce (Benelux) for WooCommerce The = DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable =
to unauthorized modification and loss of data due to a missing capability c= heck and missing nonce verification on the create_label() and delete_label(=
) functions in versions up to, and including, 2.2.3. These functions are wi= red to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_delete hook=
s and act on an attacker-supplied post_id (WooCommerce order ID). This make=
s it possible for authenticated attackers, with Subscriber-level access and=
above, to create or delete DHL shipping labels associated with any WooComm= erce order on the site. 2026-07-09 4.3 CVE-2026-9235 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-9235 ] Digi International--PortServer TS 1/2/4 This=
vulnerability allows an unauthenticated actor to bypass authentication and=
gain access to restricted resources on the device. 2026-07-07 5.9 CVE-2026= -12352 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12352 ] digiblogger--B= uddyHolis TableSearch The BuddyHolis TableSearch plugin for WordPress is vu= lnerable to Stored Cross-Site Scripting via the 'placeholder' parameter in = all versions up to, and including, 1.1.0 due to insufficient input sanitiza= tion and output escaping. This makes it possible for authenticated attacker=
s, with Contributor-level access and above, to inject arbitrary web scripts=
in pages that will execute whenever a user accesses an injected page. 2026= -07-10 6.4 CVE-2026-15301 [
https://www.cve.org/CVERecord?id=3DCVE-2026-153=
01 ] discourse--discourse Discourse is an open-source discussion platform. = Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could ro= ute direct S3 multipart uploads through ExternalUploadManager into the admi=
n backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.=
2, and 2026.1.5. 2026-07-09 6.5 CVE-2026-46413 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-46413 ] discourse--discourse Discourse is an open-source = discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, t=
he AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages = were signed by Amazon but did not bind them to trusted TopicArn values, all= owing any AWS account holder to publish validly signed forged Bounce notifi= cations that revoke a targeted user email. This issue is fixed in versions = 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. 2026-07-09 6.5 CVE-2026-53961 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-53961 ] discourse--discourse D= iscourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1=
, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names,=
sample invitees, and attendance statistics to users who could view the top=
ic but were not entitled to view the private event invitee list. This issue=
is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. 2026-07-0=
9 5.3 CVE-2026-45780 [
https://www.cve.org/CVERecord?id=3DCVE-2026-45780 ] = discourse--discourse Discourse is an open-source discussion platform. Prior=
to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitizati=
on in upload and user avatar handling could lead to cross-site scripting wh=
en a user visited specific URLs that are not normally part of community bro= wsing. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 20= 26.1.5. 2026-07-09 5.4 CVE-2026-53962 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-53962 ] discourse--discourse Discourse is an open-source discussio=
n platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revis= ions that should be hidden from regular users could be leaked through visib=
le diffs on adjacent revisions serialized by PostRevisionSerializer. This i= ssue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. 2026-= 07-09 5.3 CVE-2026-59828 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5982=
8 ] djangoproject--Django An issue was discovered in Django 6.0 before 6.0.=
7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines i=
n domain names (unless used via a form field, since `CharField` strips newl= ines). If an application uses values with newlines in an HTTP response, hea= der injection can occur. Django itself is unaffected because `HttpResponse`=
prohibits newlines in HTTP headers. Earlier, unsupported Django series (su=
ch as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.=
Django would like to thank Bence Nagy for reporting this issue. 2026-07-07=
6.1 CVE-2026-53878 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53878 ] d= jangoproject--Django An issue was discovered in Django 6.0 before 6.0.7 and=
5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorato=
r cache responses that vary on cookies when the incoming request carries un= related cookies, which allows remote attackers to read private data from th=
e shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, a=
nd 3.2.x) were not evaluated and may also be affected. Django would like to=
thank Chris Whyland for reporting this issue. 2026-07-07 4.2 CVE-2026-4858=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48588 ] djangoproject--Djan=
go An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16=
. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when=
constructed from a bytes object, which can disclose adjacent memory or cau=
se service degradation via a potential segmentation fault when the `vsi_buf= fer` property is accessed. Earlier, unsupported Django series (such as 5.0.=
x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django wo= uld like to thank Bence Nagy for reporting this issue. 2026-07-07 4.8 CVE-2= 026-53877 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53877 ] easyappoint= ments--Easy Appointments The Easy Appointments plugin for WordPress is vuln= erable to authorization bypass in all versions up to, and including, 3.12.2=
7. This is due to the plugin not properly verifying that a user is authoriz=
ed to perform an action. This makes it possible for authenticated attackers=
, with author-level access and above, to cancel all upcoming appointments s= ite-wide by marking every future appointment stored by the plugin as abando= ned. The nonce required to authenticate the cancellation request is printed=
on the Appointments admin page, which is itself gated only by the edit_pos=
ts capability that Authors possess, making the nonce readily accessible to = low-privileged users. 2026-07-10 4.3 CVE-2026-11992 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-11992 ] Eleveo--Call Recording Software A vulnerabil= ity was detected in Eleveo Call Recording Software 9.7.0. The impacted elem= ent is an unknown function of the file /callrec/userAddAction.do. Performin=
g a manipulation of the argument role results in improper authorization. It=
is possible to initiate the attack remotely. The exploit is now public and=
may be used. The vendor was contacted early about this disclosure but did = not respond in any way. 2026-07-10 6.3 CVE-2026-15373 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-15373 ] Eleveo--Call Recording Software A flaw has=
been found in Eleveo Call Recording Software 9.7.0. This affects an unknow=
n function of the file /callrec/roleAddAction.do of the component Group Int= erface. Executing a manipulation can lead to improper authorization. It is = possible to launch the attack remotely. The exploit has been published and = may be used. The vendor was contacted early about this disclosure but did n=
ot respond in any way. 2026-07-10 6.3 CVE-2026-15374 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-15374 ] Eleveo--Call Recording Software A vulnerabi= lity was found in Eleveo Call Recording Software 9.7.0. Affected is an unkn= own function of the file /callrec/statisticReportAction.do. The manipulatio=
n results in improper authorization. The attack can be launched remotely. T=
he exploit has been made public and could be used. The vendor was contacted=
early about this disclosure but did not respond in any way. 2026-07-10 6.3=
CVE-2026-15376 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15376 ] Eleve= o--Call Recording Software A vulnerability was identified in Eleveo Call Re= cording Software 9.7.0. This issue affects some unknown processing of the f= ile /callrec/restoreCallAction.do of the component Recorded Calls Page. The=
manipulation leads to improper authorization. The attack is possible to be=
carried out remotely. The exploit is publicly available and might be used.=
The vendor was contacted early about this disclosure but did not respond i=
n any way. 2026-07-12 6.3 CVE-2026-15473 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15473 ] Eleveo--Call Recording Software A vulnerability has bee=
n found in Eleveo Call Recording Software 9.7.0. This impacts an unknown fu= nction of the file /callrec/users_ldap.jsp of the component LDAP User Inter= face. The manipulation leads to improper authorization. The attack can be i= nitiated remotely. The exploit has been disclosed to the public and may be = used. The vendor was contacted early about this disclosure but did not resp= ond in any way. 2026-07-10 4.3 CVE-2026-15375 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-15375 ] Eleveo--Call Recording Software A vulnerability wa=
s determined in Eleveo Call Recording Software 9.7.0. Affected by this vuln= erability is an unknown functionality of the file /callrec/sendlogfile. Thi=
s manipulation causes improper authorization. The attack may be initiated r= emotely. The exploit has been publicly disclosed and may be utilized. The v= endor was contacted early about this disclosure but did not respond in any = way. 2026-07-10 4.3 CVE-2026-15377 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-15377 ] Eleveo--Call Recording Software A vulnerability has been foun=
d in Eleveo Call Recording Software 9.7.0. Affected by this issue is some u= nknown functionality of the file /callrec/group.jsp. Such manipulation lead=
s to improper authorization. The attack may be launched remotely. The explo=
it has been disclosed to the public and may be used. The vendor was contact=
ed early about this disclosure but did not respond in any way. 2026-07-11 4=
.3 CVE-2026-15470 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15470 ] Ele= veo--Call Recording Software A vulnerability was found in Eleveo Call Recor= ding Software 9.7.0. This affects an unknown part of the file /callrec/pci_= dss_status.jsp. Performing a manipulation results in improper authorization=
. Remote exploitation of the attack is possible. The exploit has been made = public and could be used. The vendor was contacted early about this disclos= ure but did not respond in any way. 2026-07-12 4.3 CVE-2026-15471 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-15471 ] Eleveo--Call Recording Softwar=
e A vulnerability was determined in Eleveo Call Recording Software 9.7.0. T= his vulnerability affects unknown code of the file /callrec/composeEmailAct= ion.do. Executing a manipulation can lead to improper authorization. The at= tack can be executed remotely. The exploit has been publicly disclosed and = may be utilized. The vendor was contacted early about this disclosure but d=
id not respond in any way. 2026-07-12 4.3 CVE-2026-15472 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-15472 ] Eleveo--Call Recording Software A secur= ity flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impac= ted is an unknown function of the file /callrec/audio.jsp of the component = Call Recording Handler. The manipulation of the argument callId results in = improper authorization. The attack may be performed from remote. The exploi=
t has been released to the public and may be used for attacks. The vendor w=
as contacted early about this disclosure but did not respond in any way. 20= 26-07-12 4.3 CVE-2026-15474 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 5474 ] enquirer--enquirer A security flaw has been discovered in enquirer u=
p to 2.4.1. Affected is the function Enquirer.set of the component Public P= ackage API. The manipulation of the argument question.name results in impro= perly controlled modification of object prototype attributes. The attack ca=
n be launched remotely. The exploit has been released to the public and may=
be used for attacks. The project was informed of the problem early through=
an issue report. 2026-07-09 4.3 CVE-2026-15187 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-15187 ] etcd-io--etcd etcd is a distributed key-value st= ore for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when = etcd is configured with --listen-client-http-urls to split HTTP and gRPC cl= ient endpoints onto separate listeners, the --client-crl-file Certificate R= evocation List is not enforced on the gRPC listener, allowing a client with=
a revoked certificate to authenticate successfully over gRPC. This issue i=
s fixed in versions 3.5.32 and 3.6.13. 2026-07-08 6.5 CVE-2026-59818 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-59818 ] fahadmahmood--Easy Upload F= iles During Checkout The Easy Upload Files During Checkout plugin for WordP= ress is vulnerable to unauthorized access in all versions up to, and includ= ing, 3.0.1. This is due to missing authorization checks in the ufdc_custom_= init() function, which processes the 'eufdc-delete' parameter without any n= once verification, capability check, or attachment ownership validation. Th=
is makes it possible for unauthenticated attackers to permanently delete ar= bitrary media library attachments from the WordPress site. 2026-07-10 5.3 C= VE-2026-6802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6802 ] filebrows= er--filebrowser File Browser provides a web file managing interface. Prior =
to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling = symlink as in scope and then follows the symlink during file creation, allo= wing an authenticated user with Create and Modify permissions to create att= acker-controlled files outside the user's scope. This issue is fixed in ver= sion 2.63.16. 2026-07-08 6.3 CVE-2026-55668 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-55668 ] flask-dashboard--Flask-MonitoringDashboard A vulnera= bility has been found in flask-dashboard Flask-MonitoringDashboard up to 5.= 0.2. Affected by this issue is some unknown functionality. Such manipulatio=
n leads to cross-site request forgery. The attack may be launched remotely.=
The exploit has been disclosed to the public and may be used. The project = was informed of the problem early through an issue report but has not respo= nded yet. 2026-07-08 4.3 CVE-2026-15034 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15034 ] Flowise--Flowise Flowise before 3.1.0 contains a path t= raversal vulnerability in Faiss and SimpleStore vector store implementation=
s that accept unsanitized basePath parameters from authenticated users. Att= ackers with valid API tokens can write vector store data to arbitrary files= ystem locations, potentially enabling code execution or data exfiltration. = 2026-07-08 6.5 CVE-2026-56273 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -56273 ] Formbricks--Formbricks A security vulnerability has been detected =
in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/= modules/survey/link/actions.ts of the component Survey Handler. The manipul= ation leads to improper access controls. Remote exploitation of the attack =
is possible. Upgrading to version 5.1.0-rc.1 will fix this issue. The ident= ifier of the patch is af6023b5ac3b030ffcea24fac799f76f3e3512c6. You should = upgrade the affected component. 2026-07-06 6.5 CVE-2026-14792 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-14792 ] Foxit Software Inc.--Foxit PDF Edi= tor The application opens the PDF, and JavaScript performs operations on th=
e page and the document, causing the page-related objects within the applic= ation to lose synchronization; however, the renderer still trusts the outda= ted page count, and eventually the application crashes due to out-of-bounds=
access. 2026-07-08 6.1 CVE-2026-57241 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-57241 ] Foxit Software Inc.--Foxit PDF Editor During the proces=
s of page opening and form formatting, a JavaScript reentrancy results in a=
n inconsistent document status. Subsequently, with outdated page informatio=
n, the application attempts to access invalid addresses, causing the applic= ation to crash. 2026-07-08 6.1 CVE-2026-57243 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-57243 ] Foxit Software Inc.--Foxit PDF Editor An abnormal = image object causes the renderer to enter the wrong processing branch. When=
converting the scan lines, an invalid image buffer pointer is used, result= ing in the application crashing. 2026-07-08 6.1 CVE-2026-57253 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-57253 ] Foxit Software Inc.--Foxit PDF Ed= itor The application opens a PDF containing an abnormal color space whose a= ttributes reference a valid but semantically malformed function. The functi= on's output is not validated; when subsequently read, it produces an illega=
l pointer that accesses an out-of-bounds region, crashing the application. = 2026-07-08 6.1 CVE-2026-57255 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -57255 ] Foxit Software Inc.--Foxit PDF Editor During the PRC parsing stage=
, there is a lack of boundary verification for the PRC entity index, which = leads to an out-of-bounds read of the entity array. As a result, the applic= ation crashes. 2026-07-08 6.1 CVE-2026-57257 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-57257 ] Foxit Software Inc.--Foxit PDF Editor The PRC file = header parsing logic trusts the constructed file structure description info= rmation, assumes that the underlying array contains elements and reads them=
, leading to out-of-bounds reads and application crashes. 2026-07-08 6.1 CV= E-2026-57258 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57258 ] Foxit So= ftware Inc.--Foxit PDF Editor The input file does not need to be strictly i=
n a structurally valid PDF format. Instead, after reviewing the content, th=
e original document disguised as a PDF will be sent to the parser. Maliciou=
s documents will construct malicious external entities that, through the pr= otocol, point to local paths, thereby allowing access to any local files wi= thin the user's permission range. 2026-07-08 6.5 CVE-2026-57259 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-57259 ] FreeRDP--FreeRDP FreeRDP is a fr=
ee implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP = server implementations with the MS-RDPECAM camera device enumerator channel=
enabled scan attacker-supplied DeviceName and VirtualChannelName fields fo=
r a NUL terminator in channels/rdpecam/server/camera_device_enumerator_main=
.c and then dereference once past the scan bound, allowing a malicious RDP = client to trigger a 1- to 2-byte out-of-bounds heap read. This issue is fix=
ed in version 3.28.0. 2026-07-10 6.5 CVE-2026-57157 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-57157 ] freshlabs--fresh Podcaster The fresh Podcast=
er plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th=
e 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 du=
e to insufficient input sanitization and output escaping on user supplied a= ttributes. This makes it possible for authenticated attackers, with contrib= utor-level access and above, to inject arbitrary web scripts in pages that = will execute whenever a user accesses an injected page. 2026-07-11 6.4 CVE-= 2026-1382 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1382 ] Gallagher--C= ommand Centre Server An=C2=A0Incorrect Privilege Assignment (CWE-266)=C2=A0= vulnerability in=C2=A0the Command Centre Server=C2=A0allows an=C2=A0authent= icated operator with limited privileges=C2=A0to perform some operations tha=
t they would not normally be authorized to perform.=C2=A0Version of Command=
Centre affected:=C2=A09.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.= 40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(M= R7), all versions of 9.10. 2026-07-07 5.3 CVE-2026-26053 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-26053 ] gallerycreator--SimpLy Gallery The Simp=
Ly Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cr= oss-Site Scripting via block attributes in all versions up to, and includin=
g, 3.3.3.2. This is due to insufficient input sanitization and output escap= ing on the sliderMaxHeight block attribute in the pgc_sgb_render_callback()=
function. The vulnerability exists because the pgc_sgb_sanitize_custom_css=
() function uses a flawed regex pattern that only removes event handlers wi=
th quoted values (e.g., onfocus=3D"alert()") but fails to catch unquoted ev= ent handlers (e.g., onfocus=3Dalert(document.cookie)), allowing the malicio=
us code to bypass sanitization. This makes it possible for authenticated at= tackers, with Author-level access and above, to inject arbitrary web script=
s in pages via block attributes that will execute whenever a user accesses =
an injected page. 2026-07-11 6.4 CVE-2026-5743 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-5743 ] gamaup--Blocks for ACF Fields Display Custom Field=
s in the Block Editor The Blocks for ACF Fields plugin for WordPress is vul= nerable to unauthorized access of data due to a missing capability check on=
the get_all_values() function in the /wp-json/acf-field-blocks/v1/values R= EST endpoint in versions up to, and including, 1.6.2. The permission_callba=
ck only verifies the generic publish_posts capability and the handler passe=
s a user-supplied id parameter directly to get_field_objects() without veri= fying that the requesting user is authorized to read the target object. Thi=
s makes it possible for authenticated attackers, with Author-level access a=
nd above, to read ACF field values from arbitrary posts (including private = posts, drafts, posts by other users, and other ACF-supported objects) that = they should not have access to. 2026-07-09 6.5 CVE-2026-12428 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-12428 ] gchq--CyberChef CyberChef is a web=
app for encryption, encoding, compression, and data analysis. Prior to 11.= 2.0, the Series Chart operation accepts __proto__ as a key while parsing us= er-supplied CSV, allowing prototype pollution that can be chained with oper= ations such as Parse UDP to inject malicious JavaScript into HTML output. T= his issue is fixed in version 11.2.0. 2026-07-08 5 CVE-2026-57439 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-57439 ] getgrav--grav Grav is a file-b= ased Web platform. Prior to 1.7.53, an authenticated administrator with bac= kup permissions can download a ZIP archive containing the full Grav install= ation root, including user/accounts/admin.yaml with the administrator passw= ord hash and user/config with site configuration, through the backup downlo=
ad endpoint protected only by the session-static admin-nonce URL parameter.=
This issue is reported as fixed in version 1.7.53. 2026-07-10 6.8 CVE-2026= -55885 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55885 ] getgrav--grav = Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author = (any admin.pages user, or anyone able to write to user/pages) to exfiltrate=
configuration secrets. Although the sandbox replaces the 'config' variable=
with a redacted facade and strips Config::get/toArray from the method allo= wlist, the raw container remains accessible via the allow-listed grav.offse= tGet('config'), which returns the real Config object. Allow-listed object-d= umping filters (json_encode, print_r, yaml_encode) then serialize that obje=
ct at the PHP level without invoking the sandbox method gate, exposing the = full config tree including plugin secrets such as SMTP credentials, API key=
s, and plugin DB credentials. This is an incomplete fix for GHSA-j274-39qw-= 32c9. 2026-07-10 6.5 CVE-2026-61450 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-61450 ] getgrav--grav Grav before 2.0.1 contains a decompression bom=
b vulnerability in ZipArchiver::extract() that lacks limits on uncompressed=
size, file count, and nesting depth. Attackers can supply a crafted ZIP ar= chive that expands to fill available disk space, causing denial of service =
by exhausting storage resources. 2026-07-10 6.5 CVE-2026-61455 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-61455 ] getgrav--grav The Grav Admin2 plu= gin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript va= riable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/adm=
in (and its subroutes). This object is returned in every unauthenticated re= sponse and discloses the server URL, API prefix, admin base path, runtime e= nvironment type, and exact Grav and Admin2 version numbers, allowing an una= uthenticated attacker to fingerprint the deployment and select version-spec= ific exploits without reconnaissance. 2026-07-11 5.3 CVE-2026-61454 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-61454 ] getgrav--grav Grav is a file= -based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored = XSS through the Markdown media attribute action (CVE-2026-42841) leaves the=
sibling MediaObjectTrait::style method reachable through the same Markdown=
excerpt-action pipeline, allowing an editor to save Markdown image style p= arameters that are written into the rendered img style attribute without sa= nitization. This issue is fixed in version 2.0.0-rc.9. 2026-07-10 4.8 CVE-2= 026-55890 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55890 ] getgrav--gr=
av The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sani= tize SVG files uploaded through the POST /api/v1/media endpoint. The Handle= sMediaUploads::processUploadedFile() method validates only the file extensi=
on and never invokes Security::sanitizeSVG(), so an authenticated attacker = with the api.media.write permission can upload an SVG containing arbitrary = JavaScript. The file is stored unmodified and served with Content-Type: ima= ge/svg+xml; when an administrator opens it in a browser (directly or via <o= bject>/<iframe>), the embedded script executes in their session context, en= abling cookie theft and session hijacking. 2026-07-10 4.6 CVE-2026-61456 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-61456 ] getwpfunnels--Mail Mint=
Email Marketing, Newsletter, Email Automation & WooCommerce Emails The Mai=
l Mint - Email Marketing, Newsletter, Email Automation & WooCommerce Emails=
plugin for WordPress is vulnerable to generic SQL Injection via the 'recip= ients' parameter in all versions up to, and including, 1.24.1 due to insuff= icient escaping on the user supplied parameter and lack of sufficient prepa= ration on the existing SQL query. This makes it possible for authenticated = attackers, with administrator-level access and above, to append additional = SQL queries into already existing queries that can be used to extract sensi= tive information from the database. This is a second-order SQL injection: t=
he malicious payload is first stored unsanitized via a POST request to /mrm= /v1/campaigns/ (bypassing filter_recipients() validation because an int-cas=
t of a string like '1) OR ...' evaluates to a real numeric ID), and is then=
triggered by a subsequent GET request to /mrm/v1/campaigns/{id} that deser= ializes the recipients and passes the raw id string through array_column() = into the vulnerable query. 2026-07-10 4.9 CVE-2026-12918 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-12918 ] getwpfunnels--Mail Mint Email Marketing=
, Newsletter, Email Automation & WooCommerce Emails The Mail Mint - Email M= arketing, Newsletter, Email Automation & WooCommerce Emails plugin for Word= Press is vulnerable to time-based SQL Injection via the 'contact_ids' param= eter in all versions up to, and including, 1.24.2 due to insufficient escap= ing on the user supplied parameter and lack of sufficient preparation on th=
e existing SQL query. This makes it possible for authenticated attackers, w= ith administrator-level access and above, to append additional SQL queries = into already existing queries that can be used to extract sensitive informa= tion from the database. 2026-07-09 4.9 CVE-2026-14342 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-14342 ] getwpfunnels--WPFunnels Funnel Builder for=
WooCommerce with Checkout & One Click Upsell The WPFunnels - Funnel Builde=
r for WooCommerce with Checkout & One Click Upsell plugin for WordPress is = vulnerable to Local File Inclusion in all versions up to, and including, 3.= 12.7 via the 'logKey' parameter parameter. This makes it possible for authe= nticated attackers, with administrator-level access and above, to include a=
nd execute arbitrary .php files on the server, allowing the execution of an=
y PHP code in those files. This can be used to bypass access controls, obta=
in sensitive data, or achieve code execution in cases where .php file types=
can be uploaded and included. 2026-07-09 6.6 CVE-2026-13080 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-13080 ] Ghostfolio--Ghostfolio Ghostfolio's=
PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to v= erify Access.permissions field when processing the Impersonation-Id header,=
allowing read-only access grantees to modify portfolio holding tags. Attac= kers with valid read-only share tokens can assign or remove tags on victim = holdings, corrupting portfolio categorization and reports. 2026-07-07 4.3 C= VE-2026-59709 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59709 ] GitLab-= -GitLab GitLab has remediated an issue in GitLab EE affecting all versions = from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that un= der certain conditions could have allowed an authenticated user with mainta= iner-role permissions to obtain another user's stored credentials due to im= proper authorization controls. 2026-07-08 4.9 CVE-2026-11827 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-11827 ] GitLab--GitLab GitLab has remediate=
d an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, = 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions co= uld have allowed an unauthenticated user to determine the existence of a pr= ivate project due to improper authorization controls on cross-project refer= ence pages. 2026-07-08 4.3 CVE-2026-7492 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-7492 ] GitLab--GitLab GitLab has remediated an issue in GitLab =
EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and=
19.1 before 19.1.2 that under certain conditions could have allowed an aut= henticated user with minimal access permissions to read work item metadata = from private projects due to missing authorization checks. 2026-07-08 4.3 C= VE-2026-8472 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8472 ] GNU--Libr= eDWG A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affec= ted element is the function dwg_bmp of the file src/dwg.c of the component = BMP Image Handler. Such manipulation leads to heap-based buffer overflow. T=
he attack must be carried out locally. The exploit has been disclosed to th=
e public and may be used. Upgrading to version 0.14 is sufficient to fix th=
is issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06=
. It is suggested to upgrade the affected component. 2026-07-09 5.3 CVE-202= 6-15182 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15182 ] gnuwget--wget=
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer over= flow vulnerability in the parse_content_range() function within src/http.c = that allows server-controlled values to cause signed integer arithmetic to = overflow. Attackers can supply malicious Content-Range header values to tri= gger undefined behavior and download desynchronization in the affected clie= nt. 2026-07-07 5.3 CVE-2026-58470 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-58470 ] gnuwget--wget GNU Wget through 1.25.0, fixed in commit c2640fe=
, contains a heap buffer overflow vulnerability in the convert_fname() func= tion within src/url.c that allows remote attackers to trigger memory corrup= tion through a server-supplied filename requiring character set conversion.=
When the output buffer is too small during iconv E2BIG reallocation, the r= eallocation logic miscalculates the remaining space, leading to a heap buff=
er overflow that can be exploited via a maliciously crafted server response=
. 2026-07-07 5.9 CVE-2026-58471 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-58471 ] gnuwget--wget GNU Wget through 1.25.0, fixed in commit dd692d9, = contains a heap buffer overflow vulnerability in the html_quote_string() fu= nction in src/convert.c that allows a remote attacker to trigger memory cor= ruption by supplying a crafted HTML attribute with a large number of charac= ters requiring entity encoding. A server-supplied HTML attribute causes a s= igned integer counter to overflow during output size accumulation, resultin=
g in an undersized heap allocation and subsequent heap buffer overflow duri=
ng the copy phase. 2026-07-07 5.9 CVE-2026-58472 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-58472 ] gofiber--fiber Fiber is an Express inspired web=
framework written in Go. Prior to 3.3.0, the default Authorizer function i=
n the BasicAuth middleware in middleware/basicauth/config.go uses short-cir= cuit evaluation that skips password hash comparison for non-existent userna= mes, enabling reliable remote username enumeration through response timing = differences. This issue is fixed in version 3.3.0. 2026-07-08 5.3 CVE-2026-= 44332 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44332 ] gofiber--fiber = Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 an=
d 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go us=
es Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing =
an attacker-supplied first X-Real-IP value to be forwarded to upstream serv= ers for logging, rate limiting, and access control. This issue is fixed in = version 3.3.0 and 2.52.14. 2026-07-08 5.3 CVE-2026-45045 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-45045 ] gofiber--fiber Fiber is an Express insp= ired web framework written in Go. Prior to 3.4.0, the helmet middleware in = middleware/helmet/helmet.go never sets the Strict-Transport-Security respon=
se header even when HSTSMaxAge is configured because it checks c.Protocol()=
for https instead of c.Scheme(). This issue is fixed in version 3.4.0. 202= 6-07-08 4.8 CVE-2026-53624 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53= 624 ] Grafana--Grafana OSS A user with Editor permissions can craft a dashb= oard whose table (TableNG) panel contains a malicious field name that execu= tes as a script in the browser of any user who views the dashboard (stored = cross-site scripting). 2026-07-10 6.8 CVE-2026-8595 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-8595 ] Grafana--Grafana OSS An unauthenticated attac= ker can repeatedly call Grafana's OAuth login route with unique values, cau= sing unbounded memory growth that can eventually exhaust memory and crash t=
he Grafana instance (denial of service). 2026-07-10 5.3 CVE-2026-8609 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-8609 ] Grav--Grav The Grav API plu= gin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vu= lnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The = endpoint validates only the client-declared MIME type (getClientMediaType) = beginning with 'image/' and does not inspect the actual file content or res= trict the resulting extension, allowing an authenticated user to store arbi= trary content - including PHP code, SVG with embedded JavaScript, and polyg= lot payloads - under user/accounts/avatars/ with predictable filenames. Dir= ect HTTP access to the stored files is blocked by .htaccess (returns 403), = but the files persist on disk and could lead to remote code execution or st= ored XSS in the presence of a path traversal flaw or server misconfiguratio=
n. Fixed in 1.0.1. 2026-07-08 4.3 CVE-2026-58654 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-58654 ] Grav--Grav Grav before 2.0.0 (affected through = 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerabilit=
y in the Markdown image resize() media action. Prior media hardening reject=
s direct ?style=3D payloads and unsafe attribute() fallbacks, but the resiz= e() action in Excerpts::processMediaActions() writes caller-controlled valu=
es directly into the image's styleAttributes. A lower-privileged content ed= itor who can edit page Markdown can store a crafted image URL with semicolo= n-delimited CSS declarations in the resize parameters, which are rendered i= nto the final <img style=3D...> attribute when a higher-privileged reviewer= /admin views the page or preview. This does not require JavaScript executio=
n but enables UI redress/overlay and content-manipulation attacks (e.g., a = full-viewport fixed overlay). Fixed in 2.0.0. 2026-07-08 4.8 CVE-2026-58657=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-58657 ] gristlabs--grist-cor=
e Grist is spreadsheet software using Python as its formula language. Prior=
to 1.7.15, the GET /forms endpoint read table and column metadata without = applying the document's access rules and did not check that the requested s= ection was actually a form. A user with only partial read access, including=
public access on a publicly viewable document, could request the metadata =
of any widget and reveal table and column structure that access rules would=
otherwise hide, even in documents that contain no forms. This issue is fix=
ed in version 1.7.15. 2026-07-10 4.3 CVE-2026-55664 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-55664 ] grokability--snipe-it Snipe-IT is an IT asse= t/license management system. Prior to 8.6.2, the user edit flow stores url(= )->previous() from the attacker-controlled Referer header into Laravel's in= tended URL session value and later uses redirect()->intended(...) when redi= rect_option=3Dback is submitted, allowing Snipe-IT to be used as a trusted = redirector after a legitimate user edit action. This issue is fixed in vers= ion 8.6.2. 2026-07-10 6.1 CVE-2026-55461 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55461 ] grokability--snipe-it Snipe-IT is an IT asset/license m= anagement system. Prior to 8.6.2, an authenticated user with import and ass= ets.update permissions can place a path traversal string in an asset image = field through CSV import and then trigger image deletion, allowing deletion=
of arbitrary files accessible to the server process. This issue is fixed i=
n version 8.6.2. 2026-07-10 6.5 CVE-2026-55469 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-55469 ] grokability--snipe-it Snipe-IT is an IT asset/lic= ense management system. Prior to 8.6.1, the Importer API endpoint allows a = user with CSV import capabilities and a valid API key to overwrite the crea= ted_by value of an import file, allowing unauthorized modification of impor=
t ownership metadata. This issue is fixed in version 8.6.1. 2026-07-10 5.7 = CVE-2026-55475 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55475 ] grokab= ility--snipe-it Snipe-IT is an IT asset/license management system. Prior to=
8.6.2, the unaccepted-assets report delete endpoint authorizes only report= s.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by gl= obal ID without checking access to the related checkoutable asset, allowing=
a reports user in one company to delete pending checkout acceptance record=
s for another company. This issue is fixed in version 8.6.2. 2026-07-10 5 C= VE-2026-55515 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55515 ] grokabi= lity--snipe-it Snipe-IT is an IT asset/license management system. Prior to = 8.6.2, UsersController::show() and printInventory() authorize only user vie= wing before loading and rendering assigned license, accessory, and consumab=
le relationships, allowing an authenticated user with only users.view to se=
e inventory and cost/order metadata from modules that direct permissions wo= uld otherwise deny. This issue is fixed in version 8.6.2. 2026-07-10 4.3 CV= E-2026-55462 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55462 ] grokabil= ity--snipe-it Snipe-IT is an IT asset/license management system. Prior to 8= .6.2, when Full Multiple Companies Support and scope_locations_fmcs are ena= bled, the API location creation endpoint detects an invalid parent-child co= mpany mismatch but does not return immediately, allowing creation of a chil=
d location under a parent location from a different company. This issue is = fixed in version 8.6.2. 2026-07-10 4.3 CVE-2026-55472 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-55472 ] gunthercox--ChatterBot ChatterBot is a mac= hine learning, conversational dialog engine for creating chat bots. Prior t=
o 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted outp=
ut directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create patter=
n followed by tar.extractall(path=3Dself.data_path), allowing a local attac= ker who pre-plants a symlink at the predictable path to cause archive conte= nts to be written through the symlink to an attacker-chosen directory. This=
issue is fixed in version 1.2.14. 2026-07-09 5.5 CVE-2026-58198 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-58198 ] guzzle--guzzle Guzzle is an ext= ensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookie=
s scoped to IP-address or bare-numeric Domain values to the exact host that=
set them, because SetCookie::matchesDomain() applied ordinary suffix match= ing to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie=
disclosure, cookie injection, or session fixation. This issue is fixed in = version 7.12.3. 2026-07-08 4.7 CVE-2026-59883 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-59883 ] guzzle--psr7 guzzlehttp/psr7 is a PSR-7 HTTP messa=
ge library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() d= oes not reject URI host components containing authority delimiters, embedde=
d ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree wi=
th the URI authority used for security or routing decisions. This issue is = fixed in version 2.12.3. 2026-07-08 4.2 CVE-2026-59882 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-59882 ] happyforms--Happyforms Form Builder for W= ordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms=
The Happyforms - Form Builder for WordPress: Drag & Drop Contact Forms, Su= rveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to = Local File Inclusion in all versions up to, and including, 1.26.12 via the = happyforms_get_form_partial() function. This makes it possible for authenti= cated attackers, with Administrator-level access and above, to include and = execute arbitrary .php files on the server, allowing the execution of any P=
HP code in those files. This can be used to bypass access controls, obtain = sensitive data, or achieve code execution in cases where .php file types ca=
n be uploaded and included. 2026-07-10 6.6 CVE-2025-11977 [
https://www.cve= .org/CVERecord?id=3DCVE-2025-11977 ] Harness--Harness A vulnerability was d= etermined in Harness up to 2.28.2. This vulnerability affects the function = getAuthorizedSpaces of the file app/api/controller/gitspace/list_all.go of = the component gitspaces Endpoint. Executing a manipulation can lead to auth= orization bypass. The attack can be executed remotely. The exploit has been=
publicly disclosed and may be utilized. The project was informed of the pr= oblem early through an issue report but has not responded yet. 2026-07-08 4=
.3 CVE-2026-15036 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15036 ] Has= hiCorp--Nomad HashiCorp Nomad and Nomad Enterprise are vulnerable to a cros= s-namespace authorization bypass in the dynamic host volumes feature that m=
ay allow an operator holding the host volume delete permission in one names= pace to delete a sticky volume claim belonging to a job in another namespac=
e. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition = 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14. 2026-07-08 4.2 CVE-2= 026-14896 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14896 ] HashiCorp--= Shared library HashiCorp memberlist before version 0.6.0 is vulnerable to a=
denial-of-service issue in its push/pull state handling that may allow an = attacker with network access to the gossip port to exhaust memory on a rece= iving node and cause the process to terminate. This vulnerability (CVE-2026= -14362) is fixed in memberlist 0.6.0. 2026-07-08 4.9 CVE-2026-14362 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-14362 ] HashiCorp--Tooling The consu= l-template library before version 0.42.1 is vulnerable to a path redirectio=
n issue in the writeToFile template helper that may allow template output t=
o be written outside the intended directory or to overwrite an existing fil=
e. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1. = 2026-07-08 4.7 CVE-2026-14361 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -14361 ] HCLSoftware--HCL DevOps Deploy HCL DevOps Deploy uses Cross-Origin=
Resource Sharing (CORS) which could allow an attacker to carry out privile= ged actions and retrieve sensitive information as the domain name is not be= ing limited to only trusted domains. 2026-07-09 5.4 CVE-2026-56458 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-56458 ] HCLSoftware--HCL DevOps Deplo=
y / HCL Launch HCL DevOps Deploy / HCL Launch is susceptible to sensitive i= nformation disclosure. =C2=A0The application stores potentially sensitive i= nformation in log files that could be read by a local user. 2026-07-09 6.2 = CVE-2026-56459 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56459 ] HCLSof= tware--HCL DevOps Deploy / HCL Launch HCL DevOps Deploy / HCL Launch could = disclose sensitive configurations and secrets to authenticated users in API=
responses that could be used in further attacks against the system. 2026-0= 7-09 6.5 CVE-2026-56460 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56460=
] Helicone--ai-gateway A flaw has been found in Helicone ai-gateway up to = 0.2.0-beta.30. This affects the function build_target_url of the file ai-ga= teway/src/dispatcher/service.rs of the component AWS Metadata Service. Exec= uting a manipulation of the argument extracted_path_and_query can lead to s= erver-side request forgery. The attack can be executed remotely. The exploi=
t has been published and may be used. The vendor was contacted early about = this disclosure but did not respond in any way. 2026-07-12 6.3 CVE-2026-155=
08 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15508 ] hestiacp--hestiacp=
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability=
that allows authenticated low-privilege users to inject arbitrary HTML by = creating a DNS record with a double-quote followed by a script payload in t=
he value field. The application fails to apply htmlspecialchars() encoding =
to the DNS record value field rendered into the data-sort-value HTML attrib= ute in list_dns_rec.php, allowing the payload to execute in the browser of = any user who views the DNS record list, including administrators. 2026-07-1=
0 4.6 CVE-2025-30008 [
https://www.cve.org/CVERecord?id=3DCVE-2025-30008 ] = Hewlett Packard Enterprise (HPE)--HPE Networking Instant On An unauthentica= ted remote disclosure vulnerability has been identified in HPE Networking I= nstant On 1830, 1930, and 1960 Switches. Successful exploitation of this vu= lnerability could allow an unauthenticated remote threat actor to access se= nsitive cryptographic secrets on a vulnerable system. 2026-07-07 6.5 CVE-20= 26-44877 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44877 ] Hono--Hono H= ono before 4.12.7 allows __proto__ key in parseBody with dot option enabled=
, permitting specially crafted form field names to create objects with __pr= oto__ properties. When parsed results are merged into regular JavaScript ob= jects using unsafe merge patterns, attackers can exploit this to achieve pr= ototype pollution and modify object behavior. 2026-07-11 4.8 CVE-2026-56763=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-56763 ] honojs--hono Hono is=
a Web application framework that provides support for any JavaScript runti= me. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from p= lain strings but marks the result as already escaped without HTML-escaping = the input, allowing untrusted className values used in a JSX class attribut=
e during server-side rendering to break out of the attribute and inject arb= itrary markup. This issue is fixed in version 4.12.27. 2026-07-08 6.1 CVE-2= 026-59895 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59895 ] honojs--hon=
o Hono is a Web application framework that provides support for any JavaScr= ipt runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context v= alues per request during server-side rendering, allowing createContext, use= Context, jsxRenderer, or useRequestContext data from a different in-flight = request to be used after an await in an async component. This issue is fixe=
d in version 4.12.27. 2026-07-08 6.5 CVE-2026-59896 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-59896 ] honojs--hono Hono is a Web application frame= work that provides support for any JavaScript runtime. From 4.3.3 before 4.= 12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request = header value because it de-duplicates values using a substring comparison i= nstead of an exact match, so middleware or application logic that depends o=
n the complete X-Forwarded-For chain, rate limiting, audit logging, or prox= y-chain validation can receive incomplete data. This issue is fixed in vers= ion 4.12.27. 2026-07-08 4.8 CVE-2026-59897 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-59897 ] IceHRM--IceHRM A flaw has been found in IceHRM up to = 35.0.1. This impacts an unknown function of the file core/src/Reports/User/= Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. = Executing a manipulation of the argument employeeList can lead to sql injec= tion. The attack can be launched remotely. The exploit has been published a=
nd may be used. The project was informed of the problem early through an is= sue report but has not responded yet. 2026-07-12 6.3 CVE-2026-15478 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-15478 ] idocoh--Sympl Repeater for A=
CF and Elementor The Sympl Repeater for ACF and Elementor plugin for WordPr= ess is vulnerable to Stored Cross-Site Scripting via ACF repeater field val= ues in all versions up to, and including, 2.3. This is due to insufficient = input sanitization and output escaping in the symp_arfe_replace_content() f= unction, which uses str_replace() to substitute raw ACF field values (retri= eved via get_field()) directly into Elementor-rendered HTML without any esc= aping. This makes it possible for authenticated attackers, with Author-leve=
l access and above, to inject arbitrary web scripts in pages that will exec= ute whenever a user accesses an injected page. 2026-07-08 6.4 CVE-2026-1057=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10570 ] igweze--wizgrade A = security vulnerability has been detected in igweze wizgrade up to b1d55f22b= 90cd7e7a6e5002f006d7c649e8086d6. This vulnerability affects unknown code of=
the file dashboard/studentConductManager.php. Such manipulation leads to c= ross site scripting. The attack may be performed from remote. The exploit h=
as been disclosed publicly and may be used. This product utilizes a rolling=
release system for continuous delivery, and as such, version information f=
or affected or updated releases is not disclosed. The vendor was contacted = early about this disclosure but did not respond in any way. 2026-07-12 4.3 = CVE-2026-15492 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15492 ] imhamz= aazam--ecommerceFlask A weakness has been identified in imhamzaazam ecommer= ceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected elemen=
t is an unknown function. This manipulation causes cross-site request forge= ry. The attack may be initiated remotely. The exploit has been made availab=
le to the public and could be used for attacks. This product uses a rolling=
release model to deliver continuous updates. As a result, specific version=
information for affected or updated releases is not available. The project=
was informed of the problem early through an issue report but has not resp= onded yet. 2026-07-06 4.3 CVE-2026-14800 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-14800 ] Inrove Software and Internet Services--BiEticaret Impro= per neutralization of input during web page generation ('cross-site scripti= ng') vulnerability in Inrove Software and Internet Services BiEticaret allo=
ws Reflected XSS. This issue affects BiEticaret: before v3.3.57. 2026-07-09=
6.1 CVE-2026-5793 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5793 ] iqo= nicdesign--KiviCare Clinic & Patient Management System (EHR) The KiviCare -=
Clinic & Patient Management System (EHR) plugin for WordPress is vulnerabl=
e to generic SQL Injection via the 'orderby' parameter in all versions up t=
o, and including, 4.5.0 due to insufficient escaping on the user supplied p= arameter and lack of sufficient preparation on the existing SQL query. This=
makes it possible for authenticated attackers, with doctor-level access an=
d above, to append additional SQL queries into already existing queries tha=
t can be used to extract sensitive information from the database. This requ= ires that the attacker hold at minimum a KiviCare Doctor-level account, or =
a Receptionist or Clinic Admin role that grants the doctor_session_list cap= ability. 2026-07-11 6.5 CVE-2026-15072 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15072 ] iqonicdesign--KiviCare Clinic & Patient Management Syst=
em (EHR) The KiviCare - Clinic & Patient Management System (EHR) plugin for=
WordPress is vulnerable to generic SQL Injection via the 'orderby' paramet=
er in all versions up to, and including, 4.5.0 due to insufficient escaping=
on the user supplied parameter and lack of sufficient preparation on the e= xisting SQL query. This makes it possible for authenticated attackers, with=
Doctor-level access and above, to append additional SQL queries into alrea=
dy existing queries that can be used to extract sensitive information from = the database. Exploitation requires a KiviCare Doctor, Receptionist, or Cli= nic Admin role at minimum, as the vulnerable REST endpoint is restricted to=
authenticated users with custom plugin-level access. 2026-07-11 6.5 CVE-20= 26-15073 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15073 ] iqonicdesign= --KiviCare Clinic & Patient Management System (EHR) The KiviCare - Clinic &=
Patient Management System (EHR) plugin for WordPress is vulnerable to auth= orization bypass in all versions up to, and including, 4.4.0. This is due t=
o the plugin not properly verifying that a user is authorized to perform an=
action. This makes it possible for unauthenticated attackers to mark arbit= rary pending appointments as Confirmed and forge an associated completed pa= yment record in wp_kc_payments_appointment_mappings using an attacker-suppl= ied payment ID, bypassing payment entirely. This exploit is achievable on a=
default installation because the gateway resolution logic returns all regi= stered gateways regardless of admin-enabled status, making the manual (KCPa= yLater) gateway always selectable. 2026-07-10 5.3 CVE-2026-11990 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-11990 ] isaacs--node-tar node-tar is a = tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coe= rces all-digit PAX path and linkpath values in src/pax.ts to JavaScript num= bers, causing downstream path handling such as normalizeWindowsPath(entry.p= ath).split('/') to throw an uncaught TypeError. This issue is fixed in vers= ion 7.5.18. 2026-07-08 5.3 CVE-2026-59871 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-59871 ] isaacs--node-tar node-tar is a tar archive manipulatio=
n library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes f= rom PAX path and linkpath records in src/pax.ts, allowing a crafted archive=
with values to reach fs.lstat or fs.open and terminate the process with an=
uncaught exception. This issue is fixed in version 7.5.17. 2026-07-08 5.3 = CVE-2026-59875 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59875 ] iscpco= lissimo--Colissimo shipping methods for WooCommerce The Colissimo Officiel =
: M=C3=83=C2=A9thodes de livraison pour WooCommerce plugin for WordPress is=
vulnerable to unauthorized modification of data due to a missing capabilit=
y check on the updateShippingMethod() function (registered to the wp_ajax_l= pc_order_affect AJAX action) in versions up to, and including, 2.9.0. This =
is due to the handler performing no current_user_can() capability check and=
no nonce verification before reading an attacker-supplied order_id and mod= ifying that order's shipping method, pickup-point meta, and shipping addres=
s. This makes it possible for authenticated attackers, with Subscriber-leve=
l access and above, to create or modify the shipment information (shipping = method, pickup relay data, and shipping address) of arbitrary WooCommerce o= rders, including orders placed by other users. 2026-07-09 4.3 CVE-2026-9240=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-9240 ] ivole--Customer Revie=
ws for WooCommerce The Customer Reviews for WooCommerce plugin for WordPres=
s is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attrib= ute in all versions up to, and including, 5.113.0 due to insufficient input=
sanitization and output escaping. This makes it possible for authenticated=
attackers, with contributor-level access and above, to inject arbitrary we=
b scripts in pages that will execute whenever a user accesses an injected p= age. 2026-07-09 6.4 CVE-2026-13771 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-13771 ] jegtheme--Jeg Kit for Elementor Powerful Addons for Elementor=
, Widgets & Templates for WordPress The Jeg Kit for Elementor - Powerful Ad= dons for Elementor, Widgets & Templates for WordPress plugin for WordPress =
is vulnerable to Stored Cross-Site Scripting via the Image Box widget's 'sg= _body_description' parameter in versions up to, and including, 3.2.6. This =
is due to insufficient input sanitization and output escaping on the descri= ption attribute in the render_body() method of the Image_Box_View class - e= very other attribute used by the method is wrapped in esc_attr(), but the d= escription value is concatenated directly into HTML body context. This make=
s it possible for authenticated attackers, with Contributor-level access an=
d above, to inject arbitrary web scripts in pages that will execute wheneve=
r a user accesses an injected page. 2026-07-10 6.4 CVE-2026-13710 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-13710 ] Juniper Networks--Junos OS An = Unchecked Input for Loop Condition vulnerability in the Packet Forwarding E= ngine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthentic= ated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD sessio=
n flaps generate respective up/down events which are queued by PFEMAN for p= rocessing. Especially in a Virtual-Chassis (VC) scenario with=C2=A0locality= -bias configured,=C2=A0processing takes a significant amount of time for ea=
ch event.=C2=A0If these sessions keep flapping, new events are constantly a= dded, and in turn PFEMAN never completes processing these events. This resu= lts in the PFEMAN watchdog timer expiring, which causes the FPC to crash an=
d restart, representing a complete service outage. This issue only affects =
MX series FPCs up to and including MPC9. It does not affect MPC10/11, LC480= 0/9600 and MX304. This issue affects Junos OS on MX Series: * all versions = before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before = 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R2.=
2026-07-09 6.5 CVE-2026-33800 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-33800 ] Juniper Networks--Junos OS An Improper Check for Unusual or Excep= tional Conditions vulnerability in the routing protocol daemon (RPD) of Jun= iper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthentic= ated attacker sending a specific BGP update over an established BGP session=
to cause a Denial-of-Service (DoS). Upon receipt of a specifically malform=
ed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered=
, which will cause a complete service outage until routing has reconverged.=
The rpd crash occurs before the update can be readvertised, so there is no=
downstream propagation. This issue affects: * Junos OS versions 25.2 befor=
e 25.2R2; * Junos OS Evolved versions 25.2 before 25.2R2-EVO. This issue do= esn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions = before 25.2R1-EVO. 2026-07-09 6.5 CVE-2026-33801 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-33801 ] Juniper Networks--Junos OS An Improper Validati=
on of Specified Quantity in Input vulnerability in the Packet Forwarding En= gine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthentica= ted, adjacent attacker to cause a Denial-of-Service (DoS). When a specific = packet is received from device in the same broadcast domain, an affected sy= stem calculates the packet size incorrectly. This causes further packet pro= cessing to fail, which triggers an FPC major error, resulting in a FPC rese=
t impacting traffic until the FPC has automatically recovered. Affected sce= narios are: MAP-T, or non-IP traffic encapsulated in IP (e.g. MPLS over GRE=
). When this issue happens the following logs can be observed: fpc<#> CMErr= or: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_= OVF (0x2205eb), scope: pfe, category: functional, severity: major, module: = MQSS(0), type: LI: Unroll TAIL length overflow, oc_category: default fpc<#>=
Performing action reset-fru for error /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CME= RROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb) in module: MQSS(0) with s= cope: pfe category: functional level: major, oc_category: default This issu=
e affects Junos OS on MX Series: * all versions before 23.2R2-S6, * 23.4 ve= rsions before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions = before 24.4R2-S4, * 25.2 versions before 25.2R2. 2026-07-09 6.5 CVE-2026-57= 019 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57019 ] Juniper Networks-= -Junos OS An Improper Check for Unusual or Exceptional Conditions vulnerabi= lity in the packet forwarding engine (pfe) of Juniper Networks Junos OS on = QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Den= ial-of-Service (DoS). On all QFX10000 platforms in an EVPN-VxLAN scenario, =
if an attacker sends IPv6 multicast traffic and these packets reach the non= -IRB interface of a spine switch it floods the packet to other spines and a=
ll Ethernet Segment Identifier (ESI)=C2=A0leaf switches. This flooding caus=
es the packet to be forwarded in a endless loop, which can lead to saturati=
on of the involved links and in turn impact to legitimate traffic. This iss=
ue affects Junos OS on QFX10000 Series: * all versions before 23.2R2-S7, * = 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 ve= rsions before 24.4R2-S4. This issue does not affect Junos version after 24.=
4 as the QFX10000 Series devices are not supported on newer versions anymor=
e. 2026-07-09 6.5 CVE-2026-57020 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-57020 ] Juniper Networks--Junos OS A Missing Release of Memory after Ef= fective Lifetime vulnerability in the packet forwarding engine (pfe) of Jun= iper Networks Junos OS on specific EX Series devices allows an unauthentica= ted adjacent attacker to cause a Denial-of-Service (DoS).When sFlow is conf= igured in a Virtual Chassis (VC) scenario with EX4100 Series or EX4400 Seri=
es devices, multicast traffic which is received on one VC member and sent o=
ut on another member leads to a memory leak and ultimately an FPC crash and=
restart. The leak can be monitored by watching the continuous increase of = the buffer values in the output of: user@host> show chassis fpc This issue = affects Junos OS on=C2=A0EX4100 Series and EX4400: * all versions before 23= .2R2-S7, * 23.4 versions before 23.4R2-S7, * 24.2 versions before 24.2R2-S4=
, * 24.4 versions before 24.4R2. 2026-07-09 6.5 CVE-2026-57027 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-57027 ] Juniper Networks--Junos OS An Imp= roper Handling of Undefined Parameters vulnerability in the packet forwardi=
ng engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an=
authenticated attacker with low privileges to cause a Denial-of-Service (D= oS). If an attempt is made to subscribe to an unsupported telemetry sensor = path on EX2300,=C2=A0EX3400,=C2=A0EX4000, EX4100 and EX4400 via gRPC, this = causes the FPC to crash. This leads to a complete service outage until the = module has automatically restarted.=C2=A0 The following log message can be = seen when this issue happens: agentd[<PID>]: AGENTD_RESOURCE_NOT_FOUND: No = resource name found for <sensor> This issue affects Junos OS on EX2300, EX3= 400, EX4000, EX4100 and EX4400 devices: * all versions before 23.2R2-S7, * = 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 ve= rsions before 24.4R2. 2026-07-09 6.5 CVE-2026-57032 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-57032 ] Juniper Networks--Junos OS A Missing Authori= zation vulnerability in the CLI of Juniper Networks Junos OS on EX Series a= llows a local, authenticated attacker to cause a Denial-of-Service (DoS). O=
n EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an = authenticated, local attacker with no specific permissions or class can exe= cute a specific, privileged CLI 'request' command which will cause complete=
traffic impact until the system automatically recovers. This issue affects=
Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400: *=
23.2R2 versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S8, * 24.2=
versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versio=
ns before 25.2R2, * 25.4 versions before 25.4R1-S1. 2026-07-09 5.5 CVE-2026= -33802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-33802 ] Juniper Networ= ks--Junos OS An Out-of-bounds Write vulnerability in the http-gatekeeper (h= ttp-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticate=
d, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Ser= ies device is configured for remote-access VPN with pre-logon compliance ch= eck, a network-based attacker sending specifically formatted requests can t= rigger an out of bounds write leading to an http-gk process crash. This cra=
sh leads to unavailability of all services depending on the [ system servic=
es web-management ] configuration (like J-Web, remote access VPN and firewa=
ll authentication) until the process automatically restarts. This issue aff= ects=C2=A0Junos OS on SRX Series: * 23.2 versions before 23.2R2-S7, * 23.4 = versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 version=
s before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 2= 5.4R1-S1, 25.4R2. 2026-07-09 5.3 CVE-2026-57021 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-57021 ] Juniper Networks--Junos OS An Improper Check for=
Unusual or Exceptional Conditions vulnerability in the Packet Forwarding E= ngine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series all= ows an unauthenticated, network-based attacker to cause a Denial-of-Service=
(DoS). When an affected device initiates a TCP connection to an attacker-c= ontrolled system that responds with a specific packet, this causes a PFE cr= ash and restart, which affects all services until the system has automatica= lly recovered. This issue can happen among others in the following scenario=
s: ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, URL filtering. T= his issue affects Junos OS on MX Series with SPC3, SRX5k Series with=C2=A0S= PC3, SRX1600 Series, SRX2300 Series, SRX4000 Series, and vSRX Series: * all=
versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S5, * 24.2 versio=
ns before 24.2R2. 2026-07-09 5.9 CVE-2026-57022 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-57022 ] Juniper Networks--Junos OS A Use of Multiple Res= ources with Duplicate Identifier vulnerability in the IKE daemon (iked) of = Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthen= ticated, network-based attacker to cause a Denial-of-Service (DoS). On an M=
X with SPC3 and SRX devices configured for VPN service, when a large number=
of VPN negotiations fail=C2=A0a peer index rollover will eventually occur.=
As a result, new peers are assigned index values that are already in use a=
nd the iked process starts to crash repeatedly. This results in failure to = establish new VPN connections and rekeying existing ones. To restore servic=
e the system must be rebooted. Please note that the index value can't be mo= nitored, so customers should monitor tunnel up and down events and if a lot=
of events occur over an extended period of time it becomes likely that thi=
s issue occurs. To be exposed to this issue the system needs to run iked (v=
s. kmd which is not affected), which can be verified with: user@host> show = system processes extensive | match "KMD|IKED" This issue affects Junos OS o=
n MX with SPC3, SRX Series: * all versions before 23.2R2-S7, * 23.4 version=
s before 23.4R2-S6, * 24.2 versions before 24.2R2-S3, * 24.4 versions befor=
e 24.4R2-S4, * 25.2 versions before 25.2R1-S1. 2026-07-09 5.3 CVE-2026-5702=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57024 ] Juniper Networks--J= unos OS A Return of Pointer Value Outside of Expected Range vulnerability i=
n the fileio library of Juniper Networks Junos OS and Junos OS Evolved allo=
ws a local, low-privilged attacker to cause a Denial-of-Service (DoS). On E=
X Series, QFX Series and MX Series a=C2=A0low-privileged attacker issuing a=
specific 'show l2-learning' command will cause an l2ald crash which will l= ead to a temporary service impact for all layer 2 services until the proces=
s has automatically restarted. This issue affects EX Series, QFX Series, MX=
Series: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before = 23.4R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2.=
Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions bef= ore 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions befor=
e 24.4R1-S3-EVO. 2026-07-09 5.5 CVE-2026-57025 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-57025 ] Juniper Networks--Junos OS A Concurrent Execution=
using Shared Resource with Improper Synchronization ('Race Condition') vul= nerability in the packet forwarding engine (PFE) of Juniper Networks Junos =
OS on SRX Series allows an unauthenticated, network-based attacker to cause=
a Denial-of-Service (DoS). As part of the stateful traffic processing on S=
RX Series devices flows are being established, and removed when not needed = anymore. During the removal process the timeout of a flow should be set to =
3 seconds and consequentially the flow should be removed shortly after. Due=
to a race condition occurring when setting the timeout there is a chance (= the exact conditions are outside the attackers control) that the timeout is=
instead set to a very high value of larger than 10,000 seconds: user@host>=
show security flow session | match timeout Session ID: 98784248524, Policy=
name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid = This will lead to an accumulation of flows which can be observed by an ever= -increasing value of invalidated sessions in the output of 'show security f= low session summary': user@host> show security flow session summary | match=
invalid Invalidated sessions: 216931These sessions can't be cleared manual=
ly with the 'clear security flow session' command, which will either lead t=
o forwarding to stop (and the system needs to be manually recovered with a = reboot) or to a flowd core and automatic reboot. This issue affects Junos O=
S on SRX Series: * 24.2 versions before 24.2R2-S3, * 24.4 versions before 2= 4.4R2-S1, 24.4R2-S2, * 25.2=C2=A0versions=C2=A0before 25.2R1-S2, 25.2R2. Th=
is issue does not affect releases earlier than 24.2R1; 2026-07-09 5.9 CVE-2= 026-57030 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57030 ] Juniper Net= works--Junos OS A Use of Incorrectly-Resolved Name or Reference vulnerabili=
ty in the URL filtering plugin of Juniper Networks Junos OS on MX Series al= lows an unauthenticated, network-based attacker to bypass web filtering and=
access downstream resources that should be unreachable. If an MX Series de= vice is configured with web filtering, and an attacker sends a request with=
a specifically formatted URL, this request will get forwarded despite the = system being configured to block it. In turn, an attacker can access downst= ream resources that are expected to be unreachable. This issue affects=C2= =A0Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions = before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before = 24.4R2-S4, * 25.2 versions before 25.2R2-S1, * 25.4 versions before 25.4R1-= S2, 25.4R2. 2026-07-09 5.8 CVE-2026-57054 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-57054 ] Juniper Networks--Junos OS A NULL Pointer Dereference = vulnerability in the management daemon (mgd) of Juniper Networks Junos OS a=
nd Junos OS Evolved allows a local, high-privileged attacker setting or dea= ctivating a=C2=A0specific SSH configuration parameter to create a Denial of=
Service (DoS). A local high-privileged user configuring or deactivating a = specific 'system services ssh' configuration parameter=C2=A0can exploit a n= ull pointer dereference in one of the functions used by SSH. The function a= ttempts to dereference a null pointer when accessing certain configuration = data, resulting in an mgd process crash and restart.=C2=A0Continued executi=
on of these configuration commands will create a sustained Denial of Servic=
e (DoS) condition. This issue affects: Junos OS: * from 22.3 before 22.3R3-= S5; * from 22.4 before 22.4R3-S10; * from 23.2 before 23.2R2-S7; * from 23.=
4 before 23.4R2-S8. This issue does not affect Junos OS before 22.3R1. Juno=
s OS Evolved: * from 22.3R1-EVO before 23.2R2-S7-EVO; * from 23.4 before 23= .4R2-S8-EVO. This issue does not affect Junos OS Evolved before 22.3R1-EVO.=
2026-07-09 4.4 CVE-2026-21901 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-21901 ] Juniper Networks--Junos OS An Out-of-bounds Write vulnerability i=
n the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved=
allows an authenticated network-based attacker sending specific valid SNMP=
v3 queries to trigger a memory leak. Over time, continuous receipt of these=
queries will result in snmpd process memory exhaustion, resulting in a pro= cess crash and restart, impacting the ability to monitor the system via SNM=
P. Memory usage can be monitored using the following command: user@device> = show system processes extensive | match snmpd This issue affects: Junos OS:=
* all versions before 21.2R3-S8; * from 21.4 before 21.4R3-S7; * from 22.1=
before 22.1R3-S6; * from 22.2 before 22.2R3-S4; * from 22.3 before 22.3R3-= S3; * from 22.4 before 22.4R3-S2; * from 23.2 before 23.2R2; * from 23.4 be= fore 23.4R2. Junos OS Evolved: * all versions before 21.2R3-S8-EVO; * from = 21.4 before 21.4R3-S7-EVO; * all versions of 22.1-EVO, * from 22.2 before 2= 2.2R3-S4-EVO; * from 22.3 before 22.3R3-S3-EVO; * all versions of 22.4-EVO,=
* from 23.2 before 23.2R2-EVO; * from 23.4 before 23.4R2-EVO. 2026-07-09 4=
.3 CVE-2026-33799 [
https://www.cve.org/CVERecord?id=3DCVE-2026-33799 ] Jun= iper Networks--Junos OS An Improper Check for Unusual or Exceptional Condit= ions vulnerability in the packet forwarding engine (PFE) of Juniper Network=
s Junos OS on MX Series allows adjacent subscribers to bypass configured fi= rewall filters. On MX Series devices with=C2=A0MPC10/11, LC4800/9600, and M= X304 with=C2=A0subscribers configured on static interfaces, ingress firewal=
l filters are not enforced, so that neither protocol level nor upstream ban= dwidth limitation are in effect.=C2=A0 This issue affects Junos OS on MX wi= th=C2=A0MPC10/11, LC4800/9600/4802, and MX304: * 23.2 versions from 23.2R2-=
S1 before 23.2R2-S7, * 23.4 versions from 23.4R2 before 23.4R2-S7, * 24.2 v= ersions before 24.2R2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions=
before 25.2R2. 2026-07-09 4.7 CVE-2026-57031 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-57031 ] Juniper Networks--Junos OS Evolved An Improper Res= triction of Communication Channel to Intended Endpoints vulnerability in Ju= niper Networks Junos OS Evolved allows an unauthenticated, network-based at= tacker to cause a limited information disclosure and availability impact to=
the device. Due to a wrong initialization, a process which should only be = able to communicate internally within the device can be reached over the ne= twork via an open port. This leads to a device being inadvertently exposed = and increased CPU cycles spent processing ingress packets. This issue affec=
ts Junos OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions b= efore 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions = before 24.4R2-S4-EVO, * 25.2 versions before 25.2R2-S1-EVO, * 25.4 versions=
before 25.4R1-S2-EVO. 2026-07-09 6.5 CVE-2026-33803 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-33803 ] Juniper Networks--Junos OS Evolved An Impro= per Check for Unusual or Exceptional Conditions vulnerability in the advanc=
ed forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on=
PTX Series allows an unauthenticated network-based attacker generating con= tinuous routing updates, resulting in unilist ECMP routes, to crash the evo= -aftmand process on the PFE, leading to a Denial-of-Service (DoS). The cond= itions required for successful exploitation are=C2=A0based on a sequence of=
events that are outside an attacker's direct control. Unified list (unilis=
t) ECMP routes are a specific ECMP behavior where multiple equal-cost route=
s share a single logical next-hop list entry. The router treats them as one=
route with multiple next hops and load balances traffic across that unifie=
d list. Due to an issue processing unilist ECMP routing updates, internal s= tate corruption may occur, especially in large-scale ECMP unilist deploymen= ts, leading to the evo-aftmand process crashing, resulting in an evo-aftman= d-bx core. Manual intervention is required to recover by rebooting the syst=
em or=C2=A0restarting the FPC. This issue affects Junos OS Evolved on PTX :=
* from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.2R2-EVO. 202= 6-07-09 5.9 CVE-2026-33794 [
https://www.cve.org/CVERecord?id=3DCVE-2026-33= 794 ] Juniper Networks--Junos OS Evolved A=C2=A0Missing Synchronization vul= nerability in the flow collector handler of Juniper Networks Junos OS Evolv=
ed on QFX Series allows an adjacent, unauthenticated attacker to cause a De= nial-of-Service (DoS). When the reachability of an sFlow collector changes,=
the corresponding next-hop entry is updated.=C2=A0If this update occurs si= multaneously with the sFlow thread accessing the next-hop data (which is ou= tside the attackers control), it causes the evo-pfemand process to crash, i= mpacting all traffic forwarding until the automatic process restart has com= pleted. This issue affects Junos OS Evolved on QFX Series: * all 23.2 versi= ons,=C2=A0 * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.= 2R2-S5-EVO, * 24.4 versions before 24.4R2-S3-EVO, * 25.2 versions before 25= .2R2-EVO. 2026-07-09 5.3 CVE-2026-57029 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-57029 ] kingaddons--King Addons for Elementor 80+ Elementor Wid= gets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder The=
King Addons for Elementor plugin for WordPress is vulnerable to Stored Cro= ss-Site Scripting via the 'form_page_id' parameter in versions up to, and i= ncluding, 51.1.62 This is due to insufficient input sanitization in the add= _to_submissions() function, which applies sanitize_text_field() (which pres= erves double-quote characters) before storing the value in post meta, combi= ned with missing output escaping in the king_addons_submissions_custom_colu= mn_content() function, which concatenates the stored value into an HTML hre=
f attribute via admin_url() without wrapping the result in esc_url(). This = makes it possible for authenticated attackers, with subscriber-level access=
and above, to inject arbitrary web scripts in pages that will execute when= ever a user accesses an injected page. 2026-07-10 6.4 CVE-2026-15284 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-15284 ] kitae-park--Mang Board WP T=
he Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site=
Scripting via the 'stag' parameter in all versions up to, and including, 2= .3.4 due to insufficient input sanitization and output escaping. This makes=
it possible for unauthenticated attackers to inject arbitrary web scripts =
in pages that execute if they can successfully trick a user into performing=
an action such as clicking on a link. 2026-07-09 6.1 CVE-2026-13334 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-13334 ] labring--FastGPT FastGPT is=
an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-b= eta4, FastGPT allows an authenticated tenant user to call POST /api/core/da= taset/collection/create/reTrainingCollection in a way that persists a serve= r-owned datasetId value from another tenant. This creates mixed dataset obj= ects and downstream dataset, collection, and training endpoints then make a= uthorization decisions from inconsistent ownership anchors, allowing cross-= tenant read, update, and delete access when mixed object ids are known. Thi=
s issue is fixed in version 4.15.0-beta4. 2026-07-07 6.3 CVE-2026-54601 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-54601 ] langchain-ai--langsmith-= sdk LangSmith Client SDKs provide SDK's for interacting with the LangSmith = platform. Prior to 0.8.18, an attacker who can send an HTTP request to a se= rver running the LangSmith SDK's TracingMiddleware can cause that server to=
read an arbitrary file from its local filesystem and upload the contents t=
o LangSmith as a trace attachment. Depending on how the distributed trace s= ystem is deployed, triggering a read may not require authentication. Retrie= ving the contents requires read access to the LangSmith workspace the trace=
s are sent to. The net effect is a trust-boundary crossing: a party with wo= rkspace trace-read access (for example a low-privilege workspace member, a = contractor, or a compromised teammate account) gains the ability to read fi= les from any server running TracingMiddleware, a capability outside that wo= rkspace's intended trust boundary. This vulnerability is fixed in 0.8.18. 2= 026-07-06 5 CVE-2026-59152 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59= 152 ] Leantime--Leantime A vulnerability has been found in Leantime up to 3= .8.0. This impacts the function editUser/addUser of the component JSON-RPC = Endpoint. The manipulation of the argument role leads to improper authoriza= tion. The attack is possible to be carried out remotely. The exploit has be=
en disclosed to the public and may be used. The vendor was contacted early = about this disclosure but did not respond in any way. 2026-07-12 6.3 CVE-20= 26-15509 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15509 ] Leantime--Le= antime A vulnerability was found in Leantime up to 3.8.0. Affected is the f= unction Setting::saveSetting of the component API. The manipulation results=
in improper authorization. The attack may be performed from remote. The ex= ploit has been made public and could be used. The vendor was contacted earl=
y about this disclosure but did not respond in any way. 2026-07-12 6.3 CVE-= 2026-15510 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15510 ] leap13--Pr= emium Addons for Elementor Powerful Elementor Templates & Widgets The Premi=
um Addons for Elementor - Powerful Elementor Templates & Widgets plugin for=
WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_to= oltip_text' parameter in all versions up to, and including, 4.11.84 due to = insufficient input sanitization and output escaping. This makes it possible=
for authenticated attackers, with contributor-level access and above, to i= nject arbitrary web scripts in pages that will execute whenever a user acce= sses an injected page. The injected payload is specifically triggered when =
an administrator or higher-privileged user opens the affected post in the E= lementor editor, as the raw unescaped output occurs via the print_template(=
) method registered on the 'elementor/section/print_template' hook rather t= han on the public-facing frontend. 2026-07-11 4.9 CVE-2026-12141 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-12141 ] lepture--mistune Mistune is a P= ython Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRende= rer.safe_url() does not block percent-encoded javascript URIs, allowing att= acker-supplied Markdown links or images to bypass URL protections and execu=
te script in rendered HTML. This issue is fixed in version 3.3.0. 2026-07-0=
8 6.1 CVE-2026-59923 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59923 ] = lepture--mistune Mistune is a Python Markdown parser with renderers and plu= gins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py = blocks only javascript:, vbscript:, file:, and data: schemes, allowing lega=
cy or chained schemes such as feed:, view-source:, jar:, livescript:, mocha=
:, ms-its:, mk:, and res: to reach rendered href and src attributes and pot= entially execute script in affected user agents. This issue is fixed in ver= sion 3.3.0. 2026-07-08 6.1 CVE-2026-59929 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-59929 ] lepture--mistune Mistune is a Python Markdown parser w= ith renderers and plugins. Prior to 3.3.0, Include.parse() joins and normal= izes user-supplied include paths without verifying that the result remains = within the intended markdown directory, allowing crafted include paths to a= ccess files outside that directory when markdown files are processed using = md.read(). This issue is fixed in version 3.3.0. 2026-07-08 5.9 CVE-2026-59= 924 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59924 ] lepture--mistune = Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.= 3.0, the Include directive in src/mistune/directives/include.py detects onl=
y direct self-includes and not indirect cycles, allowing two markdown files=
that include each other to trigger unbounded recursion, raise RecursionErr= or, and crash the rendering request. This issue is fixed in version 3.3.0. = 2026-07-08 5.3 CVE-2026-59927 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -59927 ] lepture--mistune Mistune is a Python Markdown parser with renderer=
s and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive=
generate heading IDs as predictable toc_N values without slugifying the he= ading text, allowing attacker-controlled id=3D"toc_N" content to collide wi=
th generated anchors and redirect same-page navigation, CSS selectors, or J= avaScript handlers. This issue is fixed in version 3.3.0. 2026-07-08 4.3 CV= E-2026-59930 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59930 ] Limatek = System Inc.--LimRAD NAC Improper neutralization of input during web page ge= neration ('cross-site scripting') vulnerability in Limatek System Inc. LimR=
AD NAC allows Stored XSS. This issue affects LimRAD NAC: through 08072026.= =C2=A0NOTE: The vendor was contacted early about this disclosure but did no=
t respond in any way. 2026-07-08 4.8 CVE-2026-6371 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-6371 ] logichunt--Logo Slider WP Responsive Logo Caro= usel, Logo Gallery & Logo Showcase The Logo Slider - Logo Carousel, Client = Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerab=
le to Stored Cross-Site Scripting via the 'lgx_tooltip_position' parameter =
in all versions up to, and including, 5.5 due to insufficient input sanitiz= ation and output escaping. This makes it possible for authenticated attacke= rs, with contributor-level access and above, to inject arbitrary web script=
s in pages that will execute whenever a user accesses an injected page. 202= 6-07-10 6.4 CVE-2026-13247 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13= 247 ] logto-io--logto Logto is the modern, open-source auth infrastructure = for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SAML Relay= State, SAMLResponse, and actionUrl into a Logto-origin auto-submit HTML for=
m in packages/core/src/saml-application/SamlApplication/utils.ts without HT= ML-attribute escaping. A SAML application flow with a crafted RelayState fr=
om GET or POST /api/saml/:id/authn could inject script that runs on the Log=
to tenant origin after the user completes login. This issue is fixed in ver= sion 1.41.0. 2026-07-10 6.1 CVE-2026-54714 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-54714 ] logto-io--logto Logto is the modern, open-source auth=
infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOT=
P verification accepted a successfully used TOTP code again while the code = remained inside the RFC 6238 acceptance window because the verifier used ot= plib's stateless check with window =3D 1 and did not persist or compare the=
accepted TOTP time-step counter. An attacker who has the victim's first fa= ctor and captures a live TOTP value can replay that value to satisfy MFA du= ring the same acceptance window. This issue is fixed in version 1.41.0. 202= 6-07-10 6.4 CVE-2026-55370 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55= 370 ] looswebstudio--Highlighting Code Block The Highlighting Code Block pl= ugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s= ettings in all versions up to, and including, 2.2.0 due to insufficient inp=
ut sanitization and output escaping. This makes it possible for authenticat=
ed attackers, with administrator-level permissions and above, to inject arb= itrary web scripts in pages that will execute whenever a user accesses an i= njected page. This only affects multi-site installations and installations = where unfiltered_html has been disabled. 2026-07-10 4.4 CVE-2026-12108 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-12108 ] lustmored--Lockme calenda=
rs integration The Lockme OAuth2 calendars integration plugin for WordPress=
is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in a=
ll versions up to, and including, 2.11.0. This is due to insufficient input=
sanitization and output escaping. The register_setting() call on line 197 = lacks a sanitize callback, allowing unsanitized data to be stored via updat= e_option(). When the settings page is rendered, the stored value is echoed = directly into an HTML input's value attribute without esc_attr() on line 21=
2. This makes it possible for authenticated attackers, with administrator-l= evel access and above, to inject arbitrary web scripts in the settings page=
that will execute whenever a user accesses the plugin settings page. Multi= ple fields are affected: App ID (client_id), App Secret (client_secret), Bo= okings ID prefix (id_prefix), and API domain (api_domain). This vulnerabili=
ty is particularly impactful in WordPress multisite installations where adm= inistrators of individual sites should not be able to execute JavaScript af= fecting other users. 2026-07-11 4.4 CVE-2026-3367 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-3367 ] macrozheng--mall A vulnerability was identified=
in macrozheng mall up to 1.0.3. This impacts an unknown function of the fi=
le /returnApply/create of the component Portal Endpoint. The manipulation o=
f the argument orderId leads to improper control of resource identifiers. T=
he attack can be initiated remotely. The exploit is publicly available and = might be used. The vendor deleted the GitHub issue for this vulnerability w= ithout any explanation. 2026-07-09 6.3 CVE-2026-15186 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-15186 ] manjurulhoque--django-job-portal A weaknes=
s has been identified in manjurulhoque django-job-portal up to dfa352f305bb= a44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the functio=
n EditEmployeeProfileAPIView of the file accounts/api/views.py of the compo= nent Employee Dashboard Endpoint. This manipulation of the argument role ca= uses improper access controls. The attack may be initiated remotely. The ex= ploit has been made available to the public and could be used for attacks. = This product uses a rolling release model to deliver continuous updates. As=
a result, specific version information for affected or updated releases is=
not available. The project was informed of the problem early through an is= sue report but has not responded yet. 2026-07-09 6.3 CVE-2026-15188 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-15188 ] matrixaddons--Easy Invoice I= nvoice Generator, PDF Quotes & Payments The Easy Invoice plugin for WordPre=
ss is vulnerable to Missing Authorization in versions up to, and including,=
2.1.19. This is due to the plugin registering the easy_invoice_accept_quot=
e and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and=
relying solely on a quote-scoped nonce that is rendered into the publicly = accessible single quote template, combined with an ownership check that is = gated behind an off-by-default Pro option (easy_invoice_pro_restrict_quote_= to_client). This makes it possible for unauthenticated attackers to accept =
or decline arbitrary published quotes - and, depending on the configured ac= cept action, automatically convert them into invoices (and even email them =
to the client) - by harvesting the per-quote nonce from the public quote pa=
ge and submitting it to admin-ajax. 2026-07-09 5.3 CVE-2026-9021 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-9021 ] mdempfle--Advanced iFrame The Ad= vanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scrip= ting via the 'additional' parameter in all versions up to, and including, 2= 026.1 due to insufficient input sanitization and output escaping. This make=
s it possible for authenticated attackers, with contributor-level access an=
d above, to inject arbitrary web scripts in pages that will execute wheneve=
r a user accesses an injected page. 2026-07-08 6.4 CVE-2026-6742 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-6742 ] MervinPraison--PraisonAI Praison=
AI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletio=
n of issue dependencies. The DELETE dependency route accepts either endpoin=
t of a dependency edge and checks delete permission only against the caller= -selected URL issue. A workspace member who cannot delete a dependency thro= ugh an owner-created issue endpoint (which returns 403) can delete the same=
dependency edge by targeting a related member-owned issue endpoint, becaus=
e permission is validated against the member-owned issue's owner. This allo=
ws members to bypass owner/admin authorization and remove owner-created iss=
ue dependencies. 2026-07-10 6.5 CVE-2026-61441 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-61441 ] MervinPraison--PraisonAI PraisonAI before 4.6.78 = contains a prompt injection defense bypass vulnerability where the injectio=
n defense only blocks threats classified as CRITICAL, requiring three or mo=
re detector families to match simultaneously. Attackers can craft single or=
double-vector prompt injections that are classified as HIGH threat level a=
nd pass through unblocked to reach the model. 2026-07-10 5.3 CVE-2026-60086=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-60086 ] MervinPraison--Prais= onAI PraisonAI before 4.6.78 fails to validate file path references in cust=
om command templates, allowing attackers to read files outside the workspac=
e. Attackers can include path traversal sequences like @../outside_secret.t=
xt or absolute paths in project command files to exfiltrate process-readabl=
e files into model prompts. 2026-07-11 5.5 CVE-2026-60088 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-60088 ] MervinPraison--PraisonAI PraisonAI (pi=
p package praisonaiagents) before 1.6.78 automatically loads defaults from =
a project-local .praisonai/config.toml when constructing an Agent, and does=
not validate the defaults.output.output_file path. A repository-controlled=
config file can set output_file to an absolute or '..' traversal path; whe=
n the developer subsequently calls agent.start() without explicitly passing=
an output parameter, PraisonAI writes the agent response to that path (cre= ating parent directories as needed), allowing an untrusted checked-out proj= ect to overwrite files outside the project root with the privileges of the = user running PraisonAI. 2026-07-10 5.5 CVE-2026-60089 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-60089 ] MervinPraison--PraisonAI PraisonAI before = 4.6.78 contains a path traversal vulnerability in ContextGatherer that fail=
s to validate include paths in .praisoncontext and .praisoninclude files. A= ttackers can supply absolute paths or parent directory traversal sequences =
to read arbitrary files outside the workspace and include their contents in=
the generated context bundle. 2026-07-10 5.5 CVE-2026-61431 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-61431 ] MervinPraison--PraisonAI PraisonAI = (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in = the FastContext feature (praisonaiagents.context.fast). FastContextAgent.ex= ecute_tool() prepends the configured workspace_path only for relative paths=
and neither rejects absolute paths nor canonicalizes joined paths before e= nforcing workspace containment. As a result, tool arguments or model-genera= ted function calls to grep_search, glob_search, read_file, or list_director=
y can supply absolute paths or '../' traversal sequences to read, search, a=
nd enumerate files outside the intended workspace directory, with file cont= ents returned to the caller or injected into the model's tool-result contex=
t. 2026-07-10 5.7 CVE-2026-61432 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-61432 ] metagauss--Memberships and User Profiles for WooCommerce Profil= eGrid WooCommerce Integration The Memberships and User Profiles for WooComm= erce - ProfileGrid WooCommerce Integration plugin for WordPress is vulnerab=
le to unauthorized plugin installation and activation in versions up to, an=
d including, 3.4. This is due to a missing capability check and missing non=
ce validation on the pg_install_profilegrid() AJAX handler registered via w= p_ajax_pg_install_profilegrid. This makes it possible for authenticated att= ackers, with Subscriber-level access and above, to install and activate the=
ProfileGrid plugin from wordpress. 2026-07-09 4.3 CVE-2026-11359 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-11359 ] mettle--sendportal A flaw has = been found in mettle sendportal up to 3.0.1. This vulnerability affects unk= nown code of the file vendor/mettle/sendportal-core/src/Http/Requests/Campa= ignStoreRequest.php of the component Campaign Creation Endpoint. Executing =
a manipulation can lead to authorization bypass. The attack can be executed=
remotely. The exploit has been published and may be used. The project was = informed of the problem early through an issue report but has not responded=
yet. 2026-07-09 6.3 CVE-2026-15191 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-15191 ] mettle--sendportal A vulnerability has been found in mettle = sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/p= ostal/mailjet of the component APIv1 Webhooks. The manipulation leads to mi= ssing authentication. The attack is possible to be carried out remotely. Th=
e exploit has been disclosed to the public and may be used. The project was=
informed of the problem early through an issue report but has not responde=
d yet. 2026-07-09 6.5 CVE-2026-15192 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-15192 ] MiniTool--Partition Wizard A weakness has been identified i=
n MiniTool Partition Wizard up to 13.6. The affected element is an unknown = function in the library pwdrvio.sys of the component Signed Kernel Driver. = This manipulation causes improper access controls. The attack can only be e= xecuted locally. The exploit has been made available to the public and coul=
d be used for attacks. Upgrading to version 13.9 is sufficient to fix this = issue. The affected component should be upgraded. The vendor was contacted = early about this disclosure. 2026-07-12 5.3 CVE-2026-15475 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-15475 ] mlfactory--DSGVO All in one for WP Th=
e DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Aut= horization in all versions up to and including 4.9. This is due to the dsgv= o_reset_policy_service_func() function lacking both capability checks and n= once verification while processing user-supplied parameters to reset plugin=
options. This makes it possible for authenticated attackers, with Subscrib= er-level access and above, to reset all customized privacy policy content i= ncluding cookie notices, Google Analytics policies, Facebook policies, and = YouTube policies to their default values. 2026-07-09 4.3 CVE-2026-4298 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-4298 ] mockoon--mockoon Mockoon p= rovides way to design and run mock APIs. Prior to 9.7.0, a FILE response wh= ose filePath embeds request data is confined by getSafeFilePath in packages= /commons-server/src/libs/server/server.ts with resolvedPath.startsWith(stat= icBaseDir). That prefix test has no path-separator boundary, so a ../-escap=
ed path whose absolute form string-prefixes the base directory passes, allo= wing an unauthenticated client to read files from sibling paths outside the=
served directory through HTTP sendFile, WebSocket, or callbacks. This issu=
e is fixed in version 9.7.0. 2026-07-09 6.5 CVE-2026-59149 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-59149 ] mvantellingen--python-zeep Zeep is a = Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is de= fined but not enforced when parsing WSDL or XSD documents, allowing transit= ive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references=
to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed in versio=
n 4.3.3. 2026-07-08 5.9 CVE-2026-58501 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-58501 ] n8n--n8n n8n before 2.25.7 and 2.26.x before 2.26.2 con= tains an authorization bypass in the Public API execution retry endpoint, w= hich authorizes access using the workflow:read scope instead of workflow:ex= ecute. An authenticated user with read-only access to a shared workflow can=
use the Public API to retry executions of that workflow, bypassing the int= ended permission boundary between read and execute access. This affects ins= tances where workflows are shared with other users or across projects. 2026= -07-08 6.4 CVE-2026-56778 [
https://www.cve.org/CVERecord?id=3DCVE-2026-567=
78 ] n8n--n8n n8n before 2.8.0 contains a cross-site scripting vulnerabilit=
y in the credential management flow where authenticated users can inject ma= licious JavaScript URLs into OAuth2 credential Authorization URL fields. At= tackers can craft malicious credentials and trick victims into clicking the=
OAuth authorization button, executing arbitrary scripts in their browser s= ession with the victim's privileges. 2026-07-08 5.4 CVE-2026-56359 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-56359 ] n8n--n8n n8n before 1.123.55,=
2.25.7, and 2.26.2 contains an authorization vulnerability in three mutati=
ng evaluation test-run endpoints that authorize state-changing actions usin=
g the workflow:read scope instead of the action-appropriate workflow:execut=
e scope. On instances using Advanced Permissions (Enterprise/Cloud) with pr= ojects and viewer roles, an authenticated user with the project:viewer role=
can start new evaluation test runs, cancel in-flight runs, and delete run = records for workflows they only have read access to. 2026-07-08 5.4 CVE-202= 6-56775 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56775 ] n8n--n8n n8n = before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) conta= ins cross-site scripting and open redirect vulnerabilities in the Form Node=
due to unsanitized HTML description fields and overly permissive iframe sa= ndbox policies. Authenticated users with workflow creation permissions can = inject malicious scripts or redirect parameters to perform stored XSS attac=
ks or phishing redirects against end users. 2026-07-10 4.1 CVE-2026-56354 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-56354 ] n8n--n8n n8n before ve= rsions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk=
webhooks in the ZendeskTrigger node. Attackers who know the webhook URL ca=
n send unsigned POST requests to trigger workflows with arbitrary malicious=
data. 2026-07-08 4 CVE-2026-56360 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-56360 ] nandhiniwp--GW AI Website Builder The GW AI Website Builder p= lugin for WordPress is vulnerable to unauthorized modification of data due =
to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handl= er() function in all versions up to, and including, 1.0.1. This makes it po= ssible for authenticated attackers, with Subscriber-level access and above,=
to disconnect the plugin from GravityWrite via the 'gwaiwebu_gravitywrite_= disconnect' AJAX action. 2026-07-10 4.3 CVE-2026-1946 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-1946 ] nats-io--nats-server NATS Server is a high-= performance server for NATS.io, the cloud and edge native messaging system.=
Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for=
the MQTT-over-WebSocket path into MQTT handling even when MQTT was not con= figured, allowing an unauthenticated client with access to the WebSocket li= stener to reach uninitialized MQTT state and crash the server process. This=
issue is fixed in versions 2.14.3 and 2.12.12. 2026-07-08 6.8 CVE-2026-582=
08 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58208 ] nats-io--nats-serv=
er NATS Server is a high-performance server for NATS.io, the cloud and edge=
native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenti= cated user with subscription deny permissions could bypass a plain subject = deny rule by using a queue subscription, because queue-specific deny evalua= tion could override the plain subject deny result when the queue name itsel=
f was not denied. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.= 16. 2026-07-08 6.5 CVE-2026-58251 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-58251 ] nats-io--nats-server NATS Server is a high-performance server = for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2= .12.7, and 2.11.16, an authenticated user could receive messages on denied = subjects when a wildcard subscription overlapped with a configured wildcard=
deny rule but was not a subset of it, and queue subscriptions could also a= ffect delivery to legitimate queue consumers. This issue is fixed in versio=
ns 2.14.0, 2.12.7, and 2.11.16. 2026-07-08 6.5 CVE-2026-58252 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-58252 ] nats-io--nats-server NATS Server i=
s a high-performance server for NATS.io, the cloud and edge native messagin=
g system. Prior to 2.14.3 and 2.12.12, a client could be registered as the = configured no_auth_user through a parser path used when the first client op= eration was not CONNECT, bypassing user-level connection restrictions such =
as allowed_connection_types or proxy_required that normal authentication wo= uld apply. This issue is fixed in versions 2.14.3 and 2.12.12. 2026-07-08 5=
.4 CVE-2026-58211 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58211 ] nat= s-io--nats-server NATS Server is a high-performance server for NATS.io, the=
cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT = retained message delivery and QoS1+ durable replay could deliver messages w= hose original topics matched a subscriber configured subscribe deny rule be= cause these delivery paths did not consistently recheck the concrete origin=
al topic before sending the MQTT PUBLISH to the subscriber. This issue is f= ixed in versions 2.14.3 and 2.12.12. 2026-07-08 4.3 CVE-2026-58209 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-58209 ] nats-io--nats-server NATS Ser= ver is a high-performance server for NATS.io, the cloud and edge native mes= saging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client co= uld subscribe to the internal $MQTT.deliver.pubrel subject family, bypassin=
g configured subscribe permissions and exposing MQTT QoS2 protocol metadata=
for sessions in the account. This issue is fixed in versions 2.14.3 and 2.= 12.12. 2026-07-08 4.3 CVE-2026-58214 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-58214 ] neeraj_slit--Brevo Email, SMS, Web Push, Chat, and more. Th=
e Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely S= endinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scrip= ting via the page parameter in all versions up to, and including, 3.1.77 du=
e to insufficient input sanitization and output escaping. This makes it pos= sible for unauthenticated attackers to inject arbitrary web scripts in page=
s that execute if they can successfully trick a user into performing an act= ion such as clicking on a link. 2026-07-10 6.1 CVE-2026-15297 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-15297 ] nocobase--nocobase NocoBase throug=
h 2.1.20 contains a server-side request forgery vulnerability in the server= Request wrapper that allows authenticated administrators to issue arbitrary=
outbound HTTP requests by supplying malicious URLs to workflow request nod= es, custom request action buttons, or the AI plugin. Attackers can target l= oopback addresses, RFC-1918 private ranges, and cloud instance metadata end= points to perform internal network port enumeration, host discovery, and re= trieval of IAM role credentials from the instance metadata service. v2.1.18=
added a warning message for when SERVER_REQUEST_WHITELIST is not configure=
d. 2026-07-07 5.5 CVE-2026-58468 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-58468 ] nodeca--js-yaml js-yaml is a JavaScript YAML parser and dumper.=
From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend qu= adratic CPU time parsing a document whose size grows only linearly when a c= hain of mappings uses merge keys where each mapping merges the previous one=
. This issue is fixed in version 5.2.0. 2026-07-08 5.3 CVE-2026-59868 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-59868 ] nodeca--js-yaml js-yaml is=
a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEM=
A support for the !!omap tag in src/tag/sequence/omap.ts uses omapTag.addIt= em() to perform a linear duplicate-key scan on every insertion, causing O(n= ^2) CPU consumption when yaml.load() parses a crafted ordered-map document.=
This issue is fixed in version 5.2.1. 2026-07-08 5.3 CVE-2026-59870 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-59870 ] NOMYSOFT Informatics Educat= ion and Consulting Inc.--Nomysem Exposure of sensitive information due to i= ncompatible policies vulnerability in NOMYSOFT Informatics Education and Co= nsulting Inc. Nomysem allows Accessing Functionality Not Properly Constrain=
ed by ACLs. This issue affects Nomysem: through 08072026.=C2=A0NOTE: The ve= ndor was contacted early about this disclosure but did not respond in any w= ay. 2026-07-08 6.5 CVE-2026-6280 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-6280 ] Nozomi Networks--Guardian A Stored HTML Injection vulnerability = was discovered in the Diagram tab and Graph view due to a shared input vali= dation function being insufficiently restrictive. An authenticated user wit=
h administrative privileges can inject malicious HTML tags into N2OS config= uration data through multiple input vectors. When a victim views the affect=
ed data in the Diagram tab and Graph view, the injected HTML renders in the=
ir browser, enabling phishing and possibly open redirect attacks. Full XSS = exploitation and direct information disclosure are prevented by the existin=
g input validation and Content Security Policy configuration. 2026-07-09 5.=
9 CVE-2026-31981 [
https://www.cve.org/CVERecord?id=3DCVE-2026-31981 ] Nozo=
mi Networks--Guardian A Missing Authentication vulnerability was discovered=
in the SSH keys synchronization endpoint. An unauthenticated attacker can = send a request to the SSH keys synchronization endpoint and obtain the list=
of users that have uploaded their public SSH keys, their groups, and the u= ploaded public SSH keys. 2026-07-09 5.3 CVE-2026-31983 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-31983 ] onnx--onnx Open Neural Network Exchange (= ONNX) is an open standard for machine learning interoperability. From 1.9.0=
before 1.22.0, onnx.version_converter.convert_version() can dereference a = null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converte= r/adapters/upsample_6_7.h when processing an untrusted model with an Upsamp=
le node that has zero inputs, causing an unrecoverable denial of service. T= his issue is fixed in version 1.22.0. 2026-07-08 5.5 CVE-2026-44512 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-44512 ] OP-TEE--optee_os OP-TEE is a=
Trusted Execution Environment (TEE) designed as companion to a non-secure = Linux kernel running on Arm; Cortex-A cores using the TrustZone technology.=
Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Ext= ensions accelerated SHA-3 implementation has an off-by-one error that can c= ause a massive heap overflow that corrupts all TEE kernel memory following = the hash state. This affects all platforms built with `CFG_CRYPTO_WITH_CE82= =3Dy` (ARMv8.2+ with SHA3 Crypto Extensions). Version 4.11.0 contains a pat= ch. As a workaround, disable SHA3 Crypto Extensions with `CFG_CRYPTO_WITH_C= E82=3Dn`. 2026-07-06 5.5 CVE-2026-40257 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-40257 ] OP-TEE--optee_os OP-TEE is a Trusted Execution Environm= ent (TEE) designed as companion to a non-secure Linux kernel running on Arm=
; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0=
and prior to version 4.11.0, a vulnerability in OP-TEE's subkey rollback p= rotection allows the use of revoked or older subkey versions because the sy= stem fails to propagate versioning data during the Trusted Application (TA)=
loading process. In `core/crypto/signed_hdr.c`, the function `shdr_load_pu= b_key()` parses subkey headers but does not assign the `subkey_version` to = the runtime `shdr_pub_key` structure. As a result, the `key->version` field=
remains at zero regardless of the version specified in the header. When `r= ee_fs_ta_open()` in `core/kernel/ree_fs_ta.c` calls `check_update_version()=
`, it passes this zeroed version to the rollback database. Because the data= base never receives a non-zero version to record, it never advances, effect= ively bypassing the rollback check and allowing TAs signed with downgraded = subkey chains to load successfully. This impacts OP-TEE mainline configurat= ions that utilize subkey-based signing chains for Trusted Application (TA) = authentication. Version 4.11.0 contains a patch. No known workarounds are a= vailable. 2026-07-06 5.5 CVE-2026-44362 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-44362 ] open-webui--open-webui Open WebUI is an extensible, fea= ture-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.1= 0.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_= webui/utils/middleware.py parsed <$skillId|label> skill mentions with overl= apping quantifiers, allowing an authenticated chat message containing <$ wi= thout a closing > to trigger quadratic backtracking and block the asyncio e= vent loop. This issue is fixed in version 0.10.0. 2026-07-09 6.5 CVE-2026-5= 9220 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59220 ] open-webui--open= -webui Open WebUI is an extensible, feature-rich, and user-friendly self-ho= sted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access o= nly checked read access while file write and delete routes later trusted ob= ject-derived access through writable model meta.knowledge entries, allowing=
a user with read-only knowledge file access to upgrade to file write or de= lete operations. This issue is fixed in version 0.10.0. 2026-07-09 5.4 CVE-= 2026-59212 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59212 ] open-webui= --open-webui Open WebUI is an extensible, feature-rich, and user-friendly s= elf-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint = looked users up by email and only ran bcrypt password verification when a c= redential existed, making registered-account attempts measurably slower tha=
n missing-email attempts and allowing unauthenticated account enumeration. = This issue is fixed in version 0.10.0. 2026-07-09 5.3 CVE-2026-59218 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-59218 ] open-webui--open-webui Open=
WebUI is an extensible, feature-rich, and user-friendly self-hosted AI pla= tform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read=
access to an arena wrapper model can reach a restricted underlying model t= hrough task endpoints such as /api/v1/tasks/moa/completions. The normal cha=
t route resolves arena models before the final chat dispatch and therefore = re-checks the selected underlying model. The task routes call utils.chat.ge= nerate_chat_completion() directly. In that direct path, arena fallback reso= lution happens after the wrapper access check and then recurses with bypass= _filter=3DTrue, skipping the selected submodel's access check. This issue i=
s fixed in version 0.10.0. 2026-07-09 5.4 CVE-2026-59225 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-59225 ] open-webui--open-webui Open WebUI is an=
extensible, feature-rich, and user-friendly self-hosted AI platform. Prior=
to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-li= nked uploaded files to a target knowledge base without applying the write-a= ccess check used by /api/v1/knowledge//file/add, allowing read-only knowled= ge-base users to add arbitrary files. This issue is fixed in version 0.10.0=
. 2026-07-09 4.3 CVE-2026-59217 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-59217 ] open-webui--open-webui Open WebUI is an extensible, feature-rich=
, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEB_FETCH_FIL= TER_LIST matching compared configured host entries against URL strings and = non-label-boundary suffixes, allowing path-based blocklist bypasses such as=
!internal.example.com in a URL path and sibling-domain matches that did no=
t reflect the intended hostname policy. This issue is fixed in version 0.10= .0. 2026-07-09 4.3 CVE-2026-59223 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-59223 ] open-webui--open-webui Open WebUI is an extensible, feature-ri= ch, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, P= OST /api/v1/images/edit required only a verified account and did not enforc=
e the global image-edit switch or the per-user image-generation permission,=
allowing a non-admin user to invoke server-side image editing with adminis= trator-configured provider credentials. This issue is fixed in version 0.10= .0. 2026-07-09 4.3 CVE-2026-59227 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-59227 ] OpenBSD--OpenSSH sshd in OpenSSH before 10.4 does not always h= onor the minimum authentication delay. 2026-07-08 6.5 CVE-2026-60001 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-60001 ] OpenBSD--OpenSSH In sshd in=
OpenSSH before 10.4, DisableForwarding=3Dyes was supposed to take preceden=
ce over PermitTunnel=3Dyes, but did not. 2026-07-08 5.9 CVE-2026-59999 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-59999 ] OpenBSD--OpenSSH sftp in = OpenSSH before 10.4 does not properly constrain the location of downloaded = files when "sftp server:/path ." is used with an attacker-controlled server=
. 2026-07-08 4.2 CVE-2026-59995 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-59995 ] OpenBSD--OpenSSH scp in OpenSSH before 10.4 may place a file in = the parent directory of an intended directory when the copy occurs between = two remote destinations. 2026-07-08 4.2 CVE-2026-59996 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-59996 ] OpenBSD--OpenSSH internal-sftp in sshd in=
OpenSSH before 10.4 recognizes only the first 9 command-line arguments, wh= ich can be important if a later command-line argument would have helped to = ensure the intended security properties of an SFTP connection. 2026-07-08 4=
.2 CVE-2026-59997 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59997 ] Ope= nBSD--OpenSSH sshd in OpenSSH before 10.4 has an undocumented security-rele= vant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in W= indows Active Directory. 2026-07-08 4.8 CVE-2026-59998 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-59998 ] OpenCTI-Platform--opencti OpenCTI is an o= pen source platform for managing cyber threat intelligence knowledge and ob= servables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script fi= lter operator in its FilterOperator enum that allows any authenticated user=
with the KNOWLEDGE capability to pass user-supplied Elasticsearch Painless=
script values directly into search queries without validation or sanitizat= ion, allowing computationally expensive scripts to consume cluster CPU reso= urces and degrade or deny service for all users. This issue is fixed in ver= sion 7.260401.0. 2026-07-08 6.5 CVE-2026-35211 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-35211 ] openfga--openfga OpenFGA is an authorization/perm= ission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authent= icator skipped JWT audience validation when authn.method was set to oidc, a= uthn.oidc.issuer was configured, and authn.oidc.audience was not set, allow= ing a token minted for an unrelated service by the same identity provider t=
o authenticate to OpenFGA. This issue is fixed in 1.18.0. 2026-07-09 6.8 CV= E-2026-55689 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55689 ] openrepl= ay--openreplay OpenReplay is a self-hosted session replay suite. Prior to 1= .27.0, the session search and analytics API in enterprise editions with mul= ti-tenancy enabled built ClickHouse queries by inserting user input into th=
e query string, including two positions that took input without escaping, a= llowing an authenticated member to read any ClickHouse table through blind = boolean and time-based exfiltration and to break the project's session sear=
ch for all viewers until the stored key is removed. This issue is fixed in = version 1.27.0. 2026-07-10 5.4 CVE-2026-57230 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-57230 ] OpenStack--Ironic OpenStack Ironic through before = 37.0.1 allows creation or modification of nodes cross-project without autho= rization. 2026-07-10 5.5 CVE-2026-44918 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-44918 ] openwrt--openwrt OpenWrt is a Linux operating system ta= rgeting embedded devices. Before v25.12.5, an integer underflow in handle_s= end_a() of the Emergency Access Daemon allows any unauthenticated attacker =
on the local network to crash the daemon by sending a single crafted UDP pa= cket. The message length underflows before a bounds check and is then passe=
d to memcpy as a very large size. This issue is fixed v25.12.5. 2026-07-07 = 6.5 CVE-2026-55490 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55490 ] os= query--osquery osquery is a SQL powered operating system instrumentation, m= onitoring, and analytics framework. Prior to 5.23.1, an unprivileged attack=
er can read the contents of an osquery file carve until the carve completes=
and the temporary files are deleted because in-progress carve directories = are not created with private permissions. If the carve targets a directory = that the attacker controls, arbitrary file reads are possible, such as sens= itive local files. This issue is fixed in version 5.23.1. 2026-07-10 4.4 CV= E-2026-46388 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46388 ] owasp-mo= dsecurity--ModSecurity ModSecurity is an open source, cross platform web ap= plication firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 throu=
gh 3.0.15, the t:utf8toUnicode transformation in src/actions/transformation= s/utf8_to_unicode.cc produces wrong output on i386 architecture because snp= rintf uses sizeof on a char pointer rather than the length of the unicode b= uffer, allowing rules that use this transformation to be bypassed on i386 a= rchitecture. This issue is fixed in version 3.0.16. 2026-07-10 5.8 CVE-2026= -52761 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52761 ] phpMyFAQ--phpM= yFAQ phpMyFAQ before 4.1.5 applies inconsistent active=3Dyes and publicatio= n-date filtering across its public FAQ API endpoints, allowing unauthentica= ted attackers to retrieve inactive (draft or review-only) FAQ content. Spec= ifically, GET /api/v3.1/faq/{categoryId}/{faqId} returns the inactive FAQ t= itle and full answer, while GET /api/v3.1/faqs/tags/{tagId} and GET /api/v4= .0/faqs/tags/{tagId} return the inactive FAQ title and answer preview, disc= losing non-public content. 2026-07-10 5.3 CVE-2026-57994 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-57994 ] pig-mesh--Pig A vulnerability was ident= ified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown f= unctionality of the file \pig-master\pig-visual\pig-codegen\src\main\java\c= om\pig4cloud\pig\codegen\service\impl\GeneratorServiceImpl.java of the comp= onent pig-codegen. Such manipulation leads to code injection. It is possibl=
e to launch the attack remotely. The exploit is publicly available and migh=
t be used. The vendor was contacted early about this disclosure but did not=
respond in any way. 2026-07-12 6.3 CVE-2026-15512 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-15512 ] plugins360--All-in-One Video Gallery The All-= in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Requ= est Forgery in all versions up to, and including, 4.8.5 via the 'vdl' param= eter. This makes it possible for authenticated attackers, with subscriber-l= evel access and above, to make web requests to arbitrary locations originat= ing from the web application and can be used to query and modify informatio=
n from internal services. A Subscriber-level attacker can plant an internal=
or loopback URL in the `mp4` post meta of a newly created `aiovg_videos` p= ost via XML-RPC `wp.newPost`, then trigger the unauthenticated `?vdl=3D<pos= t_id>` endpoint to force the server to fetch that URL and stream the full r= esponse body back to the requester. 2026-07-10 6.4 CVE-2026-12123 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-12123 ] pluginsGLPI--datainjection The=
DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-su= pplied CSV field values directly into SQL queries during CSV import, withou=
t parameterization or escaping, resulting in authenticated SQL injection. A=
n authenticated user with access to the Data injection feature can embed SQ=
L expressions such as SLEEP() in a mapped field (for example Serial Number)=
to manipulate the generated query and extract database information via tim= e-based blind injection. 2026-07-10 6.4 CVE-2026-11321 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-11321 ] posimyththemes--Nexter Blocks Gutenberg B= locks, Page Builder & AI Website Builder The Nexter Blocks - Gutenberg Bloc= ks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to=
Stored Cross-Site Scripting via the 'commentIcon' parameter in all version=
s up to, and including, 4.7.4 due to insufficient input sanitization and ou= tput escaping. This makes it possible for authenticated attackers, with con= tributor-level access and above, to inject arbitrary web scripts in pages t= hat will execute whenever a user accesses an injected page. 2026-07-08 6.4 = CVE-2026-6740 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6740 ] posimyth= themes--The Plus Addons for Elementor Addons for Elementor, Page Templates,=
Widgets, Mega Menu, WooCommerce The Plus Addons for Elementor plugin for W= ordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site S= cripting via the Button widget's `custom_attributes` setting in versions up=
to and including 6.4.11. The `render` function in `modules/widgets/tp_butt= on.php` passed the raw `custom_attributes` string through `tp_senitize_js_i= nput()`. This filter is bypassable. The issue is patched in version 6.4.12.=
2026-07-10 6.4 CVE-2026-15285 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-15285 ] postmagthemes--Context Blog The Context Blog theme for WordPress =
is vulnerable to Sensitive Information Exposure in all versions up to, and = including, 1.3.5 via the context_blog_modal_popup. This makes it possible f=
or unauthenticated attackers to extract the content of password-protected p= osts. 2026-07-11 5.3 CVE-2026-6801 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-6801 ] prasunsen--Hostel The Hostel plugin for WordPress is vulnerabl=
e to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all v= ersions up to and including 1.1.7. This is due to insufficient input saniti= zation and output escaping on user-supplied shortcode attributes. Specifica= lly, the second shortcode attribute (used as button text) is passed to the = `$text` variable without sanitization at line 79 and then output directly i= nto an HTML `value` attribute at line 91 without `esc_attr()` or any other = escaping. This makes it possible for authenticated attackers, with Contribu= tor-level access and above, to inject arbitrary web scripts in pages that w= ill execute whenever a user accesses an injected page. 2026-07-10 6.4 CVE-2= 026-3907 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3907 ] printfriendly= --Print, PDF & Email by PrintFriendly The Print, PDF, Email by PrintFriendl=
y plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the=
'content_position_css' parameter in all versions up to, and including, 5.5= .10 due to insufficient input sanitization and output escaping. This makes =
it possible for authenticated attackers, with administrator-level access an=
d above, to inject arbitrary web scripts in pages that will execute wheneve=
r a user accesses an injected page. 2026-07-11 4.4 CVE-2026-9738 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-9738 ] priyanshuchaudhary--FlowForms Co= nversational Form Builder The FlowForms - Conversational Form Builder plugi=
n for WordPress is vulnerable to Insecure Direct Object Reference in all ve= rsions up to, and including, 1.1.1 via the update_form due to missing valid= ation on a user controlled key. This makes it possible for authenticated at= tackers, with contributor-level access and above, to modify the content, de= sign, and settings of, as well as publish or revert, any form on the site -=
including forms owned by administrators - by supplying an arbitrary form I=
D in the REST URL. 2026-07-10 4.3 CVE-2026-12400 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-12400 ] Progress--MOVEit Transfer Improper Neutralizati=
on of Special Elements in Data Query Logic vulnerability in Progress MOVEit=
Transfer (Custom Reports modules). This issue affects MOVEit Transfer: bef= ore 2025.0.7, from 2025.1.0 before 2025.1.3. 2026-07-08 6.4 CVE-2026-8649 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-8649 ] Progress--MOVEit Transf=
er Relative path traversal vulnerability in Progress MOVEit Transfer (Admin=
Settings module). This issue affects MOVEit Transfer: before 2025.0.7, fro=
m 2025.1.0 before 2025.1.3. 2026-07-08 4.5 CVE-2026-8650 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-8650 ] protobufjs--protobuf.js protobufjs compi= les protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and=
8.6.6, protobufjs parsed option names by advancing through schema tokens u= ntil reaching an =3D token without checking for end of input, so a crafted = .proto schema that opens an option declaration and ends prematurely can cau=
se parse, Root.load, or Root.loadSync to loop indefinitely. This issue is f= ixed in versions 7.6.5 and 8.6.6. 2026-07-08 5.3 CVE-2026-59877 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-59877 ] protobufjs--protobuf.js protobuf=
js compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0=
until 8.6.5, the protobufjs Text Format extension parsed string-keyed map = entries using ordinary property assignment, allowing a map entry with key _= _proto__ to change the prototype of the returned map object instead of crea= ting an own map entry in protobufjs/ext/textformat. This issue is fixed in = version 8.6.5. 2026-07-08 4.8 CVE-2026-59876 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-59876 ] pydantic--pydantic-settings pydantic-settings provi= des settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSec= retsSettingsSource reads secret values from files in a configured secrets_d= ir. When secrets_nested_subdir=3DTrue, a directory entry inside secrets_dir=
that is a symbolic link pointing outside secrets_dir is followed, so files=
outside the configured directory are read into settings values. The same c= ode path bypasses the documented secrets_dir_max_size protection. An attack=
er or lower-privileged component able to influence entries in the configure=
d secrets directory (for example, a writable or shared secrets mount) can t= urn this into an unintended local file read into settings and can defeat th=
e advertised loading-size cap. This vulnerability is fixed in 2.14.2. 2026-= 07-06 5.3 CVE-2026-58203 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5820=
3 ] pypa--setuptools setuptools is a package that allows users to download,=
build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, F= ileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and=
prune directives by matching compiled glob patterns against on-disk file n= ames without Unicode normalization, so on macOS APFS or HFS+ an NFD file na=
me could bypass an NFC exclusion rule and be packed into a source distribut= ion. This issue is fixed in version 83.0.0. 2026-07-08 6.1 CVE-2026-59890 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-59890 ] python-pillow--Pillow = Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_comm= and() constructed a cmd.exe shell command by directly embedding a file path=
into an f-string without escaping and passed the result to subprocess.Pope= n(..., shell=3DTrue), allowing shell metacharacters in the file path to inj= ect arbitrary cmd.exe commands. This issue is fixed in version 12.3.0. 2026= -07-06 4.5 CVE-2026-55798 [
https://www.cve.org/CVERecord?id=3DCVE-2026-557=
98 ] QILING--Disk Master A security vulnerability has been detected in QILI=
NG Disk Master 6.0.0.0. The impacted element is an unknown function in the = library diskbckp.sys of the component Kernel Driver. Such manipulation lead=
s to improper access controls. The attack can only be performed from a loca=
l environment. The exploit has been disclosed publicly and may be used. It =
is suggested to upgrade the affected component. 2026-07-12 5.3 CVE-2026-154=
76 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15476 ] Qualcomm, Inc.--Sn= apdragon Memory Corruption when invoking device input/output control operat= ions for mapping and unmapping persistent memory buffers due to improper sy= nchronization. 2026-07-06 6.6 CVE-2025-59615 [
https://www.cve.org/CVERecor= d?id=3DCVE-2025-59615 ] Qualcomm, Inc.--Snapdragon Memory Corruption when p= rocessing multiple IOCTL calls with the same buffer file descriptor input d=
ue to accessing already freed memory. 2026-07-06 6.6 CVE-2025-59616 [ https= ://www.cve.org/CVERecord?id=3DCVE-2025-59616 ] Qualcomm, Inc.--Snapdragon M= emory Corruption when processing multiple IOCTL calls with the same buffer = file descriptor input. 2026-07-06 6.6 CVE-2025-59617 [
https://www.cve.org/= CVERecord?id=3DCVE-2025-59617 ] Qualcomm, Inc.--Snapdragon Memory Corruptio=
n when parsing jpeg commands due to unaccounted extra writes to the buffer = during validation checks. 2026-07-06 5.3 CVE-2026-21368 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-21368 ] Qualcomm, Inc.--Snapdragon Memory Corrup= tion when handling flash commands due to outdated LED count values being us=
ed after userspace modification. 2026-07-06 5.3 CVE-2026-21369 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-21369 ] Qualcomm, Inc.--Snapdragon Memory=
Corruption when validating input batch size and buffer plane count exceeds=
maximum allowed values. 2026-07-06 5.3 CVE-2026-21370 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-21370 ] Qualcomm, Inc.--Snapdragon Memory Corrupt= ion when updating prepared commands with invalid port indices based on user=
space input exceeds supported read client limits. 2026-07-06 5.3 CVE-2026-= 21384 [
https://www.cve.org/CVERecord?id=3DCVE-2026-21384 ] QuantumNous--ne= w-api New API is a large language mode (LLM) gateway and artificial intelli= gence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and = WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oau= th/wechat/bind used GET requests for state-changing account operations, all= owing an attacker to trigger a logged-in user's browser to bind an attacker= -controlled email address or OAuth identity in deployments where session co= okies could be sent on cross-site navigations. This issue is fixed in versi=
on 0.12.0-alpha.1. 2026-07-09 5.3 CVE-2026-44342 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-44342 ] rabbitmq--rabbitmq-server RabbitMQ is a messagi=
ng and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ=
management plugin static file handler rabbit_mgmt_wm_static can pass URL-e= ncoded backslashes to erl_prim_loader:read_file_info before path validation=
when multiple management extension plugins are enabled, causing outbound D=
NS and SMB requests to attacker-controlled UNC paths. This issue is fixed i=
n versions 4.1.11 and 4.2.6. 2026-07-10 6.5 CVE-2026-57211 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-57211 ] rabbitmq--rabbitmq-server RabbitMQ is=
a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.= 2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a l= oopback-restricted user such as guest to connect remotely when traffic is a= ccepted through a trusted PROXY-protocol path and the backend listener is l= oopback-bound because the loopback check uses the listener-side socket addr= ess instead of the real client source. This issue is fixed in versions 3.13= .15, 4.0.20, 4.1.11, and 4.2.6. 2026-07-10 6.8 CVE-2026-57216 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-57216 ] rainafarai--Notification for Teleg= ram The Notification for Telegram plugin for WordPress is vulnerable to aut= horization bypass in all versions up to, and including, 3.5.1. This is due =
to the plugin not properly verifying that a user is authorized to perform a=
n action. This makes it possible for authenticated attackers, with subscrib= er-level access and above, to create, modify, or reschedule the nftb_cron_h= ook WordPress cron event, enabling unauthorized manipulation of the plugin'=
s background task scheduling logic. 2026-07-11 4.3 CVE-2026-7620 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-7620 ] Red Hat--Red Hat Directory Serve=
r 11 A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-= base). When normalizing a Distinguished Name (DN) that contains a legacy-qu= oted value encoding a multivalued nested Relative Distinguished Name (RDN),=
the server can write past the end of a heap allocation while sorting RDN a= ttribute-value pairs. An unauthenticated remote attacker can trigger this c= ondition by sending an LDAP operation whose DN reaches the DN normalization=
routine, such as a search with a crafted base DN. This can corrupt heap me= mory and may cause denial of service. 2026-07-07 5.3 CVE-2026-14940 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-14940 ] Red Hat--Red Hat Directory S= erver 11 A flaw was found in 389-ds-base where the LDBM backend attribute e= ncryption uses a hardcoded static initialization vector for AES-CBC and 3DE= S-CBC operations, allowing an attacker with privileged filesystem access to=
detect plaintext equality across encrypted entries by comparing ciphertext=
blocks. 2026-07-07 4.4 CVE-2026-14969 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-14969 ] Red Hat--Red Hat Enterprise Linux 6 A flaw was found in=
GIMP. The PlayStation TIM loader, responsible for handling PlayStation ima=
ge files, incorrectly calculates the size of the Color Look-Up Table (CLUT)=
due to an integer overflow. This occurs when multiplying num_colors and nu= m_cluts, both 16-bit unsigned short integers, resulting in a value exceedin=
g the maximum integer limit. An attacker could exploit this by providing a = specially crafted image file, leading to undefined behavior and causing the=
GIMP plug-in to abort, effectively resulting in a denial of service. 2026-= 07-06 5.5 CVE-2026-59089 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5908=
9 ] Red Hat--Red Hat JBoss Enterprise Application Platform 8.1 A flaw was f= ound in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. =
If using a set of combined configuration to allow unescaped characters in U=
RL with embedded Undertow and Jastow, a server might be vulnerable to impro= per input handling. 2026-07-07 6.5 CVE-2025-12799 [
https://www.cve.org/CVE= Record?id=3DCVE-2025-12799 ] Red Hat--Red Hat OpenShift AI (RHOAI) A flaw w=
as found in the TrustyAI Service Operator. When deploying services like gor=
ch or NemoGuardrails, if a specific security setting is not enabled, these = services can expose their communication channels without requiring users to=
prove their identity. This allows any other program within the cluster to = access the AI guardrails and orchestrator without proper authorization. An = attacker could exploit this to gain unauthorized access to sensitive inform= ation and potentially make limited changes to the AI models. 2026-07-08 6.3=
CVE-2026-15044 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15044 ] Red H= at--Red Hat OpenShift AI (RHOAI) A flaw was found in the gorch service temp= late, which is part of the trustyai-service-operator. Even when authenticat= ion is enabled, the gorch service exposes unproxied orchestrator and detect=
or metrics ports. This allows any pod on the cluster network to directly ac= cess these ports, bypassing the kube-rbac-proxy and its authentication mech= anisms. This could lead to unauthorized access to the orchestrator and dete= ctor metrics. 2026-07-08 6.3 CVE-2026-15063 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-15063 ] Red Hat--Red Hat OpenShift AI (RHOAI) A flaw was fou=
nd in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vul= nerability, known as Regular Expression Denial of Service (ReDoS), allows a=
remote attacker to provide specially crafted regular expressions to the pu= blic detection API. This can cause catastrophic backtracking, leading to a = worker process consuming 100% CPU indefinitely and resulting in a denial of=
service for the entire guardrails-mediated LLM pipeline. 2026-07-08 6.5 CV= E-2026-15154 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15154 ] redefini= ngtheweb--Affiliate Program & Referral Tracking for WooCommerce & WordPress=
Affilia The Affilia - Affiliate Program & Referral Tracking for WordPress = plugin for WordPress is vulnerable to unauthorized access in all versions u=
p to, and including, 3.3.3. This is due to the plugin not properly verifyin=
g that a user is authorized to perform an action. This makes it possible fo=
r authenticated attackers, with subscriber-level access and above, to appro=
ve or reject affiliate referrals, credit commissions to affiliate wallets, = delete referral records, and modify custom banner plugin options, enabling = financial fraud. The nonce required to pass the only authentication check i=
s embedded in every frontend page load via rtwalwm_global_params.rtwalwm_no= nce, making it trivially accessible to any authenticated user regardless of=
role. 2026-07-11 4.3 CVE-2026-7559 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-7559 ] reputeinfosystems--ARMember Membership Plugin, Content Restri= ction, Member Levels, User Profile & User signup The ARMember plugin for Wo= rdPress is vulnerable to Directory Traversal in all versions up to, and inc= luding, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for=
unauthenticated attackers to upload and overwrite certain files (e.g., CSS=
) to directories outside the 'wp-content/uploads/armember' directory. 2026-= 07-10 5.3 CVE-2026-15302 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1530=
2 ] revmakx--Backup and Staging by WP Time Capsule The Backup and Staging b=
y WP Time Capsule plugin for WordPress is vulnerable to Sensitive Informati=
on Exposure in all versions up to, and including, 1.22.26 via the download_= recent_decrypted_file_wptc. This makes it possible for authenticated attack= ers, with subscriber-level access and above, to extract download the most r= ecently admin-decrypted SQL database backup, which typically contains passw= ord hashes, user credentials, and other sensitive site configuration data s= tored in the 'recent_decrypted_file' option. Exploitation requires that an = administrator has previously performed a decrypt action, causing the decryp= ted SQL backup file to exist in the plugin's upload directory; without this=
prior admin action, there is no file to serve. 2026-07-09 6.5 CVE-2026-899=
6 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8996 ] richardperdaan--MyPa= rcel The MyParcel plugin for WordPress is vulnerable to authorization bypas=
s in all versions up to, and including, 4.25.1. This is due to the plugin n=
ot properly verifying that a user is authorized to perform an action. This = makes it possible for authenticated attackers, with subscriber-level access=
and above, to view and modify shipment options - including carrier, delive=
ry type, package type, number of labels, weight, signature requirement, and=
insurance - on any arbitrary order. 2026-07-11 4.3 CVE-2026-8678 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-8678 ] robin-w--bbp style pack The bbp=
Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripti=
ng in versions up to, and including, 6.4.5 via the Topic Form Additional Fi= elds feature. This is due to insufficient input sanitization in bsp_topic_f= ields_form_save() (which writes $_POST['bsp_topic_fields_label{n}'] directl=
y to post meta via update_post_meta() with no filtering) and missing output=
escaping in bsp_topic_content_append_topic_fields() (which concatenates th=
e stored meta value into an HTML <span> and echoes it via apply_filters/ech=
o without esc_html()). This makes it possible for authenticated attackers, = with Subscriber-level access and above (who have bbPress topic-creation pri= vileges), to inject arbitrary web scripts in pages that will execute whenev=
er a user accesses an injected page, including unauthenticated visitors. 20= 26-07-11 6.4 CVE-2026-15010 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 5010 ] ronf--asyncssh AsyncSSH is a Python package which provides an asynch= ronous client and server implementation of the SSHv2 protocol on top of the=
Python asyncio framework. Version 2.23.0 contains an incomplete fix for CV= E-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before =
%u substitution in AuthorizedKeysFile but does not block a leading ~ or ${E= NV}, allowing later expansion in _expand_val and Path(filename).expanduser(=
) to escape the intended authorized-keys directory. This issue is fixed in = version 2.23.1. 2026-07-08 5.9 CVE-2026-54590 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-54590 ] room34--ICS Calendar The ICS Calendar plugin for W= ordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagti= tle' parameter in all versions up to, and including, 12.0.9 due to insuffic= ient input sanitization and output escaping. This makes it possible for una= uthenticated attackers to inject arbitrary web scripts in pages that execut=
e if they can successfully trick a user into performing an action such as c= licking on a link. The vulnerability is reachable via the unauthenticated w= p_ajax_nopriv_r34ics_ajax AJAX action, which accepts attacker-controlled js= _args values merged over stored shortcode configuration without nonce verif= ication, allowing the htmltagtitle key to bypass the normal shortcode allow= list check. 2026-07-10 6.1 CVE-2026-9838 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-9838 ] rtcamp--rtMedia for WordPress, BuddyPress and bbPress Th=
e rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vul= nerable to time-based SQL Injection via the order_by parameter in all versi= ons up to, and including, 4.6.18 due to insufficient escaping on the user s= upplied parameter and lack of sufficient preparation on the existing SQL qu= ery. This makes it possible for authenticated attackers, with subscriber ac= cess and above, to append additional SQL queries into already existing quer= ies that can be used to extract sensitive information from the database. 20= 26-07-10 6.5 CVE-2026-15287 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 5287 ] rubengc--GamiPress Gamification plugin to reward points, achievement=
s, badges & ranks in WordPress The GamiPress - Gamification plugin to rewar=
d points, achievements, badges & ranks in WordPress plugin for WordPress is=
vulnerable to Insecure Direct Object Reference in all versions up to, and = including, 7.9.4 via the 'access' parameter due to missing validation on a = user controlled key. This makes it possible for unauthenticated attackers t=
o view private GamiPress activity log entries belonging to any user, includ= ing badge earnings, points balance changes, and event records from integrat=
ed plugins such as WooCommerce, LearnDash, and BuddyPress. This is exploita= ble by any unauthenticated visitor because the required 'gamipress' nonce i=
s broadcast to all front-end users via wp_localize_script on the wp_enqueue= _scripts hook, making the sole authentication barrier trivially bypassable.=
2026-07-09 5.3 CVE-2026-13450 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-13450 ] saadiqbal--User Management The User Management plugin for WordPre=
ss is vulnerable to authorization bypass in all versions up to, and includi= ng, 1.2. This is due to the plugin not properly verifying that a user is au= thorized to perform an action. This makes it possible for unauthenticated a= ttackers to modify the plugin's export field configuration stored in the ui= ewp_export_field option, controlling which user fields such as password has= hes are included in CSV exports and how columns are mapped during imports. = 2026-07-08 5.3 CVE-2026-12097 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -12097 ] saadiqbal--WP Easy Pay Payment and Donation form Builder for Squar=
e The WP Easy Pay - Payment and Donation form Builder for Square plugin for=
WordPress is vulnerable to authorization bypass in all versions up to, and=
including, 4.5.0. This is due to the plugin not properly verifying that a = user is authorized to perform an action. This makes it possible for authent= icated attackers, with subscriber-level access and above, to set the status=
of arbitrary posts and pages to 'draft', effectively unpublishing arbitrar=
y site content. 2026-07-11 4.3 CVE-2026-12738 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-12738 ] safistudio--Bookero.pl system rezerwacji online Th=
e Bookero.pl - system rezerwacji online plugin for WordPress is vulnerable =
to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide= _products` (and `filter_products`) attributes in versions up to and includi=
ng 2.2. This is due to insufficient input sanitization and output escaping =
in the `bookero_products()` function - the raw attribute value is concatena= ted directly into an inline `<script>` block without any escaping. This mak=
es it possible for authenticated attackers with contributor-level access an=
d above to inject arbitrary web scripts into pages that will execute whenev=
er a user accesses the injected page. 2026-07-09 6.4 CVE-2026-6910 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-6910 ] Samsung Open Source--Escargot = Stack-based buffer overflow vulnerability in Samsung Open Source Escargot a= llows Overflow Buffers. This issue affects Escargot: before b30b63fc63b4039= 07d8137da1c65aaa4521fe74e. 2026-07-09 6.1 CVE-2026-58303 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-58303 ] Samsung Open Source--Escargot Out-of-bo= unds read, Out-of-bounds write vulnerability in Samsung Open Source Escargo=
t allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f= 334dec64b0a51ebb724b4708b84a. 2026-07-09 6.1 CVE-2026-58304 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-58304 ] Samsung Open Source--Escargot Access=
of resource using incompatible type ('type confusion') vulnerability in Sa= msung Open Source Escargot allows Pointer Manipulation. This issue affects = Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a. 2026-07-09 6.1 C= VE-2026-58305 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58305 ] Samsung=
Open Source--Escargot Heap-based buffer overflow vulnerability in Samsung = Open Source Escargot allows Overflow Buffers. This issue affects Escargot: = before ef525f337fafddecde77a3c426212a84bb20cb98. 2026-07-09 6.1 CVE-2026-58= 306 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58306 ] Samsung Open Sour= ce--Escargot Out-of-bounds read, Reachable assertion vulnerability in Samsu=
ng Open Source Escargot allows Overread Buffers, Input Data Manipulation. T= his issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c=
. 2026-07-09 6.1 CVE-2026-58307 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-58307 ] saskaita123--Invoice123 The Invoice123 plugin for WordPress is v= ulnerable to authorization bypass in all versions up to, and including, 1.7= .0. This is due to the plugin not properly verifying that a user is authori= zed to perform an action. This makes it possible for authenticated attacker=
s, with subscriber-level access and above, to overwrite the plugin's API ke=
y stored in wp_options, modify invoice plugin settings, and alter WooCommer=
ce tax rate data in the wp_woocommerce_tax_rates table. 2026-07-10 4.3 CVE-= 2026-9857 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9857 ] sayantandas2= 0--Bulk Order Update for WooCommerce The Bulk Order Update for WooCommerce = plugin for WordPress is vulnerable to Arbitrary File Read in versions up to=
, and including, 1.6. This is due to the bouw_fetch_csv_data() AJAX handler=
being registered on the wp_ajax_nopriv_ hook with no capability or nonce c= heck, and passing the attacker-supplied csv_url POST parameter - filtered o= nly by esc_url_raw() (which leaves absolute filesystem paths intact) and va= lidate_file() (which only rejects '..' traversal patterns) - directly into = fopen()/fgetcsv() and reflecting the first parsed line in the JSON response=
. This makes it possible for unauthenticated attackers to read the first li=
ne of arbitrary files on the server (such as /etc/passwd) and to use the ha= ndler as a file-existence oracle. 2026-07-08 5.3 CVE-2026-14500 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-14500 ] Sayax Energy Technologies Inc.--= OSOS Insertion of sensitive information into sent data vulnerability in Say=
ax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue a= ffects OSOS: through 09072026.=C2=A0NOTE: The vendor was contacted early ab= out this disclosure but did not respond in any way. 2026-07-09 6.5 CVE-2026= -1365 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1365 ] seaweedfs--seawe= edfs SeaweedFS is a distributed storage system. In versions 4.08 through 4.= 33, requests signed with SigV4 service s3tables are routed to the S3Tables = management API where authorization collapses account-less S3 identities int=
o the shared admin account and fails open, allowing an authenticated low-pr= ivileged S3 user to enumerate administrator-owned table bucket names and AR= Ns. This issue is fixed in version 4.34. 2026-07-08 4.3 CVE-2026-55873 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-55873 ] seedprod--Website Builder=
by SeedProd Theme Builder, Landing Page Builder, Coming Soon Page, Mainten= ance Mode The Website Builder by SeedProd - Theme Builder, Landing Page Bui= lder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable=
to Stored Cross-Site Scripting via the plugin's `seedprodnestedmenuwidget`=
shortcode in all versions up to, and including, 6.20.2 due to insufficient=
input sanitization and output escaping on user supplied attributes. This m= akes it possible for authenticated attackers, with contributor level access=
and above, to inject arbitrary web scripts in pages that will execute when= ever a user accesses an injected page. 2026-07-08 6.4 CVE-2025-14785 [ http= s://www.cve.org/CVERecord?id=3DCVE-2025-14785 ] showdown--showdown showdown=
contains a stored cross-site scripting vulnerability in the parseHeaders f= unction of src/subParsers/makehtml/tables.js that fails to properly escape = table header ID attributes. Attackers can inject arbitrary HTML and script-= executing SVG elements through double-quote characters in markdown table he= aders, achieving stored XSS when untrusted markdown is rendered with the de= fault github flavor configuration. 2026-07-06 6.1 CVE-2026-59710 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-59710 ] showdown--showdown showdown con= tains a cross-site scripting vulnerability in metadata title handling that = allows attackers to inject arbitrary HTML and JavaScript. When completeHTML= Document option is enabled, unescaped less-than and greater-than characters=
in markdown frontmatter metadata are inserted directly into HTML title tag=
s, enabling attackers to break out of the title context and execute malicio=
us scripts in the rendered page. 2026-07-06 6.1 CVE-2026-59711 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-59711 ] Siemens--CPCI85 Central Processin= g/Communication A vulnerability has been identified in CPCI85 Central Proce= ssing/Communication (All versions < V26.20), SICORE Base system (All versio=
ns < V26.20.0). The affected application includes a debugging interface tha=
t is accessible through HTTP endpoints. This could allow an authenticated a= ttacker to disrupt the system by crashing the web process causing denial of=
service conditions. 2026-07-09 6.5 CVE-2026-54798 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-54798 ] Siemens--CPCI85 Central Processing/Communicat= ion A vulnerability has been identified in CPCI85 Central Processing/Commun= ication (All versions < V26.20), SICORE Base system (All versions < V26.20.= 0). The affected application contains a vulnerability in its firmware updat=
e mechanism's signature validation process. This could allow an attacker to=
install malicious firmware, leading to persistent code execution and syste=
m compromise. 2026-07-09 6.7 CVE-2026-54799 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-54799 ] Siemens--CPCI85 Central Processing/Communication A v= ulnerability has been identified in CPCI85 Central Processing/Communication=
(All versions < V26.20), SICORE Base system (All versions < V26.20.0). The=
affected application ships with a default configuration that disables all = OPC UA security mechanisms. This could allow an attacker to gain unauthoriz=
ed access and control over critical system functions. 2026-07-09 4.8 CVE-20= 26-54800 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54800 ] Sipeed--Pico= Claw A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Af= fected by this vulnerability is the function WebFetchTool.Execute of the fi=
le pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. Th=
e manipulation results in server-side request forgery. The attack can be ex= ecuted remotely. The exploit has been released to the public and may be use=
d for attacks. The reported GitHub issue was closed automatically due to in= activity. 2026-07-10 6.3 CVE-2026-15317 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15317 ] Sipeed--PicoClaw A weakness has been identified in Sipe=
ed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionali=
ty of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Hand= ler. This manipulation of the argument client_id causes incorrect authoriza= tion. The attack is possible to be carried out remotely. The exploit has be=
en made available to the public and could be used for attacks. The reported=
GitHub issue was closed automatically due to inactivity. 2026-07-10 6.3 CV= E-2026-15318 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15318 ] Sipeed--= PicoClaw A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This = vulnerability affects the function rt.ReloadConfig of the file pkg/channels= /pico/pico.go. Performing a manipulation of the argument message.send resul=
ts in missing authorization. It is possible to initiate the attack remotely=
. The exploit is now public and may be used. The reported GitHub issue was = closed automatically due to inactivity. 2026-07-10 5.4 CVE-2026-15320 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-15320 ] siyuan-note--siyuan SiYuan=
is an open-source personal knowledge management system. Prior to 3.7.1, th=
e /api/storage/getCriteria endpoint returns saved search criteria from data= /storage/criteria.json without the publish-access filtering used by sibling=
storage endpoints, allowing a publish-mode Reader to read private document=
paths, notebook, document, and block IDs, and search and replace keywords = for unpublished documents. This issue is fixed in versions 3.7.1. 2026-07-0=
9 6.5 CVE-2026-59853 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59853 ] = siyuan-note--siyuan SiYuan is an open-source personal knowledge management = system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-sup= plied absolute source paths and relies on util.IsSensitivePath in kernel/ut= il/path.go, whose denylist misses common home-directory credential files su=
ch as .git-credentials, .netrc, .pgpass, .kube/config, .docker/config.json,=
and .gnupg, allowing an authenticated administrator or API-token user to c= opy those files into the workspace and exfiltrate them through the file API=
. This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1. 2026-07-09 4.9 C= VE-2026-59854 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59854 ] smub--S= mash Balloon Social Photo Feed Easy Social Feeds Plugin The Smash Balloon S= ocial Photo Feed - Easy Social Feeds Plugin plugin for WordPress is vulnera= ble to Cross-Site Request Forgery in all versions up to, and including, 6.1= 1.1. This is due to missing or incorrect nonce validation on the maybe_conn= ection_data function. This makes it possible for unauthenticated attackers =
to overwrite the site's Instagram and Facebook oEmbed access tokens via a f= orged request granted they can trick a site administrator into performing a=
n action such as clicking on a link. 2026-07-08 4.7 CVE-2026-12002 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-12002 ] solacewp--Solace Extra The So= lace Extra plugin for WordPress is vulnerable to authorization bypass in al=
l versions up to, and including, 1.5.3. This is due to the plugin not prope= rly verifying that a user is authorized to perform an action. This makes it=
possible for unauthenticated attackers to permanently delete all content p= reviously imported via the Starter Template feature, including posts, pages=
, media attachments, WooCommerce products, taxonomy terms, and sitebuilder = templates. The required nonce is emitted on every wp-admin page via wp_loca= lize_script() hooked to admin_enqueue_scripts without a page guard, meaning=
any Subscriber visiting /wp-admin/profile.php can obtain it; the handler i=
s additionally registered via wp_ajax_nopriv_, making it reachable by fully=
unauthenticated users as well. 2026-07-11 5.3 CVE-2026-13250 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-13250 ] SonicCloudOrg--sonic-agent A vulne= rability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affec= ted element is an unknown function of the file AndroidWSServer.java of the = component Android WebSocket Server. The manipulation of the argument path l= eads to os command injection. The attack can be initiated remotely. The exp= loit has been disclosed to the public and may be used. The vendor was conta= cted early about this disclosure but did not respond in any way. This vulne= rability only affects products that are no longer supported by the maintain= er. 2026-07-12 6.3 CVE-2026-15495 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15495 ] SonicCloudOrg--sonic-agent A vulnerability was found in SonicC= loudOrg sonic-agent up to 2.7.2. The impacted element is the function evalI= sFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/s= cript/GroovyScriptImpl.java of the component Groovy Script Handler. The man= ipulation results in os command injection. The attack can be launched remot= ely. The exploit has been made public and could be used. The vendor was con= tacted early about this disclosure but did not respond in any way. This vul= nerability only affects products that are no longer supported by the mainta= iner. 2026-07-12 6.3 CVE-2026-15496 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-15496 ] sovlix--GoodMeet Google Meet Integration for Webinar, Meetin=
g & Video Conference The GoodMeet - Google Meet Integration for Webinar, Me= eting & Video Conference plugin for WordPress is vulnerable to Cross-Site R= equest Forgery in versions up to and including 1.1.8. This is due to a miss= ing nonce verification in the reset_credential() function, which handles th=
e wp_ajax_goodmeet_reset_google_meet_credential AJAX action. While the func= tion does verify the user's capability (manage_options), it does not valida=
te a nonce, making it susceptible to CSRF attacks. This makes it possible f=
or unauthenticated attackers to trick a site administrator into clicking a = malicious link that will reset (delete) the plugin's stored Google Meet API=
credentials (goodmeet_google_credentials) and OAuth tokens (goodmeet_googl= e_token), effectively disabling the Google Meet integration on the site. 20= 26-07-10 4.3 CVE-2026-6440 [
https://www.cve.org/CVERecord?id=3DCVE-2026-64=
40 ] SQLite--SQLite An issue in SQLite before Fossil check-in 869a51ae84df = allows a local attacker to obtain sensitive information via the Session Ext= ension changeset concat/changegroup merge path 2026-07-08 6.1 CVE-2026-5081=
3 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50813 ] starboardsuite--Sta= rboard Suite Reservation Calendars The Starboard Suite Reservation Calendar=
s plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sho= rtcode attributes in the [starboard-suite-lightbox] shortcode in all versio=
ns up to, and including, 3.1.4 due to insufficient input sanitization and o= utput escaping. This makes it possible for authenticated attackers, with Co= ntributor-level access and above, to inject arbitrary web scripts in pages = that will execute whenever a user accesses an injected page. 2026-07-11 6.4=
CVE-2025-13968 [
https://www.cve.org/CVERecord?id=3DCVE-2025-13968 ] stell= arwp--Kadence Blocks Page Builder Toolkit for Gutenberg Editor The Gutenber=
g Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress=
is vulnerable to unauthorized post publication in all versions up to, and = including, 3.5.32 due to a misconfigured capability check on the 'get_items= _permission_check' function permission callback of the 'process_pattern' RE=
ST API endpoint. This makes it possible for authenticated attackers, with C= ontributor-level access and above, to create and immediately publish posts =
of any type (including pages), bypassing the standard WordPress review work= flow where contributors must submit posts for administrator approval. 2026-= 07-10 4.3 CVE-2026-15286 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1528=
6 ] stylemix--Cost Calculator Builder The Cost Calculator Builder plugin fo=
r WordPress is vulnerable to Sensitive Information Exposure in all versions=
up to, and including, 4.0.11 via the (template body). This makes it possib=
le for unauthenticated attackers to extract the plaintext Stripe secret key=
, Razorpay secret key, and PayPal client_secret embedded in the page source=
of any page containing a calculator, enabling full control of the merchant=
's payment gateway accounts. This exposure only occurs when the 'use in all=
calculators' option is enabled for one or more payment gateways in the plu= gin's global settings. 2026-07-11 5.3 CVE-2026-10865 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-10865 ] subratamal--Wallet for WooCommerce The Wall=
et for WooCommerce plugin for WordPress is vulnerable to authorization bypa=
ss in all versions up to, and including, 1.6.4. This is due to the plugin n=
ot properly verifying that a user is authorized to perform an action. This = makes it possible for authenticated attackers, with subscriber-level access=
and above, to enumerate the login name, email address, and user ID of all = WordPress accounts - including administrators - by submitting arbitrary sea= rch terms to the AJAX handler. The required 'search-user' nonce is localize=
d into the wallet_param object on the standard WooCommerce My Account page,=
which is accessible to any authenticated user, making it trivially obtaina= ble by a Subscriber. 2026-07-11 4.3 CVE-2026-12103 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-12103 ] supercleanse--Members Membership & User Role = Editor Plugin The Members - Membership & User Role Editor Plugin plugin for=
WordPress is vulnerable to Sensitive Information Exposure in all versions =
up to, and including, 3.2.22 via the members_filter_protected_posts_for_res=
t. This makes it possible for unauthenticated attackers to extract determin=
e the existence and exact count of access-restricted posts, and use per-pag=
e pagination as a boolean oracle to infer keywords and content contained wi= thin those hidden restricted posts. 2026-07-11 5.3 CVE-2026-12426 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-12426 ] Superior Court of California, = County of Los Angeles--Hearing Reminder Service The Superior Court of Calif= ornia Hearing Reminder Service at
https://www.hrs.courts.ca.gov exposes an = API endpoint that returns court reminder records containing potentially sen= sitive information without authentication. 2026-07-09 5.3 CVE-2026-61344 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-61344 ] surflabtech--SurfLink L= ink Manager & Backup Restore The SurfLink - Ultimate Link Manager plugin fo=
r WordPress is vulnerable to unauthorized data modification due to a missin=
g capability check on the ajax_import_410() function in all versions up to = 2.6.0. This is due to a missing capability check (current_user_can()) and m= issing nonce verification (check_ajax_referer()) in the ajax_import_410() f= unction, while all other AJAX handlers in the same class (ajax_add_single_4= 10, ajax_save_editted_410, ajax_delete_410, ajax_bulk_410_delete, ajax_empt= y_410, ajax_export_410) properly implement both authorization and nonce che= cks. This makes it possible for authenticated attackers, with Subscriber-le= vel access and above, to import arbitrary URLs into the 410 Gone database t= able via the surfl_import_410 AJAX action. Injected URLs will cause the sit=
e to return HTTP 410 Gone responses to all visitors accessing those paths, = potentially causing denial of service for legitimate pages and SEO damage t= hrough search engine delisting. 2026-07-11 4.3 CVE-2026-3552 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-3552 ] SUSE--Rancher Missing filtering when=
the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher=
Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 befo=
re 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials=
(BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml fi= le, allowing attackers able to push to fleet monitored git repos to leak he=
lm access credentials. 2026-07-06 5 CVE-2026-44936 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-44936 ] symfony--ux Symfony UX is a JavaScript ecosys= tem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the=
ux_icon() Twig function is marked is_safe=3D['html'] and Icon::toHtml() in= lines SVG source verbatim, allowing unsanitized local SVG files or Iconify = on-demand JSON body responses containing nested script elements, on* event = handlers, or dangerous URL schemes to execute cross-site scripting. This is= sue is fixed in versions 2.36.1 and 3.2.0. 2026-07-08 6.1 CVE-2026-55877 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-55877 ] Tag plugin--GLPI 11 The=
Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sani= tization and renders it into the Kanban badge markup via PluginTagTag::preK= anbanContent() without output escaping, resulting in stored cross-site scri= pting. An authenticated user with TAG MANAGEMENT create or update rights ca=
n set a tag name containing HTML, which then executes in the browser of any=
user who opens the Kanban view of a ticket, problem, change, or project th=
e tag is attached to. 2026-07-09 6.4 CVE-2026-53987 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-53987 ] the_champ--Social Share, Social Login and So= cial Comments Plugin Super Socializer The Social Share, Social Login and So= cial Comments Plugin - Super Socializer plugin for WordPress is vulnerable =
to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' paramete=
r in all versions up to, and including, 7.14.5 due to insufficient input sa= nitization and output escaping. This makes it possible for unauthenticated = attackers to inject arbitrary web scripts in pages that execute if they can=
successfully trick a user into performing an action such as clicking on a = link. 2026-07-08 6.1 CVE-2026-11798 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-11798 ] themefic--Hydra Booking Appointment Scheduling & Booking Cal= endar The Hydra Booking - Appointment Scheduling & Booking Calendar plugin = for WordPress is vulnerable to Insecure Direct Object Reference in versions=
up to, and including, 1.2.1 via the /wp-json/hydra-booking/v1/booking/deta= ils/{id} REST endpoint. This is due to the getBookingDetails() callback onl=
y enforcing the tfhb_manage_options capability via tfhb_manage_options_perm= ission(), without verifying that the requested booking belongs to the curre= ntly authenticated host (the lookup in getBookingDetailsData() filters sole=
ly on the booking id supplied in the URL). This makes it possible for authe= nticated attackers, with Hydra Host-level access and above (a role created =
by the plugin which grants tfhb_manage_options), to view sensitive booking = records belonging to other hosts, including attendee names, emails, phone n= umbers, addresses, meeting details, payment method and status, transaction = history, and internal notes by iterating booking IDs. 2026-07-09 4.3 CVE-20= 26-12433 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12433 ] themehunk--T=
H Login Registration The Themehunk Login Registration plugin for WordPress =
is vulnerable to privilege escalation in versions up to, and including, 1.0= .2. This is due to the handle_frontend_register() function in the unauthent= icated /thlogin/v1/register REST endpoint accepting a user-controlled 'role=
' parameter and validating it only against get_editable_roles() - which ret= urns every defined editable site role, including 'editor' - before passing =
it to wp_insert_user(). This makes it possible for unauthenticated attacker=
s, when public user registration is enabled, to create new accounts with th=
e editor role. 2026-07-08 6.3 CVE-2026-14250 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-14250 ] themifyme--Themify Builder The Themify Builder plug=
in for WordPress is vulnerable to Stored Cross-Site Scripting via Map Modul=
e 'b_width_map' Field in all versions up to, and including, 7.7.6 due to in= sufficient input sanitization and output escaping. This makes it possible f=
or authenticated attackers, with contributor-level access and above, to inj= ect arbitrary web scripts in pages that will execute whenever a user access=
es an injected page. 2026-07-11 6.4 CVE-2026-15096 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-15096 ] themifyme--Themify Builder The Themify Builde=
r plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'he= ight_slider' Slider Module Field in all versions up to, and including, 7.7.=
6 due to insufficient input sanitization and output escaping. This makes it=
possible for authenticated attackers, with contributor-level access and ab= ove, to inject arbitrary web scripts in pages that will execute whenever a = user accesses an injected page. 2026-07-11 6.4 CVE-2026-15097 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-15097 ] thimpress--WP Hotel Booking The WP=
Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site S= cripting via the 'check_in_date' and 'check_out_date' parameters in all ver= sions up to, and including, 2.3.1 due to insufficient input sanitization an=
d output escaping. This makes it possible for unauthenticated attackers to = inject arbitrary web scripts in pages that execute if they can successfully=
trick a user into performing an action such as clicking on a link. 2026-07= -10 6.1 CVE-2026-11392 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11392 =
] thimpress--WP Hotel Booking The WP Hotel Booking plugin for WordPress is = vulnerable to Insufficient Verification of Data Authenticity in all version=
s up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_= standard()` IPN handler selecting its PayPal validation endpoint from the a= ttacker-controlled `$_REQUEST['test_ipn']` parameter, force-upgrading any `= pending` transaction to `completed` when `test_ipn=3D1`, and omitting post-= verification checks on `receiver_email`, `mc_currency`, and `txn_id` unique= ness after receiving a `VERIFIED` response from PayPal. This makes it possi= ble for unauthenticated attackers to mark arbitrary hotel bookings as fully=
paid without submitting genuine payment to the merchant - either by routin=
g IPN validation through PayPal's sandbox using a free sandbox account, or =
by replaying a previously verified IPN from a nominal payment to an attacke= r-controlled PayPal account. An attacker requires only a free PayPal sandbo=
x account (or any PayPal account) to obtain a `VERIFIED` response; no site = credentials or special configuration are needed. 2026-07-11 5.3 CVE-2026-11= 901 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11901 ] thrivedesk--Agent=
ic Help Desk Plugin for WordPress Live Chat, AI Chatbot & Ticketing ThriveD= esk The ThriveDesk - Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugi=
n for WordPress is vulnerable to unauthorized cache deletion due to a missi=
ng capability check on the 'thrivedesk_clear_cache' AJAX action in all vers= ions up to, and including, 2.1.7. This makes it possible for authenticated = attackers, with Subscriber-level access and above, to clear the plugin's ca= che. 2026-07-11 4.3 CVE-2026-1832 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-1832 ] tibouille--Sudoku Shortcode The Sudoku Shortcode plugin for Wor= dPress is vulnerable to Stored Cross-Site Scripting via the 'background' pa= rameter in the 'sudoku-sc' shortcode in all versions up to, and including, = 1.0.0 due to insufficient input sanitization and output escaping. This make=
s it possible for authenticated attackers, with Contributor-level access an=
d above, to inject arbitrary web scripts in pages that will execute wheneve=
r a user accesses an injected page. 2026-07-10 6.4 CVE-2026-15292 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-15292 ] timstrifler--Exclusive Addons = for Elementor The Exclusive Addons for Elementor plugin for WordPress is vu= lnerable to Stored Cross-Site Scripting via the post title parameter in all=
versions up to, and including, 2.7.9.8 due to insufficient input sanitizat= ion and output escaping. This makes it possible for authenticated attackers=
, with Contributor-level access and above, to inject arbitrary web scripts =
in pages that will execute whenever a user accesses an injected page. 2026-= 07-07 6.4 CVE-2026-11328 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1132=
8 ] tokenoftrust--Age Verification & Identity Verification by Token of Trus=
t The Age Verification & Identity Verification by Token of Trust plugin for=
WordPress is vulnerable to unauthorized access in all versions up to and i= ncluding 4.0.2. This is due to the handle_export_table() function being reg= istered on the WordPress 'init' hook, which fires for all requests, includi=
ng those from unauthenticated visitors, without any capability check. This = makes it possible for unauthenticated attackers to download a CSV file cont= aining sensitive WooCommerce donation data, including order dates, order ID=
s, charitable donation amounts, and admin-only order edit URLs, simply by v= isiting any page on the site with the 'tot_export_table' GET parameter set =
to a numeric value (0-3). 2026-07-09 5.3 CVE-2026-7558 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-7558 ] ToolJet--ToolJet ToolJet is an open-source=
low-code platform for building internal tools. Prior to 3.20.180, ToolJet'=
s render preview deployment workflow interpolates github.event.comment.body=
directly into a bash conditional in a run step, allowing any GitHub user w=
ho can comment on an open pull request with a deploy command to execute she=
ll commands on the CI runner and exfiltrate deployment secrets. This issue =
is reported as fixed in version 3.20.180. 2026-07-08 4.7 CVE-2026-54344 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-54344 ] TOTOLINK--X5000R A vulne= rability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.235= 0_B20230313. Affected by this vulnerability is the function exportOvpn of t=
he file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manip= ulation results in path traversal. The attack may be launched remotely. 202= 6-07-09 5.3 CVE-2026-15204 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15= 204 ] TRENDnet--TEW-821DAP A flaw has been found in TRENDnet TEW-821DAP 1.1= 1B03. The impacted element is the function sub_43F2C4 of the file /goform/t= ools_nslookup of the component DNS Lookup Handler. This manipulation of the=
argument nslookup_target/dns_server causes os command injection. The attac=
k can be initiated remotely. The vendor explains: "We are unable to confirm=
the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these=
items have been EOL. " This vulnerability only affects products that are n=
o longer supported by the maintainer. 2026-07-12 6.3 CVE-2026-15485 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-15485 ] TRENDnet--TEW-821DAP A vulne= rability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the fu= nction sub_42026C of the file /goform/tools_ddns of the component Firmware = Update Handler. Such manipulation of the argument hostname/username/passwor=
d leads to os command injection. The attack can be launched remotely. The v= endor explains: "We are unable to confirm the existence of the vulnerabilit= ies for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulne= rability only affects products that are no longer supported by the maintain= er. 2026-07-12 6.3 CVE-2026-15486 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15486 ] TRENDnet--TEW-821DAP A vulnerability was found in TRENDnet TEW= -821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/s= ystem_ntp of the component Firmware Update Handler. Performing a manipulati=
on of the argument Hostname results in os command injection. The attack may=
be initiated remotely. The vendor explains: "We are unable to confirm the = existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these item=
s have been EOL. " This vulnerability only affects products that are no lon= ger supported by the maintainer. 2026-07-12 6.3 CVE-2026-15487 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-15487 ] trustindex--Widgets for Google Re= views The Widgets for Google Reviews plugin for WordPress is vulnerable to = Stored Cross-Site Scripting via admin settings in all versions up to, and i= ncluding, 13.3 due to insufficient input sanitization and output escaping. = This makes it possible for authenticated attackers, with editor-level permi= ssions and above, to inject arbitrary web scripts in pages that will execut=
e whenever a user accesses an injected page. This only affects multi-site i= nstallations and installations where unfiltered_html has been disabled. 202= 6-07-11 4.4 CVE-2026-11591 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11= 591 ] TryGhost--Ghost Ghost is a Node.js content management system. From 6.= 27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauth= enticated attacker to control donation checkout metadata and obtain full pa=
id gift memberships for a minimal payment without exposing customer or memb=
er data or stealing money from a site or its members. This issue is fixed i=
n version 6.44.0. 2026-07-09 5.3 CVE-2026-59817 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-59817 ] tumf--mcp-text-editor A security vulnerability h=
as been detected in tumf mcp-text-editor up to 1.0.2. This issue affects th=
e function _validate_file_path of the file mcp_text_editor/text_editor.py. = Such manipulation of the argument file_path leads to path traversal. The at= tack can be launched remotely. The exploit has been disclosed publicly and = may be used. The vendor closed the GitHub issue for this vulnerability with= out any explanation. 2026-07-09 6.3 CVE-2026-15138 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-15138 ] Twiser Informatics Technology Consulting, Tra=
de and Education Inc.--OKRs & Goals Improper neutralization of input during=
web page generation ('cross-site scripting') vulnerability in Twiser Infor= matics Technology Consulting, Trade and Education Inc. OKRs & Goals allows = Stored XSS. This issue affects OKRs & Goals: from 28220 before 28398. 2026-= 07-09 5.4 CVE-2026-5005 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5005 =
] u-boot--u-boot U-Boot through 2026.04-rc3 contains an out-of-bounds read = vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is=
enabled, allowing remote attackers to read beyond TCP segment boundaries b=
y crafting a malicious packet with a mismatched IP total length and TCP dat=
a offset field. Attackers can send a packet with an IP total length of 40 b= ytes and a TCP data offset claiming 60 bytes of header to cause tcp_parse_o= ptions() to read 40 bytes past the end of the TCP segment, potentially corr= upting connection state variables such as rmt_win_scale and rmt_timestamp t=
o disrupt TCP window calculations. 2026-07-08 5.3 CVE-2026-29007 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-29007 ] videousermanuals--White Label C=
MS The White Label CMS plugin for WordPress is vulnerable to Stored Cross-S= ite Scripting via admin settings in all versions up to, and including, 2.7.=
12 due to insufficient input sanitization and output escaping. This makes i=
t possible for authenticated attackers, with administrator-level permission=
s and above, to inject arbitrary web scripts in pages that will execute whe= never a user accesses an injected page. This only affects multi-site instal= lations and installations where unfiltered_html has been disabled. 2026-07-=
11 4.4 CVE-2026-11898 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11898 ]=
Vinchin--Backup & Recovery 9.0 Vinchin Backup & Recovery through 9.0.0.865=
62 contains a heap buffer overflow vulnerability that allows unauthenticate=
d remote attackers to cause process crash or memory corruption by sending a=
malformed TCP packet with an unchecked body_len field to the agentlink_ser= ver service. Attackers can craft a malicious packet that passes an attacker= -controlled length directly to recv(), triggering a heap overflow of up to = approximately 4 GiB and resulting in process crash or potential memory corr= uption. 2026-07-09 6.5 CVE-2026-60094 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-60094 ] Vinchin--Backup & Recovery 9.0 Vinchin Backup & Recovery t= hrough 9.0.0.86562 contains a stack buffer overflow vulnerability in the Mo= duleHandShake function of the agentlink_server service that allows unauthen= ticated remote attackers to overwrite the saved return address by supplying=
an oversized _listen_uuid field that is measured via strlen() and copied w= ithout bounds checking into a fixed-length stack buffer using strcpy(). Att= ackers can send a crafted request with a malicious _listen_uuid value to co= rrupt the stack and achieve process crash or potential control flow hijack = without requiring authentication. 2026-07-09 6.5 CVE-2026-60095 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-60095 ] vllm-project--vllm vLLM is an in= ference and serving engine for large language models. From 0.22.0 to 0.23.0=
, the /v1/audio/transcriptions and /v1/audio/translations routes call reque= st.file.read() to fully materialize an uploaded audio file into memory befo=
re vLLM checks the documented VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed up= load size limit (default 25 MB) later in the speech-to-text preprocessing s= tep, so an API caller who can reach those routes can submit an oversized mu= ltipart upload and cause vLLM to allocate memory proportional to the upload=
ed file size before the request is rejected as too large, creating memory p= ressure or terminating the process depending on deployment resource limits.=
This issue is fixed in version 0.24.0. 2026-07-06 6.5 CVE-2026-55646 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-55646 ] vxcontrol--PentAGI A vulne= rability was identified in vxcontrol PentAGI up to 2.1.0. This affects an u= nknown function of the file backend/pkg/docker/client.go of the component D= ocker API. The manipulation leads to sandbox issue. The attack may be initi= ated remotely. The pull request to fix this issue awaits acceptance. 2026-0= 7-06 6.3 CVE-2026-14784 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14784=
] Wavlink--WL-NU516U1 A security flaw has been discovered in Wavlink WL-NU= 516U1 260515. This affects the function wlink_uci_set_value of the file /cg= i-bin/adm.cgi. Performing a manipulation of the argument lan_ip results in =
os command injection. The attack can be initiated remotely. The exploit has=
been released to the public and may be used for attacks. You should upgrad=
e the affected component. The vendor was contacted early, responded in a ve=
ry professional manner and quickly released a fixed version of the affected=
product. 2026-07-12 6.3 CVE-2026-15513 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15513 ] Wazuh--Wazuh Wazuh wazuh-modulesd before 5.0.0-beta3 co= ntains a null pointer dereference vulnerability in inventory_sync FlatBuffe=
r DataValue handling. An enrolled agent can send a verifier-valid DataValue=
message omitting the optional id field, causing wazuh-modulesd to crash wh=
en dereferencing data->id()->string_view() without null validation, resulti=
ng in denial of service. 2026-07-08 6.5 CVE-2026-56401 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-56401 ] wclovers--WCFM Frontend Manager for WooCo= mmerce The WCFM - Frontend Manager for WooCommerce plugin for WordPress is = vulnerable to authorization bypass in all versions up to, and including, 6.= 7.27. This is due to the plugin not properly verifying that a user is autho= rized to perform an action. This makes it possible for unauthenticated atta= ckers to inject arbitrary reply content into any store inquiry, overwrite t=
he main inquiry record in wp_wcfm_enquiries, and trigger unsolicited notifi= cation emails to customers and vendors. Unlike sibling controller branches = (wcfm-enquiry and wcfm-enquiry-manage), the wcfm-my-account-enquiry-manage = branch performs no is_user_logged_in() or current_user_can() check, and the=
nonce that serves as the sole barrier is embedded into every public page l= oad without any login gate. 2026-07-11 5.3 CVE-2026-12994 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-12994 ] wclovers--WCFM Frontend Manager for Wo= oCommerce The WCFM - Frontend Manager for WooCommerce plugin for WordPress =
is vulnerable to Insecure Direct Object Reference in all versions up to, an=
d including, 6.7.27 via the wcfm_product_archive due to missing validation =
on a user controlled key. This makes it possible for authenticated attacker=
s, with subscriber-level access and above, to archive arbitrary vendors' pr= oducts, toggle the featured status on arbitrary listings, mark arbitrary Wo= oCommerce orders as completed, and permanently delete arbitrary enquiries a=
nd bulk messages belonging to other vendors. 2026-07-11 4.3 CVE-2026-10041 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-10041 ] wclovers--WCFM Market= place Multivendor Marketplace for WooCommerce The WCFM Marketplace - Multiv= endor Marketplace for WooCommerce plugin for WordPress is vulnerable to Sto= red Cross-Site Scripting via Attachment 'post_title' in all versions up to,=
and including, 3.7.3 due to insufficient input sanitization and output esc= aping. This makes it possible for authenticated attackers, with Vendor-leve=
l access and above, to inject arbitrary web scripts in pages that will exec= ute whenever a user accesses an injected page. An attacker can plant the pa= yload by uploading a media attachment with a crafted title via the WordPres=
s REST API (/wp-json/wp/v2/media), without ever invoking the AJAX endpoint = themselves, as the unescaped title is later emitted inside DataTables JSON = and inserted as innerHTML upon any privileged user loading the media dashbo= ard. 2026-07-11 6.4 CVE-2026-12126 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-12126 ] wealcoder--Animation Addons for Elementor GSAP Motion Element=
or Addons & Website Templates The Animation Addons for Elementor plugin for=
WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_st= yle' and 'move_direction' parameters of the Weather widget in all versions =
up to, and including, 2.6.3. This is due to insufficient output escaping in=
the Weather widget's render() function at widgets/weather.php:1246, where = both settings values are placed into an HTML class attribute without esc_at= tr(). Elementor does not server-side validate widget SELECT control values = against allowed options on save, so an authenticated attacker with Contribu= tor-level access or above can submit a crafted save_builder AJAX request st= oring arbitrary values in the _elementor_data post meta. The stored payload=
renders unescaped on every frontend visit to the affected page (the Weathe=
r widget requires an OpenWeatherMap API key to reach the vulnerable output,=
which is the normal operational state for sites using this widget). 2026-0= 7-10 6.4 CVE-2026-15299 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15299=
] web-infra-dev--midscene Midscene Bridge Server through 1.10.3, fixed in = commit 86f4118, contains a missing authentication and CORS misconfiguration=
vulnerability that allows unauthenticated remote attackers to hijack activ=
e bridge sessions by opening a cross-origin WebSocket connection to the loc=
al Socket.IO server, which performs no Origin header validation and require=
s no authentication token. Attackers can connect from any web page visited =
by the victim to seize the single-client slot, intercept and inject automat= ion commands, exfiltrate command-payload data, or unconditionally terminate=
the server by supplying the MIDSCENE_BRIDGE_SIGNAL_KILL query parameter. 2= 026-07-08 6.8 CVE-2026-59804 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 59804 ] webaways--NEX-Forms Ultimate Forms Plugin for WordPress The NEX-For=
ms - Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable=
to authorization bypass in all versions up to, and including, 9.2.2. This =
is due to the plugin not properly verifying that a user is authorized to pe= rform an action. This makes it possible for unauthenticated attackers to ov= erwrite the saved_admin_email, saved_user_email, and saved_user_email_addre=
ss fields of arbitrary form entries belonging to other users, and cause the=
site to dispatch attacker-controlled email content to attacker-chosen reci= pient addresses. 2026-07-11 5.3 CVE-2026-9017 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-9017 ] Webbeyaz Web Design--Medikm Web Improper neutraliza= tion of input during web page generation ('cross-site scripting') vulnerabi= lity in Webbeyaz Web Design Medik=C3=83=C2=BCm Web allows Reflected XSS. Th=
is issue affects Medik=C3=83=C2=BCm Web: through 08072026.=C2=A0NOTE: The v= endor was contacted and it was learned that the product is not supported. 2= 026-07-08 6.1 CVE-2026-8310 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 310 ] Webbeyaz Web Design--Medikm Web Improper neutralization of input duri=
ng web page generation ('cross-site scripting') vulnerability in Webbeyaz W=
eb Design Medik=C3=83=C2=BCm Web allows Stored XSS. This issue affects Medi= k=C3=83=C2=BCm Web: through 08072026.=C2=A0NOTE: The vendor was contacted a=
nd it was learned that the product is not supported. 2026-07-08 5.4 CVE-202= 6-8315 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8315 ] WebFactory--Und=
er Construction Page (Pro) The UnderConstructionPage PRO plugin for WordPre=
ss is vulnerable to Arbitrary File Read in all versions up to, and includin=
g, 5.76. This is due to the plugin accepting arbitrary local file paths in = the template_thumbnail parameter and copying their contents into a publicly=
accessible uploads file. This makes it possible for authenticated attacker=
s, with Subscriber-level access and above, to read arbitrary files on the s= erver, which can contain sensitive information. 2026-07-11 6.5 CVE-2026-114=
26 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11426 ] Webkul--Bagisto Ba= gisto before 2.4.4 contains a stored cross-site scripting vulnerability via=
client-side template injection that allows unauthenticated attackers to ex= ecute arbitrary JavaScript in administrator browsers by registering a custo= mer account with malicious payload in the first or last name field. The cre= ate.blade.php template renders customer name fields without the Vue.js v-pr=
e directive, causing Vue.js to evaluate stored template expressions as live=
JavaScript when an administrator opens the Create Order page for the affec= ted customer. 2026-07-09 5.4 CVE-2026-60120 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-60120 ] Webremium Istanbul Web Design--Mezunum Satiyorum Imp= roper neutralization of input during web page generation ('cross-site scrip= ting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum all= ows Stored XSS. This issue affects Mezunum Satiyorum: from 1.2.504 through = 10072026.=C2=A0NOTE: The vendor was contacted early about this disclosure b=
ut did not respond in any way. 2026-07-10 6.4 CVE-2026-3251 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-3251 ] wedevs--ERP: Complete HR, Accounting =
& CRM Suite Built for WooCommerce The ERP: Complete HR, Accounting & CRM Su= ite with Recruitment and WooCommerce CRM Support plugin for WordPress is vu= lnerable to generic SQL Injection via the 'orderby' parameter in all versio=
ns up to, and including, 1.17.5 due to insufficient escaping on the user su= pplied parameter and lack of sufficient preparation on the existing SQL que= ry. This makes it possible for authenticated attackers, with custom-level a= ccess and above, to append additional SQL queries into already existing que= ries that can be used to extract sensitive information from the database. E= xploitation requires the erp_list_employee capability, which is granted to =
HR Manager-level users and above within the WP ERP plugin. 2026-07-09 6.5 C= VE-2026-13011 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13011 ] wedevs-= -User Frontend: AI Powered Frontend Posting, User Directory, Profile Builde=
r, Membership & User Registration The User Frontend: AI Powered Frontend Po= sting, User Directory, Profile, Membership & User Registration plugin for W= ordPress is vulnerable to authorization bypass in all versions up to, and i= ncluding, 4.3.7. This is due to the plugin not properly verifying that a us=
er is authorized to perform an action. This makes it possible for unauthent= icated attackers to delete arbitrary media attachments whose post_author is=
0, such as guest and registration-form uploads, via the wpuf_file_del AJAX=
action. This is exploitable by unauthenticated visitors on any site where =
a WPUF shortcode is rendered on a front-end page, as this causes the valid = wpuf_nonce value to be localized into publicly accessible JavaScript object=
s (wpuf_upload and wpuf_frontend), satisfying the sole access control gate.=
2026-07-09 5.3 CVE-2026-12406 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-12406 ] wedevs--User Frontend: AI Powered Frontend Posting, User Director=
y, Profile Builder, Membership & User Registration The User Frontend: AI Po= wered Frontend Posting, User Directory, Profile, Membership & User Registra= tion plugin for WordPress is vulnerable to Insecure Direct Object Reference=
in all versions up to, and including, 4.3.7 via the 'wpuf_files_data' para= meter due to missing validation on a user controlled key. This makes it pos= sible for unauthenticated attackers to overwrite the post_title, post_conte= nt, and post_excerpt of any arbitrary post on the site, including posts aut= hored by administrators. Exploitation requires access to any WPUF post subm= ission form; this is achievable by users with no WordPress role, as the wpu= f_submit_post AJAX action is gated only by a nonce with no capability check=
for the downstream post-edit operation. 2026-07-09 5.3 CVE-2026-12418 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-12418 ] wedevs--User Frontend: AI=
Powered Frontend Posting, User Directory, Profile Builder, Membership & Us=
er Registration The User Frontend: AI Powered Frontend Posting, User Direct= ory, Profile, Membership & User Registration plugin for WordPress is vulner= able to Insecure Direct Object Reference in all versions up to, and includi= ng, 4.3.1 via the payment_page() function due to missing validation on the = 'user_id' user controlled key. This makes it possible for unauthenticated a= ttackers to activate a free subscription pack for any user on the site, ove= rwriting their existing paid subscription and causing loss of paid features=
. 2026-07-08 5.3 CVE-2026-5459 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-5459 ] wekan--wekan Wekan is open source kanban built with Meteor. Prior =
to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor = collection allow rules for Checklists and ChecklistItems because updates ar=
e authorized only against the current source doc.cardId and do not inspect = the destination cardId or boardId in the update modifier, allowing a low-pr= ivileged authenticated user with write access to one board and knowledge of=
a target private card id to create checklist data on an accessible card an=
d move it into a private board where they are not a member. This issue is f= ixed in version 9.64. 2026-07-10 4.3 CVE-2026-59154 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-59154 ] widgetpack--Reviews Widgets for Google, Trip= Advisor, Yelp & Recommendations The Reviews Widgets for Google, Yelp & Trip= Advisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting v=
ia the 'page_id' shortcode attribute of the [fbrev] shortcode in versions u=
p to and including 2.7.3. This is due to insufficient input sanitization an=
d output escaping in the Feed_Shortcode::fbrev() method, which passes the r=
aw shortcode attribute through Feed_Old::get_feed() into the View::render()=
method, where it is echoed directly into the data-id HTML attribute withou=
t esc_attr(). This makes it possible for authenticated attackers, with cont= ributor-level access and above, to inject arbitrary web scripts in pages th=
at will execute whenever a user accesses an injected page. 2026-07-06 6.4 C= VE-2026-12154 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12154 ] Wiresha=
rk Foundation--ciscodump Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4= .16 allows denial of service 2026-07-08 5.5 CVE-2026-15164 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-15164 ] Wireshark Foundation--Wireshark Multi= ple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0=
to 4.4.16 allow denial of service 2026-07-08 5.5 CVE-2026-15163 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-15163 ] Wireshark Foundation--Wireshark=
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of servi=
ce 2026-07-08 5.5 CVE-2026-15165 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-15165 ] Wireshark Foundation--Wireshark IEEE 802.11 protocol dissector = crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of serv= ice 2026-07-08 5.5 CVE-2026-15166 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15166 ] Wireshark Foundation--Wireshark UMTS FP protocol dissector cra=
sh in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service=
2026-07-08 5.5 CVE-2026-15169 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-15169 ] Wireshark Foundation--Wireshark Z39.50 protocol dissector crash i=
n Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service 202= 6-07-08 5.5 CVE-2026-15170 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15= 170 ] Wireshark Foundation--Wireshark SSH protocol dissector crash in Wires= hark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service 2026-07-08=
5.5 CVE-2026-15171 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15171 ] W= ireshark Foundation--Wireshark FMP/NOTIFY protocol dissector crash in Wires= hark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service 2026-07-08=
5.5 CVE-2026-15172 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15172 ] W= ireshark Foundation--Wireshark Catapult DCT2000 protocol dissector crash in=
Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service 2026= -07-08 5.5 CVE-2026-15174 [
https://www.cve.org/CVERecord?id=3DCVE-2026-151=
74 ] Wireshark Foundation--Wireshark pcapng file parser crash in Wireshark = 4.6.0 to 4.6.6 allows denial of service 2026-07-08 4.7 CVE-2026-15173 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-15173 ] wpdevart--Booking calendar=
, Appointment Booking System The Booking calendar, Appointment Booking Syst=
em plugin for WordPress is vulnerable to time-based SQL Injection via the '= wpdevart_id' parameter in all versions up to, and including, 3.2.17 due to = insufficient escaping on the user supplied parameter and lack of sufficient=
preparation on the existing SQL query. This makes it possible for unauthen= ticated attackers to append additional SQL queries into already existing qu= eries that can be used to extract sensitive information from the database. =
In order to exploit the vulnerability, the Pro version of the plugin must b=
e installed and activated, with the 'Delete previous dates' option checked.=
2026-07-10 5.9 CVE-2026-15289 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-15289 ] wpdevteam--BetterDocs AI Documentation, Knowledge Base, Docs, Wik= is, FAQ with Chatbot The BetterDocs - AI Documentation, Knowledge Base, Doc=
s, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQ=
L Injection via the 'lang' parameter in all versions up to, and including, = 4.6.0 due to insufficient escaping on the user supplied parameter and lack =
of sufficient preparation on the existing SQL query. This makes it possible=
for authenticated attackers, with custom-level access and above, to append=
additional SQL queries into already existing queries that can be used to e= xtract sensitive information from the database. Exploitation requires a sup= ported multilingual plugin (WPML, Polylang, qTranslate, Weglot, or Translat= ePress) to be active on the site, as the vulnerable code path is gated by H= elper::is_multilingual_active(). 2026-07-10 6.5 CVE-2026-15104 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-15104 ] wpdevteam--Essential Addons for E= lementor Popular Elementor Templates & Widgets The Essential Addons for Ele= mentor - Popular Elementor Templates & Widgets plugin for WordPress is vuln= erable to Stored Cross-Site Scripting via the Event Calendar widget in all = versions up to, and including, 6.6.2 due to insufficient input sanitization=
and output escaping on event titles sourced from The Events Calendar. This=
makes it possible for authenticated attackers, with Author-level access an=
d above, to inject arbitrary web scripts in pages that will execute wheneve=
r a user accesses an injected page. 2026-07-08 6.4 CVE-2026-6459 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-6459 ] wpkuf--Wp Js Detect The Wp Js De= tect plugin for WordPress is vulnerable to Cross-Site Request Forgery in al=
l versions up to, and including, 1.0.9. This is due to missing or incorrect=
nonce validation on the plugin_settings function. This makes it possible f=
or unauthenticated attackers to update the plugin's notification text and C=
SS settings (wp_non_js_notification_text and wp_non_js_notification_css), i= njecting arbitrary content that is echoed unescaped on the frontend via a f= orged request granted they can trick a site administrator into performing a=
n action such as clicking on a link. 2026-07-08 4.3 CVE-2026-9731 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-9731 ] wplegalpages--Cookie Banner for=
GDPR / CCPA WPLP Cookie Consent The GDPR Cookie Consent plugin for WordPre=
ss is vulnerable to unauthorized modification of data due to a missing capa= bility check and missing nonce verification on the gdpr_cookie_consent_ajax= _save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX act= ion) in versions up to, and including, 4.3.6. This makes it possible for au= thenticated attackers, with Subscriber-level access and above, to modify th=
e plugin's cookie scan schedule configuration stored in the gdpr_scan_sched= ule_data option, which is an administrative function intended to be limited=
to users with the manage_options capability. 2026-07-10 4.3 CVE-2026-12955=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12955 ] wplegalpages--Cookie=
Banner for GDPR / CCPA WPLP Cookie Consent The Cookie Banner for GDPR / CC=
PA - WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL = Injection via the 'scan_id' parameter in all versions up to, and including,=
4.3.6 due to insufficient escaping on the user supplied parameter and lack=
of sufficient preparation on the existing SQL query. This makes it possibl=
e for authenticated attackers, with administrator-level access and above, t=
o append additional SQL queries into already existing queries that can be u= sed to extract sensitive information from the database. 2026-07-10 4.9 CVE-= 2026-14475 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14475 ] wpmanageni= nja--Fluent Forms Customizable Contact Forms, Survey, Quiz, & Conversationa=
l Form Builder The Fluent Forms plugin for WordPress is vulnerable to incor= rect authorization via the 'subscription_id' parameter in versions up to, a=
nd including, 6.2.1. This is due to insufficient ownership authorization ch= ecks in the payment cancellation AJAX flow. This makes it possible for auth= enticated attackers, with subscriber-level access and above, to submit canc= ellation requests for other users' subscriptions. 2026-07-10 5.4 CVE-2026-5= 069 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5069 ] wpovernight--PDF I= nvoices & Packing Slips for WooCommerce The PDF Invoices & Packing Slips fo=
r WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object = Reference in all versions up to, and including, 5.14.0 via the generate_doc= ument_shortcode due to missing validation on a user controlled key. This ma= kes it possible for authenticated attackers, with contributor-level access = and above, to mint publicly accessible, session-free download links for arb= itrary third-party orders, exposing customer names, billing and shipping ad= dresses, email addresses, phone numbers, order and invoice numbers, line it= ems, totals, payment details, and customer notes contained in those orders'=
invoices and packing slips. Exploitation requires the plugin's Document li=
nk access type setting to be configured to 'full'; with the default 'logged= _in' value, generated URLs are signed with a per-session nonce rather than = the order_key, making the shortcode path unexploitable for unauthorized acc= ess to third-party orders. 2026-07-11 4.3 CVE-2026-13116 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-13116 ] wpswings--Points and Rewards for WooCom= merce The Points and Rewards for WooCommerce plugin for WordPress is vulner= able to authorization bypass in all versions up to, and including, 2.10.0. = This is due to the plugin not properly verifying that a user is authorized =
to perform an action. This makes it possible for authenticated attackers, w= ith subscriber-level access and above, to convert and drain any user's rewa=
rd points into wallet balance, exfiltrate all users' emails and point balan= ces to an attacker-controlled Klaviyo account, overwrite the site's Klaviyo=
public API key, block or unblock arbitrary users from the points system, a=
nd modify campaign banner and heading settings. The nonce used for authenti= cation of these requests (wps-wpr-verify-nonce) is injected into every publ= ic-facing page via wp_localize_script(), and the wps_wpr_generate_custom_wa= llet handler is additionally registered on the wp_ajax_nopriv_ hook, meanin=
g unauthenticated visitors can also obtain a valid nonce and exploit that s= pecific action. 2026-07-11 4.3 CVE-2026-10628 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-10628 ] wpvividplugins--WPvivid Backup for MainWP The WPvi= vid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Si=
te Scripting via admin settings in all versions up to, and including, 0.9.3=
3 due to insufficient input sanitization and output escaping. This makes it=
possible for authenticated attackers, with administrator-level permissions=
and above, to inject arbitrary web scripts in pages that will execute when= ever a user accesses an injected page. This only affects multi-site install= ations and installations where unfiltered_html has been disabled. 2026-07-1=
0 4.4 CVE-2026-15283 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15283 ] = wpxpo--Post Grid Gutenberg Blocks PostX The Ultimate Post plugin for WordPr= ess is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' = block attribute of the ultimate-post/advanced-search block in versions up t=
o and including 5.0.31. This is due to insufficient input sanitization and = output escaping in the Advanced_Search::content() render callback: the attr= ibute value is filtered with wp_kses(), which strips disallowed HTML tags b=
ut does NOT escape HTML special characters such as double quotes in plain t= ext, and the result is then concatenated directly into the data-viewmoretex=
t HTML attribute without esc_attr(). This makes it possible for authenticat=
ed attackers, with contributor-level access and above, to inject arbitrary = web scripts in pages that will execute whenever a user accesses an injected=
page. 2026-07-09 6.4 CVE-2026-13253 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-13253 ] WSO2--WSO2 Identity Server The software accepts user-suppli=
ed input via a URL parameter without adequate output encoding before reflec= ting it back to the user's browser. This condition allows an attacker to in= ject malicious script content into pages served by the application. By leve= raging this weakness, an attacker can cause the user's browser to redirect =
to a malicious website, modify the UI of the webpage, or retrieve informati=
on from the browser. However, the impact is mitigated by the use of httpOnl=
y flags on session-related cookies, preventing session hijacking. 2026-07-0=
6 6.1 CVE-2025-8591 [
https://www.cve.org/CVERecord?id=3DCVE-2025-8591 ] wu= psales--AI Copilot Content Generator The AI Chatbot & Workflow Automation b=
y AIWU plugin for WordPress is vulnerable to Missing Authorization in all v= ersions up to, and including, 1.4.12. This is due to missing capability che= cks and nonce verification on AJAX actions registered under both wp_ajax_ a=
nd wp_ajax_nopriv_ hooks, as the base controller's getPermissions() returns=
an empty array and neither removeGroup nor clear are added to getNoncedMet= hods(), causing the authorization gate to unconditionally return true for t= hese actions. This makes it possible for unauthenticated attackers to delet=
e specific records by ID or delete all records from any module's database t= able by unauthenticated attackers. 2026-07-11 5.3 CVE-2026-6803 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-6803 ] wupsales--AI Copilot Content Gene= rator The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is = vulnerable to authorization bypass in all versions up to, and including, 1.= 4.12. This is due to the plugin not properly verifying that a user is autho= rized to perform an action. This makes it possible for unauthenticated atta= ckers to publish draft WordPress posts, exposing unpublished content, or un= publish live content, causing service disruption, by supplying arbitrary sc= enario IDs. 2026-07-11 5.3 CVE-2026-6804 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-6804 ] YzmCMS--YzmCMS A security vulnerability has been detecte=
d in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp= /yzmphp.php of the component Header Handler. The manipulation of the argume=
nt HTTP_HOST leads to cross site scripting. The attack may be initiated rem= otely. The exploit has been disclosed publicly and may be used. The vendor = was contacted early about this disclosure but did not respond in any way. 2= 026-07-09 4.3 CVE-2026-15202 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 15202 ] zephyrproject--zephyr The Bluetooth BAP Broadcast Assistant GATT cl= ient in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote=
Broadcast Receive State data into a single file-static net_buf_simple (att= _buf, BT_ATT_MAX_ATTRIBUTE_LEN =3D 512 bytes) shared by all connection inst= ances, while the BUSY flag, long-read handle, and reset/offset state were p= er-connection. When the device acts as a Broadcast Assistant connected to m= ultiple Scan Delegator peripherals, notification and long-read callbacks fr=
om different connections interleave on the shared buffer: the append in not= ify_handler (net_buf_simple_add_mem at the not-busy branch) performs no tai= lroom check, so receive-state notifications from two or more delegators acc= umulate on the same 512-byte buffer and, with a sufficiently large configur=
ed ATT MTU (BT_L2CAP_TX_MTU up to 2000) and two-to-three concurrent connect= ions, write past the buffer into adjacent .bss (net_buf_simple_add only ass= erts in debug builds). Even below the overflow threshold, one connection's = net_buf_simple_reset zeroes the shared length while another connection's re= assembly and GATT read offset are in flight, mixing one peer's data into an= other's parse. A malicious or compromised Scan Delegator (or two colluding = peers) over BLE can trigger this, causing out-of-bounds writes (memory corr= uption / denial of service) and cross-connection data corruption. The fix m= oves the buffer into the per-connection instance struct so each connection = reassembles into its own buffer. Affects Zephyr releases shipping the Broad= cast Assistant with the shared buffer, including v4.4.0 and earlier. 2026-0= 7-11 6.4 CVE-2026-10660 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10660=
] zephyrproject--zephyr In Zephyr's experimental USB host stack (CONFIG_US= B_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) fre=
ed the root usb_device slab object without clearing the cached pointer ctx-= >root. The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_= core.c) decides what to tear down solely from ctx->root, checking only that=
it is non-NULL. Because UHC controller drivers (e.g. uhc_max3421e, uhc_mcu= x_common) synthesize UHC_EVT_DEV_REMOVED directly from physical bus line st= ate with no debounce or state guard, an attacker with physical USB access (=
or a rogue device that bounces its connection) can deliver a second device-= removed event after a root device disconnect. The handler then re-enters us= bh_device_disconnect() with the dangling pointer, locking a mutex inside th=
e freed object (use-after-free), removing the freed node from the device li= st, and calling k_mem_slab_free() on the already-freed block (double-free).=
If the slab block has been reissued to a newly attached device in between,=
this corrupts a live object. Impact is denial of service (crash) and memor=
y corruption; the attack vector is physical/local. The flaw was introduced =
in v4.4.0 by the connect/disconnect refactor and is fixed by clearing ctx->= root in usbh_device_disconnect() before freeing. 2026-07-12 6.1 CVE-2026-10= 663 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10663 ] zephyrproject--ze= phyr The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_= get_power_save_info() in drivers/wifi/nrf_wifi/src/wifi_mgmt.c copied TWT (= Target Wake Time) flow entries from an nrf_wifi_umac_event_power_save_info = event into the fixed-size twt_flows[WIFI_MAX_TWT_FLOWS] (8-element) array o=
f a caller-supplied struct wifi_ps_config, looping over event-provided num_= twt_flows without validating it against WIFI_MAX_TWT_FLOWS or checking even= t_len. When num_twt_flows exceeds 8, the handler writes past the destinatio=
n array (which is typically on the caller's stack, e.g. the wifi ps shell c= ommand) -- an out-of-bounds write of ~40-byte TWT entries -- and reads twt_= flow_info[i] past the event buffer. The event is delivered by the nRF70 co-= processor firmware in response to a host-initiated power-save GET, so reach= ing the overflow requires the firmware to emit a malformed or out-of-range = event; the trust boundary is host-to-trusted-coprocessor rather than a dire=
ct remote-AP write, with over-the-air influence on the flow count being ind= irect and bounded by the 3-bit TWT flow-id space. Affected: builds with CON= FIG_NRF70_STA_MODE on releases through v4.4.0. The fix rejects events with = num_twt_flows > WIFI_MAX_TWT_FLOWS or with event_len shorter than the claim=
ed entries, and adds a NULL check on the caller buffer. 2026-07-12 5 CVE-20= 26-10664 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10664 ] zephyrprojec= t--zephyr The Dhara flash translation layer disk driver (drivers/disk/ftl_d= hara.c) implemented the dhara_nand_ callbacks so that, on a flash error, th=
e error code was written unconditionally through the caller-supplied dhara_= error_t err pointer (e.g. *err =3D DHARA_E_ECC in dhara_nand_read, and simi= lar in dhara_nand_erase/prog/copy). The upstream Dhara library calls these = callbacks with err =3D=3D NULL along its journal-resume binary search: find= _last_checkblock() invokes find_checkblock(j, mid, &found, NULL), which for= wards the NULL pointer into dhara_nand_read(). This path runs during disk_f= tl_access_init() -> dhara_map_resume() whenever the FTL disk is mounted/ini= tialised. If a flash read error (uncorrectable ECC, bad block, controller e= rror) occurs on one of the probed checkpoint pages, the driver dereferences=
and writes to NULL, faulting the kernel (denial of service). The trigger i=
s conditioned on the NAND medium content/health, which can be influenced by=
media wear, induced faults, or a corrupted/crafted on-flash image. The fix=
routes all error assignments through the library's NULL-safe dhara_set_err= or() helper. Affects Zephyr v4.4.0, where the driver was introduced. 2026-0= 7-07 4.7 CVE-2026-10659 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10659=
] zhayujie--CowAgent A security flaw has been discovered in zhayujie CowAg= ent up to 2.1.0. The impacted element is an unknown function of the file ch= annel/channel.py of the component Message Endpoint. The manipulation result=
s in missing authorization. The attack may be launched remotely. The exploi=
t has been released to the public and may be used for attacks. The project = was informed of the problem early through an issue report but has not respo= nded yet. 2026-07-10 6.3 CVE-2026-15332 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15332 ] zhayujie--CowAgent A vulnerability was identified in zh= ayujie CowAgent up to 2.1.0. The affected element is the function _add_url/= _add_package of the file agent/skills/service.py of the component Skill Ins= tallation Handler. The manipulation of the argument Name leads to path trav= ersal. The attack may be initiated remotely. Upgrading to version 2.1.2 is = sufficient to fix this issue. The identifier of the patch is e85290cddcbb5f= fc9c235927f4c92e5b4c3ec264. It is advisable to upgrade the affected compone= nt. 2026-07-10 5.4 CVE-2026-15331 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15331 ] zhayujie--CowAgent A vulnerability was found in zhayujie CowAg= ent up to 2.1.0. This issue affects the function BrowserTool._do_navigate o=
f the file agent/tools/browser/browser_tool.py of the component Browser Too=
l. Performing a manipulation results in information disclosure. The attack = can be initiated remotely. The exploit has been made public and could be us= ed. The project was informed of the problem early through an issue report b=
ut has not responded yet. 2026-07-10 4.3 CVE-2026-15329 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-15329 ] zitadel--zitadel ZITADEL is an open sour=
ce identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's exte= rnal JWT Identity Provider validates a token's signature and issuer (iss) b=
ut not the audience (aud) claim, allowing a validly signed token from a tru= sted issuer for another relying party to be accepted by ZITADEL. This issue=
is fixed in versions 3.4.12 and 4.15.2. 2026-07-10 4.2 CVE-2026-55669 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-55669 ] zitadel--zitadel ZITADEL =
is an open source identity management platform. Prior to 3.4.12 and 4.15.2,=
ZITADEL's external JWT Identity Provider validation in internal/idp/provid= ers/jwt/session.go skips the maximum token age freshness check when an inco= ming token omits the iat claim, allowing arbitrarily old tokens from a trus= ted issuer to pass authentication. This issue is fixed in versions 3.4.12 a=
nd 4.15.2. 2026-07-10 4.2 CVE-2026-56664 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56664 ] zitadel--zitadel ZITADEL is an open source identity man= agement platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source ide= ntity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc=
.1 through 4.15.1, ZITADEL's external JWT Identity Provider validation in i= nternal/idp/providers/jwt/session.go skips expiration handling when an inco= ming token omits the exp claim, allowing a token from a trusted issuer to b=
e treated as valid without an automatic expiration window. This issue is fi= xed in versions 3.4.12 and 4.15.2. 2026-07-10 4.2 CVE-2026-56665 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-56665 ] zitadel--zitadel ZITADEL is an = open source identity management platform. Prior to 4.15.3, ZITADEL's extern=
al identity provider handler checks that the local user's email is verified=
but does not verify that the external IdP confirmed ownership of the same = email before auto-linking by email, allowing a permissive provider account = with a victim email address to be linked to the victim's local account. Thi=
s issue is fixed in version 4.15.3. 2026-07-10 4.8 CVE-2026-56666 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-56666 ]=20
Back to top [ #top ]
Low Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info Akpali9--Att= endance-Management-System A vulnerability was detected in Akpali9 Attendanc= e-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This is= sue affects some unknown processing of the file absent.php. Performing a ma= nipulation of the argument export_date results in cross site scripting. It =
is possible to initiate the attack remotely. This product is using a rollin=
g release to provide continious delivery. Therefore, no version details for=
affected nor updated releases are available. The vendor was contacted earl=
y about this disclosure but did not respond in any way. 2026-07-12 3.5 CVE-= 2026-15493 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15493 ] Black Lant= ern Security--BBOT BBOT's unarchive module rejects archives containing syml= ink entries before extraction, but for zip and 7z archives it failed to det= ect symlinks whose listing carries a DOS-attribute prefix before the unix m= ode, as produced by legacy versions of p7zip. Such an archive, downloaded a=
nd extracted during a scan (for example via filedownload), bypassed the gua=
rd and caused an attacker-controlled symlink to be written into the extract= ion directory. The effect is limited to planting the symlink (its target is=
not written through), and only hosts using such a legacy p7zip build are a= ffected; current mainline 7-Zip is not. 2026-07-08 3.1 CVE-2026-14966 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-14966 ] Black Lantern Security--BB=
OT BBOT's `github_workflows` module could be induced to write a downloaded = artifact outside its configured output directory: its path-containment chec=
k did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse o=
ut of the intended folder. The write is bounded to two directory levels abo=
ve the output location and its target is determined by the operator's confi= guration, not the attacker. 2026-07-08 3.1 CVE-2026-14967 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-14967 ] body-parser--body-parser Impact: In bo= dy-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when th=
e parser is configured with an invalid limit option value such as an unpars= eable string or NaN, bytes.parse returns null and the request body size che=
ck is silently skipped. Applications that rely on limit as their primary sa= feguard against oversized request bodies will accept arbitrarily large payl= oads, leading to excessive memory and CPU usage and denial of service. Patc= hes: This issue is fixed in body-parser 1.20.6 and 2.3.0. After the fix, in= valid limit values throw a clear error at parser construction time instead =
of silently disabling enforcement, while null and undefined continue to fal=
l back to the default limit of 100kb. Workarounds: Validate the limit value=
before passing it to body-parser. For example, parse the value at startup = and reject any configuration where the result is null or a non-finite numbe=
r. 2026-07-09 3.7 CVE-2026-12590 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-12590 ] Capgo--Capgo Capgo before 12.128.2 contains a sql injection vul= nerability in the POST /private/admin_stats endpoint where the limit parame= ter is destructured from unvalidated request body and interpolated directly=
into Cloudflare Analytics Engine SQL queries via template literals. An att= acker with platform admin credentials can inject SQL fragments to enumerate=
dataset schemas, extract analytics data, or cause denial-of-service agains=
t the analytics backend. 2026-07-12 3.8 CVE-2026-56281 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-56281 ] caronc--apprise Apprise is an open source=
library which allows you to send a notification to almost all of the most = popular notification services available. Prior to 1.11.0, Apprise HTTP-base=
d notification plugins and HTTP attachment and config loaders in apprise/at= tachment/http.py and apprise/config/http.py follow HTTP redirects by defaul=
t and resend user-configured auth headers and query parameters on the redir= ected request, allowing a compromised trusted destination or on-path attack=
er to receive secrets such as Authorization headers, bearer tokens, custom = headers, and service keys. This issue is fixed in version 1.11.0. 2026-07-1=
0 3.1 CVE-2026-59180 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59180 ] = coollabsio--coolify Coolify is an open-source and self-hostable tool for ma= naging servers, applications, and databases. From 4.0.0-beta.451 through 4.= 0.0-beta.470, database backup handling for MongoDB collection names did not=
fully validate shell metacharacters, allowing a highly privileged attacker=
who can configure backup inputs to inject commands. This issue is fixed in=
version 4.0.0-beta.471. 2026-07-06 3.3 CVE-2026-34049 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-34049 ] coollabsio--coolify Coolify is an open-so= urce and self-hostable tool for managing servers, applications, and databas= es. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled=
database credentials and MongoDB collection exclusion names into backup sh= ell commands without adequate escaping, allowing an authenticated user with=
database management permissions to execute commands on managed servers. Th=
is issue is fixed in version 4.0.0-beta.471. 2026-07-07 3.3 CVE-2026-34149 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-34149 ] coollabsio--coolify C= oolify is an open-source and self-hostable tool for managing servers, appli= cations, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (= app/Http/Controllers/UploadController.php) for database backup restore uplo= ads did not enforce file type or size validation, allowing an authenticated=
user to upload unexpected or oversized files that could affect service ava= ilability. This issue is fixed in version 4.0.0-beta.474. 2026-07-07 3.1 CV= E-2026-42145 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42145 ] coollabs= io--coolify Coolify is an open-source and self-hostable tool for managing s= ervers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelp= erImage method in app/Livewire/Settings/Index.php constructs a Docker build=
command using the dev_helper_version field without shell escaping, allowin=
g an attacker who can set the helper version and trigger the helper image b= uild in a development environment to execute arbitrary commands on the serv= er. This issue is fixed in version 4.0.0-beta.474. 2026-07-06 3.8 CVE-2026-= 42148 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42148 ] coollabsio--coo= lify Coolify is an open-source and self-hostable tool for managing servers,=
applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens d=
id not expire, allowing a leaked token to retain access indefinitely until = manually revoked. This issue is fixed in version 4.0.0-beta.474. 2026-07-07=
3.1 CVE-2026-42172 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42172 ] c= oollabsio--coolify Coolify is an open-source and self-hostable tool for man= aging servers, applications, and databases. Prior to 4.0.0-beta.474, databa=
se credential fields (redis_password, keydb_password, dragonfly_password, c= lickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user)=
are validated only as 'string' at the API layer, with zero shell-safety ch= ecks. These values are then interpolated directly into Docker Compose YAML = command: strings without any escaping. This issue is fixed in version 4.0.0= -beta.474. 2026-07-07 3.3 CVE-2026-42201 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-42201 ] CoreWCF--CoreWCF CoreWCF is a port of the service side =
of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and = 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo=
SignatureMethod against the configured SecurityAlgorithmSuite but does not=
validate each ds:Reference DigestMethod, allowing a sender to use a reject=
ed digest algorithm such as SHA-1 while the message is still accepted. This=
issue is fixed in versions 1.8.1 and 1.9.1. 2026-07-08 3.7 CVE-2026-54780 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-54780 ] crater-invoice-inc--c= rater A weakness has been identified in crater-invoice-inc crater up to 6.0= .6. This affects the function getFormattedString of the file app/Http/Reque= sts/InvoicesRequest.php of the component Invoice Note Handler. Executing a = manipulation of the argument notes can lead to cross site scripting. The at= tack may be launched remotely. The exploit has been made available to the p= ublic and could be used for attacks. The project was informed of the proble=
m early through an issue report but has not responded yet. 2026-07-06 3.5 C= VE-2026-14791 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14791 ] Dell--P= owerProtect Data Domain Dell PowerProtect Data Domain, versions 7.7.1.0 thr= ough 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release=
version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 throug=
h 7.13.1.70 contain an improper limitation of a pathname to a restricted di= rectory ('path traversal') vulnerability. A high privileged attacker with r= emote access could potentially exploit this vulnerability, leading to unaut= horized file modification. 2026-07-08 2.7 CVE-2026-53480 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-53480 ] filebrowser--filebrowser filebrowser ve= rsions before 2.63.17 fail to normalize paths before querying the share ind=
ex in DeleteWithPathPrefix, allowing authenticated users to leave stale pub= lic shares behind. Attackers can delete a shared directory using a trailing= -slash path, then recreate the same directory to expose new contents throug=
h the dormant public share URL. 2026-07-12 3.1 CVE-2026-61874 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-61874 ] Gallagher--Controller 7000 and 600=
0 Uncaught Exception (CWE-248)=C2=A0in the Controller 6000 and Controller 7= 000 diagnostic web interface allows an authenticated and authorized operato=
r to trigger a Controller restart by sending specific requests, resulting i=
n a temporary denial of service.=C2=A0 Version of Command Centre affected: =
* 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prio=
r to vCR9.40.260616a (distributed in=C2=A09.40.3130(MR3)) * 9.30 prior to v= CR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.2606= 16a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior. 2026-= 07-07 2.7 CVE-2026-27844 [
https://www.cve.org/CVERecord?id=3DCVE-2026-2784=
4 ] Gallagher--T-20 Readers Uncaught Exception (CWE-248)=C2=A0in=C2=A0the T=
20 Readers=C2=A0allows an authenticated and authorized operator to trigger =
a restart by sending specific requests, resulting in a temporary denial of = service.=C2=A0Version of Command Centre affected: * 9.50 prior to vCR9.50.2= 60616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (dis= tributed in=C2=A09.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distribut=
ed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.= 4349(MR7)) * all versions of 9.10 and prior. 2026-07-07 2.7 CVE-2026-27790 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-27790 ] GitLab--GitLab GitLab=
has remediated an issue in GitLab CE/EE affecting all versions from 16.5 b= efore 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certai=
n conditions could have allowed an authenticated user to create a repositor=
y where the content displayed in the web interface differed from the conten=
t available for download, due to improper handling of Git reference name re= solution. 2026-07-08 3.5 CVE-2025-12506 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-12506 ] GitLab--GitLab GitLab has remediated an issue in GitLab=
EE affecting all versions from 16.10 before 18.11.7, 19.0 before 19.0.4, a=
nd 19.1 before 19.1.2 that under certain conditions could have allowed an a= uthenticated user to modify group-level settings beyond their intended perm= issions due to improper authorization controls. 2026-07-08 2.7 CVE-2026-131=
51 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13151 ] GitLab--GitLab Git= Lab has remediated an issue in GitLab EE affecting all versions from 18.2 b= efore 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certai=
n conditions could have allowed an authenticated user with auditor-level ac= cess to modify compliance violation records due to improper authorization o=
n certain GraphQL operations. 2026-07-08 2.7 CVE-2026-6352 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-6352 ] GNU--LibreDWG A vulnerability was foun=
d in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_ne= xt_entity of the file src/dwg.c of the component DWG File Handler. Performi=
ng a manipulation of the argument next_obj results in null pointer derefere= nce. The attack must be initiated from a local position. The exploit has be=
en made public and could be used. Upgrading to version 0.14 is sufficient t=
o resolve this issue. The patch is named dde45dac3c4d902e4d8fed150a8017b973= 2019c9. Upgrading the affected component is recommended. Different than CVE= -2026-9503. 2026-07-09 3.3 CVE-2026-15184 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-15184 ] GPAC--GPAC A vulnerability was determined in GPAC up t=
o 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewr= ite of the file src/isomedia/avc_ext.c of the component MP4Box. This manipu= lation of the argument nalu_out_bs causes double free. It is possible to la= unch the attack on the local host. The exploit has been publicly disclosed = and may be utilized. Patch name: f29f955f2a3b5e8e507caad3e52319f961bf37bf. =
To fix this issue, it is recommended to deploy a patch. 2026-07-06 3.3 CVE-= 2025-15667 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15667 ] GPAC--GPAC=
A vulnerability was identified in GPAC up to b40ce70f5. This issue affects=
the function sgpd_del_entry of the file src/isomedia/box_code_base.c of th=
e component MP4Box. Such manipulation of the argument data leads to heap-ba= sed buffer overflow. Local access is required to approach this attack. The = exploit is publicly available and might be used. The name of the patch is f= 29f955f2a3b5e8e507caad3e52319f961bf37bf. It is advisable to implement a pat=
ch to correct this issue. 2026-07-06 3.3 CVE-2025-15668 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2025-15668 ] GPAC--GPAC A flaw has been found in GPAC=
26.02.0. This affects the function nhmldump_send_frame of the file src/fil= ters/write_nhml.c of the component Media File Handler. Executing a manipula= tion can lead to null pointer dereference. The attack requires local access=
. The exploit has been published and may be used. This patch is called bd1d= 94e70e3bef364c07c5a1d94eca5c9f56e160. A patch should be applied to remediat=
e this issue. The project explains: "I would consider most of these more as=
bugs than vulns but anyway they're good to fix". 2026-07-06 3.3 CVE-2026-1= 4790 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14790 ] GPAC--GPAC A sec= urity vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-m= aster. The impacted element is the function txtin_probe_duration of the fil=
e src/filters/load_text.c of the component TeXML File Handler. Such manipul= ation of the argument txml_timescale leads to divide by zero. An attack has=
to be approached locally. The name of the patch is 86a5191f2e750c767253e27= ed6cfd6d547afebc2. A patch should be applied to remediate this issue. 2026-= 07-06 3.3 CVE-2026-14801 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1480=
1 ] GPAC--GPAC A vulnerability was determined in GPAC 26.03-DEV. This affec=
ts the function vobsub_read_idx of the file /src/media_tools/vobsub.c of th=
e component MP4Box. Executing a manipulation of the argument num_langs can = lead to out-of-bounds read. The attack needs to be launched locally. The ex= ploit has been publicly disclosed and may be utilized. This patch is called=
532097084729a936bcdf6a27c41003f3bd7dc3ff. It is best practice to apply a p= atch to resolve this issue. Two different commits were applied to fix this = issue. 2026-07-09 3.3 CVE-2026-15185 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-15185 ] Grafana--Grafana Enterprise The public dashboard deletion e= ndpoint does not enforce organization isolation, allowing an Org Admin in o=
ne organization to delete public dashboards belonging to a different organi= zation by supplying the target dashboard's identifiers. 2026-07-07 3.1 CVE-= 2026-28378 [
https://www.cve.org/CVERecord?id=3DCVE-2026-28378 ] halo-dev--= halo A vulnerability was identified in halo-dev halo up to 2.24.2. This aff= ects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of th=
e component Theme Installation. Such manipulation of the argument metadata.= name leads to path traversal. The attack may be launched remotely. The expl= oit is publicly available and might be used. The project closed the issue a=
s "duplicate" but did not reference any other issue, report, or CVE. 2026-0= 7-10 3.8 CVE-2026-15326 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15326=
] ImageMagick--ImageMagick ImageMagick before 7.1.2-15 contains a heap-buf= fer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache u= pdating image channel metadata before pixel cache memory allocation. Attack= ers can trigger memory and disk allocation failures to cause a heap-buffer-= overflow read affecting any writer calling GetPixelIndex. 2026-07-08 3.3 CV= E-2026-56362 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56362 ] ImageMag= ick--ImageMagick ImageMagick before 7.1.2-18 contains a memory leak vulnera= bility in the META reader when processing APP1JPEG input paths. Attackers c=
an trigger this memory leak by providing specially crafted APP1JPEG image f= iles, causing denial of service through resource exhaustion. 2026-07-10 3.3=
CVE-2026-56366 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56366 ] Image= Magick--ImageMagick ImageMagick before 7.1.2-19 contains a heap buffer over= flow vulnerability in the magnify operation that allows attackers to read o=
ut of bounds memory. An unrecognized magnify:method value triggers an out o=
f bounds read, potentially exposing sensitive information or causing denial=
of service. 2026-07-11 3.3 CVE-2026-56372 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-56372 ] ImageMagick--ImageMagick ImageMagick before 7.1.2-15 = contains a use-after-free vulnerability in the PDB decoder that uses a stal=
e pointer when memory allocation fails. Attackers can trigger this vulnerab= ility by processing malicious PDB files to cause crashes or write a single = zero byte to freed memory. 2026-07-10 3.7 CVE-2026-56373 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-56373 ] ImageMagick--ImageMagick ImageMagick be= fore 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT enc= oder due to missing boundary checks when parsing ftxt:format. Remote attack= ers can trigger an out of bounds read by crafting malicious FTXT image file=
s to cause denial of service or information disclosure. 2026-07-08 3.3 CVE-= 2026-56374 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56374 ] ImageMagic= k--ImageMagick ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check=
for the allowed memory allocation limit in matrix-backed operations such a=
s -canny. An attacker can supply a crafted image that causes ImageMagick to=
allocate more memory than permitted by the configured policy, resulting in=
a denial of service. 2026-07-11 3.3 CVE-2026-61465 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-61465 ] ImageMagick--ImageMagick ImageMagick before = 7.1.2-26 contains a heap use-after-free vulnerability caused by missing nul=
l check when parsing XMP profiles. Attackers can craft malicious image file=
s with specially crafted XMP data to trigger the vulnerability and cause ap= plication crashes. 2026-07-11 3.7 CVE-2026-61857 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-61857 ] ImageMagick--ImageMagick ImageMagick before 7.1= .2-26 contains a policy bypass vulnerability in the APNG encoder and extern=
al delegates due to missing validation checks. Attackers can write files to=
disallowed paths by bypassing configured policy restrictions through the A= PNG encoding process. 2026-07-11 3.3 CVE-2026-61858 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-61858 ] ImageMagick--ImageMagick ImageMagick before = 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption=
method when memory allocation fails. Attackers can trigger memory allocati=
on failures to cause a dangling pointer to reference freed memory, potentia= lly enabling denial of service or code execution. 2026-07-11 3.7 CVE-2026-6= 1861 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61861 ] ImageMagick--Ima= geMagick ImageMagick before 7.1.2-26 contains a memory leak vulnerability i=
n the VIFF encoder when memory allocation fails. Attackers can trigger allo= cation failures by processing specially crafted VIFF images to exhaust avai= lable memory and cause denial of service. 2026-07-11 2.9 CVE-2026-61870 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-61870 ] JetBrains--YouTrack In J= etBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram ren= dering was possible 2026-07-10 3.5 CVE-2026-59791 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-59791 ] JetBrains--YouTrack In JetBrains YouTrack befo=
re 2026.2.17394 stored XSS via article titles in digest emails was possible=
2026-07-10 3.5 CVE-2026-61492 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-61492 ] lissy93--dashy Dashy is a self-hostable personal dashboard. Prior=
to 4.3.7, Dashy's workspace view trusts the url query parameter and assign=
s it directly to an iframe source without scheme validation. If a logged-in=
user opens a crafted workspace link containing a javascript: URL, JavaScri=
pt runs on the Dashy origin and can read same-origin browser data, interact=
with the Dashy DOM, and send requests as the victim. This issue is fixed i=
n version 4.3.7. 2026-07-07 3.9 CVE-2026-55592 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-55592 ] lo48576--fbxcel A vulnerability was detected in l= o48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pul= l_parser/v7400/parser.rs of the component Node Header Handler. The manipula= tion results in denial of service. The attack must be initiated from a loca=
l position. The exploit is now public and may be used. The pull request to = fix this issue awaits acceptance. 2026-07-09 3.3 CVE-2026-15274 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-15274 ] MyEMS--MyEMS A vulnerability was=
found in MyEMS up to 6.4.0. The affected element is the function on_post o=
f the file myems-api/core/svg.py of the component Admin Backend. The manipu= lation of the argument new_values['data'] results in cross site scripting. = The attack can be launched remotely. The exploit has been made public and c= ould be used. Upgrading to version 6.5.0 is sufficient to fix this issue. T=
he patch is identified as 4a97edfbd786c779d0322054833b21ddf54d5b06. It is s= uggested to upgrade the affected component. The issue report remains open e= ven though there is an official fix for it. 2026-07-10 2.4 CVE-2026-15321 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-15321 ] NousResearch--hermes-a= gent A vulnerability was identified in NousResearch hermes-agent up to 2026= .5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_= html of the file gateway/platforms/matrix.py of the component Matrix Adapte=
r. Such manipulation leads to cross site scripting. The attack can be execu= ted remotely. The exploit is publicly available and might be used. The pull=
request to fix this issue awaits acceptance. 2026-07-09 3.5 CVE-2026-15311=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-15311 ] OP-TEE--optee_os OP-= TEE is a Trusted Execution Environment (TEE) designed as companion to a non= -secure Linux kernel running on Arm; Cortex-A cores using the TrustZone tec= hnology. Starting in version 3.10.0 and prior to version 4.11.0, an unbound=
ed recursion can crash the PKCS#11 TA. Version 4.11.0 contains a patch. No = known workarounds are available. 2026-07-06 3.3 CVE-2026-41434 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-41434 ] OP-TEE--optee_os OP-TEE is a Trus= ted Execution Environment (TEE) designed as companion to a non-secure Linux=
kernel running on Arm; Cortex-A cores using the TrustZone technology. Star= ting in version 3.3.0 and prior to version 4.11.0, a resource leak exists i=
n OP-TEE's shared memory cleanup logic because the function `cleanup_shm_re= fs()` in `core/tee/entry_std.c` fails to apply a required bitmask (`OPTEE_M= SG_ATTR_TYPE_MASK`) to parameter attributes. When processing non-contiguous=
memory parameters from a normal-world caller, the system fails to match th=
e attribute type in its internal switch statement and skips the necessary m= obj_put() call. This results in a persistent reference leak of `mobj_reg_sh=
m` objects, which remain on internal lists with dangling refcounts. This af= fects non-FF-A configurations that support non-contiguous, non-secure share=
d memory. Over time, these accumulated leaks progressively consume the secu= re-world heap, degrading the system's ability to service trusted applicatio=
n operations and eventually requiring a reboot to recover. Version 4.11.0 c= ontains a patch. No known workarounds are available. 2026-07-06 3.8 CVE-202= 6-42546 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42546 ] OP-TEE--optee= _os OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 4.5.0 and prior to version 4.11.0, the = RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses=
non-constant-time `memcmp()` for label hash verification and has multiple = distinguishable error paths. This creates a Manger-style padding oracle tha=
t allows an attacker to recover RSA-OAEP plaintext with approximately 1000-= 2000 adaptive chosen ciphertext queries. Only affects plat-d06 with `CFG_HI= SILICON_ACC_V3=3Dy`, which seems to be disabled by default. Version 4.11.0 = contains a patch. As a workaround, disable Hisilicon HPRE RSA driver with `= CFG_HISILICON_ACC_V3=3Dn`. 2026-07-06 2.5 CVE-2026-41514 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-41514 ] OP-TEE--optee_os OP-TEE is a Trusted Ex= ecution Environment (TEE) designed as companion to a non-secure Linux kerne=
l running on Arm; Cortex-A cores using the TrustZone technology. Starting i=
n version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implem= entation in the NXP CAAM crypto driver uses non-constant-time `memcmp()` fo=
r label hash verification and has multiple distinguishable error paths. Thi=
s creates a Manger-style padding oracle that allows an attacker to recover = RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext = queries. Version 4.11.0 contains a patch. As a workaround, disable the NXP = CAAM RSA driver with `CFG_CRYPTO_DRV_RSA=3Dn`. 2026-07-06 2.5 CVE-2026-4151=
5 [
https://www.cve.org/CVERecord?id=3DCVE-2026-41515 ] OP-TEE--optee_os OP= -TEE is a Trusted Execution Environment (TEE) designed as companion to a no= n-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone te= chnology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA PK= CS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver use=
s non-constant-time `memcmp()` for label hash verification and has multiple=
distinguishable error paths. This creates a Bleichenbacher-style padding o= racle that allows an attacker to recover RSA PKCS#1 v1.5 plaintext. Version=
4.11.0 contains a patch. As a workaround, disable Hisilicon HPRE RSA drive=
r with `CFG_HISILICON_ACC_V3=3Dn`. 2026-07-06 2.5 CVE-2026-41516 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-41516 ] open-webui--open-webui Open Web=
UI is an extensible, feature-rich, and user-friendly self-hosted AI platfor=
m. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py = and routers/ollama.py passed a lambda to aiocache key instead of key_builde=
r, causing permission-filtered per-user model lists to share a static cache=
entry and exposing one user's model list to another caller during the TTL = window. This issue is fixed in version 0.10.0. 2026-07-09 3.5 CVE-2026-5921=
3 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59213 ] open-webui--open-we= bui Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, channel thread parent and reply handling di=
d not bind parent_id to the channel in the URL, allowing an authenticated u= ser to reference a message from another private or DM channel and disclose = thread context across channels. This issue is fixed in version 0.10.0. 2026= -07-09 3.1 CVE-2026-59215 [
https://www.cve.org/CVERecord?id=3DCVE-2026-592=
15 ] open-webui--open-webui Open WebUI is an extensible, feature-rich, and = user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_au= tomation rehydrated automation owners without rechecking that they were sti=
ll active or still had features.automations, and check_model_access only en= forced private-model grants for the exact user role, allowing deactivated p= ending users to continue scheduled model execution. This issue is fixed in = version 0.10.0. 2026-07-09 3.1 CVE-2026-59226 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-59226 ] open-webui--open-webui Open WebUI is an extensible=
, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 befo=
re 0.10.0, the Socket.IO server is configured with always_connect=3DTrue. T=
he ydoc:awareness:update and ydoc:document:leave Socket.IO handlers accepte=
d collaborative-document events without requiring an authenticated user, al= lowing unauthorized manipulation of document collaboration state. This issu=
e is fixed in version 0.10.0. 2026-07-09 3.1 CVE-2026-59715 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-59715 ] Open5GS--Open5GS A security flaw has=
been discovered in Open5GS 2.7.7. This affects the function amf_context_fi= nal of the file src/amf/context.c of the component AMF. Performing a manipu= lation results in use after free. The attack is only possible with local ac= cess. The exploit has been released to the public and may be used for attac= ks. 2026-07-09 3.3 CVE-2026-15194 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15194 ] OpenBSD--OpenSSH sshd in OpenSSH before 10.4 allows remote att= ackers to cause a denial of service (resource consumption from excessive au= thentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthen= tication. 2026-07-08 3.7 CVE-2026-60000 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-60000 ] pdeljanov--Symphonia A flaw has been found in pdeljanov=
Symphonia up to 0.6.0. This vulnerability affects unknown code of the comp= onent Metadata Handler. This manipulation causes denial of service. The att= ack needs to be launched locally. The exploit has been published and may be=
used. The pull request to fix this issue awaits acceptance. 2026-07-09 3.3=
CVE-2026-15276 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15276 ] phpMy= FAQ--phpMyFAQ phpMyFAQ before 4.1.5 contains a potential authenticated path=
traversal vulnerability in the concatenatePaths() function within src/phpM= yFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store H= TML containing crafted image paths that are processed during PDF generation=
. The path resolution logic locates the substring "content" within a user-c= ontrolled path using strpos(); when "content" is absent, strpos() returns f= alse, which becomes 0 when cast to an integer, preserving the entire attack= er-controlled path. This path is later passed to file_get_contents() withou=
t canonicalization or root-directory containment validation, which may allo=
w reading of files outside the intended content directory. 2026-07-10 2.7 C= VE-2026-57961 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57961 ] Progres= s--MOVEit Transfer Limited authentication bypass by spoofing vulnerability =
in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Trans= fer: before 2025.0.7, from 2025.1.0 before 2025.1.3. 2026-07-08 3.7 CVE-202= 6-8651 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8651 ] Progress--MOVEi=
t Transfer Path equivalence: vulnerability in Progress MOVEit Transfer (Fil=
e Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, fro=
m 2025.1.0 before 2025.1.4. 2026-07-08 3.5 CVE-2026-8801 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-8801 ] Progress--MOVEit Transfer Incorrect Auth= orization vulnerability in Progress MOVEit Transfer (Audit User module). Th=
is issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 202= 5.1.3. 2026-07-08 2.7 CVE-2026-8800 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-8800 ] radareorg--radare2 A security flaw has been discovered in rad= areorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of=
the file libr/util/str.c. The manipulation results in integer overflow. Th=
e attack must be initiated from a local position. The exploit has been rele= ased to the public and may be used for attacks. The patch is identified as = 11ac224c0eb8d57830fccc99e1c1cd8e5d958813. It is best practice to apply a pa= tch to resolve this issue. 2026-07-06 3.3 CVE-2026-14786 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-14786 ] radareorg--radare2 A weakness has been = identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_p= rint in the library libr/core/cmd_print.inc of the component pb Print Comma=
nd Handler. This manipulation causes integer overflow. The attack needs to =
be launched locally. The exploit has been made available to the public and = could be used for attacks. Patch name: 2b6265476c75567006b0fcbb749f4ae7b189= c5df. It is recommended to apply a patch to fix this issue. 2026-07-06 3.3 = CVE-2026-14787 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14787 ] radare= org--radare2 A security vulnerability has been detected in radareorg radare=
2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_lo=
ad of the file libr/core/cfile.c. Such manipulation leads to use after free=
. The attack needs to be performed locally. The exploit has been disclosed = publicly and may be used. The name of the patch is 635ab1eeb30340c26076722a= 90cb91fb2272130b. Applying a patch is advised to resolve this issue. 2026-0= 7-06 3.3 CVE-2026-14788 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14788=
] radareorg--radare2 A vulnerability was detected in radareorg radare2 up =
to 6.1.6. Affected by this issue is some unknown functionality of the file = libr/bin/format/mdmp/mdmp.c of the component Memory64ListStream Parser. Per= forming a manipulation results in stack-based buffer overflow. The attack r= equires a local approach. The exploit is now public and may be used. The pa= tch is named 175d4addb68981331c85b10681c2161c38fb5762. It is suggested to i= nstall a patch to address this issue. 2026-07-06 3.3 CVE-2026-14789 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-14789 ] Red Hat--Red Hat Directory S= erver 11 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 passwo=
rd verification function uses standard memcmp() for comparing password hash=
es instead of a constant-time comparison function. A remote attacker could = potentially use timing measurements of LDAP bind attempts to infer partial = hash information, though practical exploitation is extremely difficult due =
to PBKDF2 computational overhead. 2026-07-08 3.7 CVE-2026-15041 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-15041 ] Red Hat--Red Hat Enterprise Linu=
x 10 A logic vulnerability was found in GStreamer's webrtcbin component. Th=
e _check_sdp_crypto() function contains an inverted boolean condition that = causes it to accept remote SDP offers or answers that lack the required a= =3Dfingerprint attribute, while incorrectly rejecting those that include it=
. An attacker with the ability to intercept and modify WebRTC signaling mes= sages could exploit this to bypass the SDP-level DTLS certificate fingerpri=
nt binding, weakening defenses against man-in-the-middle attacks on media s= treams. 2026-07-07 3.7 CVE-2026-14935 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-14935 ] Red Hat--Red Hat Hardened Images A flaw was found in libar= chive. This vulnerability allows a remote attacker to trigger a heap overfl=
ow by providing a specially crafted tar archive. The issue occurs during th=
e parsing of a PAX extended header containing a malformed SUN.holesdata spa= rse-file attribute. Successful exploitation could lead to a denial of servi= ce, making the system unavailable, or potentially allow for arbitrary code = execution, giving the attacker control over the affected system. 2026-07-10=
3.9 CVE-2026-15028 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15028 ] V= Mware--Pinniped A user authenticating to Kubernetes clusters via the Pinnip=
ed Supervisor could potentially gain elevated permissions in the clusters, = only if all the following conditions were true: the Pinniped Supervisor ser= ver is running with an ActiveDirectoryIdentityProvider resource configured;=
the ActiveDirectoryIdentityProvider.spec.groupSearch.attributes.groupName =
is empty; the attacker gains the ability to edit some part of the distingui= shed name (DN) of group entries in the Active Directory (AD) server's datab= ase for groups to which they belong; the configured group search parameters=
cause the edited group to be included in the group search results for the = user; and the attacker knows the password for an AD user who belongs to the=
edited AD group. Affected versions: Pinniped (go.pinniped.dev) v0.11.0 thr= ough v0.46.0 inclusive; fixed in v0.47.0. 2026-07-09 3.8 CVE-2026-59269 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-59269 ] vnotex--vnote A weakness=
has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown f= unction of the file /src/data/extra/web/js/markdownit.js of the component Y= AML Frontmatter. This manipulation of the argument p_metaData causes cross = site scripting. The attack may be initiated remotely. The vendor was contac= ted early about this disclosure but did not respond in any way. 2026-07-12 = 3.5 CVE-2026-15505 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15505 ] Wi= reshark Foundation--Wireshark BLF file parser in Wireshark 4.6.0 to 4.6.6 a=
nd 4.4.0 to 4.4.16 allows possible information disclosure 2026-07-08 2.5 CV= E-2026-15168 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15168 ] zephyrpr= oject--zephyr The Nuvoton NuMaker HSUSBD USB device-controller driver (driv= ers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally = (base->CEPTXCNT =3D len in numaker_hsusbd_ep_trigger). Because the HSUSBD h= ardware cannot disarm a control Data IN already armed for a previous transf= er, a USB host that cancels an in-flight control transfer (timeout) and the=
n issues a new SETUP packet can drive the driver out of sync: stale data ma=
y be transmitted in the new transfer and the control endpoint can become pe= rmanently stuck NAK'ing every subsequent control transfer. A malicious or b= uggy host (physical/adjacent attacker driving the bus) can repeatedly cance= l-and-re-SETUP to wedge the device's USB control endpoint, denying service =
to the device's USB function (the device stops enumerating/responding on th=
e control pipe) until a USB reset or re-plug. The flaw is an availability-o= nly denial of service; the FIFO copy loops (bounded by net_buf length and t=
he hardware BUFFULL flag) and the net_buf lifecycle are independent of the = arming desync, so there is no out-of-bounds access, use-after-free, or info= rmation leak. The fix monitors the IN-token and new-SETUP events (k_event) = and only arms control Data IN when an IN token is present and no new SETUP = has arrived, cancelling the current transfer on a new SETUP. Affects boards=
using the Nuvoton NuMaker HSUSBD controller (CONFIG_UDC_NUMAKER with DT_HA= S_NUVOTON_NUMAKER_HSUSBD_ENABLED); shipped in v4.4.0. 2026-07-12 2.4 CVE-20= 26-10668 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10668 ]=20
Back to top [ #top ]
Severity Not Yet Assigned
Primary
Vendor -- Product Description Published CVSS Score Source Info actualbudget= --actual Actual is an open-source personal finance application. Prior to 26= .7.0, a missing authorization issue allows a shared user with user_access o=
n a budget file to perform owner-only file management actions. A non-owner = shared user can call file-management endpoints intended for higher-privileg=
e users, including /delete-user-file, /reset-user-file, and /user-create-ke=
y, because requireFileAccess treats ordinary shared access as sufficient fo=
r file-management operations that should be restricted to the file owner or=
an administrator. This issue is fixed in version 26.7.0. 2026-07-07 not ye=
t calculated CVE-2026-50007 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 0007 ] acymailing.com--acymailing.com AcyMailing extension for Joomla A SQL=
i vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered=
. Exploiting this flaw can lead to unauthorized database access and data le= akage. 2026-07-09 not yet calculated CVE-2026-56292 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-56292 ] Adalo No-Code App Builder--App Builder In Ad= alo's no-code app builder, (Versions 1 and 2) the attackers may extract ful=
l user records and correlate user behavior across multiple applications via=
dbId enumeration. The platform does not implement data minimization, priva=
cy by design, or implement appropriate technical safeguards, allowing sensi= tive information to be exposed to unauthorized parties. 2026-07-08 not yet = calculated CVE-2026-10706 [
https://www.cve.org/CVERecord?id=3DCVE-2026-107=
06 ] Adalo No-Code App Builder--App Builder This vulnerability enables larg= e-scale data harvesting without requiring app-specific secrets. A single re= quest to a minimal leaderboard component may return user records containing=
emails, UUIDs, and custom fields. The combination of wildcard CORS behavio=
r, long-lived twenty-day JWTs, and the absence of token revocation allows a= ttackers to gather sensitive personal information from any Adalo applicatio=
n. 2026-07-08 not yet calculated CVE-2026-10708 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-10708 ] Adiss--Biloop An authenticated user could manipu= late a company ID parameter in a POST request to the backend to gain unauth= orised access to other companies hosted within the same subdomain environme= nt. The application does not adequately verify whether the requested compan=
y ID belongs to the authenticated user's session, resulting in a cross-tena=
nt authorisation bypass. If this vulnerability is successfully exploited, i=
t allows unauthorised access to sensitive customer information, including b= illing data, and may enable the unauthorised modification of third-party da= ta. 2026-07-06 not yet calculated CVE-2026-12686 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-12686 ] adm-zip--adm-zip adm-zip before 0.5.18 is vulne= rable to denial of service via a crafted ZIP file with a manipulated uncomp= ressed size header field. In zipEntry.js line 103, Buffer.alloc(_centralHea= der.size) allocates memory based on the declared uncompressed size from the=
ZIP central directory header without validating it against the actual comp= ressed data size or imposing any upper bound. The size value is read direct=
ly from the binary header at entryHeader.js line 266 with no bounds check. =
An attacker can craft a ~120-byte ZIP file that declares ~4GB uncompressed = size, causing a memory allocation amplification ratio of over 33 million to=
1. The allocation occurs before CRC validation, so the malicious payload c= annot be rejected early. All extraction and read methods are affected: read= File(), readAsText(), extractEntryTo(), extractAllTo(), extractAllToAsync()=
, test(), and entry.getData(). Any application accepting untrusted ZIP file=
s via adm-zip is vulnerable to immediate process crash. 2026-07-10 not yet = calculated CVE-2026-39244 [
https://www.cve.org/CVERecord?id=3DCVE-2026-392=
44 ] ajenti--ajenti ajenti through v2.2.13 has a clickjacking weakness in t=
he browser-facing login and administrative UI. In ajenti-core/aj/http.py, t=
he core HTTP response path initializes an empty header list, forwards handl= er-added headers verbatim, and finalizes responses through WSGI start_respo= nse() without adding anti-framing protections such as X-Frame-Options or a = Content-Security-Policy frame-ancestors restriction. 2026-07-06 not yet cal= culated CVE-2026-38979 [
https://www.cve.org/CVERecord?id=3DCVE-2026-38979 =
] ankitects--anki Anki is a program for creating and reviewing flashcards. = Prior to 25.09.3, Anki launches a local HTTP server to serve media files an=
d web pages for parts of its interface, but requests from other origins wer=
e not sufficiently blocked. A malicious website could potentially trigger s= ide-effecting requests to the local server, with severity varying by browse=
r depending on Private Network Access protections. This issue is fixed in v= ersion 25.09.3. 2026-07-07 not yet calculated CVE-2026-59153 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-59153 ] Apache Software Foundation--Apache = Airflow A bug in `BaseSerialization.deserialize()` allowed unrestricted `im= port_string()` of attacker-controlled class paths when the Scheduler / API = Server loaded a serialized DAG: a DAG author could embed a malicious trigge=
r into a DAG to gain remote code execution on the API Server / Scheduler pr= ocess, crossing the Airflow security boundary that DAG-author code must nev=
er execute in those processes. Users are advised to upgrade to `apache-airf= low` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DA= G-author trust is limited can restrict the `[core] allowed_deserialization_= classes` config to a narrow allowlist. 2026-07-07 not yet calculated CVE-20= 26-33264 [
https://www.cve.org/CVERecord?id=3DCVE-2026-33264 ] Apache Softw= are Foundation--Apache Airflow The Bulk Variables API in Apache Airflow cal= led the redactor without passing the variable's key, so the key-based `shou= ld_hide_value_for_key` check (which triggers on secret-suffixed key names l= ike `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodabl=
e variable values. An authenticated UI/API user with bulk Variable read per= mission could retrieve plaintext values from JSON variables whose key would=
otherwise trigger redaction. Affects deployments that store sensitive valu=
es in JSON-typed Airflow Variables under secret-suffixed key names. Users a=
re advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on=
`main` after 3.2.2; no 3.2.x backport). 2026-07-07 not yet calculated CVE-= 2026-48828 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48828 ] Apache Sof= tware Foundation--Apache Airflow A bug in Apache Airflow's `/ui/dependencie=
s` scheduling graph endpoint applied the caller's readable-Dag filter to th=
e top-level serialized Dag key but still emitted referenced Dag IDs through=
the `dep.source` and `dep.target` fields of trigger / sensor dependency en= tries. An authenticated UI user with read permission on some Dags could enu= merate the identifiers of other Dags they were not authorized to read by in= specting the dependency graph for trigger / sensor references. Affects depl= oyments that rely on per-Dag read scoping to keep Dag identifiers private a= cross teams. This is a residual gap in the fix for CVE-2026-28563, which fi= ltered the top-level Dag key but did not propagate the filter into the trig= ger / sensor dep-source / dep-target fields. Users who already upgraded for=
CVE-2026-28563 should additionally upgrade to `apache-airflow` 3.3.0 or la= ter to cover the residual trigger / sensor dependency leak. 2026-07-07 not = yet calculated CVE-2026-48891 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -48891 ] Apache Software Foundation--Apache Airflow The Config API in Apach=
e Airflow surfaced per-key secrets-backend overrides (environment variables=
like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__S= ECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option = names were not in `sensitive_config_values`, so the masker did not redact t= hem. An authenticated UI/API user with Config read permission could retriev=
e plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc=
.) from the Config API output. Affects deployments that configure secrets b= ackends via per-key environment overrides. Users are advised to upgrade to = `apache-airflow` 3.3.0 or later. 2026-07-07 not yet calculated CVE-2026-488=
92 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48892 ] Apache Software Fo= undation--Apache Airflow Before apache-airflow 3.3.0, a user authorized to = read one Dag could disclose the source of other Dags co-located in the same=
source file. `GET /api/v2/dagSources/{dag_id}` - and the equivalent Dag-so= urce view in the UI - returned the entire source file without redacting Dag=
s the caller was not authorized to read, bypassing per-DAG read authorizati= on. Deployments that co-locate multiple Dags in a single file and rely on p= er-DAG access control to limit source visibility are affected; single-Dag-p= er-file deployments are not. Upgrade to apache-airflow 3.3.0 or later. 2026= -07-07 not yet calculated CVE-2026-49296 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49296 ] Apache Software Foundation--Apache Airflow In Apache Ai= rflow before 3.3.0, the REST API task-instance detail and list endpoints re= turned a deferred task's trigger kwargs without masking. When a deferred op= erator passed a secret (for example a provider API key) into its trigger, a=
ny authenticated user with DAG-scoped task-instance read access for that DA=
G could read that secret in clear text while the task was deferred. Users s= hould upgrade to apache-airflow 3.3.0 or later, which masks sensitive value=
s in trigger kwargs returned by the API. 2026-07-07 not yet calculated CVE-= 2026-49487 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49487 ] Apache Sof= tware Foundation--Apache Airflow Google provider Apache Airflow's Google pr= ovider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator`=
joined GCS object names returned by the bucket listing API directly to a d= estination filesystem path without normalisation or containment check. A us=
er with write access to the source GCS bucket (typically a different trust = principal than the DAG author - partner uploads, ingest-only service accoun= ts, public-data buckets) could create an object whose name contains `..` se= gments and cause the DAG run to write the downloaded blob outside the confi= gured destination (the SFTP `destination_path` for `GCSToSFTPOperator`; the=
worker-local temp directory for `GCSTimeSpanFileTransformOperator`), enabl= ing overwrite of arbitrary files on the SFTP server or the worker host. Aff= ects deployments that ingest from buckets writable by less-trusted principa= ls. Users are advised to upgrade to `apache-airflow-providers-google` 22.2.=
1 or later. 2026-07-06 not yet calculated CVE-2026-49297 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-49297 ] Apache Software Foundation--Apache Came=
l Improper Neutralization of Argument Delimiters in a Command ('Argument In= jection') vulnerability in Apache Camel Docling component. The camel-doclin=
g component invokes the external `docling` command-line tool by assembling =
an argument list in DoclingProducer and executing it through java.lang.Proc= essBuilder. Custom CLI arguments supplied through the `CamelDoclingCustomAr= guments` exchange header (a List<String>) were appended to that argument li=
st with insufficient validation: the original implementation relied on a de= nylist of disallowed flags and only rejected path values that contained a l= iteral `../` sequence. As a result, a Camel route that forwards externally-= influenced data into the `CamelDoclingCustomArguments` header (or into the = path-bearing headers used to build the invocation) could cause the producer=
to pass unrecognized or unintended `docling` CLI flags to the subprocess, = and could supply path-like argument values that resolved outside the intend=
ed directory through traversal sequences not caught by the literal `../` ch= eck. Because Camel itself builds the `docling` invocation from these values=
, the component is responsible for constraining them, and the weak validati=
on allowed CLI-argument injection and directory traversal in the arguments = passed to the external tool. The invocation uses the list-based form of Pro= cessBuilder, so a shell does not interpret the argument values; OS command = injection through shell metacharacters was not possible, and the metacharac= ter rejection added by the fix is defense-in-depth. This issue affects Apac=
he Camel: from 4.15.0 before 4.18.3. Users are recommended to upgrade to a = release that contains the CAMEL-23212 fix. On the mainline the fix is inclu= ded from Apache Camel 4.19.0 (and later releases such as 4.20.0). For users=
on the 4.18.x LTS releases stream, upgrade to 4.18.3. The fix replaces the=
denylist with a strict allowlist of recognized `docling` CLI flags (reject= ing any unrecognized flag, and rejecting producer-managed flags such as the=
output-directory flags), defensively rejects shell metacharacters in argum= ent values, and normalizes path-like values with Path.normalize() before va= lidating them so that traversal sequences which bypass a literal `../` chec=
k are detected. As defence in depth, route authors should avoid mapping unt= rusted message content into the `CamelDoclingCustomArguments` header and th=
e path-bearing headers, and should strip Camel-internal headers from messag=
es that arrive from untrusted producers. 2026-07-06 not yet calculated CVE-= 2026-40047 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40047 ] Apache Sof= tware Foundation--Apache Camel Deserialization of Untrusted Data vulnerabil= ity in Apache Camel. The camel-vertx-http component deserializes HTTP respo= nse bodies carrying the Content-Type application/x-java-serialized-object u= sing a raw java.io.ObjectInputStream, without applying any ObjectInputFilte=
r (VertxHttpHelper.deserializeJavaObjectFromStream) This deserialization pa=
th is reached only when the producer endpoint is configured with transferEx= ception=3Dtrue (or the component-level allowJavaSerializedObject=3Dtrue) an=
d throwExceptionOnFailure is left at its default value of true; in that cas=
e a backend HTTP response with a 5xx status and the application/x-java-seri= alized-object content type has its body deserialized with no class restrict= ions. An attacker who controls the backend the Camel producer talks to - th= rough a man-in-the-middle position on an unencrypted (plain HTTP) connectio=
n, or by compromising the backend service - can return a crafted serialized=
Java object and, if a suitable gadget chain is present on the classpath, a= chieve remote code execution on the Camel application host. The path is not=
reachable in the default configuration, where transferException is false. = This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 befo=
re 4.18.3, from 4.19.0 before 4.20.0. Users are recommended to upgrade to v= ersion 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releas=
es stream, then they are suggested to upgrade to 4.14.8. If users are on th=
e 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. Aft=
er upgrading, the deserialization performed by both helper utilities is con= strained by a default ObjectInputFilter (allow-list java.**;javax.**;org.ap= ache.camel.**;!*), which can be customised through the new deserializationF= ilter endpoint option or the JVM-wide -Djdk.serialFilter system property. F=
or deployments that cannot upgrade immediately: do not enable transferExcep= tion=3Dtrue (or allowJavaSerializedObject=3Dtrue) on producers that talk to=
untrusted or network-reachable backends; ensure producer connections use T=
LS (https) so that a response cannot be substituted by a man-in-the-middle;=
and, where the option is required, set an explicit -Djdk.serialFilter allo= w-list (for example java.**;org.apache.camel.**;!*) to constrain deserializ= ation. 2026-07-06 not yet calculated CVE-2026-40859 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-40859 ] Apache Software Foundation--Apache Camel Des= erialization of Untrusted Data vulnerability in Apache Camel. The default O= bjectInputFilter pattern shipped with several Apache Camel components for d= efense-in-depth deserialization filtering ('java.**;javax.**;org.apache.cam= el.**;!*', or the no-'javax.**' variant in the aggregation-repository compo= nents) uses a recursive 'java.**' glob that admits classes whose hashCode/e= quals/readObject methods perform network I/O, notably java.net.URL and java= .net.InetAddress. When an attacker can deliver a Java-serialized payload to=
an affected Camel consumer, deserialization of a HashMap (or any collectio=
n that calls hashCode on its elements) containing java.net.URL keys causes = the JVM to issue DNS queries to the attacker-supplied host during the deser= ialization side-effect. The class-level filter check passes because the res= ulting object's class (HashMap) is allow-listed; the DNS query is observabl=
e on an attacker-controlled DNS server, providing an out-of-band side chann= el. The exposure is highest on the camel-jms family because JmsBinding.extr= actBodyFromJms invokes ObjectMessage.getObject() unconditionally when mapJm= sMessage=3Dtrue (default). Affected components: camel-jms, camel-sjms, came= l-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http, camel-= infinispan, and the aggregation repository components camel-leveldb, camel-= cassandraql, camel-consul, camel-sql (JDBC aggregation repository). This is= sue affects Apache Camel: from 4.14.0 before 4.14.8, from 4.15.0 before 4.1= 8.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to a versi=
on that contains the CAMEL-23372 fix once available: 4.21.0 for the 4.21.x = line, 4.18.3 for the 4.18.x line, and 4.14.8 for the 4.14.x line. For deplo= yments that cannot upgrade immediately, configure a JMS-provider-side allow= -list (Apache ActiveMQ Artemis 'deserializationAllowList' / 'deserializatio= nDenyList', Apache ActiveMQ Classic 'org.apache.activemq.SERIALIZABLE_PACKA= GES') as the primary mitigation, and/or override the in-code default via th=
e endpoint-level 'deserializationFilter' option or the JVM-wide '-Djdk.seri= alFilter' system property with an explicit deny: '!java.net.**;java.**;java= x.**;org.apache.camel.**;!*' (or '!java.net.**;java.**;org.apache.camel.**;= !*' for the aggregation-repository components, which do not include javax.*= *). 2026-07-06 not yet calculated CVE-2026-42527 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-42527 ] Apache Software Foundation--Apache Camel Deseri= alization of Untrusted Data vulnerability in Apache Camel Hazelcast compone= nt. The camel-hazelcast component creates and manages Hazelcast instances u= sing a default configuration that applies no Java deserialization filter. W= hen Camel builds the Hazelcast Config itself - that is, when no user-suppli=
ed HazelcastInstance, hazelcastConfigUri, or referenced Config bean is prov= ided - neither Hazelcast's JavaSerializationFilterConfig nor a Camel-side O= bjectInputFilter is configured, so objects received over the Hazelcast clus= ter protocol are deserialized inside Hazelcast's own serialization layer (O= bjectInputStream.readObject) before Camel ever processes them. An attacker = who can join or otherwise reach the Hazelcast cluster can publish a crafted=
serialized Java object that is then deserialized on every Camel node, resu= lting in remote code execution. The exposure is present by default and requ= ires no opt-in endpoint configuration: any route using a hazelcast consumer=
(hazelcast-topic, hazelcast-queue, hazelcast-seda, hazelcast-map, hazelcas= t-multimap, hazelcast-replicatedmap, hazelcast-list, hazelcast-set), as wel=
l as the HazelcastAggregationRepository and HazelcastIdempotentRepository, =
is affected whenever the managed instance is created from Camel's default c= onfiguration. This issue affects Apache Camel: from 4.0.0 before 4.14.8, fr=
om 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended t=
o upgrade to version 4.21.0, which fixes the issue. If users are on the 4.1= 4.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If u= sers are on the 4.18.x releases stream, then they are suggested to upgrade =
to 4.18.3. The fix makes Camel apply a default Hazelcast JavaSerializationF= ilterConfig (whitelisting the java., javax. and org.apache.camel. class-nam=
e prefixes and blacklisting java.net.) to instances it creates from its own=
default configuration, while leaving any user-supplied Config or Hazelcast= Instance untouched. For deployments that cannot upgrade immediately, config= ure a deserialization filter on the Hazelcast instance (Hazelcast JavaSeria= lizationFilterConfig, or the JVM-wide system property -Djdk.serialFilter=3D= !java.net.**;java.**;javax.**;org.apache.camel.**;!*) and enable Hazelcast = cluster authentication and TLS to restrict who can reach the cluster. 2026-= 07-06 not yet calculated CVE-2026-43865 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-43865 ] Apache Software Foundation--Apache Camel Deserializatio=
n of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS compone= nt. JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBi= nding in camel-sjms - deserializes the payload of an incoming JMS ObjectMes= sage via jakarta.jms.ObjectMessage.getObject() whenever the mapJmsMessage o= ption is enabled (the default) and Camel acts as a JMS consumer. The CVE-20= 26-40860 hardening added a post-deserialization class check that rejects cl= asses outside the default allow-list java.**;javax.**;org.apache.camel.**;!=
*. However org.apache.camel.support.DefaultExchangeHolder itself lives in t=
he allow-listed org.apache.camel.** namespace, so an ObjectMessage whose to= p-level object is a DefaultExchangeHolder passes the check. The receiving s= ide then calls DefaultExchangeHolder.unmarshal() on it without requiring th=
e transferExchange option to be enabled - an asymmetric trust boundary, sin=
ce the sending side gates ObjectMessage and transferExchange handling but t=
he receiving side did not - writing every non-null field of the holder into=
the Exchange: the message body, the IN and OUT headers, the exchange prope= rties, the variables, the exchange id and the exception. An attacker who ca=
n publish an ObjectMessage to a queue or topic consumed by an affected Came=
l application can therefore inject arbitrary Exchange state using only univ= ersally-trusted java.lang and java.util types, with no deserialization gadg=
et chain required, to manipulate routing and headers, exchange properties a=
nd error handling. The same handling applies to camel-sjms and camel-sjms2,=
and to the JMS-family components built on JmsComponent and JmsBinding: cam= el-amqp, camel-activemq and camel-activemq6. This is a bypass of the CVE-20= 26-40860 fix rather than a flaw in it. This issue affects Apache Camel: fro=
m 3.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0=
; Apache Camel: from 3.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4= .19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, wh= ich fixes the issue. If users are on the 4.14.x LTS releases stream, then t= hey are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases=
stream, then they are suggested to upgrade to 4.18.3. After upgrading, JMS=
ObjectMessage handling is disabled by default in camel-jms, camel-sjms and=
the JMS-family components (a new objectMessageEnabled option defaults to f= alse at the component and endpoint level), so an incoming ObjectMessage - i= ncluding a DefaultExchangeHolder payload - is no longer deserialized unless=
the option is explicitly enabled; only set objectMessageEnabled=3Dtrue whe=
n the consumed JMS destination is fed exclusively by trusted producers. For=
deployments that cannot upgrade immediately, restrict publish access to th=
e queues and topics consumed by Camel to trusted producers via JMS broker a= uthorization, and do not expose JMS consumers that map ObjectMessage bodies=
to untrusted networks; a JMS-provider deserialization allow-list does not = mitigate this specific bypass because the crafted payload uses only univers= ally-trusted classes. 2026-07-06 not yet calculated CVE-2026-43866 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-43866 ] Apache Software Foundation--A= pache Camel Deserialization of Untrusted Data vulnerability in Apache Camel=
PQC Component. The camel-pqc component persists post-quantum key metadata = (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSec= retsManagerKeyLifecycleManager.deserializeMetadata() reads that metadata ba=
ck from the configured AWS Secrets Manager secret by Base64-decoding the st= ored value and deserializing it with a raw java.io.ObjectInputStream.readOb= ject() and no ObjectInputFilter or class allow-list; the cast to KeyMetadat=
a happens only after readObject() returns, so any readObject() side effects=
in a crafted object run before the type check. A principal who can write t=
o the AWS Secrets Manager secret that holds this metadata (requiring secret= smanager:PutSecretValue on that secret) could store a crafted serialized ob= ject that is deserialized during normal key-lifecycle operations, potential=
ly leading to code execution in the context of the application that manages=
the keys. This is the same underlying defect, in the same code path and re= mediated by the same fix, as CVE-2026-46590, which was reported independent=
ly and additionally covers the HashiCorp Vault and file-based sibling manag= ers; both are incomplete-remediation follow-ons to CVE-2026-40048 (CAMEL-23= 200). This issue affects Apache Camel: from 4.18.0 before 4.18.3, from 4.19=
.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which=
fixes the issue. If users are on the 4.18.x LTS releases stream, then they=
are suggested to upgrade to 4.18.3. For deployments that cannot upgrade im= mediately, restrict write access to the AWS Secrets Manager secret that hol=
ds the camel-pqc key metadata so that only the application's own identity h= olds secretsmanager:PutSecretValue on it (least-privilege IAM), and keep th=
e PQC key material in a secret separate from any data that less-trusted pri= ncipals can write. 2026-07-06 not yet calculated CVE-2026-43867 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-43867 ] Apache Software Foundation--Apac=
he Camel Improper Input Validation, Authorization Bypass Through User-Contr= olled Key vulnerability in Apache Camel ElasticSearch Rest Client. The came= l-elasticsearch-rest-client component reads several Exchange headers to con= trol its behaviour - SEARCH_QUERY (an advanced query body), OPERATION (whic=
h Elasticsearch operation to run), INDEX_NAME, INDEX_SETTINGS and ID. The s= tring values of these header constants, defined in ElasticSearchRestClientC= onstant, are plain unprefixed names ('SEARCH_QUERY', 'OPERATION', 'INDEX_NA= ME', 'INDEX_SETTINGS', 'ID') rather than the 'Camel'-prefixed names used by=
every other Camel component (for example CamelSqlQuery, CamelMongoDbCriter= ia, CamelCqlQuery). Camel's inbound HTTP header filter, HttpHeaderFilterStr= ategy, blocks only header names that begin with 'Camel' or 'camel'. Because=
the Elasticsearch header names do not carry that prefix, they pass through=
the inbound filter unchanged. When a Camel route exposes an HTTP entry poi=
nt (for example platform-http) in front of an elasticsearch-rest-client pro= ducer, an untrusted HTTP client can set these headers directly on its reque=
st and override the query and operation that the route author configured: r= eading every document in the index (SEARCH_QUERY with a match_all query), d= eleting documents (OPERATION set to Delete together with ID), or exfiltrati=
ng selected fields. No credentials are required and the producer reads the = headers unconditionally. This issue affects Apache Camel: from 4.3.0 before=
4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are re= commended to upgrade to version 4.21.0, which fixes the issue. If users are=
on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4= .14.8. If users are on the 4.18.x releases stream, then they are suggested =
to upgrade to 4.18.3. The fix renames the camel-elasticsearch-rest-client E= xchange header constant string values (ID, SEARCH_QUERY, INDEX_SETTINGS, IN= DEX_NAME, OPERATION) to carry the Camel prefix (CamelElasticsearchId, Camel= ElasticsearchSearchQuery, CamelElasticsearchIndexSettings, CamelElasticsear= chIndexName, CamelElasticsearchOperation) so that they are blocked by the i= nbound HttpHeaderFilterStrategy; the Java field names are unchanged. For de= ployments that cannot upgrade immediately, strip the affected headers from = untrusted inbound messages before they reach the producer (for example remo= veHeader('SEARCH_QUERY'), removeHeader('OPERATION'), removeHeader('INDEX_NA= ME'), removeHeader('INDEX_SETTINGS') and removeHeader('ID') in front of the=
elasticsearch-rest-client endpoint), or apply a custom HeaderFilterStrateg=
y that blocks these names. 2026-07-06 not yet calculated CVE-2026-46453 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-46453 ] Apache Software Foundati= on--Apache Camel Improper Input Validation vulnerability in Apache Camel Co= metd Component. The camel-cometd component maps inbound Bayeux (CometD) mes= sage headers into the Camel Exchange without applying a HeaderFilterStrateg=
y. CometdBinding.populateExchangeFromMessage copies the entire ext.CamelHea= ders map supplied by the CometD client directly onto the Camel message (mes= sage.setHeaders), so any header name - including Camel-internal control hea= ders such as CamelHttpUri, CamelFileName or CamelJmsDestinationName - is ac= cepted unmodified. Because a CometdComponent installs no Bayeux SecurityPol= icy by default, any client that can complete the Bayeux handshake against t=
he CometD endpoint can publish such a message without authentication. An at= tacker can therefore inject arbitrary Camel control headers that influence = the behaviour of downstream producers in the route (for example redirecting=
an HTTP producer, changing a file name, or overriding a JMS destination); = the injected headers also persist across internal direct, seda and vm hops.=
The concrete downstream impact depends on which producers the route uses. = This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 befo=
re 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to v= ersion 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releas=
es stream, then they are suggested to upgrade to 4.14.8. If users are on th=
e 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. The=
fix implements a HeaderFilterStrategy in the camel-cometd binding (a long-= standing TODO in the code) that filters the Camel header namespace case-ins= ensitively on inbound mapping, so client-supplied Camel* / camel* headers a=
re no longer copied into the Exchange. For deployments that cannot upgrade = immediately, strip the Camel control headers from inbound CometD messages b= efore they reach any downstream producer (for example removeHeaders('Camel*=
') and removeHeaders('camel*') at the start of the route), and install an e= xplicit Bayeux SecurityPolicy on the CometdComponent so that only authentic= ated clients can publish. 2026-07-06 not yet calculated CVE-2026-46454 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-46454 ] Apache Software Foundatio= n--Apache Camel Insufficient Session Expiration vulnerability in Apache Cam=
el Keycloak Component. The camel-keycloak security helper KeycloakSecurityH= elper.parseAndVerifyAccessToken builds a Keycloak TokenVerifier using withC= hecks(...) with only the subject-exists check and the realm-URL (issuer) ch= eck. Keycloak's TokenVerifier.withChecks(...) appends to an initially empty=
check list - the upstream default checks are installed only when withDefau= ltChecks() is called - so the built-in IS_ACTIVE predicate, which validates=
the token's exp (expiration) and nbf (not-before) claims, is never applied=
. As a result the helper verifies the token signature, subject and issuer b=
ut does not enforce the token's validity window: an access token that is ex= pired, or not yet valid, is accepted as valid. Routes that rely on this hel= per to authenticate inbound requests therefore accept access tokens that ar=
e outside their intended lifetime. This issue affects Apache Camel: from 4.= 18.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upg= rade to version 4.21.0, which fixes the issue. If users are on the 4.18.x r= eleases stream, then they are suggested to upgrade to 4.18.3. The fix makes=
KeycloakSecurityHelper.parseAndVerifyAccessToken include the TokenVerifier= .IS_ACTIVE check so that expired or not-yet-valid access tokens are rejecte=
d, aligning the helper with Keycloak's default check set. For deployments t= hat cannot upgrade immediately, enforce token expiration outside the helper=
- for example validate the access token's exp/nbf claims in the route befo=
re trusting it, keep Keycloak access-token lifetimes short, and ensure any = upstream gateway or resource server also validates the token validity windo=
w. 2026-07-06 not yet calculated CVE-2026-46455 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-46455 ] Apache Software Foundation--Apache Camel Imprope=
r Input Validation vulnerability in Apache Camel AWS2-SQS Component. The ca= mel-aws2-sqs component map inbound message attributes into the Camel Exchan=
ge through a component-specific HeaderFilterStrategy. Sqs2HeaderFilterStrat= egy configured only an outbound filter (setOutFilterPattern, which blocks C= amel*, breadcrumbId and org.apache.camel.* headers being written to the bro= ker) but did not configure an inbound filter. As a result, when Sqs2Consume=
r copies each SQS MessageAttribute into the Exchange via HeaderFilterStrate= gy.applyFilterToExternalHeaders, DefaultHeaderFilterStrategy applied no inb= ound rule and treated every header name as not filtered - including Camel-i= nternal control headers such as CamelHttpUri, CamelFileName or CamelSqlQuer=
y - copying them unmodified onto the Camel message. Any principal able to s= end messages to the consumed SQS queue (for example a cross-account sender =
or a lower-privileged in-account component holding sqs:SendMessage) could t= herefore set arbitrary Camel control headers that influence the behaviour o=
f downstream producers in the route (for example redirecting an HTTP produc= er, changing a file name, or overriding a query); the injected headers also=
persist across internal direct, seda and vm hops. The concrete downstream = impact depends on which producers the route uses. This issue affects Apache=
Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 be= fore 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixe=
s the issue. If users are on the 4.14.x LTS releases stream, then they are = suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream,=
then they are suggested to upgrade to 4.18.3. The fix adds an inbound Head= erFilterStrategy rule to Sqs2HeaderFilterStrategy that filters the Camel he= ader namespace case-insensitively on inbound mapping, so sender-supplied Ca= mel* / camel* headers are no longer copied into the Exchange. For deploymen=
ts that cannot upgrade immediately, strip the Camel control headers from in= bound messages before they reach any downstream producer (for example remov= eHeaders('Camel*') and removeHeaders('camel*') at the start of the route), = and restrict who may send to the consumed SQS queue by applying least-privi= lege sqs:SendMessage permissions on the queue resource policy. 2026-07-06 n=
ot yet calculated CVE-2026-46456 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-46456 ] Apache Software Foundation--Apache Camel Improper Input Validat= ion vulnerability in Apache Camel NATS component. The camel-nats component = maps inbound NATS message headers into the Camel Exchange but defaulted its=
headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no i= nbound rules configured (NatsConfiguration). With no inFilter, inFilterPatt= ern or inFilterStartsWith set, DefaultHeaderFilterStrategy.applyFilterToExt= ernalHeaders returns not filtered for every header name, so NatsConsumer co= pies every NATS message header - including Camel-internal control headers s= uch as CamelHttpUri, CamelFileName or CamelSqlQuery - unmodified onto the C= amel message. A client able to publish to the consumed NATS subject can the= refore inject arbitrary Camel control headers that influence the behaviour =
of downstream producers in the route (for example redirecting an HTTP produ= cer, changing a file name, or overriding a query); the injected headers als=
o persist across internal direct, seda and vm hops. The concrete downstream=
impact depends on which producers the route uses. NATS message headers req= uire NATS 2.2 or later, and the issue is reachable without credentials when=
the NATS server is configured without authentication (the NATS server defa= ult). This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.=
0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrad=
e to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS = releases stream, then they are suggested to upgrade to 4.14.8. If users are=
on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.=
3. The fix makes camel-nats default to a dedicated NatsHeaderFilterStrategy=
that filters the Camel header namespace case-insensitively on inbound mapp= ing, so client-supplied Camel* / camel* headers are no longer copied into t=
he Exchange. For deployments that cannot upgrade immediately, strip the Cam=
el control headers from inbound NATS messages before they reach any downstr= eam producer (for example removeHeaders('Camel*') and removeHeaders('camel*=
') at the start of the route), and enable authentication on the NATS server=
so that only trusted clients can publish to the consumed subject. 2026-07-=
06 not yet calculated CVE-2026-46457 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-46457 ] Apache Software Foundation--Apache Camel Improper Input Val= idation vulnerability in Apache Camel. This issue affects Apache Camel: thr= ough 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users = are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes t=
he issue. 2026-07-06 not yet calculated CVE-2026-46587 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-46587 ] Apache Software Foundation--Apache Camel = Improper Input Validation vulnerability in Apache Camel. This issue affects=
Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 thro= ugh 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.2= 1.0, which fixes the issue. 2026-07-06 not yet calculated CVE-2026-46588 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-46588 ] Apache Software Foundat= ion--Apache Camel Deserialization of Untrusted Data vulnerability in Apache=
Camel PQC component. The camel-pqc component persists post-quantum key met= adata (KeyMetadata) through pluggable KeyLifecycleManager implementations. = HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager = read that metadata back from the configured secret backend by deserializing=
a Base64-wrapped value with a raw java.io.ObjectInputStream.readObject() a=
nd no ObjectInputFilter or class allow-list; the cast to KeyMetadata happen=
s only after readObject() returns, so any readObject() side effects in a cr= afted object run before the type check. The same unfiltered legacy-migratio=
n read also remained in FileBasedKeyLifecycleManager (for the stored KeyPai=
r and KeyMetadata). A principal who can write to the operator-controlled ba= ckend that holds these values - the HashiCorp Vault KV path, or the AWS Sec= rets Manager secret (requiring a Vault token or secretsmanager:PutSecretVal= ue) - could store a crafted serialized object that is deserialized during n= ormal key-lifecycle operations, potentially leading to code execution in th=
e context of the application that manages the keys. This is an incomplete-r= emediation follow-on to CVE-2026-40048 (CAMEL-23200), which changed FileBas= edKeyLifecycleManager to store metadata as JSON / PKCS#8 / X.509 but did no=
t add an ObjectInputFilter, did not cover the Vault and AWS sibling manager=
s, and left FileBasedKeyLifecycleManager's own legacy-migration deserializa= tion unfiltered. This issue affects Apache Camel: from 4.18.0 before 4.18.3=
, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.= 21.0, which fixes the issue. If users are on the 4.18.x LTS releases stream=
, then they are suggested to upgrade to 4.18.3. For deployments that cannot=
upgrade immediately, restrict write access to the key backend so that only=
the application's own identity can write the camel-pqc secrets (least-priv= ilege HashiCorp Vault policies and secretsmanager:PutSecretValue IAM), and = keep the PQC key material in a backend separate from any data that less-tru= sted principals can write. 2026-07-06 not yet calculated CVE-2026-46590 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-46590 ] Apache Software Foundati= on--Apache Camel Improper Neutralization of Special Elements in Data Query = Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j produc=
er builds the Cypher WHERE clause for its match/retrieve and delete operati= ons from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher=
injection through the property values by binding them as query parameters = ($paramN), but the property names (the JSON keys of that map) were still co= ncatenated into the query string verbatim in Neo4jProducer.retrieveNodes() = and deleteNode(). A property name containing Cypher syntax therefore alters=
the structure of the executed query. Where a route maps untrusted input in=
to the CamelNeo4jMatchProperties map - for example by passing a request bod=
y as the match map, or from a consumer that does not filter inbound Camel* = headers - an attacker who controls the JSON key names can inject arbitrary = Cypher and read, modify or delete any node or relationship in the Neo4j dat= abase. The CamelNeo4jMatchProperties header is itself Camel-prefixed and is=
filtered by the HTTP header-filter strategy, so a plain HTTP client cannot=
set it directly; the issue is reachable through routes that deliberately o=
r inadvertently carry untrusted data into that header. This issue affects A= pache Camel: from 4.10.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.1= 9.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, whic=
h fixes the issue. If users are on the 4.14.x LTS releases stream, then the=
y are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases s= tream, then they are suggested to upgrade to 4.18.3. For deployments that c= annot upgrade immediately, do not populate the CamelNeo4jMatchProperties ma=
p from untrusted input: validate or allow-list the property names (for exam= ple against ^[A-Za-z_][A-Za-z0-9_]*$) before the Neo4j producer, and ensure=
that any consumer feeding such a route filters inbound Camel* / camel* hea= ders so the match header cannot be supplied by an external sender. 2026-07-=
06 not yet calculated CVE-2026-46591 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-46591 ] Apache Software Foundation--Apache Camel Improper Input Val= idation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability=
in Apache Camel CXF SOAP component. The camel-cxf producer selects which S= OAP operation to invoke on the backend service from the operationName (and = operationNamespace) Exchange header, whose constant values (CxfConstants.OP= ERATION_NAME / OPERATION_NAMESPACE) were the plain strings operationName / = operationNamespace. Because these names do not start with the Camel / camel=
prefix, HttpHeaderFilterStrategy - which blocks only the Camel header name= space on the HTTP boundary - let them pass from an inbound HTTP request str= aight into the Exchange. In a route that bridges an HTTP consumer (for exam= ple platform-http) into a cxf: producer, any HTTP client could therefore se=
t the operationName header and have CxfProducer resolve and invoke a differ= ent WSDL operation than the route intended - for example replacing a read o= peration with a destructive one - against the backend SOAP service (a confu= sed-deputy redirection). The constant is defined in the shared camel-cxf-co= mmon module, so the same non-prefixed names also applied to camel-cxfrs. No=
credentials are required when the bridging consumer is unauthenticated. Th=
is issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before=
4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to ver= sion 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases=
stream, then they are suggested to upgrade to 4.14.8. If users are on the = 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After=
upgrading, the operation-selection headers are named CamelCxfOperationName=
/ CamelCxfOperationNamespace and are filtered at transport boundaries; see=
the 4.21 upgrade guide for the cross-transport carrier-header pattern. For=
deployments that cannot upgrade immediately, do not select the CXF operati=
on from untrusted input: strip the operationName and operationNamespace hea= ders from any untrusted ingress before the cxf: producer and set the operat= ion from a trusted source in the route. 2026-07-06 not yet calculated CVE-2= 026-46592 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46592 ] Apache Soft= ware Foundation--Apache Camel Improper Neutralization of Special Elements i=
n Output Used by a Downstream Component ('Injection'), Improper Input Valid= ation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel Sol=
r component. The camel-solr producer copies Exchange message headers whose = names begin with the SolrParam. prefix into the parameters of the Solr requ= est, and headers whose names begin with the SolrField. prefix into the fiel=
ds of the indexed Solr document. The prefix constants (SolrConstants.HEADER= _PARAM_PREFIX / HEADER_FIELD_PREFIX) were the plain strings SolrParam. / So= lrField.. Because these names do not start with the Camel / camel prefix, H= ttpHeaderFilterStrategy - which blocks only the Camel header namespace on t=
he HTTP boundary - let them pass from an inbound HTTP request straight into=
the Exchange. In a route that bridges an HTTP consumer (for example platfo= rm-http) into a solr: producer, any HTTP client could therefore set SolrPar= am.* headers to inject arbitrary Solr request parameters - including shards=
or stream.url, which cause the Solr server to issue server-side requests t=
o an attacker-chosen URL (server-side request forgery, for example to an in= ternal service or a cloud metadata endpoint), or qt to reach administrative=
request handlers - and set SolrField.* headers to inject arbitrary fields = into indexed documents. No credentials are required when the bridging consu= mer is unauthenticated. This issue affects Apache Camel: from 4.0.0 before = 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are rec= ommended to upgrade to version 4.21.0, which fixes the issue. If users are =
on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.= 14.8. If users are on the 4.18.x releases stream, then they are suggested t=
o upgrade to 4.18.3. After upgrading, routes that set Solr parameters or fi= elds via the raw header prefixes must use CamelSolrParam. / CamelSolrField.=
instead of SolrParam. / SolrField.. For deployments that cannot upgrade im= mediately, strip the SolrParam.* and SolrField.* headers from any untrusted=
ingress before the solr: producer, and set the required Solr parameters an=
d fields from a trusted source in the route. 2026-07-06 not yet calculated = CVE-2026-48203 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48203 ] Apache=
Software Foundation--Apache Camel Improper Input Validation, Improper Acce=
ss Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.=
The camel-mongodb-gridfs producer selects the GridFS operation to perform = from the gridfs.operation Exchange header when the endpoint's operation par= ameter is not set - which is the default. The control-header constants (Gri= dFsConstants.GRIDFS_OPERATION, GRIDFS_OBJECT_ID, GRIDFS_METADATA, GRIDFS_CH= UNKSIZE, GRIDFS_FILE_ID_PRODUCED) were the plain strings gridfs.operation, = gridfs.objectid, gridfs.metadata, gridfs.chunksize and gridfs.fileid. Becau=
se these names do not start with the Camel / camel prefix, HttpHeaderFilter= Strategy - which blocks only the Camel header namespace on the HTTP boundar=
y - let them pass from an inbound HTTP request straight into the Exchange. =
In a route that bridges an HTTP consumer (for example platform-http) into a=
mongodb-gridfs: producer with no explicit operation, any HTTP client could=
therefore set the gridfs.operation header to override the route's intended=
operation - switching, for example, a file upload to remove (deleting a fi=
le identified by the attacker-supplied gridfs.objectid), listAll (enumerati=
ng every file in the bucket) or findOne (reading a file) - and supply a gri= dfs.metadata value that is parsed as a MongoDB document, enabling NoSQL ope= rator injection. No credentials are required when the bridging consumer is = unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8,=
from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommende=
d to upgrade to version 4.21.0, which fixes the issue. If users are on the = 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. I=
f users are on the 4.18.x releases stream, then they are suggested to upgra=
de to 4.18.3. After upgrading, routes that drive GridFS operations or metad= ata via the raw header names must use CamelGridFsOperation / CamelGridFsObj= ectId / CamelGridFsMetadata / CamelGridFsChunkSize / CamelGridFsFileId inst= ead of the gridfs.* names. For deployments that cannot upgrade immediately,=
set an explicit operation on the mongodb-gridfs: endpoint so the operation=
is not taken from a header, and strip the gridfs.* headers from any untrus= ted ingress before the producer. 2026-07-06 not yet calculated CVE-2026-482=
04 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48204 ] Apache Software Fo= undation--Apache Camel Improper Input Validation vulnerability in Apache Ca= mel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.=
0 through 4.20.0. Users are recommended to upgrade to version 4.18.3, 4.21.=
0, which fixes the issue. 2026-07-06 not yet calculated CVE-2026-49042 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-49042 ] Apache Software Foundatio= n--Apache Camel Improper Input Validation, Improper Neutralization of Speci=
al Elements in Output Used by a Downstream Component ('Injection') vulnerab= ility in Apache Camel IRC component. The camel-irc producer chooses the des= tination of an outgoing IRC message from the irc.sendTo Exchange header (th=
e constant IrcConstants.IRC_SEND_TO, value irc.sendTo); when that header is=
present it overrides the channel list configured on the endpoint, and the = message is sent only to the specified destination. This and the component's=
other control headers (irc.target, irc.messageType, irc.user.*, irc.num, i= rc.value) used plain, non-Camel-prefixed values. Because these names do not=
start with the Camel / camel prefix, HttpHeaderFilterStrategy - which bloc=
ks only the Camel header namespace on the HTTP boundary - let them pass fro=
m an inbound HTTP request straight into the Exchange. In a route that bridg=
es an HTTP consumer (for example platform-http) into an irc: producer, any = HTTP client could therefore set the irc.sendTo header and redirect a messag=
e that the route intended for a configured channel to an arbitrary IRC chan= nel or user - exfiltrating the message content to an attacker-chosen nickna= me, leaking it into a public channel, or delivering messages that appear to=
come from the bot. No credentials are required when the bridging consumer =
is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14= .8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recomme= nded to upgrade to version 4.21.0, which fixes the issue. If users are on t=
he 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8=
. If users are on the 4.18.x releases stream, then they are suggested to up= grade to 4.18.3. After upgrading, routes that set IRC headers via the raw h= eader names must use the CamelIrc* names (for example CamelIrcSendTo) inste=
ad of the old irc.* values. For deployments that cannot upgrade immediately=
, strip the irc.* headers from any untrusted ingress before the irc: produc=
er (for example removeHeaders('irc.*') at the start of the route), and set = the IRC destination from a trusted source. 2026-07-06 not yet calculated CV= E-2026-49097 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49097 ] Apache S= oftware Foundation--Apache Camel Improper Input Validation, Improper Neutra= lization of Special Elements in Output Used by a Downstream Component ('Inj= ection') vulnerability in Apache Camel Kafka Component. The camel-kafka pro= ducer can override its configured target topic at runtime from the kafka.OV= ERRIDE_TOPIC Exchange header: KafkaProducer.evaluateTopic() returns the hea= der value in preference to the topic configured on the endpoint. The contro= l-header constants in KafkaConstants (for example OVERRIDE_TOPIC =3D kafka.= OVERRIDE_TOPIC, OVERRIDE_TIMESTAMP =3D kafka.OVERRIDE_TIMESTAMP, PARTITION_= KEY =3D kafka.PARTITION_KEY) used plain, non-Camel-prefixed values. camel-k= afka's own KafkaHeaderFilterStrategy does filter the kafka.* namespace, but=
only on the Kafka-to-Exchange serialization boundary (reading Kafka record=
headers into the Exchange, and writing Exchange headers into a Kafka recor= d); it does not apply to headers that arrive from an upstream consumer in a=
multi-component route. The upstream HTTP consumer uses HttpHeaderFilterStr= ategy, which blocks only the Camel / camel namespace, so a kafka.* header p= asses through unfiltered. As a result, in a route that bridges an HTTP cons= umer (for example platform-http) into a kafka: producer, any HTTP client co= uld set the kafka.OVERRIDE_TOPIC header and cause the message to be publish=
ed to an arbitrary Kafka topic instead of the configured one - redirecting =
it to a sensitive internal topic, or injecting attacker-crafted messages in=
to a topic consumed by a critical downstream service. The related kafka.OVE= RRIDE_TIMESTAMP and kafka.PARTITION_KEY headers could likewise be injected =
to backdate messages or target specific partitions. No credentials are requ= ired when the bridging consumer is unauthenticated. This issue affects Apac=
he Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 = before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fi= xes the issue. If users are on the 4.14.x LTS releases stream, then they ar=
e suggested to upgrade to 4.14.8. If users are on the 4.18.x releases strea=
m, then they are suggested to upgrade to 4.18.3. After upgrading, routes th=
at set or read Kafka headers via the raw header names must use the CamelKaf= ka* names (for example CamelKafkaOverrideTopic and CamelKafkaTopic) instead=
of the old kafka.* values. For deployments that cannot upgrade immediately=
, strip the kafka.* headers from any untrusted ingress before the kafka: pr= oducer (for example removeHeaders('kafka.*') at the start of the route), an=
d set the target topic from a trusted source. 2026-07-06 not yet calculated=
CVE-2026-49098 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49098 ] Apach=
e Software Foundation--Apache Camel Generation of Error Message Containing = Sensitive Information vulnerability in Apache Camel Netty HTTP component. T=
he camel-netty-http HTTP server consumer exposes a muteException option tha=
t controls what is returned to the client when a route processing error occ= urs. This option defaulted to false because the backing field was an uninit= ialised primitive boolean (Java's default of false), whereas the other Came=
l HTTP server components (camel-http / camel-jetty / camel-servlet and came= l-platform-http) default it to true. With muteException=3Dfalse, when a req= uest triggers an exception during route processing the consumer writes the = full Throwable stack trace into the HTTP response body as text/plain (via D= efaultNettyHttpBinding) instead of returning an empty body. Any unauthentic= ated client that can reach the endpoint and cause a processing error - for = example by sending a malformed request body, an invalid parameter, or other= wise triggering a route-internal failure - therefore receives a complete Ja=
va stack trace. Such a stack trace can disclose sensitive internal informat= ion, including credentials embedded in exception messages, internal host na= mes and IP addresses, filesystem paths, dependency and version details, dat= abase and class names, and the application's internal structure, which an a= ttacker can use to plan further attacks. This issue affects Apache Camel: f= rom 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21= .0. Users are recommended to upgrade to version 4.21.0, which fixes the iss= ue. If users are on the 4.14.x LTS releases stream, then they are suggested=
to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then the=
y are suggested to upgrade to 4.18.3. For deployments that cannot upgrade i= mmediately, set muteException=3Dtrue explicitly on the camel-netty-http con= sumer (for example netty-http:
http://0.0.0.0:8080/api?muteException=3Dtrue=
, or globally via the camel.component.netty-http.configuration.mute-except= ion=3Dtrue property), so that processing errors no longer return the stack = trace to the client. 2026-07-06 not yet calculated CVE-2026-49365 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-49365 ] Apache Software Foundation--Ap= ache Camel Atmosphere Websocket Improper Input Validation, Exposure of Sens= itive Information to an Unauthorized Actor, Server-Side Request Forgery (SS= RF) vulnerability in Apache Camel in Atmosphere Websocket Component. The ca= mel-atmosphere-websocket consumer mapped inbound WebSocket query parameters=
into the Camel Exchange header map without applying any HeaderFilterStrate=
gy (WebsocketConsumer.sendEventNotification() iterates the query-string map=
collected in WebsocketConsumer.service() and copies each entry into the Ex= change). Because nothing blocked the Camel header namespace, a client conne= cting to the WebSocket endpoint could set Camel-internal control headers - = including CamelHttpUri (Exchange.HTTP_URI) - simply by supplying them as qu= ery parameters. In a route where the WebSocket consumer feeds a downstream = HTTP producer, the injected CamelHttpUri redirects the server-side HTTP req= uest to an attacker-chosen destination (server-side request forgery - for e= xample to an internal service or a cloud metadata endpoint). In addition, t=
he HTTP producer resolves Camel property placeholders on the resulting (att= acker-controlled) URI, so placeholders embedded in the injected value - suc=
h as an environment-variable reference, an application property, or a vault=
reference - are resolved to their real values and sent to the attacker, di= sclosing environment variables, application properties and vault secrets. W= hen the WebSocket endpoint is exposed without authentication, this is reach= able by an unauthenticated remote attacker. This issue affects Apache Camel=
: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4= .21.0. Users are recommended to upgrade to version 4.21.0, which fixes the = issue. If users are on the 4.14.x LTS releases stream, then they are sugges= ted to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then = they are suggested to upgrade to 4.18.3. The fix makes the consumer apply t=
he HeaderFilterStrategy it already inherits from the HTTP/servlet stack, fi= ltering the Camel header namespace case-insensitively on inbound mapping, s=
o externally-supplied Camel* / camel* headers are no longer copied into the=
Exchange. For deployments that cannot upgrade immediately, strip the Camel=
control headers from the inbound message before they reach any downstream = producer (for example removeHeaders('Camel*') and removeHeaders('camel*') a=
t the start of the route), require authentication on the WebSocket endpoint=
, and avoid bridging an untrusted consumer directly into an HTTP producer w= hose target URI can be driven from message headers. 2026-07-06 not yet calc= ulated CVE-2026-55993 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55993 ]=
Apache Software Foundation--Apache Camel AWS2 SNS Improper Input Validatio=
n vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns compo= nent filters Camel headers through a component-specific HeaderFilterStrateg=
y, Sns2HeaderFilterStrategy. Like the sibling Sqs2HeaderFilterStrategy, it = originally configured only an outbound filter (setOutFilterPattern, which b= locks Camel*, breadcrumbId and org.apache.camel.* headers from being writte=
n out) and did not configure an inbound filter rule. For the related camel-= aws2-sqs component this inbound gap was exploitable, because the Sqs2Consum=
er maps inbound SQS message attributes into the Camel Exchange via HeaderFi= lterStrategy.applyFilterToExternalHeaders, allowing a message sender to inj= ect Camel control headers (tracked as CVE-2026-46456). camel-aws2-sns, by c= ontrast, is producer-only: Sns2Endpoint does not support consumers (createC= onsumer throws UnsupportedOperationException, 'You cannot receive messages = from this endpoint'), so no externally-supplied message attributes are ever=
mapped inbound into a Camel Exchange through SNS, and the missing inbound = filter rule on Sns2HeaderFilterStrategy was therefore not reachable by an a= ttacker. As part of the same fix (CAMEL-23506), an inbound filter rule (set= InFilterStartsWith for the Camel namespace) was added to Sns2HeaderFilterSt= rategy so that its configuration matches the corrected Sqs2HeaderFilterStra= tegy and the other sibling strategies. This is a defense-in-depth alignment=
with no known exploit path in camel-aws2-sns. This issue affects Apache Ca= mel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 befor=
e 4.21.0. This is a defense-in-depth hardening change with no known exploit=
path in camel-aws2-sns, which is producer-only, so no urgent action or wor= karound is required. Users who want the aligned behaviour can upgrade to ve= rsion 4.21.0, or to 4.14.8 on the 4.14.x LTS releases stream, or to 4.18.3 =
on the 4.18.x releases stream, which contain the change. As a general best = practice, operators should continue to apply least-privilege IAM permission=
s on their SNS topics. 2026-07-06 not yet calculated CVE-2026-56140 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-56140 ] Apache Software Foundation--= Apache Camel Dapr Improper Input Validation, Unintended Proxy or Intermedia=
ry ('Confused Deputy') vulnerability in Apache Camel DAPR component. The ca= mel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from = each inbound CloudEvent - its Pub/Sub component name and its topic - into t=
he CamelDaprPubSubName and CamelDaprTopic Exchange headers. These two heade=
rs are producer-direction routing headers: when the route republishes throu=
gh a Dapr producer, DaprConfigurationOptionsProxy reads them back and prefe=
rs them over the destination configured on the endpoint. As a result, in a = route that consumes from one Dapr Pub/Sub topic and republishes to another = (for example from('dapr-pubsub:p:t').to('dapr-pubsub:p:other')), an actor a= ble to publish a message to the subscribed topic could set the CloudEvent's=
pub/sub-name and topic to values of their choosing and cause the re-publis= hed message to be delivered to an arbitrary Dapr Pub/Sub component and topi=
c instead of the configured destination - redirecting or exfiltrating the m= essage and bypassing the route's intended routing and any topic-level acces=
s controls in the underlying broker. Exploitation requires the ability to p= ublish to the topic the route subscribes to; no other authentication or use=
r interaction is needed. This issue affects Apache Camel: from 4.12.0 befor=
e 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are r= ecommended to upgrade to version 4.21.0, which fixes the issue. If users ar=
e on the 4.14.x LTS releases stream, then they are suggested to upgrade to = 4.14.8. If users are on the 4.18.x releases stream, then they are suggested=
to upgrade to 4.18.3. For deployments that cannot upgrade immediately, rem= ove the CamelDaprPubSubName and CamelDaprTopic headers from the Exchange be= tween the Dapr consumer and any Dapr producer in the route (for example rem= oveHeaders('CamelDaprPubSubName', 'CamelDaprTopic')), and restrict who can = publish to the subscribed Dapr Pub/Sub topic so that only trusted producers=
can send to it. 2026-07-06 not yet calculated CVE-2026-49086 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-49086 ] Apache Software Foundation--Apache=
Camel DNS Improper Input Validation, Server-Side Request Forgery (SSRF) vu= lnerability in Apache Camel DNS component. The camel-dns producers read DNS=
operation parameters - the resolver to query, the name or domain to look u=
p, the record type and class, and the search term - from Exchange message h= eaders whose constant values (DnsConstants.DNS_SERVER, DNS_NAME, DNS_DOMAIN=
, DNS_TYPE, DNS_CLASS, TERM) were the plain strings dns.server, dns.name, d= ns.domain, dns.type, dns.class and term. Because these names do not start w= ith the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only = the Camel header namespace on the HTTP boundary - let them pass from an inb= ound HTTP request straight into the Exchange. In a route that bridges an HT=
TP consumer (for example platform-http) into a dns: producer, any HTTP clie=
nt could therefore set the dns.server header to make the dig producer build=
a SimpleResolver pointing at an attacker-controlled DNS server - a server-= side request forgery via DNS, through which the attacker observes the queri=
ed name and can return poisoned responses - and set the dns.name / dns.doma=
in headers to resolve arbitrary internal hostnames, disclosing whether they=
exist (internal network reconnaissance). No credentials are required when = the bridging consumer is unauthenticated. This issue affects Apache Camel: = from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.2= 1.0. Users are recommended to upgrade to version 4.21.0, which fixes the is= sue. If users are on the 4.14.x LTS releases stream, then they are suggeste=
d to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then th=
ey are suggested to upgrade to 4.18.3. After upgrading, routes that drive D=
NS operations via the raw header names must use CamelDnsServer / CamelDnsNa=
me / CamelDnsDomain / CamelDnsType / CamelDnsClass / CamelDnsTerm instead o=
f the dns.* / term names. For deployments that cannot upgrade immediately, = strip the dns.* and term headers from any untrusted ingress before the dns:=
producer, and set the DNS server and lookup parameters from a trusted sour=
ce in the route. 2026-07-06 not yet calculated CVE-2026-48205 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-48205 ] Apache Software Foundation--Apache=
Camel Iggy Improper Input Validation, Exposure of Sensitive Information to=
an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in=
Apache Camel in Iggy component. The camel-iggy consumer mapped the user-he= aders of inbound Iggy messages into the Camel Exchange header map without a= pplying any HeaderFilterStrategy (IggyFetchRecords copied the message user-= headers straight into the Exchange). Because nothing blocked the Camel head=
er namespace, an actor able to publish to the consumed Iggy stream/topic co= uld set Camel-internal control headers - including CamelHttpUri (Exchange.H= TTP_URI) - simply by supplying them as message user-headers. In a route whe=
re the Iggy consumer feeds a downstream HTTP producer, the injected CamelHt= tpUri redirects the server-side HTTP request to an attacker-chosen destinat= ion (server-side request forgery - for example to an internal service or a = cloud metadata endpoint). In addition, the HTTP producer resolves Camel pro= perty placeholders on the resulting (attacker-controlled) URI, so placehold= ers embedded in the injected value - such as an environment-variable refere= nce, an application property, or a vault reference - are resolved to their = real values and sent to the attacker, disclosing environment variables, app= lication properties and vault secrets. This issue affects Apache Camel: fro=
m 4.17.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to=
upgrade to version 4.21.0, which fixes the issue. If users are on the 4.18=
.x releases stream, then they are suggested to upgrade to 4.18.3. The fix a= dds a dedicated IggyHeaderFilterStrategy (and a headerFilterStrategy endpoi=
nt option) that filters the Camel header namespace case-insensitively on in= bound mapping, so externally-supplied Camel* / camel* headers are no longer=
copied into the Exchange. For deployments that cannot upgrade immediately,=
strip the Camel control headers from the inbound message before they reach=
any downstream producer (for example removeHeaders('Camel*') and removeHea= ders('camel*') at the start of the route), restrict who can publish to the = consumed Iggy stream/topic, and avoid bridging an untrusted consumer direct=
ly into an HTTP producer whose target URI can be driven from message header=
s. 2026-07-06 not yet calculated CVE-2026-55994 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-55994 ] Apache Software Foundation--Apache Camel JIRA Im= proper Input Validation, Authorization Bypass Through User-Controlled Key v= ulnerability in Apache Camel JIRA component. The camel-jira producers read = their operation parameters - the issue key, project key, transition id, sum= mary, type, assignee, components, watchers, link type, work-log minutes and=
others - from Exchange message headers. The header constants defined in Ji= raConstants (for example ISSUE_KEY =3D IssueKey, ISSUE_PROJECT_KEY =3D Proj= ectKey, ISSUE_TRANSITION_ID =3D IssueTransitionId, LINK_TYPE =3D linkType) = used plain, non-Camel-prefixed values. Because these names do not start wit=
h the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only th=
e Camel header namespace on the HTTP boundary - let them pass from an inbou=
nd HTTP request straight into the Exchange. In a route that bridges an HTTP=
consumer (for example platform-http) into a jira: producer, any HTTP clien=
t could therefore supply these headers and override the values the route in= tended, driving JIRA operations against the configured JIRA instance with t=
he endpoint's configured service-account credentials - for example deleting=
or transitioning an arbitrary issue (via IssueKey / IssueTransitionId), cr= eating an issue in a different project (via ProjectKey), modifying issue fi= elds, adding or removing watchers, or logging work. The operations are boun= ded by what the configured service account is permitted to do. No credentia=
ls are required from the attacker when the bridging consumer is unauthentic= ated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.=
0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrad=
e to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS = releases stream, then they are suggested to upgrade to 4.14.8. If users are=
on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.=
3. After upgrading, routes that drive JIRA operations via the raw header na= mes must use the CamelJira* names (for example CamelJiraIssueKey) instead o=
f the old values. For deployments that cannot upgrade immediately, strip th=
e camel-jira control headers from any untrusted ingress before the jira: pr= oducer (for example removing the IssueKey, ProjectKey, IssueTransitionId an=
d related headers at the start of the route), and set the required JIRA ope= ration parameters from a trusted source. 2026-07-06 not yet calculated CVE-= 2026-48206 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48206 ] Apache Sof= tware Foundation--Apache Camel Keycloak Improper Authentication, Missing Au= thentication for Critical Function, Not Failing Securely ('Failing Open') v= ulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy=
of camel-keycloak guards a route by running KeycloakSecurityProcessor.befo= reProcess(), which performs three checks in sequence: it rejects a request = that carries no access token, then - only if requiredRoles is non-empty - v= alidates the roles, and - only if requiredPermissions is non-empty - valida= tes the permissions. The actual cryptographic verification of the bearer ac= cess token (signature, issuer and expiry for a local JWT, or active-state a=
nd issuer for token introspection) is performed exclusively inside those ro=
le and permission checks. KeycloakSecurityPolicy defaults requiredRoles and=
requiredPermissions to empty - which is the documented 'Basic Setup' - so =
on a route configured that way the role and permission checks are skipped a=
nd the access token is therefore never verified. The token-presence check s= till rejects a missing token, but an invalid token is accepted: any non-nul=
l value in the Authorization: Bearer header - including an arbitrary string=
or a forged, unsigned JWT - passes the policy and the request reaches the = protected route, with no signature, issuer or expiry check and no request t=
o Keycloak. The token is read from the inbound request header because allow= TokenFromHeader defaults to true. Because the normal reason to place a rout=
e behind this policy is that the route performs server-side work, the bypas=
s results in unauthenticated access to that work; where the protected route=
forwards to a code-execution-capable producer, it can result in unauthenti= cated remote code execution. This defect is independent of CVE-2026-23552: = that issue concerned the issuer claim and was fixed by adding a check insid=
e the verification routine, but here the verification routine is not reache=
d at all in the default configuration, so the defect remains. This issue af= fects Apache Camel: from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. U= sers are recommended to upgrade to version 4.21.0, which fixes the issue. I=
f users are on the 4.18.x releases stream, then they are suggested to upgra=
de to 4.18.3. For deployments that cannot upgrade immediately, configure a = non-empty requiredRoles or requiredPermissions on every KeycloakSecurityPol= icy so that the token-verification path is exercised, set allowTokenFromHea= der to false where the token is not expected from the request header, or pe= rform token verification at the framework layer ahead of the policy. 2026-0= 7-06 not yet calculated CVE-2026-53913 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-53913 ] Apache Software Foundation--Apache Camel Lucene Imprope=
r Input Validation, Authorization Bypass Through User-Controlled Key vulner= ability in Apache Camel Lucene Component. The camel-lucene producer reads t=
he search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) who=
se value was the plain string QUERY (and RETURN_LUCENE_DOCS for HEADER_RETU= RN_LUCENE_DOCS). Because these names do not start with the Camel / camel pr= efix, HttpHeaderFilterStrategy - which blocks only the Camel header namespa=
ce on the HTTP boundary - let them pass from an inbound HTTP request straig=
ht into the Exchange. In a route that exposes a Lucene query operation behi=
nd an HTTP consumer (for example platform-http), any HTTP client could ther= efore set the QUERY header and have its value executed against the full-tex=
t index, overriding the query the route intended to run. Depending on what =
is indexed, this allows reading documents the request should not have acces=
s to (for example a match-all query returns the entire index, or the route'=
s intended per-user filter can be replaced), and expensive regular-expressi=
on queries can consume significant CPU. No credentials are required when th=
e HTTP consumer is unauthenticated. This issue affects Apache Camel: from 4= .0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. U= sers are recommended to upgrade to version 4.21.0, which fixes the issue. I=
f users are on the 4.14.x LTS releases stream, then they are suggested to u= pgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are=
suggested to upgrade to 4.18.3. After upgrading, routes that set the query=
via the raw header name must use CamelLuceneQuery (and CamelLuceneReturnLu= ceneDocs) instead of QUERY / RETURN_LUCENE_DOCS. For deployments that canno=
t upgrade immediately, strip the attacker-controllable headers before the L= ucene producer and set the query from a trusted source (for example removeH= eader('QUERY') and removeHeader('RETURN_LUCENE_DOCS'), then setHeader('QUER= Y', constant(...)) at the start of the route). 2026-07-06 not yet calculate=
d CVE-2026-46585 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46585 ] Apac=
he Software Foundation--Apache Camel Mail Improper Input Validation, Exposu=
re of Sensitive Information to an Unauthorized Actor vulnerability in Apach=
e Camel Mail Component. The camel-mail producer (MailProducer.getSender) sc= anned the outgoing Exchange for message headers in the mail.smtp. / mail.sm= tps. namespace and, when any were present, built a per-message JavaMail sen= der with those values applied as JavaMail session properties, overriding th=
e endpoint configuration. This namespace is Camel-internal - only MailProdu= cer interprets it - and was not blocked by any HeaderFilterStrategy, so the=
values could originate from any inbound protocol (for example platform-htt=
p query parameters or request headers, or JMS / Kafka messages from untrust=
ed producers) that feeds a route ending in an smtp / smtps producer without=
an intervening removeHeaders. The maximal impact is version-dependent: on = releases before 4.19.0, setting mail.smtp.host redirects the SMTP connectio=
n to a server under the attacker's control, and because the producer then a= uthenticates with the endpoint's configured username and password those cre= dentials are transmitted to the attacker; on 4.19.0 and later the producer = connects to the endpoint's configured host explicitly, so the reachable imp= act is limited to weakening transport security (for example mail.smtp.ssl.t= rust, mail.smtp.starttls.enable or mail.smtp.socks.host) and interception o=
f the outgoing message rather than host redirect. Exploitation requires a r= oute that channels untrusted input into the mail producer without stripping=
the namespace. This issue affects Apache Camel: from 4.0.0 before 4.14.8, = from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended=
to upgrade to version 4.21.0, which fixes the issue. If users are on the 4= .14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If=
users are on the 4.18.x releases stream, then they are suggested to upgrad=
e to 4.18.3. After upgrading, the per-message override is disabled by defau= lt; enable it only on trusted endpoints with useJavaMailSessionPropertiesFr= omHeaders=3Dtrue. For deployments that cannot upgrade immediately, strip th=
e namespace before the mail producer with removeHeaders('mail.smtp.*') and = removeHeaders('mail.smtps.*') between any untrusted ingress and the smtp / = smtps producer. Even with the opt-in enabled, route authors should still st= rip the namespace on any path that carries untrusted input. 2026-07-06 not = yet calculated CVE-2026-46584 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -46584 ] Apache Software Foundation--Apache Camel Salesforce Improper Neutr= alization of Special Elements in Output Used by a Downstream Component ('In= jection'), Authorization Bypass Through User-Controlled Key vulnerability i=
n Apache Camel Salesforce Component. The camel-salesforce producer resolves=
its operation parameters - the SOQL query, the SOSL search, the target SOb= ject name and id, the Apex REST URL and method, and the Apex query paramete=
rs - from Exchange message headers, reading the header in preference to the=
value configured on the endpoint (AbstractSalesforceProcessor.getParameter=
() reads the header first and uses the endpoint configuration only as a fal= lback). The control-header constants in SalesforceEndpointConfig (for examp=
le SOBJECT_QUERY =3D sObjectQuery, SOBJECT_SEARCH =3D sObjectSearch, SOBJEC= T_NAME =3D sObjectName, SOBJECT_ID =3D sObjectId, APEX_URL =3D apexUrl, APE= X_METHOD =3D apexMethod, and the apexQueryParam. prefix) used plain, non-Ca= mel-prefixed values. Because these names do not start with the Camel / came=
l prefix, HttpHeaderFilterStrategy - which blocks only the Camel header nam= espace on the HTTP boundary - let them pass from an inbound HTTP request st= raight into the Exchange. In a route that bridges an HTTP consumer (for exa= mple platform-http) into a salesforce: producer, any HTTP client could ther= efore set these headers and override what the route intended - supplying it=
s own SOQL query or SOSL search to read data from any SObject the connected=
Salesforce user can access, overriding the target SObject name and id for = CRUD operations, or redirecting an Apex REST call to a different endpoint a=
nd HTTP method (including destructive methods) with injected query paramete= rs. All such operations run with the full permissions of the Salesforce con= nected (integration) user, which is typically broad. No credentials are req= uired from the attacker when the bridging consumer is unauthenticated. This=
issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4= .18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to versi=
on 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases s= tream, then they are suggested to upgrade to 4.14.8. If users are on the 4.= 18.x releases stream, then they are suggested to upgrade to 4.18.3. After u= pgrading, routes that set Salesforce operation parameters via the raw heade=
r names must use the CamelSalesforce* names (for example CamelSalesforceSOb= jectQuery and CamelSalesforceApexUrl) instead of the old sObject* / apex* v= alues; the endpoint-option spelling is unchanged. For deployments that cann=
ot upgrade immediately, strip the Salesforce control headers from any untru= sted ingress before the salesforce: producer (for example removeHeaders('sO= bject*') and removeHeaders('apex*') at the start of the route), and set the=
query, SObject and Apex parameters from a trusted source. 2026-07-06 not y=
et calculated CVE-2026-49099 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 49099 ] Apache Software Foundation--Apache Camel Undertow Generation of Err=
or Message Containing Sensitive Information vulnerability in Apache Camel U= ndertow Component. The camel-undertow HTTP server consumer exposes a muteEx= ception option that controls what is returned to the client when a route pr= ocessing error occurs. This option defaulted to false, whereas the other Ca= mel HTTP server components (camel-http / camel-jetty / camel-servlet and ca= mel-platform-http) default it to true. With muteException=3Dfalse, when a r= equest triggers an exception during route processing the consumer writes th=
e full Throwable stack trace into the HTTP response body as text/plain inst= ead of returning an empty body. Any unauthenticated client that can reach t=
he endpoint and cause a processing error - for example by sending a malform=
ed request body, an invalid parameter, or otherwise triggering a route-inte= rnal failure - therefore receives a complete Java stack trace. Such a stack=
trace can disclose sensitive internal information, including credentials e= mbedded in exception messages, internal host names and IP addresses, filesy= stem paths, dependency and version details, database and class names, and t=
he application's internal structure, which an attacker can use to plan furt= her attacks. In addition, for Rest DSL consumers the muteException option w=
as not honoured at all: the RestUndertowHttpBinding was created with a hard= -coded false, so the stack trace was returned even when muteException=3Dtru=
e had been configured. This issue affects Apache Camel: from 4.0.0 before 4= .14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are reco= mmended to upgrade to version 4.21.0, which fixes the issue. If users are o=
n the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.1= 4.8. If users are on the 4.18.x releases stream, then they are suggested to=
upgrade to 4.18.3. For deployments that cannot upgrade immediately, set mu= teException=3Dtrue explicitly on the camel-undertow consumer (for example u= ndertow:
http://0.0.0.0:8080/api?muteException=3Dtrue , or globally via the=
camel.component.undertow.mute-exception=3Dtrue property), so that processi=
ng errors no longer return the stack trace to the client; note that on affe= cted releases this workaround does not cover Rest DSL consumers, whose bind= ing ignores the option until the fix is applied. 2026-07-06 not yet calcula= ted CVE-2026-56139 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56139 ] Ap= ache Software Foundation--Apache Camel Vertx Websocket Improper Input Valid= ation, Exposure of Sensitive Information to an Unauthorized Actor, Server-S= ide Request Forgery (SSRF) vulnerability in Apache Camel in Vertx Websocket=
component. The camel-vertx-websocket consumer mapped inbound WebSocket que=
ry and path parameters into the Camel Exchange header map without applying = any HeaderFilterStrategy (VertxWebsocketConsumer.populateExchangeHeaders())=
. Because nothing blocked the Camel header namespace, a client connecting t=
o the WebSocket endpoint could set Camel-internal control headers - includi=
ng CamelHttpUri (Exchange.HTTP_URI) - simply by supplying them as query par= ameters. In a route where the WebSocket consumer feeds a downstream HTTP pr= oducer, the injected CamelHttpUri redirects the server-side HTTP request to=
an attacker-chosen destination (server-side request forgery - for example =
to an internal service or a cloud metadata endpoint). In addition, the HTTP=
producer resolves Camel property placeholders on the resulting (attacker-c= ontrolled) URI, so placeholders embedded in the injected value - such as an=
environment-variable reference, an application property, or a vault refere= nce - are resolved to their real values and sent to the attacker, disclosin=
g environment variables, application properties and vault secrets. When the=
WebSocket endpoint is exposed without authentication, this is reachable by=
an unauthenticated remote attacker. This issue affects Apache Camel: from = 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. = Users are recommended to upgrade to version 4.21.0, which fixes the issue. =
If users are on the 4.14.x LTS releases stream, then they are suggested to = upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they ar=
e suggested to upgrade to 4.18.3. The fix makes the affected consumers appl=
y a HeaderFilterStrategy that filters the Camel header namespace case-insen= sitively on inbound mapping, so externally-supplied Camel* / camel* headers=
are no longer copied into the Exchange. For deployments that cannot upgrad=
e immediately, strip the Camel control headers from the inbound message bef= ore they reach any downstream producer (for example removeHeaders('Camel*')=
and removeHeaders('camel*') at the start of the route), require authentica= tion on the WebSocket endpoint, and avoid bridging an untrusted consumer di= rectly into an HTTP producer whose target URI can be driven from message he= aders. 2026-07-06 not yet calculated CVE-2026-46726 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-46726 ] Apache Software Foundation--Apache Gravitino=
Unauthenticated callers can supply a malicious H2 JDBC URL through the tes= tConnection API, which executes arbitrary Java code on the server via H2's = INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apach=
e Gravitino: before 1.2.1. Users are recommended to upgrade to version 1.2.=
1, which fixes the issue. This issue only happens when using H2, and H2 is = mainly used for testing and local development. Also, Gravitino is typically=
deployed in the internal environment, so the severity is low. 2026-07-08 n=
ot yet calculated CVE-2026-41042 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-41042 ] Apache Software Foundation--Apache Helix REST Permissive Cross-= Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.heli= x.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all plat= forms allows a remote attacker controlling a web page visited by an authori= zed user to read responses from and issue cross-origin requests to administ= rative REST endpoints via a cross-origin request from an arbitrary origin, = since the filter unconditionally returns Access-Control-Allow-Origin: * tog= ether with Access-Control-Allow-Credentials: true and reflects arbitrary Ac= cess-Control-Request-Method / Access-Control-Request-Headers values in pref= light responses. Users are recommended to upgrade to version 2.0.1, which f= ixes this issue. 2026-07-09 not yet calculated CVE-2026-57111 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-57111 ] Apache Software Foundation--Apache=
IoTDB Uncontrolled Resource Consumption vulnerability in Apache IoTDB.=C2=
=A0 Some interface=C2=A0fails to impose reasonable limits on the time span = and aggregation interval of the query.=C2=A0An attacker can construct a req= uest with extreme parameters (e.g., a very large time range combined with a=
minimal interval).=C2=A0This forces the DataNode to build an enormous resu=
lt set in memory, which exhausts the Java heap and causes the DataNode proc= ess to crash. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Use=
rs are recommended to upgrade to version 2.0.8, which fixes the issue. 2026= -07-06 not yet calculated CVE-2026-24012 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-24012 ] Apache Software Foundation--Apache IoTDB Authentication=
Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query=
handlers lack strict validation of the sessionId parameter. An attacker ca=
n construct requests with a forged sessionId and, without performing openSe= ssion authentication, receive valid query results. This allows authenticati=
on bypass and unauthorized reading of time-series data. This issue affects = Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to = version 2.0.8, which fixes the issue. 2026-07-06 not yet calculated CVE-202= 6-24013 [
https://www.cve.org/CVERecord?id=3DCVE-2026-24013 ] Apache Softwa=
re Foundation--Apache IoTDB Apache IoTDB DataNode's internal RPC interface = for creating Trigger instances uses the uploaded Trigger JAR name to build =
a file path without sufficient validation. If the internal DataNode RPC por=
t is exposed to an untrusted network, an attacker may use path traversal se= quences in the JAR name to write files outside the intended Trigger install= ation directory. This could allow arbitrary file write with the permissions=
of the IoTDB process. This issue affects Apache IoTDB: from 1.3.3 before 2= .0.8. Users are recommended to upgrade to version 2.0.8, which fixes the is= sue. 2026-07-06 not yet calculated CVE-2026-24014 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-24014 ] Apache Software Foundation--Apache IoTDB Insuf= ficient Session Expiration, Authentication Bypass by Capture-replay vulnera= bility in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Cred= entials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users ar=
e recommended to upgrade to version 2.0.10, which fixes the issue. 2026-07-=
10 not yet calculated CVE-2026-28564 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-28564 ] Apache Software Foundation--Apache IoTDB Improper Limitatio=
n of a Pathname to a Restricted Directory ('Path Traversal') vulnerability =
in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB p= rocess has write permissions with unsafe API. This issue affects Apache IoT= DB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2= .0.10, which fixes the issue. 2026-07-10 not yet calculated CVE-2026-40005 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-40005 ] Apache Software Found= ation--Apache IoTDB Memory Allocation with Excessive Size Value, Allocation=
of Resources Without Limits or Throttling, Missing Authentication for Crit= ical Function vulnerability in Apache IoTDB. When pipe_air_gap_receiver_ena= bled=3Dtrue, the IoTDB AirGap pipe receiver accepts raw TCP connections on = port 9780 with no authentication. The readLength method reads an attacker-c= ontrolled 32-bit integer from the socket and readData passes it directly to=
new byte[length] with no upper-bound check. An unauthenticated attacker ca=
n cause the JVM to attempt an allocation of up to 2,147,483,647 bytes per c= onnection, exhausting heap memory and crashing or severely degrading the Da= taNode process. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. = Users are recommended to upgrade to version 2.0.10, which fixes the issue. = 2026-07-10 not yet calculated CVE-2026-40006 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-40006 ] Apache Software Foundation--Apache IoTDB Uncontroll=
ed Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoT= DB. When pipe_air_gap_receiver_enabled=3Dtrue, the IoTDB AirGap receiver's = readLength method calls itself recursively each time it recognises the E-la= nguage prefix in socket data, with no depth limit. An unauthenticated attac= ker can send a stream of repeated E-language prefixes that drives the recur= sion arbitrarily deep, exhausting the receiver thread's JVM stack and raisi=
ng StackOverflowError. This issue affects Apache IoTDB: from 1.0.0 before 2= .0.10. Users are recommended to upgrade to version 2.0.10, which fixes the = issue. 2026-07-10 not yet calculated CVE-2026-40007 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-40007 ] Apache Software Foundation--Apache IoTDB Use=
of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflecti= on') vulnerability in Apache IoTDB. The pipe processor reads a fully qualif= ied Java class name and instantiates it using Class.forName().newInstance()=
without any validation or allowlisting. This issue affects Apache IoTDB: f= rom 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10=
, which fixes the issue. 2026-07-10 not yet calculated CVE-2026-40008 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-40008 ] Apache Software Foundation= --Apache IoTDB Improper Privilege Management, Improper Access Control vulne= rability in Apache IoTDB. Authenticated users can escalate to full tree-pat=
h access by renaming themselves to __internal_auditor. This issue affects A= pache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to upgrade to = version 2.0.10, which fixes the issue. 2026-07-10 not yet calculated CVE-20= 26-40009 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40009 ] Apache Softw= are Foundation--Apache IoTDB Incorrect Authorization, Improper Access Contr=
ol vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLast= Query exposes last-value data to unauthorized authenticated users. This iss=
ue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10.=
Users are recommended to upgrade to version 2.0.10, which fixes the issue.=
2026-07-10 not yet calculated CVE-2026-40452 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-40452 ] Apache Software Foundation--Apache IoTDB C++ clien=
t Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoT=
DB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer=
crash client process on malformed server data. This issue affects Apache I= oTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users a=
re recommended to upgrade to version 2.0.10, which fixes the issue. 2026-07= -10 not yet calculated CVE-2026-40454 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-40454 ] Apache Software Foundation--Apache Log4j API Improper enco= ding of non-finite floating-point values during MapMessage JSON serializati=
on in Apache Log4j API produces output that is not valid JSON. This issue a= ffects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. = The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage = contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMess= age.asJson() emits the corresponding bare token. RFC 8259 does not permit t= hese tokens, so a conformant parser rejects the resulting document. The def= ect is reachable only when both of the following conditions hold: * The app= lication uses the message resolver
https://logging.apache.org/log4j/2.x/man= ual/json-template-layout.html#event-template-resolver-message of JsonTempla= teLayout or any other layout that relies on MapMessage.asJson() or MapMessa= ge.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapM= essage that contains an attacker-controlled floating-point value. An attack=
er who can supply a non-finite value can cause the affected layout to emit = malformed JSON, which may corrupt the enclosing log record or disrupt downs= tream log ingestion and parsing. Users are advised to upgrade to Apache Log=
4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non= -finite values. 2026-07-10 not yet calculated CVE-2026-49844 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-49844 ] Apache Software Foundation--Apache = OpenNLP :: Core :: ML :: LibSVM Untrusted Java Deserialization in Apache Op= enNLP SvmDoccatModel Versions Affected: =C2=A0 before 3.0.0-M4 (libsvm docu= ment categorization module; introduced in =C2=A0 OPENNLP-1808 and only pres= ent on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream) r= eads an attacker-controlled stream with java.io.ObjectInputStream and calls=
readObject() without an ObjectInputFilter installed. ObjectInputStream mat= erialises every class referenced in the stream before the resulting object =
is cast to SvmDoccatModel, so the cast that follows readObject() executes o= nly after the foreign object graph has already been deserialised in full. I=
f a Java deserialization gadget chain is available on the consumer's classp= ath, a crafted payload supplied to deserialize() executes arbitrary code in=
the JVM that loads it. Apache OpenNLP itself does not ship a known gadget = chain, so the realistic risk is to downstream applications that embed the l= ibsvm module alongside vulnerable transitive dependencies. The method is pu= blic and static, so any caller can pass an untrusted stream to it directly.=
The practical impact is remote code execution against processes that load = SvmDoccatModel instances from untrusted or semi-trusted origins. Mitigation=
: 3.x users should upgrade to 3.0.0-M4. Users who cannot upgrade immediatel=
y should treat all serialized SvmDoccatModel streams as untrusted input unl= ess their provenance is verified, and should avoid invoking SvmDoccatModel.= deserialize() on streams supplied by end users or fetched from third-party = sources without integrity checks. 2026-07-06 not yet calculated CVE-2026-43= 825 [
https://www.cve.org/CVERecord?id=3DCVE-2026-43825 ] arcinfo--PcVue Cr= edentials of built-in users are insecurely stored in the User directory of = PcVue projects, all=C2=A0versions prior to 17.0.0. A local attacker could r= etrieve users' credentials.=C2=A0 Active Directory accounts are not affecte=
d by this vulnerability. 2026-07-07 not yet calculated CVE-2026-14867 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-14867 ] arcinfo--PcVue The encrypt= ion algorithm used to protect the configuration of user accounts, stored in=
the built-in user directory of PcVue projects, all=C2=A0versions prior to = 17.0.0, is not strong enough for the level of protection required. A local = attacker could alter the existing configuration and ultimately gain privile= ged access to the PcVue application. 2026-07-07 not yet calculated CVE-2026= -14868 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14868 ] Artifex--Artif=
ex An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artife=
x commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a c= rafted input. 2026-07-09 not yet calculated CVE-2026-38076 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-38076 ] BAKERSCOT--String::Util String::Util = versions before 1.36 for Perl are susceptible to a regular expression denia=
l of service. The trim and rtrim functions stripped trailing whitespace wit=
h s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a=
non-whitespace character follows the whitespace, the regex engine retries = the match at each offset of a long whitespace run, producing quadratic back= tracking. The fix replaces \s*$ with \s+$. Any caller that passes untrusted=
input to trim or rtrim can trigger CPU exhaustion with a string containing=
a long run of whitespace. 2026-07-07 not yet calculated CVE-2026-14895 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-14895 ] balbooa.com--balbooa.com=
Balbooa Forms extension for Joomla The Joomla extension Balbooa Forms is v= ulnerable to an unauthenticated arbitrary file upload that allows uploading=
executable files and leads to full RCE. 2026-07-09 not yet calculated CVE-= 2026-56291 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56291 ] BerriAI--l= itellm LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (o=
r native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connectio=
n endpoint resolved request-supplied environment and OIDC file references i=
n litellm_params, allowing a proxy administrator or another privileged call=
er with permission to test model connections to read files from the local f= ilesystem via an oidc/file/ reference. This issue is fixed in version 1.83.= 10-stable. 2026-07-08 not yet calculated CVE-2026-59819 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-59819 ] BerriAI--litellm LiteLLM is a proxy serv=
er (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.8= 3.7-stable, LiteLLM Skills archive extraction did not sufficiently validate=
file paths from uploaded skill ZIP archives, allowing an authenticated use=
r with access to LiteLLM LLM API routes or a key whose allowed_routes inclu= des /v1/skills, anthropic_routes, or llm_api_routes to upload a crafted ski=
ll archive containing path traversal entries that could be written outside = the intended extraction or staging directory. This issue is fixed in versio=
n 1.83.7-stable. 2026-07-08 not yet calculated CVE-2026-59820 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-59820 ] BerriAI--litellm LiteLLM is a prox=
y server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior =
to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and up= date paths did not apply the same sandboxing and validation used by the tes=
t endpoint, allowing a privileged user with access to create or update guar= drails to submit custom Python code that executed in the LiteLLM proxy envi= ronment and could expose secrets available to the process. This issue is fi= xed in version 1.82.0-stable. 2026-07-08 not yet calculated CVE-2026-59821 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-59821 ] BerriAI--litellm Lite= LLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) f= ormat. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an u= nauthenticated attacker to use a fabricated Authorization header to trigger=
an OAuth2 passthrough fallback path that replaced failed LiteLLM key valid= ation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP=
tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0=
. 2026-07-08 not yet calculated CVE-2026-59822 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-59822 ] BeyondTrust--Remote Support A critical pre-authen= tication vulnerability exists in the authentication subsystem of BeyondTrus=
t Remote Support and Privileged Remote Access. Improper validation of authe= ntication data may allow a network-positioned attacker to bypass access con= trols and gain unauthorized access to the appliance, including accounts wit=
h elevated privileges. Exploitation requires a specific authentication conf= iguration to be enabled 2026-07-06 not yet calculated CVE-2026-40138 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-40138 ] BeyondTrust--Remote Support=
A critical pre-authentication vulnerability exists in the authentication s= ubsystem of BeyondTrust Remote Support.=C2=A0Improper processing of authent= ication requests may allow an unauthenticated remote attacker to bypass acc= ess controls and gain unauthorized access to the appliance, including accou= nts with elevated privileges. Exploitation requires a specific authenticati=
on configuration to be enabled. 2026-07-06 not yet calculated CVE-2026-4013=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40139 ] BeyondTrust--Remote=
Support BeyondTrust Remote Support and Privileged Remote Access contain a = high-severity pre-authentication vulnerability in the network communication=
subsystem.=C2=A0Insufficient validation of client-supplied input may allow=
an unauthenticated remote attacker to trigger a denial-of-service conditio=
n affecting appliance availability. 2026-07-06 not yet calculated CVE-2026-= 40140 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40140 ] BeyondTrust--Re= mote Support A high-severity vulnerability exists in a web application comp= onent of BeyondTrust Remote Support and Privileged Remote Access related to=
the processing of certain input parameters.=C2=A0Insufficient validation o=
f user-supplied input may allow an authenticated attacker with limited priv= ileges to access unintended resources or data beyond their authorization sc= ope. Exploitation is restricted to accounts with specific permissions. 2026= -07-06 not yet calculated CVE-2026-40141 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-40141 ] BINGOS--Module::Load Module::Load versions before 0.22 = for Perl allow arbitrary modules outside of @INC to be loaded. Module names=
starting with "::" could be passed to the load function to specify arbitra=
ry module paths. Attackers able to influence module names passed to load co= uld use that bug to execute arbitrary code. 2026-07-07 not yet calculated C= VE-2011-10043 [
https://www.cve.org/CVERecord?id=3DCVE-2011-10043 ] BitWiza= rd--mtr mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_look= up() function. An attacker who can influence the TXT response used for AS l= ookups can trigger this bug by returning a DNS response that is larger than=
512 bytes and uses a crafted compression pointer in the answer NAME field.= =C2=A0ipinfo_lookup() function uses the length of the response as the=C2=A0= end-of-message boundary for dn_expand() function.=C2=A0The result is a reli= able crash. This issue exists in the mtr through version 0.96 and it was fi= xed in commit=C2=A048e1794414d338ce47abc0f27c25ade8788af9c3. 2026-07-10 not=
yet calculated CVE-2026-14461 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-14461 ] BOSH-Ecosystem / BOSH (bosh-cli)--bosh-cli During bosh create-env=
and bosh delete-env, the CLI uploads compiled CPI packages and rendered jo=
b templates to the new VM's DAV blobstore over HTTPS without verifying the = server certificate, even though a CA certificate for that endpoint is avail= able in the installation manifest. A network attacker can terminate the TLS=
connection, harvest the Basic-auth credentials, and read the rendered-temp= lates archive containing every bootstrap secret for the new BOSH Director, = then replay the credentials against the real VM's agent for root code execu= tion. Affected versions: bosh-cli versions prior to v7.10.4. 2026-07-09 not=
yet calculated CVE-2026-47828 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-47828 ] cakephp--authentication CakePHP Authentication is an authenticati=
on plugin for CakePHP that can also be used in PSR-7 based applications. Pr= ior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a w= eakness to backslash bypasses that allows redirect targets with attacker-co= ntrolled hostnames through the redirect query string parameter. This issue =
is fixed in versions 2.11.1, 3.3.6, and 4.1.1. 2026-07-09 not yet calculate=
d CVE-2026-55590 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55590 ] CAXp= erts--UPVWebServices/UDiTH Portal In CAXperts UPVWebServices 2.4.2212.603 t= hrough 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated r= emote user can invoke an administrative API endpoint intended for privilege=
d users. Due to missing authorization checks, this allows the attacker to d= eactivate the application's license. 2026-07-08 not yet calculated CVE-2026= -35552 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35552 ] chevereto--che= vereto Chevereto is a self-hosted media-sharing platform. Starting in versi=
on 3.7.5 and prior to version 4.5.4, when a user enables the private profil=
e option, visiting their profile HTML route (`/username`) correctly returns=
404. However, the `/json` AJAX listing endpoint does not apply the same ch= eck. An unauthenticated caller who knows the target's user ID can retrieve = all of that user's publicly-scoped images, revealing the username (which sh= ould be private). This is patched in Chevereto v4.5.4. No known workarounds=
are available. 2026-07-07 not yet calculated CVE-2026-55417 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-55417 ] Chocobozzz--PeerTube PeerTube is an=
ActivityPub-federated video streaming platform. Prior to 8.2.2, server-sid= e-rendered video watch pages embed a schema.org JSON-LD block by JSON.strin= gify-ing video metadata without escaping less-than, greater-than, or slash = characters, allowing a value containing the byte sequence that closes a scr= ipt element to inject arbitrary HTML or JavaScript that executes in the ins= tance origin for visitors to the attacker's videos. This issue is fixed in = version 8.2.2. 2026-07-10 not yet calculated CVE-2026-57167 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-57167 ] CIENA--6500 S-Series An authenticati=
on bypass vulnerability exists in the default SFTP server component utilize=
d across the Ciena products listed. This vulnerability allows a remote, una= uthenticated attacker to bypass security controls and gain unauthorized acc= ess to the underlying filesystem. Successful exploitation could allow an at= tacker to read or modify system files. 2026-07-06 not yet calculated CVE-20= 26-5268 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5268 ] Cisco--RV130/R= V130W An OS command injection vulnerability exists in the start_bonjour() f= unction of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and=
RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configura= tion parameter is not properly sanitized, which could allow an authenticate=
d remote attacker to execute arbitrary OS commands with root privileges. 20= 26-07-08 not yet calculated CVE-2026-24697 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-24697 ] Cisco--RV130/RV130W An OS command injection vulnerabi= lity exists in the save_syslog_to_file() function of the "httpd" binary in = Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware = 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly s= anitized, which could allow an authenticated remote attacker to execute arb= itrary OS commands with root privileges. 2026-07-08 not yet calculated CVE-= 2026-24698 [
https://www.cve.org/CVERecord?id=3DCVE-2026-24698 ] Cisco--RV1= 30/RV130W An OS command injection vulnerability exists in the sub_34984() f= unction of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and=
RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen con= figuration parameter is not properly sanitized, which could allow an authen= ticated remote attacker to execute arbitrary OS commands with root privileg= es. 2026-07-08 not yet calculated CVE-2026-24699 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-24699 ] Cisco--RV130/RV130W An OS command injection vul= nerability exists in the start_lltd() function of the "rc" binary in Cisco = RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.=
5 / 1.2.2.8. The machine_name configuration parameter is not properly sanit= ized, which could allow an authenticated remote attacker to execute arbitra=
ry OS commands with root privileges. 2026-07-08 not yet calculated CVE-2026= -24700 [
https://www.cve.org/CVERecord?id=3DCVE-2026-24700 ] Claris--FileMa= ker Server An authenticated administrator may be able to achieve arbitrary = code execution on the host system by uploading a malicious file through the=
Open Source LLM setup feature in the Admin Console. This vulnerability has=
been addressed in FileMaker Server 26.0.1. 2026-07-09 not yet calculated C= VE-2026-43752 [
https://www.cve.org/CVERecord?id=3DCVE-2026-43752 ] Cloud F= oundry Foundation--bosh-windows-stemcell-builder Incorrect Permission Assig= nment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder al= lows low-privilege authenticated users to overwrite C:\bosh\service_wrapper= .exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next ser= vice restart or reboot. This can lead to full host control. Affected versio= ns: bosh-windows-stemcell-builder versions prior to v2019.98. 2026-07-09 no=
t yet calculated CVE-2026-47830 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-47830 ] Cloud Foundry Foundation--bosh-windows-stemcell-builder Use of a=
cryptographically weak random number generator in the GenerateRandomPasswo=
rd function in bosh-windows-stemcell-builder allows a remote attacker to br= ute-force the resulting SSH login via TCP/22. Affected versions: bosh-windo= ws-stemcell-builder versions prior to v2019.98. 2026-07-09 not yet calculat=
ed CVE-2026-47831 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47831 ] Clo= udFoundry BOSH--BOSH CLI A compromised or malicious BOSH Director can execu=
te arbitrary shell commands on the operator's workstation when the operator=
runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected vers= ions: BOSH CLI versions prior to 7.10.5. 2026-07-09 not yet calculated CVE-= 2026-41857 [
https://www.cve.org/CVERecord?id=3DCVE-2026-41857 ] CloudFound=
ry Foundation--BOSH CLI tool The blobs.yml path key traversal vulnerability=
in the BOSH CLI tool allows an attacker to write arbitrary files and exfil= trate sensitive information. Affected versions: BOSH CLI tool versions prio=
r to v7.10.4. 2026-07-09 not yet calculated CVE-2026-47826 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-47826 ] CloudFoundry Foundation--bosh-cli Arg= ument Injection in bosh-cli allows a compromised BOSH Director to inject ar= bitrary OpenSSH options into the locally-spawned ssh process when an operat=
or runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, lead= ing to local command execution on the operator's workstation. Affected vers= ions: bosh-cli versions prior to v7.10.4. 2026-07-09 not yet calculated CVE= -2026-47829 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47829 ] Code27--C= ompanion Hub An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a p= hysically proximate attacker to execute arbitrary code via the USB debuggin=
g (ADB) and Android Debug Bridge components 2026-07-08 not yet calculated C= VE-2026-36027 [
https://www.cve.org/CVERecord?id=3DCVE-2026-36027 ] Code27-= -Companion Hub A protection mechanism failure in the Code 27 Companion Hub = allows an attacker with physical access to completely bypass kiosk restrict= ions via a factory reset 2026-07-08 not yet calculated CVE-2026-36028 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-36028 ] copier-org--copier Copier =
is a library and CLI app for rendering project templates. In versions 9.5.0=
through 9.15.1, the `trust` setting's prefix match (`copier/_settings.py`)=
compares the template URL against a trusted prefix with a raw `str.startsw= ith` and no path normalization, while the URL is normalized when the templa=
te is actually fetched (`Path.resolve()` for local paths; libcurl dot-segme=
nt removal for `https`). A template reference that textually starts with a = trusted prefix but contains `..` is therefore granted trust yet resolves to=
a different, attacker-controlled template, whose `tasks` / `migrations` / = `jinja_extensions` then run without the `--trust` prompt - arbitrary comman=
d execution. Version 9.15.2 patches the issue. 2026-07-08 not yet calculate=
d CVE-2026-53951 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53951 ] Cycl= oneDX--cyclonedx-node-npm @cyclonedx/cyclonedx-npm creates CycloneDX Softwa=
re Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI pa= sses user-supplied --workspace values to a subshell without proper sanitiza= tion when npm_execpath is unset or empty, allowing arbitrary OS command exe= cution with the privileges of the invoking user. This issue is fixed in ver= sion 5.0.0. 2026-07-08 not yet calculated CVE-2026-55849 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-55849 ] dataease--dataease DataEase is an open = source data visualization and analysis tool. Prior to 2.10.24, the /de2api/= share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN befor=
e validating the share password or ticket, allowing unauthenticated attacke=
rs who know a protected share UUID to obtain a valid link token for subsequ= ent share-related API calls even with missing or invalid credentials. This = issue is fixed in version 2.10.24. 2026-07-07 not yet calculated CVE-2026-5= 0529 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50529 ] dataease--dataea=
se DataEase is an open source data visualization and analysis tool. Prior t=
o 2.10.24, a share mode chart data interface only validates that sceneId ma= tches the resourceId in the link token and fails to validate whether tableI=
d and field IDs in the request body belong to the shared resource, allowing=
an attacker with a valid share link token to replace dataset identifiers a=
nd retrieve unauthorized data through POST /de2api/chartData/getData. This = issue is fixed in version 2.10.24. 2026-07-07 not yet calculated CVE-2026-5= 0530 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50530 ] dataease--dataea=
se DataEase is an open source data visualization and analysis tool. Prior t=
o 2.10.24, any authenticated user can download (/exportCenter/download/{id}=
), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or gene= rate download links (/exportCenter/generateDownloadUri/{id}) for export tas=
ks belonging to other users by manipulating the task ID parameter, and the = /exportCenter/download/{id} endpoint is whitelisted from authentication, al= lowing unauthenticated access to exported files. This issue is fixed in ver= sion 2.10.24. 2026-07-07 not yet calculated CVE-2026-53729 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-53729 ] dataease--dataease DataEase is an ope=
n source data visualization and analysis tool. Prior to 2.10.24, the /de2ap= i/datasetData/previewSql endpoint lacks the mandatory @DePermit permission = validation annotation, allowing any authenticated user to specify datasourc= eId=3D-1, access the built-in engine database, execute arbitrary SQL statem= ents, and read sensitive core data. This issue is fixed in version 2.10.24.=
2026-07-07 not yet calculated CVE-2026-53730 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-53730 ] dataease--dataease DataEase is an open source data=
visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC UR=
L validation logic can be bypassed with special Unicode characters whose ca= se-conversion behavior differs between DataEase validation and H2 parsing, = allowing attackers to smuggle dangerous parameters such as init in maliciou=
s H2 JDBC connection strings and achieve arbitrary code execution. This iss=
ue is fixed in version 2.10.24. 2026-07-07 not yet calculated CVE-2026-5375=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53751 ] dataease--dataease = DataEase is an open source data visualization and analysis tool. Prior to 2= .10.24, the font management module allows authenticated users to submit an = arbitrary fileTransName when creating a font record; when the record is lat=
er deleted, the backend concatenates that stored value with the font storag=
e directory and passes it to FileUtils.deleteFile() without path traversal = sanitization, allowing deletion of arbitrary writable files in the applicat= ion container. This issue is fixed in version 2.10.24. 2026-07-07 not yet c= alculated CVE-2026-55631 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5563=
1 ] dataease--dataease DataEase is an open source data visualization and an= alysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dro= pper fix allows an authenticated attacker to upload a zip archive disguised=
with a .ttf extension through FontManage.saveFile and then exploit it thro= ugh the zip protocol to achieve remote code execution. This issue is fixed =
in version 2.10.24. 2026-07-07 not yet calculated CVE-2026-55633 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-55633 ] dataease--dataease DataEase is =
an open source data visualization and analysis tool. Prior to 2.10.24, char=
t quota and Y-axis filters embed attacker-controlled filter values directly=
into generated SQL in Quota2SQLObj.getYWheres() without applying the SQL l= iteral validation and escaping used by other filter paths, allowing an auth= enticated user who can create or modify chart definitions or submit chart d= ata requests containing quota filters to inject SQL into queries executed a= gainst configured datasources. This issue is fixed in version 2.10.24. 2026= -07-07 not yet calculated CVE-2026-55635 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55635 ] dataease--dataease DataEase is an open source data visu= alization and analysis tool. Prior to 2.10.24, dashboard text components re= nder stored component content with Vue v-html without server-side HTML sani= tization, allowing an authenticated user who can edit dashboard component d= ata to inject HTML with executable event handlers that execute when another=
user or shared-link visitor views the dashboard. This issue is fixed in ve= rsion 2.10.24. 2026-07-07 not yet calculated CVE-2026-55647 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-55647 ] dataease--dataease DataEase is an op=
en source data visualization and analysis tool. Prior to 2.10.24, ShareSecr= etManage uses a hardcoded default share link signature key, allowing an att= acker who can obtain a passwordless share for a resource and user to use th=
e known key link-pwd-fit2cloud to forge linkToken JWTs, bypass TokenFilter = verification, and access backend resources as the share creator even if the=
original share has been revoked. This issue is fixed in version 2.10.24. 2= 026-07-07 not yet calculated CVE-2026-57172 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-57172 ] decompress--decompress decompress before 4.2.2 allow=
s arbitrary hardlink creation during archive extraction, enabling file read=
disclosure and file corruption. When processing hardlink entries (type =3D= =3D=3D 'link'), the x.linkname field from the archive is passed directly to=
fs.link() without validation (index.js line 113). An attacker can craft an=
archive with a hardlink entry whose linkname is an absolute path to any fi=
le on the same filesystem. This creates a hardlink inside the extraction di= rectory that shares the same inode as the target file, enabling both readin=
g and overwriting the original file's content. Hardlinks are limited to fil=
es on the same filesystem and cannot target directories. 2026-07-09 not yet=
calculated CVE-2026-39243 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39= 243 ] decompress--decompress decompress before 4.2.2 contains an improper p= ath containment check that enables directory traversal and arbitrary file w= rite. The safeMakeDir function (index.js line 29) and the extraction path v= alidation (index.js line 106) use String.indexOf() to verify the resolved p= ath is within the output directory: realDestinationDir.indexOf(realOutputPa= th) !=3D=3D 0. This check is flawed because it does not enforce a path sepa= rator boundary. For example, "/tmp/app_config".indexOf("/tmp/app") returns =
0, incorrectly passing the check even though /tmp/app_config is outside /tm= p/app. Combined with the unvalidated symlink creation in the same package, =
an attacker can write arbitrary files to directories adjacent to the extrac= tion target. This is a bypass of the fix for CVE-2020-12265. The correct ch= eck requires appending a path separator: realParentPath.indexOf(realOutputP= ath + path.sep) !=3D=3D 0. 2026-07-09 not yet calculated CVE-2026-39245 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-39245 ] decompress--decompress d= ecompress before 4.2.2 allows arbitrary symlink creation during archive ext= raction. When processing symlink entries (type =3D=3D=3D 'symlink'), the x.= linkname field from the archive is passed directly to fs.symlink() without = validation (index.js line 121). The preventWritingThroughSymlink check on l= ine 98 only applies to file entries, not symlink creation. An attacker can = craft an archive with symlink entries pointing to sensitive files outside t=
he extraction directory (e.g., /etc/passwd), enabling information disclosur=
e when the application reads the extracted contents. 2026-07-09 not yet cal= culated CVE-2026-39246 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39246 =
] Devolutions--Server Improper enforcement of a mandatory multi-factor auth= entication policy in Devolutions Server 2026.2.9.0 allows an attacker with = valid user credentials to bypass the MFA Required policy and authenticate w= ithout completing multi-factor authentication. The problem occurs when DVLS=
encounters an invalid default MFA value. 2026-07-06 not yet calculated CVE= -2026-14536 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14536 ] Digi Inte= rnational--Digi PortServer TS A stored cross-site scripting (XSS) vulnerabi= lity in the web management interface of the Digi PortServer TS, Digi One SP=
, Digi One SP IA, and Digi One IA allows a remote, authenticated administra= tor to inject script into certain system configuration fields. The script s= ubsequently executes in the browser of a user who views the affected pages = (CWE-79). 2026-07-07 not yet calculated CVE-2026-12948 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-12948 ] discourse--discourse Discourse is an open= -source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 202= 6.1.5, secure uploads could be exposed by pull_hotlinked_images when an att= acker knew the secured upload URL and the secure_uploads site setting was e= nabled. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2= 026.1.5. 2026-07-09 not yet calculated CVE-2026-45788 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-45788 ] discourse--discourse Discourse is an open-= source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026= .1.5, restricted tag and tag-group names attached to publicly readable cate= gories as allowed_tags, allowed_tag_groups, or required tag groups could le=
ak to anonymous and unauthorized users through category and group endpoints=
. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.=
5. 2026-07-09 not yet calculated CVE-2026-49256 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-49256 ] discourse--discourse Discourse is an open-source=
discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, =
a topic "featured link" was not sufficiently normalized and escaped before = being rendered in the topic list, allowing a user who can set a featured li=
nk to inject JavaScript when default Content Security Policy protections we=
re modified or disabled. This issue is fixed in versions 2026.6.0, 2026.5.1=
, 2026.4.2, and 2026.1.5. 2026-07-09 not yet calculated CVE-2026-55424 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-55424 ] docuForm--GmbH Client v.1= 1.11c An Insecure Direct Object Reference (IDOR) vulnerability exists in do= cuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary=
code via the user settings component, and modify or retrieve sensitive dat=
a associated with other users' accounts. 2026-07-09 not yet calculated CVE-= 2026-51923 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51923 ] docuForm--= GmbH Client v.11.11c An issue in docuForm GmbH Client v.11.11c allows a rem= ote attacker to execute arbitrary code via the file upload and report.php c= omponent 2026-07-09 not yet calculated CVE-2026-51924 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-51924 ] docuForm--GmbH Client v.11.11c A Local Fil=
e Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c tha=
t allows a remote attacker to execute arbitrary code via the dfm-menu_repor= t.php component. Attackers can exploit this flaw to read arbitrary files on=
the server, including sensitive configuration files, source code or system=
files. 2026-07-09 not yet calculated CVE-2026-51925 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-51925 ] docuForm--GmbH FSM Client v.11.11c An issue=
in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain se= nsitive information via the login.php component. A vulnerability was identi= fied in the authentication mechanism that allows user enumeration through t=
he login interface. An attacker can differentiate between valid and invalid=
usernames based on variations in server responses. This information can be=
leveraged to identify existing accounts and facilitate further attacks, in= cluding brute-force or credential stuffing. 2026-07-09 not yet calculated C= VE-2026-51926 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51926 ] Drupal-= -Advanced Content Feedback (aka admin_feedback) Improper Neutralization of = Input During Web Page Generation ("Cross-site Scripting") vulnerability in = Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. Th=
is issue affects Advanced Content Feedback (aka admin_feedback) versions: f= rom 0.0.0 to 2.8.0. 2026-07-10 not yet calculated CVE-2026-13231 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-13231 ] Drupal--Advanced Content Feedba=
ck (aka admin_feedback) Incorrect Authorization vulnerability in Drupal Adv= anced Content Feedback (aka admin_feedback) allows Forceful Browsing. This = issue affects Advanced Content Feedback (aka admin_feedback) versions: from=
0.0.0 to 2.8.0. 2026-07-10 not yet calculated CVE-2026-13232 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-13232 ] Drupal--AI (Artificial Intelligenc=
e) Improper Neutralization of Input During Web Page Generation ("Cross-site=
Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cr= oss-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) v= ersions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. 20= 26-07-10 not yet calculated CVE-2026-13234 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-13234 ] Drupal--AI (Artificial Intelligence) Missing Authoriz= ation vulnerability in Drupal AI (Artificial Intelligence) allows Forceful = Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.= 0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. 2026-07-10 not yet=
calculated CVE-2026-13235 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13= 235 ] Drupal--AI Agents Missing Authorization vulnerability in Drupal AI Ag= ents allows Forceful Browsing. This issue affects AI Agents versions: from = 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. 2026-07-10 not ye=
t calculated CVE-2026-13236 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 3236 ] Drupal--AI Agents Incorrect Authorization vulnerability in Drupal AI=
Agents allows Forceful Browsing. This issue affects AI Agents versions: fr=
om 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. 2026-07-10 not=
yet calculated CVE-2026-13237 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-13237 ] Drupal--AI SEO/GEO Analyzer Improper Neutralization of Input Duri=
ng Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI = SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer = versions: from 0.0.0 to 1.1.3. 2026-07-10 not yet calculated CVE-2026-15085=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-15085 ] Drupal--Anti-Spam by=
CleanTalk Improper Neutralization of Input During Web Page Generation ("Cr= oss-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows = Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0=
.0 to 9.7.1. 2026-07-10 not yet calculated CVE-2026-10770 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-10770 ] Drupal--Brute force attack protection = vulnerability in Drupal Brute force attack protection allows . This issue a= ffects Brute force attack protection versions: *.*. 2026-07-10 not yet calc= ulated CVE-2026-11915 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11915 ]=
Drupal--Clean RESTful vulnerability in Drupal Clean RESTful allows . This = issue affects Clean RESTful versions: *.*. 2026-07-10 not yet calculated CV= E-2026-15087 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15087 ] Drupal--= Colorbox Improper Neutralization of Input During Web Page Generation ("Cros= s-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scrip= ting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from=
0.0.0 to 2.2.0. 2026-07-10 not yet calculated CVE-2026-58591 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-58591 ] Drupal--Commerce Core Improper Neu= tralization of Input During Web Page Generation ("Cross-site Scripting") vu= lnerability in Drupal Commerce Core allows Stored XSS. This issue affects C= ommerce Core versions: from 3.3.0 to 3.3.6. 2026-07-10 not yet calculated C= VE-2026-10769 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10769 ] Drupal-= -Commerce guest registration vulnerability in Drupal Commerce guest registr= ation allows . This issue affects Commerce guest registration versions: *.*=
. 2026-07-10 not yet calculated CVE-2026-15089 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-15089 ] Drupal--Commerce Realex / Global Payments Incorre=
ct Authorization vulnerability in Drupal Commerce Realex / Global Payments = allows Forceful Browsing. This issue affects Commerce Realex / Global Payme= nts versions: from 0.0.0 to 3.0.2. 2026-07-10 not yet calculated CVE-2026-1= 3238 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13238 ] Drupal--Composer=
vulnerability in Drupal Composer allows . This issue affects Composer vers= ions: *.*. 2026-07-10 not yet calculated CVE-2026-11914 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-11914 ] Drupal--Drupal AlternativeCommerce (Bask= et) Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows = Object Injection. This issue affects Drupal AlternativeCommerce (Basket) ve= rsions: from 0.0.0 to 2.1.17. 2026-07-10 not yet calculated CVE-2026-9726 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-9726 ] Drupal--Drupal Canvas I= mproper Neutralization of Input During Web Page Generation ("Cross-site Scr= ipting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting = (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from=
1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. 2026-07-10 not y=
et calculated CVE-2026-58587 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 58587 ] Drupal--Drupal Canvas Improper Neutralization of Input During Web P= age Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv=
as allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas vers= ions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1= .7.0 to 1.7.1. 2026-07-10 not yet calculated CVE-2026-58588 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-58588 ] Drupal--Drupal core Improperly Contr= olled Modification of Dynamically-Determined Object Attributes vulnerabilit=
y in Drupal Drupal core allows Object Injection. This issue affects Drupal = core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 t=
o 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1= .*. 2026-07-10 not yet calculated CVE-2026-55803 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-55803 ] Drupal--Drupal core Improperly Controlled Modif= ication of Dynamically-Determined Object Attributes vulnerability in Drupal=
Drupal core allows Object Injection. This issue affects Drupal core versio= ns: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, = from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. 2026-07= -10 not yet calculated CVE-2026-55804 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-55804 ] Drupal--Drupal core URL Redirection to Untrusted Site ('Op=
en Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. = This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0=
to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to = 11.0.*, from 0.0.0 to 11.1.*. 2026-07-10 not yet calculated CVE-2026-55806 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-55806 ] Drupal--Drupal core S= erver-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allow=
s Server Side Request Forgery. This issue affects Drupal core versions: fro=
m 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11= .3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. 2026-07-10 not=
yet calculated CVE-2026-55807 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-55807 ] Drupal--Drupal core Improper Neutralization of Input During Web P= age Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core=
allows Cross-Site Scripting (XSS). This issue affects Drupal core versions=
: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, fr=
om 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. 2026-07-1=
0 not yet calculated CVE-2026-55808 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-55808 ] Drupal--ECA: Event - Condition - Action Improperly Controlle=
d Modification of Dynamically-Determined Object Attributes vulnerability in=
Drupal ECA: Event - Condition - Action allows Object Injection. This issue=
affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, fr=
om 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4. 2026-07-10 not yet calculated CVE-= 2026-15083 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15083 ] Drupal--Ex= amples for Developers Missing Authorization vulnerability in Drupal Example=
s for Developers allows Forceful Browsing. This issue affects Examples for = Developers versions: from 0.0.0 to 4.0.6. 2026-07-10 not yet calculated CVE= -2026-11909 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11909 ] Drupal--F= lag attendance field Improperly Controlled Modification of Dynamically-Dete= rmined Object Attributes vulnerability in Drupal Flag attendance field allo=
ws Object Injection. This issue affects Flag attendance field versions: fro=
m 0.0.0 to 1.2. 2026-07-10 not yet calculated CVE-2026-55809 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-55809 ] Drupal--FlowDrop Missing Authorizat= ion vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue a= ffects FlowDrop versions: from 0.0.0 to 1.6.0. 2026-07-10 not yet calculate=
d CVE-2026-58589 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58589 ] Drup= al--FlowDrop Missing Authorization vulnerability in Drupal FlowDrop allows = Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.=
0. 2026-07-10 not yet calculated CVE-2026-58590 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-58590 ] Drupal--Formatter Field Improperly Controlled Mo= dification of Dynamically-Determined Object Attributes vulnerability in Dru= pal Formatter Field allows Object Injection. This issue affects Formatter F= ield versions: from 0.0.0 to 2.0.0. 2026-07-10 not yet calculated CVE-2026-= 12535 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12535 ] Drupal--Geoloca= tion Field Improper Neutralization of Special Elements used in an SQL Comma=
nd ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL I= njection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15= .0. 2026-07-10 not yet calculated CVE-2026-13242 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-13242 ] Drupal--LocalGov Workflows Missing Authorizatio=
n vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This=
issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. 2026-07-10=
not yet calculated CVE-2026-10768 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-10768 ] Drupal--Location Selector Improper Neutralization of Special = Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal L= ocation Selector allows SQL Injection. This issue affects Location Selector=
versions: from 0.0.0 to 1.3.0. 2026-07-10 not yet calculated CVE-2026-1508=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15081 ] Drupal--Login Disab=
le Improper Restriction of Excessive Authentication Attempts vulnerability =
in Drupal Login Disable allows Brute Force. This issue affects Login Disabl=
e versions: from 0.0.0 to 2.1.4. 2026-07-10 not yet calculated CVE-2026-150=
79 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15079 ] Drupal--Mother May=
I vulnerability in Drupal Mother May I allows . This issue affects Mother = May I versions: *.*. 2026-07-10 not yet calculated CVE-2026-11913 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-11913 ] Drupal--OpenAI Provider Server= -Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows=
Server Side Request Forgery. This issue affects OpenAI Provider versions: = from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2. 2026-07-10 not yet calculated CVE= -2026-13233 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13233 ] Drupal--P= aragraphs Missing Authorization vulnerability in Drupal Paragraphs allows F= orceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.2= 1.0. 2026-07-10 not yet calculated CVE-2026-13240 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-13240 ] Drupal--Paragraphs Missing Authorization vulne= rability in Drupal Paragraphs allows Forceful Browsing. This issue affects = Paragraphs versions: from 0.0.0 to 1.21.0. 2026-07-10 not yet calculated CV= E-2026-13241 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13241 ] Drupal--= Plotly.js Graphing Improperly Controlled Modification of Dynamically-Determ= ined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Ob= ject Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 =
to 3.0.2. 2026-07-10 not yet calculated CVE-2026-55810 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-55810 ] Drupal--Raw Formatter [Meta Tag Formatter=
] vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This = issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. 2026-07-10 = not yet calculated CVE-2026-15086 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15086 ] Drupal--Ray Enterprise Translation Cross-Site Request Forgery = (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site=
Request Forgery. This issue affects Ray Enterprise Translation versions: f= rom 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4. 2026-07-10 = not yet calculated CVE-2026-15080 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15080 ] Drupal--Salesforce Suite Cross-Site Request Forgery (CSRF) vul= nerability in Drupal Salesforce Suite allows Cross Site Request Forgery. Th=
is issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3. 2026-07-10=
not yet calculated CVE-2026-13243 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-13243 ] Drupal--Siteimprove Analytics Improper Neutralization of Inpu=
t During Web Page Generation ("Cross-site Scripting") vulnerability in Drup=
al Siteimprove Analytics allows Cross-Site Scripting (XSS). This issue affe= cts Siteimprove Analytics versions: from 0.0.0 to 2.0.1. 2026-07-10 not yet=
calculated CVE-2026-15082 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15= 082 ] Drupal--Tagify Improper Neutralization of Input During Web Page Gener= ation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Stored=
XSS. This issue affects Tagify versions: from 0.0.0 to 1.2.52. 2026-07-10 = not yet calculated CVE-2026-11908 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-11908 ] Drupal--Tealium iQ Tag Management Improperly Controlled Modifi= cation of Dynamically-Determined Object Attributes vulnerability in Drupal = Tealium iQ Tag Management allows Object Injection. This issue affects Teali=
um iQ Tag Management versions: from 0.0.0 to 2.4.0. 2026-07-10 not yet calc= ulated CVE-2026-13244 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13244 ]=
Drupal--UI Patterns (SDC in Drupal UI) Improper Neutralization of Input Du= ring Web Page Generation ("Cross-site Scripting") vulnerability in Drupal U=
I Patterns (SDC in Drupal UI) allows Stored XSS. This issue affects UI Patt= erns (SDC in Drupal UI) versions: from 2.0.0 to 2.0.17. 2026-07-10 not yet = calculated CVE-2026-15084 [
https://www.cve.org/CVERecord?id=3DCVE-2026-150=
84 ] Drupal--WissKI Missing Authorization vulnerability in Drupal WissKI al= lows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4= .2.0. 2026-07-10 not yet calculated CVE-2026-13239 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-13239 ] elixir-ecto--postgrex SQL Injection vulnerabi= lity in elixir-ecto postgrex allows an attacker who can influence a LISTEN = channel name to inject SQL into the reconnect replay query, causing a denia=
l of service of the notification connection. Postgrex.Notifications sanitiz=
es channel names with quote_channel/1, which doubles double quotes so the n= ame is safe inside a double-quoted identifier. This protects the single-sta= tement LISTEN and UNLISTEN paths. On every (re)connect, however, handle_con= nect/1 replays all registered channels at once by concatenating their LISTE=
N statements and wrapping them in a dollar-quoted anonymous code block (DO = $$BEGIN ... END$$). quote_channel/1 does not escape the $$ dollar-quote del= imiter that opens and closes this block. The listen/3 guards only reject nu=
ll bytes and names longer than 63 bytes, so a channel name containing $$ pa= sses validation unchanged. Once such a name is embedded, its $$ prematurely=
terminates the outer dollar-quoted string and PostgreSQL parses the remain= der as additional top-level statements. Because handle_connect/1 runs on ev= ery (re)connect, the malformed replay query is rejected each time and the n= otification connection never re-establishes its subscriptions, silently dro= pping notifications for every channel sharing that connection. An applicati=
on is affected when it passes untrusted input (for example a tenant or user=
identifier) as a channel name to Postgrex.Notifications.listen/3. The doub= le-quote doubling prevents forming a fully valid injected statement, so arb= itrary SQL execution is not possible, but the corrupted query reliably brea=
ks the shared notification connection for all tenants, resulting in denial =
of service. This issue affects postgrex: from 0.16.0 before 0.22.3. 2026-07= -10 not yet calculated CVE-2026-58225 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-58225 ] elixir-mint--hpax Inefficient Algorithmic Complexity vulne= rability in elixir-mint hpax allows unauthenticated denial-of-service via u= nbounded HPACK integer decoding. hpax decodes HPACK variable-length integer=
s with no upper bound on the decoded value or the number of continuation oc= tets. 'Elixir.HPAX.Types':decode_remaining_integer/3 accumulates the intege=
r as int + (value <<< m), shifting by 7 more bits for each continuation oct=
et and stopping only on a terminating octet or truncated input, never becau=
se the integer grew too large. Because BEAM integers are arbitrary precisio=
n, a run of N continuation octets builds an O(N)-bit bignum and re-adds int=
o an ever-larger bignum on each step, so the total decoding cost is superli= near (about O(N^2)). An unauthenticated attacker who can send an HTTP/2 hea= der block to a server using this decoder (reached through the 'Elixir.HPAX'= :decode/2 entry point) can supply a small header block that forces a large,=
attacker-controlled amount of CPU (and transient memory), a denial-of-serv= ice amplification. This issue affects hpax from 0.1.1 before 1.0.4. 2026-07= -06 not yet calculated CVE-2026-58226 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-58226 ] elixir-mint--mint Allocation of Resources Without Limits o=
r Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a=
denial of service via an oversized chunked transfer-encoded response. This=
vulnerability is associated with program files lib/mint/http1.ex and progr=
am routines 'Elixir.Mint.HTTP1':decode_body/5, 'Elixir.Mint.HTTP1':add_body= _to_buffer/2. When Mint decodes a chunked HTTP response body, it accumulate=
s each partial fragment of the current chunk in the connection's data_buffe=
r (an unbounded iolist) via add_body_to_buffer/2 and does not emit the data=
to the caller until the full declared chunk length has been received. The = chunk size is taken directly from the server and parsed with no upper bound=
, so a malicious or compromised server can announce one enormous chunk (for=
example a size line of 7FFFFFFF, about 2 GiB) and then send the body bytes=
slowly without ever completing the chunk. The client buffers every receive=
d byte while it waits for a completion that never arrives, and because no d= ata responses are produced until the chunk finishes, a caller that otherwis=
e streams large content-length bodies safely gains no protection. An unauth= enticated remote server (reachable whenever a client follows redirects, fet= ches user-supplied URLs, or processes webhooks) can drive the client's memo=
ry arbitrarily high and trigger an out-of-memory condition. This issue affe= cts mint: from 0.5.0 before 1.9.1. 2026-07-06 not yet calculated CVE-2026-5= 6810 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56810 ] elixir-plug--plu=
g Improper Neutralization of Parameter/Argument Delimiters vulnerability in=
elixir-plug plug allows an attacker to inject or override HTTP cookie attr= ibutes. The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex=
builds the Set-Cookie response header by interpolating the cookie value an=
d its path, domain, same_site, and extra attributes directly into the heade=
r without neutralizing the ';' delimiter that separates cookie attributes. =
An application that places attacker-controlled data into a cookie value or = attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a us= ername or preference) lets an attacker inject a ';' to append or override c= ookie attributes (such as Domain and Path scope, or dropping the Secure and=
HttpOnly flags), enabling cookie tossing and session fixation. Carriage re= turn, line feed, and null bytes are rejected by Plug.Conn header validation=
, so HTTP response splitting is not possible, but attribute injection throu=
gh ';' is not prevented. This issue affects plug: from 0.1.0 before 1.16.6,=
from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.0 before 1= .19.5, from 1.20.0 before 1.20.3. 2026-07-10 not yet calculated CVE-2026-56= 813 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56813 ] elixir-plug--plug=
Plug.Parsers.MULTIPART, the multipart request-body parser used to handle f= ile uploads and multipart forms, does not enforce its :length budget agains=
t all consumed resources, allowing an unauthenticated remote attacker to ca= use denial of service. The parser charges the :length limit only for part b= ody bytes; part header bytes are never counted, and a part with an empty bo=
dy costs zero. Because every part whose Content-Disposition carries a non-e= mpty filename creates a fresh temporary file (via Plug.Upload) and retains =
a Plug.Upload struct for the duration of the request, an attacker can send =
a single request composed of many empty-body file parts. Such a request sta=
ys well under the configured :length limit (8,000,000 bytes by default) whi=
le creating one temporary file per part, leading to inode and disk exhausti=
on and unbounded memory growth. Any application using Plug.Parsers with the=
:multipart parser is affected, and no authentication is required, only rea= chability of a multipart endpoint over HTTP. This vulnerability is associat=
ed with program files lib/plug/parsers/multipart.ex and program routines Pl= ug.Parsers.MULTIPART.parse_multipart/2, Plug.Parsers.MULTIPART.parse_multip= art_headers/5, Plug.Parsers.MULTIPART.parse_multipart_body/4, and Plug.Pars= ers.MULTIPART.parse_multipart_file/4. This issue affects plug: from 1.4.0 b= efore 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.= 19.0 before 1.19.5, and from 1.20.0 before 1.20.3. 2026-07-10 not yet calcu= lated CVE-2026-56814 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56814 ] = FireBoltt--Smartwatch FB BGS001 Fire-Boltt Smartwatch FB BGS001 Firmware: M= OY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts = GATT Write Request commands without sufficient authentication or strong ses= sion validation. Under specific conditions, previously captured BLE packets=
can be replayed from a nearby device to trigger functionality on the smart= watch. 2026-07-07 not yet calculated CVE-2026-37271 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-37271 ] FOSSBilling--FOSSBilling FOSSBilling is a fr= ee, open-source billing and client management system. Versions 0.6.0 throug=
h 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filte=
r functionality. An authenticated administrator can supply crafted filter v= alues when updating a mass email message, causing untrusted input to be int= erpolated directly into SQL in the recipient selection query. Version 0.8.0=
patches the issue. Some workarounds are available. Restrict administrator = access to trusted users only, disable the `Massmailer` module if it is not = required, audit existing records in the `mod_massmailer` table for suspicio=
us filter values, and/or review administrator activity related to `Massmail= er` message updates. 2026-07-06 not yet calculated CVE-2026-33734 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-33734 ] FOSSBilling--FOSSBilling FOSSB= illing is a free, open-source billing and client management system. Prior t=
o version 0.8.0, the Guest API invoice/update endpoint is missing an author= ization check present in other invoice-related endpoints, allowing an unaut= henticated user with knowledge of an invoice hash to modify the payment gat= eway associated with an unpaid invoice. An attacker who obtains an invoice = hash, which may leak through shared URLs, referrer headers, or email links,=
can change the `gateway_id` on an unpaid invoice to any payment gateway co= nfigured in the system. This does not allow redirecting payments to an arbi= trary external endpoint, as the gateway must already be installed and confi= gured by an administrator. The practical impact is further limited by the `= invoice_accessible_from_hash` system setting. Version 0.8.0 contains a patc=
h. No known workarounds are available. 2026-07-06 not yet calculated CVE-20= 26-42331 [
https://www.cve.org/CVERecord?id=3DCVE-2026-42331 ] FOSSBilling-= -FOSSBilling FOSSBilling is a free, open-source billing and client manageme=
nt system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment byp= ass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom p= ayment adapter is enabled, an attacker can mark any unpaid invoice as paid = and credit the associated client account without making an actual payment, =
by sending a single crafted HTTP request. Version 0.8.0 patches the issue. = Some workarounds are available. Disable the Custom payment gateway if not a= ctively needed and/or restrict access to `/ipn.php` at the web server level=
(e.g., via IP allowlisting), noting that this may interfere with legitimat=
e payment callback processing. 2026-07-06 not yet calculated CVE-2026-42341=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-42341 ] FOSSBilling--FOSSBil= ling FOSSBilling is a free, open-source billing and client management syste=
m. Prior to version 0.8.0, when a client or staff/admin account is suspende=
d or marked inactive, existing authenticated sessions are not invalidated. = The session identity loaders in src/di.php (loggedin_client and loggedin_ad= min) only reject sessions if the backing account record no longer exists in=
the database. They do not verify that the account's status is still active=
. This allows a suspended or deactivated user to retain full access until t= heir session naturally expires. This issue has been fixed in version 0.8.0.=
2026-07-06 not yet calculated CVE-2026-43918 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-43918 ] FOSSBilling--FOSSBilling FOSSBilling is a free, op= en-source billing and client management system. Versions 0.6.10 through 0.7=
.2 have a PHP code injection vulnerability in FOSSBilling's `Config::pretty= PrintArrayToPHP()` method. When configuration values are updated, string va= lues are written into `config.php` without escaping single quotes. Because = `config.php` is loaded via a bare `include` on every HTTP request, an attac= ker with admin privileges can inject arbitrary PHP code that executes on ev= ery subsequent request. Version 0.8.0 contains a patch. Some workarounds ar=
e available. Restrict admin access to trusted personnel only; audit `config= .php` for unexpected PHP code; and/ or at the reverse proxy/WAF level, rest= rict access to admin API endpoints that modify configuration. 2026-07-06 no=
t yet calculated CVE-2026-43921 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-43921 ] FOSSBilling--FOSSBilling FOSSBilling is a free, open-source bill= ing and client management system. Prior to version 0.8.0, an unauthenticate=
d mass assignment vulnerability in the client self-registration endpoint al= lows any visitor to assign themselves to an arbitrary client group during s= ign-up. Because client groups can gate promo code eligibility, an attacker = may apply group-restricted discount codes and receive unauthorized discount=
s. Version 0.8.0 contains a patch. As a workaround, administrators can eith=
er remove group restrictions from promo codes or disable client self-regist= ration (Settings =C3=A2=E2=80=A0=E2=80=99 Clients =C3=A2=E2=80=A0=E2=80=99 = Disable signup). 2026-07-06 not yet calculated CVE-2026-43925 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-43925 ] FOSSBilling--FOSSBilling FOSSBilli=
ng is a free, open-source billing and client management system. Prior to ve= rsion 0.8.0, a race condition in the cart checkout flow allows an authentic= ated client to apply a promo code beyond its configured maximum uses. By se= nding concurrent checkout requests before any single request completes the = usage increment, a client can obtain unlimited discounted or free orders fr=
om a single-use or limited-use promo code. Version 0.8.0 patches the issue.=
Some workarounds are available. Disable promo codes entirely until a patch=
is available or monitor the `promo` table for `used` values exceeding `max= uses` and manually review affected orders. 2026-07-06 not yet calculated CV= E-2026-43927 [
https://www.cve.org/CVERecord?id=3DCVE-2026-43927 ] FOSSBill= ing--FOSSBilling FOSSBilling is a free, open-source billing and client mana= gement system. Prior to version 0.8.0, the PayPalEmail payment adapter acce= pts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) t=
o the client's balance without validating it against the invoice total. Com= bined with a $0.05 floating-point epsilon tolerance in the invoice credit-p= ayment logic, this allows a client to underpay an invoice by up to $0.04 an=
d still have it marked as fully paid. Version 0.8.0 patches the issue. Ther=
e is no effective workaround without modifying the source code. Merchants u= sing the PayPalEmail adapter should monitor IPN transactions for amounts th=
at do not match their corresponding invoice totals, and manually review and=
refund suspicious payments. 2026-07-06 not yet calculated CVE-2026-43928 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-43928 ] FOSSBilling--FOSSBilli=
ng FOSSBilling is a free, open-source billing and client management system.=
Prior to version 0.8.0, low-privileged staff accounts may read sensitive d= ata via admin API endpoints that lack permission checks. While sibling writ=
e endpoints correctly enforce fine-grained permissions, the corresponding r= ead endpoints have no authorization guards. Version 0.8.0 contains a fix. S= ome workarounds are available. Restrict staff accounts to only those who ne=
ed access to sensitive data and/or use a reverse proxy or WAF to restrict a= ccess to the affected endpoints. 2026-07-06 not yet calculated CVE-2026-536=
40 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53640 ] FOSSBilling--FOSSB= illing FOSSBilling is a free, open-source billing and client management sys= tem. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) = vulnerability in the client-facing email history views of FOSSBilling. Emai=
l HTML content (`content_html`) is rendered into a JavaScript template lite= ral using the `|raw` filter, bypassing all output escaping. An attacker wit=
h admin access can inject malicious JavaScript payloads into email content = that execute in the browser of any client who views their email history. Ve= rsion 0.8.0 contains a fix. Some workarounds are available. Restrict admin = account access, audit email content in the database for suspicious payloads=
, and/or monitor client accounts for unusual activity. 2026-07-06 not yet c= alculated CVE-2026-53641 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5364=
1 ] FOSSBilling--FOSSBilling FOSSBilling is a free, open-source billing and=
client management system. In versions 0.5.6 through 0.7.2, when the "Requi=
re Email Confirmation" setting is enabled, a logged-in client with an unver= ified email address (`email_approved =3D 0`) can access all client-area pag=
es (e.g. `/client/balance`, `/client/order/list`, `/client/invoice`) and re=
ad real account data, including wallet balances and transaction history. Th=
e API-side enforcement correctly restricts unverified clients to only profi= le-related endpoints, but the page-side enforcement is overly permissive, a= llowing any request whose path starts with `/client`. Version 0.8.0 contain=
s a fix. No known workarounds that don't involve modifying the source code = are available. 2026-07-06 not yet calculated CVE-2026-53642 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-53642 ] FOSSBilling--FOSSBilling FOSSBilling=
is a free, open-source billing and client management system. Versions prio=
r to 0.8.0 allow low-privileged staff accounts to perform unauthorized acti= ons via admin API endpoints. The root cause is a combination of the `can_al= ways_access` module flag (which grants all staff access to certain modules)=
and insufficient permission checks or unsafe parameter handling on individ= ual endpoints. Version 0.8.0 contains a fix. Some workarounds are available=
. Restrict staff accounts to only those who need access to sensitive settin=
gs and/or use a reverse proxy or WAF to restrict access to the affected end= points to trusted IP addresses or higher-privilege roles. 2026-07-06 not ye=
t calculated CVE-2026-53643 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 3643 ] FOSSBilling--FOSSBilling FOSSBilling is a free, open-source billing = and client management system. Versions 0.5.3 through 0.7.2 allow authentica= ted clients to both read and reset API key service secrets for orders that = are no longer in an `active` state (e.g., `suspended`, `canceled`). The roo=
t cause is missing order-state validation in two client API endpoints, desp= ite an `isActive()` helper already existing in the `Serviceapikey` module a=
nd the frontend UI correctly gating access on `order.status =3D=3D 'active'=
`. Version 0.8.0 contains a fix. Some workarounds are available. If the `Se= rviceapikey` module is not needed, uninstall it to remove the affected endp= oints. One may also use a reverse proxy or WAF to restrict access to `/api/= client/order/service` and `/api/client/serviceapikey/reset` based on applic= ation-level order-state logic. 2026-07-06 not yet calculated CVE-2026-53644=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-53644 ] FOSSBilling--FOSSBil= ling FOSSBilling is a free, open-source billing and client management syste=
m. Versions prior to 0.8.0 allow a low-privileged staff account to grant ar= bitrary module permissions to itself through the admin API, resulting in pe= rsistent privilege escalation. A staff user that only has `staff.create_and= _edit_staff` can call `/api/admin/staff/permissions_update` targeting their=
own account and write any permission structure, bypassing the intended rol= e-based access control boundary. Version 0.8.0 patches the issue. Some work= arounds are available. Restrict the `staff.create_and_edit_staff` permissio=
n to only highly trusted staff members and/or use a reverse proxy or WAF to=
restrict access to `/api/admin/staff/permissions_update` to specific trust=
ed roles. 2026-07-06 not yet calculated CVE-2026-53645 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-53645 ] FOSSBilling--FOSSBilling FOSSBilling is a=
free, open-source billing and client management system. In versions 0.5.6 = through 0.7.2, when a `ClientPasswordReset` record already exists for a cli= ent (from a previous unexpired reset request), subsequent calls to the `res= et_password` guest API endpoint reuse the existing token instead of generat= ing a new one. The 15-minute validity window is anchored to the first reque= st's `created_at` timestamp, not the time of the most recent email. An atta= cker who obtained the original reset link remains able to use it even after=
the victim requests a new reset, because the original token is never inval= idated or rotated. Version 0.8.0 patches the issue. Some workarounds are av= ailable. Configure a reverse proxy (e.g., Nginx, Apache, Cloudflare) to app=
ly per-IP rate limiting to the `/client/reset-password` endpoint to minimiz=
e the window of opportunity, and/or manually clear expired `client_password= _reset` records from the database after a client reports a suspected compro= mise. 2026-07-06 not yet calculated CVE-2026-53646 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-53646 ] FOSSBilling--FOSSBilling FOSSBilling is a fre=
e, open-source billing and client management system. In versions 0.5.3 thro= ugh 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible wi= thout authentication. Any caller with a valid API key can retrieve all cust=
om configuration parameters (`custom_*` fields) stored in the key's databas=
e record. These custom fields are populated by billing administrators and c=
an contain business-sensitive data such as pricing tiers, feature flags, ra=
te limits, expiry overrides, or access scope data. Version 0.8.0 patches th=
e issue. Some workarounds are available. Administrators can avoid storing s= ensitive data in `custom_*` API key configuration fields, monitor API logs = for suspicious calls to `/api/guest/serviceapikey/get_info`, and/or disable=
the Serviceapikey module if not in active use. 2026-07-06 not yet calculat=
ed CVE-2026-53647 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53647 ] FOS= SBilling--FOSSBilling FOSSBilling is a free, open-source billing and client=
management system. Prior to version 0.8.1, downloadable product files are = stored using a deterministic filename-derived path. When an administrator u= ploads a file for a downloadable product, FOSSBilling stores the file as `m= d5(<original filename>)` under the uploads directory. Because the stored pa=
th depends only on the client-supplied filename, two different downloadable=
products, or product/order files, uploaded with the same original filename=
will resolve to the same stored file path. A later upload can overwrite an=
earlier upload, causing customers or administrators downloading the earlie=
r product to receive the later file instead. Version 0.8.1 patches the issu=
e. Some workarounds are available. Restrict the `servicedownloadable.manage=
` permission to fully trusted administrators only. As an operational mitiga= tion, ensure downloadable product files use unique filenames before upload.=
This reduces accidental collisions but does not fully address the underlyi=
ng issue. 2026-07-06 not yet calculated CVE-2026-53648 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-53648 ] frappe--frappe Frappe is a full-stack web=
application framework. Prior to 16.18.3, possible path traversal and local=
file inclusion were possible through secure local resource access in the C= hrome PDF Generator. This issue is fixed in version 16.18.3. 2026-07-10 not=
yet calculated CVE-2026-41482 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-41482 ] frappe--frappe Frappe is a full-stack web application framework. = Prior to 16.19.0 and 15.109.0, path traversal via download_backups was poss= ible due to lack of hardening. This issue is fixed in versions 16.19.0 and = 15.109.0. 2026-07-10 not yet calculated CVE-2026-42219 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-42219 ] frappe--frappe Frappe is a full-stack web=
application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query=
permitted SELECT INTO OUTFILE queries, which could potentially work on sel= f-hosted sites if database permissions are not well aligned and MySQL FILE = privileges are available. This issue is fixed in versions 16.18.3 and 15.10= 8.0. 2026-07-10 not yet calculated CVE-2026-47199 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-47199 ] frappe--frappe Frappe is a full-stack web appl= ication framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview=
lacked appropriate permission checks and that has since been fixed. This v= ulnerability is fixed in 15.107.5 and 16.18.2. 2026-07-10 not yet calculate=
d CVE-2026-47422 [
https://www.cve.org/CVERecord?id=3DCVE-2026-47422 ] frap= pe--frappe Frappe is a full-stack web application framework. Prior to 16.20=
.0 and 15.110.0, users without write access could attach files to any docty=
pe through file-handling API endpoints such as add_attachments. This issue =
is fixed in versions 16.20.0 and 15.110.0. 2026-07-10 not yet calculated CV= E-2026-48127 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48127 ] frappe--= frappe Frappe is a full-stack web application framework. Prior to 16.19.0, = authorization bypass was possible via the update_page endpoint in Workspace=
because public workspaces did not receive the required Workspace Manager e= dit check. This issue is fixed in version 16.19.0. 2026-07-10 not yet calcu= lated CVE-2026-49394 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49394 ] = frappe--frappe Frappe is a full-stack web application framework. Prior to 1= 6.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tar= file members were not sufficiently checked before extraction. This issue is=
fixed in versions 16.23.0 and 15.112.0. 2026-07-10 not yet calculated CVE-= 2026-55852 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55852 ] frappe--fr= appe Frappe is a full-stack web application framework. Prior to 16.16.0 and=
15.106.0, user enumeration could be performed via the reset_password endpo= int. This issue is fixed in versions 16.16.0 and 15.106.0. 2026-07-10 not y=
et calculated CVE-2026-58503 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 58503 ] FreeRDP--FreeRDP FreeRDP is a free implementation of the Remote Des= ktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an=
integer overflow in update_read_delta_points in libfreerdp/core/orders.c w= hen multiplying an attacker-controlled point count by sizeof(DELTA_POINT), = allowing a malicious RDP peer to allocate an undersized heap buffer and the=
n write beyond it during initialization. This issue is fixed in version 3.2= 8.0. 2026-07-10 not yet calculated CVE-2026-57156 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-57156 ] FreeRDP--FreeRDP FreeRDP is a free implementat= ion of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clie= nts using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in = planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a m= alicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar=
payload that reads one byte past the input buffer. This issue is fixed in = version 3.28.0. 2026-07-10 not yet calculated CVE-2026-57158 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-57158 ] FreeType--FreeType 2.14.3 An out-of= -bounds read vulnerability exists in FreeType 2.14.3 and versions before co= mmit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in=
the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates=
2026-07-07 not yet calculated CVE-2026-50811 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-50811 ] Fuji Electric Co.,Ltd.--Pupsman Uncontrolled searc=
h path element issue exists in Pupsman versions prior to 3.9.0. If a crafte=
d DLL file is placed in the same folder as the affected installer and the i= nstaller is executed, arbitrary code may be executed with SYSTEM privilege.=
2026-07-08 not yet calculated CVE-2026-56437 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-56437 ] Fuji Electric Co.,Ltd.--Pupsman Incorrect default = permissions issue exists in Pupsman versions prior to 3.9.0. An attacker ca=
n place a malicious executable in the installation folder, which results in=
arbitrary code execution with SYSTEM privilege 2026-07-08 not yet calculat=
ed CVE-2026-57895 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57895 ] get= grav--grav Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.=
8, Grav allows an unauthenticated visitor to exhaust server memory and CPU =
by requesting image derivatives with oversized dimensions through URL query=
image actions such as forceResize in Grav::fallbackUrl, which passes reque=
st parameters to ImageMedium magic actions without a dimension or pixel cei= ling. This issue is fixed in versions 1.7.53 and 2.0.0-rc.8. 2026-07-10 not=
yet calculated CVE-2026-53653 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-53653 ] getgrav--grav grav-plugin-database is the database plugin for Gra=
v CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table a= rgument directly into a raw SQL query string without sanitization, escaping=
, quoting, or whitelisting, allowing attacker-controlled table names passed=
by consuming plugin or developer code to execute arbitrary SQL against the=
configured database. This issue is fixed in version 1.2.0. 2026-07-10 not = yet calculated CVE-2026-58492 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -58492 ] getgrav--grav grav-plugin-database is the database plugin for Grav=
CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by directly c= oncatenating user-configurable YAML values from fields such as host, dbname=
, charset, server, database, directory, and filename without sanitization o=
r validation, allowing an administrator with plugin configuration access to=
inject DSN attributes or path traversal values. This issue is fixed in ver= sion 1.2.0. 2026-07-10 not yet calculated CVE-2026-58493 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-58493 ] getgrav--grav grav-plugin-admin is an H= TML user interface that provides a way to configure Grav and create and mod= ify pages. In 1.10.52 and earlier, an authenticated attacker with admin.use=
rs permission can change the password of any user account, including the su= per administrator, by sending a direct POST request to /admin/user/{usernam= e}?task=3Dsave with data[password] because saveUser authorizes the caller's=
user-management permission but does not verify whether the caller may edit=
the target user. This issue is expected to be fixed in version 1.10.53. 20= 26-07-10 not yet calculated CVE-2026-59190 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-59190 ] getgrav--grav Grav is a file-based Web platform. Prio=
r to 2.0.0, an authenticated admin.super user can crash Grav or fill the di=
sk by uploading a specially crafted ZIP archive through the Direct Install = tool because Installer::unZip calls ZipArchive::extractTo without limits on=
uncompressed size, entry count, or directory depth. This issue is fixed in=
version 2.0.0. 2026-07-10 not yet calculated CVE-2026-59193 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-59193 ] getkirby--kirby Kirby is an open-so= urce content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using=
the pages field with roles that have the pages.access permission disabled = allowed authenticated users to provide an inaccessible parent page or site =
to the page picker backend and confirm arbitrary page existence and retriev=
e title field values. This issue is fixed in versions 4.9.4 and 5.4.4. 2026= -07-09 not yet calculated CVE-2026-49274 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49274 ] getkirby--kirby Kirby is an open-source content managem= ent system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in=
any blueprint allowed a scripting link to be included as the target of a l= ink or email link in writer mark components, making the target clickable by=
the user who entered it and enabling self cross-site scripting in the Pane=
l. This issue is fixed in versions 4.9.4 and 5.4.4. 2026-07-09 not yet calc= ulated CVE-2026-49276 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49276 ]=
getkirby--kirby Kirby is an open-source content management system. Prior t=
o 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote clas=
s, including Remote::request(), Remote::get(), and Remote::post(), to send = outgoing HTTP requests with untrusted data in the headers option could allo=
w newline characters in a header value to inject a separate unintended requ= est header to the remote service. This issue is fixed in versions 4.9.4 and=
5.4.4. 2026-07-09 not yet calculated CVE-2026-50188 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-50188 ] getkirby--kirby Kirby is an open-source con= tent management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins t= hat use the writer or list fields or call Dom::sanitize(), Sane::sanitize()=
, Sane::Html::sanitize(), Sane::Svg::sanitize(), Sane::Xml::sanitize(), San= e::sanitizeFile(), or file sanitizeContents() with untrusted input allow ma= licious markup injected as children of an unknown HTML or XML tag to pass t= hrough Dom::sanitize() without being correctly sanitized, causing stored cr= oss-site scripting. This issue is fixed in versions 4.9.4 and 5.4.4. 2026-0= 7-09 not yet calculated CVE-2026-54002 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-54002 ] getkirby--kirby Kirby is an open-source content managem= ent system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured u= ser accounts that run on publicly accessible servers behind a reverse proxy=
setting the Forwarded, X-Client-IP, or X-Real-IP request header could allo=
w remote attackers to install the Panel and create the first admin user bec= ause local-IP checks trusted those headers incorrectly. This issue is fixed=
in versions 4.9.4 and 5.4.4. 2026-07-09 not yet calculated CVE-2026-54003 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-54003 ] getkirby--kirby Kirby=
is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kir=
by sites with content.fileRedirects enabled could redirect unauthenticated = clean file URL requests for files stored in top-level draft pages to physic=
al media URLs without checking page access permissions or preview tokens, l= eading to disclosure of draft file contents. This issue is fixed in version=
s 4.9.4 and 5.4.4. 2026-07-09 not yet calculated CVE-2026-54004 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-54004 ] getkirby--kirby Kirby is an open= -source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites wh= ere a role has the pages.access permission disabled allowed authenticated u= sers who know or guess page IDs or UUIDs to retrieve page information, incl= uding full content and metadata, for arbitrary published pages through the = /api/site/find route without authorization to access those pages. This issu=
e is fixed in versions 4.9.4 and 5.4.4. 2026-07-09 not yet calculated CVE-2= 026-54005 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54005 ] GNU wget--W= get GNU Wget does not validate the IP address provided by an FTP PASV respo= nse while operating in FTP passive mode. A malicious FTP server, or an HTTP=
server that redirects to an FTP URL, can exploit this behavior to redirect=
Wget's data connection to an arbitrary IP address and port. This allows an=
attacker to forge server-side requests (SSRF) from the machine running Wge=
t, potentially accessing localhost services or internal network resources. = 2026-07-10 not yet calculated CVE-2026-15146 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-15146 ] GNU--patch GNU patch is vulnerable to a NULL pointe=
r dereference when processing a specially crafted unified-diff patch file. = Improper handling of consecutive end-of-file newline markers can corrupt in= ternal hunk (single block of changes in diff) data structures, causing the = application to pass a NULL pointer to fwrite() during patch processing. An = attacker can trigger this condition with a malicious patch file, causing th=
e utility to crash and resulting in a denial of service. This issue has bee=
n fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313 2026-07-09 n=
ot yet calculated CVE-2026-56288 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-56288 ] GNU--patch GNU patch is vulnerable to a denial of service (DoS)=
due to improper validation of hunk (single block of changes in diff) line = offsets in unified-diff input. A specially crafted patch can specify an ext= remely large line number, causing the application to enter an effectively i= nfinite processing loop while attempting to locate the requested position. = This results in excessive CPU consumption and prevents the process from com= pleting. An attacker can trigger this behavior by supplying a malicious pat=
ch file, causing the utility to become unresponsive and require manual term= ination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9d= c85e350929c4b9 2026-07-09 not yet calculated CVE-2026-56289 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-56289 ] Go standard library--crypto/tls Hand= shakes which used Encrypted Client Hello could be de-anonymized by a passiv=
e network observer due to a disclosure of pre-shared key identities in the = unencrypted client hello. 2026-07-08 not yet calculated CVE-2026-42505 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-42505 ] Go standard library--os O=
n Unix systems, opening a file in an os.Root improperly follows symlinks to=
locations outside of the Root when the final path component of the a path =
is a symbolic link and the path ends in /. For example, 'root.Open("symlink= /")' will open "symlink" even when "symlink" is a symbolic link pointing ou= tside of the root. 2026-07-08 not yet calculated CVE-2026-39822 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-39822 ] gohugoio--hugo Hugo is a static = site generator. Prior to 0.162.0, Hugo accepts content files in several mar= kup formats. Files mapped to the text/html media type (typically .html file=
s under /content, or pages produced by a content adapter that sets content.= mediaType =3D "text/html") had their body emitted verbatim into the rendere=
d page. A site that ingests HTML content from an untrusted source could the= refore be served stored cross-site scripting. This vulnerability is fixed i=
n 0.162.0. 2026-07-06 not yet calculated CVE-2026-50133 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-50133 ] gohugoio--hugo Hugo is a static site gen= erator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.ht= tp.urls on the URL it is called with, but it did not re-validate intermedia=
te URLs on HTTP 3xx redirects. An allowed server (or an attacker controllin=
g its DNS or response) could therefore redirect the request to a host that = the policy was meant to forbid and Hugo would fetch from the redirected tar= get. The same bypass also lifted any host-shape restriction the operator ha=
d put in place. This vulnerability is fixed in 0.162.0. 2026-07-06 not yet = calculated CVE-2026-50134 [
https://www.cve.org/CVERecord?id=3DCVE-2026-501=
34 ] gohugoio--hugo Hugo is a static site generator. From 0.123.0 to 0.161.=
1, a regression made =C2=A0RootMappingFs.statRoot=C2=A0 use =C2=A0Stat=C2=
=A0 (follows symlinks) instead of =C2=A0Lstat=C2=A0, so a direct =C2=A0reso= urces.Get=C2=A0 of a symlink pointing outside its mount returned the target=
's contents - letting a symlink planted in a local mount (e.g. a vendored = =C2=A0themes/=C2=A0 theme) read arbitrary files accessible to the Hugo user=
. Go-module themes from GitHub (symlinks stripped) and directory walks were=
unaffected. Fixed in 0.162.0. 2026-07-06 not yet calculated CVE-2026-50135=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-50135 ] gohugoio--hugo Hugo =
is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-= block renderer wrote the Markdown code-fence language or info-string into t=
he code class=3D"language-=C2=A6" data-lang=3D"=C2=A6" wrapper without HTML=
escaping. A fence info-string containing a quote and a script payload brea=
ks out of the attribute and injects a live script element. This issue is fi= xed in 0.163.3. 2026-07-06 not yet calculated CVE-2026-58402 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-58402 ] gohugoio--hugo Hugo is a static sit=
e generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is d= esigned so that files under a mount cannot reach outside the mount tree, bu=
t a regression caused RootMappingFs.statRoot to call Stat, which follows sy= mlinks, instead of Lstat, so a direct os.ReadFile "somefile" where somefile=
was a symlink pointing outside the mount would return the target's content=
s. This effectively let a symlink planted inside a theme or local mount rea=
d arbitrary files reachable to the user running hugo. This issue is fixed i=
n v0.163.1. 2026-07-06 not yet calculated CVE-2026-58403 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-58403 ] gohugoio--hugo Hugo is a static site ge= nerator. From v0.162.0 through v0.163.0, the default security.http.urls pol= icy denies requests to loopback, internal, and cloud-metadata IPv4 literals=
, but the deny rule only matched dotted-decimal notation, so alternate IPv4=
encodings of the same addresses, including integer, hex, or octal, passed = the policy. When a template passes an untrusted or data-derived URL to reso= urces.GetRemote and the host platform uses the cgo system resolver, these e= ncodings resolve to the blocked address, allowing build-time server-side re= quests to loopback and internal services, including the cloud-metadata endp= oint in hosted or CI builds; the same check is reused on redirects, so the = gap also applies to each redirect hop. This issue is fixed in v0.163.1. 202= 6-07-06 not yet calculated CVE-2026-58404 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-58404 ] Google Cloud--Apigee An Improper Input Validation vuln= erability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-=
12 on Google Cloud Platform allows an authenticated attacker to exfiltrate = cross-tenant data. This vulnerability was patched on 12 June 2026 on the Ap= igee Servers, and no customer action is needed. 2026-07-09 not yet calculat=
ed CVE-2026-12879 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12879 ] Goo= gle--Chrome Use after free in IndexedDB in Google Chrome prior to 150.0.787= 1.115 allowed a remote attacker to execute arbitrary code inside a sandbox = via a crafted HTML page. (Chromium security severity: Medium) 2026-07-08 no=
t yet calculated CVE-2026-15107 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-15107 ] Google--Chrome Integer overflow in Extensions API in Google Chro=
me prior to 150.0.7871.115 allowed an attacker who convinced a user to inst= all a malicious extension to perform an out of bounds memory read via a cra= fted Chrome Extension. (Chromium security severity: High) 2026-07-08 not ye=
t calculated CVE-2026-15108 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 5108 ] Google--Chrome Uninitialized Use in ANGLE in Google Chrome prior to = 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive in= formation from process memory via a crafted HTML page. (Chromium security s= everity: High) 2026-07-08 not yet calculated CVE-2026-15109 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-15109 ] Google--Chrome Use after free in Ext= ensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who co= nvinced a user to install a malicious extension to potentially exploit heap=
corruption via a crafted Chrome Extension. (Chromium security severity: Hi= gh) 2026-07-08 not yet calculated CVE-2026-15110 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-15110 ] Google--Chrome Use after free in Views in Googl=
e Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a = user to engage in specific UI gestures to potentially exploit heap corrupti=
on via a crafted HTML page. (Chromium security severity: High) 2026-07-08 n=
ot yet calculated CVE-2026-15111 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-15111 ] Google--Chrome Use after free in Ozone in Google Chrome prior t=
o 150.0.7871.115 allowed a remote attacker to potentially exploit heap corr= uption via a crafted HTML page. (Chromium security severity: Critical) 2026= -07-08 not yet calculated CVE-2026-15112 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15112 ] Google--Chrome Use after free in Autofill in Google Chr= ome on Android prior to 150.0.7871.115 allowed a remote attacker to potenti= ally perform a sandbox escape via a crafted HTML page. (Chromium security s= everity: High) 2026-07-08 not yet calculated CVE-2026-15113 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-15113 ] Google--Chrome Out of bounds read an=
d write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote=
attacker to potentially exploit heap corruption via a crafted video file. = (Chromium security severity: High) 2026-07-08 not yet calculated CVE-2026-1= 5114 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15114 ] Google--Chrome I= nsufficient validation of untrusted input in WebAppInstalls in Google Chrom=
e on Android prior to 150.0.7871.115 allowed a local attacker to bypass sam=
e origin policy via a crafted HTML page. (Chromium security severity: High)=
2026-07-08 not yet calculated CVE-2026-15115 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-15115 ] Google--Chrome Use after free in Actor in Google C= hrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrar=
y code inside a sandbox via a crafted HTML page. (Chromium security severit=
y: High) 2026-07-08 not yet calculated CVE-2026-15116 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-15116 ] Google--Chrome Use after free in Payments =
in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who conv= inced a user to engage in specific UI gestures to potentially exploit heap = corruption via a crafted HTML page. (Chromium security severity: High) 2026= -07-08 not yet calculated CVE-2026-15117 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15117 ] Google--Chrome Use after free in Input in Google Chrome=
prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary cod=
e inside a sandbox via a crafted HTML page. (Chromium security severity: Hi= gh) 2026-07-08 not yet calculated CVE-2026-15118 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-15118 ] Google--Chrome Race in GetUserMedia in Google C= hrome prior to 150.0.7871.115 allowed a remote attacker who had compromised=
the renderer process to potentially perform a sandbox escape via a crafted=
HTML page. (Chromium security severity: High) 2026-07-08 not yet calculate=
d CVE-2026-15119 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15119 ] Goog= le--Chrome Use after free in Core in Google Chrome on Windows prior to 150.= 0.7871.115 allowed a remote attacker who had compromised the renderer proce=
ss to potentially perform a sandbox escape via a crafted HTML page. (Chromi=
um security severity: High) 2026-07-08 not yet calculated CVE-2026-15120 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-15120 ] Google--Chrome Use afte=
r free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote = attacker to execute arbitrary code inside a sandbox via a crafted HTML page=
. (Chromium security severity: High) 2026-07-08 not yet calculated CVE-2026= -15121 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15121 ] Google--Chrome=
Insufficient validation of untrusted input in Codecs in Google Chrome on W= indows prior to 150.0.7871.115 allowed a remote attacker who had compromise=
d the renderer process to potentially perform a sandbox escape via a crafte=
d HTML page. (Chromium security severity: High) 2026-07-08 not yet calculat=
ed CVE-2026-15122 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15122 ] Goo= gle--Chrome Inappropriate implementation in DOM in Google Chrome prior to 1= 50.0.7871.115 allowed a remote attacker to potentially exploit heap corrupt= ion via a crafted HTML page. (Chromium security severity: High) 2026-07-08 = not yet calculated CVE-2026-15123 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-15123 ] Google--Chrome Insufficient policy enforcement in Passwords in=
Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass = same origin policy via a crafted HTML page. (Chromium security severity: Hi= gh) 2026-07-08 not yet calculated CVE-2026-15124 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-15124 ] Google--Chrome Inappropriate implementation in = Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to=
execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium=
security severity: High) 2026-07-08 not yet calculated CVE-2026-15125 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-15125 ] Google--Chrome Use after = free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote att= acker to execute arbitrary code inside a sandbox via a crafted HTML page. (= Chromium security severity: High) 2026-07-08 not yet calculated CVE-2026-15= 126 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15126 ] Google--Chrome In= appropriate implementation in WebGL in Google Chrome prior to 150.0.7871.11=
5 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via =
a crafted HTML page. (Chromium security severity: High) 2026-07-08 not yet = calculated CVE-2026-15127 [
https://www.cve.org/CVERecord?id=3DCVE-2026-151=
27 ] Google--Chrome Inappropriate implementation in Forms in Google Chrome = prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scrip=
ts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Hig=
h) 2026-07-08 not yet calculated CVE-2026-15128 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-15128 ] Google--Chrome Use after free in Views in Google=
Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially ex= ploit heap corruption via a crafted HTML page. (Chromium security severity:=
Critical) 2026-07-08 not yet calculated CVE-2026-15129 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-15129 ] Google--Chrome Insufficient policy enfor= cement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a rem= ote attacker to bypass site isolation via a crafted HTML page. (Chromium se= curity severity: High) 2026-07-08 not yet calculated CVE-2026-15130 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-15130 ] Google--Chrome Inappropriate=
implementation in Navigation in Google Chrome prior to 150.0.7871.115 allo= wed a remote attacker to bypass site isolation via a crafted HTML page. (Ch= romium security severity: Medium) 2026-07-08 not yet calculated CVE-2026-15= 131 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15131 ] Google--Chrome Un= initialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a re= mote attacker to execute arbitrary code inside a sandbox via a crafted HTML=
page. (Chromium security severity: High) 2026-07-08 not yet calculated CVE= -2026-15132 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15132 ] Google--C= hrome Use after free in InterestGroups in Google Chrome prior to 150.0.7871= .115 allowed a remote attacker to execute arbitrary code inside a sandbox v=
ia a crafted HTML page. (Chromium security severity: High) 2026-07-08 not y=
et calculated CVE-2026-15133 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 15133 ] GPAC--GPAC A NULL pointer dereference in smooth_parse_stream_index(=
) in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85f= bb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service 20= 26-07-07 not yet calculated CVE-2026-50810 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-50810 ] gristlabs--grist-core Grist is spreadsheet software u= sing Python as its formula language. Prior to 1.7.15, Grist contained two c= ross-site scripting vulnerabilities where an attacker-controlled value reac= hed a link's href without scheme validation, so a javascript URL could run =
in a victim's Grist origin on a single click. On the account-selection page=
, /welcome/select-account used its next query parameter as the account butt= ons' link target. In document tours, the GristDocTour table's Link_URL colu=
mn became a clickable button, allowing an editor of a shared document to st= ore a javascript URL there that ran when another user opened the document a=
nd clicked the tour link. Because the script runs in the victim's authentic= ated session, it can call Grist APIs as the victim, reading or modifying da=
ta and changing sharing settings and access rules. A document editor could = therefore escalate to owner-level access. This issue is fixed in version 1.= 7.15. 2026-07-10 not yet calculated CVE-2026-55665 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-55665 ] grokability--snipe-it Snipe-IT is an IT asset= /license management system. Prior to version 8.6.1, the GET /api/v1/{object= }/selectlist API endpoint is missing an authorization check. Any user who c=
an log into Snipe-IT - regardless of permissions - can retrieve a paginated=
list of all user accounts using only their web session cookie. No API toke=
n or elevated permissions are required. This exposes usernames, display nam= es, employee numbers, and user IDs for every active account in the system i=
f FMCS is not enabled, and within the company they belong to if FMCS is ena= bled. Version 8.6.1 contains a patch. 2026-07-08 not yet calculated CVE-202= 6-48492 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48492 ] grokability--= snipe-it Snipe-IT is an IT asset/license management system. Prior to 8.5.0,=
Actionlog::logaction() stores the request User-Agent header and ReportsCon= troller::postActivityReport() writes that value to the Activity Report CSV = without formula escaping, allowing a low-privileged authenticated user to s= tore a formula-like User-Agent that may execute when a report viewer opens = the exported CSV in spreadsheet software. This issue is fixed in version 8.= 5.0. 2026-07-10 not yet calculated CVE-2026-55452 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-55452 ] grokability--snipe-it Snipe-IT is an IT asset/= license management system. Prior to 8.6.2, CommonMark escapes raw HTML but = does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user = with assets.edit permission to place a malicious link in a markdown-textare=
a custom field that executes arbitrary JavaScript when another user opens t=
he asset detail page and clicks the link. This issue is fixed in version 8.= 6.2. 2026-07-10 not yet calculated CVE-2026-55464 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-55464 ] grokability--snipe-it Snipe-IT is an IT asset/= license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG = content only when PHP finfo reports image/svg+xml and UploadedFilesControll=
er serves attachments inline without using StorageHelper::allowSafeInline()=
, allowing a low-privilege user to upload active XHTML or XML content that =
is later served same-origin and executes JavaScript in a viewer's browser. = This issue is fixed in version 8.6.2. 2026-07-10 not yet calculated CVE-202= 6-55466 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55466 ] grokability--= snipe-it Snipe-IT is an IT asset/license management system. Prior to 8.5.0,=
ActionlogController::displaySig concatenates the route filename parameter = into a private upload-directory path without sanitization, allowing an auth= enticated attacker to traverse outside the intended directory and read arbi= trary files accessible to the web server process. This issue is fixed in ve= rsion 8.5.0. 2026-07-10 not yet calculated CVE-2026-55474 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-55474 ] grokability--snipe-it Snipe-IT is an I=
T asset/license management system. Prior to 8.6.0, POST /account/request/{i= temType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_ad= min as a URL path segment without sufficient authorization, allowing an aut= henticated user to supply a victim user ID and silently cancel that user's = pending asset requests. This issue is fixed in version 8.6.0. 2026-07-10 no=
t yet calculated CVE-2026-55476 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-55476 ] grokability--snipe-it Snipe-IT is an IT asset/license management=
system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether=
the caller can edit kits but does not authorize access to the referenced l= icense object, allowing a low-privilege user with predefined-kit permission=
s to bind a license they should not be able to access or manage into a kit.=
This issue is fixed in version 8.6.2. 2026-07-10 not yet calculated CVE-20= 26-55478 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55478 ] grokability-= -snipe-it Snipe-IT is an IT asset/license management system. Prior to 8.6.2=
, the legacy single-seat license checkin flow authorizes the action with th=
e checkout permission instead of the checkin permission, allowing a user wh=
o can assign licenses but not unassign them to directly access the old chec= kin endpoint and reclaim a license seat assigned to another user or asset. = This issue is fixed in version 8.6.2. 2026-07-10 not yet calculated CVE-202= 6-55479 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55479 ] grokability--= snipe-it Snipe-IT is an IT asset/license management system. Prior to 8.6.2,=
default.blade.php renders header_color and related branding color settings=
inside a CSS style block with HTML escaping that is insufficient for the C=
SS context, allowing a superadmin to inject arbitrary CSS that affects auth= enticated users on subsequent page loads when Content Security Policy is di= sabled. This issue is fixed in version 8.6.2. 2026-07-10 not yet calculated=
CVE-2026-55481 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55481 ] groka= bility--snipe-it Snipe-IT is an IT asset/license management system. Prior t=
o version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization = before temporary URL. On S3-backed deployments, authenticated users who kno=
w a signature filename can obtain a 5-minute signed S3 URL because the S3 b= ranch returns before the `authorize()` call used by the local-file branch. = Version 8.6.1 contains a patch. 2026-07-08 not yet calculated CVE-2026-5554=
2 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55542 ] grokability--snipe-=
it Snipe-IT is an IT asset/license management system. Prior to 8.6.0, Users= Controller::update() passes a missing permission request field through Norm= alizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissions= Action in a way that can overwrite a target user's permissions with a spars=
e result, allowing an administrator updating another administrator, or a us=
er with users.edit updating a regular account, to remove the target's admin= istrative or granular permissions. This issue is fixed in version 8.6.0. 20= 26-07-10 not yet calculated CVE-2026-55843 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-55843 ] HAARG--HTTP::Tiny HTTP::Tiny versions before 0.095 fo=
r Perl forward credential headers to cross-origin redirect targets. When th=
e server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` = header and `_prepare_headers_and_cb` re-merges the caller's `headers` argum= ent into the new request, without checking whether the redirect target shar=
es an origin with the original URL. Caller-supplied `Authorization`, `Cooki=
e` and `Proxy-Authorization` headers are therefore re-sent to whatever host=
the redirect names, across scheme, host or port boundaries, and including = `https` to `http` downgrades that expose them in plaintext on the wire. The=
HTTP::Tiny POD note that "Authorization headers will not be included in a = redirected request" applied only to the URL-userinfo Basic-auth path, not t=
o headers passed explicitly by the caller. 2026-07-07 not yet calculated CV= E-2026-7017 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7017 ] hapifhir--= org.hl7.fhir.core HAPI FHIR is a complete implementation of the HL7 FHIR st= andard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fh= ir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bar=
e net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCE= SS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or c=
an tamper with transformed XML to trigger XML External Entity injection for=
local file disclosure and blind XXE or SSRF to arbitrary URLs reachable fr=
om the host. This issue is fixed in version 6.9.10. 2026-07-08 not yet calc= ulated CVE-2026-55471 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55471 ]=
harttle--liquidjs LiquidJS is a Shopify / GitHub Pages compatible template=
engine in pure JavaScript. Prior to 10.27.1, the pop array filter at src/f= ilters/array.ts allocated a full clone of its input array via [...toArray(v=
)] without calling this.context.memoryLimit.use(...), allowing a template r= ender such as {{ huge_array | pop }} to allocate an O(N) clone of an attack= er-influenced array outside the configured memoryLimit budget. This issue i=
s fixed in version 10.27.1. 2026-07-08 not yet calculated CVE-2026-55575 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-55575 ] hasura--graphql-engine = Hasura is an open-source product that provides users GraphQL or REST APIs. = Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table comput=
ed field (returning SETOF some_table) to infer row values that ought to be = filtered for their role based on some_table's row-level permissions. While = such rows cannot be returned directly, like predicates on strings for insta= nce allow values to be brute forced efficiently with the where clause as an=
oracle. This issue is fixed in versions 2.49.2 and 2.45.5. 2026-07-07 not = yet calculated CVE-2026-54698 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -54698 ] HMBRAND--DBI DBI versions before 1.650 for Perl are vulnerable to = code injection via caller-influenced Profile. When a string is assigned to =
a DBI handle's Profile attribute, DBI splits it into path, package and argu= ments, and interpolates the package part in a string eval with no validatio=
n of the package name. Any caller-influenced value that reaches the Profile=
attribute is therefore arbitrary Perl code execution, including calls to r=
un system commands. The Profile attribute can be set from three different s= ources that can carry untrusted data: the DBI_PROFILE environment variable,=
a direct attribute assignment, and a DSN driver-attribute clause dbi:Drive= r(Profile=3D>SPEC):db. An attacker controlling any of those inputs runs arb= itrary Perl in the host process. The strongest remote position is a network= -exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Pr= ofile attribute, letting a client execute code on the broker host. 2026-07-=
07 not yet calculated CVE-2026-14380 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-14380 ] HMBRAND--DBI DBI versions before 1.650 for Perl have a heap=
overflow when preparsing SQL statements with an extreme number of placehol= ders. The fix for CVE-2026-10879 did not allocate enough memory to handle a= pproximately 1.2-million placeholders. DBI version 1.650 sets a hard limit =
of 99,999 placeholders. 2026-07-07 not yet calculated CVE-2026-14739 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-14739 ] HMBRAND--DBI DBI versions b= efore 1.650 for Perl read one byte out-of-bounds in preparse when deleting =
an initial SQL comment. The preparse method normalises SQL and removes comm= ents. When the SQL starts with a comment line, the deletion of that line du= ring normalisation led to an out-of-bounds read by one byte. The result is =
a fault on memory-hardened builds and nondeterministic newline retention on=
normal builds. 2026-07-07 not yet calculated CVE-2026-14740 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-14740 ] HP Inc.--HP 2800 Printer Series A m= issing authorization vulnerability exists in the embedded webserver of HP D= eskjet 2800 Series Printers running firmware version <=3DTBP1CN2612AR. An u= nauthenticated attacker with network access can send GET requests to multip=
le exposed administrative API endpoints and retrieve sensitive configuratio=
n data such as plaintext Wi-Fi Direct credentials, unique device identity i= nformation, and other administrative security state details. When accessed = through the web interface, these setting pages explicitly require administr= ator credentials before sensitive information is displayed. 2026-07-06 not = yet calculated CVE-2026-13753 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -13753 ] HP Inc.--Poly CCX The IP phone might use malicious input stored in=
configuration parameters and render it as content for the WebUI's webpage.=
2026-07-08 not yet calculated CVE-2026-5922 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-5922 ] HP Inc.--Poly CCX Malicious use of a stolen cookie m= ight allow modifications to the contents of the IP phone's webpage. 2026-07= -08 not yet calculated CVE-2026-5923 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-5923 ] Imagination Technologies--Graphics DDK Software installed an=
d run as a non-privileged user may conduct improper GPU system calls to cau=
se an integer overflow and map two GPU virtual addresses to the same physic=
al address. One of these virutal mappings can be freed along with the physi= cal page, allowing for a read/write UAF via the second mapping The second v= irtual mapping references a physical address that has been freed after the = first virtual mapping has been freed. This allows the physical memory to be=
allocated (for example) by another process and read/written to. 2026-07-10=
not yet calculated CVE-2026-34196 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-34196 ] Imagination Technologies--Graphics DDK Software installed and=
run as a non-privileged user may cause OOB kernel memory reads or writes t= hrough GPU API calls. When indexing pages larger than 4kB in the page freei=
ng logic of the sparse memory implementation, incorrect buffer indexing lea=
ds to OOB access. 2026-07-10 not yet calculated CVE-2026-41154 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-41154 ] Imagination Technologies--Graphic=
s DDK Kernel software installed and running inside a Host VM may post impro= per commands to the GPU Firmware to trigger a GPU register access which can=
lead to privilege escalation. 2026-07-10 not yet calculated CVE-2026-45196=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-45196 ] Imagination Technolo= gies--Graphics DDK Kernel software installed and running inside a Host VM m=
ay post improper commands to the GPU Firmware to trigger a memory write out= side the permitted range of memory for the host kernel. A TOCTOU bug existe=
d where a malicious driver could modify values in memory after firmware val= idation but before use. 2026-07-10 not yet calculated CVE-2026-45203 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-45203 ] Imagination Technologies--G= raphics DDK Software installed and run as a non-privileged user may conduct=
a sequence of improper GPU system calls causing use after free, which help=
s in facilitating unprivileged memory access from a shader code. Triggering=
failure path in the MMU mapping logic by a malicious code could lead to in= complete cleanup of an internal driver state, allowing for future unauthori= zed access to the contents of the physical memory. 2026-07-10 not yet calcu= lated CVE-2026-7639 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7639 ] im= mutable-js--immutable-js Immutable.js provides many Persistent Immutable da=
ta structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn=
, List#updateIn, and the functional set, setIn, and updateIn mishandle an i= ndex or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.j=
s, causing an empty List to enter an uncatchable infinite loop, a populated=
List to allocate without bound until process abort, or setSize to silently=
wrap large values. This issue is fixed in versions 4.3.9 and 5.1.8. 2026-0= 7-08 not yet calculated CVE-2026-59879 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-59879 ] immutable-js--immutable-js Immutable.js provides many P= ersistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Ma=
p and Immutable.Set keep keys that share the same 32-bit hash in a HashColl= isionNode collision bucket that is scanned linearly, allowing an attacker w=
ho controls keys inserted into a Map, such as through Immutable.Map(obj), I= mmutable.fromJS(obj), state.merge(userObject), or mergeDeep, to craft many = colliding keys and degrade insertion and lookup to consume disproportionate=
CPU. This issue is fixed in versions 4.3.9 and 5.1.8. 2026-07-08 not yet c= alculated CVE-2026-59880 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5988=
0 ] Invixium--IXM WEB v.2.3.85.25 An issue in Invixium IXM WEB v.2.3.85.25 = allows an attacker to escalate privileges via the /SystemUsers/CreateAppUse=
r components 2026-07-10 not yet calculated CVE-2026-51119 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-51119 ] isaacs--node-tar node-tar is a tar arc= hive manipulation library for Node.js. Prior to 7.5.19, node-tar does not e= nforce hard upper bounds on total decompressed data, entry counts, or decom= pression ratio in extraction and parsing paths such as src/extract.ts, allo= wing a small crafted gzip bomb to exhaust disk space and CPU. This issue is=
fixed in version 7.5.19. 2026-07-08 not yet calculated CVE-2026-59873 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-59873 ] isaacs--node-tar node-tar=
is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.re= place accepts a checksum-valid tar header with a negative base-256 encoded = entry size, causing the archive scanner to make no progress while repeatedl=
y parsing the same header. This issue is fixed in version 7.5.18. 2026-07-0=
8 not yet calculated CVE-2026-59874 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-59874 ] jg-rp--liquid Python Liquid is a Python engine for the Liqui=
d template language. Prior to 2.2.1, given a malformed {% case %} tag witho=
ut an associated {% when %} or {% else %} block and no terminating {% endca=
se %} tag, Python Liquid hangs in an infinite loop at parse time because li= quid.TokenStream.eof did not give the EOF token matching kind and value fie= lds, allowing malicious template authors to craft templates for a denial of=
service attack. This issue is fixed in version 2.2.1. 2026-07-09 not yet c= alculated CVE-2026-55865 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5586=
5 ] Joomla! Project--Joomla! CMS An improper access check allows privileged=
users to overwrite media files without editing permissions. 2026-07-07 not=
yet calculated CVE-2026-48947 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-48947 ] Joomla! Project--Joomla! CMS An improper access check allows user=
to download vcard exports of com_contact contacts that are inaccessible. 2= 026-07-07 not yet calculated CVE-2026-48948 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-48948 ] Joomla! Project--Joomla! CMS Lack of validation lead=
s to an XSS vulnerability in the MFA management views. 2026-07-07 not yet c= alculated CVE-2026-48949 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4894=
9 ] Joomla! Project--Joomla! CMS Lack of escaping leads to an XSS vulnerabi= lity in the file management view of com_templates. 2026-07-07 not yet calcu= lated CVE-2026-48950 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48950 ] = Joomla! Project--Joomla! CMS Lack of escaping leads to XSS vulnerabilities =
in modalreturn layouts of various components. 2026-07-07 not yet calculated=
CVE-2026-48951 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48951 ] Jooml=
a! Project--Joomla! CMS Lack of escaping leads to an XSS vulnerability in t=
he update list view of com_installer. 2026-07-07 not yet calculated CVE-202= 6-48952 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48952 ] Joomla! Proje= ct--Joomla! CMS Lack of escaping leads to an XSS vulnerability in the gener=
ic image output layout. 2026-07-07 not yet calculated CVE-2026-48953 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-48953 ] Joomla! Project--Joomla! CM=
S Improper validation leads to a generic XSS vector in the language overrid=
e feature. 2026-07-07 not yet calculated CVE-2026-48954 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-48954 ] Joomla! Project--Joomla! CMS An improper=
access check allows unauthorized users to access workflow stage and transi= tion information. 2026-07-07 not yet calculated CVE-2026-48955 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-48955 ] Joomla! Project--Joomla! CMS An i= mproper access check allows users to display a list of modules in the front= end. 2026-07-07 not yet calculated CVE-2026-48956 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-48956 ] Joomla! Project--Joomla! CMS An improper acces=
s check allows unauthorized users to access com_privacy datasets. 2026-07-0=
7 not yet calculated CVE-2026-48957 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-48957 ] Joomla! Project--Joomla! CMS An improper access check allows=
unauthorized users to create custom fields via webservices endpoints. 2026= -07-07 not yet calculated CVE-2026-48958 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-48958 ] jupyterlab--jupyterlab-git JupyterLab Git is a Git exte= nsion for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts cre= ateHeader() method passes Git filenames directly to innerHTML when renderin=
g renamed files in commit history, allowing a crafted filename to execute J= avaScript when a victim views the rename diff in the Git History tab. This = issue is fixed in version 0.54.0. 2026-07-08 not yet calculated CVE-2026-54= 527 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54527 ] koodo-reader--koo= do-reader Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Ko= odo Reader is vulnerable to remote code execution through malicious EPUB fi= les because the open-book IPC handler enables nodeIntegrationInSubFrames an=
d EPUB chapter content is rendered with unsanitized innerHTML. An attacker = can craft an EPUB book that, when imported and opened by the victim, instan= tiates a hidden iframe with Node.js API access and executes arbitrary opera= ting system commands with the victim user's privileges. This issue is fixed=
in version 2.3.1. 2026-07-07 not yet calculated CVE-2026-55408 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-55408 ] kovidgoyal--calibre calibre is a=
n e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can e= xecute arbitrary Python code when its metadata is read by calibre, includin=
g through Add books or Edit books, by embedding a custom column definition = with a python: template in calibre:user_metadata that is passed unsanitized=
to exec() in the template formatter. This issue is fixed in version 9.10.0=
. 2026-07-07 not yet calculated CVE-2026-53511 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-53511 ] Kyocera--Command Center RX Unauthorized use of Ky= ocera printers, allows all information stored in the Kyocera address book t=
o be exported. The security measure that encrypts incoming data ian be bypa= ssed with this vulnerability, allowing encrypted data to be decrypted. Pass= words and other sensitive information can be obtained. This affects Kyocera=
Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKa= lfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 605= 2ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TA= SKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505. 2026-07-09 not yet calculated=
CVE-2025-63579 [
https://www.cve.org/CVERecord?id=3DCVE-2025-63579 ] Labce= nter--Proteus The application contains an out-of-bounds write vulnerability=
that can be exploited by an attacker to cause the program to write data pa=
st the end of an allocated memory buffer. This can lead to arbitrary code e= xecution. 2026-07-07 not yet calculated CVE-2026-42953 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-42953 ] labring--FastGPT FastGPT is a knowledge-b= ased AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getR= ecord authenticates the caller but loads LLM request and response traces on=
ly by requestId without team scoping, allowing any authenticated user to re=
ad another team's prompts, retrieved RAG chunks, and completions if the req= uestId is known. This issue is fixed in version 4.15.0. 2026-07-07 not yet = calculated CVE-2026-54602 [
https://www.cve.org/CVERecord?id=3DCVE-2026-546=
02 ] Lamaper--LTE Router V3.4.3 An issue in Generic OEM UZ801_v2.1 4G LTE R= outer V3.4.3 allows a remote attacker to execute arbitrary code via the /aj=
ax web management API endpoint in MifiService.apk 2026-07-08 not yet calcul= ated CVE-2026-52200 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52200 ] l= angroid--langroid Langroid is a framework for building large-language-model= -powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid=
` ships a `_validate_query` defense-in-depth layer whose `_DANGEROUS_SQL_PA= TTERNS` regex blocklist enumerates dangerous SQL primitives by specific fun= ction name. The list misses the canonical PostgreSQL filesystem-disclosure = family `pg_read_file()`, `pg_stat_file()`, `pg_ls_logdir()`, `pg_ls_waldir(= )`, `pg_current_logfile()` (and similar `SELECT`-shaped functions in the sa=
me family). It also leaves SQL Server `OPENDATASOURCE` and SQLite `ATTACH '= <file>' AS x` (DATABASE keyword omitted) unblocked. An attacker able to sha=
pe the LLM's generated SQL (directly via prompt input or transitively via p= rompt-injection in data the LLM ingests) can read arbitrary files from the = PostgreSQL host through ordinary `SELECT` queries, even with the agent's st= rict default configuration (`allow_dangerous_operations=3DFalse`, `allowed_= statement_types=3D['SELECT']`). The payloads survive the statement-type all= owlist (each is a `SELECT`) and pass through the regex blocklist (none of t=
he function names match), then reach the live SQLAlchemy engine via `SQLCha= tAgent.run_query`. Version 0.64.0 contains a patch for the issue. 2026-07-0=
9 not yet calculated CVE-2026-50180 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-50180 ] langroid--langroid Langroid is a framework for building larg= e-language-model-powered applications. Prior to version 0.65.1, the `SQLCha= tAgent` SQL-injection mitigation, with default `allow_dangerous_operations= =3DFalse`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) = with a `sqlglot` SELECT-only statement allowlist. The blocklist entries tha=
t target callable functions require the function name to be immediately fol= lowed by `\s*\(`. PostgreSQL accepts the same call with the name separated = from `(` by a quoted identifier, an inline comment, or schema qualification=
. These forms evade the regex, still parse as `SELECT`, and execute the sam=
e PostgreSQL function. This restores the `pg_read_file` server-side file-re=
ad primitive that the prior CVE-2026-25879 / GHSA-pmch-g965-grmr fix was me= ant to block: the parent advisory fixed a missing `pg_read_file` blocklist = entry, while this report shows that the added regex is bypassable. Version = 0.65.1 fixes the issue. 2026-07-09 not yet calculated CVE-2026-54760 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-54760 ] langroid--langroid Langroid=
is a framework for building large-language-model-powered applications. Pri=
or to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries st= raight to the Neo4j driver with no validation, no statement-type allowlist,=
and no opt-out gate. The query text is influenceable by prompt injection (= direct user input or indirect content the agent reads back via RAG), so an = attacker who can influence the prompt can read or destroy all graph data an=
d, when APOC or dbms.security procedures are enabled on the server, achieve=
OS-command and filesystem access. This is the same defect class and threat=
model as the SQLChatAgent prompt-to-SQL-to-RCE issue fixed in version 0.63=
.0 (CVE-2026-25879); that fix did not extend to the neo4j module. Version 0= .65.5 contains a fix for the neo4j module. 2026-07-09 not yet calculated CV= E-2026-55615 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55615 ] lepture-= -mistune Mistune is a Python Markdown parser with renderers and plugins. Pr= ior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py c= oncatenates the Admonition directive :class: option into the HTML class att= ribute without escaping, allowing attribute injection and cross-site script= ing even when HTMLRenderer escape mode is enabled. This issue is fixed in v= ersion 3.2.1. 2026-07-08 not yet calculated CVE-2026-59926 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-59926 ] Linux--Linux In the Linux kernel, the=
following vulnerability has been resolved: xfrm: iptfs: preserve shared-fr=
ag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fr= agments from one socket buffer to another but fails to propagate the SKBFL_= SHARED_FRAG flag. This is the same class of bug that was fixed in skb_try_c= oalesce() for CVE-2026-46300: when fragments backed by read-only page-cache=
pages are merged, the marker indicating their shared nature must be preser= ved so that ESP can decide correctly whether in-place encryption is safe. A= pply the same two-line fix used in skb_try_coalesce() to iptfs_consume_frag= s(). 2026-07-10 not yet calculated CVE-2026-53363 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-53363 ] LiquidFiles--LiquidFiles v4.2.7 An authenticat=
ed stored cross-site scripting (XSS) vulnerability in the Upload File Share=
s API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascrip=
t or HTML via injecting a crafted payload into the Name parameter. 2026-07-=
07 not yet calculated CVE-2026-36162 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-36162 ] LiquidFiles--LiquidFiles v4.2.7 An HTML injection vulnerabi= lity in the file view endpoint of LiquidFiles v4.2.7 allows authenticated a= ttackers to execute arbitrary JavaScript in the context of the victim's bro= wser via the uploading of and user interaction with a crafted HTML file. 20= 26-07-07 not yet calculated CVE-2026-36163 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-36163 ] M2Team--NanaZip NanaZip is the 7-Zip derivative inten= ded for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET = single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp s= izes its extraction buffer from the bundle entry Size field, which is only = checked for sign and is not validated against the real file size. A crafted=
bundle can cause an attacker-chosen allocation inside Extract, where std::= bad_alloc or std::length_error can escape across the COM STDMETHODCALLTYPE = boundary and crash the process. This issue is fixed in version 6.5.1749.0. = 2026-07-10 not yet calculated CVE-2026-55780 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-55780 ] M2Team--NanaZip NanaZip is the 7-Zip derivative int= ended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS=
and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the supe= rblock block size only against the MINBSIZE lower bound and does not valida=
te the fs_fsize fragment size, allowing attacker-controlled 32-bit fields t=
o flow into indirect-block, directory, and extraction buffer allocations. A=
tiny crafted UFS image can force multi-gigabyte allocations during open or=
extraction, causing memory exhaustion or process termination. This issue i=
s fixed in version 6.5.1749.0. 2026-07-10 not yet calculated CVE-2026-55781=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-55781 ] M2Team--NanaZip Nana= Zip is the 7-Zip derivative intended for the modern Windows experience. Pri=
or to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.A= rchive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit se= ction and custom-name length fields without validating them against the dat=
a present in the file. A tiny crafted module can force multi-gigabyte alloc= ations during listing or extraction through NameSize, Information.Size, and=
std::string or vector allocation paths, causing memory exhaustion or proce=
ss termination. This issue is fixed in version 6.5.1749.0. 2026-07-10 not y=
et calculated CVE-2026-55782 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 55782 ] M2Team--NanaZip NanaZip is the 7-Zip derivative intended for the mo= dern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-house IInA= rchive handlers in NanaZip.Codecs unconditionally dereference the caller-su= pplied Indices array inside Extract when the archive engine signals extract=
everything by passing Indices as NULL and NumItems as 0xFFFFFFFF. This cau= ses a NULL pointer dereference in the standard Test archive or Extract all = code path for WebAssembly, ElectronAsar, Zealfs, Romfs, Ufs, Littlefs, and = DotNetSingleFile archives, resulting in a process crash. This issue is fixe=
d in version 6.5.1749.0. 2026-07-10 not yet calculated CVE-2026-55783 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-55783 ] Mercury--MIPC252W IP Camer=
a MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implem= ent nonce expiration in RTSP Digest authentication. An adjacent network att= acker can capture a legitimate authentication exchange and replay the nonce=
and response values in a new connection to bypass authentication without k= nowledge of the device credentials, gaining unauthorized access to the live=
video stream. 2026-07-09 not yet calculated CVE-2026-51597 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-51597 ] Mercury--MIPC252W IP Camera An input=
validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera=
v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacen=
t attacker to cause a denial of service via a crafted DESCRIBE request with=
a malformed URL in the request line. 2026-07-09 not yet calculated CVE-202= 6-51598 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51598 ] Mercury--MIPC= 252W IP Camera An insufficient input validation vulnerability in the RTSP s= ervice of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthe= nticated remote attacker to render an individual TCP connection temporarily=
unusable via sending an RTSP request with a Content-Length header but no c= orresponding message body. The affected RTSP parser enters a body-waiting s= tate instead of rejecting the malformed request, causing all subsequent dat=
a on the connection to be silently consumed as body content until a server-= side timeout closes the connection. 2026-07-09 not yet calculated CVE-2026-= 51599 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51599 ] Mercusys--MW302= R/MW302R(EU) Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerabl=
e to Buffer Overflow in the administrative web interface. A stack buffer ov= erflow vulnerability in the administrative web interface allows an authenti= cated attacker with administrative privileges to trigger a system crash by = sending a specially crafted request. The vulnerability results in denial of=
service through control flow manipulation to an arbitrary instruction addr= ess. 2026-07-09 not yet calculated CVE-2026-31267 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-31267 ] MicroRealEstate--MicroRealEstate MicroRealEsta=
te allows adversaries to bypass authentication due to a lack of token state=
management. This would permit adversaries targeting MicroRealEstate deploy= ments to brute-force One-Time Passwords (OTP) to log in as any user. This i= ssue affects MicroRealEstate: through 1.0.0-alpha3. 2026-07-07 not yet calc= ulated CVE-2026-57867 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57867 ]=
MicroRealEstate--MicroRealEstate MicroRealEstate is affected by broken obj= ect-level access controls in PDF generator functionality. This issue affect=
s MicroRealEstate: through 1.0.0-alpha3. 2026-07-07 not yet calculated CVE-= 2026-57868 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57868 ] MicroRealE= state--MicroRealEstate Broken object-level access controls and the use of a=
deterministic pattern during random ID generation in MicroRealEstate allow=
s attackers to access documents uploaded by landlords or tenants without au= thorization. This issue affects MicroRealEstate: through 1.0.0-alpha3. 2026= -07-07 not yet calculated CVE-2026-57869 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-57869 ] MicroRealEstate--MicroRealEstate Broken object-level ac= cess control on the Template API in MicroRealEstate allows attackers to ret= rieve document templates used by other organizations without authorization.=
This issue affects MicroRealEstate: through 1.0.0-alpha3. 2026-07-07 not y=
et calculated CVE-2026-57870 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 57870 ] MicroRealEstate--MicroRealEstate Relative path traversal vulnerabil= ity in MicroRealEstate file upload functionality allows attackers to potent= ially overwrite system files. This issue affects MicroRealEstate: through 1= .0.0-alpha3. 2026-07-07 not yet calculated CVE-2026-57871 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-57871 ] misp--misp An authorization bypass in = MISP's EventsController::importModule() allowed authenticated users or read= -only API keys with event view access to persist data to events they were n=
ot allowed to modify. When an import module returned results in the misp_st= andard format, the write path did not verify event modification rights befo=
re saving the module output. This could allow a view-only user to inject or=
alter event data, impacting the integrity of MISP event content. The issue=
was fixed by enforcing the same modification-rights check used by related = module result handling paths before processing misp_standard imports. 2026-= 07-08 not yet calculated CVE-2026-60124 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-60124 ] misp--misp MISP's importModule() path used getEnabledMo= dule() to resolve a single import module by name, but this lookup did not e= nforce the per-organisation module restriction checked by getEnabledModules= (). As a result, an authenticated user from an organisation that was not al= lowed to use a module restricted via Plugin.Import_<module>_restrict could = still invoke that import module directly if they knew its name. This could = allow unauthorised access to restricted import-module functionality and, de= pending on the module and the user's event permissions, may allow unauthori= sed import or modification of event data through a module that should have = been unavailable to the user's organisation. 2026-07-08 not yet calculated = CVE-2026-60125 [
https://www.cve.org/CVERecord?id=3DCVE-2026-60125 ] misp--= misp An improper authorization check in MISP's attribute creation endpoint = allowed an authenticated user with permission to add attributes to submit a=
sharing_group_id without triggering the corresponding sharing group author= ization check, as long as the attribute distribution value was not explicit=
ly set to 4 - "sharing group". As a result, a user could reference or assoc= iate an attribute with a sharing group they were not authorized to use. Thi=
s could lead to an access-control bypass affecting the integrity of attribu=
te sharing metadata and potentially expose or misuse restricted sharing gro=
up relationships. The patch changes the authorization logic so that the sha= ring group permission check is performed whenever a non-empty sharing_group= _id is provided, regardless of the selected distribution value. 2026-07-09 = not yet calculated CVE-2026-61474 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-61474 ] misskey-dev--misskey Misskey is an open source, federated soci=
al media platform. Prior to 2026.6.0, Misskey contains a vulnerability in T= ime-based One-Time Password (TOTP) authentication in UserAuthService where = insufficient validation of used tokens allows the reuse of a single-use cod=
e within its valid time step. If both credentials and a TOTP code are obtai= ned concurrently, an attacker may reuse the code to perform unauthorized ac= tions, potentially leading to account takeover. This issue is fixed in vers= ion 2026.6.0. 2026-07-10 not yet calculated CVE-2026-57574 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-57574 ] misskey-dev--misskey Misskey is an op=
en source, federated social media platform. Prior to 2026.6.0, Misskey cont= ains a Server-Side Request Forgery (SSRF) vulnerability in URL preview func= tionality in UrlPreviewService. Due to missing network restrictions before = establishing outbound connections, a remote attacker can cause the Misskey = server to initiate HTTP requests to loopback, private, or link-local servic= es. Because IP address validation takes place after the request has been se=
nt and the process is subsequently rejected, no sensitive internal data is = believed to be transmitted back or exposed to the attacker. This issue is f= ixed in version 2026.6.0. 2026-07-10 not yet calculated CVE-2026-57575 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-57575 ] miurahr--py7zr py7zr is a=
Python-based library and utility to support 7zip archive compression, deco= mpression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decomp= ress() extracted archive entries without tracking total decompressed size, = allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 M=
B to exhaust disk or memory before extraction completes. This issue is fixe=
d in version 1.1.3. 2026-07-08 not yet calculated CVE-2026-55195 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-55195 ] miurahr--py7zr py7zr is a Pytho= n-based library and utility to support 7zip archive compression, decompress= ion, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archive= info.py used an O(n^2) cumulative sum pattern for attacker-controlled numst= reams values parsed from archive headers, allowing a crafted .7z archive to=
cause excessive CPU consumption during SevenZipFile.init() before extracti= on. This issue is fixed in version 1.1.3. 2026-07-08 not yet calculated CVE= -2026-55206 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55206 ] Mozilla--= Firefox for iOS A malicious webpage could interrupt a pending navigation by=
enqueuing a synchronous JavaScript dialog, causing the browser UI to displ=
ay the destination origin in the address bar while continuing to render att= acker-controlled content. This vulnerability was fixed in Firefox for iOS 1= 52.3. 2026-07-06 not yet calculated CVE-2026-13356 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-13356 ] mrubyc--mrubyc mrubyc through release3.4.1 wa=
s found to contain an out-of-bounds read in builtin missing-method lookup i= nside mrbc_find_method(). 2026-07-06 not yet calculated CVE-2026-38973 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-38973 ] mrubyc--mrubyc mrubyc thr= ough 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in o= p_super() / OP_SUPER due to a missing runtime guard for top-level super. 20= 26-07-06 not yet calculated CVE-2026-38976 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-38976 ] Mysterium--Mysterium Improper authorization in the /t= equilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unaut= henticated attackers to arbitrarily overwrite the node's configuration and = achieve a full node takeover via supplying a crafted POST request. 2026-07-=
08 not yet calculated CVE-2026-31309 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-31309 ] n8n--n8n n8n before 2.28.0 (and before 1.123.58 on the 1.x = branch) contains a disk space exhaustion vulnerability in the data-table fi=
le upload endpoint. The per-request quota check does not account for files = already written to the shared temporary directory, allowing an authenticate=
d user to repeatedly upload files that accumulate on disk until the periodi=
c cleanup runs, potentially exhausting available disk space on the host. 20= 26-07-10 not yet calculated CVE-2026-58661 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-58661 ] n8n--n8n n8n before 2.28.0 contains an improper autho= rization vulnerability allowing authenticated users to assign workflows to = folders in other projects. Attackers can bypass project and folder authoriz= ation boundaries by supplying crafted request payloads during workflow crea= tion, causing logical integrity violations in target project folder structu= res. 2026-07-08 not yet calculated CVE-2026-59253 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-59253 ] n8n--n8n n8n before 1.123.61, 2.x before 2.27.=
4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the l= egacy MySQL v1 node's executeQuery operation. The operation substitutes eva= luated {{ ... }} expression values directly into the raw SQL string without=
parameterization. When a workflow uses this operation with expression-sour= ced values and is connected to an externally-reachable trigger (such as a W= ebhook node), attacker-controlled input reaching those expressions results =
in SQL injection, allowing execution of arbitrary SQL with the configured M= ySQL credentials' privileges. The MySQL v2 node, which uses parameterized q= ueries, is not affected. 2026-07-08 not yet calculated CVE-2026-59257 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-59257 ] n8n-io--n8n n8n is an open=
source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.=
1, an authenticated user with the default workflow:create permission could = pollute Object.prototype through a crafted workflow saved, updated, or impo= rted via the workflow API, allowing unauthenticated requests to be treated =
as a privileged user and exposing user and project listing endpoints. This = issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1. 2026-07-09 not yet=
calculated CVE-2026-59206 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59= 206 ] n8n-io--n8n n8n is an open source workflow automation platform. Prior=
to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HT=
TP Request Domains restriction configured on credentials when an MCP tool w=
as pointed at an arbitrary URL, allowing a member-level user with use-only = access to a shared credential to send its secret to an external server they=
control. This issue is fixed in versions 2.27.4 and 2.28.1. 2026-07-09 not=
yet calculated CVE-2026-59207 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-59207 ] n8n-io--n8n n8n is an open source workflow automation platform. P= rior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured wi=
th more than one trusted token-exchange issuer resolved external identities=
to local accounts using only the JWT sub claim and ignored the iss claim, = allowing an attacker with a valid token from one trusted issuer and a sub m= atching a victim under another issuer to authenticate as that victim. This = issue is fixed in versions 2.27.4 and 2.28.1. 2026-07-09 not yet calculated=
CVE-2026-59208 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59208 ] n8n-i= o--n8n n8n is an open source workflow automation platform. Prior to 1.123.6=
1, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access=
to a shared workflow could read credential-populated headers exposed via t=
he $request object inside an HTTP Request node's pagination expression and = exfiltrate the secret through item data. This issue is fixed in versions 1.= 123.61, 2.27.4, and 2.28.1. 2026-07-09 not yet calculated CVE-2026-59209 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-59209 ] nats-io--nats-server NA=
TS Server is a high-performance server for NATS.io, the cloud and edge nati=
ve messaging system. Prior to 2.14.3 and 2.12.8, message trace destination = checks were applied to ordinary client connections but not consistently to = messages arriving through leafnode connections, allowing a leafnode operato=
r to send trace events to subjects that would not otherwise be permitted an=
d to use trace-only behavior to prevent normal delivery or storage of affec= ted messages. This issue is fixed in versions 2.14.3 and 2.12.8. 2026-07-08=
not yet calculated CVE-2026-58254 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-58254 ] nezhahq--nezha Nezha Monitoring is a self-hostable, lightweig= ht, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /= api/v1/ddns and GET /api/v1/notification endpoints return full resource obj= ects including plaintext third-party API credentials, including Cloudflare = API tokens, TencentCloud SecretKeys, Slack, Discord, and Telegram webhook U= RLs with embedded bot tokens, and Authorization header values, without any = field-level redaction. Any authenticated admin or PAT with nezha:ddns:read =
or nezha:notification:read scope can receive stored credentials through the=
listDDNS and listNotification handlers in a single API response. This issu=
e is fixed in version 2.2.5. 2026-07-10 not yet calculated CVE-2026-59155 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-59155 ] NT-ware--uniFLOW ULM (= Universal Login Manager) Standalone uniFLOW Universal Login Manager (ULM) S= tandalone contains an information disclosure vulnerability that may allow a=
n authenticated administrator to access sensitive configuration information=
through the ULM Remote User Interface (RUI). Exploitation requires adminis= trative privileges and may disclose configuration data associated with SMTP=
or LDAP integrations. ULM deployments connected to uniFLOW Server or uniFL=
OW Online are not affected. 2026-07-06 not yet calculated CVE-2026-1433 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-1433 ] Oneblog--Oneblog V2.3.9 A=
n issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive info= rmation via the RestApiController.java, JsApiTicketComponent.java, and the = GetAccessTokenComponent.java component 2026-07-07 not yet calculated CVE-20= 26-51937 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51937 ] OP-TEE--opte= e_os OP-TEE is a Trusted Execution Environment (TEE) designed as companion =
to a non-secure Linux kernel running on Arm; Cortex-A cores using the Trust= Zone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-= bit integer overflows in OP-TEE core's AES-GCM implementation cause the aut= hentication tag to be computed with incorrect bit-length values after proce= ssing more than 512 megabytes of payload or Additional Authenticated Data (= AAD). Version 4.11.0 contains a patch. No known workarounds are available. = 2026-07-06 not yet calculated CVE-2026-53763 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-53763 ] open-webui--open-webui Open WebUI is an extensible,=
feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before=
0.10.0, GET /api/v1/channels//members returned full UserModelResponse obje= cts for channel members, including settings.ui.toolServers[].key and webhoo=
k configuration, allowing a normal channel participant to retrieve other us= ers' sensitive settings. This issue is fixed in version 0.10.0. 2026-07-09 = not yet calculated CVE-2026-59222 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-59222 ] OpenAI--Codex desktop app for macOS The OpenAI Codex desktop a=
pp for macOS rendered remote images from Markdown in model responses. An at= tacker who could place an indirect prompt injection in content processed by=
Codex, such as a connected-tool result or another untrusted source, could = induce the model to construct a remote image URL containing sensitive data.=
The app automatically fetched that URL when rendering the response, sendin=
g the embedded data to an attacker-controlled server without a separate use=
r click. Successful exploitation could exfiltrate secrets and other informa= tion accessible in the Codex session, including API keys, source code, and = data returned by connected tools. No direct integrity or availability impac=
t was demonstrated, and there is no known exploitation in the wild. 2026-07= -06 not yet calculated CVE-2026-14898 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-14898 ] OpENer--OpENer 2.3.0 In OpENer 2.3.0 (commit 76b95cf), a r= esource exhaustion (Denial of Service) vulnerability exists in its network = processing loop. 2026-07-08 not yet calculated CVE-2026-51535 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-51535 ] openfga--openfga OpenFGA is an aut= horization/permission engine built for developers. Prior to 1.18.0, when My= SQL is being used as the datastore and authorization decisions rely on case= -sensitive user strings, the tuple, changelog, and authorization_model iden= tifier columns can compare case-distinct values such as user:Alice and user= :alice as equivalent, causing two distinct check requests to return the sam=
e response. This issue is fixed in 1.18.0. 2026-07-09 not yet calculated CV= E-2026-55170 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55170 ] openrepl= ay--openreplay OpenReplay is a self-hosted session replay suite. From 1.22.=
0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs = for a session's DOM-replay recording based solely on the session path param= eter, while validateProjectAccess checked only that the project belonged to=
the requester's tenant and did not verify that the session belonged to tha=
t project, allowing any authenticated low-privilege user to read another te= nant's first 15 seconds of session-replay recording data. This issue is fix=
ed in version 1.27.0. 2026-07-10 not yet calculated CVE-2026-55881 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-55881 ] OpenVPN--Access Server OpenVP=
N Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside=
HTTP header values, allowing remote attackers to perform HTTP request smug= gling when deployed behind a reverse proxy 2026-07-08 not yet calculated CV= E-2025-3110 [
https://www.cve.org/CVERecord?id=3DCVE-2025-3110 ] OpenVPN--O= penVPN A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through=
2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid t= ls-crypt-v2 client key to potentially cause a denial of service 2026-07-06 = not yet calculated CVE-2026-13698 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-13698 ] Openvpn--OpenVPN OpenVPN version 2.6.0 through 2.6.20 and 2.7_= alpha1 through 2.7.4 allows remote attackers to cause a denial of service v=
ia a malformed authentication token that triggers a reachable assertion whe=
n external-auth is enabled 2026-07-06 not yet calculated CVE-2026-13122 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-13122 ] osquery--osquery osquery=
is a SQL powered operating system instrumentation, monitoring, and analyti=
cs framework. Prior to 5.23.1, on Windows, a local unprivileged attacker ca=
n cause a heap buffer out-of-bounds write if there is a query of the proces= ses table targeting a maliciously crafted process, due to unchecked PEB str= ing lengths in process command-line and current-directory reads. If exploit=
ed successfully, this could allow a potential local privilege escalation fr=
om standard user to SYSTEM. This issue is fixed in version 5.23.1. 2026-07-=
10 not yet calculated CVE-2026-54000 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-54000 ] osquery--osquery osquery is a SQL powered operating system = instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on W= indows, a local unprivileged attacker can cause a heap buffer out-of-bounds=
write if there is a query of the authenticode table targeting a maliciousl=
y crafted binary, due to publisher information parsing in getOriginalProgra= mName. If exploited successfully, this could allow a potential local privil= ege escalation from standard user to SYSTEM. This issue is fixed in version=
5.23.1. 2026-07-10 not yet calculated CVE-2026-54001 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-54001 ] Palo Alto Networks--Cloud NGFW Multiple cr= oss site scripting vulnerabilities in the User-ID=C3=A2=E2=80=9E=C2=A2 Auth= entication Portal (aka Captive Portal) service, GlobalProtect=C3=A2=E2=80= =9E=C2=A2 gateway/portal features and Clientless VPN of Palo Alto Networks = PAN-OS=C3=82=C2=AE software enables a malicious unauthenticated user to sto=
re or execute malicious JavaScript payload. The security risk posed by this=
issue is minimized when the management interface and access to the User-ID= =C3=A2=E2=80=9E=C2=A2 Authentication Portal is restricted to only trusted i= nternal IP addresses according to our recommended best practice deployment = guidelines
https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tr= icks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This is= sue is applicable to PAN-OS software on PA-Series and VM-Series firewalls a=
nd on Panorama (virtual and M-Series). Cloud NGFW is not affected by this v= ulnerability. 2026-07-09 not yet calculated CVE-2026-0279 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-0279 ] Palo Alto Networks--Cloud NGFW An IPv6 = packet processing vulnerability in the dataplane of Palo Alto Networks PAN-= OS=C3=82=C2=AE software enables an unauthenticated attacker to bypass firew= all security policy enforcement, allowing network traffic that should be bl= ocked to reach protected services. Cloud NGFW and Panorama are not impacted=
by this vulnerability. 2026-07-09 not yet calculated CVE-2026-0280 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-0280 ] Palo Alto Networks--Cloud NGF=
W An information disclosure vulnerability in Palo Alto Networks PAN-OS=C3= =82=C2=AE software enables an unauthenticated attacker with network access =
to the management web interface to obtain web session tokens. This requires=
a legitimate user to first click on a malicious link provided by the attac= ker. The security risk posed by this issue is minimized by restricting acce=
ss to the management web interface to only trusted internal IP addresses ac= cording to our recommended best practice deployment guidelines
https://live= .paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-= management-access-of-your-palo/ba-p/464431 . This issue is applicable to PA= N-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual=
and M-Series). Cloud NGFW and Prisma=C3=82=C2=AE Access are not impacted b=
y this vulnerability. 2026-07-09 not yet calculated CVE-2026-0281 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-0281 ] Palo Alto Networks--Cloud NGFW =
A file deletion vulnerability in Palo Alto Networks PAN-OS=C3=82=C2=AE soft= ware enables an unauthenticated attacker with network access to the managem= ent web interface to delete files from a temporary directory. The security = risk posed by this issue is minimized by restricting access to the manageme=
nt web interface to only trusted internal IP addresses according to our rec= ommended best practice deployment guidelines
https://live.paloaltonetworks.= com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-= of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on P= A-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cl= oud NGFW and Prisma=C3=82=C2=AE Access are not impacted by this vulnerabili= ty. 2026-07-09 not yet calculated CVE-2026-0282 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-0282 ] Palo Alto Networks--Cloud NGFW An authentication = bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto=
Networks PAN-OS software allows an attacker with network access to bypass = security restrictions and establish an unauthorized site-to-site VPN connec= tion. Panorama, Cloud NGFW, and Prisma=C3=82=C2=AE Access are not impacted =
by this vulnerability. 2026-07-09 not yet calculated CVE-2026-0283 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-0283 ] Palo Alto Networks--Cloud NGFW=
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionalit=
y of Palo Alto Networks PAN-OS=C3=82=C2=AE software enables an unauthentica= ted attacker with network access to inject malicious XML content, potential=
ly leading to information disclosure or corruption of internal LSVPN satell= ite data. Panorama, Cloud NGFW, and Prisma=C3=82=C2=AE Access are not impac= ted by this vulnerability. 2026-07-09 not yet calculated CVE-2026-0284 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-0284 ] Palo Alto Networks--Cloud = NGFW A server-side request forgery (SSRF) vulnerability in Palo Alto Networ=
ks PAN-OS software enables an authenticated administrator with network acce=
ss to the management web interface to make unauthorized requests from the f= irewall to internal services. The security risk posed by this issue is mini= mized when the management interface is restricted to only trusted internal =
IP addresses according to our recommended=C2=A0 best practice deployment gu= idelines
https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tric= ks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .=C2=A0 Pan= orama, Cloud NGFW, and Prisma=C3=82=C2=AE Access are not impacted by this v= ulnerability. 2026-07-09 not yet calculated CVE-2026-0285 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-0285 ] Palo Alto Networks--Cloud NGFW A comman=
d injection vulnerability in the management plane of Palo Alto Networks PAN= -OS=C3=82=C2=AE software enables an authenticated administrator to execute = arbitrary OS commands as root. The security risk posed by this issue is sig= nificantly minimized when CLI access is restricted to a limited group of ad= ministrators. This issue is applicable to PAN-OS software on PA-Series and = VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and = Prisma Access=C3=82=C2=AE are not impacted by this vulnerability. 2026-07-0=
9 not yet calculated CVE-2026-0286 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-0286 ] Palo Alto Networks--Cloud NGFW Multiple denial of service vuln= erabilities in Palo Alto Networks PAN-OS=C3=82=C2=AE software allow an unau= thenticated attacker with network access to cause a denial of service (DoS)=
condition by sending specially crafted network traffic to or through a dat= aplane interface. Repeated attempts to trigger this condition result in the=
firewall entering maintenance mode. Panorama is not impacted by these vuln= erabilities. 2026-07-09 not yet calculated CVE-2026-0287 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-0287 ] Palo Alto Networks--Cloud NGFW Multiple = buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) = component of Palo Alto Networks PAN-OS software allow an unauthenticated at= tacker with network access to cause a denial of service (DoS) condition or = potentially execute arbitrary code by sending specially crafted network tra= ffic. The security risk posed by this issue is minimized when the User-ID T= erminal Server Agent connectivity is restricted to only trusted internal IP=
addresses according to our recommended best practice deployment guidelines=
https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identification/devic= e-user-identification-terminal-services-agents#:~:text=3DTo%20minimize%20se= curity%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%20trusted%20in= ternal%20IP%20addresses%20only. . Panorama is not impacted by this vulnerab= ility. 2026-07-08 not yet calculated CVE-2026-0288 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-0288 ] Palo Alto Networks--Cortex XDR Broker VM A pri= vilege escalation vulnerability in Palo Alto Networks Cortex=C3=82=C2=AE XD=
R Broker VM enables a locally authenticated user to perform actions as the = root user. 2026-07-09 not yet calculated CVE-2026-0276 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-0276 ] Palo Alto Networks--Prisma Access Agent An=
improper certificate validation vulnerability in the Prisma=C3=82=C2=AE Ac= cess Agent for iOS enables an attacker to perform a man-in-the-middle (MitM=
) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macO=
S, Linux, Android and ChromeOS are not affected. 2026-07-09 not yet calcula= ted CVE-2026-0277 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0277 ] Palo=
Alto Networks--Prisma Access Agent Multiple protection mechanism failures =
in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows=
allow a local user to bypass DLP policy enforcement controls. The Prisma A= ccess Agent on macOS is not affected. 2026-07-09 not yet calculated CVE-202= 6-0278 [
https://www.cve.org/CVERecord?id=3DCVE-2026-0278 ] Palo Alto Netwo= rks--Prisma Browser A local privilege escalation vulnerability in Palo Alto=
Networks Prisma=C3=82=C2=AE Browser allows a locally authenticated adminis= trator with access to the macOS local filesystem to perform actions on the = device with root privileges. This issue only affects Prisma=C3=82=C2=AE Bro= wser on macOS. 2026-07-09 not yet calculated CVE-2026-0275 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-0275 ] parse-community--parse-server Parse Se= rver is an open source backend that can be deployed to any infrastructure t= hat can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUp= load.fileExtensions blocklist could be bypassed by uploading a file with a = non-standard or compound extension and dangerous content type, allowing sto= rage adapters such as S3 and GCS to serve attacker-supplied active content = and enable stored cross-site scripting. This issue is fixed in versions 9.9= .1-alpha.11 and 8.6.81. 2026-07-08 not yet calculated CVE-2026-55778 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-55778 ] parse-community--parse-serv=
er Parse Server is an open source backend that can be deployed to any infra= structure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply = nested $or, $and, and $nor query condition operators in the REST API or Liv= eQuery query handling could trigger exponential-time processing in the inte= rnal query-traversal helper and block the Node.js event loop. This issue is=
fixed in versions 9.9.1-alpha.12 and 8.6.82. 2026-07-08 not yet calculated=
CVE-2026-57480 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57480 ] parse= -community--parse-server Parse Server is an open source backend that can be=
deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.=
13 and 8.6.83, a LiveQuery subscriber could receive object field values the=
y were not authorized to read when a single save changed both an object fie=
ld and the subscriber's ACL read access, because leave and enter events inc= luded the wrong object state. This issue is fixed in versions 9.9.1-alpha.1=
3 and 8.6.83. 2026-07-08 not yet calculated CVE-2026-57481 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-57481 ] parse-community--parse-server Parse S= erver is affected by a stored cross-site scripting (XSS) vulnerability in v= ersions >=3D 9.0.0, < 9.10.0-alpha.2 and <=3D 8.6.83. When an uploaded file=
's extension is not recognized by the mime package, Parse Server preserves = the client-supplied Content-Type. A malformed Content-Type that is not a va= lid type/subtype media type (e.g., 'image', 'image/', or 'image//svg+xml') = bypasses the fileUpload.fileExtensions blocklist and is stored unchanged. O=
n storage adapters that persist and serve the uploaded Content-Type (such a=
s Amazon S3, Google Cloud Storage, or Azure Blob Storage), a browser cannot=
parse the malformed value and falls back to MIME-sniffing; a file whose bo=
dy begins with HTML is rendered as HTML, executing embedded script in the a= pplication's origin against other users who open the file URL. The default = GridFS storage adapter is not affected. Fixed in 9.10.0-alpha.2 and 8.6.84.=
2026-07-11 not yet calculated CVE-2026-61448 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-61448 ] PayRange--PayRange When coupled with the SSL bypas=
s vulnerability, JavaScript can be injected into a WebView in the PayRange = version 7.0.7 app. The injection of specific JavaScript function calls allo=
ws the attacker to escape the WebView sandbox and perform a number of dange= rous actions on the user's device. 2026-07-09 not yet calculated CVE-2026-1= 3461 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13461 ] PayRange--PayRan=
ge PayRange Android app, version 7.0.7 and below, contains an SSL bypass vu= lnerability that allows invalid certificates to be accepted in application = webviews. A remote and unauthenticated attacker can steal information that = the user sends. 2026-07-09 not yet calculated CVE-2026-13462 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-13462 ] PETDANCE--App::Ack App::Ack version=
s through 3.10.0 for Perl read arbitrary files via --files-from in a projec=
t .ackrc. ack searches up the directory hierarchy from the current director=
y for a project .ackrc and loads its options. The project-source option blo= cklist in App::Ack::ConfigLoader does not include --files-from, so a projec=
t .ackrc can set it to a path whose listed files ack then reads and searche=
s. Version 3.10.0 added --follow to the blocklist; --files-from remains acc= epted. A project .ackrc committed to an untrusted repository can make ack r= ead files outside the project and print their matching lines. 2026-07-08 no=
t yet calculated CVE-2026-49145 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-49145 ] PETDANCE--App::Ack App::Ack versions before 3.10.0 for Perl allo=
w memory exhaustion via an unbounded context value in a project .ackrc. ack=
searches up the directory hierarchy from the current directory for a proje=
ct .ackrc and loads its options. The -B and -C context options accepted any=
positive integer, and ack sized the before-context buffer to that value, s=
o a project .ackrc setting --before-context=3D100000000 made ack allocate a=
buffer of 100 million elements. A project .ackrc committed to an untrusted=
repository can abort ack with an out-of-memory condition. 2026-07-08 not y=
et calculated CVE-2026-49146 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 49146 ] PETDANCE--App::Ack App::Ack versions through 3.10.0 for Perl print = unsanitised terminal escape sequences from filenames in several output mode=
s. When ack prints a filename whose basename contains terminal control byte=
s such as ANSI escape sequences, those bytes reach the terminal unchanged. = Version 3.10.0 added a _safe_filename helper that sanitises the filenames p= rinted by -f, -g, the colored match heading, and per-match lines, but the -= -show-types, -l/-L, and -c paths still emit the raw filename. A file whose = name embeds cursor-movement or color escapes can overwrite or recolor earli=
er terminal output, or be passed unchanged to a downstream consumer. 2026-0= 7-08 not yet calculated CVE-2026-49147 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-49147 ] pgjdbc--pgjdbc pgjdbc is an open source postgresql JDBC=
Driver. In releases 42.7.4 through 42.7.11, channelBinding=3Drequire conne= ctions can be silently downgraded from SCRAM-SHA-256-PLUS with channel bind= ing to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protect= ion the setting is meant to guarantee. An attacker who can intercept the TL=
S connection can trigger the downgrade with a certificate whose signature a= lgorithm has no tls-server-end-point channel-binding hash, because the bund= led com.ongres.scram:scram-client returns an empty byte array instead of fa= iling and pgJDBC ScramAuthenticator checks only that the server advertised =
a PLUS mechanism, without rejecting the empty binding or checking that the = negotiated mechanism uses channel binding. This issue is fixed in version 4= 2.7.12. 2026-07-06 not yet calculated CVE-2026-54291 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-54291 ] phalcon--cphalcon Phalcon is a high-perform= ance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::= decrypt compares the attacker-supplied HMAC tag against the freshly compute=
d HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise co= mparison that returns early on the first differing byte. This observable ti= ming discrepancy can allow an attacker to recover a valid tag byte-by-byte = and attach it to a chosen IV and ciphertext so that decrypt() accepts tampe= red encrypted content as authentic. This issue is fixed in version 5.14.1. = 2026-07-10 not yet calculated CVE-2026-54736 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-54736 ] phalcon--cphalcon Phalcon is a high-performance, fu= ll-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application buil=
t with a default router registers a built-in route whose compiled PCRE patt= ern contains the nested quantifier (/.), and the same construct is produced=
by the /:params placeholder and the CLI router. Phalcon\Mvc\Router::handle=
() matches this pattern against the attacker-controlled request URI on ever=
y request, so a crafted path such as one containing repeated slashes follow=
ed by decoded newlines can trigger catastrophic backtracking and cause CPU = exhaustion or route-matching failure. This issue is fixed in version 5.15.0=
. 2026-07-10 not yet calculated CVE-2026-57584 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-57584 ] phoca.cz--phoca.cz Phoca Download extension for J= oomla The Joomla extension Phoca Downloads is vulnerable to an authenticate=
d arbitrary file upload that allows registered users uploading executable f= iles and leads to full RCE. 2026-07-11 not yet calculated CVE-2026-57828 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-57828 ] phoenixframework--phoen=
ix Allocation of Resources Without Limits or Throttling vulnerability in ph= oenixframework phoenix (Phoenix.Socket module) allows an unauthenticated at= tacker to cause a denial of service against any endpoint that mounts a Phoe= nix socket with a reachable channel transport (WebSocket or LongPoll). This=
vulnerability is associated with program files lib/phoenix/socket.ex and p= rogram routine 'Elixir.Phoenix.Socket':handle_in/4. Phoenix transports do n=
ot limit the number of channels that a single transport process may join. E= very phx_join message a client sends over one connection starts a persisten=
t channel process, and the socket process accepts an unbounded number of th= em. A single unauthenticated client can therefore open one WebSocket or Lon= gPoll connection and stream a large number of phx_join messages, spawning h= undreds of thousands of channel processes over that one connection and even= tually reaching the BEAM maximum process limit. Once the process table is e= xhausted the virtual machine can no longer start new processes, denying ser= vice to legitimate traffic across the whole node. Because the amplification=
happens inside a single connection, network-layer connection caps and rate=
limiting do not mitigate it. The fix adds a :max_channels_per_transport op= tion (default 100) that bounds the number of channels a single transport pr= ocess can join, forcing abusive clients to open many connections instead, w= here external load balancers and reverse proxies can throttle them. This is= sue affects phoenix: from 0.11.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.= 17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9. 2026-0= 7-07 not yet calculated CVE-2026-56811 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56811 ] phoenixframework--phoenix Improper Check for Unusual or=
Exceptional Conditions vulnerability in phoenixframework phoenix (Presence=
JavaScript client) allows an attacker with ordinary channel access to caus=
e a persistent client-side denial of service against every viewer of a pres= ence channel topic. This vulnerability is associated with program files ass= ets/js/phoenix/presence.js and program routines Presence.syncState and Pres= ence.syncDiff. The Phoenix JavaScript presence client checks whether a pres= ence already exists with a bare truthiness test (state[key]) instead of an = own-property check. Presence keys can be attacker-controlled, because appli= cations track presences under a username or id supplied by the client. A us=
er who joins a channel choosing a key that is an Object.prototype member na=
me (__proto__, constructor, toString, hasOwnProperty, and similar) makes th=
at lookup return JavaScript's built-in Object.prototype instead of undefine=
d. Because the prototype is truthy, the code treats it as an existing prese= nce and reads .metas.map(...) off it, which throws an uncaught TypeError. T=
he exception propagates out of the presence message handler, so the local s= tate is never updated and onSync() never fires. Because the malicious key i=
s tracked on the server, it is re-pushed on every presence update and keeps=
re-throwing, so presence sync stays broken for every viewer of that channe=
l topic until the attacker leaves. Both syncState and syncDiff use the same=
unsafe existence-check pattern. The impact is limited to the affected topi=
c and is a read-time confusion of the prototype object, not a mutation of O= bject.prototype (it is not prototype pollution). This issue affects phoenix=
: from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-= rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9. 2026-07-07 not yet ca= lculated CVE-2026-56812 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56812=
] portainer--portainer Portainer Community Edition is a lightweight servic=
e delivery platform for containerized applications that can be used to mana=
ge Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 throu=
gh 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrato=
r initialization endpoints (/api/restore and /api/users/admin/init) remain = accessible during the five-minute setup window for uninitialized instances,=
allowing a network attacker to restore a crafted backup or create the firs=
t administrator account and gain full administrative access. This issue is = fixed in versions 2.39.4 and 2.43.0. 2026-07-08 not yet calculated CVE-2026= -55761 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55761 ] Proximus--b-bo=
x v8c.725A Incorrect access control in Proximus b-box v8c.725A allows authe= nticated attackers to bypass normal restrictions and make arbitrary changes=
to port forwarding rules. 2026-07-09 not yet calculated CVE-2025-45422 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2025-45422 ] py-pdf--pypdf pypdf is a=
free and open-source pure-python PDF library. Prior to 6.14.2, an attacker=
can craft a PDF with a page content stream containing a not terminated inl= ine image that uses the ASCII85 or ASCIIHex filters, causing an infinite lo=
op during parsing such as when extracting page text. This issue is fixed in=
version 6.14.2. 2026-07-08 not yet calculated CVE-2026-59935 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-59935 ] py-pdf--pypdf pypdf is a free and = open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft=
a PDF with a page content stream containing a not terminated inline image,=
causing an infinite loop during inline image end marker detection such as = when extracting page text. This issue is fixed in version 6.14.1. 2026-07-0=
8 not yet calculated CVE-2026-59936 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-59936 ] py-pdf--pypdf pypdf is a free and open-source pure-python PD=
F library. Prior to 6.14.0, an attacker can craft a PDF with repeated malfo= rmed cross-reference streams that cause pypdf to spend long runtimes recove= ring broken cross-reference table entries. This issue is fixed in version 6= .14.0. 2026-07-08 not yet calculated CVE-2026-59937 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-59937 ] py-pdf--pypdf pypdf is a free and open-sourc=
e pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF wit=
h declared image size values that are much too large compared to the actual=
data, causing large memory usage in pypdf image parsing. This issue is fix=
ed in version 6.14.0. 2026-07-08 not yet calculated CVE-2026-59938 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-59938 ] Python Software Foundation--C= Python The incremental HTML parser (html.parser.HTMLParser) allows for CPU = denial-of-service through repeated unterminated markup declarations when pr= ocessing uncontrolled data. 2026-07-09 not yet calculated CVE-2026-15308 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-15308 ] qax-os--excelize Exceli=
ze is a Go language library for reading and writing Microsoft Excel spreads= heets. Prior to 2.11.0, the streaming worksheet reader used by Rows and Get= Rows does not enforce the TotalRows limit on the row r attribute, allowing =
a small XLSX file with a row number above 1048576 and no cell coordinate to=
make GetRows append empty rows up to the attacker-controlled index and con= sume excessive memory and CPU. This issue is fixed in version 2.11.0. 2026-= 07-10 not yet calculated CVE-2026-59161 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-59161 ] qax-os--excelize Excelize is a Go language library for = reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize=
parses shared-string cell values with strconv.Atoi and checks only the upp=
er bound before indexing the shared string slice, allowing an XLSX file con= taining a shared-string cell with -1 to trigger sharedStrings[-1] and panic=
when read through GetCellValue or GetRows. This issue is fixed in version = 2.11.0. 2026-07-10 not yet calculated CVE-2026-59162 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-59162 ] Qt--Axivion The implementation of an intern= al=C2=A0and=C2=A0undocumented=C2=A0Dashboard=C2=A0API endpoint=C2=A0(POST /= api/users/~/{user}/tokens)=C2=A0forgot=C2=A0to ensure an HTTP=C2=A0request = for creating an=C2=A0API=C2=A0Token for another=C2=A0user had sufficient pe= rmission to do so. Precondition for successful exploitation was a preexisti=
ng internal user (with more privileges than the attacker),=C2=A0the attacke=
r knowing=C2=A0its login name and the attacker being able to authenticate t=
o the Dashboard via OAuth/OIDC. The attacker=C2=A0would then have=C2=A0had= =C2=A0to forge a token creation=C2=A0API=C2=A0request=C2=A0on behalf of the= =C2=A0other user and could have authenticated=C2=A0and=C2=A0finalized=C2=A0= the token creation=C2=A0with their own=C2=A0OAuth/OIDC=C2=A0credentials. In=
the worst case, this would mean an attacker could=C2=A0have=C2=A0become Da= shboard Administrator=C2=A0and=C2=A0been=C2=A0able to=C2=A0perform=C2=A0all= =C2=A0administrative actions=C2=A0if the preexisting internal user had admi= nistrative=C2=A0privileges.=C2=A0In combination with a separate weakness,= =C2=A0this could have=C2=A0further=C2=A0led=C2=A0to code execution on the= =C2=A0host=C2=A0system running the Dashboard with the privileges of the OS-= User running the Dashboard=C2=A0server. 2026-07-09 not yet calculated CVE-2= 026-12593 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12593 ] R-SOFT SERW= IS--DMS R-SOFT DMS is vulnerable to=C2=A0OS Command Injection in konwertujA= ction() function.=C2=A0The document converter executes shell commands using=
unsanitized file paths and format parameters.=C2=A0This allows an authenti= cated attacker to execute arbitrary system commands with the privileges of = the web server user. This issue was fixed in version=C2=A0v3.19-2752 and v3= .17-2580. 2026-07-10 not yet calculated CVE-2026-41876 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-41876 ] R-SOFT SERWIS--DMS R-SOFT DMS is vulnerab=
le to Stored XSS in file upload functionality. Authenticated attacker can i= nject arbitrary HTML and JS into the name=C2=A0of the file being uploaded, = which will be executed when visiting file list or upload status by other us= ers. This issue was fixed in version v3.19-2832=C2=A0and v3.17-2580. 2026-0= 7-10 not yet calculated CVE-2026-41877 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-41877 ] R-SOFT SERWIS--DMS R-SOFT DMS is vulnerable to=C2=A0Ins= ecure Direct Object Reference (IDOR) attack in multiple file download endpo= ints. The application fetches files from the database by ID and serves them=
to whoever requests them, relying only on session authentication, meaning = any valid user can access any file. This issue was fixed in version v3.19-2= 862=C2=A0and v3.17-2580. 2026-07-10 not yet calculated CVE-2026-41878 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-41878 ] R-SOFT SERWIS--DMS R-SOFT = DMS=C2=A0stores superadmin credentials using a non-salted nested MD5 hash. = This allows an attacker who obtain password hash to decode superadmin crede= ntials. Critically, this password cannot be changed=C2=A0except by modifyin=
g the configuration file. This issue was fixed in version=C2=A0v3.17-2000. = 2026-07-10 not yet calculated CVE-2026-41879 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-41879 ] R-SOFT SERWIS--DMS R-SOFT DMS is vulnerable to=C2= =A0OS Command Injection in the Optical Character Recognition (OCR) module. = Multiple command execution functions accept user-controllable file paths wi= thout proper sanitization before passing them to the system shell via SSH. =
In current infrastructure the URL encoding neutralizes the injection during=
the standard web upload flow. An authenticated attacker who=C2=A0is able t=
o trigger the OCR functionality for the uploaded file can execute OS comman=
ds within the context of a root user. This issue was fixed in version=C2=A0= v3.19-2862=C2=A0and v3.17-2580. 2026-07-10 not yet calculated CVE-2026-4188=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-41880 ] rabbitmq--rabbitmq-= server RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.= 19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized v= alid JSON bodies on with_decode and direct_request paths because read_compl= ete_body checks the accumulated size before the final chunk but not the fin=
al combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, = and 4.2.5. 2026-07-10 not yet calculated CVE-2026-57212 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-57212 ] rabbitmq--rabbitmq-server RabbitMQ is a = messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5=
, the rabbitmq_federation_management plugin renders the consumer_tag field =
on the Federation Status page without HTML escaping, allowing a user who ca=
n configure a federation upstream or policy to execute JavaScript in the br= owser of a user viewing that page. This issue is fixed in versions 3.13.14,=
4.0.19, 4.1.10, and 4.2.5. 2026-07-10 not yet calculated CVE-2026-57213 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-57213 ] rabbitmq--rabbitmq-serv=
er RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the Rabbit=
MQ management UI renders the x-internal-purpose queue or exchange argument = into an HTML title attribute without proper escaping on the Queues and Exch= anges pages, allowing a user with permission to declare a queue or exchange=
to execute JavaScript in another user's browser. This issue is fixed in ve= rsion 4.2.5. 2026-07-10 not yet calculated CVE-2026-57214 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-57214 ] rabbitmq--rabbitmq-server RabbitMQ is =
a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2= .6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations = because volatile direct-reply-to queues can be accepted at bind and route t= ime but are missing from Khepri-backed deletion checks, leaving persistent = route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20=
, 4.1.11, and 4.2.6. 2026-07-10 not yet calculated CVE-2026-57215 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-57215 ] rabbitmq--rabbitmq-server Rabb= itMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11,=
and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes = and binds during metadata-store failures because topic-permission lookup er= rors from Khepri can collapse to undefined, which the internal backend trea=
ts as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4= .2.6. 2026-07-10 not yet calculated CVE-2026-57217 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-57217 ] rabbitmq--rabbitmq-server RabbitMQ is a messa= ging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an ex= isting consumer to keep receiving messages after OAuth token expiry or conn= ection.update_secret refresh to reduced scopes because existing consumers a=
re not canceled or reauthorized at delivery time after the channel user sta=
te changes. This issue is fixed in version 4.2.6. 2026-07-10 not yet calcul= ated CVE-2026-57218 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57218 ] r= abbitmq--rabbitmq-server RabbitMQ is a messaging and streaming broker. Prio=
r to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoin=
t can disclose the OAuth 2 client secret on RabbitMQ installations configur=
ed with management.oauth_client_secret, exposing credentials to unauthentic= ated callers when the management plugin and that OAuth configuration are en= abled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6. = 2026-07-10 not yet calculated CVE-2026-57219 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-57219 ] rabbitmq--rabbitmq-server RabbitMQ is a messaging a=
nd streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ = does not perform authorization checks on passive queue.declare and exchange= .declare AMQP 0-9-1 operations, allowing any authenticated user who can con= nect to a virtual host to enumerate queue and exchange names and read queue=
message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.= 20, 4.1.11, and 4.2.6. 2026-07-10 not yet calculated CVE-2026-57221 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-57221 ] Raspberry Pi--Raspberry Pi 5=
and Compute Module 5 EEPROM firmware on Raspberry Pi 5 and Compute Module =
5 devices produced non-random KASLR and RNG seed values. This resulted in c= onsistent kernel addresses across boots and devices, potentially making it = easier to exploit other vulnerabilities. Additionally, the low-quality RNG = seed may affect the quality of random numbers or delay booting while suffic= ient entropy is accumulated from other sources. 2026-07-07 not yet calculat=
ed CVE-2026-13199 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13199 ] rsj= oomla.com--rsjoomla.com RSFiles extension for Joomla The Joomla extension R= SFiles is vulnerable to an unauthenticated arbitrary file upload that allow=
s uploading executable files and leads to full RCE. 2026-07-11 not yet calc= ulated CVE-2026-57827 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57827 ]=
Samsung Mobile--Bixby Improper export of android application components in=
Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrar=
y commands with Bixby privilege. 2026-07-10 not yet calculated CVE-2026-210=
55 [
https://www.cve.org/CVERecord?id=3DCVE-2026-21055 ] Samsung Mobile--In= putSharing Improper export of android application components in InputSharin=
g prior to version 2.7.01.4 allows local attackers to access sharing data. = 2026-07-10 not yet calculated CVE-2026-21054 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-21054 ] Samsung Mobile--Samsung Email Improper input valida= tion in Samsung Email prior to version 6.2.13.1 allows local attackers to c= reate arbitrary files within the application sandbox. 2026-07-10 not yet ca= lculated CVE-2026-21053 [
https://www.cve.org/CVERecord?id=3DCVE-2026-21053=
] Samsung Mobile--Samsung Health Improper authorization in Samsung Health = prior to version 7.00.0.107 allows local attackers to access connected devi=
ce information. 2026-07-10 not yet calculated CVE-2026-21056 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-21056 ] Samsung Mobile--Samsung Mobile Devi= ces Improper access control in Settings prior to SMR Jul-2026 Release 1 all= ows local attackers to configure Theft protection settings. 2026-07-10 not = yet calculated CVE-2026-21039 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -21039 ] Samsung Mobile--Samsung Mobile Devices Improper access control in = IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attacke=
rs to use the privileged APIs. 2026-07-10 not yet calculated CVE-2026-21040=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-21040 ] Samsung Mobile--Sams= ung Mobile Devices Improper access control in SamsungSEAgentService prior t=
o SMR Jul-2026 Release 1 allows local attackers to access sensitive informa= tion. 2026-07-10 not yet calculated CVE-2026-21041 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-21041 ] Samsung Mobile--Samsung Mobile Devices Out-of= -bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local = attackers to execute arbitrary code. 2026-07-10 not yet calculated CVE-2026= -21042 [
https://www.cve.org/CVERecord?id=3DCVE-2026-21042 ] Samsung Mobile= --Samsung Mobile Devices Path traversal in Wallpaper service prior to SMR J= ul-2026 Release 1 allows local privileged attackers to access files with sy= stem server privilege. 2026-07-10 not yet calculated CVE-2026-21043 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-21043 ] Samsung Mobile--Samsung Mobi=
le Devices Improper authorization in KnoxGuardManager prior to SMR Jul-2026=
Release 1 allows local attackers to bypass the persistence configuration o=
f the application. 2026-07-10 not yet calculated CVE-2026-21044 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-21044 ] Samsung Mobile--Samsung Mobile D= evices Out-of-bounds write in parsing TIFF format in libimagecodec.media.qu= ram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out= -of-bounds memory. 2026-07-10 not yet calculated CVE-2026-21045 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-21045 ] Samsung Mobile--Samsung Mobile D= evices Time-of-check time-of-use race condition in fabricKeymaster trustlet=
prior to SMR Jul-2026 Release 1 allows local privileged attackers to execu=
te arbitrary code. 2026-07-10 not yet calculated CVE-2026-21046 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-21046 ] Samsung Mobile--Samsung Mobile D= evices Out-of-bounds write in parsing DNG format in libimagecodec.media.qur= am.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-= of-bounds memory. 2026-07-10 not yet calculated CVE-2026-21048 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-21048 ] Samsung Mobile--Samsung Mobile De= vices Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Relea=
se 1 allows local attackers to execute arbitrary code. 2026-07-10 not yet c= alculated CVE-2026-21049 [
https://www.cve.org/CVERecord?id=3DCVE-2026-2104=
9 ] Samsung Mobile--Samsung Mobile Devices Improper access control in Smart= ThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access = sensitive information. 2026-07-10 not yet calculated CVE-2026-21050 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-21050 ] Samsung Mobile--Samsung Mobi=
le Devices Incorrect default permissions in WLAN security prior to SMR Jul-= 2026 Release 1 allows local attackers to configure TencentWifiSecurity sett= ings. 2026-07-10 not yet calculated CVE-2026-21051 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-21051 ] Samsung Mobile--Samsung Mobile Devices Path t= raversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows loca=
l privileged attackers to access files with system privilege. 2026-07-10 no=
t yet calculated CVE-2026-21052 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-21052 ] Samsung Mobile--Samsung Pass Improper input validation in Samsun=
g Pass prior to version 5.2.10.3 allows local privileged attackers to write=
out-of-bounds memory. 2026-07-10 not yet calculated CVE-2026-21057 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-21057 ] SEIKO EPSON CORPORATION--Web=
Config Cross-site request forgery vulnerability exists in SEIKO EPSON Web = Config. If a user views a malicious page while logged into Web Config, unin= tended operations may be performed. 2026-07-07 not yet calculated CVE-2026-= 58315 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58315 ] siyuan-note--si= yuan SiYuan is an open-source personal knowledge management system. Prior t=
o 3.7.1, SiYuan renders note and package content to HTML through the Lute e= ngine with sanitization enabled, but Lute's dangerous javascript scheme blo=
ck does not check form action or SVG xlink:href attributes, allowing stored=
cross-site scripting in document export-preview and Bazaar package README = render paths that can execute OS commands in the Electron desktop renderer.=
This issue is fixed in versions 3.7.1. 2026-07-09 not yet calculated CVE-2= 026-59833 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59833 ] siyuan-note= --siyuan SiYuan is an open-source personal knowledge management system. Pri=
or to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsani= tized this.path value into HTML assigned to innerHTML, allowing a crafted a= sset link containing a double quote to break out of the src attribute, inje=
ct an event handler, and execute JavaScript that can run OS commands in the=
Electron renderer. This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1=
. 2026-07-09 not yet calculated CVE-2026-59855 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-59855 ] SOGo--SOGo A SQL injection vulnerability in SOGo = before 5.12.7 allows authenticated users to execute arbitrary SQL statement=
s via the search parameter of the allContactSearch endpoint. 2026-07-08 not=
yet calculated CVE-2026-39178 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-39178 ] SOGo--SOGo A SQL injection vulnerability in SOGo before 5.12.7 al= lows authenticated users to execute arbitrary SQL statements via the newPas= sword parameter in the password change functionality. 2026-07-08 not yet ca= lculated CVE-2026-39179 [
https://www.cve.org/CVERecord?id=3DCVE-2026-39179=
] SOPlanning--SOPlanning SOPlanning is vulnerable to SQL injection in the = audit retention configuration. An attacker holding=C2=A0parameters_all righ=
ts can inject SQL commands into the audit configuration form which is then = saved. The execution is=C2=A0triggered when the audit functionality is acce= ssed (by the attacker or another user). This issue was fixed in version=C2= =A01.56.01. 2026-07-09 not yet calculated CVE-2026-50644 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-50644 ] SQLite--SQLite A NULL pointer dereferen=
ce in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds=
before check-in e807d4e3798efd53 allows an attacker who can supply a malfo= rmed changeset blob to cause a denial of service. The issue occurs when sql= ite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_va= lue_type() with a NULL sqlite3_value pointer. 2026-07-08 not yet calculated=
CVE-2026-50812 [
https://www.cve.org/CVERecord?id=3DCVE-2026-50812 ] SRI--= Mojo::JSON Mojo::JSON versions before 9.47 for Perl allow memory exhaustion=
via unbounded recursion in the pure-Perl decoder. The pure-Perl decode pat=
h (`_decode_value` dispatching to `_decode_array` and `_decode_object`) rec= urses with no depth limit, so a small deeply nested JSON document can consu=
me excessive memory. This path is the default when Cpanel::JSON::XS is not = installed or `MOJO_NO_JSON_XS=3D1` is set; the Cpanel::JSON::XS fast path i=
s not affected. Any caller that decodes an untrusted JSON body, for example=
`Mojo::Message::json` reached through `$c->req->json`, can exhaust process=
memory and cause denial of service. 2026-07-06 not yet calculated CVE-2026= -14803 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14803 ] SUSE--Rancher =
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agen=
t 1.0 before 1.0.2 could leak API keys or LLM response text with potential = sensitive data into logfiles, allowing local attackers to misuse respective=
gained data or credentials. 2026-07-06 not yet calculated CVE-2026-44934 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-44934 ] SUSE--Rancher Potentia=
l forgery of webhook requests when using a unauthenticated webhook in SUSE = Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 a=
nd 0.12 before 0.12.5 could be used by remote attackers to cause a denial o=
f service or a downgrade attack on other repositories on the system. 2026-0= 7-06 not yet calculated CVE-2026-44937 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-44937 ] swoosh--swoosh URL path injection in the Microsoft Grap=
h adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API=
request URL by interpolating the sender's email address into the URL path = (/users/{from}/sendMail) without percent-encoding or validation. In applica= tions that derive the from address from untrusted or user-influenced input = (for example a relay, a contact form, or a "send as" feature), an attacker = can place URL-special characters such as /, ?, or # in the local part of th=
e address to escape the intended path segment and rewrite the path and quer=
y string of the request. Because the same authenticated POST is sent with t=
he application's Microsoft Graph bearer token, the attacker can redirect it=
to other Graph endpoints within the token's scopes and control the request=
's query string. Applications that always use a fixed, trusted from address=
are not affected. This issue affects swoosh from 1.12.0 before 1.26.3. 202= 6-07-06 not yet calculated CVE-2026-54893 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-54893 ] T-Systems--Archivo A validation vulnerability has been=
identified in certain web features related to file management or upload in=
several products of the TAO 2.0 suite. This vulnerability could allow an a= ttacker capable of interacting with the affected feature to attempt to acce=
ss file system resources outside the scope intended by the application. 202= 6-07-06 not yet calculated CVE-2026-7185 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-7185 ] Tenda--CP3 V3.0 Tenda CP3 V3.0 firmware V31.1.9.91 does = not validate the Content-Length header field in RTSP requests (including DE= SCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length = header is received without a corresponding message body, the RTSP parser en= ters a persistent body-awaiting state, causing the affected TCP connection =
to become permanently non-functional. The device does not actively close th=
e connection, resulting in a TCP resource leak. This issue can be exploited=
by an unauthenticated remote attacker to cause a denial-of-service conditi= on. 2026-07-09 not yet calculated CVE-2026-51600 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-51600 ] Tenda--CP3 V3.0 Tenda CP3 V3.0 firmware V31.1.9= .91 contains a stack-based buffer overflow in the RTSP service. The device = fails to validate the length of the clock=3D value in the Range header fiel=
d when processing a PLAY request. An unauthenticated remote attacker who ha=
s completed a standard RTSP session handshake can send a PLAY request with =
an excessively long clock=3D value to cause the RTSP service to crash. 2026= -07-09 not yet calculated CVE-2026-51601 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-51601 ] Tenda--CP3 V3.0 A stack-based buffer overflow vulnerabi= lity in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an = unauthenticated remote attacker to cause a denial of service via a crafted = SETUP request. The RTSP service's second-stage URL routing parser fails to = validate the length of the URL field in the first SETUP request. By supplyi=
ng a URL consisting of exactly four consecutive repetitions of a valid RTSP=
URL, an attacker can bypass first-stage format validation and trigger a st= ack buffer overflow, causing an immediate crash of the RTSP service process=
and rendering the device inaccessible to all clients on the local network.=
2026-07-09 not yet calculated CVE-2026-51602 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-51602 ] Tenda--CP3 V3.0 A stack-based buffer overflow vuln= erability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allow=
s an unauthenticated remote attacker to cause a denial of service via a cra= fted second SETUP request. After completing the OPTIONS, DESCRIBE, and a le= gitimate first SETUP request to obtain a valid session ID, the RTSP service=
's second-stage URL routing parser fails to validate the length of the URL = field in the subsequent SETUP request. By supplying a URL consisting of exa= ctly four consecutive repetitions of a valid RTSP URL, an attacker can bypa=
ss first-stage format validation and trigger a stack buffer overflow, causi=
ng an immediate crash of the RTSP service process and rendering the device = inaccessible to all clients on the local network. 2026-07-09 not yet calcul= ated CVE-2026-51603 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51603 ] T= enda--CP3 V3.0 A stack-based buffer overflow vulnerability in the RTSP serv= ice of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remot=
e attacker to cause a denial of service via a crafted PLAY request. 2026-07= -09 not yet calculated CVE-2026-51604 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-51604 ] Tenda--CP3 V3.0 A stack-based buffer overflow vulnerabilit=
y in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an un= authenticated remote attacker to cause a denial of service via a crafted TE= ARDOWN request. 2026-07-09 not yet calculated CVE-2026-51605 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-51605 ] Tenda--CP3 V3.0 An improper input h= andling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1= .9.91) causes the device to abruptly terminate the TCP connection with a RS=
T packet when a request containing an oversized field value is received, wi= thout returning any RFC 2326-compliant error response. This behavior affect=
s the request-line URL field and header field values across multiple RTSP r= equest types. 2026-07-09 not yet calculated CVE-2026-51606 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-51606 ] Tenda--firmware The web server binary=
/bin/httpd contains a hidden backdoor authentication mechanism in the logi= n() function at 004c88b8. - The function contains a normal authentication p= ath using MD5/hash-based password verification (prod_encode64/PasswordToMd5= /check_rand_key). - After normal authentication fails, it calls GetValue("s= ys.rzadmin.password") to read a backdoor password from the device configura= tion. - It performs a direct strcmp() comparison (plaintext, not hashed) be= tween the config value and the user-supplied password. A successful match g= rants role=3D2 (admin-level access) and creates a valid session. The rzadmi=
n username is never checked - any username works with the backdoor 2026-07-=
06 not yet calculated CVE-2026-11405 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-11405 ] tilt-dev--tilt Tilt defines dev environments as code for mi= croservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD ser= ver mounts Go net/http/pprof handlers under /debug with no access control. = When the HUD or apiserver listener is network-exposed, an unauthenticated c= aller can read process memory through /debug/pprof/heap and /debug/pprof/go= routine, including session and apiserver tokens, and degrade performance th= rough /debug/pprof/profile or /debug/pprof/trace. This issue is fixed in ve= rsion 0.37.4. 2026-07-10 not yet calculated CVE-2026-55882 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-55882 ] tilt-dev--tilt Tilt defines dev envir= onments as code for microservice apps on Kubernetes. From 0.24.0 through 0.= 37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the = token is served by the unauthenticated /api/websocket_token endpoint and th=
e upgrader accepts clients that omit an Origin header. When the HUD is netw= ork-exposed, an attacker who can reach the listener can open the HUD WebSoc= ket and receive the full view stream, including session state, Tiltfile con= tents, resource statuses, and continued updates. This issue is fixed in ver= sion 0.37.4. 2026-07-10 not yet calculated CVE-2026-55883 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-55883 ] tilt-dev--tilt Tilt defines dev enviro= nments as code for microservice apps on Kubernetes. From 0.20.8 through 0.3= 7.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router wi=
th no authenticating middleware. When the HUD is bound to a non-loopback ad= dress, an unauthenticated network caller can trigger developer-defined reso= urces, tamper with Tiltfile arguments, read full engine state including the=
session token, and invoke apiserver resources through the token-attaching = /proxy handler. This issue is fixed in version 0.37.4. 2026-07-10 not yet c= alculated CVE-2026-55884 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5588=
4 ] TONYC--Imager Imager versions before 1.032 for Perl have a heap out-of-= bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE litera=
l run in read_rgb_16_rle. read_rgb_16_rle guards each literal run with if (= count > data_left), but count is a pixel count while every 16-bit sample co= nsumes two bytes. The copy loop reads inp[0] * 256 + inp[1] and advances tw=
o bytes per pixel, so a run with data_left / 2 < count <=3D data_left passe=
s the guard yet consumes 2 * count bytes and reads past the end of the buff= er. The 8-bit path is unaffected because there one pixel is one byte. Readi=
ng a crafted SGI image through Imager->read triggers the over-read before t=
he parser rejects the malformed image, which can crash the process. 2026-07= -06 not yet calculated CVE-2026-13705 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-13705 ] TONYC--Imager Imager versions before 1.033 for Perl treat = unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD = entry count values, treating them as negative numbers. This could lead to a=
n attempt to allocate a block nearly the size of the address space, which f= ails and kills the process. An attacker could craft an image with EXIF data=
that terminates a worker process. 2026-07-08 not yet calculated CVE-2026-1= 4454 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14454 ] TONYC--Imager::F= ile::JPEG Imager::File::JPEG versions before 1.003 for Perl leak heap memor=
y when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_rea= djpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker=
, allocates a new buffer with *iptc_itext =3D mymalloc(...) and overwrites = the previous pointer without freeing it. Only the final payload is later tu= rned into a Perl scalar and freed, so a JPEG with N such markers leaks the = first N-1 payloads on every read. In a long-lived process, such as an uploa=
d or thumbnailing service, repeated reads accumulate these leaks and exhaus=
t available memory, a denial of service. The same handler ships bundled in = the Imager distribution, where versions before 1.032 are affected and the f=
ix ships in 1.032. 2026-07-06 not yet calculated CVE-2026-13708 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-13708 ] traefik--traefik Traefik is an H= TTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6=
, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canoni= cal-cased spoofed identity headers before writing Traefik's own value, but =
do not account for underscore-variant header names, which many backends nor= malize identically to dashed forms. An attacker able to reach a protected r= oute can inject an underscore-variant header that survives Traefik's stripp= ing and reaches the backend alongside, or on the unauthenticated ForwardAut=
h authResponseHeaders path instead of, the value Traefik intended to set, s= poofing identity or authorization context. This issue is fixed in versions = v2.11.51, v3.6.22, and v3.7.6. 2026-07-06 not yet calculated CVE-2026-54763=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-54763 ] traefik--traefik Tra= efik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22=
, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with t= rustForwardHeader: false, derives the X-Forwarded-Port header sent to the a= uthentication service from the original incoming request instead of the san= itized forwarded request. As a result, an unauthenticated remote attacker c=
an inject an X-Forwarded-Proto: https header over a plain HTTP connection a=
nd cause Traefik to forward X-Forwarded-Port: 443 to the authentication ser= vice, bypassing port-based authorization checks. This issue is fixed in ver= sions v2.11.51, v3.6.22, and v3.7.6. 2026-07-06 not yet calculated CVE-2026= -54764 [
https://www.cve.org/CVERecord?id=3DCVE-2026-54764 ] traefik--traef=
ik Traefik is an open source HTTP reverse proxy and load balancer. From v3.= 7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve = two accepted HTTPRoutes that target the same backend Service:port but confi= gure different backendRef filters to the same child service and apply only = one route's filter set to all requests reaching that backend. In Gateway de= ployments where backendRef filters set security-sensitive headers, such as = tenant identity, authorization context, or values the backend trusts, an at= tacker who can create an accepted HTTPRoute sharing the same backend Servic= e:port may cause their route's filter context to be applied to another rout= e's requests, potentially crossing namespace boundaries when a ReferenceGra=
nt permits cross-namespace targeting. This issue is fixed in version v3.7.6=
. 2026-07-06 not yet calculated CVE-2026-54765 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-54765 ] Trueview--T18161-AF Trueview Security camera T181= 61- AF v4.9.60.0 contains an authentication bypass vulnerability caused by = improper password validation and the presence of hard-coded credentials in = the firmware. 2026-07-07 not yet calculated CVE-2026-37270 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-37270 ] Unknown--Admin and Site Enhancements = (ASE) The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, = admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform = authentication, authorization, or nonce checks on a role-restoration reques=
t handler, allowing unauthenticated attackers to restore a previously demot=
ed administrator account back to the administrator role. This is an incompl= ete fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only=
one of the demotion paths the WordPress role API exposes. 2026-07-06 not y=
et calculated CVE-2026-12083 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 12083 ] Unknown--AllCoach The AllCoach WordPress plugin before 1.0.2 does n=
ot verify that an email address submitted to a public account-registration = endpoint is not already associated with an existing user before overwriting=
that user's password, allowing unauthenticated attackers to reset the pass= word of arbitrary accounts, including administrators, and take over the sit=
e. 2026-07-06 not yet calculated CVE-2026-10830 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-10830 ] Unknown--Appointment Booking Calendar Plugin and=
Scheduling Plugin The Appointment Booking Calendar Plugin and Scheduling P= lugin WordPress plugin through 1.1.28 does not validate data before passing=
it to a PHP deserialization function, allowing unauthenticated attackers t=
o inject arbitrary PHP objects; where a suitable gadget chain is present on=
the site this can be leveraged to achieve remote code execution. 2026-07-0=
8 not yet calculated CVE-2026-12378 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-12378 ] Unknown--DoLeads Integrator The DoLeads Integrator WordPress=
plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen =
to be used to achieve RCE, once they are added adding to a blog, for exampl=
e using a vulnerability where unclosed extensions from wordpress.org can be=
installed by unauthorized users. 2026-07-07 not yet calculated CVE-2026-43=
75 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4375 ] Unknown--escortwp T=
he EscortWP escortwp WordPress theme through 3.6.2 was distributed with a v= endor-authored, obfuscated backdoor that lets an unauthenticated attacker w=
ho supplies a hard-coded, per-build key permanently delete all of the site'=
s content, and that covertly transmits the site URL, administrator email ad= dress, and license key to a third-party server. 2026-07-10 not yet calculat=
ed CVE-2026-12685 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12685 ] Unk= nown--Everest Forms The Everest Forms WordPress plugin before 3.5.0 does no=
t reliably delete temporary CSV files generated during email-notification p= rocessing and leaves them publicly accessible in the uploads directory, all= owing unauthenticated attackers to retrieve other users' form submission re= cords via predictable, enumerable filenames. 2026-07-09 not yet calculated = CVE-2026-11571 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11571 ] Unknow= n--Everest Forms The Everest Forms WordPress plugin before 3.5.0 does not c= orrectly restrict access to several REST API endpoints belonging to its onb= oarding assistant: the capability check is only applied when an attacker-co= ntrollable request header holds a specific value, so it can be bypassed by = omitting or changing that header. This makes it possible for unauthenticate=
d attackers to read onboarding status information, modify the related Evere=
st Forms WordPress plugin before 3.5.0 options, and trigger an email from t=
he site to an arbitrary address. 2026-07-09 not yet calculated CVE-2026-122=
70 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12270 ] Unknown--Fediverse=
Embeds The Fediverse Embeds WordPress plugin before 1.5.8 does not validat=
e the destination of the server-side request performed by an unauthenticate=
d media-proxying endpoint, allowing anonymous users to make the site fetch = arbitrary URLs, including internal and private-network addresses, and read = back the response body. This results in a full-read Server-Side Request For= gery and open proxy. 2026-07-09 not yet calculated CVE-2026-12516 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-12516 ] Unknown--Fediverse Embeds The = Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destin= ation of the server-side request performed by an unauthenticated site-info = endpoint before fetching it, allowing anonymous users (the gating nonce is = exposed on public pages carrying an embed) to make the site request interna=
l and private-network URLs and read back the parsed page metadata. This is =
a Server-Side Request Forgery. 2026-07-09 not yet calculated CVE-2026-12517=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-12517 ] Unknown--FileOrganiz=
er The FileOrganizer WordPress plugin before 1.2.0 does not validate the fi=
le type on several of its file-management operations, allowing authenticate=
d users who have been granted file-manager access - which its premium add-o=
n can extend to sub-administrator roles - to upload arbitrary PHP files and=
achieve remote code execution. This is an incomplete fix of CVE-2024-7985,=
which only added file-type validation to the upload operation. 2026-07-06 = not yet calculated CVE-2026-11962 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-11962 ] Unknown--FileOrganizer The FileOrganizer WordPress plugin befo=
re 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manage=
r Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8= .0.4 do not properly escape a parameter before passing it to a shell comman=
d when processing image operations, allowing authenticated users to perform=
OS Command Injection. This requires the server to have the ImageMagick con= vert CLI available without either the PHP imagick or GD extensions. 2026-07= -06 not yet calculated CVE-2026-6382 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-6382 ] Unknown--Frontend File Manager Plugin The Frontend File Mana= ger Plugin WordPress plugin through 23.6 does not validate a file path deri= ved from user input before deleting the referenced file, allowing unauthent= icated users to delete arbitrary files on the server (such as wp-config.php=
) when guest upload mode is enabled. Deleting wp-config.php forces the site=
into its setup routine, which can be leveraged toward a full site takeover=
. 2026-07-07 not yet calculated CVE-2026-12277 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-12277 ] Unknown--LA-Studio Element Kit for Elementor The = LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not = check whether user registration is enabled on the site before creating an a= ccount through one of its unauthenticated AJAX actions, allowing unauthenti= cated attackers to register new accounts even when registration has been di= sabled site-wide. 2026-07-10 not yet calculated CVE-2026-12276 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-12276 ] Unknown--Notifications for Forms =
& WordPress Actions The Notifications for Forms & WordPress Actions WordPre=
ss plugin before 2.6 does not validate a user-supplied value before using i=
t to build a server-side file inclusion path, allowing authenticated users = with subscriber-level access and above to include and execute arbitrary loc=
al PHP files on the server. 2026-07-06 not yet calculated CVE-2024-6228 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2024-6228 ] Unknown--Simple Membershi=
p The Simple Membership WordPress plugin before 4.7.5 does not verify the a= uthenticity of Stripe webhook requests when no signing secret is configured=
, nor escape a value taken from them before outputting it in an administrat=
or notice, allowing unauthenticated attackers to inject arbitrary web scrip=
ts that execute in the context of a logged-in administrator. 2026-07-06 not=
yet calculated CVE-2026-11855 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-11855 ] Unknown--Ultimate Member The Ultimate Member WordPress plugin bef= ore 2.12.0 does not properly sanitise and escape the value of custom textar=
ea profile fields before outputting it on user profiles, allowing authentic= ated users with Subscriber-level access and above to store JavaScript that = executes when any user, including an administrator, views the affected prof= ile. 2026-07-06 not yet calculated CVE-2026-11766 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-11766 ] Unknown--uncanny-automator-pro The uncanny-aut= omator-pro WordPress plugin before 7.3.0.6 was distributed with malicious c= ode after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.=
6 update/distribution infrastructure was compromised; the injected backdoor=
grants unauthenticated attackers an administrator session on affected site=
s and beacons the site's secret keys and administrator details to attacker-= controlled servers. 2026-07-07 not yet calculated CVE-2026-12375 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-12375 ] Unknown--WP DSGVO Tools (GDPR) = The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform a=
n authorization check on the immediate-processing path of its data subject = access request feature, allowing unauthenticated attackers to generate and = download the full personal-data export (including name, postal address, pho=
ne number, email, and comment content) of any user, customer, or commenter =
by supplying their email address. 2026-07-09 not yet calculated CVE-2026-11= 869 [
https://www.cve.org/CVERecord?id=3DCVE-2026-11869 ] Unknown--WP Suppo=
rt Plus Responsive Ticket System The WP Support Plus Responsive Ticket Syst=
em WordPress plugin through 9.1.2 does not sign or verify its guest-session=
cookie, allowing unauthenticated attackers to forge it and impersonate any=
ticket owner (identified by email address) to read, reply to, and close th=
at person's support tickets. 2026-07-09 not yet calculated CVE-2026-11875 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-11875 ] Unknown--WP Travel Eng= ine The WP Travel Engine WordPress plugin before 6.8.1 does not properly va= lidate the source of a user-supplied profile image path before moving the f= ile, allowing authenticated users with subscriber-level access and above to=
relocate arbitrary files within the WordPress uploads directory into their=
own profile-image path. This removes the targeted media from its original = location and can break content across the site. 2026-07-07 not yet calculat=
ed CVE-2026-10834 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10834 ] vim= --vim Vim is an open source, command line text editor. Prior to 9.2.0736, t=
he PHP omni-completion script in runtime/autoload/phpcomplete.vim interpola= tes a class or trait name, taken from the contents of the edited buffer, in=
to a search() pattern that is run via win_execute() without escaping. A nam=
e containing a single quote can terminate the search() string argument earl=
y, and because the bar is honored as an Ex command separator, the remainder=
of the name is run as Ex commands; via the :! command this allows arbitrar=
y operating-system command execution when a victim opens a crafted PHP file=
and invokes omni-completion. This issue is fixed in version 9.2.0736. 2026= -07-09 not yet calculated CVE-2026-59856 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-59856 ] vim--vim Vim is an open source, command line text edito=
r. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in sr= c/spell.c translates a word through a spell file's SAL sound-folding rules = into a caller-owned result buffer, but its result writes are guarded with r= eslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] =3D NU=
L writes one byte past the end of the MAXWLEN-element stack buffer. A bound= ary-length word passed to soundfold(), or reached via sound-based spell sug= gestion while a SAL-based spell language is active under a non-multibyte 8-= bit encoding, can corrupt the eval_soundfold() stack frame and crash the ed= itor. This issue is fixed in version 9.2.0725. 2026-07-09 not yet calculate=
d CVE-2026-59857 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59857 ] vim-= -vim Vim is an open source, command line text editor. Prior to 9.2.0735, th=
e C omni-completion script in runtime/autoload/ccomplete.vim interpolates t=
he typeref: or typename: extension field of a tags entry, without escaping,=
into a :vimgrep pattern that is run through :execute. Because :vimgrep hon= ors the bar as a command separator, a crafted tag field can close the searc=
h pattern and append an arbitrary Ex command; opening a hostile .c file who=
se project tags file contains such an entry and invoking C omni-completion = runs that command as the editing user. This issue is fixed in version 9.2.0= 735. 2026-07-09 not yet calculated CVE-2026-59858 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-59858 ] vllm-project--vllm vLLM is a library for LLM i= nference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt e= mbeds payload in a /v1/completions request with a model using M-RoPE causes=
EngineCore to fail an assertion and fatally crash, shutting down the entir=
e server application. Any remote user who is authorized to make a /v1/compl= etions request can make such a request and induce a crash. This issue is fi= xed in version 0.24.0. 2026-07-06 not yet calculated CVE-2026-55514 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-55514 ] vllm-project--vllm vLLM is a=
high-throughput and memory-efficient inference and serving engine for LLMs=
. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user= -supplied regular expression string directly to the grammar compiler backen=
ds with no compilation timeout; in the xgrammar backend the string reaches = the regex compiler with no guard, and in the outlines backend the validatio=
n step blocks structural issues such as lookarounds and backreferences but = performs no complexity analysis, so a pattern with nested quantifiers passe=
s all checks and causes exponential state-space expansion, allowing a singl=
e request containing an adversarial regex to hang an inference worker indef= initely and deny service. This issue is fixed in version 0.24.0. 2026-07-06=
not yet calculated CVE-2026-55574 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-55574 ] Wireless Technology, Inc.--Wireless Technology, Inc. An unaut= henticated path traversal vulnerability exists in the web management interf= ace of WTI (Wireless Technology, Inc.) version 3.5.0.r 2024/05/24 00:00:00.=
An unauthenticated attacker can craft malicious HTTP requests containing t= raversal sequences to access files outside of the intended web root directo= ry. This may allow disclosure of sensitive system files and configuration d= ata 2026-07-10 not yet calculated CVE-2025-70796 [
https://www.cve.org/CVER= ecord?id=3DCVE-2025-70796 ] X.Org--xorg-x11-server Local attackers with a X=
connection able to provide GLX commit to the X server xorg-server before 2= 1.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due t= o=C2=A0CommonMakeCurrent() pointing into potentially reallocated memory. 20= 26-07-08 not yet calculated CVE-2026-56000 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-56000 ] Xen--oxenstored When oxenstored is tearing a domain d= own, the node data is cleaned up but the usage counts are leaked. When the = domain ID is eventually reused, the new domain can create fewer nodes befor=
e beeing deemed to be over quota. 2026-07-09 not yet calculated CVE-2026-23= 556 [
https://www.cve.org/CVERecord?id=3DCVE-2026-23556 ] Xen--varstored va= rstored is a component of the Xapi toolstack handling UEFI Variables for a = VM. It has a communication path with OVMF inside the VM involving mapping a=
buffer prepared by OVMF. Within varstored, there were insufficient compile=
r barriers, creating TOCTOU issues with data in the shared buffer. The exac=
t vulnerable behaviour depends on the code generated by the compiler. In a = build of varstored using default settings, the attacker can control an inde=
x used in a jump table. 2026-07-09 not yet calculated CVE-2025-58151 [ http= s://www.cve.org/CVERecord?id=3DCVE-2025-58151 ] Xen--Windows PV drivers [Th=
is CNA information record relates to multiple CVEs; the text explains which=
aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers e= xpose various facilities to userspace. Several of these have no security de= scriptor, and are therefore fully accessible to unprivileged users. These a= re: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2= 025-27464 2026-07-09 not yet calculated CVE-2025-27462 [
https://www.cve.or= g/CVERecord?id=3DCVE-2025-27462 ] Xen--Windows PV drivers [This CNA informa= tion record relates to multiple CVEs; the text explains which aspects/vulne= rabilities correspond to which CVE.] The Windows PV drivers expose various = facilities to userspace. Several of these have no security descriptor, and = are therefore fully accessible to unprivileged users. These are: 1. XenCons=
, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464 2026= -07-09 not yet calculated CVE-2025-27463 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-27463 ] Xen--Windows PV drivers [This CNA information record re= lates to multiple CVEs; the text explains which aspects/vulnerabilities cor= respond to which CVE.] The Windows PV drivers expose various facilities to = userspace. Several of these have no security descriptor, and are therefore = fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-274=
62 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464 2026-07-09 not yet=
calculated CVE-2025-27464 [
https://www.cve.org/CVERecord?id=3DCVE-2025-27= 464 ] Xen--XAPI There are multiple issues. 1. Updates to the XAPI database = sanitise input strings, but try generating the notification using the unsan= itised input. This causes the database's event thread to terminate and ceas=
e further processing. 2. XAPI's UTF-8 encoder implements v3.0 of the Unicod=
e spec, but XAPI uses libraries which conform to the stricter v3.1 of the U= nicode spec. This causes some strings to be accepted as valid UTF-8 by XAPI=
, but rejected by other libraries in use. Notably, such strings can be ente= red into the database, after which the database can no longer be loaded. 3.=
There is no input sanitisation for Map/Set updates on objects in the XAPI = database. 2026-07-09 not yet calculated CVE-2025-58146 [
https://www.cve.or= g/CVERecord?id=3DCVE-2025-58146 ] Xen--XAPI [This CNA information record re= lates to multiple CVEs; the text explains which aspects/vulnerabilities cor= respond to which CVE.] XAPI can configure different users with different ro= les, using Role Based Access Control. For more details, see:
https://docs.x= enserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles = The pool-admin role is fully privileged. Notably, users with this role can = also SSH into the host as root. The other administrator roles are pool-oper= ator, vm-power-admin and vm-admin, each of which are authorised to configur=
e and manage various aspects of the system. Some settings are inadequately = restricted, and can be set by a lower privilege of administrator than expec= ted. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local an=
d turn arbitrary files in dom0 into VDIs (virtual disks) and give said disk=
s to a VM they control. This is an arbitrary read and/or modify of files in=
dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domai=
n and mark a VM as a system domain. System domains are ignored and left run= ning during certain other host/pool operations, and may be hidden from view=
in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_d= river_domain and mark a VM as the storage domain for a particular host stor= age connection (PBD). Shutting down the VM can cause the PBD to be erroneou= sly marked as unplugged when it is not. * CVE-2026-23562: Configuration of = PCI passthrough is normally restricted to the pool-admin role. However one = API was missing this check, allowing a vm-admin access to unintended host h= ardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial pa= rameter, which should be restricted to the pool-admin role, as it can allow=
arbitrary dom0 file write. 2026-07-09 not yet calculated CVE-2026-23559 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-23559 ] Xen--XAPI [This CNA inf= ormation record relates to multiple CVEs; the text explains which aspects/v= ulnerabilities correspond to which CVE.] XAPI can configure different users=
with different roles, using Role Based Access Control. For more details, s= ee:
https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overvie= w.html#rbac-roles The pool-admin role is fully privileged. Notably, users w= ith this role can also SSH into the host as root. The other administrator r= oles are pool-operator, vm-power-admin and vm-admin, each of which are auth= orised to configure and manage various aspects of the system. Some settings=
are inadequately restricted, and can be set by a lower privilege of admini= strator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_confi= g:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) = and give said disks to a VM they control. This is an arbitrary read and/or = modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-conf= ig:is_system_domain and mark a VM as a system domain. System domains are ig= nored and left running during certain other host/pool operations, and may b=
e hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.othe= r_config:storage_driver_domain and mark a VM as the storage domain for a pa= rticular host storage connection (PBD). Shutting down the VM can cause the = PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562:=
Configuration of PCI passthrough is normally restricted to the pool-admin = role. However one API was missing this check, allowing a vm-admin access to=
unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.plat= form:hvm_serial parameter, which should be restricted to the pool-admin rol=
e, as it can allow arbitrary dom0 file write. 2026-07-09 not yet calculated=
CVE-2026-23560 [
https://www.cve.org/CVERecord?id=3DCVE-2026-23560 ] Xen--= XAPI [This CNA information record relates to multiple CVEs; the text explai=
ns which aspects/vulnerabilities correspond to which CVE.] XAPI can configu=
re different users with different roles, using Role Based Access Control. F=
or more details, see:
https://docs.xenserver.com/en-us/xencenter/current-re= lease/rbac-overview.html#rbac-roles The pool-admin role is fully privileged=
. Notably, users with this role can also SSH into the host as root. The oth=
er administrator roles are pool-operator, vm-power-admin and vm-admin, each=
of which are authorised to configure and manage various aspects of the sys= tem. Some settings are inadequately restricted, and can be set by a lower p= rivilege of administrator than expected. * CVE-2026-23559: A vm-admin can s=
et VBD.other_config:backend-local and turn arbitrary files in dom0 into VDI=
s (virtual disks) and give said disks to a VM they control. This is an arbi= trary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can=
set VM.other-config:is_system_domain and mark a VM as a system domain. Sys= tem domains are ignored and left running during certain other host/pool ope= rations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-adm=
in can set VM.other_config:storage_driver_domain and mark a VM as the stora=
ge domain for a particular host storage connection (PBD). Shutting down the=
VM can cause the PBD to be erroneously marked as unplugged when it is not.=
* CVE-2026-23562: Configuration of PCI passthrough is normally restricted =
to the pool-admin role. However one API was missing this check, allowing a = vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin c=
an set the VM.platform:hvm_serial parameter, which should be restricted to = the pool-admin role, as it can allow arbitrary dom0 file write. 2026-07-09 = not yet calculated CVE-2026-23561 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-23561 ] Xen--XAPI [This CNA information record relates to multiple CVE=
s; the text explains which aspects/vulnerabilities correspond to which CVE.=
] XAPI can configure different users with different roles, using Role Based=
Access Control. For more details, see:
https://docs.xenserver.com/en-us/xe= ncenter/current-release/rbac-overview.html#rbac-roles The pool-admin role i=
s fully privileged. Notably, users with this role can also SSH into the hos=
t as root. The other administrator roles are pool-operator, vm-power-admin = and vm-admin, each of which are authorised to configure and manage various = aspects of the system. Some settings are inadequately restricted, and can b=
e set by a lower privilege of administrator than expected. * CVE-2026-23559=
: A vm-admin can set VBD.other_config:backend-local and turn arbitrary file=
s in dom0 into VDIs (virtual disks) and give said disks to a VM they contro=
l. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-235= 60: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a = system domain. System domains are ignored and left running during certain o= ther host/pool operations, and may be hidden from view in tooling. * CVE-20= 26-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark=
a VM as the storage domain for a particular host storage connection (PBD).=
Shutting down the VM can cause the PBD to be erroneously marked as unplugg=
ed when it is not. * CVE-2026-23562: Configuration of PCI passthrough is no= rmally restricted to the pool-admin role. However one API was missing this = check, allowing a vm-admin access to unintended host hardware. * CVE-2026-4= 2486: A vm-admin can set the VM.platform:hvm_serial parameter, which should=
be restricted to the pool-admin role, as it can allow arbitrary dom0 file = write. 2026-07-09 not yet calculated CVE-2026-23562 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-23562 ] Xen--XAPI [This CNA information record relat=
es to multiple CVEs; the text explains which aspects/vulnerabilities corres= pond to which CVE.] XAPI can configure different users with different roles=
, using Role Based Access Control. For more details, see:
https://docs.xens= erver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The=
pool-admin role is fully privileged. Notably, users with this role can als=
o SSH into the host as root. The other administrator roles are pool-operato=
r, vm-power-admin and vm-admin, each of which are authorised to configure a=
nd manage various aspects of the system. Some settings are inadequately res= tricted, and can be set by a lower privilege of administrator than expected=
. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and t= urn arbitrary files in dom0 into VDIs (virtual disks) and give said disks t=
o a VM they control. This is an arbitrary read and/or modify of files in do= m0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain a=
nd mark a VM as a system domain. System domains are ignored and left runnin=
g during certain other host/pool operations, and may be hidden from view in=
tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driv= er_domain and mark a VM as the storage domain for a particular host storage=
connection (PBD). Shutting down the VM can cause the PBD to be erroneously=
marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI=
passthrough is normally restricted to the pool-admin role. However one API=
was missing this check, allowing a vm-admin access to unintended host hard= ware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial param= eter, which should be restricted to the pool-admin role, as it can allow ar= bitrary dom0 file write. 2026-07-09 not yet calculated CVE-2026-42486 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-42486 ] Xerte--Xerte Online Tools =
A vulnerability in the Xerte Online Tools allows for RCE through the antivi= rus binary path in the tools server settings, which can be changed to a PHP=
interpreter, allowing an attacker to upload PHP data that will then be exe= cuted. 2026-07-09 not yet calculated CVE-2026-12116 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-12116 ] Xerte--Xerte Online Tools A vulnerability in=
the Xerte Online Tools allows for authentication bypass and remote code ex= ecution via reinstallation through the /setup/ folder, enabling attackers t=
o reinstall the service to a remote database they control. 2026-07-09 not y=
et calculated CVE-2026-14261 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 14261 ] zen-browser--desktop Zen is a firefox-based browser. Prior to 1.21.= 5b, Zen's glance and split-view context-menu actions, Open link in glance a=
nd Split link in new tab, load a page-controlled link URL with the System p= rincipal instead of the originating page's principal, allowing a malicious = web page to place a link to a file URL that can load with System privileges=
when opened through either context-menu item and bypass the content-to-fil=
e security check that blocks an ordinary click. This issue is fixed in vers= ion 1.21.5b. 2026-07-09 not yet calculated CVE-2026-57501 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-57501 ] zitadel--zitadel ZITADEL is an open so= urce identity management platform. Prior to 4.15.1, ZITADEL's event store v= alidation can retain the original resource owner for a deleted user identif= ier, causing a later user recreated with the same identifier in another org= anization to be provisioned under the original organization and exposed to = that organization's administrator. This issue is fixed in version 4.15.2. 2= 026-07-10 not yet calculated CVE-2026-55670 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-55670 ] zitadel--zitadel ZITADEL is an open source identity = management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notific= ation channels, OIDC BackChannel Logout, and SAML metadata URL fetches do n=
ot consistently validate user-defined URLs against protected denylist handl= ing, allowing server-side requests to loopback, internal IP, link-local, or=
redirected endpoints through DNS rebinding, redirects, or protocol downgra= des. This issue is fixed in version 4.15.2. 2026-07-10 not yet calculated C= VE-2026-55671 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55671 ]=20
Back to top [ #top ]
body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
: normal; font-style: normal; color: #333333; }=20
Having trouble viewing this message?=C2=A0View it as a webpage [
https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/4205501 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]
You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [
https://www.cisa.gov ] (CISA)
Manage Subscriptions [
https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [
https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]
Connect with CISA:=20
Facebook [
https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [
https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [
https://Instagram.com/cisag=
ov ]=C2=A0 |=C2=A0 LinkedIn [
https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]
________________________________________________________________________
This email was sent to
cisa@toolazy.synchro.net using Granicus Communicatio=
ns Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency = =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ h= ttps://granicus.com/solution/digital-communication-engagement/ ]=20
body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}
--===============2360347132490274785==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns=3D"
http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
<title> Vulnerability Summary for the Week of July 6, 2026
</title>
</head>
<body style=3D"">
<table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
align=3D"center">
<tr>
<td>
<!--[if (gte mso 9)|(IE)]>
<table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
<![endif]-->
<a name=3D"gd_top" id=3D"gd_top"></a>
=20
<p><img src=3D"
https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
<p>You are subscribed to Vulnerability Bulletins for Cybersecurity and In= frastructure Security Agency. This information has recently been updated an=
d is now available.</p>
<p>The CISA Vulnerability Bulletin provides a summary of new vulnerabilitie=
s that have been recorded in the past week. In some cases, the vulnerabilit= ies in the bulletin may not yet have assigned CVSS scores.</p> <p>Vulnerabilities are based on the=C2=A0<a href=3D"
https://www.cve.org/" t= arget=3D"_blank" class=3D"ext" data-extlink=3D"" rel=3D"noopener">Common Vu= lnerabilities and Exposures</a>=C2=A0(CVE) vulnerability naming standard an=
d are organized according to severity, determined by the=C2=A0<a href=3D"ht= tps://www.cve.org/about/relatedefforts" target=3D"_blank" rel=3D"noopener">= Common Vulnerability Scoring System</a>=C2=A0(CVSS) standard. The division =
of high, medium, and low severities correspond to the following scores:</p>
<strong>High</strong>: vulnerabilities with a CVSS base score of 7.0=E2=80= =9310.0</li>
<strong>Medium</strong>: vulnerabilities with a CVSS base score of 4.0=E2= =80=936.9</li>
<strong>Low</strong>: vulnerabilities with a CVSS base score of 0.0=E2=80= =933.9</li>
</ul>
<p>Entries may include additional information provided by organizations and=
efforts sponsored by CISA. This information may include identifying inform= ation, values, definitions, and related links. Patch information is provide=
d when available. Please note that some of the information in the bulletin =
is compiled from external, open-source reports and is not a direct result o=
f CISA analysis.</p>
<p>=C2=A0</p>
<div class=3D"rss_item" style=3D"margin-bottom: 2em;">
<div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
n: 0 0 0.3em; padding: 0;"><a href=3D"
https://www.cisa.gov/news-events/bull= etins/sb26-194">Vulnerability Summary for the Week of July 6, 2026</a></div=
<div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">07/13/2026 12:15 PM EDT</div>
<div class=3D"rss_description" style=3D"margin: 0 0 0.3em; padding: 0;">
<div id=3D"high_v">
<h2 id=3D"high_v_title">High Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"High Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">1Panel-dev--MaxKB</td>
<td>MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lt=
s, MaxKB tool import functionality in apps/tools/serializers/tool.py and MC=
P referencing mode in apps/application/chat_pipeline/step/chat_step/impl/ba= se_chat_step.py do not consistently validate MCP transport type, allowing a=
n authenticated user to import a .tool file containing stdio transport with=
malicious commands and trigger the configuration through an AI Chat node s=
o MultiServerMCPClient executes arbitrary system commands. This issue is fi= xed in version 2.10.0-lts.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54149" target=3D= "_blank" rel=3D"noopener">CVE-2026-54149</a></td>
</tr>
<td class=3D"vendor-product">389ds--389-ds-base</td>
<td>A heap buffer overflow flaw was found in the SASL I/O layer of 389 Dire= ctory Server (389-ds-base). After a successful SASL bind with integrity pro= tection (SSF > 0), an authenticated attacker can send a specially crafte=
d oversized LDAP UNBIND packet that is copied into a 512-byte heap receive = buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows u=
p to approximately 2 megabytes of attacker-controlled data to overflow the = buffer, causing a denial of service (server crash). In FreeIPA and Red Hat = Identity Management deployments, any domain user with a valid Kerberos tick= et, any enrolled host, or any service account can trigger this vulnerabilit=
y over the network after authenticating via GSSAPI. The vulnerable code pat=
h has existed since approximately 2013 (389-ds-base 1.3.2) and was not addr= essed by the CVE-2025-14905 fix, which patched a separate heap overflow in = schema.c only.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11610" target=3D= "_blank" rel=3D"noopener">CVE-2026-11610</a></td>
</tr>
<td class=3D"vendor-product">actualbudget--actual</td>
<td>Actual is a local-first personal finance app. Prior to 26.6.0, in OpenI=
D multi-user mode, disabling a user only blocks future OpenID login for tha=
t identity, while existing Actual session tokens for the disabled user rema=
in valid. The shared session validation path accepts any existing token row=
that has not expired without checking whether the associated user is still=
enabled, allowing a disabled user to continue calling authenticated server=
endpoints. This issue is fixed in version 26.6.0.</td>
<td>2026-07-07</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49229" target=3D= "_blank" rel=3D"noopener">CVE-2026-49229</a></td>
</tr>
<td class=3D"vendor-product">Adam Retail Automation Ltd.--MobilMen 20T</td> <td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T all= ows SQL Injection. This issue affects MobilMen 20T: from v3 through 1007202= 6.=C2=A0NOTE: The vendor was contacted early about this disclosure but did = not respond in any way.</td>
<td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2397" target=3D"= _blank" rel=3D"noopener">CVE-2026-2397</a></td>
</tr>
<td class=3D"vendor-product">Adam Retail Automation Ltd.--MobilMen 20T</td> <td>Authorization bypass through User-Controlled key vulnerability in Adam = Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue=
affects MobilMen 20T: from v3 through 10072026.=C2=A0NOTE: The vendor was = contacted early about this disclosure but did not respond in any way.</td> <td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2398" target=3D"= _blank" rel=3D"noopener">CVE-2026-2398</a></td>
</tr>
<td class=3D"vendor-product">Adobe--ColdFusion</td>
<td>ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Impr= oper Input Validation vulnerability that could result in arbitrary code exe= cution in the context of the current user. Exploitation of this issue does = not require user interaction. Scope is changed.</td>
<td>2026-07-06</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48316" target=3D= "_blank" rel=3D"noopener">CVE-2026-48316</a></td>
</tr>
<td class=3D"vendor-product">Allwinner--H616</td>
<td>Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network o=
n production. An attacker could request for ADB authorization and gain root=
level privileges if the victim allows access.</td>
<td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58378" target=3D= "_blank" rel=3D"noopener">CVE-2026-58378</a></td>
</tr>
<td class=3D"vendor-product">appium--appium</td>
<td>Appium is a cross-platform automation framework for all kinds of apps, = built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium stor= age plugin exposes POST /storage/delete, whose handler passes the user-supp= lied name value directly into path.join(storageRoot, name) and fs.rimraf() = without path sanitization, allowing an unauthenticated remote client to esc= ape the storage root with ../ sequences and recursively delete arbitrary wr= itable files or directories. This issue is fixed in version 1.1.6.</td> <td>2026-07-08</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58192" target=3D= "_blank" rel=3D"noopener">CVE-2026-58192</a></td>
</tr>
<td class=3D"vendor-product">arikusi--deepseek-mcp-server</td>
<td>DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in versi=
on 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` acce= pts caller-supplied `session_id` values without binding them to any authent= icated principal or transport session. An attacker can enumerate active ses= sion IDs via `deepseek_sessions`, then reuse a victim-controlled `session_i=
d` in `deepseek_chat` to retrieve and continue the victim's conversation co= ntext. Version 1.7.0 contains a patch.</td>
<td>2026-07-09</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55604" target=3D= "_blank" rel=3D"noopener">CVE-2026-55604</a></td>
</tr>
<td class=3D"vendor-product">Armiya Information Technologies Ltd. Co.--Acce=
ss Control System (GKS)</td>
<td>Missing Authorization vulnerability in Armiya Information Technologies = Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resour=
ce Locations. This issue affects Access Control System (GKS): before Versio=
n 2.</td>
<td>2026-07-07</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8377" target=3D"= _blank" rel=3D"noopener">CVE-2026-8377</a></td>
</tr>
<td class=3D"vendor-product">Aster Telecom--Azcall</td>
<td>A weakness has been identified in Aster Telecom Azcall 10/11. This issu=
e affects some unknown processing of the file /azcall/adm/gestao_loja/sis.p= hp?t=3Dconsultar of the component HTTP Handler. Executing a manipulation of=
the argument nome/perfil/status can lead to sql injection. The attack may =
be performed from remote. The exploit has been made available to the public=
and could be used for attacks. The vendor was contacted early about this d= isclosure but did not respond in any way.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15482" target=3D= "_blank" rel=3D"noopener">CVE-2026-15482</a></td>
</tr>
<td class=3D"vendor-product">AWS--MCP Gateway & Registry</td>
<td>Improper Neutralization of Special Elements in the metrics-service rete= ntion policy management component in Amazon mcp-gateway-registry before 1.0= .13 might allow an authenticated remote user to execute arbitrary SQL queri=
es via a crafted table_name value that is interpolated into SQL statements =
in identifier position. To remediate this issue, users should upgrade to ve= rsion 1.0.13 or later.</td>
<td>2026-07-06</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14471" target=3D= "_blank" rel=3D"noopener">CVE-2026-14471</a></td>
</tr>
<td class=3D"vendor-product">B&R Industrial Automation GmbH--APROL</td> <td>Improper certificate validation vulnerability in B&R Industrial Aut= omation GmbH APROL. This issue affects APROL: before R 4.4-01P5.</td> <td>2026-07-06</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6900" target=3D"= _blank" rel=3D"noopener">CVE-2026-6900</a></td>
</tr>
<td class=3D"vendor-product">B&R Industrial Automation GmbH--APROL</td> <td>Untrusted Search Path vulnerability in B&R Industrial Automation Gm=
bH APROL. This issue affects APROL: before R 4.4-01P5.</td>
<td>2026-07-06</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6901" target=3D"= _blank" rel=3D"noopener">CVE-2026-6901</a></td>
</tr>
<td class=3D"vendor-product">badhonrocks--Divi Torque Lite Divi Modules for=
the Divi Builder & Theme</td>
<td>The Divi Torque Lite - Divi Theme, Divi Builder & Extra Theme plugi=
n for WordPress is vulnerable to Cross-Site Request Forgery in all versions=
up to, and including, 4.2.3. This is due to the use of '__return_true' as = the permission_callback for the /install_plugin and /activate_plugin REST A=
PI endpoints, which bypasses WordPress's built-in REST API nonce verificati= on. Although the endpoint callbacks contain internal current_user_can() che= cks, the absence of nonce verification means that a forged cross-site reque=
st from a logged-in administrator's browser will pass the capability check = via the admin's session cookies. This makes it possible for unauthenticated=
attackers to install arbitrary plugins from WordPress.</td> <td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4275" target=3D"= _blank" rel=3D"noopener">CVE-2026-4275</a></td>
</tr>
<td class=3D"vendor-product">baptisteArno--typebot.io</td>
<td>TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SS=
RF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed=
with the IPv6 unspecified address :: because validateIPAddress blocks loca=
l, metadata, and private ranges but does not block :: or its expanded form.=
A workspace editor or creator can configure a server-side HTTP Request blo=
ck or guarded script fetch to make the Typebot server connect to local HTTP=
services through safeKy, including flows triggered by POST /v1/typebots/{p= ublicId}/startChat or POST /v1/sessions/{sessionId}/continueChat. This issu=
e is fixed in version 3.17.2.</td>
<td>2026-07-10</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49213" target=3D= "_blank" rel=3D"noopener">CVE-2026-49213</a></td>
</tr>
<td class=3D"vendor-product">bitpressadmin--Bit Form Contact Form, Payment = Forms, Multi Step Forms, Calculator & Custom Form Builder</td>
<td>The Bit Form - Contact Form, Payment Forms, Multi Step Forms, Calculato=
r & Custom Form Builder plugin for WordPress is vulnerable to arbitrary=
file deletion due to insufficient file path validation in the deleteFiles = function in all versions up to, and including, 3.1.1 This makes it possible=
for authenticated attackers, with subscriber-level access and above, to de= lete arbitrary files on the server, which can easily lead to remote code ex= ecution when the right file is deleted (such as wp-config).</td> <td>2026-07-09</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14372" target=3D= "_blank" rel=3D"noopener">CVE-2026-14372</a></td>
</tr>
<td class=3D"vendor-product">bitwarden--server</td>
<td>Bitwarden Server before 2026.6.0 does not verify that the email in a PO=
ST /auth-requests/admin-request body belongs to the authenticated caller, a= llowing a low-privileged organization member to obtain another user's vault=
key and a victim-scoped access token by creating a Trusted Device Encrypti=
on authentication request, bound to an attacker-controlled public key, that=
is readable from an unauthenticated endpoint once approved resulting in di= sclosure of the victim's vault key and account takeover.</td> <td>2026-07-08</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60104" target=3D= "_blank" rel=3D"noopener">CVE-2026-60104</a></td>
</tr>
<td class=3D"vendor-product">blakeblackshear--frigate</td>
<td>Frigate is an open source network video recorder. In version 0.17.1, th=
e GET /api/logs/{service} endpoint allows any authenticated user including = the viewer role to download Frigate and nginx logs, exposing auto-generated=
admin passwords and camera credentials logged in request query strings and=
enabling viewer-to-admin privilege escalation. A fixed release has not bee=
n identified.</td>
<td>2026-07-08</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54652" target=3D= "_blank" rel=3D"noopener">CVE-2026-54652</a></td>
</tr>
<td class=3D"vendor-product">blendmedia--WP CTA Call Now Button, Sticky But= ton & Call to Action Builder</td>
<td>The WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin f=
or WordPress is vulnerable to time-based blind SQL Injection via the 'fildn= ame' parameter in all versions up to, and including, 2.2.2. This is due to = insufficient escaping of user-supplied column names in the ajaxCheck() meth=
od and lack of preparation in the $wpdb->update() call. The vulnerabilit=
y is compounded by the complete absence of authorization checks and the end= point being registered for unauthenticated users via wp_ajax_nopriv_. This = makes it possible for unauthenticated attackers to inject arbitrary SQL que= ries and extract sensitive information from the database via time-based bli=
nd SQL injection techniques, including administrator password hashes.</td> <td>2026-07-11</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4661" target=3D"= _blank" rel=3D"noopener">CVE-2026-4661</a></td>
</tr>
<td class=3D"vendor-product">boldgrid--W3 Total Cache</td>
<td>The W3 Total Cache plugin for WordPress is vulnerable to Directory Trav= ersal in all versions up to, and including, 2.9.4 via the setupSources func= tion. This makes it possible for unauthenticated attackers to read the cont= ents of arbitrary files on the server, which can contain sensitive informat= ion. Exploitation requires enabling manual minify mode and supplying a manu= al-format minify filename so that the hash is empty and the f_array[] entri=
es are not overwritten before reaching setupSources().</td>
<td>2026-07-11</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9282" target=3D"= _blank" rel=3D"noopener">CVE-2026-9282</a></td>
</tr>
<td class=3D"vendor-product">brainstormforce--SureForms Drag & Drop Con= tact Form & Form Builder, Payment Form, Survey, Quiz & Calculator</=
<td>The SureForms - Drag and Drop Form Builder for WordPress plugin for Wor= dPress is vulnerable to Improper Input Validation in all versions up to, an=
d including, 2.2.1. This is due to the plugin accepting the payment amount = directly from user-controlled POST data in the 'create_payment_intent' and = 'create_subscription_intent' functions without validating it against the fo= rm's configured price. This makes it possible for unauthenticated attackers=
to modify the payment amount to any arbitrary value when submitting a Stri=
pe payment form, potentially purchasing products or services at significant=
ly reduced prices.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15288" target=3D= "_blank" rel=3D"noopener">CVE-2026-15288</a></td>
</tr>
<td class=3D"vendor-product">Canonical--Ubuntu</td>
<td>A sandbox escape vulnerability exists in the OpenJDK packages provided =
in Ubuntu. The .jar MIME handlers installed by these packages execute files=
marked as executable when the mailcap package is installed. A compromised =
or malicious sandboxed application with access to the OpenURI portal via xd= g-desktop-portal-gtk can write a malicious .jar file to the host file syste=
m, set its executable bit, and trigger the handler to execute arbitrary cod=
e outside of the sandbox environment.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10037" target=3D= "_blank" rel=3D"noopener">CVE-2026-10037</a></td>
</tr>
<td class=3D"vendor-product">Cap--Cap</td>
<td>Cap's GET /api/video/ai endpoint fails to validate user ownership or me= mbership before returning private video AI metadata including titles, summa= ries, and chapters. Authenticated attackers can supply arbitrary video IDs =
to read sensitive AI-generated content and trigger unauthorized AI generati=
on that consumes the video owner's credits without consent.</td> <td>2026-07-07</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59704" target=3D= "_blank" rel=3D"noopener">CVE-2026-59704</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC=
function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and gr= anted to the anon role, allowing unauthenticated access. Because the functi=
on accepts a caller-supplied user UUID without verifying it matches the aut= henticated user, an attacker using only the public publishable API key can = query POST /rest/v1/rpc/get_orgs_v6 with an arbitrary user UUID to retrieve=
that user's organization membership, roles, subscription/trial metadata, a=
nd management_email (PII).</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56226" target=3D= "_blank" rel=3D"noopener">CVE-2026-56226</a></td>
</tr>
<td class=3D"vendor-product">capacitor-updater--capacitor-updater</td>
<td>In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-= end encryption scheme distributes the private key to each device that downl= oads the app. Because the public key can be derived from the private key, a=
n attacker performing a man-in-the-middle attack or compromising the Capgo = server can create a validly signed update bundle and cause devices to insta=
ll an update not produced by the original app maker.</td>
<td>2026-07-10</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56254" target=3D= "_blank" rel=3D"noopener">CVE-2026-56254</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a privilege escalation vulnerability whe=
re demoted super_admin users retain access to delete_non_compliant_bundles = and count_non_compliant_bundles RPCs due to stale org_users.user_right colu=
mn not being cleared during role binding deletion. Attackers can exploit th=
is by maintaining a previously granted super_admin role to enumerate and bu=
lk delete non-compliant bundles across the entire organization indefinitely= .</td>
<td>2026-07-12</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56241" target=3D= "_blank" rel=3D"noopener">CVE-2026-56241</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a broken access control vulnerability in=
the organization management API where a scoped API key (limited_to_orgs) i= nherits its owner-user's permissions, allowing destructive cross-organizati=
on actions. When a user is an admin in two organizations and creates a writ= e-mode API key restricted to one organization, that key can still perform d= estructive operations (e.g., DELETE /organization, DELETE /organization/mem= bers) against another organization. The root cause is route-level authoriza= tion (rbac_check_permission_direct) that evaluates the key owner's user pri= vileges before enforcing the API key's limited_to_orgs scope.</td> <td>2026-07-08</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56246" target=3D= "_blank" rel=3D"noopener">CVE-2026-56246</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authentication bypass vulnerability i=
n the password change endpoint that allows attackers to change user passwor=
ds without requiring current password confirmation. Attackers with temporar=
y session access can exploit this flaw to permanently lock out legitimate u= sers and achieve full account takeover.</td>
<td>2026-07-10</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56305" target=3D= "_blank" rel=3D"noopener">CVE-2026-56305</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a cross-organization account disruption = vulnerability in the SSO prelink endpoint that allows enterprise administra= tors to delete password identities of users in foreign organizations. Attac= kers with org.update_settings permission and an active SSO provider can cal=
l the prelink-users endpoint to permanently remove email-based authenticati=
on for any user matching the provider's email domain, forcing victims to us=
e the attacker's SSO provider or complete password reset recovery.</td> <td>2026-07-12</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56313" target=3D= "_blank" rel=3D"noopener">CVE-2026-56313</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an information disclosure vulnerability =
in the Supabase PostgREST global_stats endpoint that allows unauthenticated=
attackers to read sensitive financial and operational metrics using only t=
he public apikey. Remote attackers can query the /rest/v1/global_stats endp= oint to expose MRR, total revenue, plan-tier revenue breakdown, customer co= unts, and operational telemetry.</td>
<td>2026-07-12</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56238" target=3D= "_blank" rel=3D"noopener">CVE-2026-56238</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 allows upload-scoped API keys to modify the mutab=
le app_versions.r2_path field through PostgREST, enabling retargeting to ar= bitrary R2 bundle objects. Attackers can patch r2_path to point to victim o= bjects, soft-delete the attacker-controlled version, and trigger the on_ver= sion_update cleanup function to delete the victim R2 object, causing denial=
of service and bundle availability disruption.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56250" target=3D= "_blank" rel=3D"noopener">CVE-2026-56250</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an information disclosure vulnerability =
in the get_orgs_v7(userid) RPC function that remains publicly invokable des= pite intended private access controls. Unauthenticated attackers can supply=
arbitrary user UUIDs to retrieve foreign users' organization membership, r= oles, management emails, and billing metadata.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56279" target=3D= "_blank" rel=3D"noopener">CVE-2026-56279</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an information disclosure vulnerability =
in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and=
executable by the anon role. Unauthenticated attackers can call this funct= ion via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitiv=
e API key metadata including user_id, mode, org scoping, and expiration det= ails when supplied a valid key value.</td>
<td>2026-07-11</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56303" target=3D= "_blank" rel=3D"noopener">CVE-2026-56303</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 allows email address changes without requiring cu= rrent password re-authentication or verification of the existing email addr= ess. An attacker with access to a valid session cookie or authenticated bro= wser can change the account email to gain control of account recovery and b= ypass multi-factor authentication protections.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56308" target=3D= "_blank" rel=3D"noopener">CVE-2026-56308</a></td>
</tr>
<td class=3D"vendor-product">Cesanta--Mongoose</td>
<td>Cesanta Mongoose before 7.22 contains an out-of-bounds read in the buil= t-in TLS server function mg_tls_server_recv_hello(), which uses an attacker= -controlled session_id_len byte from a TLS ClientHello as a buffer index wi= thout validating it against the length of received data. A remote, unauthen= ticated attacker can send a single crafted ClientHello with an oversized se= ssion id length to read past the receive buffer, crashing any HTTPS, MQTTS,=
or WSS service built on MG_TLS_BUILTIN.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11404" target=3D= "_blank" rel=3D"noopener">CVE-2026-11404</a></td>
</tr>
<td class=3D"vendor-product">choijun--LA-Studio Element Kit for Elementor</=
<td>The LA-Studio Element Kit for Elementor plugin for WordPress is vulnera= ble to Local File Inclusion in all versions up to, and including, 1.6.1 via=
the get_type_template function. This makes it possible for authenticated a= ttackers, with contributor-level access and above, to include and execute a= rbitrary .php files on the server, allowing the execution of any PHP code i=
n those files. This can be used to bypass access controls, obtain sensitive=
data, or achieve code execution in cases where .php file types can be uplo= aded and included. The wp_normalize_path function used in get_template only=
normalizes directory separators and does not resolve or reject path traver= sal sequences, while the extension check is trivially bypassed because the = caller already appends the required extension to the traversal payload.</td=
<td>2026-07-11</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15338" target=3D= "_blank" rel=3D"noopener">CVE-2026-15338</a></td>
</tr>
<td class=3D"vendor-product">cifi--GEO Plugin by Squirrly SEO</td>
<td>The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Ar= bitrary Post Creation and Stored Cross-Site Scripting in all versions up to=
, and including, 14.0.0 due to a leak of an API token and insufficient inpu=
t sanitization and output escaping. This makes it possible for unauthentica= ted attackers to create arbitrary posts, and, if the Advanced Custom Fields=
plugin is installed and activated, inject arbitrary web scripts in pages t= hat will execute whenever a user accesses an injected page.</td> <td>2026-07-10</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1667" target=3D"= _blank" rel=3D"noopener">CVE-2026-1667</a></td>
</tr>
<td class=3D"vendor-product">cline--cline</td>
<td>Cline is an autonomous coding agent as an SDK, IDE extension, or CLI as= sistant. Prior to 3.0.30, the Cline Hub dashboard server launched by the cl= ine dashboard command accepts WebSocket connections on the /browser endpoin=
t without validating the Origin header, and when ROOM_SECRET is unset for l= ocal 127.0.0.1 binds, isAuthorizedBrowserRequest() allows attacker-controll=
ed websites to send desktopCommand frames that read workspace state, mutate=
MCP and provider settings, and trigger command execution when a provider o=
r model is configured. This issue is fixed in version 3.0.30.</td> <td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59723" target=3D= "_blank" rel=3D"noopener">CVE-2026-59723</a></td>
</tr>
<td class=3D"vendor-product">CloudFoundry Foundation--UAA</td>
<td>A network attacker positioned between UAA and its LDAP directory can im= personate the directory using any certificate from any trusted CA, then har= vest the LDAP bind password and every end-user password sent during simple-= bind authentication, and return forged group memberships that grant themsel= ves admin scopes. This affects every deployment that authenticates users ag= ainst LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0=
; Cf-deployment versions prior to v56.2.0.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47840" target=3D= "_blank" rel=3D"noopener">CVE-2026-47840</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Interview Management System</td=
<td>A weakness has been identified in code-projects Interview Management Sy= stem 1.0. This vulnerability affects unknown code of the file \inc\classes\= View.php. This manipulation of the argument ID causes sql injection. The at= tack can be initiated remotely. The exploit has been made available to the = public and could be used for attacks.</td>
<td>2026-07-09</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15137" target=3D= "_blank" rel=3D"noopener">CVE-2026-15137</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Online Food Order System</td>
<td>A security flaw has been discovered in code-projects Online Food Order = System 1.0. This affects an unknown part of the file /edit_food_items.php. = The manipulation of the argument update results in sql injection. It is pos= sible to launch the attack remotely. The exploit has been released to the p= ublic and may be used for attacks.</td>
<td>2026-07-08</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15135" target=3D= "_blank" rel=3D"noopener">CVE-2026-15135</a></td>
</tr>
<td class=3D"vendor-product">CodeAstro--Simple Online Leave Management Syst= em</td>
<td>A vulnerability was determined in CodeAstro Simple Online Leave Managem= ent System 1.0. Affected by this vulnerability is an unknown functionality =
of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the a= rgument email can lead to sql injection. The attack may be performed from r= emote. The exploit has been publicly disclosed and may be utilized.</td> <td>2026-07-08</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15134" target=3D= "_blank" rel=3D"noopener">CVE-2026-15134</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32= .2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer = certificate chains to a trusted Azure CA but never verifies the PKCS#7 sign= ature itself. An attacker can embed a legitimate Azure certificate alongsid=
e arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` = will be accepted returning the victim workspace agent's session token. No a= uthentication is required. The attacker only needs to know a target VM's `v= mId` which is a `UUIDv4`. That's a practical limitation which would typical=
ly require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, = 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure a=
ny Azure templates to use token authentication rather than `azure-instance-= identity`.</td>
<td>2026-07-07</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46354" target=3D= "_blank" rel=3D"noopener">CVE-2026-46354</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registr=
y module passed unsanitized user input to shell commands, allowing arbitrar=
y code execution inside a provisioned workspace. Any user who supplied a cr= afted `dotfiles_uri` value (for example, one containing shell command subst= itution such as `$(...)`) could achieve command execution in their own work= space. The Create Workspace page's `mode=3Dauto` deep links amplified this = into a one-click attack: an attacker could craft a URL that prefilled `para= m.dotfiles_uri` and silently provisioned a workspace with the attacker-cont= rolled value, with no explicit user confirmation. In versions 2.29.7 and 2.= 30.2, input validation was added to the dotfiles module to reject URIs and = usernames containing special characters, and the unsafe `eval`/`sh -c` usag=
e was removed. This eliminated the command injection at its source.</td> <td>2026-07-07</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44454" target=3D= "_blank" rel=3D"noopener">CVE-2026-44454</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `code=
r config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHCon= figOptions`) into the user's `~/.ssh/config` without sanitizing embedded ne= wlines or restricting directives so a malicious or compromised Coder server=
could inject arbitrary SSH configuration. Practical exploitation requires = control of the server-supplied values through a malicious or compromised de= ployment, a man-in-the-middle position or admin access to the `HostnameSuff= ix` and `SSHConfigOptions` settings. The fix in versions 2.29.7, 2.32.7, 2.= 33.8, and 2.34.2 validates `HostnameSuffix` and `SSHConfigOptions` against =
a strict character set that rejects newlines and other control characters. =
As a workaround, inspect `coder config-ssh --dry-run` output before applyin=
g changes.</td>
<td>2026-07-07</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55427" target=3D= "_blank" rel=3D"noopener">CVE-2026-55427</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the t= ailnet coordinator validates that an agent's `Addresses` derive from its au= thenticated UUID but applies no equivalent check to `AllowedIPs`. The coord= inator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which = install them into the WireGuard peer configuration. The fix in versions 2.2= 9.7, 2.32.7, 2.33.8, and 2.34.2 validates each `AllowedIPs` prefix against = the authenticating agent's UUID just like `Addresses`. As a workaround, mon= itor coordinator logs for agents advertising unexpected `AllowedIPs` prefix= es.</td>
<td>2026-07-07</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55428" target=3D= "_blank" rel=3D"noopener">CVE-2026-55428</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `Upse= rtWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key co= nflict and `insertAgentApp` accepts the app ID from the provisioner's `Comp= leteJob` payload without verifying it belongs to the workspace being built.=
`CompleteJob` runs under `dbauthz.AsProvisionerd` so the authorization lay=
er does not block the cross-workspace upsert. Exploitation requires elevate=
d access as a template author or external provisioner operator. The fix in = versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 verifies that any existing `wor= kspace_apps` row matching the supplied ID belongs to the workspace being bu= ilt and rejects cross-workspace agent reassignment. No known workarounds ar=
e available.</td>
<td>2026-07-08</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55429" target=3D= "_blank" rel=3D"noopener">CVE-2026-55429</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two f= laws in Coder's OIDC login chained into account takeover. Email-based user = matching fell back to linking by email without checking for an existing lin=
k to a different IdP subject and the `email_verified` claim was only enforc=
ed when present as a boolean `false` so an absent or non-boolean claim was = treated as verified. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2=
restricts the email fallback to first-time and legacy linking and defaults=
`email_verified` to false when the claim is absent or of an unexpected typ=
e. As a workaround, configure the OIDC provider to disallow self-registrati=
on or to require email verification before issuing tokens.</td> <td>2026-07-07</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55075" target=3D= "_blank" rel=3D"noopener">CVE-2026-55075</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder=
's OIDC callback checked `email_verified` with a direct Go `bool` type asse= rtion. When an IdP returned the claim as a non-boolean (for example the str= ing `"false"`) or omitted it, the assertion failed open and the email was t= reated as verified. Combined with an unconditional email-based account fall= back, this enabled account takeover. The fix in versions 2.29.7, 2.32.7, 2.= 33.8, and 2.34.2 coerces `email_verified` across bool, string and numeric t= ypes (fail-closed) and blocks the email fallback when the matched user alre= ady has a different linked IdP subject. As a workaround, ensure the IdP ret= urns `email_verified` as a native JSON boolean. The email-fallback linking = issue has no configuration workaround; upgrading is required.</td> <td>2026-07-07</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55076" target=3D= "_blank" rel=3D"noopener">CVE-2026-55076</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `= PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePe= rsonal` and did not prevent a `user-admin` from resetting an `owner` accoun= t's password. It also did not require the current password when an admin re= set another user's password. Exploitation requires the privileged `user-adm= in` role so practical risk is limited to deployments that grant `user-admin=
` to less trusted operators. The fix in versions 2.29.7, 2.32.7, 2.33.8, an=
d 2.34.2 prevents non-owner users from resetting the password of an account=
that holds the `owner` role. As a workaround, restrict the `user-admin` ro=
le to trusted administrators.</td>
<td>2026-07-07</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55077" target=3D= "_blank" rel=3D"noopener">CVE-2026-55077</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `code=
r open app` opens external workspace-app URLs without validating the scheme=
or host. When an external app URL contains the `$SESSION_TOKEN` placeholde=
r the CLI replaces it with the user's real session token before handing the=
URL to the OS open handler. Practical exploitation requires the victim to = run `coder open app` against a workspace whose external app definition the = attacker controls. Only a malicious template author can control external ap=
p URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a UR= L-scheme allowlist in the CLI and limits `$SESSION_TOKEN` substitution to t= rusted destinations like the web frontend. As a workaround, avoid running `= coder open app` for untrusted workspaces.</td>
<td>2026-07-08</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55431" target=3D= "_blank" rel=3D"noopener">CVE-2026-55431</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.= 33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy = server whose default transport set `InsecureSkipVerify: true` and only assi= gned a secure transport when an upstream proxy was configured. In the defau=
lt configuration (no upstream proxy), outbound HTTPS to the Coder access UR=
L accepted any TLS certificate. Practical exploitation requires an on-path = (man-in-the-middle) position between the AI Bridge Proxy and the Coder serv= er. Deployments where they are co-located over loopback are effectively una= ffected. The fix in versions 2.32.7, 2.33.8, and 2.34.2 applies the secure = transport (TLS 1.2 or higher using system root CAs) unconditionally. As a w= orkaround, ensure the Coder access URL uses a trusted certificate and secur=
e the network path between the AI Bridge Proxy and the Coder server (for ex= ample, loopback or mTLS).</td>
<td>2026-07-08</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55436" target=3D= "_blank" rel=3D"noopener">CVE-2026-55436</a></td>
</tr>
<td class=3D"vendor-product">Comfast--CF-WR631AX V3</td>
<td>A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. = Affected by this vulnerability is the function system_wl_upload_pic_file of=
the file /usr/bin/webmgnt of the component FastCGI Backend. This manipulat= ion of the argument filename causes os command injection. It is possible to=
initiate the attack remotely. The exploit has been publicly disclosed and = may be utilized. The vendor was contacted early about this disclosure but d=
id not respond in any way.</td>
<td>2026-07-12</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15511" target=3D= "_blank" rel=3D"noopener">CVE-2026-15511</a></td>
</tr>
<td class=3D"vendor-product">composer--composer</td>
<td>Composer is a dependency Manager for the PHP language. Prior to 2.2.29 = and 2.10.2, a maliciously crafted package from an untrusted repository othe=
r than Packagist.org or Private Packagist can cause Composer to write attac= ker-controlled files outside the vendor directory and outside the project d= uring install or update by using an invalid package name that is not correc= tly validated before dependency-resolution results are written or installed=
. This issue is fixed in versions 2.2.29 and 2.10.2.</td>
<td>2026-07-08</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59948" target=3D= "_blank" rel=3D"noopener">CVE-2026-59948</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewir=
e action in ResourceOperations.php authorizes the source resource but resol= ves destination resources with unscoped Eloquent lookups, allowing an authe= nticated user to clone resources into destinations owned by other teams and=
access cross-tenant resources. This issue is fixed in version 4.0.0-beta.4= 64.</td>
<td>2026-07-07</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34037" target=3D= "_blank" rel=3D"noopener">CVE-2026-34037</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.469, an authenticated remo=
te command injection vulnerability in application deployment handling allow=
s users with application write permissions to achieve remote code execution=
and exfiltrate sensitive environment variables through deployment logs via=
fields such as dockerfile_location and deployment commands. This issue is = fixed in version 4.0.0-beta.469.</td>
<td>2026-07-06</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34038" target=3D= "_blank" rel=3D"noopener">CVE-2026-34038</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bo= otstrap routes did not enforce the expected authorization middleware, allow= ing an authenticated user to access terminal functionality for resources ou= tside the authorized scope and potentially execute commands. This issue is = fixed in version 4.0.0-beta.471.</td>
<td>2026-07-07</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34047" target=3D= "_blank" rel=3D"noopener">CVE-2026-34047</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bo= otstrap routes only check authentication and do not enforce terminal author= ization, allowing a low-privileged team member to connect to terminal route=
s and execute commands on team servers. This issue is fixed in version 4.0.= 0-beta.471.</td>
<td>2026-07-07</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34048" target=3D= "_blank" rel=3D"noopener">CVE-2026-34048</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token se= tting is used in shell commands without sufficient validation, allowing an = authenticated user with access to server Sentinel settings to inject shell = syntax and execute commands on the host when Sentinel is restarted. This is= sue is fixed in version 4.0.0-beta.466.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34034" target=3D= "_blank" rel=3D"noopener">CVE-2026-34034</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.466, log drain secret and = environment values were interpolated into shell commands without sufficient=
encoding, allowing an authenticated user to inject commands executed on th=
e host. This issue is fixed in version 4.0.0-beta.466.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34035" target=3D= "_blank" rel=3D"noopener">CVE-2026-34035</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the database import L= ivewire component (app/Livewire/Project/Database/Import.php) allows client-= controlled container and server properties to reach shell commands without = locking or validation, allowing an authenticated user to inject commands th= rough a database import container name. This issue is fixed in version 4.0.= 0-beta.471.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34057" target=3D= "_blank" rel=3D"noopener">CVE-2026-34057</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the Livewire componen=
t Server\Resources exposes public methods (startUnmanaged, stopUnmanaged, r= estartUnmanaged) that accept a container ID parameter directly from the bro= wser without any sanitization or escaping. This parameter is interpolated d= irectly into shell commands executed via SSH on managed servers, enabling a=
ny authenticated team member to execute arbitrary OS commands on remote ser= vers. This issue is fixed in version 4.0.0-beta.471.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34058" target=3D= "_blank" rel=3D"noopener">CVE-2026-34058</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and po= st-deployment commands are single-quote escaped but then sent through SSH h= eredoc transport that preserves newlines, allowing an authenticated user to=
inject additional shell statements that execute on the remote server durin=
g deployment. This issue is fixed in version 4.0.0-beta.471.</td> <td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34152" target=3D= "_blank" rel=3D"noopener">CVE-2026-34152</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, LocalFileVolume::save= StorageOnServer builds shell commands using unescaped fs_path and parent_di=
r values before validation, and submitFileStorage does not validate the use= r-controlled file-mount path before creating a volume, allowing an authenti= cated user who can add file storage to execute commands when the storage is=
saved. This issue is fixed in version 4.0.0-beta.471.</td>
<td>2026-07-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34153" target=3D= "_blank" rel=3D"noopener">CVE-2026-34153</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker()=
helper wraps user-controlled commands in single quotes without escaping em= bedded single quotes. Attackers who can edit application settings can injec=
t a single quote into docker_compose_custom_build_command or docker_compose= _custom_start_command to break out of the quoted context and execute arbitr= ary commands on the managed server host during deployments, escaping the in= tended Docker container confinement. This issue is fixed in version 4.0.0-b= eta.469.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34158" target=3D= "_blank" rel=3D"noopener">CVE-2026-34158</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVo= lume.name field is interpolated directly into docker volume shell commands = without shell argument escaping, allowing an authenticated user to set a st= orage name containing shell metacharacters and execute commands on managed = servers when the resource is deleted. This issue is fixed in version 4.0.0-= beta.471.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34168" target=3D= "_blank" rel=3D"noopener">CVE-2026-34168</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/= {uuid} endpoint can perform a state-changing password reset using an attack= er-known invitation UUID, allowing an attacker who can cause a victim to vi= sit the crafted invitation URL to reset the victim account password to a pr= edictable value. This issue is fixed in version 4.0.0-beta.471.</td> <td>2026-07-07</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34171" target=3D= "_blank" rel=3D"noopener">CVE-2026-34171</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, there is an authentic= ated command injection vulnerability in the GetLogs Livewire component whic=
h allows users with team membership (lowest privilege member role) to execu=
te arbitrary commands as root on managed servers. The $container Livewire p= ublic property is interpolated directly into shell commands (docker logs, d= ocker service logs) without sanitization, and can be modified by any client=
via the Livewire wire protocol because it lacks the #[Locked] attribute. T= his issue is fixed in version 4.0.0-beta.471.</td>
<td>2026-07-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34599" target=3D= "_blank" rel=3D"noopener">CVE-2026-34599</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, user-controlled persi= stent volume names are interpolated into shell commands executed on managed=
servers without escaping or validation, allowing an authenticated member t=
o inject shell metacharacters and execute commands as root when volume oper= ations are triggered. This issue appears to be fixed in version 4.0.0-beta.= 471.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42143" target=3D= "_blank" rel=3D"noopener">CVE-2026-42143</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthchec=
k command generation used attacker-controlled database settings (postgres_u= ser and postgres_db) in shell-form commands, allowing an authenticated user=
to inject commands executed in the database container. This issue is fixed=
in version 4.0.0-beta.474.</td>
<td>2026-07-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42153" target=3D= "_blank" rel=3D"noopener">CVE-2026-42153</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initializa= tion script (generate_init_scripts() method in app/Actions/Database/StartPo= stgresql.php) filename handling did not sufficiently restrict paths, allowi=
ng an authenticated user to write files outside the intended directory and = achieve command execution through database initialization. This issue is fi= xed in version 4.0.0-beta.474.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42200" target=3D= "_blank" rel=3D"noopener">CVE-2026-42200</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a = regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docke=
r Compose build, start, and pre/post-deployment command fields, allowing an=
authenticated team member to inject shell commands that execute on the hos=
t. This issue is fixed in version 4.0.0-beta.474.</td>
<td>2026-07-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42204" target=3D= "_blank" rel=3D"noopener">CVE-2026-42204</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/Ap= plicationDeploymentJob.php generate_healthcheck_commands() function directl=
y interpolated the health_check_host, health_check_method, and health_check= _path parameters into shell commands without proper sanitization, allowing = authenticated users to execute arbitrary commands inside deployment contain= ers. This issue is fixed in version 4.0.0-beta.469.</td>
<td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59734" target=3D= "_blank" rel=3D"noopener">CVE-2026-59734</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() com= ponent looks up resources by UUID without scoping the lookup to the current=
team, allowing an authenticated user to access logs for applications owned=
by other teams by supplying a victim resource UUID. This issue is fixed in=
version 4.0.0-beta.466.</td>
<td>2026-07-07</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34044" target=3D= "_blank" rel=3D"noopener">CVE-2026-34044</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML = 2.0 token validation does not correctly resolve the issuer signing key or r= equire signed tokens when IdentityConfiguration is used with federated bind= ings, allowing an unauthenticated remote attacker to impersonate any princi= pal the trusted STS could issue. This issue is fixed in versions 1.8.1 and = 1.9.1.</td>
<td>2026-07-08</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54782" target=3D= "_blank" rel=3D"noopener">CVE-2026-54782</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote = attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomain= SocketBinding endpoint can trigger premature EOF handling in the CoreWCF ne= t.tcp, net.pipe, or net.uds framing handshake and pin one server thread-poo=
l worker at full CPU per connection. This issue is fixed in versions 1.8.1 = and 1.9.1.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54772" target=3D= "_blank" rel=3D"noopener">CVE-2026-54772</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final=
SignatureValue verification when a CoreWCF service validates SAML tokens u= sing a non-X.509 signing token, allowing an attacker to reference a non-X.5=
09 SecurityToken key identifier and bypass assertion signature verification=
. This issue is fixed in versions 1.8.1 and 1.9.1.</td>
<td>2026-07-08</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54774" target=3D= "_blank" rel=3D"noopener">CVE-2026-54774</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validat= ion does not enforce SubjectConfirmation method URIs or holder-of-key proof=
keys in SamlSecurityTokenHandler, allowing holder-of-key downgrade or cust=
om confirmation method assertions to authenticate a subject without proving=
authority over the assertion. This issue is fixed in versions 1.8.1 and 1.= 9.1.</td>
<td>2026-07-08</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54781" target=3D= "_blank" rel=3D"noopener">CVE-2026-54781</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endors= ing and supporting signature verification does not ensure the selected ds:S= ignature covers the expected Security header target, allowing an attacker w= ith one captured signed SOAP envelope to replay arbitrary service operation=
s as the victim principal. This issue is fixed in versions 1.8.1 and 1.9.1.= </td>
<td>2026-07-08</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54783" target=3D= "_blank" rel=3D"noopener">CVE-2026-54783</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToke=
n negotiation can expose the proof key recovered from the RSTR when Transpo= rtWithMessageCredential with Windows client credentials and session establi= shment are used, allowing an observer to impersonate the authenticated Wind= ows principal and decrypt or forge WS-SecureConversation traffic. This issu=
e is fixed in version 1.9.1.</td>
<td>2026-07-08</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54784" target=3D= "_blank" rel=3D"noopener">CVE-2026-54784</a></td>
</tr>
<td class=3D"vendor-product">corvusinfo--CorvusPay WooCommerce Payment Gate= way</td>
<td>The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulne= rable to Stored Cross-Site Scripting via the 'approval_code' parameter in a=
ll versions up to, and including, 2.7.4 due to insufficient input sanitizat= ion and output escaping. This makes it possible for unauthenticated attacke=
rs to inject arbitrary web scripts in pages that will execute whenever a us=
er accesses an injected page. The unauthenticated REST endpoint POST /wp-js= on/corvuspay/success/ is registered with permission_callback set to __retur= n_true, and although a signature validation step exists it only logs the re= sult without halting execution, meaning an attacker can supply a completely=
arbitrary signature and have a malicious approval_code stored in the datab= ase unchallenged.</td>
<td>2026-07-11</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6939" target=3D"= _blank" rel=3D"noopener">CVE-2026-6939</a></td>
</tr>
<td class=3D"vendor-product">Cotonti--Cotonti</td>
<td>Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery = vulnerability that allows unauthenticated attackers to modify administrator=
configuration by tricking a logged-in administrator into submitting a forg=
ed POST request to the admin.php config update handler, which never invokes=
the application's CSRF validation function. Attackers can disable the PFS = module's file extension whitelist by setting pfsfilecheck to 0, enabling an=
y user with PFS access to upload and execute arbitrary PHP files on the ser= ver.</td>
<td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58143" target=3D= "_blank" rel=3D"noopener">CVE-2026-58143</a></td>
</tr>
<td class=3D"vendor-product">coturn--coturn</td>
<td>Coturn is a free open source implementation of TURN and STUN Server. Pr= ior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters di= rectly into SQL queries via snprintf string interpolation without sanitizat= ion. The is_secure_string filter that protects the STUN protocol path is no=
t applied to the admin panel's delete-user, delete-secret, and delete-IP op= erations, so an authenticated admin can inject arbitrary SQL through the du=
, ds, and dip parameters, gaining full database control and potentially OS-= level access via PostgreSQL COPY TO PROGRAM. This issue is fixed in version=
4.12.0.</td>
<td>2026-07-10</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53448" target=3D= "_blank" rel=3D"noopener">CVE-2026-53448</a></td>
</tr>
<td class=3D"vendor-product">coturn--coturn</td>
<td>Coturn is a free open source implementation of TURN and STUN Server. Pr= ior to 4.13.0, coturn rejects loopback peers by default unless allow-loopba= ck-peers is enabled, but the default loopback guard can be bypassed by usin=
g the IPv4-mapped IPv6 peer address ::ffff:127.0.0.1 in a TURN XOR-PEER-ADD= RESS attribute. ioa_addr_is_loopback checks for the literal IPv6 loopback s= hape before IPv4-mapped IPv6 handling, so good_peer_addr does not apply the=
default loopback rejection and an authenticated TURN client can expose ser= vices bound only to localhost on the coturn host through TURN relay traffic=
. This issue is fixed in version 4.13.0.</td>
<td>2026-07-10</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53450" target=3D= "_blank" rel=3D"noopener">CVE-2026-53450</a></td>
</tr>
<td class=3D"vendor-product">Crawl4AI--Crawl4AI</td>
<td>Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in=
the Docker API server's /screenshot and /pdf endpoints. The output_path pa= rameter accepts arbitrary filesystem paths without validation, allowing an = attacker to supply absolute or path-traversal values to write to any locati=
on writable by the application's user, overwriting server files and causing=
denial of service.</td>
<td>2026-07-12</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56260" target=3D= "_blank" rel=3D"noopener">CVE-2026-56260</a></td>
</tr>
<td class=3D"vendor-product">Crawl4AI--Crawl4AI</td>
<td>Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities =
in the Docker API server that allow attackers to redirect LLM API calls to = attacker-controlled endpoints and read arbitrary environment variables. Att= ackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by=
supplying a malicious base_url parameter and setting api_token to env:VARI= ABLE_NAME to exfiltrate provider API keys and server secrets including JWT = SECRET_KEY for authentication bypass.</td>
<td>2026-07-12</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56259" target=3D= "_blank" rel=3D"noopener">CVE-2026-56259</a></td>
</tr>
<td class=3D"vendor-product">Crawl4AI--Crawl4AI</td>
<td>Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vul= nerability in the Docker API server's /crawl/job and /llm/job endpoints, wh= ich accept webhook URLs without destination validation. An attacker can sup= ply webhook URLs pointing to private or internal IP ranges, Docker networks=
, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to=
make requests to internal services and potentially expose cloud metadata.<=
<td>2026-07-10</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56261" target=3D= "_blank" rel=3D"noopener">CVE-2026-56261</a></td>
</tr>
<td class=3D"vendor-product">Creative Themes--Blocksy Companion</td> <td>Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an un= authenticated arbitrary file upload vulnerability that allows attackers to = upload executable files by bypassing extension validation in the save_attac= hments function exposed through the Advanced Reviews feature. Attackers can=
exploit the Custom Fonts extension's flawed strpos() substring check by up= loading double-extension filenames such as shell.woff2.php, causing the val= idation to pass on the substring match while the web server executes the fi=
le as PHP, achieving remote code execution.</td>
<td>2026-07-08</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58480" target=3D= "_blank" rel=3D"noopener">CVE-2026-58480</a></td>
</tr>
<td class=3D"vendor-product">creativethemeshq--Blocksy Companion</td>
<td>The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary F= ile Upload in all versions up to, and including, 2.1.46 via the save_attach= ments function. This is due to the Custom Fonts extension registering a wp_= check_filetype_and_ext filter that approves any filename containing .woff2 =
or .ttf as a substring via strpos() rather than validating that those strin=
gs appear as the final extension via PATHINFO_EXTENSION - allowing double-e= xtension filenames such as shell.woff2.php to pass MIME validation and be h= andled as permitted font files. This makes it possible for unauthenticated = attackers to upload files that may be executable, which makes remote code e= xecution possible. This vulnerability is only exploitable when the premium = version of the plugin (blocksy-companion-pro) is installed with both the Wo= oCommerce Extra (Advanced Reviews) and Custom Fonts extensions active; the = free blocksy-companion plugin does not contain the vulnerable code paths.</=
<td>2026-07-09</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15158" target=3D= "_blank" rel=3D"noopener">CVE-2026-15158</a></td>
</tr>
<td class=3D"vendor-product">cyberlord92--miniOrange OTP Login, Verificatio=
n and SMS Notifications</td>
<td>The miniOrange OTP Login, Verification and SMS Notifications plugin for=
WordPress is vulnerable to Authentication Bypass leading to Administrator = Account Takeover in all versions up to, and including, 5.5.1. This is due t=
o the `um_reset_password_process_hook()` function performing no server-side=
verification that the OTP validation step was completed, and relying solel=
y on a public `form_nonce` nonce that the plugin itself emits to unauthenti= cated visitors via the `moumprvar` JavaScript object on the Ultimate Member=
password reset page, while still accepting the attacker-controlled `userna= me_b` parameter to target any WordPress user without role restriction or an=
y binding to a previously validated OTP session. This makes it possible for=
unauthenticated attackers to obtain a freshly generated password-reset URL=
for an arbitrary Administrator account - returned in a 302 `Location` head=
er - and use it to take full control of that account. Exploitation requires=
the Ultimate Member Password Reset Form integration to be active and the p= lugin to not be configured for phone-only reset.</td>
<td>2026-07-09</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14245" target=3D= "_blank" rel=3D"noopener">CVE-2026-14245</a></td>
</tr>
<td class=3D"vendor-product">cyberlord92--miniOrange Social Login and Regis= ter (Discord, Google, Twitter, LinkedIn)</td>
<td>The miniOrange Social Login and Register (Discord, Google, Twitter, Lin= kedIn) plugin for WordPress is vulnerable to authentication bypass leading =
to account takeover in versions up to and including 7.7.0. This is due to t=
he Profile Completion flow accepting an arbitrary email address via the 'em= ail_field' POST parameter without verifying that the email belongs to the i= dentity returned by the OAuth provider, combined with send_otp_token() retu= rning the SHA-512(customer_key || otp) transaction hash to the client where=
the OTP space is only 99,000 values (wp_rand(1000, 99999)) and the custome= r_key is a static option (empty on unregistered installs). This makes it po= ssible for unauthenticated attackers to trigger an OTP email to an arbitrar=
y admin's address, crack the OTP offline from the leaked hash in under a se= cond, and submit the cracked OTP to mo_openid_social_login_validate_otp(), = which logs the attacker in as the user whose email was supplied - granting = full administrator access.</td>
<td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12761" target=3D= "_blank" rel=3D"noopener">CVE-2026-12761</a></td>
</tr>
<td class=3D"vendor-product">D-link--DIR-823G</td>
<td>A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Af= fected by this vulnerability is an unknown functionality of the file /etc/b= oa/boa.conf of the component Web Interface. Executing a manipulation can le=
ad to least privilege violation. The attack can be launched remotely. The a= ttack requires a high level of complexity. The exploitation appears to be d= ifficult. The exploit has been made available to the public and could be us=
ed for attacks.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15270" target=3D= "_blank" rel=3D"noopener">CVE-2026-15270</a></td>
</tr>
<td class=3D"vendor-product">danieliser--Popup Maker Boost Sales, Conversio= ns, Optins, Subscribers with the Ultimate WP Popup Builder</td>
<td>The Popup Maker - Boost Sales, Conversions, Optins, Subscribers with th=
e Ultimate WP Popup Builder plugin for WordPress is vulnerable to authoriza= tion bypass in all versions up to, and including, 1.22.0. This is due to th=
e plugin not properly verifying that a user is authorized to perform an act= ion. This makes it possible for authenticated attackers, with editor-level = access and above, to install and activate an arbitrary plugin from an attac= ker-controlled URL, leading to remote code execution. Exploitation requires=
that a valid Popup Maker Pro license is active on the target site and that=
Popup Maker Pro is not yet installed, as these conditions are necessary fo=
r the legacy v1/connect/info endpoint to issue the bearer token used to sat= isfy the install endpoint's only non-spoofable validation check.</td> <td>2026-07-09</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8848" target=3D"= _blank" rel=3D"noopener">CVE-2026-8848</a></td>
</tr>
<td class=3D"vendor-product">Dassault Systmes--DELMIA Apriso</td>
<td>An Improper Authentication vulnerability affecting DELMIA Apriso from R= elease 2020 through Release 2026 could allow an attacker to gain privileged=
access to the server.</td>
<td>2026-07-08</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9695" target=3D"= _blank" rel=3D"noopener">CVE-2026-9695</a></td>
</tr>
<td class=3D"vendor-product">decolua--9router</td>
<td>9Router is an AI router & token saver. Prior to 0.4.80, the /api/se= ttings/database endpoint allows full database export (containing all creden= tials, API keys, OAuth tokens, and settings) and full database import (comp= lete overwrite) without any authentication requirement beyond the ALWAYS_PR= OTECTED middleware check, which only validates JWT or CLI token. This issue=
is fixed in version 0.4.80.</td>
<td>2026-07-10</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55500" target=3D= "_blank" rel=3D"noopener">CVE-2026-55500</a></td>
</tr>
<td class=3D"vendor-product">decolua--9router</td>
<td>9Router before 0.4.44 contains an OS command injection vulnerability in=
the unauthenticated POST /api/tunnel/tailscale-install endpoint (this rout=
e is not covered by the dashboard middleware matcher, so no authorization c= heck is applied). The sudoPassword field from the request body is written t=
o the stdin of a 'sudo -S sh' child process. When sudo does not prompt for =
a password (the process runs as root, NOPASSWD is configured, or a recent s= udo timestamp cache exists), the sudoPassword value is interpreted by sh as=
a shell command, allowing a remote unauthenticated attacker to execute arb= itrary OS commands. Exploitation evidence was first observed by the Shadows= erver Foundation on 2026-07-04 (UTC).</td>
<td>2026-07-07</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59800" target=3D= "_blank" rel=3D"noopener">CVE-2026-59800</a></td>
</tr>
<td class=3D"vendor-product">decolua--9router</td>
<td>9Router is an AI router & token saver. Prior to 0.5.2, 9router prot= ects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but om= its /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A=
remote unauthenticated attacker can send requests to /codex/* to bypass th=
e API-key gate and cause the server to make upstream provider calls using o= perator-stored LLM provider credentials. This issue is fixed in version 0.5= .2.</td>
<td>2026-07-10</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55638" target=3D= "_blank" rel=3D"noopener">CVE-2026-55638</a></td>
</tr>
<td class=3D"vendor-product">decolua--9router</td>
<td>9Router is an AI router & token saver. Prior to 0.5.2, 9router dete= rmines whether a /v1 LLM proxy request is local by reading the client-contr= olled Host header, allowing a remote unauthenticated attacker to send Host:=
localhost and bypass API-key authentication. In the default configuration,=
this exposes the /v1 proxy to upstream provider calls using stored provide=
r credentials and allows /v1/search with the searxng provider_options.baseU=
rl parameter to drive server-side requests to internal or cloud-metadata ho= sts. This issue is fixed in version 0.5.2.</td>
<td>2026-07-10</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55641" target=3D= "_blank" rel=3D"noopener">CVE-2026-55641</a></td>
</tr>
<td class=3D"vendor-product">decolua--9router</td>
<td>9Router is an AI router & token saver. Prior to 0.5.2, 9router trea=
ts loopback requests as trusted and allows /v1/* access without an API key,=
so a same-host reverse proxy that forwards public traffic to the backend t= hrough 127.0.0.1 causes src/dashboardGuard.js to misclassify external reque= sts as local. A remote unauthenticated attacker can access /v1 APIs such as=
/v1/models and may abuse configured upstream provider credentials through = /v1 proxy endpoints depending on enabled providers. This issue is fixed in = version 0.5.2.</td>
<td>2026-07-10</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56675" target=3D= "_blank" rel=3D"noopener">CVE-2026-56675</a></td>
</tr>
<td class=3D"vendor-product">decolua--9router</td>
<td>9Router is an AI router & token saver. Prior to 0.4.80, the dashboa=
rd login rate limiter in src/lib/auth/loginLimiter.js derives the client id= entity from the attacker-controlled X-Forwarded-For HTTP header, and src/ap= p/api/auth/login/route.js uses that spoofable value for checkLock and recor= dFail. A remote attacker can rotate the X-Forwarded-For value on each login=
attempt to receive a fresh rate-limit bucket, bypass the 5-attempt thresho=
ld and progressive lockout durations, and perform unlimited brute-force att= empts against the dashboard password. This issue is fixed in version 0.4.80= .</td>
<td>2026-07-10</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55501" target=3D= "_blank" rel=3D"noopener">CVE-2026-55501</a></td>
</tr>
<td class=3D"vendor-product">decolua--9router</td>
<td>9Router is an AI router & token saver. Prior to 0.5.2, 9router vali= dates image URLs by resolving the host before fetching, but open-sse/transl= ator/concerns/image.js performs the later server-side image fetch with a se= parate DNS resolution. An authenticated attacker with access to the LLM pro=
xy can use a vision-capable model and an attacker-controlled DNS name that = first resolves to a public IP and then rebinds to an internal address, allo= wing server-side requests to internal-only HTTP services. This issue is fix=
ed in version 0.5.2.</td>
<td>2026-07-10</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56676" target=3D= "_blank" rel=3D"noopener">CVE-2026-56676</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex Manager</td>
<td>Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Imprope=
r Neutralization of Special Elements used in an OS Command ('OS Command Inj= ection') vulnerability. A high privileged attacker with remote access could=
potentially exploit this vulnerability during OS Repository processing to = achieve arbitrary command execution as root, potentially leading to full ap= pliance compromise and lateral movement into managed infrastructure.</td> <td>2026-07-10</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56688" target=3D= "_blank" rel=3D"noopener">CVE-2026-56688</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex Manager</td>
<td>Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Imprope=
r Neutralization of Special Elements used in an SQL Command ('SQL Injection=
') vulnerability. A low privileged attacker with remote access could potent= ially exploit this vulnerability, leading to Information disclosure, Inform= ation exposure, and Unauthorized access.</td>
<td>2026-07-10</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56690" target=3D= "_blank" rel=3D"noopener">CVE-2026-56690</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerFlex Manager</td>
<td>Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Imprope=
r Neutralization of Special Elements used in an SQL Command ('SQL Injection=
') vulnerability. A low privileged attacker with remote access could potent= ially exploit this vulnerability, leading to Information exposure.</td> <td>2026-07-10</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56689" target=3D= "_blank" rel=3D"noopener">CVE-2026-56689</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Domain</td>
<td>Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 re= lease version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 thr= ough 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain =
an improper limitation of a pathname to a restricted directory ('Path Trave= rsal') vulnerability. An unauthenticated attacker with remote access could = potentially exploit this vulnerability, leading to unauthorized access to t=
he system. This is a critical severity vulnerability as it allows an attack=
er to take complete control of system; so Dell recommends customers to upgr= ade at the earliest opportunity.</td>
<td>2026-07-07</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53481" target=3D= "_blank" rel=3D"noopener">CVE-2026-53481</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Domain</td>
<td>Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 re= lease version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 thr= ough 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an impro= per authentication vulnerability. An unauthenticated attacker with remote a= ccess could potentially exploit this vulnerability, leading to unauthorized=
access. This is a critical severity vulnerability as it allows an attacker=
to take complete control of system; so Dell recommends customers to upgrad=
e at the earliest opportunity.</td>
<td>2026-07-07</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53483" target=3D= "_blank" rel=3D"noopener">CVE-2026-53483</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Domain</td>
<td>Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 re= lease version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 thr= ough 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain =
an Incorrect Authorization vulnerability. A low privileged attacker with re= mote access could potentially exploit this vulnerability, leading to unauth= orized access.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56086" target=3D= "_blank" rel=3D"noopener">CVE-2026-56086</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Domain</td>
<td>Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 re= lease version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 thr= ough 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain =
a stored cross-site scripting vulnerability. An unauthenticated attacker wi=
th remote access could potentially exploit this vulnerability. Exploitation=
may lead to information disclosure, session theft, or client-side request = forgery.</td>
<td>2026-07-08</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41122" target=3D= "_blank" rel=3D"noopener">CVE-2026-41122</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Domain</td> <td>Dell=C2=A0PowerProtect=C2=A0Data Domain, versions 7.7.1.0 through 8.7, = LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8= .3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.7= 0=C2=A0contain-an improper neutralization of special elements used in an OS= =C2=A0command ('OS=C2=A0command Injection') vulnerability.=C2=A0A=C2=A0remo= te=C2=A0high=C2=A0privileged attacker could potentially exploit this vulner= ability, leading to=C2=A0protection mechanism bypass.=C2=A0This is a Critic=
al vulnerability as it allows an attacker=C2=A0to=C2=A0invoke arbitrary com= mand execution with root privileges;=C2=A0so=C2=A0Dell recommends customers=
to upgrade at the earliest opportunity.</td>
<td>2026-07-07</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53479" target=3D= "_blank" rel=3D"noopener">CVE-2026-53479</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Domain</td>
<td>Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 re= lease version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 thr= ough 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain =
an Integer overflow or wraparound vulnerability. An unauthenticated attacke=
r with remote access could potentially exploit this vulnerability, leading =
to denial of service.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53482" target=3D= "_blank" rel=3D"noopener">CVE-2026-53482</a></td>
</tr>
<td class=3D"vendor-product">Dell--Unisphere for PowerMax</td>
<td>Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) =
a Deserialization of Untrusted Data vulnerability. A low privileged attacke=
r with remote access could potentially exploit this vulnerability, leading =
to arbitrary command execution with root privileges.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54469" target=3D= "_blank" rel=3D"noopener">CVE-2026-54469</a></td>
</tr>
<td class=3D"vendor-product">dgraph-io--dgraph</td>
<td>Dgraph is an open source distributed GraphQL database. Prior to version=
25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on=
the public gRPC port `:9080` without authentication or authorization. As a=
result, an unauthenticated network client can open `StreamExtSnapshot` and=
send Badger stream data to the target group's store. In addition, the rece= iver calls `Prepare()` before processing the stream. This operation deletes=
and replaces the existing DB data. Version 25.3.5 patches the issue.</td> <td>2026-07-08</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54061" target=3D= "_blank" rel=3D"noopener">CVE-2026-54061</a></td>
</tr>
<td class=3D"vendor-product">dgraph-io--dgraph</td>
<td>Dgraph is an open source distributed GraphQL database. Prior to version=
25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to D=
QL (Dgraph Query Language) injection. User-supplied password values are int= erpolated directly into a DQL `checkpwd()` query via `fmt.Sprintf` without = any escaping or parameterization. An attacker can inject a password contain= ing a double-quote character to break out of the DQL string literal and app= end arbitrary DQL query blocks. Version 25.3.4 patches the issue.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44840" target=3D= "_blank" rel=3D"noopener">CVE-2026-44840</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered=
users to set primary_group_id and gain whisper-group privileges without le= gitimate group membership on sites with whispers_allowed_groups configured.=
This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5= .</td>
<td>2026-07-09</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44787" target=3D= "_blank" rel=3D"noopener">CVE-2026-44787</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacke= r-controlled account was not escaped in the delete confirmation dialog, all= owing stored cross-site scripting when an administrator impersonated that a= ccount. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2= 026.1.5.</td>
<td>2026-07-09</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53963" target=3D= "_blank" rel=3D"noopener">CVE-2026-53963</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, pr= ocessing of PDF uploads could be exploited to obtain RCE on the server. Thi=
s issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.</td> <td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55420" target=3D= "_blank" rel=3D"noopener">CVE-2026-55420</a></td>
</tr>
<td class=3D"vendor-product">Divi Engine--Divi Form Builder</td>
<td>The Divi Form Builder plugin for WordPress is vulnerable to Missing Aut= horization in versions up to, and including, 5.1.8. This is due to the upda= te_user() function accepting a user ID parameter from form submissions with= out verifying that the authenticated user has permission to edit that speci= fic user account, and the handle_register_submission() function only checki=
ng if any user is logged in rather than validating permissions for the targ=
et user. This makes it possible for authenticated attackers, with subscribe= r-level access and above, to change the email address and password of any u= ser account, including administrators, resulting in complete account takeov= er.</td>
<td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5523" target=3D"= _blank" rel=3D"noopener">CVE-2026-5523</a></td>
</tr>
<td class=3D"vendor-product">e4jvikwp--VikBooking Hotel Booking Engine &=
; PMS</td>
<td>The VikBooking Hotel Booking Engine & PMS plugin for WordPress is v= ulnerable to Stored Cross-Site Scripting via the 'special_requests' paramet=
er in all versions up to, and including, 1.8.8 due to insufficient input sa= nitization and output escaping. This makes it possible for unauthenticated = attackers to inject arbitrary web scripts in pages that will execute whenev=
er a user accesses an injected page.</td>
<td>2026-07-08</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6818" target=3D"= _blank" rel=3D"noopener">CVE-2026-6818</a></td>
</tr>
<td class=3D"vendor-product">e4jvikwp--VikBooking Hotel Booking Engine &=
; PMS</td>
<td>The VikBooking Hotel Booking Engine & PMS plugin for WordPress is v= ulnerable to Stored Cross-Site Scripting via the 'email' parameter in all v= ersions up to, and including, 1.8.8 due to insufficient input sanitization = and output escaping. This makes it possible for unauthenticated attackers t=
o inject arbitrary web scripts in pages that will execute whenever a user a= ccesses an injected page.</td>
<td>2026-07-08</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6820" target=3D"= _blank" rel=3D"noopener">CVE-2026-6820</a></td>
</tr>
<td class=3D"vendor-product">elysiajs--elysia</td>
<td>Elysia is a Typescript framework for request validation, type inference=
, OpenAPI documentation, and client-server communication. Prior to 1.4.29, = Elysia uses getAll in form data normalization for multipart/form-data endpo= ints, causing the amount of work to grow quadratically with the number of u= nique key-value pairs and allowing CPU exhaustion. This issue is fixed in v= ersion 1.4.29.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56669" target=3D= "_blank" rel=3D"noopener">CVE-2026-56669</a></td>
</tr>
<td class=3D"vendor-product">espressif--esp-idf</td>
<td>ESF-IDF is the Espressif Internet of Things (IOT) Development Framework=
. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possibly prior contain an out-of= -bounds write in jpeg_parse_dqt_marker() in components/esp_driver_jpeg/jpeg= _parse_marker.c because the attacker-controlled DQT marker Tq nibble is use=
d as an index into the qt_tbl array without validating that it is in the ra= nge 0..3, allowing malformed JPEG input to corrupt stack memory and reliabl=
y trigger a denial of service. This issue is fixed in version 6.0.2 and is = expected to be fixed in versions 5.5.5, 5.4.5, and 5.3.6.</td> <td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55687" target=3D= "_blank" rel=3D"noopener">CVE-2026-55687</a></td>
</tr>
<td class=3D"vendor-product">Esri--ArcGIS Server</td>
<td>Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS=
Enterprise on Kubernetes is not impacted. An unauthenticated attacker coul=
d exploit this issue by sending crafted path parameters. Successful exploit= ation could allow overwriting sensitive files on the system. Abuse of this = issue can allow full administrative access to ArcGIS Server, with high impa=
ct to confidentiality, integrity, and availability. This issue impacts all = versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue d= oes not impact ArcGIS Enterprise for Kubernetes.</td>
<td>2026-07-06</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9181" target=3D"= _blank" rel=3D"noopener">CVE-2026-9181</a></td>
</tr>
<td class=3D"vendor-product">Esri--ArcGIS Server</td>
<td>Esri ArcGIS Server contains an unrestricted file upload vulnerability. =
An unauthenticated attacker could exploit this issue by uploading a crafted=
file to the affected endpoint. Successful exploitation could allow arbitra=
ry file upload, potentially allowing for other attacks. This issue impacts = all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This iss=
ue does not impact ArcGIS Enterprise for Kubernetes.</td>
<td>2026-07-06</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9182" target=3D"= _blank" rel=3D"noopener">CVE-2026-9182</a></td>
</tr>
<td class=3D"vendor-product">Esri--Portal for ArcGIS</td>
<td>Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and = Kubernetes have a missing authentication for critical function vulnerabilit=
y allows a remote, unauthenticated attacker to access an unprotected API.</=
<td>2026-07-07</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13019" target=3D= "_blank" rel=3D"noopener">CVE-2026-13019</a></td>
</tr>
<td class=3D"vendor-product">Esri--Portal for ArcGIS</td>
<td>A Weak Password Recovery Mechanism for Forgotten Password exists in Esr=
i Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kuberne= tes. A remote, unauthorized attacker may assume ownership of a user's accou=
nt by manipulating this mechanism. ArcGIS Administrators should configure a=
n email server with ArcGIS Enterprise to facilitate user self-service passw= ord recovery. The ability for an administrator to reset a user's password r= emains unchanged.</td>
<td>2026-07-07</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13020" target=3D= "_blank" rel=3D"noopener">CVE-2026-13020</a></td>
</tr>
<td class=3D"vendor-product">EverMind-AI--EverOS</td>
<td>EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulner= able to path traversal in the POST /api/v1/memory/add ingestion endpoint be= cause the per-message sender_id field was not validated as a path-safe iden= tifier, unlike app_id and project_id. During user-memory extraction, sender= _id is used as owner_id and joined into the filesystem path where the extra= cted episode is persisted as a Markdown file, so a sender_id containing ../=
sequences could direct writes outside the configured memory root and allow=
an unauthenticated caller to create or overwrite .md files at locations wr= itable by the server process with partially attacker-influenced content. Th=
is issue is fixed in version 1.0.1.</td>
<td>2026-07-10</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58499" target=3D= "_blank" rel=3D"noopener">CVE-2026-58499</a></td>
</tr>
<td class=3D"vendor-product">flaskbb--flaskbb</td>
<td>FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorizati=
on bypass vulnerability that allows authenticated moderators to perform una= uthorized actions on topics in forums they do not control by submitting cra= fted topic ID lists. Attackers can include a low-ID topic from a permitted = forum as an anchor in a batch request, causing the permission check applied=
only to the first result to pass, and then execute lock, unlock, delete, o=
r hide actions against topics in unmoderated forums.</td>
<td>2026-07-10</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22659" target=3D= "_blank" rel=3D"noopener">CVE-2026-22659</a></td>
</tr>
<td class=3D"vendor-product">flaskbb--flaskbb</td>
<td>FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw v= ulnerability that allows authenticated administrators to delete all built-i=
n authorization groups by exploiting a type mismatch in the bulk delete pro= tection check. The bulk AJAX endpoint in the management views compares rece= ived JSON integer group IDs against string literals, causing the protection=
check to always pass, which allows deletion of all six built-in groups and=
destroys the forum's permission model, potentially rendering the site unus= able.</td>
<td>2026-07-10</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22660" target=3D= "_blank" rel=3D"noopener">CVE-2026-22660</a></td>
</tr>
<td class=3D"vendor-product">Flowise--Flowise</td>
<td>Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak h= ardcoded default JWT secrets ('auth_token', 'refresh_token') and default au= dience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport = authentication middleware (packages/server/src/enterprise/middleware/passpo= rt/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_= SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, th=
e application silently falls back to these publicly known defaults, allowin=
g an attacker to forge valid JWTs and impersonate any user, including admin= istrators, resulting in authentication bypass.</td>
<td>2026-07-12</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56271" target=3D= "_blank" rel=3D"noopener">CVE-2026-56271</a></td>
</tr>
<td class=3D"vendor-product">fluent--fluentd</td>
<td>Fluentd collects events from various data sources and writes them to fi= les, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd a= llows dynamically constructing file paths using the ${tag} placeholder, and=
insufficient validation of ${tag} in file configurations such as the path = parameter of the out_file plugin allows attackers sending untrusted tags co= ntaining path traversal characters to write or overwrite arbitrary files an=
d potentially achieve remote code execution. This issue is fixed in version=
1.19.3.</td>
<td>2026-07-08</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44024" target=3D= "_blank" rel=3D"noopener">CVE-2026-44024</a></td>
</tr>
<td class=3D"vendor-product">fluent--fluentd</td>
<td>Fluentd collects events from various data sources and writes them to fi= les, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's=
Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin = information via a REST API, and responses from /api/plugins.json and relate=
d endpoints unintentionally include internal instance variables that may co= ntain database passwords, API keys, or cloud credentials. This issue is fix=
ed in version 1.19.3.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44025" target=3D= "_blank" rel=3D"noopener">CVE-2026-44025</a></td>
</tr>
<td class=3D"vendor-product">fluent--fluentd</td>
<td>Fluentd collects events from various data sources and writes them to fi= les, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's=
in_http and in_forward plugins support gzip-compressed data but enforce li= mits only on compressed payloads through settings such as body_size_limit a=
nd chunk_size_limit, allowing crafted compressed payloads to decompress in = memory to an excessive size and cause denial of service through memory exha= ustion. This issue is fixed in version 1.19.3.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44160" target=3D= "_blank" rel=3D"noopener">CVE-2026-44160</a></td>
</tr>
<td class=3D"vendor-product">fluent--fluentd</td>
<td>Fluentd collects events from various data sources and writes them to fi= les, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluen=
td out_http output plugin allows placeholders such as ${tag} in the endpoin=
t configuration parameter, and if a placeholder value is derived from untru= sted input an attacker can control the destination hostname of outbound HTT=
P requests and force requests to arbitrary internal services. This issue is=
fixed in version 1.19.3.</td>
<td>2026-07-08</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44161" target=3D= "_blank" rel=3D"noopener">CVE-2026-44161</a></td>
</tr>
<td class=3D"vendor-product">Flux159--mcp-server-kubernetes</td>
<td>MCP Server Kubernetes before 3.9.0 contains an argument injection vulne= rability in structured tools (kubectl_get, kubectl_describe, kubectl_delete=
) that allows attackers to bypass the assertNoDangerousFlags security check=
by supplying resourceType and name parameters with leading dashes. Attacke=
rs can inject the --server flag to redirect kubectl commands to an attacker= -controlled API server, causing the operator's bearer token to be transmitt=
ed externally and enabling full cluster compromise.</td>
<td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61459" target=3D= "_blank" rel=3D"noopener">CVE-2026-61459</a></td>
</tr>
<td class=3D"vendor-product">FluxInk--Color Management Driver</td>
<td>FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPer= ipheral64.sys) 1.0.7.2 allows local privilege escalation for a standard use=
r account via arbitrary physical memory mapping at \Device\PhysicalMemory. = Fixed in version 1.0.7.6. The fixed driver is currently available in the Wi= ndows 11 25H2 HLK (Hardware Lab Kit). The fixed driver may be available thr= ough Windows Update or from Lenovo directly.</td>
<td>2026-07-07</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58583" target=3D= "_blank" rel=3D"noopener">CVE-2026-58583</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The user-controllable executable files will be directly executed by hig= h-privilege processes, allowing low-privilege users to have the opportunity=
to elevate their privileges to NT AUTHORITY\SYSTEM.</td>
<td>2026-07-08</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57239" target=3D= "_blank" rel=3D"noopener">CVE-2026-57239</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The embedded JavaScript in the PDF deleted the pages, making the object=
invalid. The application attempted to perform a write operation on the inv= alid pop-up annotations, resulting in the program crashing.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13126" target=3D= "_blank" rel=3D"noopener">CVE-2026-13126</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The application opens the PDF file. JavaScript then rewrites the docume=
nt to modify the page structure, resulting in the invalidation of the page = objects. However, the thumbnails still use the invalid page objects, ultima= tely causing the application to crash.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13127" target=3D= "_blank" rel=3D"noopener">CVE-2026-13127</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>Embedding JavaScript within a PDF file will cause the page to be delete=
d. Subsequent scripts will continue to access the relevant properties of th=
e document view, eventually leading to the crash of the application.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13128" target=3D= "_blank" rel=3D"noopener">CVE-2026-13128</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF file, JavaScript uses the damaged fiel=
d tree to trigger field traversal, resulting in the program holding an inva= lid form object when accessing the field property path. Eventually, the app= lication crashes due to reading an invalid pointer.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13129" target=3D= "_blank" rel=3D"noopener">CVE-2026-13129</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF and JavaScript modifies the properties=
of form fields, it causes the state of the underlying objects referenced b=
y the program to become invalid. Eventually, it reads an illegal memory add= ress, which leads to the crash of the application.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57237" target=3D= "_blank" rel=3D"noopener">CVE-2026-57237</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>After the application opened the PDF, JavaScript deleted the form field=
object. Subsequently, it attempted to access the invalid object, which cau= sed the application to crash.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57238" target=3D= "_blank" rel=3D"noopener">CVE-2026-57238</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF file and JavaScript deletes the PDF fi= elds, the subsequent logic still uses the old field pointers, resulting in = invalid pointer references and causing the application to crash.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57240" target=3D= "_blank" rel=3D"noopener">CVE-2026-57240</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The application opens the PDF, and JavaScript modifies the form. Howeve=
r, the related objects on the page lack complete lifecycle management and n= ull value validation; when the page state changes, the application continuo= usly dereferences invalid objects, eventually leading to a crash.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57242" target=3D= "_blank" rel=3D"noopener">CVE-2026-57242</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>After JavaScript resetting the form, the synchronization process lacks = re-entry protection and object lifecycle verification, resulting in the fai= lure of the control pointer during the traversal process. After the pointer=
fails, it still continues to dereference, causing the application to crash= .</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57244" target=3D= "_blank" rel=3D"noopener">CVE-2026-57244</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF, traverses and builds the annotation e= lements related to hyperlinks, it fails to validate the abnormal annotation=
relationships and field combinations. This results in the internal objects=
entering an invalid state. Eventually, during the destruction phase, an in= valid pointer write occurred, causing the application to crash.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57245" target=3D= "_blank" rel=3D"noopener">CVE-2026-57245</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When dealing with abnormally constructed objects, there is a lack of ar= gument validation; JavaScript triggers signature verification, but the sign= ature plugin does not perform validation when copying the abnormal string, = causing the application to crash.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57246" target=3D= "_blank" rel=3D"noopener">CVE-2026-57246</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The application re-enters the document structure via field processing a=
nd deletes the current page, and then continues using the field objects obt= ained before deletion, triggering an illegal read and crashing.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57247" target=3D= "_blank" rel=3D"noopener">CVE-2026-57247</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF file and JavaScript writes annotation = attributes, there is a lack of sufficient object type and argument checks. =
As a result, due to the damage to the internal structure of the annotations=
, it causes the application to crash during subsequent release.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57248" target=3D= "_blank" rel=3D"noopener">CVE-2026-57248</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>After the application opened the PDF file, the script first reset the a= nnotation status, then triggered the reset form event by additional action.=
During the re-entry process, the application access invalid objects and cr= ashed.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57249" target=3D= "_blank" rel=3D"noopener">CVE-2026-57249</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF and JavaScript resets the form fields,=
the script re-enters the interface. The underlying native object is damage=
d, but the application does not perform validation. The function call on th=
e damaged object leads to the application crashing.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57250" target=3D= "_blank" rel=3D"noopener">CVE-2026-57250</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The application opens a PDF, but the cloud-like appearance of the const= ruction process lacks proper setting of an upper limit and consistency chec= ks. Out-of-bounds access to the underlying array is exposed, ultimately lea= ding to a crash of the application.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57251" target=3D= "_blank" rel=3D"noopener">CVE-2026-57251</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF file, during the process of JavaScript=
deleting pages and removing attachment annotations, it will cause the atta= chment panel to continue accessing invalid pointers, eventually leading to = the application crashing.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57252" target=3D= "_blank" rel=3D"noopener">CVE-2026-57252</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>There is an abnormal annotation within the PDF that is referenced by ot= her objects. When the application parses the PDF, it fails to perform prope=
r type checking, ultimately causing the application to crash.</td> <td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57254" target=3D= "_blank" rel=3D"noopener">CVE-2026-57254</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>When the application opens a PDF and executes JavaScript, it performs a= bnormal operations on the list box field, and this operation is repeated af= ter the form is reset. During this process, the application failed to adequ= ately verify the validity of the form objects and their internal dictionary=
pointers, resulting in accessing internal members of invalid or improperly=
initialized fields. This led to an illegal pointer read, ultimately causin=
g the application to crash.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57256" target=3D= "_blank" rel=3D"noopener">CVE-2026-57256</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The application opened a PDF file containing an abnormal Unity 3D objec=
t. During parsing, the application incorrectly resolved a portion of the ab= normal object as a pointer and used it as a valid address, ultimately causi=
ng the application to crash.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57260" target=3D= "_blank" rel=3D"noopener">CVE-2026-57260</a></td>
</tr>
<td class=3D"vendor-product">FreeRDP--FreeRDP</td>
<td>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior =
to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx o= ption pass desktop stride and height to RemoteFX decoding for Cache Bitmap =
V3 data while allocating bitmap->data only for the smaller DstWidth and = DstHeight in gdi_Bitmap_Decompress, allowing a malicious RDP server to trig= ger a heap out-of-bounds write with attacker-controlled offset and content.=
This issue is fixed in version 3.27.1.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55827" target=3D= "_blank" rel=3D"noopener">CVE-2026-55827</a></td>
</tr>
<td class=3D"vendor-product">FreeRDP--FreeRDP</td>
<td>FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman= _channel_close and dvcman_call_on_receive due to improper synchronization o=
f channel_callback access. A malicious RDP server can trigger a race condit= ion by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing he= ap-use-after-free in the drdynvc client thread and potentially enabling rem= ote code execution or denial of service.</td>
<td>2026-07-08</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56297" target=3D= "_blank" rel=3D"noopener">CVE-2026-56297</a></td>
</tr>
<td class=3D"vendor-product">Genetec Inc.--Genetec Security Center</td>
<td>A flaw in the authentication mechanism for video stream requests in Gen= etec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unaut= henticated attacker to access live video streams.</td>
<td>2026-07-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55727" target=3D= "_blank" rel=3D"noopener">CVE-2026-55727</a></td>
</tr>
<td class=3D"vendor-product">genolve--Genolve Genolve AI Business Graphics,=
AI Images</td>
<td>The Genolve - AI image AI video generation plugin for WordPress is vuln= erable to unauthorized modification of data due to a missing capability che=
ck on the genolve_setOpt() function in all versions up to, and including, 5= .0.5. This makes it possible for authenticated attackers, with Contributor-= level access and above, to update arbitrary WordPress options, including en= abling user registration and setting the default role to administrator, res= ulting in privilege escalation.</td>
<td>2026-07-11</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1359" target=3D"= _blank" rel=3D"noopener">CVE-2026-1359</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token=
=3D URL query parameter and responds with Access-Control-Allow-Origin: *, a= llowing unauthenticated attackers to make fully authenticated cross-origin = API requests from any malicious website. Attackers who obtain a leaked JWT = token from access logs, proxy logs, browser history, or Referrer headers ca=
n create persistent backdoor super-admin accounts and exfiltrate sensitive = configuration and user data.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58656" target=3D= "_blank" rel=3D"noopener">CVE-2026-58656</a></td>
</tr>
<td class=3D"vendor-product">getwpfunnels--WPFunnels Funnel Builder for Woo= Commerce with Checkout & One Click Upsell</td>
<td>The WPFunnels - Funnel Builder for WooCommerce with Checkout & One = Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in=
all versions up to, and including, 3.12.7 via the 'postData' parameter par= ameter. This is due to unsanitized write of attacker-controlled postData va= lues into a PHP-includeable .log file combined with the use of include_once=
to render that file in wpfnl_show_log. This makes it possible for unauthen= ticated attackers to execute code on the server. Exploitation requires that=
the Log Settings "Enable Logs" toggle is on and that an administrator subs= equently opens the polluted log file via the plugin's Log Settings View UI;=
however, the nonce required to reach the optin endpoint is publicly emitte=
d on every funnel step page, so the injection step itself is fully unauthen= ticated.</td>
<td>2026-07-07</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14345" target=3D= "_blank" rel=3D"noopener">CVE-2026-14345</a></td>
</tr>
<td class=3D"vendor-product">ghostfolio--ghostfolio</td>
<td>The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accep=
ts private access IDs without validating granteeUserId filtering, allowing = unauthenticated access to full portfolio data. Attackers with a private acc= ess ID can retrieve sensitive portfolio information including holdings, qua= ntities, buy prices, and performance metrics without authentication.</td> <td>2026-07-07</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59708" target=3D= "_blank" rel=3D"noopener">CVE-2026-59708</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab EE affecting all versions from=
13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that unde=
r certain conditions could have allowed an authenticated user with develope= r-role permissions to execute arbitrary scripts in another user's browser s= ession due to improper sanitization of user-supplied input.</td> <td>2026-07-08</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6896" target=3D"= _blank" rel=3D"noopener">CVE-2026-6896</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that un= der certain conditions could have allowed an authenticated user to execute = arbitrary scripts in another user's browser session due to improper sanitiz= ation of user-supplied input.</td>
<td>2026-07-08</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13320" target=3D= "_blank" rel=3D"noopener">CVE-2026-13320</a></td>
</tr>
<td class=3D"vendor-product">globalprogramming--WHMCS Bridge</td>
<td>The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file u= ploads due to missing file type validation in the connect() function in all=
versions up to, and including, 6.9. This makes it possible for authenticat=
ed attackers, with Custom-level access and above, to upload arbitrary files=
on the affected site's server which may make remote code execution possibl= e.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14489" target=3D= "_blank" rel=3D"noopener">CVE-2026-14489</a></td>
</tr>
<td class=3D"vendor-product">gnuwget--wget</td>
<td>GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffe=
r underread vulnerability in the clean_metalink_string() function within sr= c/metalink.c that allows a malicious server to trigger memory corruption by=
serving a Metalink document containing a whitespace-only URL. Attackers ca=
n cause the function to decrement a pointer past the start of the buffer wh=
en processing an all-whitespace Metalink URL, potentially leading to abnorm=
al program behavior.</td>
<td>2026-07-07</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58469" target=3D= "_blank" rel=3D"noopener">CVE-2026-58469</a></td>
</tr>
<td class=3D"vendor-product">gotenberg--gotenberg</td>
<td>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.3= 4.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially cra= fted document to cause LibreOffice to automatically retrieve external HTTP(=
S) resources and local file resources during document conversion, enabling = blind SSRF and limited local file disclosure via linked image resource load= ing. This issue is fixed in version 8.34.0.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55229" target=3D= "_blank" rel=3D"noopener">CVE-2026-55229</a></td>
</tr>
<td class=3D"vendor-product">gradio-app--gradio</td>
<td>Gradio before 6.20.0 contains an open redirect and server-side request = forgery vulnerability that allows attackers to redirect users to arbitrary = URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs t=
o the file_fetch() function in the /gradio_api/file=3D endpoint. Attackers = can craft a malicious FileData response targeting internal endpoints such a=
s cloud metadata services to retrieve sensitive credentials including EC2 I=
AM role credentials.</td>
<td>2026-07-08</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59806" target=3D= "_blank" rel=3D"noopener">CVE-2026-59806</a></td>
</tr>
<td class=3D"vendor-product">Grafana--Grafana OSS</td>
<td>Several Grafana API endpoints, some of them unauthenticated, do not lim=
it the size of the request body before processing it. An attacker can send = very large payloads that force excessive memory allocation, potentially exh= austing memory and causing a denial of service.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33382" target=3D= "_blank" rel=3D"noopener">CVE-2026-33382</a></td>
</tr>
<td class=3D"vendor-product">gristlabs--grist-core</td>
<td>Grist is spreadsheet software using Python as its formula language. Pri=
or to 1.7.15, several server-rendered Grist pages embedded user-controlled = values into the page and into inline scripts without fully escaping them, a= llowing cross-site scripting. On the main application page, a document's na=
me or description, set by a document editor, is rendered into the page that=
other users load when opening the document. On the OAuth2 end-of-flow page=
, the openerOrigin request parameter was reflected back into the served pag=
e. Injected script runs in the victim's Grist origin and can act through th=
e authenticated session, reading or modifying data and changing sharing set= tings and access rules. A document editor could therefore escalate to owner= -level access. This issue is fixed in version 1.7.15.</td>
<td>2026-07-10</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55659" target=3D= "_blank" rel=3D"noopener">CVE-2026-55659</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the = Accessories API create path mass-assigns request parameters to the Accessor=
y model while company_id is mass assignable, allowing a low-privileged auth= enticated user in one company to create accessory records under another com= pany when Full Multiple Companies Support is enabled. This issue is fixed i=
n version 8.6.2.</td>
<td>2026-07-10</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54329" target=3D= "_blank" rel=3D"noopener">CVE-2026-54329</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an a= uthenticated non-admin user with users.view and users.edit but without user= s.delete can directly POST to /users/bulksave with delete_user=3D1 because = BulkUsersController::destroy() authorizes only update, allowing the user to=
soft-delete another non-admin user. This issue is fixed in version 8.6.2.<=
<td>2026-07-10</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55460" target=3D= "_blank" rel=3D"noopener">CVE-2026-55460</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATC=
H or PUT /api/v1/maintenances/{maintenance_id} checks access to the current=
maintenance record and asset but then fills attacker-controlled fields inc= luding asset_id without re-authorizing the newly supplied asset, allowing a=
n authorized user to move a maintenance record onto an asset outside their = company scope. This issue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55516" target=3D= "_blank" rel=3D"noopener">CVE-2026-55516</a></td>
</tr>
<td class=3D"vendor-product">h2o--h2o</td>
<td>h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pri=
or to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a=
QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might = allocate an on-stack buffer as large as approximately 800 KB by calling all= oca, which exceeds the default pthread stack size used by musl libc and cau= ses the h2o server to crash with a segmentation fault while touching the gu= ard page. This issue is fixed in commit edd7a120bfc4af11ac0cbebce2a43cc1f93= f9af1.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55213" target=3D= "_blank" rel=3D"noopener">CVE-2026-55213</a></td>
</tr>
<td class=3D"vendor-product">H3C--NX15</td>
<td>A vulnerability was found in H3C NX15 V100R017. Affected by this vulner= ability is the function change_passwd of the file /api/login/modify of the = component Administrator Password Modification Endpoint. The manipulation of=
the argument newPass results in weak password recovery. The attack may be = launched remotely. The exploit has been made public and could be used. The = vendor was contacted early about this disclosure.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15479" target=3D= "_blank" rel=3D"noopener">CVE-2026-15479</a></td>
</tr>
<td class=3D"vendor-product">hapifhir--org.hl7.fhir.core</td>
<td>HAPI FHIR is a complete implementation of the HL7 FHIR standard for hea= lthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-453=
67 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() =
in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call raw String.matches(= sw) without RegexTimeout protection while replaceMatches() was updated, all= owing an unauthenticated attacker to trigger catastrophic regex backtrackin=
g and exhaust server CPU. This issue is fixed in version 6.9.10.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55470" target=3D= "_blank" rel=3D"noopener">CVE-2026-55470</a></td>
</tr>
<td class=3D"vendor-product">HashiCorp--Nomad</td>
<td>HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape=
in the Docker task driver that may allow a job submitter to bind-mount a h= ost path into a container even when volume bind mounts are disabled, potent= ially leading to reading and writing files on the host. This vulnerability,=
CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterp= rise 2.0.4, 1.11.8, and 1.10.14.</td>
<td>2026-07-08</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14891" target=3D= "_blank" rel=3D"noopener">CVE-2026-14891</a></td>
</tr>
<td class=3D"vendor-product">HashiCorp--Nomad</td>
<td>HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileg=
ed restriction for the Docker task driver's host namespace mode options. Th=
is may allow an authenticated job submitter to run a container in a host na= mespace and access information belonging to the host or to other workloads =
on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad C= ommunity Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.</td=
<td>2026-07-08</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14373" target=3D= "_blank" rel=3D"noopener">CVE-2026-14373</a></td>
</tr>
<td class=3D"vendor-product">HashiCorp--Terraform Enterprise</td>
<td>HashiCorp Terraform Enterprise contained an issue in its version contro=
l system (VCS) ingestion of registry modules that did not correctly enforce=
the intended boundary on packaged module content. This may allow an authen= ticated user to include files from outside the intended repository content =
in a module and then download them, potentially exposing sensitive files re= adable by the ingestion process. This vulnerability, CVE-2026-14468, is fix=
ed in Terraform Enterprise v2.0.4 and v1.2.4.</td>
<td>2026-07-06</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14468" target=3D= "_blank" rel=3D"noopener">CVE-2026-14468</a></td>
</tr>
<td class=3D"vendor-product">HAVELSAN Inc.--Liman MYS</td>
<td>Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows A= ccessing Functionality Not Properly Constrained by ACLs. This issue affects=
Liman MYS: before release.Master.1107.</td>
<td>2026-07-07</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11340" target=3D= "_blank" rel=3D"noopener">CVE-2026-11340</a></td>
</tr>
<td class=3D"vendor-product">HAVELSAN Inc.--Liman MYS</td>
<td>Improper verification of cryptographic signature vulnerability in HAVEL= SAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman=
MYS: before release.Master.1107.</td>
<td>2026-07-07</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11348" target=3D= "_blank" rel=3D"noopener">CVE-2026-11348</a></td>
</tr>
<td class=3D"vendor-product">HAVELSAN Inc.--Liman MYS</td>
<td>Improper neutralization of special elements used in an LDAP query ('LDA=
P injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injectio=
n. This issue affects Liman MYS: before release.Master.1107.</td> <td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13696" target=3D= "_blank" rel=3D"noopener">CVE-2026-13696</a></td>
</tr>
<td class=3D"vendor-product">hcr707305003--shiroiAdmin</td>
<td>A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Aff= ected is the function FileController::upload of the file app/common/control= ler/FileController.php. Executing a manipulation of the argument File can l= ead to unrestricted upload. The attack may be launched remotely. The exploi=
t has been publicly disclosed and may be utilized. Upgrading to version 1.4=
is able to address this issue. This patch is called 3ecde28ea8a20a3840dbfe= fd6d6863ee79a83e70. It is suggested to upgrade the affected component. The = vendor was contacted early about this disclosure but did not respond in any=
way.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15488" target=3D= "_blank" rel=3D"noopener">CVE-2026-15488</a></td>
</tr>
<td class=3D"vendor-product">hestiacp--hestiacp</td>
<td>HestiaCP before 1.9.5 contains an authenticated OS command injection vu= lnerability that allows low-privilege authenticated users to execute arbitr= ary commands as root by injecting a single-quote character into unvalidated=
DNS record types. Attackers can exploit insufficient input validation in i= s_dns_record_format_valid() combined with unsafe eval-based parsing in upda= te_domain_zone() to prematurely close a variable assignment string and achi= eve full root code execution on the underlying host in a single DNS record = creation step.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-30007" target=3D= "_blank" rel=3D"noopener">CVE-2025-30007</a></td>
</tr>
<td class=3D"vendor-product">hoppscotch--hoppscotch</td>
<td>Hoppscotch is an open source API development ecosystem. Prior to 2026.6= .0, mock server creation in mock-server.service.ts does not persist the isP= ublic input field while schema.prisma defaults isPublic to true, causing mo=
ck servers linked to private collections to be publicly accessible without = authentication and potentially expose sensitive API data. This issue is fix=
ed in version 2026.6.0.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59720" target=3D= "_blank" rel=3D"noopener">CVE-2026-59720</a></td>
</tr>
<td class=3D"vendor-product">hoppscotch--hoppscotch</td>
<td>Hoppscotch is an open source API development ecosystem. Prior to 2026.6= .0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts acce= pts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in ut= ils.ts permits path, query, or fragment content that nodemailer parses into=
sendmail transport options, allowing an admin to execute arbitrary command=
s as root in the backend container after restart and mail sending. This iss=
ue is fixed in version 2026.6.0.</td>
<td>2026-07-09</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59721" target=3D= "_blank" rel=3D"noopener">CVE-2026-59721</a></td>
</tr>
<td class=3D"vendor-product">horde--Vfs</td>
<td>Horde Virtual File System (VFS) API before 3.0.1 contains an OS command=
injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShell= Command() method fails to sanitize command substitution sequences, allowing=
authenticated attackers to inject arbitrary shell commands through user-co= ntrolled filenames. Attackers can supply malicious filenames containing une= scaped command substitution payloads through operations such as file upload=
, folder creation, rename, or deletion, which are interpolated into a doubl= e-quoted shell context and executed via proc_open() through /bin/sh -c befo=
re smbclient runs, resulting in arbitrary command execution on the underlyi=
ng system.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60102" target=3D= "_blank" rel=3D"noopener">CVE-2026-60102</a></td>
</tr>
<td class=3D"vendor-product">httplib2--httplib2</td>
<td>httplib2 is a comprehensive HTTP client library for Python. Prior to 0.= 32.0, httplib2 performs unbounded decompression of HTTP response bodies enc= oded with Content-Encoding: gzip or deflate in _decompressContent in httpli= b2/init.py, allowing a malicious or compromised HTTP server to return a sma=
ll compressed payload that expands to an arbitrarily large size in memory a=
nd causes MemoryError or OOM-kill in the client process. This issue is fixe=
d in version 0.32.0.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59939" target=3D= "_blank" rel=3D"noopener">CVE-2026-59939</a></td>
</tr>
<td class=3D"vendor-product">Hydro-Qubec--Le Circuit Electrique charging st= ation backend</td>
<td>The charging station websocket endpoint accepts connections without pro= per authentication, which could lead to privilege escalation.</td> <td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20744" target=3D= "_blank" rel=3D"noopener">CVE-2026-20744</a></td>
</tr>
<td class=3D"vendor-product">Hydro-Qubec--Le Circuit Electrique charging st= ation backend</td>
<td>Previously, there was no throttling on repeated authentication attempts=
to the charging station backend, which could allow an attacker to execute =
a denial-of-service attack.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42952" target=3D= "_blank" rel=3D"noopener">CVE-2026-42952</a></td>
</tr>
<td class=3D"vendor-product">Hydro-Qubec--Le Circuit Electrique charging st= ation backend</td>
<td>Multiple connections to the backend using the same charging station ID = are allowed, which could allow an attacker to deploy multiple instances of = malicious OCPP clients to overwhelm the backend.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44383" target=3D= "_blank" rel=3D"noopener">CVE-2026-44383</a></td>
</tr>
<td class=3D"vendor-product">IBM--API Connect</td>
<td>IBM API Connect 10.0.8.0 through 10.0.8.9 and=C2=A012.1.0.0 through 12.= 1.0.3=C2=A0contains an unauthenticated SQL injection vulnerability in the p= assword reset functionality.</td>
<td>2026-07-08</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9074" target=3D"= _blank" rel=3D"noopener">CVE-2026-9074</a></td>
</tr>
<td class=3D"vendor-product">IBM--API Connect</td>
<td>IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials whic=
h could allow an attacker to gain unauthorized access to the application be= fore the system enforces a credential update.</td>
<td>2026-07-08</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3144" target=3D"= _blank" rel=3D"noopener">CVE-2026-3144</a></td>
</tr>
<td class=3D"vendor-product">Idvlabs Software and Consulting Services Inc.-= -Ontime</td>
<td>Authorization bypass through User-Controlled key vulnerability in Idvla=
bs Software and Consulting Services Inc. Ontime allows Exploitation of Trus= ted Identifiers. This issue affects Ontime: through 04052026.</td> <td>2026-07-07</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5730" target=3D"= _blank" rel=3D"noopener">CVE-2026-5730</a></td>
</tr>
<td class=3D"vendor-product">Idvlabs Software and Consulting Services Inc.-= -Ontime</td>
<td>Authorization bypass through User-Controlled key vulnerability in Idvla=
bs Software and Consulting Services Inc. Ontime allows Exploitation of Trus= ted Identifiers. This issue affects Ontime: through 04052026.</td> <td>2026-07-07</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5799" target=3D"= _blank" rel=3D"noopener">CVE-2026-5799</a></td>
</tr>
<td class=3D"vendor-product">Inrove Software and Internet Services--BiEtica= ret</td>
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in Inrove Software and Internet Services BiEtic= aret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.</=
<td>2026-07-09</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5955" target=3D"= _blank" rel=3D"noopener">CVE-2026-5955</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--IntelliJ IDEA</td>
<td>In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via p= ath traversal in project workspace ID handling was possible</td> <td>2026-07-10</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59792" target=3D= "_blank" rel=3D"noopener">CVE-2026-59792</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--TeamCity</td>
<td>In JetBrains TeamCity before 2026.1.2 arbitrary file access was possibl=
e via the Perforce VCS integration</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59793" target=3D= "_blank" rel=3D"noopener">CVE-2026-59793</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--TeamCity</td>
<td>In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated ag= ent registration was possible</td>
<td>2026-07-10</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59795" target=3D= "_blank" rel=3D"noopener">CVE-2026-59795</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--TeamCity</td>
<td>In JetBrains TeamCity before 2026.1.2 pipeline modification was possibl=
e due to improper permission checks</td>
<td>2026-07-10</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59796" target=3D= "_blank" rel=3D"noopener">CVE-2026-59796</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--TeamCity</td>
<td>In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile p= age was possible via agent-reported data</td>
<td>2026-07-10</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59794" target=3D= "_blank" rel=3D"noopener">CVE-2026-59794</a></td>
</tr>
<td class=3D"vendor-product">jknack--handlebars.java</td>
<td>Handlebars.java provides logic-less and semantic Mustache templates wit=
h Java. Prior to 4.5.2, applications that pass user-controlled input to Han= dlebars.compile() using FileTemplateLoader or ClassPathTemplateLoader are v= ulnerable to path traversal, allowing arbitrary file read through template = names derived from URL path parameters, request parameters, or other user-c= ontrolled sources. This issue is fixed in version 4.5.2.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55760" target=3D= "_blank" rel=3D"noopener">CVE-2026-55760</a></td>
</tr>
<td class=3D"vendor-product">joe007--Eventer</td>
<td>The Eventer plugin for WordPress is vulnerable to an insecure password = reset mechanism in all versions up to, and including, 4.4.2. The plugin sto= res a plaintext copy of the password reset key in the `eventer_verification= _code` user meta field when a user requests a password reset. The plaintext=
key stored in `wp_usermeta` can be used with the plugin's custom reset act= ion to set a new password for any user. Combined with another vulnerability=
such as SQL Injection (CVE-2026-9700), this makes it possible for unauthen= ticated attackers to extract the plaintext reset key and take over any user=
account, including administrators. Note: The password reset function only = works up to PHP version 7.4.</td>
<td>2026-07-08</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9701" target=3D"= _blank" rel=3D"noopener">CVE-2026-9701</a></td>
</tr>
<td class=3D"vendor-product">joe007--Eventer</td>
<td>The Eventer plugin for WordPress is vulnerable to time-based SQL Inject= ion via the 'code' parameter in all versions up to, and including, 4.4.2 du=
e to insufficient escaping on the user supplied parameter and lack of suffi= cient preparation on the existing SQL query. This makes it possible for una= uthenticated attackers to append additional SQL queries into already existi=
ng queries that can be used to extract sensitive information from the datab= ase.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9700" target=3D"= _blank" rel=3D"noopener">CVE-2026-9700</a></td>
</tr>
<td class=3D"vendor-product">joedolson--My Calendar Accessible Event Manage= r</td>
<td>The My Calendar - Accessible Event Manager plugin for WordPress is vuln= erable to time-based blind SQL Injection via the 'mc_auth' parameter in all=
versions up to, and including, 3.7.8 due to insufficient escaping on the u= ser supplied parameter and lack of sufficient preparation on the existing S=
QL query. This makes it possible for unauthenticated attackers to append ad= ditional SQL queries into already existing queries that can be used to extr= act sensitive information from the database.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6854" target=3D"= _blank" rel=3D"noopener">CVE-2026-6854</a></td>
</tr>
<td class=3D"vendor-product">joeyoungblood--WP Business Intelligence Lite</=
<td>The WP Business Intelligence Lite plugin for WordPress is vulnerable to=
authorization bypass in all versions up to, and including, 3.2.0. This is = due to the plugin not properly verifying that a user is authorized to perfo=
rm an action. This makes it possible for authenticated attackers, with Subs= criber-level access and above, to modify stored SQL queries, which can lead=
to privilege escalation via arbitrary SQL execution when the modified quer=
y is viewed by an administrator.</td>
<td>2026-07-10</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15293" target=3D= "_blank" rel=3D"noopener">CVE-2026-15293</a></td>
</tr>
<td class=3D"vendor-product">jssor--Jssor Slider by jssor.com</td>
<td>The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Dir= ectory Traversal in all versions up to, and including, 3.1.24 via the 'url'=
parameter parameter. This makes it possible for unauthenticated attackers =
to read the contents of arbitrary files on the server, which can contain se= nsitive information.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14244" target=3D= "_blank" rel=3D"noopener">CVE-2026-14244</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Validation of Specified Quantity in Input vulnerability in = the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, a=
nd SRX Series allows an unauthenticated, network-based attacker to cause a = complete Denial of Service (DoS). When TCP proxy is engaged in a flow sessi= on, to support ALGs,=C2=A0Advanced Anti-Malware, ICAP=C2=A0or UTM, a TCP pa= cket with specifically malformed TCP header will cause flow processing daem=
on (flowd) to crash and restart. This causes a complete service outage unti=
l the system has automatically recovered. This issue affects Junos OS on MX=
with SPC3, and SRX Series:=C2=A0 * 23.4 versions before 23.4R2-S7,=C2=A0 *=
24.2 versions before 24.2R2-S4,=C2=A0 * 24.4 versions before 24.4R2-S3, * = 25.2 versions before 25.2R2. This issue does not affect releases before 23.= 4R1.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57023" target=3D= "_blank" rel=3D"noopener">CVE-2026-57023</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Validation of Syntactic Correctness of Input vulnerability =
in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and S=
RX Series allows an unauthenticated, network-based attacker to cause a Deni= al-of-Service (DoS).If the SIP ALG is enabled on an affected device, the pr= ocessing of a malformed SIP invite packet will cause a flow processing daem=
on (flowd) crash and restart. This leads to a complete service outage until=
the system has automatically recovered. This issue affects Junos OS on MX = Series with SPC3 and SRX Series: * all versions before 23.2R2-S7, * 23.4 ve= rsions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions = before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.= 4R1-S2.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57026" target=3D= "_blank" rel=3D"noopener">CVE-2026-57026</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS Evolved</td>
<td>An Improper Restriction of Communication Channel to Intended Endpoints = vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticate=
d, network-based attacker to cause license exhaustion. Due to an incorrect = initialization, a process which should only be able to communicate internal=
ly within the device, can be reached over the network via an open port. Thi=
s leads to unauthorized access to the license management. This issue affect=
s all Junos OS Evolved versions before 23.2R2-EVO.</td>
<td>2026-07-09</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57028" target=3D= "_blank" rel=3D"noopener">CVE-2026-57028</a></td>
</tr>
<td class=3D"vendor-product">jupyterlab--jupyterlab-git</td>
<td>JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupy= terlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab= _git/handlers.py to enforce excluded_paths, allowing an authenticated user =
on a case-insensitive filesystem to vary URL path casing and read excluded = directories. This issue is fixed in version 0.54.0.</td>
<td>2026-07-08</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54528" target=3D= "_blank" rel=3D"noopener">CVE-2026-54528</a></td>
</tr>
<td class=3D"vendor-product">krayin--laravel-crm</td>
<td>Krayin CRM through 2.2.3 contains an insecure direct object reference v= ulnerability in LeadController, PersonController, OrganizationController, Q= uoteController, and ActivityController that allows authenticated users to e= dit, update, or delete records owned by other users. Attackers can modify C=
RM records and reassign ownership by exploiting missing record-level owners= hip validation in edit, update, and destroy methods.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61460" target=3D= "_blank" rel=3D"noopener">CVE-2026-61460</a></td>
</tr>
<td class=3D"vendor-product">Labcenter--Proteus</td>
<td>The application contains a use-after-free vulnerability that can be exp= loited to cause memory corruption while parsing specially crafted files. Th=
is could allow an attacker to execute arbitrary code in the context of the = current process.</td>
<td>2026-07-07</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42958" target=3D= "_blank" rel=3D"noopener">CVE-2026-42958</a></td>
</tr>
<td class=3D"vendor-product">Labcenter--Proteus</td>
<td>The application contains a stack-based buffer overflow vulnerability th=
at can be exploited by an attacker to execute arbitrary code.</td> <td>2026-07-07</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49033" target=3D= "_blank" rel=3D"noopener">CVE-2026-49033</a></td>
</tr>
<td class=3D"vendor-product">labring--FastGPT</td>
<td>FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-= beta5, two FastGPT file handlers authorize an unrelated resource and then s= ign or read an S3 object using a key taken directly from the request, witho=
ut checking that the key belongs to the caller's team. Because S3 object ke=
ys are global within the bucket and carry the tenant id only as a path segm= ent, an attacker can supply another team's key and obtain its file contents=
through the chat-file presign endpoint or dataset preview endpoint. This i= ssue is fixed in version v4.15.0-beta5.</td>
<td>2026-07-07</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55418" target=3D= "_blank" rel=3D"noopener">CVE-2026-55418</a></td>
</tr>
<td class=3D"vendor-product">labring--FastGPT</td>
<td>FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-b= eta4, the HTTP-tool OpenAPI schema importer validates only the top-level UR=
L before passing it to SwaggerParser.bundle, whose remote reference resolve=
r fetches $ref URLs without FastGPT's internal-address guard and returns fe= tched content inline, allowing an authenticated team member to read interna=
l services or cloud metadata. This issue is fixed in version 4.15.0-beta4.<=
<td>2026-07-07</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54607" target=3D= "_blank" rel=3D"noopener">CVE-2026-54607</a></td>
</tr>
<td class=3D"vendor-product">langchain4j--langchain4j</td>
<td>LangChain4j is a Java library for building LLM-powered applications on = the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta= 26, the MariaDB and pgvector embedding stores build metadata-filter SQL by = string-concatenating filter keys, and in MariaDB string values, directly in=
to the query without adequate escaping. A crafted metadata key in Embedding= SearchRequest.filter() can break out of its SQL context and inject arbitrar=
y SQL into the statements executed by the stores' search and removeAll(Filt= er) operations, enabling blind data exfiltration, denial of service via sle=
ep functions, and deletion of arbitrary rows through removeAll(Filter). Thi=
s issue is fixed in langchain4j-mariadb and langchain4j-pgvector versions 1= .2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26.</td> <td>2026-07-10</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55405" target=3D= "_blank" rel=3D"noopener">CVE-2026-55405</a></td>
</tr>
<td class=3D"vendor-product">langgenius--dify</td>
<td>Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the My= Scale vector store backend that allows attackers to execute arbitrary SQL b=
y supplying unsanitized search parameters to the search_by_full_text method=
without escaping or parameterization. Attackers can inject malicious SQL t= hrough the search parameters to read, modify, or delete data in the underly= ing ClickHouse database.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61461" target=3D= "_blank" rel=3D"noopener">CVE-2026-61461</a></td>
</tr>
<td class=3D"vendor-product">langroid--langroid</td>
<td>Langroid is a framework for building large-language-model-powered appli= cations. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Esca=
pe leading to Remote Code Execution (RCE) in its `TableChatAgent` and `Vect= orStore` capabilities. When these agents evaluate LLM-generated tool messag=
es with `full_eval=3DTrue`, they attempt to sandbox the execution by explic= itly setting `locals` to an empty dictionary `{}` inside Python's `eval()` = function. However, this relies on an incomplete understanding of Python's e= xecution model. Because `__builtins__` is not explicitly scrubbed from the = `globals` dictionary mapping, Python implicitly injects all built-ins durin=
g execution, granting full access to functions like `__import__('os').syste= m()`. Since `TableChatAgent.pandas_eval()` executes external LLM outputs na= tively, this bypass permits any attacker providing prompt payload to achiev=
e unauthenticated RCE on the host system. Version 0.65.2 patches the issue.= </td>
<td>2026-07-09</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54769" target=3D= "_blank" rel=3D"noopener">CVE-2026-54769</a></td>
</tr>
<td class=3D"vendor-product">langroid--langroid</td>
<td>Langroid is a framework for building large-language-model-powered appli= cations. Prior to version 0.65.3, a Langroid application exposing a chat in= terface to untrusted users may allow direct tool invocation via raw JSON pa= yloads, even when tools are registered with `use=3DFalse, handle=3DTrue`. V= ersion 0.65.3 fixes the issue.</td>
<td>2026-07-09</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54771" target=3D= "_blank" rel=3D"noopener">CVE-2026-54771</a></td>
</tr>
<td class=3D"vendor-product">langroid--langroid</td>
<td>Langroid is a framework for building large-language-model-powered appli= cations. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileT= ool` appear to treat `curr_dir` as the intended working-directory boundary = for file operations. However, the tools only change the process working dir= ectory to `curr_dir` and then operate on the user-supplied `file_path` with= out resolving and enforcing that the final path remains inside `curr_dir`. =
As a result, a tool caller can supply path traversal sequences such as `../= secret.txt` to read files outside the configured current directory, or `../= written_by_tool.txt` to write files outside that directory. This can impact=
applications that expose Langroid file tools to an LLM agent, user-control= led tool call, or delegated coding/documentation agent while relying on `cu= rr_dir` to restrict file access to a project/workspace directory. Version 0= .64.0 patches the issue.</td>
<td>2026-07-09</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50181" target=3D= "_blank" rel=3D"noopener">CVE-2026-50181</a></td>
</tr>
<td class=3D"vendor-product">latepoint--LatePoint Calendar Booking Plugin f=
or Appointments and Events</td>
<td>The LatePoint - Calendar Booking Plugin for Appointments and Events plu= gin for WordPress is vulnerable to Improper Input Validation in all version=
s up to, and including, 5.4.0. This is due to the plugin's Stripe Connect p= ayment processor accepting a client-supplied PaymentIntent ID. This makes i=
t possible for unauthenticated attackers to pay an arbitrary amount by supp= lying a previously succeeded PaymentIntent token.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5356" target=3D"= _blank" rel=3D"noopener">CVE-2026-5356</a></td>
</tr>
<td class=3D"vendor-product">Leantime--Leantime</td>
<td>Leantime's Users::getUser method in the JSON-RPC API lacks proper autho= rization checks, allowing authenticated users to retrieve full user credent= ial rows including password hashes, TOTP secrets, and session tokens. Attac= kers can exploit this by calling users.getUser with arbitrary user IDs to e= numerate all accounts and obtain credentials for offline password cracking,=
2FA bypass, and session hijacking.</td>
<td>2026-07-06</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59712" target=3D= "_blank" rel=3D"noopener">CVE-2026-59712</a></td>
</tr>
<td class=3D"vendor-product">Leantime--Leantime</td>
<td>Leantime contains an OIDC login CSRF vulnerability in the verifyState()=
method that unconditionally returns true without validating state paramete= rs. Attackers can craft malicious callback URLs with attacker-controlled au= thorization codes to perform session fixation, logging victims in as the at= tacker.</td>
<td>2026-07-06</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59713" target=3D= "_blank" rel=3D"noopener">CVE-2026-59713</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a=
character causes quadratic work in src/mistune/plugins/formatting.py when = the strikethrough, mark, or insert plugin scans for matching markers from e= ach possible start position, allowing denial of service through CPU exhaust= ion. This issue is fixed in version 3.3.0.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59922" target=3D= "_blank" rel=3D"noopener">CVE-2026-59922</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk e= mphasis pairs around a character cause quadratic work in src/mistune/inline= _parser.py because the parser scans forward for matching close markers from=
every potential opening run, allowing denial of service in default Mistune=
parsing. This issue is fixed in version 3.3.0.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59925" target=3D= "_blank" rel=3D"noopener">CVE-2026-59925</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, a Markdown document containing many repeated or distinct reference= -link definitions causes quadratic work in src/mistune/block_parser.py and = the ref_links environment dictionary handling, allowing denial of service t= hrough CPU exhaustion. This issue is fixed in version 3.3.0.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59928" target=3D= "_blank" rel=3D"noopener">CVE-2026-59928</a></td>
</tr>
<td class=3D"vendor-product">libp2p--js-libp2p</td>
<td>libp2p is a JavaScript Implementation of libp2p networking stack. Prior=
to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs=
and maxIwantMessageIDs to Infinity, allowing oversized IHAVE and IWANT con= trol message arrays in message/decodeRpc.ts and gossipsub.ts to synchronous=
ly iterate roughly 180,000 message IDs per 4 MB frame and block the Node.js=
event loop. This issue is fixed in version 16.0.0.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49866" target=3D= "_blank" rel=3D"noopener">CVE-2026-49866</a></td>
</tr>
<td class=3D"vendor-product">LibreBooking--LibreBooking</td>
<td>LibreBooking's email template editor save action passes the submitted t= emplate name directly into the destination file path, allowing a remote att= acker with administrator credentials to write an arbitrary file outside the=
template directory and execute code. Fixed in 5.1.0.</td>
<td>2026-07-09</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61343" target=3D= "_blank" rel=3D"noopener">CVE-2026-61343</a></td>
</tr>
<td class=3D"vendor-product">lima-vm--lima</td>
<td>Lima launches Linux virtual machines, typically on macOS, for running c= ontainerd. Prior to 2.1.3, on an instance of Lima running with the qemu dri= ver, an arbitrary user in the VM could access /run/lima-guestagent.sock whe=
n the guest agent is enabled, which could result in running arbitrary comma= nds with root privileges in the VM because the guest agent socket provides = tunneling for arbitrary addresses, including Unix socket addresses for priv= ileged daemons like D-Bus. This issue is fixed in version 2.1.3.</td> <td>2026-07-10</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53657" target=3D= "_blank" rel=3D"noopener">CVE-2026-53657</a></td>
</tr>
<td class=3D"vendor-product">LocalAI--LocalAI</td>
<td>LocalAI contains an unauthenticated server-side request forgery vulnera= bility in the POST /models/apply endpoint that allows attackers to fetch ar= bitrary internal URLs. The endpoint passes unsanitized gallery URL fields d= irectly to gallery.GetGalleryConfigFromURLWithContext without proper valida= tion, enabling attackers to force the server to issue HTTP GET requests to = private and loopback ranges with partial response content leaked through er= ror messages.</td>
<td>2026-07-07</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59707" target=3D= "_blank" rel=3D"noopener">CVE-2026-59707</a></td>
</tr>
<td class=3D"vendor-product">LoginPress--LoginPress Pro</td>
<td>The LoginPress Pro plugin for WordPress is vulnerable to Authentication=
Bypass via Unverified OAuth Email in all versions up to and including 6.2.=
3. The vulnerability exists in the loginpress_on_discord_login() Discord OA= uth callback handler, which accepts the email field returned by Discord's /= users/@me endpoint without ever checking that the profile's verified flag i=
s true, then directly maps that email to a local WordPress account via get_= user_by('email', $profile['email']) and issues an authenticated session coo= kie via wp_set_auth_cookie(). This makes it possible for unauthenticated at= tackers to take over any existing WordPress account - including administrat=
or accounts - by registering a Discord account configured with an unverifie=
d email address that matches the target user's registered WordPress email a=
nd completing the standard Discord OAuth flow.</td>
<td>2026-07-09</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12595" target=3D= "_blank" rel=3D"noopener">CVE-2026-12595</a></td>
</tr>
<td class=3D"vendor-product">LoginPress--LoginPress Pro</td>
<td>The LoginPress Pro plugin for WordPress is vulnerable to Authentication=
Bypass via the GitHub OAuth callback in versions up to, and including, 6.2= .3. The vulnerability exists in the loginpress_on_github_login() function, = which blindly trusts the first element (profile[0]['email']) of the array r= eturned by GitHub's /user/emails endpoint as an account-binding identifier = without verifying that the email carries a verified =3D=3D=3D true status. = This makes it possible for unauthenticated attackers to log in as any exist= ing WordPress user, including administrators, by adding an unverified email=
address matching a local account to their GitHub profile and triggering th=
e OAuth callback via a crafted code parameter - causing the plugin to call = get_user_by('email', ...) and establish an authenticated session for the ma= tched account. Practical exploitation is conditional on GitHub returning th=
e attacker-added unverified email at index 0 of the /user/emails response, =
as GitHub typically prioritizes the primary verified address first; nonethe= less, the absence of any email verification check in the plugin constitutes=
a fundamental authentication bypass flaw.</td>
<td>2026-07-09</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12597" target=3D= "_blank" rel=3D"noopener">CVE-2026-12597</a></td>
</tr>
<td class=3D"vendor-product">LoginPress--LoginPress Pro</td>
<td>The LoginPress Pro plugin for WordPress is vulnerable to authentication=
bypass in versions up to and including 6.2.3 via the Spotify Social Login = addon. This is due to the loginpress_on_spotify_login() function trusting t=
he unverified 'email' field returned by Spotify's /v1/me endpoint and using=
it directly with get_user_by('email', $profile['email']) to identify and l=
og in an existing WordPress account, without confirming that the Spotify us=
er actually owns the email address (Spotify documents that the profile emai=
l is unverified) and without requiring the user to prove ownership of the m= atching WordPress account. This makes it possible for unauthenticated attac= kers to log in as any existing WordPress user, including Administrators, by=
registering a Spotify account using the targeted user's email address and = authenticating via the Spotify provider.</td>
<td>2026-07-09</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12598" target=3D= "_blank" rel=3D"noopener">CVE-2026-12598</a></td>
</tr>
<td class=3D"vendor-product">logto-io--logto</td>
<td>Logto is the modern, open-source auth infrastructure for SaaS and AI ap= ps. Prior to 1.41.0, Logto's Account Center step-up check accepted any acti=
ve verification record that belonged to the current user and had isVerified=
=3D=3D=3D true. A WebAuthn registration verification record for binding a = new passkey could be created and verified with only an existing Account API=
bearer token, then sent in the logto-verification-id header and treated as=
identityVerified=3Dtrue by Account Center routes, allowing MFA factor mana= gement without proving possession of an existing password, identifier, or M=
FA factor. This issue is fixed in version 1.41.0.</td>
<td>2026-07-10</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55377" target=3D= "_blank" rel=3D"noopener">CVE-2026-55377</a></td>
</tr>
<td class=3D"vendor-product">logto-io--logto</td>
<td>Logto is the modern, open-source auth infrastructure for SaaS and AI ap= ps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the sig= ned SAML response and assertion by string-substituting user-controlled prof= ile attributes such as name, email, and custom attribute-mapping values int=
o element-text placeholders of a SAML XML template using samlify 2.10.0, wh= ich left those placeholders unescaped. An authenticated low-privilege user = could place XML markup in a profile attribute so Logto signed a forged SAML=
attribute, such as an arbitrary role, allowing privilege escalation at rel= ying Service Providers that authorize on SAML attributes. This issue is fix=
ed in version 1.41.0.</td>
<td>2026-07-10</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55789" target=3D= "_blank" rel=3D"noopener">CVE-2026-55789</a></td>
</tr>
<td class=3D"vendor-product">loopus--WP Cost Estimation & Payment Forms=
Builder</td>
<td>The WP Cost Estimation & Payment Forms Builder (E&P Forms) plug=
in for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cust= omerInfos' parameter in all versions up to, and including, 10.5.97 due to i= nsufficient input sanitization and output escaping. This makes it possible = for unauthenticated attackers to inject arbitrary web scripts in pages that=
will execute whenever a user accesses an injected page.</td> <td>2026-07-09</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9253" target=3D"= _blank" rel=3D"noopener">CVE-2026-9253</a></td>
</tr>
<td class=3D"vendor-product">lucee--Lucee</td>
<td>Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x re= lease lines contain a reflected cross-site scripting vulnerability in URL p= ath parsing that allows unauthenticated remote attackers to execute arbitra=
ry JavaScript in a victim's browser by embedding HTML or JavaScript payload=
s within the request path. Attackers can craft a malicious URL containing i= njected script content that is reflected in the server's response without p= roper output encoding, enabling session hijacking or unauthorized actions a= gainst the Lucee administrative interface when a victim visits the crafted = link.</td>
<td>2026-07-10</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-29519" target=3D= "_blank" rel=3D"noopener">CVE-2026-29519</a></td>
</tr>
<td class=3D"vendor-product">markdown-it--linkify-it</td>
<td>linkify-it is a links recognition library with full Unicode support. Pr= ior to 5.0.2, the mailto: schema validator used by .test() and .match() can=
be invoked at every mailto: occurrence and scan the remaining input throug=
h src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted u= ser text. This issue is fixed in version 5.0.2.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59887" target=3D= "_blank" rel=3D"noopener">CVE-2026-59887</a></td>
</tr>
<td class=3D"vendor-product">masaakitanaka--Booking Package</td>
<td>The Booking Package plugin for WordPress is vulnerable to generic SQL I= njection via 'email' Form Parameter (form<N>) in all versions up to, = and including, 1.7.20 due to insufficient escaping on the user supplied par= ameter and lack of sufficient preparation on the existing SQL query. This m= akes it possible for unauthenticated attackers to append additional SQL que= ries into already existing queries that can be used to extract sensitive in= formation from the database. The vulnerable REST API endpoint /wp-json/book= ing-package/v1/request is registered with permission_callback: __return_tru=
e and wp_magic_quotes does not apply to REST-sourced $_POST values, meaning=
single quotes in the payload reach the SQL sink intact without any authent= ication requirement. The impact of this is severely limited as the vulnerab=
le parameter goes through is_email.</td>
<td>2026-07-11</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15335" target=3D= "_blank" rel=3D"noopener">CVE-2026-15335</a></td>
</tr>
<td class=3D"vendor-product">mem0--mem0</td>
<td>mem0's openmemory/api component contains an unauthenticated access vuln= erability that allows unauthenticated attackers to read, write, and delete = arbitrary user memories by accessing API routers registered without authent= ication middleware. Attackers can supply arbitrary user_id parameters or di= rectly access memory retrieval endpoints to expose private memory content, =
or invoke pause endpoints with global_pause=3Dtrue to cause denial-of-servi=
ce across all users.</td>
<td>2026-07-07</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59705" target=3D= "_blank" rel=3D"noopener">CVE-2026-59705</a></td>
</tr>
<td class=3D"vendor-product">mem0--mem0</td>
<td>mem0 contains unauthenticated config API endpoints that expose LLM API = keys in plaintext and allow server-side request forgery via attacker-contro= lled ollama_base_url parameter. Unauthenticated attackers can retrieve stor=
ed secrets like OpenAI API keys via GET /api/v1/config/ or trigger SSRF att= acks by setting ollama_base_url to internal addresses like cloud IMDS via P=
UT /api/v1/config/mem0/llm endpoint.</td>
<td>2026-07-07</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59706" target=3D= "_blank" rel=3D"noopener">CVE-2026-59706</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 1.6.78 contains a remote code execution vulnerability =
in CodeAgent._execute_python() that executes LLM-generated Python code with= out AST validation, import restrictions, or sandbox enforcement. Attackers = can influence LLM output through prompt injection to exfiltrate all environ= ment secrets and execute arbitrary code on the host system.</td> <td>2026-07-11</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61447" target=3D= "_blank" rel=3D"noopener">CVE-2026-61447</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 4.6.78 fails to validate the caller-controlled dimensi=
on argument in the PGVector and Cassandra knowledge-store create_collection=
() backends. Although schema, keyspace, and collection-name identifiers are=
validated, the dimension value (declared as int but not enforced at runtim=
e) is interpolated directly into the vector column of the generated CREATE = TABLE DDL. A caller able to influence collection-creation dimensions can pa=
ss a string such as '3); DROP TABLE tenant_secrets; --' to inject SQL/CQL t= okens into the statement executed by the database driver.</td> <td>2026-07-11</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60090" target=3D= "_blank" rel=3D"noopener">CVE-2026-60090</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI versions before 4.6.78 contain a code injection vulnerability=
in deploy/api.py where the agents_file parameter is directly interpolated = into an f-string without sanitization. Attackers can inject arbitrary Pytho=
n code that executes when the generated server code runs via subprocess.Pop= en().</td>
<td>2026-07-10</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61444" target=3D= "_blank" rel=3D"noopener">CVE-2026-61444</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 4.6.78 contains arbitrary file write and command execu= tion vulnerabilities in the AICoder component due to missing path validatio=
n and command sanitization in LLM tool calls. Attackers can inject maliciou=
s prompts through the chat interface to write files to arbitrary filesystem=
locations and execute arbitrary shell commands with root privileges.</td> <td>2026-07-11</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61445" target=3D= "_blank" rel=3D"noopener">CVE-2026-61445</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 1.7.3 contains an insecure default configuration that = binds to all interfaces with no API key requirement and wildcard CORS. Unau= thenticated attackers can call GET /api/agents to read agent instructions a=
nd system prompts, or POST /api/chat to invoke agents without authenticatio= n.</td>
<td>2026-07-11</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61426" target=3D= "_blank" rel=3D"noopener">CVE-2026-61426</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI versions before 1.6.78 contain a server-side request forgery = vulnerability in the Crawl4AI/Chromium backend that allows attackers to byp= ass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attacke=
rs can craft URLs that resolve to internal services after the initial valid= ation check, enabling the headless browser to follow redirects and read int= ernal responses including sensitive canary values.</td>
<td>2026-07-11</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61429" target=3D= "_blank" rel=3D"noopener">CVE-2026-61429</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerabil= ity in shell command execution that allows attackers to execute restricted = commands via find's built-in -exec, -execdir, and -delete actions. Attacker=
s can craft find commands with these built-in actions to read blocked files=
, delete files, or execute non-allowlisted binaries without triggering shel=
l metacharacter filters.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61434" target=3D= "_blank" rel=3D"noopener">CVE-2026-61434</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 4.6.78 contains an unauthenticated server-side request=
forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_u=
rl parameter is validated at request time but re-resolved at connection tim=
e, allowing attackers to use DNS rebinding to reach internal services with =
a blind SSRF attack.</td>
<td>2026-07-10</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60091" target=3D= "_blank" rel=3D"noopener">CVE-2026-60091</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI AgentMail versions before 4.6.78 lack signature verification =
in webhook mode, allowing unauthenticated attackers to inject messages with=
spoofed sender addresses. Attackers can POST crafted message.received even=
ts to the webhook endpoint to inject arbitrary content into the agent and t= rigger replies to attacker-controlled addresses, bypassing sender allow/blo=
ck lists.</td>
<td>2026-07-11</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61428" target=3D= "_blank" rel=3D"noopener">CVE-2026-61428</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsaf=
e dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class=
(src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a work= flow step uses a string output_pydantic reference, the framework locates an=
d imports a sibling tools.py from the workflow file's directory via importl=
ib exec_module without sandboxing, ignoring the PRAISONAI_ALLOW_*_TOOLS env= ironment variables. An attacker who controls a workflow file and its siblin=
g tools.py can execute arbitrary Python code with the workflow runner's pri= vileges when the workflow is executed via WorkflowManager or after load_yam= l.</td>
<td>2026-07-10</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61437" target=3D= "_blank" rel=3D"noopener">CVE-2026-61437</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI versions before 4.6.78 contain a prompt injection defense mis= configuration where the block threshold defaults to CRITICAL severity, allo= wing HIGH-level threats to pass through unblocked. Attackers can submit sin= gle-vector prompt injection attacks such as instruction overrides or financ= ial manipulation that trigger HIGH severity detection but are logged withou=
t blocking, enabling system prompt extraction and unauthorized tool invocat= ions.</td>
<td>2026-07-11</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61439" target=3D= "_blank" rel=3D"noopener">CVE-2026-61439</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce o= wner/admin authorization on the PATCH routes for projects, issues, and agen= ts, which only require workspace-member role. A workspace member can modify=
owner-created records; for projects, a member can reassign lead_id to thei=
r own user id and then delete the owner-created project, bypassing the dele=
te route's owner/admin permission check.</td>
<td>2026-07-11</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61442" target=3D= "_blank" rel=3D"noopener">CVE-2026-61442</a></td>
</tr>
<td class=3D"vendor-product">metabase--metabase</td>
<td>Metabase is an open-source business intelligence and embedded analytics=
tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase=
did not validate unsafe H2 connection properties on one database-creation = code path, allowing an authenticated administrator to register a crafted H2=
database connection and execute arbitrary Java code on the Metabase server=
. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.= </td>
<td>2026-07-09</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59826" target=3D= "_blank" rel=3D"noopener">CVE-2026-59826</a></td>
</tr>
<td class=3D"vendor-product">metabase--metabase</td>
<td>Metabase is an open-source business intelligence and embedded analytics=
tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instance=
s with an H2 database connection, including the default sample database, de= serialize arbitrary Java objects returned in H2 native query result columns=
of type OTHER without validation, allowing an authenticated user who can r=
un native H2 queries to execute code on the Metabase server. This issue is = fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.</td> <td>2026-07-09</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59827" target=3D= "_blank" rel=3D"noopener">CVE-2026-59827</a></td>
</tr>
<td class=3D"vendor-product">metagauss--EventPrime Events Calendar, Booking=
s and Tickets</td>
<td>The EventPrime - Events Calendar, Bookings and Tickets plugin for WordP= ress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_b= ackground_color' parameter in all versions up to, and including, 4.3.4.2 du=
e to insufficient input sanitization and output escaping. This makes it pos= sible for authenticated attackers, with custom-level access and above, to i= nject arbitrary web scripts in pages that will execute whenever a user acce= sses an injected page. This requires the plugin's Guest Submissions setting=
(allow_submission_by_anonymous_user) to be enabled, which allows unauthent= icated attackers to submit event types via the frontend form; when that set= ting is disabled, exploitation requires at minimum a subscriber-level authe= nticated account.</td>
<td>2026-07-09</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13441" target=3D= "_blank" rel=3D"noopener">CVE-2026-13441</a></td>
</tr>
<td class=3D"vendor-product">Metasoft --MetaCRM</td>
<td>A weakness has been identified in Metasoft =C3=A7=C2=BE=C5=BD=C3=A7=E2= =80=B0=C2=B9=C3=A8=C2=BD=C2=AF=C3=A4=C2=BB=C2=B6 MetaCRM up to 6.4.0 Beta06=
. This vulnerability affects the function RPCService.query of the file /cus= tomizemt/xkq/rpc.jsp of the component PHPRPC Remote Call Interface. Executi=
ng a manipulation of the argument phprpc_args can lead to sql injection. Th=
e attack can be launched remotely. The exploit has been made available to t=
he public and could be used for attacks. The vendor was contacted early abo=
ut this disclosure but did not respond in any way.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15514" target=3D= "_blank" rel=3D"noopener">CVE-2026-15514</a></td>
</tr>
<td class=3D"vendor-product">Micro-Star International (MSI)--KernCoreLib64.= sys</td>
<td>MSI Feature Manager contains a local privilege escalation vulnerability=
in the KernCoreLib64.sys kernel driver that allows any locally logged-on u= ser to perform arbitrary physical memory read/write and unrestricted I/O po=
rt operations by accessing exposed IOCTL handlers without administrator pri= vileges. Attackers can exploit the accessible device object through IOCTL h= andlers to manipulate kernel objects, tamper with kernel-mode callbacks, by= pass Protected Process Light protections, and disable security software.</t=
<td>2026-07-07</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57851" target=3D= "_blank" rel=3D"noopener">CVE-2026-57851</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Dynamics 365 Customer Voice</td> <td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') in Dynamics 365 Customer Voice allows an unauthorized attacke=
r to perform spoofing over a network.</td>
<td>2026-07-08</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47646" target=3D= "_blank" rel=3D"noopener">CVE-2026-47646</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Edge (Chromium-based)</td=
<td>Deserialization of untrusted data in Microsoft Edge (Chromium-based) al= lows an unauthorized attacker to execute code over a network.</td> <td>2026-07-11</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58281" target=3D= "_blank" rel=3D"noopener">CVE-2026-58281</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Edge (Chromium-based)</td=
<td>Improper access control in Microsoft Edge (Chromium-based) allows an un= authorized attacker to bypass a security feature over a network.</td> <td>2026-07-08</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58525" target=3D= "_blank" rel=3D"noopener">CVE-2026-58525</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Edge (Chromium-based)</td=
<td>Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows=
an unauthorized attacker to elevate privileges over a network.</td> <td>2026-07-12</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58596" target=3D= "_blank" rel=3D"noopener">CVE-2026-58596</a></td>
</tr>
<td class=3D"vendor-product">miniOrange Security Software Pvt Ltd.--OAuth S= ingle Sign On - SSO (OAuth Client)</td>
<td>Authentication Bypass Using an Alternate Path or Channel vulnerability =
in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth = Client) allows Password Recovery Exploitation. This issue affects OAuth Sin= gle Sign On - SSO (OAuth Client): from n/a through 38.5.8.</td> <td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57807" target=3D= "_blank" rel=3D"noopener">CVE-2026-57807</a></td>
</tr>
<td class=3D"vendor-product">mockoon--mockoon</td>
<td>Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mocko= on's admin API in commons-server/src/libs/server/admin-api.ts is mounted on=
the same Express listener as user-defined mock routes, enabled by default =
in shipped runtimes, serves Access-Control-Allow-Origin: * with write metho=
ds allowed, and has no authentication. Any unauthenticated caller who can r= each the mock server port can read MOCKOON_* environment variables, write a= rbitrary process environment variables through /mockoon-admin/env-vars, rew= rite mock route bodies, statuses, and headers through PUT /mockoon-admin/en= vironment, read transaction logs and SSE streams, and purge state. This iss=
ue is fixed in version 9.7.0.</td>
<td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59148" target=3D= "_blank" rel=3D"noopener">CVE-2026-59148</a></td>
</tr>
<td class=3D"vendor-product">mohammed_kaludi--AMP for WP Accelerated Mobile=
Pages</td>
<td>The AMP for WP - Accelerated Mobile Pages plugin for WordPress is vulne= rable to Arbitrary File Write in versions up to and including 1.1.12. This =
is due to unsafe ZIP file extraction in the ampforwp_save_local_font() func= tion combined with inadequate cleanup that fails to remove nested directori=
es and files. This makes it possible for authenticated attackers, with Auth= or-level access and above, and permissions granted by an Administrator, to = write arbitrary files to the server in a web-accessible location, potential=
ly leading to remote code execution on hosts that execute PHP files in the = uploads directory.</td>
<td>2026-07-07</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6101" target=3D"= _blank" rel=3D"noopener">CVE-2026-6101</a></td>
</tr>
<td class=3D"vendor-product">Monsta Limited of New Zealand--Monsta FTP</td> <td>Monsta FTP before 2.14.5 contains a server-side request forgery vulnera= bility in the fetchRemoteFile action caused by an incomplete IP blocklist c= heck in the isBlockedIP() function, which fails to detect embedded IPv4 add= resses within IPv4-mapped IPv6 addresses. An unauthenticated attacker can o= btain a CSRF token from the public getSystemVars endpoint and submit a fetc= hRemoteFile request with a source URL resolving to an IPv4-mapped address, = causing the server to issue HTTP requests to internal services and write re= sponses to an attacker-controlled FTP destination, enabling retrieval of cl= oud instance metadata credentials.</td>
<td>2026-07-08</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60105" target=3D= "_blank" rel=3D"noopener">CVE-2026-60105</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypas=
s in the POST /workflows/{workflowId}/test-runs/new endpoint, which authori= zes access using the workflow:read scope instead of workflow:execute. An au= thenticated user with read-only access to a workflow can trigger a real eva= luation test run, causing the workflow to execute via the internal workflow=
runner and resulting in unintended outbound API calls, data mutations, or = other side effects in connected downstream systems. The issue primarily aff= ects instances using the Evaluations feature where RBAC project roles grant=
workflow:read without workflow:execute.</td>
<td>2026-07-08</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56776" target=3D= "_blank" rel=3D"noopener">CVE-2026-56776</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_au= th_user was configured, a parser fast path intended for ordinary client con= nections could also apply to route or leafnode listeners, allowing an unaut= henticated peer to bypass inter-server CONNECT authentication and operate w= ith the privileges associated with that connection type. This issue is fixe=
d in versions 2.14.0, 2.12.7, and 2.11.16.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58253" target=3D= "_blank" rel=3D"noopener">CVE-2026-58253</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.3 and 2.12.12, a client able to se=
nd account-scoped connection monitoring requests could crash the server by = supplying Connz pagination Offset and Limit values that overflowed internal=
arithmetic before the response window was safely bounded. This issue is fi= xed in versions 2.14.3 and 2.12.12.</td>
<td>2026-07-08</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58207" target=3D= "_blank" rel=3D"noopener">CVE-2026-58207</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated = MQTT client could cause the server to retain large incomplete MQTT CONNECT = packets before authentication completed, consuming server memory while the = parser waited for the advertised MQTT packet length. This issue is fixed in=
versions 2.14.3 and 2.12.12.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58210" target=3D= "_blank" rel=3D"noopener">CVE-2026-58210</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could=
include protocol control characters in subscription filters that were late=
r forwarded as NATS protocol data to route or leafnode connections, corrupt= ing the forwarded protocol stream and allowing injection of unintended NATS=
protocol operations. This issue is fixed in versions 2.14.1 and 2.12.9.</t=
<td>2026-07-08</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58213" target=3D= "_blank" rel=3D"noopener">CVE-2026-58213</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated = peer with network access to a leafnode listener with compression enabled co= uld crash the server during the pre-authentication leafnode handshake by se= nding repeated leafnode INFO protocol messages before authentication and ac= count setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.<=
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58250" target=3D= "_blank" rel=3D"noopener">CVE-2026-58250</a></td>
</tr>
<td class=3D"vendor-product">nesquena--hermes-webui</td>
<td>Hermes WebUI before 0.51.307 contains an authentication bypass vulnerab= ility that allows unauthenticated remote attackers to circumvent local-orig=
in IP restrictions on onboarding endpoints by supplying a spoofed X-Forward= ed-For header with a loopback address. Attackers can exploit this bypass to=
perform server-side request forgery against internal services including cl= oud metadata endpoints, overwrite LLM provider configuration and API keys w= ith attacker-controlled values, or initiate OAuth device-code flows to obta=
in persistent access tokens stored in auth.json.</td>
<td>2026-07-09</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58122" target=3D= "_blank" rel=3D"noopener">CVE-2026-58122</a></td>
</tr>
<td class=3D"vendor-product">nesquena--hermes-webui</td>
<td>Hermes WebUI before 0.51.788 contains an unauthenticated remote code ex= ecution vulnerability that allows remote attackers to execute arbitrary she=
ll commands by accessing the embedded terminal API endpoints without creden= tials. Attackers can create a session, attach a PTY shell, and write arbitr= ary commands through the terminal input endpoint to achieve full command ex= ecution as the server process user via four sequential unauthenticated HTTP=
requests.</td>
<td>2026-07-09</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58123" target=3D= "_blank" rel=3D"noopener">CVE-2026-58123</a></td>
</tr>
<td class=3D"vendor-product">nicu_m--Simple JWT Login Allows you to use JWT=
on REST endpoints.</td>
<td>The Simple JWT Login - Allows you to use JWT on REST endpoints. plugin = for WordPress is vulnerable to Authentication Bypass to Privilege Escalatio=
n in all versions up to, and including, 3.6.6 via the `payload` parameter. = The vulnerability exists because `AuthenticateService::generatePayload()` o= nly overwrites JWT payload keys whose names appear in the admin-configured = `jwt_payload` list - leaving any attacker-supplied identity claims such as = `email`, `id`, or `username` intact and signed into the JWT with the site's=
HS256 secret. This makes it possible for authenticated attackers, with sub= scriber-level access and above, to escalate their privileges to that of an = Administrator by injecting a target administrator's email address into the = `payload` parameter at the `/wp-json/simple-jwt-login/v1/auth` endpoint, th=
en redeeming the resulting JWT at the `/autologin` endpoint to obtain a ful=
ly authenticated session as that administrator.</td>
<td>2026-07-11</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14262" target=3D= "_blank" rel=3D"noopener">CVE-2026-14262</a></td>
</tr>
<td class=3D"vendor-product">ninjew--GEO my WP</td>
<td>The GEO my WP plugin for WordPress was vulnerable to SQL Injection via = the 'distance', 'lat', and 'lng' parameters in versions up to, and includin=
g, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str(=
) (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed t= hrough bare esc_sql() before being interpolated into unquoted numeric posit= ions in the proximity-search query (HAVING/SELECT clause distance math, BET= WEEN bounding-box pre-filter) built by gmw_locations_query() in plugins/pos= ts-locator/includes/class-gmw-wp-query.php. Because esc_sql() only escapes = string delimiters and these positions are numeric, payloads such as `1 OR S= LEEP(3)` survived sanitization. Fixed in 4.5.5 by adding an upstream is_num= eric() guard that short-circuits the WHERE clause to `AND 1 =3D 0` when eit= her coordinate is non-numeric, and by replacing the three esc_sql() calls w= ith (float) casts.</td>
<td>2026-07-10</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15300" target=3D= "_blank" rel=3D"noopener">CVE-2026-15300</a></td>
</tr>
<td class=3D"vendor-product">nodeca--js-yaml</td>
<td>js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.=
0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing=
a document whose size grows only linearly when a chain of mappings uses me= rge keys where each mapping merges the previous one. This issue is fixed in=
versions 3.15.0 and 4.3.0.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59869" target=3D= "_blank" rel=3D"noopener">CVE-2026-59869</a></td>
</tr>
<td class=3D"vendor-product">Nozomi Networks--Guardian</td>
<td>An Incorrect Privilege Assignment vulnerability was discovered in the s= ynchronization functionality due to Arc sensors receiving CLI permissions. =
An authenticated user with limited privileges can push administrative CLI c= ommands through the sync, altering the device configuration, and/or affecti=
ng its availability.</td>
<td>2026-07-09</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33390" target=3D= "_blank" rel=3D"noopener">CVE-2026-33390</a></td>
</tr>
<td class=3D"vendor-product">Nozomi Networks--Guardian</td>
<td>An Open Redirect vulnerability was discovered in the SAML Single Sign-O=
n functionality due to insufficient validation of a user-controlled redirec= tion parameter. An unauthenticated attacker can craft a request to the SAML=
sign-in endpoint and poison the cached SAML redirection for other users wh=
o subsequently initiate SAML Single Sign-On, enabling phishing and credenti= al-theft attacks, as well as disrupting SAML authentication for all affecte=
d users.</td>
<td>2026-07-09</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31982" target=3D= "_blank" rel=3D"noopener">CVE-2026-31982</a></td>
</tr>
<td class=3D"vendor-product">Nozomi Networks--Guardian</td>
<td>A denial-of-service vulnerability caused by unbounded resource allocati=
on was discovered in the audit logging functionality, due to a missing size=
limit on input recorded into audit entries. An unauthenticated attacker ca=
n submit requests containing excessively large input that is recorded into = audit entries, possibly exhausting the available disk space and rendering t=
he system inoperable.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31984" target=3D= "_blank" rel=3D"noopener">CVE-2026-31984</a></td>
</tr>
<td class=3D"vendor-product">Nozomi Networks--Remote Collector</td>
<td>When the upstream Guardian or CMC was configured in the Remote Collecto=
r via n2os-tui, the generated configuration disabled TLS certificate verifi= cation, and no option was provided to enable it. A malicious actor could pe= rform a man-in-the-middle attack and intercept the communication between th=
e Remote Collector and the Guardian or CMC. This could result in theft of t=
he sync token, impersonation of the server, injection of spoofed data (such=
as false asset information or vulnerabilities) into the Guardian or CMC, o=
r disruption of the data flow between the Remote Collector and the Guardian=
or CMC.</td>
<td>2026-07-09</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31985" target=3D= "_blank" rel=3D"noopener">CVE-2026-31985</a></td>
</tr>
<td class=3D"vendor-product">ntpsec--gpsd</td>
<td>gpsd through release-3.27.5, fixed at commit 4c06658, contains a comman=
d injection vulnerability in gpsprof that allows attackers who control the = GPS device subtype value to execute arbitrary shell commands by embedding b= acktick payloads in the gnuplot plot title without proper escaping. The sub= type field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is = written into a generated gnuplot program via a set title statement with onl=
y double-quote characters escaped, enabling arbitrary shell command executi=
on as the user running gnuplot when the victim renders the generated plot t= hrough the gpsprof and gnuplot workflow.</td>
<td>2026-07-09</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58459" target=3D= "_blank" rel=3D"noopener">CVE-2026-58459</a></td>
</tr>
<td class=3D"vendor-product">OceanicSoft Informatics Systems Ltd.--ValeApp<=
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp=
allows Stored XSS. This issue affects ValeApp: through 09072026.=C2=A0NOTE=
: The vendor was contacted early about this disclosure but did not respond =
in any way.</td>
<td>2026-07-09</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2342" target=3D"= _blank" rel=3D"noopener">CVE-2026-2342</a></td>
</tr>
<td class=3D"vendor-product">Omnissa--Omnissa Workspace ONE Tunnel for Wind= ows</td>
<td>Omnissa Workspace ONE=C3=82=C2=AE Tunnel for Windows addresses a Local = Privilege Escalation Vulnerability.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-22927" target=3D= "_blank" rel=3D"noopener">CVE-2026-22927</a></td>
</tr>
<td class=3D"vendor-product">open-telemetry--opentelemetry-js</td> <td>OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior =
to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id a=
nd uberctx-* HTTP header values with decodeURIComponent() without handling = decode errors, allowing an unauthenticated remote attacker to send a malfor= med percent-encoded value that throws an uncaught URIError and terminates a=
Node.js process using JaegerPropagator as the active propagator. This issu=
e is fixed in version 2.9.0.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59892" target=3D= "_blank" rel=3D"noopener">CVE-2026-59892</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py bui=
lt the ws_terminal upstream URL from an unencoded session_id and appended u= ser_id as a query parameter, allowing query injection to make the terminal = backend resolve another user identity; the HTTP proxy path also forwarded X= -User-Id as an integrity-unbound identity claim. This issue is fixed in ver= sion 0.10.0.</td>
<td>2026-07-09</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59224" target=3D= "_blank" rel=3D"noopener">CVE-2026-59224</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyo= dide in a same-origin web worker, allowing stored chat payloads that use py= odide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue = authenticated same-origin requests when a victim clicks Run, which can reac=
h admin-only endpoints and execute server-side code through configured tool=
s. This issue is fixed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59214" target=3D= "_blank" rel=3D"noopener">CVE-2026-59214</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, get_event_call delivered execute:python and=
execute:tool Socket.IO events to a client-supplied session_id after checki=
ng only that the session was connected, allowing authenticated users who le= arned another socket ID through ydoc:document:join to run code interpreter = Python or tools in that user session. This issue is fixed in version 0.10.0= .</td>
<td>2026-07-09</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59216" target=3D= "_blank" rel=3D"noopener">CVE-2026-59216</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO co= nnect, user-join, join-channels, join-note, and the terminal websocket firs= t-message authentication used decode_token without the Redis-backed is_vali= d_token revocation check, allowing revoked JWTs to continue authenticating = realtime connections. This issue is fixed in version 0.10.0.</td> <td>2026-07-09</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59219" target=3D= "_blank" rel=3D"noopener">CVE-2026-59219</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/op= en_webui/routers/terminals.py decoded proxy paths only eight times, allowin=
g a nine-times percent-encoded ../ traversal value to pass normalization ch= ecks and be decoded by the upstream terminal server. This issue is fixed in=
version 0.10.0.</td>
<td>2026-07-09</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59221" target=3D= "_blank" rel=3D"noopener">CVE-2026-59221</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>ssh in OpenSSH before 10.4 can have a use-after-free when a server chan= ges its host key during a key re-exchange. (This outcome occurs only on the=
client side.)</td>
<td>2026-07-08</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60002" target=3D= "_blank" rel=3D"noopener">CVE-2026-60002</a></td>
</tr>
<td class=3D"vendor-product">OpenClaw--OpenClaw</td>
<td>OpenClaw before 2026.5.28 contains a credential exposure vulnerability = where workspace dotenv files can override provider credentials. Attackers w= ith lower-trust access to configured input paths can expose sensitive data = and credentials that should remain within trusted boundaries.</td> <td>2026-07-08</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59261" target=3D= "_blank" rel=3D"noopener">CVE-2026-59261</a></td>
</tr>
<td class=3D"vendor-product">OpenCTI-Platform--opencti</td>
<td>OpenCTI is an open source platform for managing cyber threat intelligen=
ce knowledge and observables. Prior to 7.260326.0, an authorization bypass = vulnerability in OpenCTI allows any authenticated user with KNOWLEDGE_KNUPD= ATE permission to bypass Confidence Level validation and Object Marking res= trictions by injecting the synchronized-upsert: true HTTP header, enabling = attackers to downgrade confidence levels, remove security markings such as = TLP:RED, manipulate relationships, and affect STIX object types including I= ndicators, ThreatActors, Malware, and Reports. This issue is fixed in versi=
on 7.260326.0.</td>
<td>2026-07-08</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35210" target=3D= "_blank" rel=3D"noopener">CVE-2026-35210</a></td>
</tr>
<td class=3D"vendor-product">OpenPLC--OpenPLC</td>
<td>OpenPLC Runtime v3 contains an authenticated arbitrary file write vulne= rability in the legacy web UI program-upload workflow. The application stor=
es an attacker-supplied filename (prog_file) directly into the Programs.Fil=
e database field and later uses this value as the destination path for an u= ploaded file without validating or restricting the path. Because Python os.= path.join() honors attacker-controlled absolute paths, an authenticated use=
r can write arbitrary files anywhere writable by the OpenPLC webserver proc= ess. In the default build pipeline, all C++ source files within the OpenPLC=
runtime core directory are automatically compiled into the executable runt= ime binary. By writing a malicious .cpp file into this directory, an authen= ticated attacker can escalate the arbitrary file write into arbitrary nativ=
e code execution when the operator triggers a normal program compilation an=
d runtime start.</td>
<td>2026-07-10</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14480" target=3D= "_blank" rel=3D"noopener">CVE-2026-14480</a></td>
</tr>
<td class=3D"vendor-product">openreplay--openreplay</td>
<td>OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.= 25.0, the OpenReplay tracking SDK accepts custom event names and captured p= age URLs from any visitor using a public project key, stores them in ClickH= ouse without output encoding, and later renders them in the authenticated d= ashboard through TextEllipsis and the event-details modal, allowing an unau= thenticated attacker to store script that executes in the dashboard origin,=
reads the session JWT from localStorage, and takes over a dashboard accoun=
t. This issue is fixed in version 1.25.0.</td>
<td>2026-07-10</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55879" target=3D= "_blank" rel=3D"noopener">CVE-2026-55879</a></td>
</tr>
<td class=3D"vendor-product">openreplay--openreplay</td>
<td>OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier=
, three dashboard and note mutation functions ran their SQL without the own= ership predicate that their sibling read and edit functions use: notes.dele=
te filtered only on note id and project id, while dashboards.update_widget = and dashboards.remove_widget filtered only on dashboard id and widget id, a= llowing any authenticated member to delete another user's private session n= otes and remove or rewrite widgets on another user's private dashboards.</t=
<td>2026-07-10</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55880" target=3D= "_blank" rel=3D"noopener">CVE-2026-55880</a></td>
</tr>
<td class=3D"vendor-product">openresty--openresty</td>
<td>OpenResty is a high performance web platform. From 1.29.2.1 to before 1= .29.2.5, an out-of-bounds write vulnerability exists in the upstream PROXY = protocol v2 implementation. When OpenResty is configured to send PROXY prot= ocol version 2 headers to upstream servers, constructing the header in the = stream proxy protocol v2 patch can write beyond the bounds of the allocated=
buffer, causing the worker process to crash and resulting in a denial of s= ervice. Only configurations that explicitly enable PROXY protocol v2 for up= stream connections are impacted. This issue is fixed in version 1.29.2.5.</=
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55233" target=3D= "_blank" rel=3D"noopener">CVE-2026-55233</a></td>
</tr>
<td class=3D"vendor-product">OpenStack--Ironic</td>
<td>In OpenStack Ironic before 37.0.1, an Ironic user with the ability to d= eploy nodes using the IPMI management interface can maliciously use the sen= d_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's ac= cess control.</td>
<td>2026-07-10</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54423" target=3D= "_blank" rel=3D"noopener">CVE-2026-54423</a></td>
</tr>
<td class=3D"vendor-product">openwrt--luci</td>
<td>OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sb= in/smbd, allowing authenticated delegated users to execute the Samba daemon=
with caller-controlled command-line arguments. Attackers can pass arbitrar=
y Samba global options such as message command to a root smbd process, trig= gering command execution when SMB protocol messages are processed.</td> <td>2026-07-12</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59260" target=3D= "_blank" rel=3D"noopener">CVE-2026-59260</a></td>
</tr>
<td class=3D"vendor-product">openwrt--luci</td>
<td>luci-app-upnp contains a stored cross-site scripting vulnerability that=
allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPo= rtMapping SOAP requests. Attackers can send malicious HTML in the NewPortMa= ppingDescription field, which miniupnpd stores and luci-app-upnp renders wi= thout output encoding, executing the payload when administrators view the U= PnP or Status pages.</td>
<td>2026-07-12</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61875" target=3D= "_blank" rel=3D"noopener">CVE-2026-61875</a></td>
</tr>
<td class=3D"vendor-product">openwrt--luci</td>
<td>LuCI versions fail to properly encode DHCPv6 lease hostnames before ren= dering in status tables, allowing adjacent network attackers to inject HTML=
markup. Attackers can send a DHCPv6 Client FQDN containing script tags tha=
t execute in the administrator's browser when viewing DHCP lease pages.</td=
<td>2026-07-12</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61876" target=3D= "_blank" rel=3D"noopener">CVE-2026-61876</a></td>
</tr>
<td class=3D"vendor-product">oraios--serena</td>
<td>Serena is a powerful MCP toolkit for coding that provides semantic retr= ieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dash= board exposes an unauthenticated Flask API on a fixed, predictable port, wi=
th no authentication, no CSRF protection, and no Host header validation. A = DNS rebinding attack allows a malicious webpage to reach this API from any = browser and write arbitrary content to the agent's persistent memory store,=
which the agent reads and acts on autonomously. Combined with execute_shel= l_command using shell=3DTrue, this creates a remote code execution chain re= quiring only that the victim visit a malicious webpage while Serena is runn= ing. This issue is fixed in version v1.5.2.</td>
<td>2026-07-07</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49471" target=3D= "_blank" rel=3D"noopener">CVE-2026-49471</a></td>
</tr>
<td class=3D"vendor-product">owasp-modsecurity--ModSecurity</td> <td>ModSecurity is an open source, cross platform web application firewall = (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form= -data request body parser in libmodsecurity silently removes embedded line = breaks from non-file form-field values before exporting them to ARGS and AR= GS_POST because src/request_body_processor/multipart.cc overwrites reserved=
bytes in m_reserve instead of appending the current buffer. This creates a=
parser differential between ModSecurity and backend applications that pres= erve line breaks in form fields, allowing rules that inspect ARGS or ARGS_P= OST to miss payloads whose dangerous syntax depends on a line break. This i= ssue is fixed in version 3.0.16.</td>
<td>2026-07-10</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52747" target=3D= "_blank" rel=3D"noopener">CVE-2026-52747</a></td>
</tr>
<td class=3D"vendor-product">owncloud--Anti-Virus for ownCloud</td> <td>Anti-Virus for ownCloud is an anti-virus application for file storage, = synchronization, and sharing application ownCloud. Versions of Anti-Virus f=
or ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSR= F). This corresponds to versions of ownCloud 10 prior to 10.15.3. Upgrade o= wnCloud 10 to version 10.15.3 or later or upgrade Anti-Virus for ownCloud 1=
0 to version 1.2.3 or later to receive a fix.</td>
<td>2026-07-06</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-53830" target=3D= "_blank" rel=3D"noopener">CVE-2025-53830</a></td>
</tr>
<td class=3D"vendor-product">owncloud--DrawIO for ownCloud</td>
<td>DrawIO for ownCloud is an application for using DrawIO with the file st= orage, synchronization, and sharing application ownCloud Classic. In DrawIO=
for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prio=
r to version 10.15.3, attackers with access to the DrawIO app can leverage = improper neutralization of input during web page generation to achieve stor=
ed XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO f=
or ownCloud 10 to version 1.0.2 or later to receive a patch.</td> <td>2026-07-06</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-53831" target=3D= "_blank" rel=3D"noopener">CVE-2025-53831</a></td>
</tr>
<td class=3D"vendor-product">owncloud--ownCloud 10</td>
<td>ownCloud is a file storage, synchronization, and sharing application. I=
n ownCloud 10 prior to version 10.15.3, an attacker with administrative pri= vileges can exploit a path traversal vulnerability in the system to execute=
arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive=
a patch.</td>
<td>2026-07-06</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-53829" target=3D= "_blank" rel=3D"noopener">CVE-2025-53829</a></td>
</tr>
<td class=3D"vendor-product">owncloud--ownCloud Core</td>
<td>ownCloud Core is the server-side component of the file storage, synchro= nization, and sharing application ownCloud Classic. In versions prior to 10= .15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous m= ethod or function. Attackers with administrative privileges may leverage fu= nctionality to execute arbitrary code. This issue has been fixed in version=
10.15.3.</td>
<td>2026-07-06</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-53827" target=3D= "_blank" rel=3D"noopener">CVE-2025-53827</a></td>
</tr>
<td class=3D"vendor-product">owncloud--SharePoint</td>
<td>SharePoint for ownCloud is an application for using SharePoint with the=
file storage, synchronization, and sharing application ownCloud Classic. I=
n SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownC= loud 10 prior to 10.15.3, an attacker with administrative privileges can us=
e a SSRF vulnerability in the SharePoint app to execute arbitrary code on t=
he system. Upgrade ownCloud 10 to version 10.15.3 or later to receive Share= Point for ownCloud 0.4.1, the fixed version.</td>
<td>2026-07-06</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-53828" target=3D= "_blank" rel=3D"noopener">CVE-2025-53828</a></td>
</tr>
<td class=3D"vendor-product">PasswordPusher--PasswordPusher</td> <td>PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloa=
ds due to insufficient validation in the valid_url function. Attackers can = create malicious pushes containing data:text/html URIs that execute arbitra=
ry JavaScript in victims' browsers when clicked, enabling phishing and cred= ential theft under the trusted PasswordPusher domain.</td>
<td>2026-07-08</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59802" target=3D= "_blank" rel=3D"noopener">CVE-2026-59802</a></td>
</tr>
<td class=3D"vendor-product">PAVO Financial Technology Solutions Inc.--PAVO=
Pay</td>
<td>Authorization bypass through User-Controlled key vulnerability in PAVO = Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted=
Identifiers. This issue affects PAVO Pay: through 09072026.=C2=A0NOTE: The=
vendor was contacted early about this disclosure but did not respond in an=
y way.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1989" target=3D"= _blank" rel=3D"noopener">CVE-2026-1989</a></td>
</tr>
<td class=3D"vendor-product">PEAKUP Technology Inc.--PassGate</td>
<td>Improper neutralization of special elements used in an LDAP query ('LDA=
P injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP = Injection. This issue affects PassGate: through 30042026.</td> <td>2026-07-09</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4256" target=3D"= _blank" rel=3D"noopener">CVE-2026-4256</a></td>
</tr>
<td class=3D"vendor-product">pechenki--TelSender ontact form 7, Events, Wpf= orms, ninja forms and woocommerce to telegram bot</td>
<td>The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Sit=
e Scripting in all versions up to, and including, 1.14.14. This is due to i= nsufficient input sanitization when processing Telegram API responses conta= ining attacker-controlled chat titles. This makes it possible for unauthent= icated attackers to inject malicious scripts via Telegram chat titles that = execute when an administrator opens the TelSender settings page and clicks = the "Tested" button.</td>
<td>2026-07-10</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15298" target=3D= "_blank" rel=3D"noopener">CVE-2026-15298</a></td>
</tr>
<td class=3D"vendor-product">pimcore--pimcore</td>
<td>Pimcore is an Open Source Data & Experience Management Platform. Pr= ior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid=
admin username can take over any Pimcore admin account by sending a passwo=
rd reset request with an attacker-controlled resetPasswordUrl. The server g= enerates a real cryptographic recovery token, appends it to the supplied UR=
L, and emails the link to the victim; when the victim clicks the link, the = token is sent to the attacker and can be used with POST /pimcore-studio/api= /login/token to authenticate with full admin privileges while bypassing two= -factor authentication. This issue is fixed in versions 2025.4.6 and 2026.1= .6.</td>
<td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55207" target=3D= "_blank" rel=3D"noopener">CVE-2026-55207</a></td>
</tr>
<td class=3D"vendor-product">pimcore--pimcore</td>
<td>Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio.=
Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admi=
n password hash and other database content through time-based blind SQL inj= ection in the DateFilter column key parameter. The POST /pimcore-studio/api= /website-settings endpoint and other listing endpoints accept a columnFilte=
rs array where the key field is interpolated directly into SQL with manual = backtick wrapping, allowing a backtick character to break out of quoting an=
d append arbitrary SQL such as SLEEP() and IF() subqueries. This issue is f= ixed in versions 2025.4.6 and 2026.1.6.</td>
<td>2026-07-09</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55208" target=3D= "_blank" rel=3D"noopener">CVE-2026-55208</a></td>
</tr>
<td class=3D"vendor-product">pimcore--pimcore</td>
<td>Pimcore is an Open Source Data & Experience Management Platform. Pr= ior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endp= oint POST /pimcore-studio/api/class/definition/configuration-view/detail/cr= eate is guarded by the objects permission instead of the classes permission=
, allowing a standard editor-level user to create class definitions without=
admin privileges. Class definition creation generates new database tables = and PHP class files on the server, and missing API-layer UID format validat= ion allows malformed UIDs to reach model-layer validation and return intern=
al exceptions. This issue is fixed in versions 2025.4.6 and 2026.1.6.</td> <td>2026-07-09</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55212" target=3D= "_blank" rel=3D"noopener">CVE-2026-55212</a></td>
</tr>
<td class=3D"vendor-product">pipecat-ai--pipecat</td>
<td>Pipecat is an open-source Python framework for building real-time voice=
and multimodal conversational agents. Prior to 1.4.0, the pipecat developm= ent runner registers a /ws WebSocket endpoint for telephony testing that ac= cepts connections without authentication, reads an attacker-supplied callSi=
d from a Twilio stream-start handshake in src/pipecat/runner/utils.py, and = passes it to TwilioFrameSerializer so the server can issue an authenticated=
Twilio REST API hang-up request with the server operator's credentials; eq= uivalent unauthenticated call-control sinks exist for Telnyx and Plivo. Thi=
s issue is fixed in version 1.4.0.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54695" target=3D= "_blank" rel=3D"noopener">CVE-2026-54695</a></td>
</tr>
<td class=3D"vendor-product">pixelgrade--Backstage Customizer Demo Access</=
<td>The Backstage - Customizer Demo Access plugin for WordPress is vulnerab=
le to Privilege Escalation in all versions up to, and including, 1.4.2. Thi=
s is due to the plugin assigning the `manage_options` capability to the `ba= ckstage_customizer_user` demo role, which is more permissive than necessary=
for Customizer-only demo access. This makes it possible for unauthenticate=
d attackers to navigate beyond the Customizer and update arbitrary WordPres=
s options such as `default_role`, leading to privilege escalation.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9842" target=3D"= _blank" rel=3D"noopener">CVE-2026-9842</a></td>
</tr>
<td class=3D"vendor-product">pnpm--pnpm</td>
<td>pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts pa= ckage names from the env lockfile configDependencies section and uses those=
names directly when creating config dependency symlinks under node_modules= /.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml w= hose env-lockfile document contains a traversal-shaped config dependency na= me. During pnpm install, pnpm installs the config dependency and creates a = symlink at a path derived from that name. This vulnerability is fixed in 10= .34.4 and 11.8.0.</td>
<td>2026-07-06</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59195" target=3D= "_blank" rel=3D"noopener">CVE-2026-59195</a></td>
</tr>
<td class=3D"vendor-product">pnpm--pnpm</td>
<td>pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch=
entry could resolve outside the configured patches directory and cause pnp=
m patch-remove to delete an arbitrary reachable file. This vulnerability is=
fixed in 10.34.4 and 11.7.0.</td>
<td>2026-07-06</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59194" target=3D= "_blank" rel=3D"noopener">CVE-2026-59194</a></td>
</tr>
<td class=3D"vendor-product">pnpm--pnpm</td>
<td>pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockf= ile alias could be joined directly under a hoisted node_modules directory. = Traversal aliases could escape that directory, while reserved aliases such =
as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is f= ixed in 10.34.4 and 11.7.0.</td>
<td>2026-07-06</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59196" target=3D= "_blank" rel=3D"noopener">CVE-2026-59196</a></td>
</tr>
<td class=3D"vendor-product">PROG MIS--ERP App</td>
<td>ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulne= rability, allowing unauthenticated remote attackers to log in to view appli= cation code and obtain the database account and password.</td> <td>2026-07-06</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14807" target=3D= "_blank" rel=3D"noopener">CVE-2026-14807</a></td>
</tr>
<td class=3D"vendor-product">PROG MIS--Prog Management System</td>
<td>Prog Management System developed by PROG MIS has a Exposure of Sensitiv=
e Information vulnerability, allowing unauthenticated remote attackers to v= iew a specific page and obtain the database account and password.</td> <td>2026-07-06</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14808" target=3D= "_blank" rel=3D"noopener">CVE-2026-14808</a></td>
</tr>
<td class=3D"vendor-product">PROG MIS--Prog Management System</td>
<td>Prog Management System developed by PROG MIS has a SQL Injection vulner= ability, allowing unauthenticated remote attackers to inject arbitrary SQL = commands to read database contents.</td>
<td>2026-07-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14809" target=3D= "_blank" rel=3D"noopener">CVE-2026-14809</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). Th=
is issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.= 1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.</td>
<td>2026-07-08</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11903" target=3D= "_blank" rel=3D"noopener">CVE-2026-11903</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Improper Neutralization of Special Elements in Data Query Logic vulnera= bility in Progress MOVEit Transfer (Custom Reports modules). This issue aff= ects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2= 025.1.4, from 2026.0.0 before 2026.0.1.</td>
<td>2026-07-08</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10698" target=3D= "_blank" rel=3D"noopener">CVE-2026-10698</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Missing release of memory after effective lifetime vulnerability in Pro= gress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit T= ransfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from=
2026.0.0 before 2026.0.1.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10699" target=3D= "_blank" rel=3D"noopener">CVE-2026-10699</a></td>
</tr>
<td class=3D"vendor-product">prowler-cloud--prowler</td>
<td>Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML a= uthentication flow trusted the email domain asserted in a SAMLResponse when=
deciding which tenant should receive the final token, and the ACS finish l= ogic in api/src/backend/api/v1/views.py recalculated the tenant from user.e= mail instead of binding token issuance to the validated SAML configuration.=
An authenticated attacker with a controlled SAML IdP could complete a vali=
d SAML flow for an attacker-controlled domain while asserting an email addr= ess from another configured domain, causing a SAMLToken and tenant-scoped J=
WT to be issued for the wrong tenant and enabling cross-tenant account take= over. This issue is fixed in version 5.30.3.</td>
<td>2026-07-10</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59151" target=3D= "_blank" rel=3D"noopener">CVE-2026-59151</a></td>
</tr>
<td class=3D"vendor-product">python-pillow--Pillow</td>
<td>Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py=
_load_bitmaps() read glyph dimensions from the PCF METRICS section and pas= sed them directly to Image.frombytes() without calling Image._decompression= _bomb_check(), allowing crafted PCF font data to cause excessive memory all= ocation. This issue is fixed in version 12.3.0.</td>
<td>2026-07-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54059" target=3D= "_blank" rel=3D"noopener">CVE-2026-54059</a></td>
</tr>
<td class=3D"vendor-product">python-pillow--Pillow</td>
<td>Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py Fo= ntFile.compile() assembled per-glyph images into a combined bitmap with Ima= ge.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check= (), allowing a font to trigger excessive allocation during conversion or sa= ving. This issue is fixed in version 12.3.0.</td>
<td>2026-07-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54060" target=3D= "_blank" rel=3D"noopener">CVE-2026-54060</a></td>
</tr>
<td class=3D"vendor-product">python-pillow--Pillow</td>
<td>Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py=
bdf_char() read the BBX width and height field from a BDF font file and pa= ssed attacker-controlled dimensions to Image.new() without calling Image._d= ecompression_bomb_check(), bypassing Pillow's documented decompression bomb=
protection and allowing excessive memory allocation. This issue is fixed i=
n version 12.3.0.</td>
<td>2026-07-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55379" target=3D= "_blank" rel=3D"noopener">CVE-2026-55379</a></td>
</tr>
<td class=3D"vendor-product">python-pillow--Pillow</td>
<td>Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py=
GdImageFile._open() read image dimensions from the GD 2.x header and store=
d them in self._size without calling Image._decompression_bomb_check(), all= owing a crafted .gd file to trigger excessive C-heap allocation when loaded=
. This issue is fixed in version 12.3.0.</td>
<td>2026-07-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55380" target=3D= "_blank" rel=3D"noopener">CVE-2026-55380</a></td>
</tr>
<td class=3D"vendor-product">qax-os--excelize</td>
<td>Excelize is a Go language library for reading and writing Microsoft Exc=
el spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/x= uri/excelize/v2 uses an attacker-controlled <row r=3D"N"> XML attribu=
te value directly as the length argument to make([]xlsxRow, row) without va= lidating it against the Excel row limit (TotalRows =3D 1,048,576). A specia= lly crafted XLSX file can trigger two denial-of-service variants: (A) an ou= t-of-memory process kill when r=3D2147483647 forces a ~16 GB allocation att= empt, and (B) a runtime panic via out-of-bounds slice indexing when r=3D-1.=
Any service that opens attacker-supplied XLSX files and calls GetCellValue=
is affected. No authentication is required. This issue is fixed in version=
2.11.0.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54063" target=3D= "_blank" rel=3D"noopener">CVE-2026-54063</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when processing invalid HT40 channel layouts during d= ynamic channel switching operations.</td>
<td>2026-07-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25268" target=3D= "_blank" rel=3D"noopener">CVE-2026-25268</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when allocating memory with sizes that exceed the max= imum allowed value.</td>
<td>2026-07-06</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21379" target=3D= "_blank" rel=3D"noopener">CVE-2026-21379</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Cryptographic Issue when using a static initialization vector for AES-G=
CM key wrapping, which requires a unique value for each call to ensure secu= rity.</td>
<td>2026-07-06</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21383" target=3D= "_blank" rel=3D"noopener">CVE-2026-21383</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when processing asynchronous input parameters due to = improper handling of modified values between check and use.</td> <td>2026-07-06</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25271" target=3D= "_blank" rel=3D"noopener">CVE-2026-25271</a></td>
</tr>
<td class=3D"vendor-product">QuantumNous--new-api</td>
<td>New API is a large language mode (LLM) gateway and artificial intellige= nce (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF=
protection configuration did not apply IP filtering to hostnames; with App= lyIPFilterForDomain disabled by default, URL validation checked domain allo= w/block rules but did not resolve a hostname and validate the resolved IP a= ddress, allowing authenticated users to configure Webhook, Bark, or Gotify = notification URLs that point at an internal or metadata IP address. This is= sue is fixed in version 0.12.0-alpha.1.</td>
<td>2026-07-09</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33655" target=3D= "_blank" rel=3D"noopener">CVE-2026-33655</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the Rabbi= tMQ stream listener does not enforce the configured stream frame-size limit=
while assembling frames during authentication and before Tune negotiation,=
allowing an unauthenticated remote client to declare oversized frame lengt=
hs and consume broker memory in rabbit_stream_core. This issue is fixed in = version 4.2.6.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57220" target=3D= "_blank" rel=3D"noopener">CVE-2026-57220</a></td>
</tr>
<td class=3D"vendor-product">rabilal--WP Learn Manager</td>
<td>The WP Learn Manager plugin for WordPress is vulnerable to authorizatio=
n bypass in all versions up to, and including, 1.1.8. This is due to the pl= ugin not properly verifying that a user is authorized to perform an action.=
This makes it possible for unauthenticated attackers to install and activa=
te arbitrary plugins from the WordPress.org repository on the vulnerable si= te.</td>
<td>2026-07-08</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12153" target=3D= "_blank" rel=3D"noopener">CVE-2026-12153</a></td>
</tr>
<td class=3D"vendor-product">RafyMrX--TOKO-ONLINE-ROTI</td>
<td>A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1c= d587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an un= known functionality of the file proses/login.php. The manipulation of the a= rgument Username leads to sql injection. Remote exploitation of the attack =
is possible. The exploit is publicly available and might be used. This prod= uct follows a rolling release approach for continuous delivery, so version = details for affected or updated releases are not provided. The vendor was c= ontacted early about this disclosure but did not respond in any way.</td> <td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15489" target=3D= "_blank" rel=3D"noopener">CVE-2026-15489</a></td>
</tr>
<td class=3D"vendor-product">RafyMrX--TOKO-ONLINE-ROTI</td>
<td>A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to d= dfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unk= nown functionality of the file proses/add.php. The manipulation of the argu= ment kode_produk/kd_cs results in sql injection. The attack can be executed=
remotely. The exploit has been released to the public and may be used for = attacks. This product implements a rolling release for ongoing delivery, wh= ich means version information for affected or updated releases is unavailab= le. The vendor was contacted early about this disclosure but did not respon=
d in any way.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15490" target=3D= "_blank" rel=3D"noopener">CVE-2026-15490</a></td>
</tr>
<td class=3D"vendor-product">RafyMrX--TOKO-ONLINE-ROTI</td>
<td>A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1c= d587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This mani= pulation causes missing authentication. The attack is possible to be carrie=
d out remotely. This product adopts a rolling release strategy to maintain = continuous delivery. Therefore, version details for affected or updated rel= eases cannot be specified. The vendor was contacted early about this disclo= sure but did not respond in any way.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15491" target=3D= "_blank" rel=3D"noopener">CVE-2026-15491</a></td>
</tr>
<td class=3D"vendor-product">react--create-react-app</td>
<td>A vulnerability was detected in react create-react-app up to 5.0.1 on m= acOS. This affects the function startBrowserProcess of the file openBrowser= .js of the component react-dev-utils. Performing a manipulation results in =
os command injection. Remote exploitation of the attack is possible. The ex= ploit is now public and may be used. The project was informed of the proble=
m early through an issue report but has not responded yet.</td> <td>2026-07-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14802" target=3D= "_blank" rel=3D"noopener">CVE-2026-14802</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Advanced Cluster Security for=
Kubernetes 4.10</td>
<td>A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (R= HACS). Central does not limit the depth of GraphQL queries served on the au= thenticated GraphQL API. An authenticated user with a valid API token can s= end deeply nested queries that cause excessive resource consumption in Cent= ral, resulting in a denial of service for the management plane.</td> <td>2026-07-06</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9165" target=3D"= _blank" rel=3D"noopener">CVE-2026-9165</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_searc= h_base option is not explicitly configured, SSSD searches the entire LDAP d= irectory tree for sudoRole objects. An authenticated attacker with write ac= cess to any subtree can inject a sudoRole object granting root-level sudo p= rivileges on all SSSD-enrolled hosts.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14474" target=3D= "_blank" rel=3D"noopener">CVE-2026-14474</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_e= xtract_smb_components() function does not sanitize .. sequences in the gPCF= ileSysPath LDAP attribute, allowing an attacker with AD GPO management acce=
ss to write files outside the GPO cache directory as root. On default RHEL = configurations with SELinux enforcing, this can be used to inject Kerberos = configuration leading to authentication bypass.</td>
<td>2026-07-07</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14476" target=3D= "_blank" rel=3D"noopener">CVE-2026-14476</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A heap buffer overflow vulnerability was found in GStreamer's rfbsrc pl= ugin. When a client connects to a malicious RFB/VNC server that advertises =
a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile backgrou=
nd fill path writes 32-bit pixel values into a buffer allocated for 16-bit = pixels. This type mismatch causes an out-of-bounds heap write that can lead=
to denial of service (process crash) and potential memory corruption.</td> <td>2026-07-09</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59691" target=3D= "_blank" rel=3D"noopener">CVE-2026-59691</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A stack buffer overflow vulnerability was found in GStreamer's DTLS plu= gin. During a DTLS handshake, the peer certificate Subject Distinguished Na=
me is printed into a fixed-size 2048-byte stack buffer without bounds check= ing. A remote unauthenticated attacker can send a certificate with an overs= ized Subject DN that exceeds the buffer, causing a stack buffer overflow an=
d process crash, resulting in denial of service.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59692" target=3D= "_blank" rel=3D"noopener">CVE-2026-59692</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 6</td>
<td>A flaw was found in GIMP's PNM file format parser. When parsing a speci= ally crafted PNM file, the pnmscanner_gettoken() function writes a null ter= minator one byte past the end of a stack-allocated buffer due to an off-by-= one error in the loop boundary check. This could lead to memory corruption,=
potentially resulting in denial of service or arbitrary code execution.</t=
<td>2026-07-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58380" target=3D= "_blank" rel=3D"noopener">CVE-2026-58380</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 6</td>
<td>A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_= channel() can cause an undersized heap allocation for the RLE row-length ta= ble, after which subsequent per-row writes corrupt heap memory. This could = lead to memory corruption, potentially resulting in denial of service or ar= bitrary code execution.</td>
<td>2026-07-07</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58384" target=3D= "_blank" rel=3D"noopener">CVE-2026-58384</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat OpenShift AI (RHOAI)</td>
<td>A flaw was found in the file_type content detector of guardrails-detect= ors. This vulnerability allows a remote attacker to supply an arbitrary XML=
Schema Definition (XSD) string, which is processed without proper restrict= ions. This can lead to server-side requests to arbitrary URLs or local file=
reads, potentially resulting in sensitive information disclosure, such as = cloud provider credentials or access to internal network services.</td> <td>2026-07-10</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15143" target=3D= "_blank" rel=3D"noopener">CVE-2026-15143</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat OpenShift AI (RHOAI)</td>
<td>A flaw was found in the `guardrails-detectors` component. This vulnerab= ility allows a remote attacker to perform a blind Server-Side Request Forge=
ry (SSRF) by submitting a specially crafted XML Schema Definition (XSD) str= ing. This can lead to unauthorized access to sensitive information, includi=
ng credentials from cloud metadata services, Kubernetes API, internal MinIO=
, and other internal network endpoints. Additionally, it enables local file=
reads of critical data such as service account tokens and pod secrets.</td=
<td>2026-07-10</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15378" target=3D= "_blank" rel=3D"noopener">CVE-2026-15378</a></td>
</tr>
<td class=3D"vendor-product">repomix--repomix</td>
<td>repomix contains a server-side request forgery vulnerability in the POS=
T /api/pack endpoint that allows unauthenticated attackers to make arbitrar=
y outbound requests. The endpoint fails to properly validate
http://, https= ://, and file:// URLs before passing them to git clone, enabling attackers =
to access private network addresses, GCP metadata services, or local filesy= stem paths.</td>
<td>2026-07-08</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59702" target=3D= "_blank" rel=3D"noopener">CVE-2026-59702</a></td>
</tr>
<td class=3D"vendor-product">repomix--repomix</td>
<td>repomix contains a local file inclusion vulnerability in the git clone = endpoint that allows unauthenticated attackers to read arbitrary local git = repositories. The isValidRemoteValue function in src/core/git/gitRemotePars= e.ts fails to block file:// URLs, permitting attackers to supply file:// sc= heme URLs that bypass validation and are passed directly to git clone, enab= ling unauthorized access to all tracked file contents on the server filesys= tem.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59703" target=3D= "_blank" rel=3D"noopener">CVE-2026-59703</a></td>
</tr>
<td class=3D"vendor-product">rnzo--Connect Contact Form 7 and Mailchimp</td=
<td>The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulner= able to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all=
versions up to, and including, 0.9.78.06 due to insufficient input sanitiz= ation and output escaping. This makes it possible for unauthenticated attac= kers to inject arbitrary web scripts in pages that will execute whenever a = user accesses an injected page. The injected payload is only triggered when=
a privileged user (Administrator) performs a Contact Lookup for the email = address submitted via the CF7 form, meaning execution is deferred until an = administrator interacts with the affected entry.</td>
<td>2026-07-09</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15000" target=3D= "_blank" rel=3D"noopener">CVE-2026-15000</a></td>
</tr>
<td class=3D"vendor-product">ronf--asyncssh</td>
<td>AsyncSSH is a Python package which provides an asynchronous client and = server implementation of the SSHv2 protocol on top of the Python asyncio fr= amework. Prior to 2.23.1, a malicious SSH server can write arbitrary files =
on the asyncssh SCP client's filesystem by sending filenames containing ../=
traversal sequences because _parse_cd_args in scp.py returns server-provid=
ed names verbatim and _recv_files joins them to the destination path withou=
t enforcing the target directory boundary. This issue is fixed in version 2= .23.1.</td>
<td>2026-07-08</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54591" target=3D= "_blank" rel=3D"noopener">CVE-2026-54591</a></td>
</tr>
<td class=3D"vendor-product">RustDesk--RustDesk</td>
<td>RustDesk before 1.4.9 does not enforce a session's authorized connectio=
n scope on the server side, so a peer granted a limited session type (FileT= ransfer, PortForward, ViewCamera, or Terminal) can send control messages an=
d login options reserved for a full Remote session. An authenticated remote=
peer can exploit this missing scope check to act outside its granted scope=
, injecting out-of-scope control messages to observe and control the host b= eyond the permissions it was given.</td>
<td>2026-07-10</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57850" target=3D= "_blank" rel=3D"noopener">CVE-2026-57850</a></td>
</tr>
<td class=3D"vendor-product">ruvnet--ruflo</td>
<td>Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16= .3, ruflo's default docker-compose deployment exposed the MCP bridge POST /= mcp and POST /mcp/:group endpoints without authentication, allowing an unau= thenticated network attacker to invoke tools/call to terminal_execute, obta=
in a shell in the bridge container, read provider API keys, and poison Agen= tDB learning-store patterns. This issue is fixed in version 3.16.3.</td> <td>2026-07-09</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59726" target=3D= "_blank" rel=3D"noopener">CVE-2026-59726</a></td>
</tr>
<td class=3D"vendor-product">seaweedfs--seaweedfs</td>
<td>SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API ga= teway does not reject dot-dot path segments in the X-Amz-Copy-Source header=
used by CopyObject and UploadPartCopy, allowing an authenticated identity = scoped to one bucket to read objects from other buckets through server-side=
copy. This issue is fixed in version 4.34.</td>
<td>2026-07-08</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55874" target=3D= "_blank" rel=3D"noopener">CVE-2026-55874</a></td>
</tr>
<td class=3D"vendor-product">SecureAge--CatchPulse</td>
<td>A security vulnerability has been detected in SecureAge CatchPulse up t=
o 10.9.3. The affected element is an unknown function in the library saappc= tl.sys of the component Driver. Such manipulation leads to heap-based buffe=
r overflow. An attack has to be approached locally. The exploit has been di= sclosed publicly and may be used. The vendor was contacted early about this=
disclosure.</td>
<td>2026-07-12</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15506" target=3D= "_blank" rel=3D"noopener">CVE-2026-15506</a></td>
</tr>
<td class=3D"vendor-product">Semtek Informatics Software Consulting Trade L= td. Co.--SEM-PMP</td>
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in Semtek Informatics Software Consulting Trade=
Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This=
issue affects SEM-PMP: through 23042026.</td>
<td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5801" target=3D"= _blank" rel=3D"noopener">CVE-2026-5801</a></td>
</tr>
<td class=3D"vendor-product">sergomanov--SmartHomeAdatum</td>
<td>A vulnerability was identified in sergomanov SmartHomeAdatum up to cf49= 5353d81b680675eb8d9aa14a318aa45ce12c. This impacts an unknown function of t=
he file users.php of the component Login. Such manipulation of the argument=
Login leads to sql injection. The attack may be launched remotely. This pr= oduct operates on a rolling release basis, ensuring continuous delivery. Co= nsequently, there are no version details for either affected or updated rel= eases. The vendor was contacted early about this disclosure but did not res= pond in any way.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15498" target=3D= "_blank" rel=3D"noopener">CVE-2026-15498</a></td>
</tr>
<td class=3D"vendor-product">shen2--</td>
<td>The =C3=A5=C2=A4=C5=A1=C3=A8=C2=AF=C2=B4=C3=A7=C2=A4=C2=BE=C3=A4=C2=BC= =C5=A1=C3=A5=C5=92=E2=80=93=C3=A8=C2=AF=E2=80=9E=C3=A8=C2=AE=C2=BA=C3=A6=C2= =A1=E2=80=A0 plugin for WordPress is vulnerable to Privilege Escalation in = all versions up to, and including, 1.2. The vulnerability exists due to a m= issing capability and nonce check on a directly web-accessible API endpoint=
, combined with a trivially forgeable HMAC-SHA1 signature keyed on an alway= s-empty WordPress option, which allows the endpoint's `update_option` handl=
er to pass attacker-controlled `option` and `value` parameters directly to = WordPress's `update_option` function without any allowlist or sanitization.=
This makes it possible for unauthenticated attackers to update arbitrary W= ordPress options - such as setting `default_role` to `administrator` and en= abling open registration - and subsequently register an account with full a= dministrator privileges.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14482" target=3D= "_blank" rel=3D"noopener">CVE-2026-14482</a></td>
</tr>
<td class=3D"vendor-product">Siemens--CPCI85 Central Processing/Communicati= on</td>
<td>A vulnerability has been identified in CPCI85 Central Processing/Commun= ication (All versions < V26.20), SICORE Base system (All versions < V= 26.20.0). The affected application contains insufficient validation of auth= entication credentials when processing administrative account modifications=
through the web API. This could allow an authenticated attacker to bypass = security controls and gain unauthorized elevated privileges.</td> <td>2026-07-09</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54801" target=3D= "_blank" rel=3D"noopener">CVE-2026-54801</a></td>
</tr>
<td class=3D"vendor-product">SimpleMachines--SMF</td>
<td>Simple Machines Forum 2.1 prior to 2.1.8 and 3.0 prior to 3.0 Alpha 5 c= ontains an authorization bypass vulnerability in Sources/Actions/Attachment= Approve.php where a single-character operator error causes the permission c= heck to always pass regardless of user permissions. An authenticated low-pr= ivileged user can approve, reject, or delete any pending attachments on any=
board without holding the required approve_posts permission, bypass modera= tion queues for their own uploads, and enumerate and delete other users' pe= nding attachments.</td>
<td>2026-07-10</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39903" target=3D= "_blank" rel=3D"noopener">CVE-2026-39903</a></td>
</tr>
<td class=3D"vendor-product">Sipeed--PicoClaw</td>
<td>A security vulnerability has been detected in Sipeed PicoClaw up to 0.2= .9. This affects the function IPAllowlist of the file web/backend/middlewar= e/access_control.go of the component Launcher. Such manipulation leads to i= mproper access controls. The attack may be performed from remote. The explo=
it has been disclosed publicly and may be used. The name of the patch is 31= 26. A patch should be applied to remediate this issue.</td>
<td>2026-07-10</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15319" target=3D= "_blank" rel=3D"noopener">CVE-2026-15319</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan is an open-source personal knowledge management system. Prior to=
3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/serve= r/serve.go joins a single-decoded request path with the snippets directory = without subpath containment or sensitive-path checks, allowing an authentic= ated request such as /snippets/%2e%2e/%2e%2e/conf/conf.json to read workspa=
ce secrets and the document database. This issue is fixed in versions 3.7.1= .</td>
<td>2026-07-09</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59832" target=3D= "_blank" rel=3D"noopener">CVE-2026-59832</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan is an open-source personal knowledge management system. Prior to=
3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock conc= atenates attacker-controlled paths values into SQL predicates used by non-S=
QL search modes, allowing an unauthenticated publish visitor to inject a UN= ION SELECT and return rows from hidden documents by projecting an allowed v= isible box and path. This issue is fixed in versions 3.7.1.</td> <td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59834" target=3D= "_blank" rel=3D"noopener">CVE-2026-59834</a></td>
</tr>
<td class=3D"vendor-product">smackcoders--WP Ultimate CSV Importer WordPres=
s Import & Export for CSV, XML & Excel</td>
<td>The WP Ultimate CSV Importer - WordPress Import & Export for CSV, X=
ML & Excel plugin for WordPress is vulnerable to Remote Code Execution =
in all versions up to, and including, 8.0.1 via the 'MappedFields' paramete=
r. This is due to missing capability checks on the AJAX handlers for instal= l_addon, saveMappedFields, and StartImport, combined with the plugin nonce = being exposed to any authenticated user who can load an admin page, allowin=
g a Subscriber to install the Import WooCommerce add-on, persist attacker-c= ontrolled PHP expressions in the MappedFields parameter, and trigger evalua= tion via eval() in ImportHelpers::get_meta_values(). This makes it possible=
for authenticated attackers, with subscriber-level access and above, to ex= ecute code on the server.</td>
<td>2026-07-11</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13353" target=3D= "_blank" rel=3D"noopener">CVE-2026-13353</a></td>
</tr>
<td class=3D"vendor-product">smallnest--rpcx</td>
<td>rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-servi=
ce vulnerability in protocol.Message.Decode (protocol/message.go). When a m= essage has the compression flag set, the payload is gzip-decompressed via u= til.Unzip with no limit on the decompressed output size. The only built-in = size guard, protocol.MaxMessageLength, is checked against the compressed on= -the-wire frame length, not the decompressed size, so it provides no protec= tion. Because decoding (and decompression) occurs in readRequest before aut= hentication, a single unauthenticated connection can send a small (under 2 = MB) gzip-compressed message that expands to gigabytes of heap allocation, l= eading to out-of-memory conditions and service unavailability.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59803" target=3D= "_blank" rel=3D"noopener">CVE-2026-59803</a></td>
</tr>
<td class=3D"vendor-product">Snowflake--Snowpark Python SDK</td>
<td>SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (sno= wpark-python) versions prior to 1.53.0 could allow authenticated low-privil= ege users to execute SQL beyond their authorization scope. An attacker coul=
d exploit these vulnerabilities by embedding SQL payloads in source databas=
e column names to escalate privileges via the DataFrameReader.dbapi() API b=
y supplying a specially crafted location parameter to DataFrameWriter write=
methods to redirect a COPY INTO to an arbitrary source query, or by includ= ing a backslash-single-quote sequence in an export path to defeat the norma= lize_path() sanitizer and inject SQL via DataFrame.to_csv(). Successful exp= loitation may result in source database compromise, unauthorized cross-tena=
nt data exfiltration, or unauthorized read of Snowflake account data.</td> <td>2026-07-08</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15062" target=3D= "_blank" rel=3D"noopener">CVE-2026-15062</a></td>
</tr>
<td class=3D"vendor-product">Snowflake--Terraform Provider for Snowflake</t=
<td>Snowflake Terraform Provider versions prior to 2.18.0 contain several s= ecurity vulnerabilities, including SQL injection via an unsanitized data so= urce input could result in arbitrary SQL execution under the provider's pri= vileged Snowflake session, potentially enabling sensitive data exfiltration=
and minting of long-lived access credentials. Exploitation requires the ab= ility for an attacker to influence a workspace variable in a pipeline where=
this data source was enabled. Improper neutralization of identifier conten=
t in user resource inputs could allow DDL injection into user management st= atements, potentially causing accounts to be created with attacker-controll=
ed credentials and without the security controls configured by the operator=
. The fix is available in Snowflake Terraform Provider version 2.18.0. User=
s must manually upgrade.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15067" target=3D= "_blank" rel=3D"noopener">CVE-2026-15067</a></td>
</tr>
<td class=3D"vendor-product">socketio--socket.io</td>
<td>Socket.IO enables bidirectional and low-latency communication for every=
platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport ena= bled can resolve a crafted session ID such as __proto__ through an inherite=
d property of the clients object during WebTransport upgrade handling, caus= ing a TypeError and denial of service. This issue is fixed in version 6.6.7= .</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59724" target=3D= "_blank" rel=3D"noopener">CVE-2026-59724</a></td>
</tr>
<td class=3D"vendor-product">socketio--socket.io</td>
<td>Socket.IO enables bidirectional and low-latency communication for every=
platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport=
does not properly close the HTTP response for invalid binary POST requests=
with Content-Type: application/octet-stream, allowing an unauthenticated a= ttacker to exhaust server-side connections and sockets. This issue is fixed=
in version 6.6.7.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59725" target=3D= "_blank" rel=3D"noopener">CVE-2026-59725</a></td>
</tr>
<td class=3D"vendor-product">SonicCloudOrg--sonic-agent</td>
<td>A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2=
. This affects an unknown function of the file sonic-server-controller/src/= main/java/org/cloud/sonic/controller/controller/ExchangeController.java of = the component JWT Authentication Filter. This manipulation causes code inje= ction. The attack may be initiated remotely. The exploit has been publicly = disclosed and may be utilized. The vendor was contacted early about this di= sclosure but did not respond in any way. This vulnerability only affects pr= oducts that are no longer supported by the maintainer.</td>
<td>2026-07-12</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15497" target=3D= "_blank" rel=3D"noopener">CVE-2026-15497</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Simple and Nice Shopping Cart = Script</td>
<td>A vulnerability was detected in SourceCodester Simple and Nice Shopping=
Cart Script 1.0. This affects an unknown part of the file /login.php. Perf= orming a manipulation of the argument Username results in sql injection. Re= mote exploitation of the attack is possible. The exploit is now public and = may be used.</td>
<td>2026-07-09</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15190" target=3D= "_blank" rel=3D"noopener">CVE-2026-15190</a></td>
</tr>
<td class=3D"vendor-product">spinnaker--spinnaker</td>
<td>Spinnaker is an open source, multi-cloud continuous delivery platform. = Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing=
bypasses safe deserialization when using CloudFormation deployments or Clo= udFoundry baking. The use of a non-safe constructor allows arbitrary loadin=
g of Java classes, leading to remote code execution. This issue is fixed in=
versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44795" target=3D= "_blank" rel=3D"noopener">CVE-2026-44795</a></td>
</tr>
<td class=3D"vendor-product">spinnaker--spinnaker</td>
<td>Spinnaker is an open source, multi-cloud continuous delivery platform. = Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respe= ctive release lines, Kustomize bake operations allow unsafe YAML tag proces= sing in rosco manifests. This can lead to remote code execution on rosco po=
ds when performing Kustomize bakes. This issue is fixed in versions 2026.1.=
1, 2026.0.3, 2025.4.4, and 2025.3.4.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55175" target=3D= "_blank" rel=3D"noopener">CVE-2026-55175</a></td>
</tr>
<td class=3D"vendor-product">ST Engineering iDirect--Evolution iQSeries ter= minals</td>
<td>The iDirect iQ200 does not validate CSRF tokens on state-changing API e= ndpoints after authentication. The /api/reboot endpoint accepts POST reques=
ts authenticated solely by a session cookie that lacks the SameSite attribu= te. A remote attacker can host a malicious web page that, when visited by a=
n authenticated administrator, automatically submits a cross-site POST requ= est causing an immediate device reboot and satellite link loss. Repeated at= tacks can sustain a denial-of-service condition.</td>
<td>2026-07-10</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38057" target=3D= "_blank" rel=3D"noopener">CVE-2026-38057</a></td>
</tr>
<td class=3D"vendor-product">ST Engineering iDirect--Evolution iQSeries ter= minals</td>
<td>The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoint=
s without authentication. An unauthenticated attacker with network access c=
an retrieve sensitive device information including the serial number, Devic=
e ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact f= irmware version. The DID and TPK are used for satellite network authenticat= ion in the iDirect platform, potentially enabling terminal impersonation an=
d network reconnaissance.</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38059" target=3D= "_blank" rel=3D"noopener">CVE-2026-38059</a></td>
</tr>
<td class=3D"vendor-product">stanfordnlp--stanza</td>
<td>Stanza is a Stanford NLP Python library for tokenization, sentence segm= entation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza=
model loaders such as stanza.models.common.pretrain.Pretrain.load() attemp=
t torch.load(..., weights_only=3DTrue) but fall back to torch.load(..., wei= ghts_only=3DFalse) on attacker-controllable pickle.UnpicklingError, allowin=
g a malicious .pt pretrain or model file to execute arbitrary pickle code w= hen a Stanza NLP pipeline loads it. This issue is fixed in version 1.12.2.<=
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54499" target=3D= "_blank" rel=3D"noopener">CVE-2026-54499</a></td>
</tr>
<td class=3D"vendor-product">stiofansisland--UsersWP Front-end login form, = User Registration, User Profile & Members Directory plugin for WP</td> <td>The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deleti=
on in versions up to, and including, 1.2.65. This is due to insufficient va= lidation of file-field values in the UsersWP_Validation::validate_fields() = function (which falls through to sanitize_text_field() for fields of type '= file', leaving directory-traversal sequences intact) combined with the User= sWP_Forms::upload_file_remove() AJAX handler building the deletion target f= rom the uploads basedir concatenated with the attacker-controlled metadata = value without any realpath canonicalization or uploads-directory boundary c= heck before calling unlink(). This makes it possible for authenticated atta= ckers, with Subscriber-level access and above, to delete arbitrary files on=
the affected site's server, including wp-config.</td>
<td>2026-07-09</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13492" target=3D= "_blank" rel=3D"noopener">CVE-2026-13492</a></td>
</tr>
<td class=3D"vendor-product">stylemix--Motors Car Dealership & Classifi=
ed Listings Plugin</td>
<td>The Motors - Car Dealership & Classified Listings Plugin plugin for=
WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content=
and User Biographical Info in all versions up to, and including, 1.4.112 d=
ue to insufficient input sanitization and output escaping. This makes it po= ssible for unauthenticated attackers to inject arbitrary web scripts in pag=
es that will execute whenever a user accesses an injected page.</td> <td>2026-07-11</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13114" target=3D= "_blank" rel=3D"noopener">CVE-2026-13114</a></td>
</tr>
<td class=3D"vendor-product">surecart--SureCart Ecommerce Made Easy For Sel= ling Physical Products, Digital Downloads, Subscriptions, Donations, & = Payments</td>
<td>The SureCart plugin for WordPress is vulnerable to privilege escalation=
via account takeover in versions up to, and including, 4.2.3. This is due =
to the plugin not properly validating a user's identity prior to updating t= heir details like email during customer profile synchronization from webhoo=
k events. This makes it possible for unauthenticated attackers to change li= nked user's email addresses, including administrators if the administrator = account is linked to a SureCart customer record, and leverage that to reset=
the user's password and gain access to their account if the customer ID is=
known.</td>
<td>2026-07-11</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7655" target=3D"= _blank" rel=3D"noopener">CVE-2026-7655</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A vulnerability has been identified in Fleet's agent-side deployer, whi=
ch did not filter security-sensitive keys from namespaceLabels in fleet.yam=
l (or BundleDeployment.spec.options.namespaceLabels) when applying them to = the target namespace. An attacker with git push access to a Fleet-monitored=
repository could overwrite Pod Security Standards (PSS) enforcement labels=
on a target namespace. This allows the attacker to weaken admission contro=
ls and deploy workloads that PSS policies would otherwise block.</td> <td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44938" target=3D= "_blank" rel=3D"noopener">CVE-2026-44938</a></td>
</tr>
<td class=3D"vendor-product">symfony--ux</td>
<td>Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.= 36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs f= iles from a recipe kit by copying paths listed in a copy-files map, and bec= ause Path::isRelative() accepts paths like ../../../etc, a crafted or compr= omised kit can write attacker-controlled content to arbitrary locations or = read local files outside the recipe directory. This issue is fixed in versi= ons 2.36.1 and 3.2.0.</td>
<td>2026-07-08</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55878" target=3D= "_blank" rel=3D"noopener">CVE-2026-55878</a></td>
</tr>
<td class=3D"vendor-product">tainacan--Tainacan</td>
<td>The Tainacan plugin for WordPress is vulnerable to time-based blind SQL=
Injection via the 'geoquery' parameter in all versions up to and including=
1.0.3 due to insufficient escaping on the user supplied parameter and lack=
of sufficient preparation on the existing SQL query. This makes it possibl=
e for unauthenticated attackers to append additional SQL queries into alrea=
dy existing queries that can be used to extract sensitive information from = the database.</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6230" target=3D"= _blank" rel=3D"noopener">CVE-2026-6230</a></td>
</tr>
<td class=3D"vendor-product">Tanium--Tanium Server</td>
<td>Tanium addressed a denial of service vulnerability in Tanium Server.</t=
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15053" target=3D= "_blank" rel=3D"noopener">CVE-2026-15053</a></td>
</tr>
<td class=3D"vendor-product">templatic1--Hide My WP Lite</td>
<td>The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary Fil=
e Read in versions up to and including 1.3 via the he_wrapper_js and he_wra= pper_css query parameters processed by the elementor_assets_filter() functi= on. This is due to the function concatenating user-supplied input directly = onto ABSPATH and passing the result to file_get_contents() without any path=
traversal validation, allow-list, realpath containment, or extension check=
; the result is then echoed in the HTTP response. Although the output is pa= ssed through wp_kses_post(), that function only filters HTML tags and does = not prevent disclosure of arbitrary file contents. This makes it possible f=
or unauthenticated attackers to read the contents of arbitrary files on the=
affected site's server (such as wp-config). Note: The exploit requires the=
Elementor plugin and the 'Hide Elementor' feature to be enabled.</td> <td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13347" target=3D= "_blank" rel=3D"noopener">CVE-2026-13347</a></td>
</tr>
<td class=3D"vendor-product">tenteeglobal--Instant Appointment</td>
<td>The Instant Appointment plugin for WordPress is vulnerable to arbitrary=
file uploads due to missing file type validation in the 'insapp_upload_ima= ge_as_attachment' function in all versions up to, and including, 1.2. This = makes it possible for unauthenticated attackers to upload arbitrary files o=
n the affected site's server which may make remote code execution possible.= </td>
<td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15282" target=3D= "_blank" rel=3D"noopener">CVE-2026-15282</a></td>
</tr>
<td class=3D"vendor-product">Teracity Software Technologies Inc.--TeraMIS</=
<td>Authorization bypass through User-Controlled key vulnerability in Terac= ity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue a= ffects TeraMIS: from V03.26.01.14 through 30.04.2026.</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6212" target=3D"= _blank" rel=3D"noopener">CVE-2026-6212</a></td>
</tr>
<td class=3D"vendor-product">themeatelier--ChatHelp Click to Chat Button, W= ooCommerce Chat to Order & Floating Chat Form</td>
<td>The Chat Help - Click to Chat Button & Form plugin for WordPress is=
vulnerable to Sensitive Information Exposure in all versions up to, and in= cluding, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /= wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing a=
ny authentication and authorization checks. This makes it possible for unau= thenticated attackers to extract sensitive data including customer names, e= mail addresses, phone numbers, WhatsApp messages, complete geolocation data=
(IP addresses, city, country, ISP, coordinates), device fingerprinting inf= ormation (browser, OS, screen resolution), and WordPress account credential=
s (user IDs, usernames, emails, names) for logged-in users who submit forms= .</td>
<td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15291" target=3D= "_blank" rel=3D"noopener">CVE-2026-15291</a></td>
</tr>
<td class=3D"vendor-product">tigroumeow--Code Engine PHP Snippets, AI Funct= ions & Automation for WordPress</td>
<td>The Code Engine plugin for WordPress is vulnerable to Remote Code Execu= tion in all versions up to, and including, 0.3.5 via the 'code-engine' shor= tcode. This is due to the plugin not restricting access to the code injecti=
ng functionality of the plugin. This makes it possible for authenticated at= tackers, with Contributor-level access and above, to execute code on the se= rver.</td>
<td>2026-07-11</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-6784" target=3D"= _blank" rel=3D"noopener">CVE-2025-6784</a></td>
</tr>
<td class=3D"vendor-product">tombgtn--Simple Coherent Form</td>
<td>The Simple Coherent Form plugin for WordPress is vulnerable to arbitrar=
y file deletion due to insufficient file path validation in the removeUploa= dDir function in all versions up to, and including, 2.4.13. This makes it p= ossible for unauthenticated attackers to delete arbitrary files on the serv= er, which can easily lead to remote code execution when the right file is d= eleted (such as wp-config.php). The scf_get_id_upload endpoint freely issue=
s a valid scf_upload_file_removal nonce to any unauthenticated visitor, and=
the removal endpoint's secondary hash check is forgeable offline because i=
t relies on a hardcoded salt embedded in the plugin source, meaning neither=
control presents a real authorization boundary.</td>
<td>2026-07-08</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14487" target=3D= "_blank" rel=3D"noopener">CVE-2026-14487</a></td>
</tr>
<td class=3D"vendor-product">topoteretes--cognee</td>
<td>Cognee before 1.2.0 contains an improper access control vulnerability t= hat allows unauthenticated attackers to overwrite the global LLM provider c= onfiguration by self-registering an account and calling the settings endpoi= nt, which performs no admin or superuser check. Attackers can redirect all = LLM operations instance-wide to an attacker-controlled endpoint by exploiti=
ng the process-wide singleton configuration cache, enabling exfiltration of=
prompts, uploaded documents, extracted entities, and knowledge graph conte=
nt from all users.</td>
<td>2026-07-07</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58473" target=3D= "_blank" rel=3D"noopener">CVE-2026-58473</a></td>
</tr>
<td class=3D"vendor-product">totalbounty--Widget Logic Visual</td>
<td>The Widget Logic Visual plugin for WordPress is vulnerable to Remote Co=
de Execution in all versions up to, and including, 1.52 via the widget_logi= c_visual_check_visibility function. This is due to missing capability check=
and nonce verification on the widget-logic-update-conditional-tags AJAX ac= tion combined with insufficient sanitization of the 'nwlv[cod-tag]' paramet=
er before storage and subsequent use in an eval() call. This makes it possi= ble for authenticated attackers, with subscriber-level access and above, to=
execute code on the server.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14158" target=3D= "_blank" rel=3D"noopener">CVE-2026-14158</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--A3000RU</td>
<td>A security vulnerability has been detected in TOTOLINK A3000RU, A3100R,=
A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by=
this issue is some unknown functionality of the file /etc/boa/boa.conf of = the component Web Interface. The manipulation leads to least privilege viol= ation. The attack may be initiated remotely. The attack's complexity is rat=
ed as high. The exploitation is known to be difficult.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15271" target=3D= "_blank" rel=3D"noopener">CVE-2026-15271</a></td>
</tr>
<td class=3D"vendor-product">Trendnet--TEW-635BRM</td>
<td>A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. Th=
is affects the function start_httpd of the file /sbin/rc of the component W=
eb Service. Such manipulation of the argument device_name leads to stack-ba= sed buffer overflow. The attack can be executed remotely. The exploit is pu= blicly available and might be used. The vendor explains: "We are unable to = confirm if the vulnerability exists. This item has been EOL since 2011. We = will make an official announcement of possible vulnerabilities, and recomme=
nd users to switch devices." This vulnerability only affects products that = are no longer supported by the maintainer.</td>
<td>2026-07-12</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15480" target=3D= "_blank" rel=3D"noopener">CVE-2026-15480</a></td>
</tr>
<td class=3D"vendor-product">Trendnet--TEW-635BRM</td>
<td>A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.0=
3. This vulnerability affects the function ipoa_test of the file /sbin/rc o=
f the component IPoA WAN Connection Setup. Performing a manipulation of the=
argument ipoa_ipaddr results in command injection. The attack is possible =
to be carried out remotely. The exploit has been released to the public and=
may be used for attacks. The vendor explains: "We are unable to confirm if=
the vulnerability exists. This item has been EOL since 2011. We will make =
an official announcement of possible vulnerabilities, and recommend users t=
o switch devices." This vulnerability only affects products that are no lon= ger supported by the maintainer.</td>
<td>2026-07-12</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15481" target=3D= "_blank" rel=3D"noopener">CVE-2026-15481</a></td>
</tr>
<td class=3D"vendor-product">TRENDnet--TEW-821DAP</td>
<td>A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B= 01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup =
of the component ssi. The manipulation of the argument nslookup_target lead=
s to buffer overflow. It is possible to initiate the attack remotely. The v= endor explains: "We are unable to confirm the existence of the vulnerabilit= ies for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulne= rability only affects products that are no longer supported by the maintain= er.</td>
<td>2026-07-12</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15483" target=3D= "_blank" rel=3D"noopener">CVE-2026-15483</a></td>
</tr>
<td class=3D"vendor-product">TRENDnet--TEW-821DAP</td>
<td>A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affect=
ed element is the function sub_41EC14 of the file /goform/tools_nslookup of=
the component ssi. The manipulation results in buffer overflow. It is poss= ible to launch the attack remotely. The vendor explains: "We are unable to = confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) a=
s these items have been EOL. " This vulnerability only affects products tha=
t are no longer supported by the maintainer.</td>
<td>2026-07-12</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15484" target=3D= "_blank" rel=3D"noopener">CVE-2026-15484</a></td>
</tr>
<td class=3D"vendor-product">u-boot--u-boot</td>
<td>U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in = nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, all= owing a malicious or compromised NFS server to overflow the 2048-byte nfs_p= ath_buff buffer by returning multiple relative symlink targets that are app= ended without cumulative length validation. Attackers can send two or more = READLINK responses containing relative symlink targets of approximately 110=
0 bytes each to corrupt adjacent BSS variables including nfs_server_ip, nfs= _server_mount_port, nfs_server_port, nfs_our_port, nfs_state, and rpc_id, p= otentially achieving memory corruption and control over the NFS client stat=
e machine.</td>
<td>2026-07-08</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-29009" target=3D= "_blank" rel=3D"noopener">CVE-2026-29009</a></td>
</tr>
<td class=3D"vendor-product">u-boot--u-boot</td>
<td>U-Boot through 2026.04-rc3 contains an integer underflow vulnerability =
in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-ad= jacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK = packet with a manipulated data offset field causing payload_len to become n= egative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without inv= oking tcp_seg_in_wnd() validation, the negative payload_len is implicitly c= onverted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcp= y() in store_block(), causing an immediate crash that prevents device boot = and may enable memory corruption when CONFIG_LMB is disabled.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-29008" target=3D= "_blank" rel=3D"noopener">CVE-2026-29008</a></td>
</tr>
<td class=3D"vendor-product">udecode--plate</td>
<td>Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53= .1.4, the media embed renderer trusts serialized provider or sourceUrl meta= data in useMediaState and skips parseMediaUrl protocol validation, allowing=
a crafted Plate document to set a known video provider while keeping url a=
s a javascript: iframe source that the registry MediaEmbedElement renders d= irectly as an iframe src when a victim opens the document. This issue is fi= xed in version 53.1.4.</td>
<td>2026-07-08</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55596" target=3D= "_blank" rel=3D"noopener">CVE-2026-55596</a></td>
</tr>
<td class=3D"vendor-product">ultimatemember--Ultimate Member User Profile, = Registration, Login, Member Directory, Content Restriction & Membership=
Plugin</td>
<td>The Ultimate Member - User Profile, Registration, Login, Member Directo= ry, Content Restriction & Membership Plugin plugin for WordPress is vul= nerable to blind SQL Injection via the search parameter in all versions up = to, and including, 2.10.1 due to insufficient escaping on the user supplied=
parameter and lack of sufficient preparation on the existing SQL query. Th=
is makes it possible for unauthenticated attackers to append additional SQL=
queries into already existing queries that can be used to extract sensitiv=
e information from the database. This vulnerability was partially patched i=
n version 2.9.2 when initially addressing CVE-2025-0308.</td> <td>2026-07-10</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15290" target=3D= "_blank" rel=3D"noopener">CVE-2026-15290</a></td>
</tr>
<td class=3D"vendor-product">unclecode--crawl4ai</td>
<td>Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior =
to 0.9.0, the Docker API server accepted request-supplied browser_config.ex= tra_args, which flowed into Chromium's launch arguments. An attacker could = inject Chromium switches that replace a child-process launch command togeth=
er with --no-zygote, causing Chromium to fork or exec an attacker-controlle=
d command as the container's runtime user. The Docker API is unauthenticate=
d by default, so a single request yields arbitrary command execution. This = issue is fixed in version 0.9.0.</td>
<td>2026-07-06</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57572" target=3D= "_blank" rel=3D"noopener">CVE-2026-57572</a></td>
</tr>
<td class=3D"vendor-product">unclecode--crawl4ai</td>
<td>Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior =
to 0.9.0, when the crawler saves a downloaded file, the destination filenam=
e was taken from attacker-influenced input and joined to the downloads dire= ctory with no confinement. A filename containing an absolute path or traver= sal escaped the downloads directory, giving an arbitrary file write with at= tacker-controlled contents; the HTTP crawler path uses the response Content= -Disposition filename and the browser crawler path uses the download's sugg= ested filename. Because the written bytes are attacker-controlled, this can=
escalate to remote code execution. This issue is fixed in version 0.9.0.</=
<td>2026-07-06</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57571" target=3D= "_blank" rel=3D"noopener">CVE-2026-57571</a></td>
</tr>
<td class=3D"vendor-product">unclecode--crawl4ai</td>
<td>Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior =
to 0.9.0, the Docker API server applied its SSRF destination check on the n= on-streaming /crawl path but not on the streaming path. handle_stream_crawl= _request passed seed URLs straight to the crawler with no destination valid= ation, allowing a remote unauthenticated client to call POST /crawl/stream =
or POST /crawl with crawler_config.stream=3Dtrue with a URL pointing at an = internal, private, or link-local address; the server fetched it and streame=
d the response body back. This issue is fixed in version 0.9.0.</td> <td>2026-07-06</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57573" target=3D= "_blank" rel=3D"noopener">CVE-2026-57573</a></td>
</tr>
<td class=3D"vendor-product">Vikunja--Vikunja</td>
<td>Vikunja before 2.2.1 contains an authorization flaw where the LinkShari= ng.ReadAll endpoint exposes share hashes to users with read access, enablin=
g permission escalation to admin-level shares. The GetTaskAttachment endpoi=
nt performs permission checks against user-supplied task IDs but fetches at= tachments by sequential ID without verifying ownership, allowing attackers =
to download and delete all file attachments across all projects instance-wi= de.</td>
<td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56765" target=3D= "_blank" rel=3D"noopener">CVE-2026-56765</a></td>
</tr>
<td class=3D"vendor-product">vllm-project--vllm</td>
<td>vLLM is a high-throughput and memory-efficient inference and serving en= gine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative = decoding workload can cause the rejection sampler to produce a recovered to= ken equal to the model vocabulary size boundary value, which is then conver= ted to negative one when the engine selects the next live token for a reque=
st and is written back into the drafter's input ids; that out-of-vocabulary=
value is later consumed by the model's embedding and attention path and cr= ashes the engine worker with a GPU device-side assertion. The same triggeri=
ng request sequence is reachable through the public gRPC Generate and Abort=
endpoints, so a remote client that can send generation requests can crash = the shared engine worker, aborting concurrent requests and causing a servic= e-wide denial of service for other clients of the deployment until the work=
er is restarted. This issue is fixed in version 0.24.0.</td> <td>2026-07-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54234" target=3D= "_blank" rel=3D"noopener">CVE-2026-54234</a></td>
</tr>
<td class=3D"vendor-product">Vtiger--Vtiger CRM</td>
<td>Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerabi= lity that allows low-privileged users to achieve remote code execution by u= ploading a .phar file containing arbitrary PHP code through the Documents m= odule, bypassing the extension denylist in config.inc.php which omits the .= phar extension. The uploaded file is stored with its original .phar extensi=
on under the web-accessible storage directory, and a misconfigured .htacces=
s using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, al= lowing unauthenticated HTTP requests to directly execute the uploaded PHP p= ayload.</td>
<td>2026-07-07</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23697" target=3D= "_blank" rel=3D"noopener">CVE-2026-23697</a></td>
</tr>
<td class=3D"vendor-product">Vtiger--Vtiger CRM</td>
<td>Vtiger CRM through 8.4.0 contains an authenticated remote code executio=
n vulnerability in the admin module import feature that allows administrato= r-level attackers to upload arbitrary PHP files by submitting a crafted zip=
archive through the ModuleManager import function, which extracts contents=
directly into the modules/ directory under the web root without validating=
file types beyond the manifest.xml descriptor. Attackers can place executa= ble PHP files in the modules/ directory that become directly accessible via=
HTTP, bypassing Vtiger's authentication and authorization layer entirely s= ince Apache resolves the path and invokes the PHP interpreter before the ap= plication routing layer is involved, resulting in a persistent web shell in= dependent of the originating session.</td>
<td>2026-07-07</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23698" target=3D= "_blank" rel=3D"noopener">CVE-2026-23698</a></td>
</tr>
<td class=3D"vendor-product">wclovers--WCFM Membership WooCommerce Membersh= ips for Multivendor Marketplace</td>
<td>The WCFM Membership - WooCommerce Memberships for Multivendor Marketpla=
ce plugin for WordPress is vulnerable to Insecure Direct Object Reference i=
n all versions up to, and including, 2.11.10. This is due to the 'wcfmvm_me= mbership_change' AJAX action not validating user permission to modify other=
users. This makes it possible for authenticated attackers, with vendor lev=
el access and above, to change any user's role to 'wcfm_vendor' by changing=
their membership plan.</td>
<td>2026-07-08</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3688" target=3D"= _blank" rel=3D"noopener">CVE-2026-3688</a></td>
</tr>
<td class=3D"vendor-product">Webbeyaz Web Design--Medikm Web</td>
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in Webbeyaz Web Design Medik=C3=83=C2=BCm Web a= llows SQL Injection. This issue affects Medik=C3=83=C2=BCm Web: through 080= 72026.=C2=A0NOTE: The vendor was contacted and it was learned that the prod= uct is not supported.</td>
<td>2026-07-08</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8307" target=3D"= _blank" rel=3D"noopener">CVE-2026-8307</a></td>
</tr>
<td class=3D"vendor-product">WebPros--Plesk</td>
<td>An improper authorization vulnerability in the Plesk XML API allows an = authenticated user to inject arbitrary configuration directives, resulting =
in arbitrary file write as root and full privilege escalation on the underl= ying server.</td>
<td>2026-07-06</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48614" target=3D= "_blank" rel=3D"noopener">CVE-2026-48614</a></td>
</tr>
<td class=3D"vendor-product">Webpros--Plesk</td>
<td>Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0= .78.4 allows a low-privileged authenticated customer to look up domains the=
y do not own, because ownership is enforced only for certain lookup filters=
and schema validation is bypassed for legacy protocol versions. This resul=
ts in cross-tenant disclosure of other tenants' FTP credentials stored in c= leartext, which can be leveraged to execute code as another tenant's system=
user.</td>
<td>2026-07-08</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56843" target=3D= "_blank" rel=3D"noopener">CVE-2026-56843</a></td>
</tr>
<td class=3D"vendor-product">WebRehab--Super Forms Drag & Drop Form Bui= lder</td>
<td>The Super Forms - Drag & Drop Form Builder plugin for WordPress is = vulnerable to Arbitrary File Upload in all versions up to, and including, 6= .3.313 via the submit_form function. This is due to missing file type valid= ation and the absence of any capability check on the submit_form nopriv AJA=
X handler, whose only barrier is a session nonce freely obtainable by unaut= henticated visitors via a separate nopriv endpoint. This makes it possible = for unauthenticated attackers to upload files that may be executable, which=
makes remote code execution possible. The nonce requirement is trivially b= ypassed because the super_create_nonce nopriv AJAX action allows any unauth= enticated visitor to mint a valid sf_nonce and session cookie in a single p= rior request, reducing exploitation to two unauthenticated HTTP requests.</=
<td>2026-07-10</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14894" target=3D= "_blank" rel=3D"noopener">CVE-2026-14894</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 =
to 4.4.16 allows denial of service</td>
<td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15167" target=3D= "_blank" rel=3D"noopener">CVE-2026-15167</a></td>
</tr>
<td class=3D"vendor-product">withastro--astro</td>
<td>Astro is a web framework for content-driven websites. Version 6.4.7 per= forms authorization decisions on a partially decoded pathname after reachin=
g the iterative URL decoder limit, while later rewrite route matching perfo= rms an additional decodeURI() operation and can resolve the request to a pr= otected route. This issue is fixed in version 6.4.8.</td>
<td>2026-07-08</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59731" target=3D= "_blank" rel=3D"noopener">CVE-2026-59731</a></td>
</tr>
<td class=3D"vendor-product">wordpresschef--Salon Booking System Free Versi= on</td>
<td>The Salon Booking System - Free Version plugin for WordPress is vulnera= ble to Cross-Site Request Forgery in all versions up to, and including, 10.= 30.32. This is due to missing or incorrect nonce validation on the setCusto= mText function. This makes it possible for unauthenticated attackers to inj= ect arbitrary PHP code into the web-accessible translate-constants.php file=
within the plugin directory, enabling remote code execution on the server = via a forged request granted they can trick a site administrator into perfo= rming an action such as clicking on a link. sanitize_text_field() is applie=
d to the POST 'value' parameter but does not neutralize the characters - si= ngle quotes, parentheses, semicolons, $, and [] - required to break out of = the PHP string literal into which the value is interpolated before being wr= itten to disk via file_put_contents().</td>
<td>2026-07-10</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15070" target=3D= "_blank" rel=3D"noopener">CVE-2026-15070</a></td>
</tr>
<td class=3D"vendor-product">WP Grid Builder--WP Grid Builder</td>
<td>The WP Grid Builder plugin for WordPress is vulnerable to Privilege Esc= alation in all versions up to, and including, 2.3.3. This is due to missing=
authorization and meta key validation in the `update()` handler for the `/= wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authent= icated attackers, with Subscriber-level access and above, to elevate their = privileges to Administrator by updating their own `wp_capabilities` user me=
ta with a crafted nested array payload.</td>
<td>2026-07-11</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13756" target=3D= "_blank" rel=3D"noopener">CVE-2026-13756</a></td>
</tr>
<td class=3D"vendor-product">wpazleen--Post Export Import with Media</td> <td>The Post Export Import with Media plugin for WordPress is vulnerable to=
Arbitrary File Upload in all versions up to, and including, 1.13.1 via the=
import_media_file_secure function. This is due to insufficient file extens= ion validation caused by a trailing-dot filename bypass, where the extensio=
n allow-list check in ajax_import_media_start() uses pathinfo() on the raw = ZIP entry name (e.g., 'shell.php.'), which returns an empty string for the = extension, causing the allow-list guard to be skipped and the file to be ex= tracted to a temporary location, after which import_media_file_secure() cop= ies it into the WordPress uploads directory without re-validating the exten= sion. This makes it possible for authenticated attackers, with administrato= r-level access and above, to upload files that may be executable, which mak=
es remote code execution possible.</td>
<td>2026-07-10</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13430" target=3D= "_blank" rel=3D"noopener">CVE-2026-13430</a></td>
</tr>
<td class=3D"vendor-product">wpdevteam--Essential Addons for Elementor Popu= lar Elementor Templates & Widgets</td>
<td>The Essential Addons for Elementor - Popular Elementor Templates & = Widgets plugin for WordPress is vulnerable to Authenticated Account Takeove=
r via Email Header Injection in all versions up to, and including, 6.6.10 T= his is due to insufficient server-side validation of a Login/Register widge=
t setting used to construct outgoing email headers - the allowed-values res= triction is enforced only in the client-side editor UI and not on the serve=
r, and the applied sanitization does not strip or encode CR/LF characters, = allowing CRLF sequences stored in that setting to survive into raw mail hea= ders. This makes it possible for authenticated attackers, with Contributor-= level access and above, to inject an additional Bcc header into the WordPre=
ss administrator's password-reset notification email, receive a copy of a v= alid administrator password-reset link, and achieve full administrator acco= unt takeover.</td>
<td>2026-07-11</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15155" target=3D= "_blank" rel=3D"noopener">CVE-2026-15155</a></td>
</tr>
<td class=3D"vendor-product">wpdo5ea--DoLogin Security</td>
<td>The DoLogin Security plugin for WordPress is vulnerable to Authenticati=
on Bypass via Insufficient Randomness in all versions up to, and including,=
4.3. The vulnerability exists because `dologin\s::rrand()` seeds the Merse= nne Twister with `mt_srand((double) microtime() * 1000000)` - discarding th=
e integer-seconds component of `microtime()` and constraining the seed to a=
range of approximately 10^6 values (~20 bits of entropy) - after which eve=
ry character of the 32-character magic-link token is drawn sequentially wit=
h `mt_rand()`, making the entire token a deterministic function of that see=
d. Because `Pswdless::try_login()` is registered on the unauthenticated `in= it` hook, resolves the target account by the auto-increment numeric ID embe= dded in the `?dologin=3D<id>.<hash>` parameter, performs the ha=
sh comparison using a non-constant-time `!=3D` operator, and then calls `wp= _set_auth_cookie()` directly - never passing through `wp_authenticate()` an=
d therefore never triggering the plugin's own `Auth::_has_login_err()` lock= out - an unauthenticated attacker can brute-force the ~10^6-candidate seed = space to reconstruct an active passwordless login token and authenticate as=
any targeted user, including administrators, without a password. Exploitat= ion requires that a valid, unexpired passwordless login link (active for up=
to 7 days) exists for the target account at the time of the attack, and th=
at the numeric link ID is known or guessable from the auto-increment primar=
y key.</td>
<td>2026-07-08</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14495" target=3D= "_blank" rel=3D"noopener">CVE-2026-14495</a></td>
</tr>
<td class=3D"vendor-product">wpmessiah--Swiss Toolkit For WP</td>
<td>The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrar=
y file upload due to a flawed file type validation bypass in the `upload_ex= tension_files()` function in all versions up to, and including, 1.4.6. The = `upload_extension_files()` function hooks into WordPress's `wp_check_filety= pe_and_ext` filter and uses `strpos()` to check if a filename contains a co= nfigured extension string, rather than verifying the actual file extension.=
This makes it possible for authenticated attackers, with Author-level acce=
ss and above, to upload arbitrary files (including PHP) on the affected sit= e's server which may make remote code execution possible, granted the "Enha= nced Multi-Format Image Support" feature is enabled with at least one exten= sion (e.g., avif) in the allowed formats.</td>
<td>2026-07-11</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2354" target=3D"= _blank" rel=3D"noopener">CVE-2026-2354</a></td>
</tr>
<td class=3D"vendor-product">wpvibes--Form Vibes Save Contact Form 7 & = Elementor Form Entries to Database</td>
<td>The Form Vibes - Database Manager for Forms plugin for WordPress is vul= nerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all=
versions up to, and including, 1.5.2 due to insufficient input sanitizatio=
n and output escaping. This makes it possible for unauthenticated attackers=
to inject arbitrary web scripts in pages that will execute whenever a user=
accesses an injected page.</td>
<td>2026-07-11</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13378" target=3D= "_blank" rel=3D"noopener">CVE-2026-13378</a></td>
</tr>
<td class=3D"vendor-product">WSO2--WSO2 Universal Gateway</td>
<td>The throttling event handling mechanism in multiple WSO2 products accep=
ts user-supplied JSON payloads without sufficient validation of their struc= ture and content. This allows an unauthenticated remote attacker to inject = malicious JSON data that can lead to a persistent denial of service conditi= on. Successful exploitation of this vulnerability can disrupt the API Gatew= ay, preventing legitimate API traffic from being processed and impacting co= mplete service availability. The denial of service is persistent, requiring=
manual intervention to restore normal operations.</td>
<td>2026-07-06</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4249" target=3D"= _blank" rel=3D"noopener">CVE-2026-4249</a></td>
</tr>
<td class=3D"vendor-product">X.Org--libXfont2</td>
<td>A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 = due to an overflowing 32bit size could be used by attackers able to access = the X Server to execute code within the X server cont</td>
<td>2026-07-08</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56001" target=3D= "_blank" rel=3D"noopener">CVE-2026-56001</a></td>
</tr>
<td class=3D"vendor-product">X.Org--libXfont2</td>
<td>A heap bufferflow in pcfReadFont() due to missing glyph bounds checking= =C2=A0in libXfont2 before 2.0.8=C2=A0 allows attackers authenticated as X c= lient to execute code within the X server.</td>
<td>2026-07-08</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56002" target=3D= "_blank" rel=3D"noopener">CVE-2026-56002</a></td>
</tr>
<td class=3D"vendor-product">X.Org--libXfont2</td>
<td>A heap buffer overflow due to missing size checking in the property buf= fer when parsing PCF files in libXfont2 ComputeScaledProperties() before li= bXfont2 before 2.0.8 could be used by attackers using authenticated X clien=
ts to execute code within the X server.</td>
<td>2026-07-08</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56003" target=3D= "_blank" rel=3D"noopener">CVE-2026-56003</a></td>
</tr>
<td class=3D"vendor-product">X.Org--xorg-server</td>
<td>Local attackers with a X connection able to provide PCX fonts to the X = server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a=
heap buffer overflow via SetFont due to missing glyph boundary checks.</td=
<td>2026-07-08</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55999" target=3D= "_blank" rel=3D"noopener">CVE-2026-55999</a></td>
</tr>
<td class=3D"vendor-product">xtreeme--Planyo online reservation system</td> <td>The Planyo Online Reservation System plugin for WordPress is vulnerable=
to Server-Side Request Forgery leading to Local File Inclusion in all vers= ions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and=
is directly accessible without WordPress bootstrapping or any authenticati= on. The send_http_post() function validates the host of the provided URL ag= ainst an allowlist that includes 'localhost', but critically fails to valid= ate the URL scheme/protocol. This makes it possible for unauthenticated att= ackers to supply a file:// URL (e.g., file://localhost/etc/passwd) which by= passes the host allowlist check because parse_url() returns 'localhost' as = the host. The URL is then passed to curl_init() or fopen(), both of which s= upport the file:// protocol, allowing the attacker to read arbitrary local = files on the server and have their contents returned in the HTTP response. = This can lead to disclosure of sensitive files such as /etc/passwd, wp-conf= ig.php (containing database credentials and authentication keys), and other=
server-side files.</td>
<td>2026-07-11</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3576" target=3D"= _blank" rel=3D"noopener">CVE-2026-3576</a></td>
</tr>
<td class=3D"vendor-product">yhirose--cpp-httplib</td>
<td>cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTP=
S library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1=
and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib =
is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and =
a client connects to an IP-literal host with server certificate verificatio=
n enabled, SSLClient and Client in HTTPS mode skip certificate chain valida= tion and WebSocketClient on the Mbed TLS backend skips verification altoget= her, allowing a man-in-the-middle attacker positioned to intercept traffic =
to present a crafted certificate and read or modify the traffic. This issue=
is fixed in version 0.47.0.</td>
<td>2026-07-10</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54919" target=3D= "_blank" rel=3D"noopener">CVE-2026-54919</a></td>
</tr>
<td class=3D"vendor-product">yt-dlp--yt-dlp</td>
<td>yt-dlp and youtube-dl are command-line audio/video downloaders. Prior t=
o 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link op= tions can write .url or .desktop shortcut files using attacker-controlled w= ebpage_url or filename metadata without sufficient validation or escaping, = allowing malicious file:// URI injection on Windows or newline-based deskto=
p entry key injection on Linux that can execute commands if the generated s= hortcut is opened. This issue is fixed in version 2026.7.4.</td> <td>2026-07-08</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55404" target=3D= "_blank" rel=3D"noopener">CVE-2026-55404</a></td>
</tr>
<td class=3D"vendor-product">zeek--zeek</td>
<td>Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerabi= lity in the FTP analyzer that allows unauthenticated remote attackers to ca= use process termination by sending a crafted FTP control session negotiatin=
g AUTH GSSAPI followed by a large ADAT control line. Attackers can exploit = the NVT_Analyzer component's lack of a maximum line length check, causing i=
t to continuously double its internal buffer without bounds during base64 d= ecoding of an attacker-controlled ADAT token, resulting in denial of servic=
e of the Zeek sensor.</td>
<td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60108" target=3D= "_blank" rel=3D"noopener">CVE-2026-60108</a></td>
</tr>
<td class=3D"vendor-product">zeek--zeek</td>
<td>Zeek before 8.0.9 contains a null pointer dereference vulnerability in = its Kerberos protocol analyzer that allows unauthenticated remote attackers=
to crash the sensor by sending a crafted KRB_ERROR message with error-code=
25 (KDC_ERR_PREAUTH_REQUIRED) containing a PA-DATA element with padata-typ=
e 2, 3, 11, or 19. Attackers can exploit a parser and analyzer state mismat=
ch where proc_padata() dereferences an uninitialized pa_data_element field = selected by the wrong parsing arm, triggering a crash via a single UDP or T=
CP packet to port 88 without any credentials or prior authentication.</td> <td>2026-07-09</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60109" target=3D= "_blank" rel=3D"noopener">CVE-2026-60109</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() f=
or strings of the form "a.b.c.d:port") copies the port substring into a fix=
ed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length=
of str_len - end - 1, where str_len is the full, unbounded input length an=
d end is only the (<=3D15-byte) offset of the ':' delimiter. Because the=
destination size is never consulted, a crafted address string with a long = suffix after the colon (e.g. "1.2.3.4:" followed by hundreds of bytes) caus=
es an out-of-bounds stack write whose length and contents are fully attacke= r-controlled (memcpy of the suffix plus a trailing NUL), enabling memory co= rruption and at minimum a denial of service, and potentially control-flow h= ijack. The parser is reached from the standard socket API (zsock_getaddrinf=
o / literal-address resolution), DNS server-string configuration, and the e= swifi Wi-Fi co-processor DNS-response path, so an application that resolves=
a network-influenced address string is exposed. The bug was introduced whe=
n the parser was added (Zephyr v1.9.0) and shipped in all releases through = v4.4.0. The fix removes the unbounded copy and validates the port length be= fore copying into a small dedicated buffer. Note: the equivalent IPv6 "[add= r]:port" path in parse_ipv6() retains the same unbounded copy at this commi=
t and remains a separate, still-reachable instance of the defect.</td> <td>2026-07-12</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10666" target=3D= "_blank" rel=3D"noopener">CVE-2026-10666</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_= data_message() in wg_crypto.c linearizes an inbound transport-data payload = into a fixed pool buffer of CONFIG_WIREGUARD_BUF_LEN bytes before decryptio=
n. The call net_buf_linearize(buf->data, data_len, pkt->buffer, ..., = data_len) passed the attacker-derived data_len as both the destination capa= city and the copy length, defeating the function's internal len =3D min(len=
, dst_len) bound. data_len is derived from the received UDP datagram length=
and is only lower-bounded by wg_ctrl_recv() (no upper bound). When data_le=
n exceeds CONFIG_WIREGUARD_BUF_LEN - e.g. when the buffer length is lowered=
below the link MTU, on links with MTU above the buffer size, or via reasse= mbled IPv4/IPv6 fragments that exceed it - the underlying memcpy writes pas=
t the end of the pool buffer, an out-of-bounds write (CWE-787). The overflo=
w occurs before the Poly1305 authentication check, so it requires only a va= lid receiver session index rather than a valid authenticator, and is reacha= ble by a malicious or compromised peer (or an on-path attacker driving an e= stablished session) over the network, yielding remote memory corruption and=
at minimum a reliable denial of service. The defect was present in the Wir= eGuard implementation shipped in Zephyr 4.4.0. The fix adds an explicit dat= a_len > CONFIG_WIREGUARD_BUF_LEN rejection and corrects the linearize ca=
ll to pass net_buf_max_len(buf) as the destination capacity.</td> <td>2026-07-12</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10665" target=3D= "_blank" rel=3D"noopener">CVE-2026-10665</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, = formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of d= ynamically allocated kernel objects. Iteration over this list in k_object_w= ordlist_foreach() was performed under lists_lock using the SAFE iterator (w= hich caches the next node), but list removal and freeing of nodes was perfo= rmed under different, disjoint spinlocks: objfree_lock in k_object_free() a=
nd obj_lock in unref_check(). On an SMP system, while one CPU iterated obj_= list under lists_lock, another CPU could unlink and k_free() the dyn_obj no=
de that the iterator had cached as its next pointer, causing the iterator t=
o dereference freed kernel memory (use-after-free / dangling list traversal=
). All of the racing operations are reachable from unprivileged user-mode t= hreads via system calls: k_object_alloc/k_object_alloc_size and k_object_re= lease drive removals through unref_check() (under obj_lock), while k_thread= _abort and thread creation drive the iteration through k_thread_perms_all_c= lear()/k_thread_perms_inherit() (under lists_lock). A deprivileged user thr= ead on a CONFIG_SMP + CONFIG_USERSPACE build can therefore corrupt the kern= el's object-tracking structures across the userspace security boundary, yie= lding kernel memory corruption (potential privilege escalation) or a kernel=
crash (denial of service). The fix removes objfree_lock and serializes eve=
ry obj_list modification under lists_lock, including holding it across find= +remove in k_object_free() and around unref_check() in k_thread_perms_clear= (). Affects CONFIG_SMP+CONFIG_USERSPACE+CONFIG_DYNAMIC_OBJECTS configuratio= ns; the defect dates to the 2019 spinlockification (commit 8a3d57b6cc6, fir=
st released in v1.14.0) and shipped through v4.4.0.</td>
<td>2026-07-12</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10667" target=3D= "_blank" rel=3D"noopener">CVE-2026-10667</a></td>
</tr>
<td class=3D"vendor-product">zhayujie--CowAgent</td>
<td>A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impact=
ed is the function _build_image_content/_download_to_data_url of the file a= gent/tools/vision/vision.py of the component Vision Tool. Executing a manip= ulation of the argument image can lead to server-side request forgery. The = attack can be launched remotely. The exploit has been publicly disclosed an=
d may be utilized. Upgrading to version 2.1.2 is recommended to address thi=
s issue. This patch is called e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. Upg= rading the affected component is advised.</td>
<td>2026-07-10</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15330" target=3D= "_blank" rel=3D"noopener">CVE-2026-15330</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 4.15.3=
, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-= type:token-exchange does not verify that the subject token belongs to the r= equesting client or that requested scopes remain within the original token'=
s scopes, allowing a low-privilege token to be exchanged for elevated permi= ssions at another application. This issue is fixed in version 4.15.3.</td> <td>2026-07-10</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56668" target=3D= "_blank" rel=3D"noopener">CVE-2026-56668</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 3.4.12=
and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and devi=
ce token flows fail to verify that the requesting client matches the client=
that initiated the authorization flow, allowing intercepted grants or refr= esh tokens to be exchanged under a different client. This issue is fixed in=
versions 3.4.12 and 4.15.2.</td>
<td>2026-07-10</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55672" target=3D= "_blank" rel=3D"noopener">CVE-2026-55672</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 4.15.3=
, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return logi= nSettings.defaultRedirectUri to router.push without applying the isSafeRedi= rectUri check, allowing an organization or instance administrator to store =
a javascript or data URI that can execute in a user's browser when an affec= ted login error path is reached. This issue is fixed in version 4.15.3.</td=
<td>2026-07-10</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56667" target=3D= "_blank" rel=3D"noopener">CVE-2026-56667</a></td>
</tr>
<td class=3D"vendor-product">zopefoundation--RestrictedPython</td> <td>RestrictedPython is a tool that helps to define a subset of the Python = language which allows to provide a program input into a trusted environment=
. Prior to 8.3, check_function_argument_names() rejected protected guard ho=
ok names for regular, variadic, and keyword-only arguments but omitted posi= tional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_=
to be shadowed by a local parameter and bypass the embedding application's=
access policy. This issue is fixed in version 8.3.</td>
<td>2026-07-08</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55830" target=3D= "_blank" rel=3D"noopener">CVE-2026-55830</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"medium_v">
<h2 id=3D"medium_v_title">Medium Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Medium Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">2coders--Mux Video Uploader</td>
<td>The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive = Information Exposure in all versions up to, and including, 1.1.4 via the mu= xvideo_enqueue_settings_script. This makes it possible for authenticated at= tackers, with subscriber-level access and above, to extract sensitive data = including Mux API credentials.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7544" target=3D"= _blank" rel=3D"noopener">CVE-2026-7544</a></td>
</tr>
<td class=3D"vendor-product">actualbudget--actual</td>
<td>Actual is a local-first personal finance app. Prior to 26.6.0, @actual-= app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts us=
ed whenever the global --format csv option is passed, whose escapeCsv helpe=
r only handles RFC 4180 delimiter, quote, and newline escaping and does not=
neutralize standard CSV formula-injection prefixes. Any CLI command that s= treams an object array containing user-controlled strings, including transa= ctions list, accounts list, payees list, categories list, tags list, catego= ry-groups list, rules list, schedules list, and query, can emit cells that = auto-evaluate when the resulting CSV is opened in Excel, LibreOffice Calc, =
or Google Sheets, enabling data exfiltration and arbitrary formula executio=
n. This issue is fixed in version 26.6.0.</td>
<td>2026-07-07</td>
<td>4.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46672" target=3D= "_blank" rel=3D"noopener">CVE-2026-46672</a></td>
</tr>
<td class=3D"vendor-product">actualbudget--actual</td>
<td>Actual is a local-first personal finance tool. Prior to 26.6.0, the GET=
/secret/:name endpoint in @actual-app/sync-server checks only that the cal= ler has a valid session and does not verify the caller is an admin, while t=
he sibling POST /secret/ handler enforces an admin check in OpenID mode. An=
y authenticated non-admin BASIC user in OpenID multi-user deployments can p= robe the secrets store and learn which admin-managed bank-sync integrations=
have been configured, including simplefin_accessKey, pluggyai_clientSecret=
, pluggyai_itemIds, and the gocardless secrets. This issue is fixed in vers= ion 26.6.0.</td>
<td>2026-07-07</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46700" target=3D= "_blank" rel=3D"noopener">CVE-2026-46700</a></td>
</tr>
<td class=3D"vendor-product">actualbudget--actual</td>
<td>Actual is a local-first personal finance tool. Prior to 26.6.0, exportT= oCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/exp= ort/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Catego=
ry strings to csv-stringify with no cast callback and no formula-prefix neu= tralization. Strings that begin with equals sign, plus, minus, at sign, tab=
, or carriage return survive verbatim into the exported CSV, and when a rec= ipient opens the file in Excel, LibreOffice Calc, or Google Sheets, the str= ings are interpreted as formulas, enabling transaction data exfiltration an=
d attacker-chosen spreadsheet display values. This issue is fixed in versio=
n 26.6.0.</td>
<td>2026-07-07</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50179" target=3D= "_blank" rel=3D"noopener">CVE-2026-50179</a></td>
</tr>
<td class=3D"vendor-product">acyba--AcyMailing An Ultimate Newsletter Plugi=
n and Marketing Automation Solution for WordPress</td>
<td>The AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation=
Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-= Site Scripting via the 'alignment' attribute in all versions up to, and inc= luding, 10.10.2 due to insufficient input sanitization and output escaping.=
This makes it possible for authenticated attackers, with contributor-level=
access and above, to inject arbitrary web scripts in pages that will execu=
te whenever a user accesses an injected page.</td>
<td>2026-07-09</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12170" target=3D= "_blank" rel=3D"noopener">CVE-2026-12170</a></td>
</tr>
<td class=3D"vendor-product">Adobe--DNG SDK</td>
<td>DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer = Dereference vulnerability that could result in an application denial-of-ser= vice. An attacker could exploit this vulnerability to crash the application=
, leading to a denial-of-service condition. Exploitation of this issue requ= ires user interaction in that a victim must open a malicious file.</td> <td>2026-07-06</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48267" target=3D= "_blank" rel=3D"noopener">CVE-2026-48267</a></td>
</tr>
<td class=3D"vendor-product">aerostackdev--aerostack-mcp</td>
<td>A security vulnerability has been detected in aerostackdev aerostack-mc=
p up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is=
the function upload_media of the component mcp-whatsapp. Such manipulation=
of the argument media_url leads to server-side request forgery. The attack=
may be launched remotely. This product operates on a rolling release basis=
, ensuring continuous delivery. Consequently, there are no version details = for either affected or updated releases. The project was informed of the pr= oblem early through an issue report but has not responded yet.</td> <td>2026-07-09</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15189" target=3D= "_blank" rel=3D"noopener">CVE-2026-15189</a></td>
</tr>
<td class=3D"vendor-product">affine--monorepo</td>
<td>AFFiNE's histories GraphQL field fails to validate Doc.Read permission = before exposing document edit history, allowing authenticated workspace mem= bers to retrieve restricted content timelines. Attackers can supply arbitra=
ry document GUIDs to access full edit histories including user names, email=
s, and timestamps of private pages they lack access to.</td> <td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59262" target=3D= "_blank" rel=3D"noopener">CVE-2026-59262</a></td>
</tr>
<td class=3D"vendor-product">ahmadmj--Majestic Support The Leading-Edge Hel=
p Desk & Customer Support Plugin</td>
<td>The Majestic Support - The Leading-Edge Help Desk & Customer Suppor=
t Plugin plugin for WordPress is vulnerable to generic SQL Injection via th=
e 'val' parameter in all versions up to, and including, 1.1.9 due to insuff= icient escaping on the user supplied parameter and lack of sufficient prepa= ration on the existing SQL query. This makes it possible for unauthenticate=
d attackers to append additional SQL queries into already existing queries = that can be used to extract sensitive information from the database. Exploi= tation requires a valid 'get-smart-reply' nonce, which any Subscriber-level=
user can obtain by creating a ticket via the public frontend and visiting = the resulting ticket detail page, making this effectively exploitable by an=
y authenticated user.</td>
<td>2026-07-11</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13262" target=3D= "_blank" rel=3D"noopener">CVE-2026-13262</a></td>
</tr>
<td class=3D"vendor-product">AidanPark--openclaw-android</td>
<td>A vulnerability was determined in AidanPark openclaw-android up to 0.4.=
0. The affected element is an unknown function of the file android/app/src/= main/java/com/openclaw/android/JsBridge.kt of the component Android WebView=
Bridge. This manipulation causes os command injection. The attack can only=
be executed locally. The exploit has been publicly disclosed and may be ut= ilized. The pull request to fix this issue awaits acceptance.</td> <td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15193" target=3D= "_blank" rel=3D"noopener">CVE-2026-15193</a></td>
</tr>
<td class=3D"vendor-product">AMTT--Hotel Broadband Operation System</td>
<td>A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Imp= acted is an unknown function of the file manager/network/switch_status.php.=
Executing a manipulation of the argument ID can lead to sql injection. It =
is possible to launch the attack remotely. The exploit has been published a=
nd may be used. The vendor was contacted early about this disclosure but di=
d not respond in any way.</td>
<td>2026-07-12</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15494" target=3D= "_blank" rel=3D"noopener">CVE-2026-15494</a></td>
</tr>
<td class=3D"vendor-product">ankitects--anki</td>
<td>Anki is a program for creating and reviewing flashcards. Prior to 25.09= .4, Anki's webview-based pages communicate with the Rust backend using an i= nternal localhost API, and user scripts included via iframes in the editor = can access this API despite protections intended to block reviewer and edit=
or scripts. A malicious imported card package with an embedded iframe can u=
se exposed API methods such as getImageForOcclusion to read arbitrary files=
accessible to the Anki process and exfiltrate them over the network. This = issue is fixed in version 25.09.4.</td>
<td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58266" target=3D= "_blank" rel=3D"noopener">CVE-2026-58266</a></td>
</tr>
<td class=3D"vendor-product">antiwork--gumroad</td>
<td>Gumroad before 2026.07.06.2 contains a broken access control vulnerabil= ity in the PurchasesController that allows authenticated sellers to manipul= ate purchase access for other sellers' products by sending PUT requests to = the revoke_access and undo_revoke_access actions without seller ownership v= alidation. Attackers can modify the is_access_revoked status on arbitrary p= urchases to unauthorized revoke or restore buyer access to products they do=
not own.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59805" target=3D= "_blank" rel=3D"noopener">CVE-2026-59805</a></td>
</tr>
<td class=3D"vendor-product">AojiaoZero--Antaris</td>
<td>A vulnerability was detected in AojiaoZero Antaris 1.0. This affects th=
e function _rewardPurchase of the file /ipn.php of the component PayPal IPN=
Payment Handler. The manipulation of the argument item_number results in s=
ql injection. The attack may be performed from remote. The vendor was conta= cted early about this disclosure but did not respond in any way.</td> <td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15502" target=3D= "_blank" rel=3D"noopener">CVE-2026-15502</a></td>
</tr>
<td class=3D"vendor-product">apidevtools--json-schema-ref-parser</td>
<td>A weakness has been identified in apidevtools json-schema-ref-parser up=
to 15.3.5. This impacts the function Refs.set/Pointer.set in the library l= ib/pointer.ts. Executing a manipulation can lead to improperly controlled m= odification of object prototype attributes. The attack can be launched remo= tely. Upgrading to version 15.3.6 will fix this issue. This patch is called=
a786bc6afc3674f650496472ee93d5cf74c4bd84. It is suggested to upgrade the a= ffected component.</td>
<td>2026-07-09</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15195" target=3D= "_blank" rel=3D"noopener">CVE-2026-15195</a></td>
</tr>
<td class=3D"vendor-product">appium--appium</td>
<td>Appium is a cross-platform automation framework for all kinds of apps, = built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-= driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scroll= able, and /test/guinea-pig-app-banner routes, and compileLodashTemplate ref= lects the throwError query parameter, comments POST field, and User-Agent r= equest header into HTML without escaping, allowing reflected cross-site scr= ipting and arbitrary JavaScript execution on the server origin. This issue =
is fixed in version 10.7.0.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58191" target=3D= "_blank" rel=3D"noopener">CVE-2026-58191</a></td>
</tr>
<td class=3D"vendor-product">arikusi--deepseek-mcp-server</td>
<td>DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in versi=
on 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@ar= ikusi/deepseek-mcp-server` exposes `POST /mcp` without any authentication: = `createMcpExpressApp` is called without an `authProvider` and no middleware=
guards the route, so any network-reachable client can issue an unauthentic= ated `initialize` request and obtain a valid MCP session identifier. In rep= roduced testing against commit `5e1302171e99`, an unauthenticated client wa=
s able to initialize a session, enumerate tools, and invoke the local `deep= seek_sessions` tool with no credentials. The same unauthenticated session a= lso exposes `deepseek_chat`, whose handler uses the server-side `DEEPSEEK_A= PI_KEY` when self-hosted deployments configure one. This issue applies to s= elf-hosted HTTP mode, not the separately documented hosted BYOK endpoint in=
`README.md`, which expects an `Authorization: Bearer ...` header. Upstream=
self-hosted container assets enable HTTP mode by default (`Dockerfile`) an=
d publish port `3000` (`docker-compose.yml`). Version 1.8.0 contains a patc=
h for this issue.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55605" target=3D= "_blank" rel=3D"noopener">CVE-2026-55605</a></td>
</tr>
<td class=3D"vendor-product">Armiya Information Technologies Ltd. Co.--Acce=
ss Control System (GKS)</td>
<td>Improper neutralization of Script-Related HTML tags in a web page (basi=
c XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Con= trol System (GKS) allows XSS Targeting HTML Attributes. This issue affects = Access Control System (GKS): before Version 2.</td>
<td>2026-07-07</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7380" target=3D"= _blank" rel=3D"noopener">CVE-2026-7380</a></td>
</tr>
<td class=3D"vendor-product">Armiya Information Technologies Ltd. Co.--Acce=
ss Control System (GKS)</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Armiya Information Technologies Ltd. Co. Acc= ess Control System (GKS) allows Stored XSS. This issue affects Access Contr=
ol System (GKS): before Version 2.</td>
<td>2026-07-07</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8306" target=3D"= _blank" rel=3D"noopener">CVE-2026-8306</a></td>
</tr>
<td class=3D"vendor-product">Armiya Information Technologies Ltd. Co.--Acce=
ss Control System (GKS)</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Armiya Information Technologies Ltd. Co. Acc= ess Control System (GKS) allows Reflected XSS. This issue affects Access Co= ntrol System (GKS): before Version 2.</td>
<td>2026-07-07</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8309" target=3D"= _blank" rel=3D"noopener">CVE-2026-8309</a></td>
</tr>
<td class=3D"vendor-product">arraytics--Eventin Event Calendar, Event Regis= tration, Tickets & Booking (AI Powered)</td>
<td>The Eventin - Event Calendar, Event Registration, Tickets & Booking=
(AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scrip= ting via the 'etn_faq_content' parameter in all versions up to, and includi= ng, 4.1.15 due to insufficient input sanitization and output escaping. This=
makes it possible for authenticated attackers, with contributor-level acce=
ss and above, to inject arbitrary web scripts in pages that will execute wh= enever a user accesses an injected page.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12924" target=3D= "_blank" rel=3D"noopener">CVE-2026-12924</a></td>
</tr>
<td class=3D"vendor-product">arraytics--Eventin Event Calendar, Event Regis= tration, Tickets & Booking (AI Powered)</td>
<td>The Eventin - Event Calendar, Event Registration, Tickets & Booking=
(AI Powered) plugin for WordPress is vulnerable to authorization bypass du=
e to a regression in versions from 4.0.26 up to and including 4.1.15. This =
is due to the plugin not properly verifying that a user is authorized to pe= rform an action in the payment_complete() function of PaymentController.php=
. This makes it possible for unauthenticated attackers to mark unpaid ticke=
t orders as completed by submitting a fabricated SureCart checkout ID or Fl= uentCart cart hash, granting themselves paid event access, QR-code attendee=
tickets, and order confirmation emails without making any real payment. Th=
e wp_rest nonce required to reach the vulnerable endpoint is embedded in ev= ery public event page, meaning no WordPress session or credentials are need=
ed to obtain it. This vulnerability represents a regression - the same func= tion and endpoint were previously patched but the fix did not persist throu=
gh subsequent releases.</td>
<td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13039" target=3D= "_blank" rel=3D"noopener">CVE-2026-13039</a></td>
</tr>
<td class=3D"vendor-product">arraytics--WPCafe Restaurant Menu, Online Food=
Ordering & Table Booking System</td>
<td>The WPCafe - Restaurant Menu, Online Food Ordering & Table Booking = System plugin for WordPress is vulnerable to authorization bypass in all ve= rsions up to, and including, 3.0.14. This is due to the plugin not properly=
verifying that a user is authorized to perform an action. This makes it po= ssible for authenticated attackers, with subscriber-level access and above,=
to list, create, update, delete, clone, and bulk-delete notification flow = workflows that are intended to be managed only by administrators. The only = protection on these endpoints is a wp_rest nonce check, which is obtainable=
by any logged-in user from the frontend page source.</td>
<td>2026-07-10</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11818" target=3D= "_blank" rel=3D"noopener">CVE-2026-11818</a></td>
</tr>
<td class=3D"vendor-product">AstrBotDevs--AstrBot</td>
<td>A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2=
. Affected is the function FutureTaskTool.call of the file astrbot/core/too= ls/cron_tools.py of the component Scheduled Task Handler. Performing a mani= pulation of the argument payload["note"] results in improper authorization.=
Remote exploitation of the attack is possible. The exploit has been releas=
ed to the public and may be used for attacks. The vendor was contacted earl=
y about this disclosure but did not respond in any way.</td> <td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15499" target=3D= "_blank" rel=3D"noopener">CVE-2026-15499</a></td>
</tr>
<td class=3D"vendor-product">AstrBotDevs--AstrBot</td>
<td>A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Aff= ected by this vulnerability is the function get_online_plugins of the file = astrbot/dashboard/routes/plugin.py of the component market_list Endpoint. E= xecuting a manipulation of the argument custom_registry can lead to server-= side request forgery. The attack can be executed remotely. The exploit has = been made available to the public and could be used for attacks. The vendor=
was contacted early about this disclosure but did not respond in any way.<=
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15500" target=3D= "_blank" rel=3D"noopener">CVE-2026-15500</a></td>
</tr>
<td class=3D"vendor-product">AstrBotDevs--AstrBot</td>
<td>A security vulnerability has been detected in AstrBotDevs AstrBot up to=
4.25.2. Affected by this issue is the function ToolsRoute.test_mcp_connect= ion of the file astrbot/dashboard/routes/tools.py of the component MCP Test=
Endpoint. The manipulation of the argument mcp_server_config.url leads to = server-side request forgery. The attack is possible to be carried out remot= ely. The exploit has been disclosed publicly and may be used. The vendor wa=
s contacted early about this disclosure but did not respond in any way.</td=
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15501" target=3D= "_blank" rel=3D"noopener">CVE-2026-15501</a></td>
</tr>
<td class=3D"vendor-product">AVideo--AVideo</td>
<td>AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024= f59f8 contains a stored cross-site scripting vulnerability in the Meet plug= in's getMeetInfo.json.php endpoint. When a participant joins a public meeti= ng, the raw HTTP User-Agent header is stored (meet_join_log.user_agent) wit= hout sanitization (bypassing AVideo's setter-level xss_esc() layer) and lat=
er echoed without output encoding (no htmlspecialchars()) in the Participan=
ts management panel, which is accessible to the meeting host and site admin= istrators. An anonymous, unauthenticated attacker can join any public meeti=
ng while supplying a User-Agent header containing an HTML/JavaScript payloa=
d; the payload is persisted and executes in the privileged, authenticated b= rowser session of the meeting host or a site administrator when they open t=
he participant list. The issue was unpatched at the time of the report.</td=
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60092" target=3D= "_blank" rel=3D"noopener">CVE-2026-60092</a></td>
</tr>
<td class=3D"vendor-product">AWS--res</td>
<td>AWS Research and Engineering Studio (RES) is an open-source solution th=
at enables researchers and engineers to create and manage secure virtual de= sktops and computing resources on AWS. Improper link resolution before file=
access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated = remote user could read arbitrary files on the cluster-manager EC2 instance =
by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic lin=
k targeting any file on the host. Because the cluster-manager process runs =
as root, any file readable by root is exposed, including other users' SSH p= rivate keys and application configuration secrets. It's recommended to upgr= ade to RES version 2026.06.</td>
<td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14904" target=3D= "_blank" rel=3D"noopener">CVE-2026-14904</a></td>
</tr>
<td class=3D"vendor-product">axllent--mailpit</td>
<td>Mailpit is an email testing tool and API for developers. Prior to 1.30.=
2, the remediation shipped for CVE-2026-27808 is incomplete because the too= ls.IsInternalIP deny-list in internal/tools/net.go relies on Go's standard = library classification helpers and does not block IPv6 transition mechanism=
s or prefixes such as NAT64, 6to4, IPv4-compatible IPv6, ISATAP, fec0::/10,=
and 2001:db8::/32. An attacker who can deliver email and invoke POST /api/= v1/message/{ID}/link-check can coerce the Link Check API's safeDialContext = path into dialing internal destinations and can use status-code and error f= eedback to map internal service reachability, including cloud metadata endp= oints. This issue is fixed in version 1.30.2.</td>
<td>2026-07-10</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55187" target=3D= "_blank" rel=3D"noopener">CVE-2026-55187</a></td>
</tr>
<td class=3D"vendor-product">Bahmni--bahmnicore</td>
<td>A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affe= cts the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicor= e/sql of the component Search Endpoint. Performing a manipulation of the ar= gument test results in sql injection. The attack can be initiated remotely.=
The exploit is now public and may be used. Upgrading to version 0.93.1, 1.= 0.1, 1.1.1, 1.2.1, 1.3.1 and 2.0.1 mitigates this issue. Upgrading the affe= cted component is recommended.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15477" target=3D= "_blank" rel=3D"noopener">CVE-2026-15477</a></td>
</tr>
<td class=3D"vendor-product">beardev--JoomSport for Sports: Team & Leag= ue, Football, Hockey & more</td>
<td>The JoomSport - for Sports: Team & League, Football, Hockey & m= ore plugin for WordPress is vulnerable to time-based SQL Injection via 'eve= nt' Shortcode Attribute in all versions up to, and including, 5.7.9 due to = insufficient escaping on the user supplied parameter and lack of sufficient=
preparation on the existing SQL query. This makes it possible for authenti= cated attackers, with contributor-level access and above, to append additio= nal SQL queries into already existing queries that can be used to extract s= ensitive information from the database. The shortcode can be embedded in po= sts or pages by Contributor-level users, making this exploitable by any aut= henticated user with at least that role.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13010" target=3D= "_blank" rel=3D"noopener">CVE-2026-13010</a></td>
</tr>
<td class=3D"vendor-product">bentoml--OpenLLM</td>
<td>A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the f= unction async_run_command of the file src/openllm/common.py of the componen=
t Model Repository Directory Name Handler. Performing a manipulation of the=
argument cmd results in command injection. Attacking locally is a requirem= ent. The exploit has been made public and could be used. The project was in= formed of the problem early through an issue report but has not responded y= et.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15035" target=3D= "_blank" rel=3D"noopener">CVE-2026-15035</a></td>
</tr>
<td class=3D"vendor-product">Bixilon--Minosoft</td>
<td>Minosoft is an open-source, multi-version Minecraft Java Edition client=
written in Kotlin. Starting in commit f1ae30e2b046a490026a8413b075685deb79= 5122, the CryptManager=C2=A0 encryption routine (=C2=A0CryptManager.kt=C2=
=A0) initializes its AES cipher using an initialization vector (IV) that is=
set equal to the secret key rather than to a sufficiently random value. Be= cause the IV is not random and is derived directly from the key, the encryp= tion is vulnerable to chosen-ciphertext/chosen-plaintext attacks: an attack=
er who can submit specific messages for encryption can recover the secret k= ey. This affects all versions supporting Minecraft protocol 1.7 and later. =
No patched version is available, and no known workarounds are available.</t=
<td>2026-07-06</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-56141" target=3D= "_blank" rel=3D"noopener">CVE-2024-56141</a></td>
</tr>
<td class=3D"vendor-product">bouncingsprout--Block, Suspend, Report for Bud= dyPress</td>
<td>The Block, Suspend, Report for BuddyPress plugin for WordPress is vulne= rable to Stored Cross-Site Scripting via the 'link' parameter in versions u=
p to and including 3.6.4. This is due to insufficient input sanitization an=
d output escaping. This makes it possible for authenticated attackers with = subscriber-level access and above to inject arbitrary web scripts in pages = that will execute whenever a user accesses an injected page.</td> <td>2026-07-09</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4653" target=3D"= _blank" rel=3D"noopener">CVE-2026-4653</a></td>
</tr>
<td class=3D"vendor-product">bytecodealliance--wasmtime</td>
<td>Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.=
3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check director=
y permissions but not matching FilePerms on source and destination preopens=
, allowing a WASI guest with a read-only source file capability to overwrit=
e host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 f= ilesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.= 0.3, and 46.0.1.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58494" target=3D= "_blank" rel=3D"noopener">CVE-2026-58494</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure=
vulnerability in the Supabase PostgREST RPC function public.get_total_metr= ics(org_id), which is callable by the anon role using only the public sb_pu= blishable_* key. An unauthenticated attacker can probe organization existen=
ce and leak sensitive usage metrics including MAU, bandwidth, and install c= ounts by sending POST requests to /rest/v1/rpc/get_total_metrics with valid=
organization UUIDs.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56284" target=3D= "_blank" rel=3D"noopener">CVE-2026-56284</a></td>
</tr>
<td class=3D"vendor-product">Cap-go--capgo</td>
<td>Cap-go before 12.128.2 contains an information disclosure vulnerability=
in the public.transfer_app RPC function that returns distinct error messag=
es for existing versus non-existing app IDs. Unauthenticated attackers can = enumerate valid app IDs by observing error message differences when calling=
transfer_app with only the publishable API key.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56296" target=3D= "_blank" rel=3D"noopener">CVE-2026-56296</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authorization bypass vulnerability in=
the public.manifest INSERT policy that allows read-only org members to ins= ert OTA manifest rows. Attackers with read-only org access can inject malic= ious manifest entries with arbitrary s3_path values that are served to devi= ces via the unauthenticated /updates endpoint, enabling OTA metadata poison= ing and potential malicious asset delivery.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56220" target=3D= "_blank" rel=3D"noopener">CVE-2026-56220</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an improper validation vulnerability in = the accept_invitation endpoint that creates user accounts before captcha va= lidation is enforced. Attackers can bypass captcha protection by sending PO=
ST requests with invalid captcha tokens to create unwanted accounts and bur=
n invite links.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56312" target=3D= "_blank" rel=3D"noopener">CVE-2026-56312</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a cross-tenant preview namespace collisi=
on vulnerability caused by non-bijective decoding of double underscores to = dots in preview hostname parsing. Attackers can register app IDs with under= scores that collide with other tenants' dotted app IDs, causing preview mis= routing and denial of preview access for victim applications.</td> <td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56329" target=3D= "_blank" rel=3D"noopener">CVE-2026-56329</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authorization bypass vulnerability wh= ere write-scoped API keys can directly mutate protected channel configurati=
on fields through PostgREST by exploiting a null authentication check in th=
e immutability trigger. Attackers with write API keys can modify sensitive = channel attributes such as public, allow_emulator, and security-related fla=
gs outside intended application routes.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56335" target=3D= "_blank" rel=3D"noopener">CVE-2026-56335</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a scope isolation vulnerability in the P= OST /webhooks/test endpoint that allows app-scoped API keys to invoke org-s= coped webhook operations. Attackers with app-scoped credentials can trigger=
signed outbound webhook deliveries for arbitrary organization webhooks out= side their declared app boundary, bypassing the limited_to_apps authorizati=
on check.</td>
<td>2026-07-12</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56252" target=3D= "_blank" rel=3D"noopener">CVE-2026-56252</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an html injection vulnerability in the o= rganization settings endpoint that allows attackers to inject malicious HTM=
L content. Attackers can craft payloads in the organization name field to r= edirect users to untrusted websites, enabling phishing attacks and reputati= onal damage.</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56283" target=3D= "_blank" rel=3D"noopener">CVE-2026-56283</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an authorization flaw in transfer_app() = that fails to update deploy_history.owner_org when transferring application=
s between organizations. Attackers can exploit this omission to retain unau= thorized access to deployment history records in the source organization or=
cause the destination organization to lose access to transferred applicati=
on deployment records.</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56293" target=3D= "_blank" rel=3D"noopener">CVE-2026-56293</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /= files/upload/attachments endpoint, allowing plan-blocked apps to create pub= licly readable R2 objects. Attackers can upload arbitrary attachments using=
upload-scoped API keys that bypass plan checks, persist outside normal bun= dle metadata, and survive app deletion, enabling storage and bandwidth abus= e.</td>
<td>2026-07-10</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56309" target=3D= "_blank" rel=3D"noopener">CVE-2026-56309</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains an information disclosure vulnerability =
in the unauthenticated /private/sso/check-domain endpoint that returns inte= rnal org_id and provider_id values. Attackers can enumerate email domains t=
o build mappings of domains to organization UUIDs and SSO provider identifi= ers, enabling reconnaissance against Capgo tenants.</td>
<td>2026-07-12</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56336" target=3D= "_blank" rel=3D"noopener">CVE-2026-56336</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a policy bypass vulnerability in app_ver= sions update enforcement that allows app-scoped API keys to downgrade encry= pted bundles to non-encrypted state. Attackers with app-scoped all API keys=
can directly update the app_versions table via PostgREST to clear session_= key and key_id fields, bypassing organization-enforced encrypted-bundle pol= icies and weakening OTA security controls.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56217" target=3D= "_blank" rel=3D"noopener">CVE-2026-56217</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.12 contains a billing authorization bypass vulnerab= ility in the plan_valid calculation that allows organizations with exhauste=
d or expired usage credit grants to bypass billing gates. Attackers can exp= loit the divergence between the plugin hot-path plan_valid expression and t=
he authoritative billing gate to gain continued access to /updates, /stats,=
/channel_self, and attachment upload endpoints after credit depletion.</td=
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56240" target=3D= "_blank" rel=3D"noopener">CVE-2026-56240</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded=
via the app information endpoint, exposing sensitive geolocation data. Att= ackers can upload images containing EXIF metadata to extract geographic loc= ation information and other embedded metadata from uploaded files.</td> <td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56298" target=3D= "_blank" rel=3D"noopener">CVE-2026-56298</a></td>
</tr>
<td class=3D"vendor-product">carazo--Import and export users and customers<=
<td>The Import and export users and customers plugin for WordPress is vulne= rable to Sensitive Information Exposure in all versions up to, and includin=
g, 2.4.0 via the email_template_selected. This makes it possible for authen= ticated attackers, with subscriber-level access and above, to extract the p= ost_title and raw post_content of arbitrary posts regardless of status (dra= ft, private, future, trash, password-protected) or post type (including non= -public CPTs such as WooCommerce orders and internal CRM records) by enumer= ating post IDs. The required codection-security nonce is exposed as inline = JavaScript on any wp-admin page when ?post_type=3Dacui_email_template is ap= pended to the URL, which is reachable by any authenticated user including S= ubscribers.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15026" target=3D= "_blank" rel=3D"noopener">CVE-2026-15026</a></td>
</tr>
<td class=3D"vendor-product">catalyst2020--Catalyst Connect Zoho CRM Client=
Portal</td>
<td>The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vul= nerable to time-based SQL Injection via the 'uid' parameter in all versions=
up to, and including, 2.2.0 due to insufficient escaping on the user suppl= ied parameter and lack of sufficient preparation on the existing SQL query.=
This makes it possible for authenticated attackers, with Administrator-lev=
el access and above, to append additional SQL queries into already existing=
queries that can be used to extract sensitive information from the databas= e.</td>
<td>2026-07-11</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-5017" target=3D"= _blank" rel=3D"noopener">CVE-2025-5017</a></td>
</tr>
<td class=3D"vendor-product">chatra--Chatra Live Chat + ChatBot + Cart Save= r</td>
<td>The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vul= nerable to Stored Cross-Site Scripting via admin settings in all versions u=
p to, and including, 1.0.12 due to insufficient input sanitization and outp=
ut escaping. This makes it possible for authenticated attackers, with admin= istrator-level permissions and above, to inject arbitrary web scripts in pa= ges that will execute whenever a user accesses an injected page. This only = affects multi-site installations and installations where unfiltered_html ha=
s been disabled.</td>
<td>2026-07-08</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12041" target=3D= "_blank" rel=3D"noopener">CVE-2026-12041</a></td>
</tr>
<td class=3D"vendor-product">christopherthielen--check-peer-dependencies</t=
<td>A flaw has been found in christopherthielen check-peer-dependencies up =
to 4.3.4. Affected by this vulnerability is the function shelljs.exec of th=
e file dist/packageUtils.js of the component peerDependencies. This manipul= ation causes os command injection. The attack may be initiated remotely. Th=
e project was informed of the problem early through an issue report but has=
not responded yet.</td>
<td>2026-07-08</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15033" target=3D= "_blank" rel=3D"noopener">CVE-2026-15033</a></td>
</tr>
<td class=3D"vendor-product">cilium--cilium</td>
<td>Cilium is a networking, observability, and security solution. Prior to = 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the a= bility to create CiliumLocalRedirectPolicies can specify arbitrary ClusterI=
Ps via addressMatcher, enabling hijacking traffic to Services in any namesp= ace and bypassing namespace scoping enforced by serviceMatcher; deleting su=
ch a policy can also corrupt Cilium internal service state and stop service=
translation for the affected Service. This issue is fixed in versions 1.17= .16, 1.18.10, and 1.19.4.</td>
<td>2026-07-07</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53935" target=3D= "_blank" rel=3D"noopener">CVE-2026-53935</a></td>
</tr>
<td class=3D"vendor-product">cli--cli</td>
<td>GitHub CLI (gh) is GitHub's official command line tool. From 2.10.0 thr= ough 2.95.0, connecting to a malicious Codespace with gh codespace jupyter = can allow command execution because the command opens a JupyterLab URL supp= lied by a process inside the Codespace without validating that it is a loop= back HTTP or HTTPS address, allowing a crafted vscode:// or vscode-insiders= :// URL to be handed to VS Code. This issue is fixed in version 2.96.0.</td=
<td>2026-07-09</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59831" target=3D= "_blank" rel=3D"noopener">CVE-2026-59831</a></td>
</tr>
<td class=3D"vendor-product">CodeAstro--Apartment Visitor Management System= </td>
<td>A vulnerability has been found in CodeAstro Apartment Visitor Managemen=
t System 1.0. Affected by this issue is some unknown functionality of the f= ile /apartment-visitor/action-visitor.php. Such manipulation of the argumen=
t remark leads to sql injection. The attack may be performed from remote. T=
he exploit has been disclosed to the public and may be used.</td> <td>2026-07-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14795" target=3D= "_blank" rel=3D"noopener">CVE-2026-14795</a></td>
</tr>
<td class=3D"vendor-product">CodeAstro--Apartment Visitor Management System= </td>
<td>A vulnerability was found in CodeAstro Apartment Visitor Management Sys= tem 1.0. This affects an unknown part of the file /apartment-visitor/report= .php. Performing a manipulation of the argument fromdate results in sql inj= ection. It is possible to initiate the attack remotely. The exploit has bee=
n made public and could be used.</td>
<td>2026-07-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14796" target=3D= "_blank" rel=3D"noopener">CVE-2026-14796</a></td>
</tr>
<td class=3D"vendor-product">CodeAstro--Apartment Visitor Management System= </td>
<td>A vulnerability was determined in CodeAstro Apartment Visitor Managemen=
t System 1.0. This vulnerability affects unknown code of the file /apartmen= t-visitor/edit-apartment.php. Executing a manipulation of the argument edit=
id can lead to sql injection. It is possible to launch the attack remotely.=
The exploit has been publicly disclosed and may be utilized.</td> <td>2026-07-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14797" target=3D= "_blank" rel=3D"noopener">CVE-2026-14797</a></td>
</tr>
<td class=3D"vendor-product">CodeAstro--Apartment Visitor Management System= </td>
<td>A vulnerability was identified in CodeAstro Apartment Visitor Managemen=
t System 1.0. This issue affects some unknown processing of the file /apart= ment-visitor/visitor-entry.php. The manipulation of the argument visname le= ads to sql injection. The attack can be initiated remotely. The exploit is = publicly available and might be used.</td>
<td>2026-07-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14798" target=3D= "_blank" rel=3D"noopener">CVE-2026-14798</a></td>
</tr>
<td class=3D"vendor-product">CodeAstro--Ecommerce Website</td>
<td>A security flaw has been discovered in CodeAstro Ecommerce Website 1.0.=
Impacted is an unknown function of the file /customer/my_account.php?my_wi= shlist. The manipulation of the argument delete_wishlist results in sql inj= ection. The attack can be launched remotely. The exploit has been released =
to the public and may be used for attacks.</td>
<td>2026-07-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14799" target=3D= "_blank" rel=3D"noopener">CVE-2026-14799</a></td>
</tr>
<td class=3D"vendor-product">codename065--Download Manager</td>
<td>The Download Manager plugin for WordPress is vulnerable to Stored Cross= -Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in = all versions up to, and including, 3.3.61 due to insufficient input sanitiz= ation and output escaping. This makes it possible for authenticated attacke= rs, with contributor-level access and above, to inject arbitrary web script=
s in pages that will execute whenever a user accesses an injected page. Bec= ause wp_kses_post filters post content on save for users without unfiltered= _html, only kses-allowed tag and attribute payloads that survive save-time = filtering will reach the unescaped sink; however, the sink itself remains u= nsafe and such payloads can still execute in the browser when a user render=
s the shortcode.</td>
<td>2026-07-09</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14343" target=3D= "_blank" rel=3D"noopener">CVE-2026-14343</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2,=
and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Reques=
t Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/wo= rkspaceagents/azure-instance-identity`). An external attacker can force the=
Coder server to issue HTTP GET requests to arbitrary internal or external = hosts by submitting a crafted PKCS#7 signature. The server does not return = the target's response body, but error messages in the API response reveal w= hether the target is reachable and what type of failure occurred. Versions = 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a = workaround, if the Azure identity-auth mechanism is not being used then res= trict access to the corresponding endpoint (`/api/v2/workspaceagents/azure-= instance-identity`) using ingress firewall and/or proxy ACLs.</td> <td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45796" target=3D= "_blank" rel=3D"noopener">CVE-2026-45796</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.= 32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` converts zip uploads to tar =
in memory via `CreateTarFromZip`, which enforced a per-entry size limit but=
no aggregate limit on total decompressed output, writing to an unbounded i= n-memory buffer. Exploitation requires authenticated file-upload access and=
the impact is limited to availability (denial of service). The fix in vers= ions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds a metadata preflight check tha=
t sums projected entry sizes and a streaming writer that enforces the aggre= gate limit during decompression. As a workaround, restrict file-upload perm= issions to trusted users or place a reverse proxy with request-body size li= mits in front of `coderd`.</td>
<td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55078" target=3D= "_blank" rel=3D"noopener">CVE-2026-55078</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and=
2.34.2, AI Bridge provider handlers read request bodies with `io.ReadAll` = without a maximum size so an authenticated user with AI Bridge access could=
send an arbitrarily large body and exhaust memory. Exploitation requires a= uthenticated access to the AI Bridge endpoints and the impact is limited to=
availability (denial of service). Versions 2.33.8 and 2.34.2 patch the iss= ue. No known workarounds are available.</td>
<td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55434" target=3D= "_blank" rel=3D"noopener">CVE-2026-55434</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the w= orkspace app proxy resolves the target app from `httpapi.RequestHost()` whi=
ch prefers the `X-Forwarded-Host` header over the real `Host` header. No mi= ddleware strips `X-Forwarded-Host` before routing and the header is not bro= wser-forbidden so client-side JavaScript can set it on `fetch()` calls. Pra= ctical exploitation requires subdomain app routing (wildcard hostname) enab= led, a victim who visits the attacker's shared app and a deployment whose u= pstream proxy does not strip `X-Forwarded-Host`. The fix in versions 2.29.7=
, 2.32.7, 2.33.8, and 2.34.2 trusts `X-Forwarded-Host` only from configured=
trusted proxies and otherwise resolves the routing host from the verified = request host. As a workaround, place an upstream reverse proxy that strips =
or overwrites `X-Forwarded-Host` on untrusted requests.</td> <td>2026-07-08</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55430" target=3D= "_blank" rel=3D"noopener">CVE-2026-55430</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `= CreateSubAgent` RPC did not validate a requested app sharing level against = the template's `MaxPortSharingLevel` before persisting workspace apps, lett= ing a workspace owner exceed the administrator's configured maximum. Exploi= tation requires the ability to register sub-agent apps in a workspace the a= ttacker controls. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2cla= mps the sub-agent app sharing level to the template's `MaxPortSharingLevel`=
. As a workaround, disable wildcard app hostnames (`CODER_WILDCARD_ACCESS_U= RL`) to block subdomain-based app routing.</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55432" target=3D= "_blank" rel=3D"noopener">CVE-2026-55432</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the d= evcontainer recreate endpoint relied on route middleware that checked only = `ActionRead` on the workspace and, unlike the sibling delete endpoint, perf= ormed no `ActionUpdate` check before triggering the destructive rebuild. Ex= ploitation requires an existing low-privilege role with access to the targe=
t workspace. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds an=
explicit `ActionUpdate` authorization check before the agent is dialed lik=
e the delete endpoint. No known workarounds are available.</td> <td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55433" target=3D= "_blank" rel=3D"noopener">CVE-2026-55433</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.= 33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuth= orized` in `coderd/aibridgedserver`, which validates key format, expiry, se= cret and deleted or system users but does not check whether the account is = suspended. Because suspension does not revoke existing API keys, a suspende=
d user's unexpired token keeps working. Practical impact is limited to alre= ady-issued API keys of suspended users until those keys are deleted. Versio=
ns 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspensi= on, delete the user's API keys via `DELETE /api/v2/users/{user}/keys`.</td> <td>2026-07-07</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55435" target=3D= "_blank" rel=3D"noopener">CVE-2026-55435</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the = `AgentLogLine` dashboard component instantiated `ansi-to-html` without `esc= apeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML=
embedded in workspace agent log lines was rendered as live markup. Server-= side sanitization did not neutralize HTML metacharacters. Exploitation requ= ires a victim to view attacker-controlled agent logs in the dashboard. The = fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 enables `escapeXML: tru=
e` so HTML metacharacters are escaped before DOM insertion. No known workar= ounds are available.</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55437" target=3D= "_blank" rel=3D"noopener">CVE-2026-55437</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Code= r's subdomain-based workspace app proxy allowed the same-owner CORS check t=
o be bypassed. When a workspace-name subdomain segment parsed as a UUID, th=
e workspace was resolved by ID without confirming the URL's username matche=
d the real owner, while the CORS middleware trusted the unverified username=
in the hostname. Practical exploitation requires subdomain app routing (wi= ldcard hostname) enabled and a victim who visits the attacker's crafted app=
URL while authenticated. The fix in versions 2.29.17, 2.32.7, 2.33.8, and = 2.34.2 validates the subdomain username against the resolved workspace's ac= tual owner and bases the same-owner CORS decision on the authoritative owne=
r identity. No known workarounds are available.</td>
<td>2026-07-08</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55438" target=3D= "_blank" rel=3D"noopener">CVE-2026-55438</a></td>
</tr>
<td class=3D"vendor-product">coder--coder</td>
<td>Coder allows organizations to provision remote development environments=
via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.= 32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupl= oad.go` allocated a byte slice using the client-supplied `FileSize` from a = `DataUpload` message without an upper-bound check. Although the DRPC wire l= imit is 4 MiB, the `FileSize` value itself was unconstrained. The fix in ve= rsions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `FileSize` against an u= pper bound (`MaxFileSize =3D 100 MiB`) before allocation. As a workaround, = restrict access to the provisioner daemon serve endpoint to trusted provisi= oner daemon service accounts.</td>
<td>2026-07-07</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55079" target=3D= "_blank" rel=3D"noopener">CVE-2026-55079</a></td>
</tr>
<td class=3D"vendor-product">composer--composer</td>
<td>Composer is a dependency Manager for the PHP language. Prior to 2.2.29 = and 2.10.2, a Composer package bin entry containing .. path segments can re= solve outside the package install directory and cause Composer's binary ins= tallation flow to chmod an existing host file to a world-readable and world= -executable mode during composer install, update, or require. This issue is=
fixed in versions 2.2.29 and 2.10.2.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59946" target=3D= "_blank" rel=3D"noopener">CVE-2026-59946</a></td>
</tr>
<td class=3D"vendor-product">composer--composer</td>
<td>Composer is a dependency Manager for the PHP language. Prior to 2.2.29 = and 2.10.2, when Composer is run with -vvv debug verbosity, it could print =
a credential embedded in the username slot of a repository or package URL, = such as a GitHub Personal Access Token in
https://TOKEN@host/, to debug out= put because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize=
username-only URL credentials. This issue is fixed in versions 2.2.29 and = 2.10.2.</td>
<td>2026-07-08</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59947" target=3D= "_blank" rel=3D"noopener">CVE-2026-59947</a></td>
</tr>
<td class=3D"vendor-product">ComposioHQ--composio</td>
<td>Composio SDK before 0.2.32-beta.283 contains a path validation bypass v= ulnerability that allows attackers to read and exfiltrate sensitive files b=
y exploiting a missing assertSafeFileUploadPath check in the readFileFromDi=
sk function within tool-file-uploads.ts. Attackers can exploit prompt injec= tion to manipulate file_uploadable parameters to reference sensitive paths = such as SSH private keys, causing the CLI to upload credential files to att= acker-controlled storage.</td>
<td>2026-07-08</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59807" target=3D= "_blank" rel=3D"noopener">CVE-2026-59807</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--Coolify</td>
<td>A vulnerability was detected in coollabsio Coolify up to 4.1.1. The imp= acted element is an unknown function of the file /app/Policies/ of the comp= onent Policy Handler. Performing a manipulation results in missing authoriz= ation. Remote exploitation of the attack is possible. The exploit is now pu= blic and may be used.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15507" target=3D= "_blank" rel=3D"noopener">CVE-2026-15507</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.466, mutating API validati=
on endpoints are guarded by read ability, allowing read-scoped API tokens t=
o perform state-changing operations such as validating cloud tokens and ser= vers. This issue is fixed in version 4.0.0-beta.466.</td>
<td>2026-07-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32718" target=3D= "_blank" rel=3D"noopener">CVE-2026-32718</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates = Livewire component does not check isInstanceAdmin in its mount method, allo= wing non-admin users to access the Updates settings page and potentially mo= dify auto-update settings or trigger update checks. This issue is fixed in = version 4.0.0-beta.471.</td>
<td>2026-07-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34050" target=3D= "_blank" rel=3D"noopener">CVE-2026-34050</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback ha=
s no authentication, no rate limiting, and no input validation, allowing ar= bitrary content to be forwarded directly to a Discord webhook and enabling = spam, content injection, and webhook abuse. This issue is fixed in version = 4.0.0-beta.474.</td>
<td>2026-07-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41899" target=3D= "_blank" rel=3D"noopener">CVE-2026-41899</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor L= ivewire component exposes a public $activityId property without Livewire's = #[Locked] attribute. It loads activities via Activity::find($this->activ= ityId) with no authorization or team scoping. Activity IDs are auto-increme= nting integers. Any authenticated user can enumerate activity records acros=
s all teams and read the full command output from remote SSH processes, whi=
ch may include secrets, configuration files, and infrastructure details. Th=
is issue is fixed in version 4.0.0-beta.471.</td>
<td>2026-07-06</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34167" target=3D= "_blank" rel=3D"noopener">CVE-2026-34167</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies midd= leware trusts all proxies ($proxies =3D '*'), accepting X-Forwarded-Host fr=
om any source. The TrustHosts middleware, intended to prevent host header a= ttacks, has a circular caching dependency that prevents it from ever valida= ting hosts. When a password reset is requested, the ResetPassword notificat= ion generates the reset URL using url(route(..., false)), which derives the=
host from the (spoofable) request. An unauthenticated attacker can trigger=
a password reset email containing a link pointing to an attacker-controlle=
d domain, enabling token theft and account takeover. This issue is fixed in=
version 4.0.0-beta.471.</td>
<td>2026-07-07</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34198" target=3D= "_blank" rel=3D"noopener">CVE-2026-34198</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url=
field is used as the base URL for server-side HTTP requests without allowl= isting or private IP blocking, allowing an authenticated user to configure =
a GitHub App source that causes Coolify to request internal services or clo=
ud metadata endpoints. This issue is reported as fixed in version 4.0.0-bet= a.471.</td>
<td>2026-07-07</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34170" target=3D= "_blank" rel=3D"noopener">CVE-2026-34170</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint v= alidation only checks URL format and testConnection() sends a server-side r= equest to the configured endpoint, allowing an authenticated user with stor= age management permissions to make Coolify request internal or metadata-ser= vice URLs. This issue is fixed in version 4.0.0-beta.474.</td> <td>2026-07-07</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42147" target=3D= "_blank" rel=3D"noopener">CVE-2026-42147</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listenin=
g on a Kafka topic stops processing new records from that topic when KafkaT= ransportPump receives a null-value tombstone record, causing a persistent e= ndpoint denial of service for attackers with produce permission. This issue=
is fixed in versions 1.8.1 and 1.9.1.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54775" target=3D= "_blank" rel=3D"noopener">CVE-2026-54775</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe trans= port accepts attachment to a pre-existing named pipe instance, allowing loc=
al interception of NetNamedPipe traffic when an attacker races NamedPipeLis= tener startup between shared memory GUID publication and service named pipe=
creation. This issue is fixed in versions 1.8.1 and 1.9.1.</td> <td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54777" target=3D= "_blank" rel=3D"noopener">CVE-2026-54777</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket P= OSIX peer identity resolution uses non-reentrant getpwuid and getgrgid call=
s, allowing concurrent connections to attribute one connection's identity t=
o another or crash the host process under contention. This issue is fixed i=
n versions 1.8.1 and 1.9.1.</td>
<td>2026-07-08</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54778" target=3D= "_blank" rel=3D"noopener">CVE-2026-54778</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signat= ure verification performs a document-wide ds:Signature lookup, allowing an = unauthenticated remote attacker to place a SOAP header before wsse:Security=
and cause WSSecurityOneDotZeroReceiveSecurityHeader to verify an attacker-= supplied signature instead of the security header signature. This issue is = fixed in versions 1.8.1 and 1.9.1.</td>
<td>2026-07-08</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54773" target=3D= "_blank" rel=3D"noopener">CVE-2026-54773</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay = protection is inoperative because DefaultTokenReplayCache.TryAdd does not r= eject duplicate tokens when DetectReplayedTokens is enabled, allowing a cap= tured token to be reused. This issue is fixed in versions 1.8.1 and 1.9.1.<=
<td>2026-07-08</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54779" target=3D= "_blank" rel=3D"noopener">CVE-2026-54779</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted o=
n Unix Domain Sockets with PosixIdentity client credentials can accept conn= ections that skip the application/unixposix stream upgrade before dispatchi=
ng messages, bypassing framing-layer identity checks in UnixPosixIdentitySe= curityUpgradeProvider. This issue is fixed in versions 1.8.1 and 1.9.1.</td=
<td>2026-07-08</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54776" target=3D= "_blank" rel=3D"noopener">CVE-2026-54776</a></td>
</tr>
<td class=3D"vendor-product">corvusinfo--CorvusPay WooCommerce Payment Gate= way</td>
<td>The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulne= rable to Payment Bypass via Improper Verification of Cryptographic Signatur=
e in all versions up to, and including, 2.7.4. The `corvuspay_success_handl= er` function registers the REST endpoint `POST /wp-json/corvuspay/success/`=
with `'permission_callback' =3D> '__return_true'`, and while it calls `= $this->client->validate->signature()` and stores the boolean resul=
t in `$res`, the result is never evaluated in a conditional - it is only wr= itten to the debug log - causing execution to unconditionally reach `$order= ->payment_complete()` regardless of whether the cryptographic signature =
is valid. This makes it possible for unauthenticated attackers to mark any = pending WooCommerce order as fully paid by sending a POST request to the su= ccess endpoint containing an arbitrary or forged signature value, allowing = them to obtain goods or services without payment. Because WooCommerce order=
IDs are sequential integers, target orders are trivially enumerable via th=
e `order_number` POST parameter, requiring no prior knowledge of the victim=
order.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9027" target=3D"= _blank" rel=3D"noopener">CVE-2026-9027</a></td>
</tr>
<td class=3D"vendor-product">corvusinfo--CorvusPay WooCommerce Payment Gate= way</td>
<td>The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulne= rable to authorization bypass in all versions up to, and including, 2.7.4. = This is due to the plugin not properly verifying that a user is authorized =
to perform an action. This makes it possible for unauthenticated attackers =
to cancel any WooCommerce order placed via the CorvusPay payment method by = supplying an arbitrary order number to the /wp-json/corvuspay/cancel/ REST = endpoint.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9028" target=3D"= _blank" rel=3D"noopener">CVE-2026-9028</a></td>
</tr>
<td class=3D"vendor-product">Cotonti--Cotonti</td>
<td>Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting=
vulnerability that allows authenticated users with PFS access to inject ar= bitrary script payloads by supplying malicious HTML in the ntitle parameter=
processed through the TXT filter in pfs.main.php. Attackers can create a f= older with a crafted title containing script tags that are stored unescaped=
in the database and execute in the browser of any user who views the folde=
r listing, including administrators.</td>
<td>2026-07-09</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58144" target=3D= "_blank" rel=3D"noopener">CVE-2026-58144</a></td>
</tr>
<td class=3D"vendor-product">coturn--coturn</td>
<td>Coturn is a free open source implementation of TURN and STUN Server. Pr= ior to 4.13.0, the psd print sessions dump CLI command in coturn takes a fi= lename argument and directly passes it to fopen with no path validation. An=
authenticated admin with CLI access can overwrite arbitrary files writable=
by the coturn process because the command string is used as-is after strip= ping the psd prefix and leading spaces, allowing truncation and overwrite w= ith session dump data. This issue is fixed in version 4.13.0.</td> <td>2026-07-10</td>
<td>6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53449" target=3D= "_blank" rel=3D"noopener">CVE-2026-53449</a></td>
</tr>
<td class=3D"vendor-product">Craft--CMS</td>
<td>A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is t=
he function actionReorderSets of the file src/controllers/GlobalsController= .php of the component reorder-sets Endpoint. The manipulation results in au= thorization bypass. The attack can be executed remotely. Upgrading to versi=
on 4.18.1 is able to address this issue. The patch is identified as 9bd05c9= 1e6a7e6da5e949ec41a31c220c059aa04. The affected component should be upgrade= d.</td>
<td>2026-07-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14793" target=3D= "_blank" rel=3D"noopener">CVE-2026-14793</a></td>
</tr>
<td class=3D"vendor-product">Craft--CMS</td>
<td>A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vul= nerability is the function actionGetNewUsersData of the file src/controller= s/ChartsController.php of the component Charts Endpoint. This manipulation =
of the argument userGroupId causes improper authorization. The attack is po= ssible to be carried out remotely. Upgrading to version 4.18.1 addresses th=
is issue. Patch name: 9ee53efc1314e6aba32771c66a13e072a246f4ce. It is sugge= sted to upgrade the affected component.</td>
<td>2026-07-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14794" target=3D= "_blank" rel=3D"noopener">CVE-2026-14794</a></td>
</tr>
<td class=3D"vendor-product">crewhrm--Employee, Leave and Recruitment Manag= ement System Crew HRM</td>
<td>The Employee, Leave and Recruitment Management System - Crew HRM plugin=
for WordPress is vulnerable to authorization bypass in all versions up to,=
and including, 1.2.2. This is due to the plugin not properly verifying tha=
t a user is authorized to perform an action. This makes it possible for aut= henticated attackers, with subscriber-level access and above, to delete, ar= chive, unarchive, and duplicate arbitrary job listings - along with their a= ssociated stages, meta, addresses, and applications - by supplying an arbit= rary integer job_id. The nonce verified by Dispatcher::dispatch() is expose=
d to all authenticated front-end visitors via wp_head script localization, = meaning subscribers can trivially obtain it and satisfy the nonce check wit= hout possessing any elevated privilege.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9237" target=3D"= _blank" rel=3D"noopener">CVE-2026-9237</a></td>
</tr>
<td class=3D"vendor-product">cservit--affiliate-toolkit Multi-Network Affil= iate & Amazon Product Display</td>
<td>The affiliate-toolkit - WP Affiliate Plugin with Amazon plugin for Word= Press is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_p= roduct' shortcode in all versions up to, and including, 3.7.0 due to insuff= icient input sanitization and output escaping on user supplied attributes. = This makes it possible for authenticated attackers, with contributor-level = access and above, to inject arbitrary web scripts in pages that will execut=
e whenever a user accesses an injected page. This is a bypass to CVE-2024-1= 0227.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15296" target=3D= "_blank" rel=3D"noopener">CVE-2026-15296</a></td>
</tr>
<td class=3D"vendor-product">davenardella--snap7</td>
<td>A flaw has been found in davenardella snap7 up to 1.4.3. This affects t=
he function TS7Worker::PerformFunctionRead of the file src/core/s7_server.c=
pp of the component ReadVar Request Handler. This manipulation causes deser= ialization. The attack requires access to the local network. The exploit ha=
s been published and may be used. The project was informed of the problem e= arly through an issue report but has not responded yet.</td> <td>2026-07-08</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15105" target=3D= "_blank" rel=3D"noopener">CVE-2026-15105</a></td>
</tr>
<td class=3D"vendor-product">dcooney--Ajax Load More Infinite Scroll, Load = More, & Lazy Load</td>
<td>The WordPress Infinite Scroll - Ajax Load More plugin for WordPress is = vulnerable to Stored Cross-Site Scripting via admin settings in all version=
s up to, and including, 7.0.1 due to insufficient input sanitization and ou= tput escaping. This makes it possible for authenticated attackers, with adm= inistrator-level permissions and above, to inject arbitrary web scripts in = pages that will execute whenever a user accesses an injected page. This onl=
y affects multi-site installations and installations where unfiltered_html = has been disabled.</td>
<td>2026-07-10</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15295" target=3D= "_blank" rel=3D"noopener">CVE-2026-15295</a></td>
</tr>
<td class=3D"vendor-product">Dell--Unisphere for PowerMax</td>
<td>Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) =
a path traversal vulnerability. A low privileged attacker with remote acces=
s could potentially exploit this vulnerability to read arbitrary files.</td=
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54468" target=3D= "_blank" rel=3D"noopener">CVE-2026-54468</a></td>
</tr>
<td class=3D"vendor-product">Dell--Unisphere for PowerMax</td>
<td>Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) a=
n Improper Restriction of XML External Entity Reference vulnerability. A lo=
w privileged attacker with remote access could potentially exploit this vul= nerability, leading to Unauthorized access.</td>
<td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54470" target=3D= "_blank" rel=3D"noopener">CVE-2026-54470</a></td>
</tr>
<td class=3D"vendor-product">Deloitte--AI Assist for Customer</td>
<td>Deloitte AI Assist for Customer disclosed some configuration informatio=
n through public-facing API endpoints that accepted unauthenticated request=
s. This information could reduce an attacker's reconnaissance effort. On 20= 26-03-25, AI Assist for Customer restricted network access and enforced aut= hentication for the previously exposed endpoints.</td>
<td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57474" target=3D= "_blank" rel=3D"noopener">CVE-2026-57474</a></td>
</tr>
<td class=3D"vendor-product">Deloitte--AI Assist for Customer</td>
<td>Deloitte AI Assist for Customer accepted unauthenticated POST requests = through public-facing API endpoints that allowed a remote attacker to make = limited additions to the configuration. These additions were not used by th=
e system. On 2026-03-25, AI Assist for Customer restricted network access a=
nd enforced authentication for the previously exposed endpoints.</td> <td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57475" target=3D= "_blank" rel=3D"noopener">CVE-2026-57475</a></td>
</tr>
<td class=3D"vendor-product">Deloitte--AI Assist for Customer</td>
<td>Deloitte AI Assist for Customer exposed unauthenticated API endpoints t= hat allowed an attacker with knowledge of additional parameters to read fro=
m or inject content into the retrieval-augmented generation (RAG) corpus. O=
n 2026-03-25, AI Assist for Customer restricted network access and enforced=
authentication for the previously exposed endpoints.</td>
<td>2026-07-10</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57476" target=3D= "_blank" rel=3D"noopener">CVE-2026-57476</a></td>
</tr>
<td class=3D"vendor-product">devitemsllc--Recurio Ultimate Subscription for=
WooCommerce</td>
<td>The Recurio - Ultimate Subscription for WooCommerce plugin for WordPres=
s is vulnerable to generic SQL Injection via the 'data' parameter in all ve= rsions up to, and including, 1.1.3 due to insufficient escaping on the user=
supplied parameter and lack of sufficient preparation on the existing SQL = query. This makes it possible for authenticated attackers, with shop manage= r-level access and above, to append additional SQL queries into already exi= sting queries that can be used to extract sensitive information from the da= tabase.</td>
<td>2026-07-08</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12936" target=3D= "_blank" rel=3D"noopener">CVE-2026-12936</a></td>
</tr>
<td class=3D"vendor-product">dhlparcel--DHL eCommerce (Benelux) for WooComm= erce</td>
<td>The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vul= nerable to unauthorized modification and loss of data due to a missing capa= bility check and missing nonce verification on the create_label() and delet= e_label() functions in versions up to, and including, 2.2.3. These function=
s are wired to the wp_ajax_dhlpwc_label_create and wp_ajax_dhlpwc_label_del= ete hooks and act on an attacker-supplied post_id (WooCommerce order ID). T= his makes it possible for authenticated attackers, with Subscriber-level ac= cess and above, to create or delete DHL shipping labels associated with any=
WooCommerce order on the site.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9235" target=3D"= _blank" rel=3D"noopener">CVE-2026-9235</a></td>
</tr>
<td class=3D"vendor-product">Digi International--PortServer TS 1/2/4</td> <td>This vulnerability allows an unauthenticated actor to bypass authentica= tion and gain access to restricted resources on the device.</td> <td>2026-07-07</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12352" target=3D= "_blank" rel=3D"noopener">CVE-2026-12352</a></td>
</tr>
<td class=3D"vendor-product">digiblogger--BuddyHolis TableSearch</td>
<td>The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored=
Cross-Site Scripting via the 'placeholder' parameter in all versions up to=
, and including, 1.1.0 due to insufficient input sanitization and output es= caping. This makes it possible for authenticated attackers, with Contributo= r-level access and above, to inject arbitrary web scripts in pages that wil=
l execute whenever a user accesses an injected page.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15301" target=3D= "_blank" rel=3D"noopener">CVE-2026-15301</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipar=
t uploads through ExternalUploadManager into the admin backup store. This i= ssue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.</td> <td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46413" target=3D= "_blank" rel=3D"noopener">CVE-2026-46413</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks= /aws verified that SNS messages were signed by Amazon but did not bind them=
to trusted TopicArn values, allowing any AWS account holder to publish val= idly signed forged Bounce notifications that revoke a targeted user email. = This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.= </td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53961" target=3D= "_blank" rel=3D"noopener">CVE-2026-53961</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group n= ames, sample invitees, and attendance statistics to users who could view th=
e topic but were not entitled to view the private event invitee list. This = issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.</td> <td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45780" target=3D= "_blank" rel=3D"noopener">CVE-2026-45780</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and = user avatar handling could lead to cross-site scripting when a user visited=
specific URLs that are not normally part of community browsing. This issue=
is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.</td> <td>2026-07-09</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53962" target=3D= "_blank" rel=3D"noopener">CVE-2026-53962</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from re= gular users could be leaked through visible diffs on adjacent revisions ser= ialized by PostRevisionSerializer. This issue is fixed in versions 2026.6.0=
, 2026.5.1, 2026.4.2, and 2026.1.5.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59828" target=3D= "_blank" rel=3D"noopener">CVE-2026-59828</a></td>
</tr>
<td class=3D"vendor-product">djangoproject--Django</td>
<td>An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.1=
6. `DomainNameValidator` does not prohibit newlines in domain names (unless=
used via a form field, since `CharField` strips newlines). If an applicati=
on uses values with newlines in an HTTP response, header injection can occu=
r. Django itself is unaffected because `HttpResponse` prohibits newlines in=
HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, an=
d 3.2.x) were not evaluated and may also be affected. Django would like to = thank Bence Nagy for reporting this issue.</td>
<td>2026-07-07</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53878" target=3D= "_blank" rel=3D"noopener">CVE-2026-53878</a></td>
</tr>
<td class=3D"vendor-product">djangoproject--Django</td>
<td>An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.1=
6. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses=
that vary on cookies when the incoming request carries unrelated cookies, = which allows remote attackers to read private data from the shared cache. E= arlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were no=
t evaluated and may also be affected. Django would like to thank Chris Whyl= and for reporting this issue.</td>
<td>2026-07-07</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48588" target=3D= "_blank" rel=3D"noopener">CVE-2026-48588</a></td>
</tr>
<td class=3D"vendor-product">djangoproject--Django</td>
<td>An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.1=
6. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer whe=
n constructed from a bytes object, which can disclose adjacent memory or ca= use service degradation via a potential segmentation fault when the `vsi_bu= ffer` property is accessed. Earlier, unsupported Django series (such as 5.0= .x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django w= ould like to thank Bence Nagy for reporting this issue.</td> <td>2026-07-07</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53877" target=3D= "_blank" rel=3D"noopener">CVE-2026-53877</a></td>
</tr>
<td class=3D"vendor-product">easyappointments--Easy Appointments</td>
<td>The Easy Appointments plugin for WordPress is vulnerable to authorizati=
on bypass in all versions up to, and including, 3.12.27. This is due to the=
plugin not properly verifying that a user is authorized to perform an acti= on. This makes it possible for authenticated attackers, with author-level a= ccess and above, to cancel all upcoming appointments site-wide by marking e= very future appointment stored by the plugin as abandoned. The nonce requir=
ed to authenticate the cancellation request is printed on the Appointments = admin page, which is itself gated only by the edit_posts capability that Au= thors possess, making the nonce readily accessible to low-privileged users.= </td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11992" target=3D= "_blank" rel=3D"noopener">CVE-2026-11992</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability was detected in Eleveo Call Recording Software 9.7.0. T=
he impacted element is an unknown function of the file /callrec/userAddActi= on.do. Performing a manipulation of the argument role results in improper a= uthorization. It is possible to initiate the attack remotely. The exploit i=
s now public and may be used. The vendor was contacted early about this dis= closure but did not respond in any way.</td>
<td>2026-07-10</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15373" target=3D= "_blank" rel=3D"noopener">CVE-2026-15373</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A flaw has been found in Eleveo Call Recording Software 9.7.0. This aff= ects an unknown function of the file /callrec/roleAddAction.do of the compo= nent Group Interface. Executing a manipulation can lead to improper authori= zation. It is possible to launch the attack remotely. The exploit has been = published and may be used. The vendor was contacted early about this disclo= sure but did not respond in any way.</td>
<td>2026-07-10</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15374" target=3D= "_blank" rel=3D"noopener">CVE-2026-15374</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affe= cted is an unknown function of the file /callrec/statisticReportAction.do. = The manipulation results in improper authorization. The attack can be launc= hed remotely. The exploit has been made public and could be used. The vendo=
r was contacted early about this disclosure but did not respond in any way.= </td>
<td>2026-07-10</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15376" target=3D= "_blank" rel=3D"noopener">CVE-2026-15376</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability was identified in Eleveo Call Recording Software 9.7.0.=
This issue affects some unknown processing of the file /callrec/restoreCal= lAction.do of the component Recorded Calls Page. The manipulation leads to = improper authorization. The attack is possible to be carried out remotely. = The exploit is publicly available and might be used. The vendor was contact=
ed early about this disclosure but did not respond in any way.</td> <td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15473" target=3D= "_blank" rel=3D"noopener">CVE-2026-15473</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability has been found in Eleveo Call Recording Software 9.7.0.=
This impacts an unknown function of the file /callrec/users_ldap.jsp of th=
e component LDAP User Interface. The manipulation leads to improper authori= zation. The attack can be initiated remotely. The exploit has been disclose=
d to the public and may be used. The vendor was contacted early about this = disclosure but did not respond in any way.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15375" target=3D= "_blank" rel=3D"noopener">CVE-2026-15375</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability was determined in Eleveo Call Recording Software 9.7.0.=
Affected by this vulnerability is an unknown functionality of the file /ca= llrec/sendlogfile. This manipulation causes improper authorization. The att= ack may be initiated remotely. The exploit has been publicly disclosed and = may be utilized. The vendor was contacted early about this disclosure but d=
id not respond in any way.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15377" target=3D= "_blank" rel=3D"noopener">CVE-2026-15377</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability has been found in Eleveo Call Recording Software 9.7.0.=
Affected by this issue is some unknown functionality of the file /callrec/= group.jsp. Such manipulation leads to improper authorization. The attack ma=
y be launched remotely. The exploit has been disclosed to the public and ma=
y be used. The vendor was contacted early about this disclosure but did not=
respond in any way.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15470" target=3D= "_blank" rel=3D"noopener">CVE-2026-15470</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability was found in Eleveo Call Recording Software 9.7.0. This=
affects an unknown part of the file /callrec/pci_dss_status.jsp. Performin=
g a manipulation results in improper authorization. Remote exploitation of = the attack is possible. The exploit has been made public and could be used.=
The vendor was contacted early about this disclosure but did not respond i=
n any way.</td>
<td>2026-07-12</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15471" target=3D= "_blank" rel=3D"noopener">CVE-2026-15471</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A vulnerability was determined in Eleveo Call Recording Software 9.7.0.=
This vulnerability affects unknown code of the file /callrec/composeEmailA= ction.do. Executing a manipulation can lead to improper authorization. The = attack can be executed remotely. The exploit has been publicly disclosed an=
d may be utilized. The vendor was contacted early about this disclosure but=
did not respond in any way.</td>
<td>2026-07-12</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15472" target=3D= "_blank" rel=3D"noopener">CVE-2026-15472</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A security flaw has been discovered in Eleveo Call Recording Software 9= .7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the=
component Call Recording Handler. The manipulation of the argument callId = results in improper authorization. The attack may be performed from remote.=
The exploit has been released to the public and may be used for attacks. T=
he vendor was contacted early about this disclosure but did not respond in = any way.</td>
<td>2026-07-12</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15474" target=3D= "_blank" rel=3D"noopener">CVE-2026-15474</a></td>
</tr>
<td class=3D"vendor-product">enquirer--enquirer</td>
<td>A security flaw has been discovered in enquirer up to 2.4.1. Affected i=
s the function Enquirer.set of the component Public Package API. The manipu= lation of the argument question.name results in improperly controlled modif= ication of object prototype attributes. The attack can be launched remotely=
. The exploit has been released to the public and may be used for attacks. = The project was informed of the problem early through an issue report.</td> <td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15187" target=3D= "_blank" rel=3D"noopener">CVE-2026-15187</a></td>
</tr>
<td class=3D"vendor-product">etcd-io--etcd</td>
<td>etcd is a distributed key-value store for the data of a distributed sys= tem. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-clie= nt-http-urls to split HTTP and gRPC client endpoints onto separate listener=
s, the --client-crl-file Certificate Revocation List is not enforced on the=
gRPC listener, allowing a client with a revoked certificate to authenticat=
e successfully over gRPC. This issue is fixed in versions 3.5.32 and 3.6.13= .</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59818" target=3D= "_blank" rel=3D"noopener">CVE-2026-59818</a></td>
</tr>
<td class=3D"vendor-product">fahadmahmood--Easy Upload Files During Checkou= t</td>
<td>The Easy Upload Files During Checkout plugin for WordPress is vulnerabl=
e to unauthorized access in all versions up to, and including, 3.0.1. This =
is due to missing authorization checks in the ufdc_custom_init() function, = which processes the 'eufdc-delete' parameter without any nonce verification=
, capability check, or attachment ownership validation. This makes it possi= ble for unauthenticated attackers to permanently delete arbitrary media lib= rary attachments from the WordPress site.</td>
<td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6802" target=3D"= _blank" rel=3D"noopener">CVE-2026-6802</a></td>
</tr>
<td class=3D"vendor-product">filebrowser--filebrowser</td>
<td>File Browser provides a web file managing interface. Prior to 2.63.16, = ScopedFs validates the nearest existing ancestor of a dangling symlink as i=
n scope and then follows the symlink during file creation, allowing an auth= enticated user with Create and Modify permissions to create attacker-contro= lled files outside the user's scope. This issue is fixed in version 2.63.16= .</td>
<td>2026-07-08</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55668" target=3D= "_blank" rel=3D"noopener">CVE-2026-55668</a></td>
</tr>
<td class=3D"vendor-product">flask-dashboard--Flask-MonitoringDashboard</td=
<td>A vulnerability has been found in flask-dashboard Flask-MonitoringDashb= oard up to 5.0.2. Affected by this issue is some unknown functionality. Suc=
h manipulation leads to cross-site request forgery. The attack may be launc= hed remotely. The exploit has been disclosed to the public and may be used.=
The project was informed of the problem early through an issue report but = has not responded yet.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15034" target=3D= "_blank" rel=3D"noopener">CVE-2026-15034</a></td>
</tr>
<td class=3D"vendor-product">Flowise--Flowise</td>
<td>Flowise before 3.1.0 contains a path traversal vulnerability in Faiss a=
nd SimpleStore vector store implementations that accept unsanitized basePat=
h parameters from authenticated users. Attackers with valid API tokens can = write vector store data to arbitrary filesystem locations, potentially enab= ling code execution or data exfiltration.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56273" target=3D= "_blank" rel=3D"noopener">CVE-2026-56273</a></td>
</tr>
<td class=3D"vendor-product">Formbricks--Formbricks</td>
<td>A security vulnerability has been detected in Formbricks 5.0.0. This im= pacts an unknown function of the file apps/web/modules/survey/link/actions.=
ts of the component Survey Handler. The manipulation leads to improper acce=
ss controls. Remote exploitation of the attack is possible. Upgrading to ve= rsion 5.1.0-rc.1 will fix this issue. The identifier of the patch is af6023= b5ac3b030ffcea24fac799f76f3e3512c6. You should upgrade the affected compone= nt.</td>
<td>2026-07-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14792" target=3D= "_blank" rel=3D"noopener">CVE-2026-14792</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The application opens the PDF, and JavaScript performs operations on th=
e page and the document, causing the page-related objects within the applic= ation to lose synchronization; however, the renderer still trusts the outda= ted page count, and eventually the application crashes due to out-of-bounds=
access.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57241" target=3D= "_blank" rel=3D"noopener">CVE-2026-57241</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>During the process of page opening and form formatting, a JavaScript re= entrancy results in an inconsistent document status. Subsequently, with out= dated page information, the application attempts to access invalid addresse=
s, causing the application to crash.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57243" target=3D= "_blank" rel=3D"noopener">CVE-2026-57243</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>An abnormal image object causes the renderer to enter the wrong process= ing branch. When converting the scan lines, an invalid image buffer pointer=
is used, resulting in the application crashing.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57253" target=3D= "_blank" rel=3D"noopener">CVE-2026-57253</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The application opens a PDF containing an abnormal color space whose at= tributes reference a valid but semantically malformed function. The functio= n's output is not validated; when subsequently read, it produces an illegal=
pointer that accesses an out-of-bounds region, crashing the application.</=
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57255" target=3D= "_blank" rel=3D"noopener">CVE-2026-57255</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td> <td>During the PRC parsing stage, there is a lack of boundary verification = for the PRC entity index, which leads to an out-of-bounds read of the entit=
y array. As a result, the application crashes.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57257" target=3D= "_blank" rel=3D"noopener">CVE-2026-57257</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The PRC file header parsing logic trusts the constructed file structure=
description information, assumes that the underlying array contains elemen=
ts and reads them, leading to out-of-bounds reads and application crashes.<=
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57258" target=3D= "_blank" rel=3D"noopener">CVE-2026-57258</a></td>
</tr>
<td class=3D"vendor-product">Foxit Software Inc.--Foxit PDF Editor</td>
<td>The input file does not need to be strictly in a structurally valid PDF=
format. Instead, after reviewing the content, the original document disgui= sed as a PDF will be sent to the parser. Malicious documents will construct=
malicious external entities that, through the protocol, point to local pat= hs, thereby allowing access to any local files within the user's permission=
range.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57259" target=3D= "_blank" rel=3D"noopener">CVE-2026-57259</a></td>
</tr>
<td class=3D"vendor-product">FreeRDP--FreeRDP</td>
<td>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior =
to 3.28.0, FreeRDP server implementations with the MS-RDPECAM camera device=
enumerator channel enabled scan attacker-supplied DeviceName and VirtualCh= annelName fields for a NUL terminator in channels/rdpecam/server/camera_dev= ice_enumerator_main.c and then dereference once past the scan bound, allowi=
ng a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read=
. This issue is fixed in version 3.28.0.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57157" target=3D= "_blank" rel=3D"noopener">CVE-2026-57157</a></td>
</tr>
<td class=3D"vendor-product">freshlabs--fresh Podcaster</td>
<td>The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-= Site Scripting via the 'freshpodcaster' shortcode in all versions up to, an=
d including, 1.0.7 due to insufficient input sanitization and output escapi=
ng on user supplied attributes. This makes it possible for authenticated at= tackers, with contributor-level access and above, to inject arbitrary web s= cripts in pages that will execute whenever a user accesses an injected page= .</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1382" target=3D"= _blank" rel=3D"noopener">CVE-2026-1382</a></td>
</tr>
<td class=3D"vendor-product">Gallagher--Command Centre Server</td> <td>An=C2=A0Incorrect Privilege Assignment (CWE-266)=C2=A0vulnerability in= =C2=A0the Command Centre Server=C2=A0allows an=C2=A0authenticated operator = with limited privileges=C2=A0to perform some operations that they would not=
normally be authorized to perform.=C2=A0Version of Command Centre affected= :=C2=A09.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.=
30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all version=
s of 9.10.</td>
<td>2026-07-07</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-26053" target=3D= "_blank" rel=3D"noopener">CVE-2026-26053</a></td>
</tr>
<td class=3D"vendor-product">gallerycreator--SimpLy Gallery</td>
<td>The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnera= ble to Stored Cross-Site Scripting via block attributes in all versions up = to, and including, 3.3.3.2. This is due to insufficient input sanitization = and output escaping on the sliderMaxHeight block attribute in the pgc_sgb_r= ender_callback() function. The vulnerability exists because the pgc_sgb_san= itize_custom_css() function uses a flawed regex pattern that only removes e= vent handlers with quoted values (e.g., onfocus=3D"alert()") but fails to c= atch unquoted event handlers (e.g., onfocus=3Dalert(document.cookie)), allo= wing the malicious code to bypass sanitization. This makes it possible for = authenticated attackers, with Author-level access and above, to inject arbi= trary web scripts in pages via block attributes that will execute whenever =
a user accesses an injected page.</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5743" target=3D"= _blank" rel=3D"noopener">CVE-2026-5743</a></td>
</tr>
<td class=3D"vendor-product">gamaup--Blocks for ACF Fields Display Custom F= ields in the Block Editor</td>
<td>The Blocks for ACF Fields plugin for WordPress is vulnerable to unautho= rized access of data due to a missing capability check on the get_all_value= s() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in ve= rsions up to, and including, 1.6.2. The permission_callback only verifies t=
he generic publish_posts capability and the handler passes a user-supplied =
id parameter directly to get_field_objects() without verifying that the req= uesting user is authorized to read the target object. This makes it possibl=
e for authenticated attackers, with Author-level access and above, to read = ACF field values from arbitrary posts (including private posts, drafts, pos=
ts by other users, and other ACF-supported objects) that they should not ha=
ve access to.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12428" target=3D= "_blank" rel=3D"noopener">CVE-2026-12428</a></td>
</tr>
<td class=3D"vendor-product">gchq--CyberChef</td>
<td>CyberChef is a web app for encryption, encoding, compression, and data = analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as =
a key while parsing user-supplied CSV, allowing prototype pollution that ca=
n be chained with operations such as Parse UDP to inject malicious JavaScri=
pt into HTML output. This issue is fixed in version 11.2.0.</td> <td>2026-07-08</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57439" target=3D= "_blank" rel=3D"noopener">CVE-2026-57439</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav is a file-based Web platform. Prior to 1.7.53, an authenticated ad= ministrator with backup permissions can download a ZIP archive containing t=
he full Grav installation root, including user/accounts/admin.yaml with the=
administrator password hash and user/config with site configuration, throu=
gh the backup download endpoint protected only by the session-static admin-= nonce URL parameter. This issue is reported as fixed in version 1.7.53.</td=
<td>2026-07-10</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55885" target=3D= "_blank" rel=3D"noopener">CVE-2026-55885</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav before 2.0.2 contains a Twig sandbox bypass that allows a page aut= hor (any admin.pages user, or anyone able to write to user/pages) to exfilt= rate configuration secrets. Although the sandbox replaces the 'config' vari= able with a redacted facade and strips Config::get/toArray from the method = allowlist, the raw container remains accessible via the allow-listed grav.o= ffsetGet('config'), which returns the real Config object. Allow-listed obje= ct-dumping filters (json_encode, print_r, yaml_encode) then serialize that = object at the PHP level without invoking the sandbox method gate, exposing = the full config tree including plugin secrets such as SMTP credentials, API=
keys, and plugin DB credentials. This is an incomplete fix for GHSA-j274-3= 9qw-32c9.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61450" target=3D= "_blank" rel=3D"noopener">CVE-2026-61450</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArc= hiver::extract() that lacks limits on uncompressed size, file count, and ne= sting depth. Attackers can supply a crafted ZIP archive that expands to fil=
l available disk space, causing denial of service by exhausting storage res= ources.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61455" target=3D= "_blank" rel=3D"noopener">CVE-2026-61455</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds=
a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA boot= strap page at /grav/admin (and its subroutes). This object is returned in e= very unauthenticated response and discloses the server URL, API prefix, adm=
in base path, runtime environment type, and exact Grav and Admin2 version n= umbers, allowing an unauthenticated attacker to fingerprint the deployment = and select version-specific exploits without reconnaissance.</td> <td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61454" target=3D= "_blank" rel=3D"noopener">CVE-2026-61454</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomple=
te fix for stored XSS through the Markdown media attribute action (CVE-2026= -42841) leaves the sibling MediaObjectTrait::style method reachable through=
the same Markdown excerpt-action pipeline, allowing an editor to save Mark= down image style parameters that are written into the rendered img style at= tribute without sanitization. This issue is fixed in version 2.0.0-rc.9.</t=
<td>2026-07-10</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55890" target=3D= "_blank" rel=3D"noopener">CVE-2026-55890</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to san= itize SVG files uploaded through the POST /api/v1/media endpoint. The Handl= esMediaUploads::processUploadedFile() method validates only the file extens= ion and never invokes Security::sanitizeSVG(), so an authenticated attacker=
with the api.media.write permission can upload an SVG containing arbitrary=
JavaScript. The file is stored unmodified and served with Content-Type: im= age/svg+xml; when an administrator opens it in a browser (directly or via &= lt;object>/<iframe>), the embedded script executes in their sessio=
n context, enabling cookie theft and session hijacking.</td> <td>2026-07-10</td>
<td>4.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61456" target=3D= "_blank" rel=3D"noopener">CVE-2026-61456</a></td>
</tr>
<td class=3D"vendor-product">getwpfunnels--Mail Mint Email Marketing, Newsl= etter, Email Automation & WooCommerce Emails</td>
<td>The Mail Mint - Email Marketing, Newsletter, Email Automation & Woo= Commerce Emails plugin for WordPress is vulnerable to generic SQL Injection=
via the 'recipients' parameter in all versions up to, and including, 1.24.=
1 due to insufficient escaping on the user supplied parameter and lack of s= ufficient preparation on the existing SQL query. This makes it possible for=
authenticated attackers, with administrator-level access and above, to app= end additional SQL queries into already existing queries that can be used t=
o extract sensitive information from the database. This is a second-order S=
QL injection: the malicious payload is first stored unsanitized via a POST = request to /mrm/v1/campaigns/ (bypassing filter_recipients() validation bec= ause an int-cast of a string like '1) OR ...' evaluates to a real numeric I= D), and is then triggered by a subsequent GET request to /mrm/v1/campaigns/= {id} that deserializes the recipients and passes the raw id string through = array_column() into the vulnerable query.</td>
<td>2026-07-10</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12918" target=3D= "_blank" rel=3D"noopener">CVE-2026-12918</a></td>
</tr>
<td class=3D"vendor-product">getwpfunnels--Mail Mint Email Marketing, Newsl= etter, Email Automation & WooCommerce Emails</td>
<td>The Mail Mint - Email Marketing, Newsletter, Email Automation & Woo= Commerce Emails plugin for WordPress is vulnerable to time-based SQL Inject= ion via the 'contact_ids' parameter in all versions up to, and including, 1= .24.2 due to insufficient escaping on the user supplied parameter and lack =
of sufficient preparation on the existing SQL query. This makes it possible=
for authenticated attackers, with administrator-level access and above, to=
append additional SQL queries into already existing queries that can be us=
ed to extract sensitive information from the database.</td>
<td>2026-07-09</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14342" target=3D= "_blank" rel=3D"noopener">CVE-2026-14342</a></td>
</tr>
<td class=3D"vendor-product">getwpfunnels--WPFunnels Funnel Builder for Woo= Commerce with Checkout & One Click Upsell</td>
<td>The WPFunnels - Funnel Builder for WooCommerce with Checkout & One = Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in = all versions up to, and including, 3.12.7 via the 'logKey' parameter parame= ter. This makes it possible for authenticated attackers, with administrator= -level access and above, to include and execute arbitrary .php files on the=
server, allowing the execution of any PHP code in those files. This can be=
used to bypass access controls, obtain sensitive data, or achieve code exe= cution in cases where .php file types can be uploaded and included.</td> <td>2026-07-09</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13080" target=3D= "_blank" rel=3D"noopener">CVE-2026-13080</a></td>
</tr>
<td class=3D"vendor-product">Ghostfolio--Ghostfolio</td>
<td>Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags end= point fails to verify Access.permissions field when processing the Imperson= ation-Id header, allowing read-only access grantees to modify portfolio hol= ding tags. Attackers with valid read-only share tokens can assign or remove=
tags on victim holdings, corrupting portfolio categorization and reports.<=
<td>2026-07-07</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59709" target=3D= "_blank" rel=3D"noopener">CVE-2026-59709</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab EE affecting all versions from=
9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under = certain conditions could have allowed an authenticated user with maintainer= -role permissions to obtain another user's stored credentials due to improp=
er authorization controls.</td>
<td>2026-07-08</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11827" target=3D= "_blank" rel=3D"noopener">CVE-2026-11827</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that und=
er certain conditions could have allowed an unauthenticated user to determi=
ne the existence of a private project due to improper authorization control=
s on cross-project reference pages.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7492" target=3D"= _blank" rel=3D"noopener">CVE-2026-7492</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab EE affecting all versions from=
18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under=
certain conditions could have allowed an authenticated user with minimal a= ccess permissions to read work item metadata from private projects due to m= issing authorization checks.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8472" target=3D"= _blank" rel=3D"noopener">CVE-2026-8472</a></td>
</tr>
<td class=3D"vendor-product">GNU--LibreDWG</td>
<td>A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affect=
ed element is the function dwg_bmp of the file src/dwg.c of the component B=
MP Image Handler. Such manipulation leads to heap-based buffer overflow. Th=
e attack must be carried out locally. The exploit has been disclosed to the=
public and may be used. Upgrading to version 0.14 is sufficient to fix thi=
s issue. The name of the patch is 18fd542bb4d5ccedf9de12052bf50068b2b26f06.=
It is suggested to upgrade the affected component.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15182" target=3D= "_blank" rel=3D"noopener">CVE-2026-15182</a></td>
</tr>
<td class=3D"vendor-product">gnuwget--wget</td>
<td>GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer o= verflow vulnerability in the parse_content_range() function within src/http=
.c that allows server-controlled values to cause signed integer arithmetic =
to overflow. Attackers can supply malicious Content-Range header values to = trigger undefined behavior and download desynchronization in the affected c= lient.</td>
<td>2026-07-07</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58470" target=3D= "_blank" rel=3D"noopener">CVE-2026-58470</a></td>
</tr>
<td class=3D"vendor-product">gnuwget--wget</td>
<td>GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffe=
r overflow vulnerability in the convert_fname() function within src/url.c t= hat allows remote attackers to trigger memory corruption through a server-s= upplied filename requiring character set conversion. When the output buffer=
is too small during iconv E2BIG reallocation, the reallocation logic misca= lculates the remaining space, leading to a heap buffer overflow that can be=
exploited via a maliciously crafted server response.</td>
<td>2026-07-07</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58471" target=3D= "_blank" rel=3D"noopener">CVE-2026-58471</a></td>
</tr>
<td class=3D"vendor-product">gnuwget--wget</td>
<td>GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffe=
r overflow vulnerability in the html_quote_string() function in src/convert=
.c that allows a remote attacker to trigger memory corruption by supplying =
a crafted HTML attribute with a large number of characters requiring entity=
encoding. A server-supplied HTML attribute causes a signed integer counter=
to overflow during output size accumulation, resulting in an undersized he=
ap allocation and subsequent heap buffer overflow during the copy phase.</t=
<td>2026-07-07</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58472" target=3D= "_blank" rel=3D"noopener">CVE-2026-58472</a></td>
</tr>
<td class=3D"vendor-product">gofiber--fiber</td>
<td>Fiber is an Express inspired web framework written in Go. Prior to 3.3.=
0, the default Authorizer function in the BasicAuth middleware in middlewar= e/basicauth/config.go uses short-circuit evaluation that skips password has=
h comparison for non-existent usernames, enabling reliable remote username = enumeration through response timing differences. This issue is fixed in ver= sion 3.3.0.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44332" target=3D= "_blank" rel=3D"noopener">CVE-2026-44332</a></td>
</tr>
<td class=3D"vendor-product">gofiber--fiber</td>
<td>Fiber is an Express inspired web framework written in Go. Prior to 3.3.=
0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.g=
o uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allow= ing an attacker-supplied first X-Real-IP value to be forwarded to upstream = servers for logging, rate limiting, and access control. This issue is fixed=
in version 3.3.0 and 2.52.14.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45045" target=3D= "_blank" rel=3D"noopener">CVE-2026-45045</a></td>
</tr>
<td class=3D"vendor-product">gofiber--fiber</td>
<td>Fiber is an Express inspired web framework written in Go. Prior to 3.4.=
0, the helmet middleware in middleware/helmet/helmet.go never sets the Stri= ct-Transport-Security response header even when HSTSMaxAge is configured be= cause it checks c.Protocol() for https instead of c.Scheme(). This issue is=
fixed in version 3.4.0.</td>
<td>2026-07-08</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53624" target=3D= "_blank" rel=3D"noopener">CVE-2026-53624</a></td>
</tr>
<td class=3D"vendor-product">Grafana--Grafana OSS</td>
<td>A user with Editor permissions can craft a dashboard whose table (Table= NG) panel contains a malicious field name that executes as a script in the = browser of any user who views the dashboard (stored cross-site scripting).<=
<td>2026-07-10</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8595" target=3D"= _blank" rel=3D"noopener">CVE-2026-8595</a></td>
</tr>
<td class=3D"vendor-product">Grafana--Grafana OSS</td>
<td>An unauthenticated attacker can repeatedly call Grafana's OAuth login r= oute with unique values, causing unbounded memory growth that can eventuall=
y exhaust memory and crash the Grafana instance (denial of service).</td> <td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8609" target=3D"= _blank" rel=3D"noopener">CVE-2026-8609</a></td>
</tr>
<td class=3D"vendor-product">Grav--Grav</td>
<td>The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestr= icted file upload vulnerability in the avatar upload endpoint (/api/v1/user= s/user/avatar). The endpoint validates only the client-declared MIME type (= getClientMediaType) beginning with 'image/' and does not inspect the actual=
file content or restrict the resulting extension, allowing an authenticate=
d user to store arbitrary content - including PHP code, SVG with embedded J= avaScript, and polyglot payloads - under user/accounts/avatars/ with predic= table filenames. Direct HTTP access to the stored files is blocked by .htac= cess (returns 403), but the files persist on disk and could lead to remote = code execution or stored XSS in the presence of a path traversal flaw or se= rver misconfiguration. Fixed in 1.0.1.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58654" target=3D= "_blank" rel=3D"noopener">CVE-2026-58654</a></td>
</tr>
<td class=3D"vendor-product">Grav--Grav</td>
<td>Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) cont= ains a stored CSS injection vulnerability in the Markdown image resize() me= dia action. Prior media hardening rejects direct ?style=3D payloads and uns= afe attribute() fallbacks, but the resize() action in Excerpts::processMedi= aActions() writes caller-controlled values directly into the image's styleA= ttributes. A lower-privileged content editor who can edit page Markdown can=
store a crafted image URL with semicolon-delimited CSS declarations in the=
resize parameters, which are rendered into the final <img style=3D...&g=
t; attribute when a higher-privileged reviewer/admin views the page or prev= iew. This does not require JavaScript execution but enables UI redress/over= lay and content-manipulation attacks (e.g., a full-viewport fixed overlay).=
Fixed in 2.0.0.</td>
<td>2026-07-08</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58657" target=3D= "_blank" rel=3D"noopener">CVE-2026-58657</a></td>
</tr>
<td class=3D"vendor-product">gristlabs--grist-core</td>
<td>Grist is spreadsheet software using Python as its formula language. Pri=
or to 1.7.15, the GET /forms endpoint read table and column metadata withou=
t applying the document's access rules and did not check that the requested=
section was actually a form. A user with only partial read access, includi=
ng public access on a publicly viewable document, could request the metadat=
a of any widget and reveal table and column structure that access rules wou=
ld otherwise hide, even in documents that contain no forms. This issue is f= ixed in version 1.7.15.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55664" target=3D= "_blank" rel=3D"noopener">CVE-2026-55664</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the = user edit flow stores url()->previous() from the attacker-controlled Ref= erer header into Laravel's intended URL session value and later uses redire= ct()->intended(...) when redirect_option=3Dback is submitted, allowing S= nipe-IT to be used as a trusted redirector after a legitimate user edit act= ion. This issue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55461" target=3D= "_blank" rel=3D"noopener">CVE-2026-55461</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an a= uthenticated user with import and assets.update permissions can place a pat=
h traversal string in an asset image field through CSV import and then trig= ger image deletion, allowing deletion of arbitrary files accessible to the = server process. This issue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55469" target=3D= "_blank" rel=3D"noopener">CVE-2026-55469</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the = Importer API endpoint allows a user with CSV import capabilities and a vali=
d API key to overwrite the created_by value of an import file, allowing una= uthorized modification of import ownership metadata. This issue is fixed in=
version 8.6.1.</td>
<td>2026-07-10</td>
<td>5.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55475" target=3D= "_blank" rel=3D"noopener">CVE-2026-55475</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the = unaccepted-assets report delete endpoint authorizes only reports.view and d= eletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID w= ithout checking access to the related checkoutable asset, allowing a report=
s user in one company to delete pending checkout acceptance records for ano= ther company. This issue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55515" target=3D= "_blank" rel=3D"noopener">CVE-2026-55515</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, User= sController::show() and printInventory() authorize only user viewing before=
loading and rendering assigned license, accessory, and consumable relation= ships, allowing an authenticated user with only users.view to see inventory=
and cost/order metadata from modules that direct permissions would otherwi=
se deny. This issue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55462" target=3D= "_blank" rel=3D"noopener">CVE-2026-55462</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when=
Full Multiple Companies Support and scope_locations_fmcs are enabled, the = API location creation endpoint detects an invalid parent-child company mism= atch but does not return immediately, allowing creation of a child location=
under a parent location from a different company. This issue is fixed in v= ersion 8.6.2.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55472" target=3D= "_blank" rel=3D"noopener">CVE-2026-55472</a></td>
</tr>
<td class=3D"vendor-product">gunthercox--ChatterBot</td>
<td>ChatterBot is a machine learning, conversational dialog engine for crea= ting chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predi= ctable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a c= heck-then-create pattern followed by tar.extractall(path=3Dself.data_path),=
allowing a local attacker who pre-plants a symlink at the predictable path=
to cause archive contents to be written through the symlink to an attacker= -chosen directory. This issue is fixed in version 1.2.14.</td> <td>2026-07-09</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58198" target=3D= "_blank" rel=3D"noopener">CVE-2026-58198</a></td>
</tr>
<td class=3D"vendor-product">guzzle--guzzle</td>
<td>Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did=
not restrict cookies scoped to IP-address or bare-numeric Domain values to=
the exact host that set them, because SetCookie::matchesDomain() applied o= rdinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowi=
ng cross-host cookie disclosure, cookie injection, or session fixation. Thi=
s issue is fixed in version 7.12.3.</td>
<td>2026-07-08</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59883" target=3D= "_blank" rel=3D"noopener">CVE-2026-59883</a></td>
</tr>
<td class=3D"vendor-product">guzzle--psr7</td>
<td>guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. = Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components=
containing authority delimiters, embedded ports, or malformed IPv6 bracket=
s, allowing Uri::getHost() to disagree with the URI authority used for secu= rity or routing decisions. This issue is fixed in version 2.12.3.</td> <td>2026-07-08</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59882" target=3D= "_blank" rel=3D"noopener">CVE-2026-59882</a></td>
</tr>
<td class=3D"vendor-product">happyforms--Happyforms Form Builder for WordPr= ess: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Fo= rms</td>
<td>The Happyforms - Form Builder for WordPress: Drag & Drop Contact Fo= rms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vul= nerable to Local File Inclusion in all versions up to, and including, 1.26.=
12 via the happyforms_get_form_partial() function. This makes it possible f=
or authenticated attackers, with Administrator-level access and above, to i= nclude and execute arbitrary .php files on the server, allowing the executi=
on of any PHP code in those files. This can be used to bypass access contro= ls, obtain sensitive data, or achieve code execution in cases where .php fi=
le types can be uploaded and included.</td>
<td>2026-07-10</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-11977" target=3D= "_blank" rel=3D"noopener">CVE-2025-11977</a></td>
</tr>
<td class=3D"vendor-product">Harness--Harness</td>
<td>A vulnerability was determined in Harness up to 2.28.2. This vulnerabil= ity affects the function getAuthorizedSpaces of the file app/api/controller= /gitspace/list_all.go of the component gitspaces Endpoint. Executing a mani= pulation can lead to authorization bypass. The attack can be executed remot= ely. The exploit has been publicly disclosed and may be utilized. The proje=
ct was informed of the problem early through an issue report but has not re= sponded yet.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15036" target=3D= "_blank" rel=3D"noopener">CVE-2026-15036</a></td>
</tr>
<td class=3D"vendor-product">HashiCorp--Nomad</td>
<td>HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespac=
e authorization bypass in the dynamic host volumes feature that may allow a=
n operator holding the host volume delete permission in one namespace to de= lete a sticky volume claim belonging to a job in another namespace. This vu= lnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and = Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.</td>
<td>2026-07-08</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14896" target=3D= "_blank" rel=3D"noopener">CVE-2026-14896</a></td>
</tr>
<td class=3D"vendor-product">HashiCorp--Shared library</td>
<td>HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-= service issue in its push/pull state handling that may allow an attacker wi=
th network access to the gossip port to exhaust memory on a receiving node = and cause the process to terminate. This vulnerability (CVE-2026-14362) is = fixed in memberlist 0.6.0.</td>
<td>2026-07-08</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14362" target=3D= "_blank" rel=3D"noopener">CVE-2026-14362</a></td>
</tr>
<td class=3D"vendor-product">HashiCorp--Tooling</td>
<td>The consul-template library before version 0.42.1 is vulnerable to a pa=
th redirection issue in the writeToFile template helper that may allow temp= late output to be written outside the intended directory or to overwrite an=
existing file. This vulnerability (CVE-2026-14361) is fixed in consul-temp= late 0.42.1.</td>
<td>2026-07-08</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14361" target=3D= "_blank" rel=3D"noopener">CVE-2026-14361</a></td>
</tr>
<td class=3D"vendor-product">HCLSoftware--HCL DevOps Deploy</td>
<td>HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could=
allow an attacker to carry out privileged actions and retrieve sensitive i= nformation as the domain name is not being limited to only trusted domains.= </td>
<td>2026-07-09</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56458" target=3D= "_blank" rel=3D"noopener">CVE-2026-56458</a></td>
</tr>
<td class=3D"vendor-product">HCLSoftware--HCL DevOps Deploy / HCL Launch</t=
<td>HCL DevOps Deploy / HCL Launch is susceptible to sensitive information = disclosure. =C2=A0The application stores potentially sensitive information =
in log files that could be read by a local user.</td>
<td>2026-07-09</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56459" target=3D= "_blank" rel=3D"noopener">CVE-2026-56459</a></td>
</tr>
<td class=3D"vendor-product">HCLSoftware--HCL DevOps Deploy / HCL Launch</t=
<td>HCL DevOps Deploy / HCL Launch could disclose sensitive configurations = and secrets to authenticated users in API responses that could be used in f= urther attacks against the system.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56460" target=3D= "_blank" rel=3D"noopener">CVE-2026-56460</a></td>
</tr>
<td class=3D"vendor-product">Helicone--ai-gateway</td>
<td>A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This = affects the function build_target_url of the file ai-gateway/src/dispatcher= /service.rs of the component AWS Metadata Service. Executing a manipulation=
of the argument extracted_path_and_query can lead to server-side request f= orgery. The attack can be executed remotely. The exploit has been published=
and may be used. The vendor was contacted early about this disclosure but = did not respond in any way.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15508" target=3D= "_blank" rel=3D"noopener">CVE-2026-15508</a></td>
</tr>
<td class=3D"vendor-product">hestiacp--hestiacp</td>
<td>HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerabil= ity that allows authenticated low-privilege users to inject arbitrary HTML =
by creating a DNS record with a double-quote followed by a script payload i=
n the value field. The application fails to apply htmlspecialchars() encodi=
ng to the DNS record value field rendered into the data-sort-value HTML att= ribute in list_dns_rec.php, allowing the payload to execute in the browser =
of any user who views the DNS record list, including administrators.</td> <td>2026-07-10</td>
<td>4.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-30008" target=3D= "_blank" rel=3D"noopener">CVE-2025-30008</a></td>
</tr>
<td class=3D"vendor-product">Hewlett Packard Enterprise (HPE)--HPE Networki=
ng Instant On</td>
<td>An unauthenticated remote disclosure vulnerability has been identified =
in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful expl= oitation of this vulnerability could allow an unauthenticated remote threat=
actor to access sensitive cryptographic secrets on a vulnerable system.</t=
<td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44877" target=3D= "_blank" rel=3D"noopener">CVE-2026-44877</a></td>
</tr>
<td class=3D"vendor-product">Hono--Hono</td>
<td>Hono before 4.12.7 allows __proto__ key in parseBody with dot option en= abled, permitting specially crafted form field names to create objects with=
__proto__ properties. When parsed results are merged into regular JavaScri=
pt objects using unsafe merge patterns, attackers can exploit this to achie=
ve prototype pollution and modify object behavior.</td>
<td>2026-07-11</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56763" target=3D= "_blank" rel=3D"noopener">CVE-2026-56763</a></td>
</tr>
<td class=3D"vendor-product">honojs--hono</td>
<td>Hono is a Web application framework that provides support for any JavaS= cript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class n= ames from plain strings but marks the result as already escaped without HTM= L-escaping the input, allowing untrusted className values used in a JSX cla=
ss attribute during server-side rendering to break out of the attribute and=
inject arbitrary markup. This issue is fixed in version 4.12.27.</td> <td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59895" target=3D= "_blank" rel=3D"noopener">CVE-2026-59895</a></td>
</tr>
<td class=3D"vendor-product">honojs--hono</td>
<td>Hono is a Web application framework that provides support for any JavaS= cript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context=
values per request during server-side rendering, allowing createContext, u= seContext, jsxRenderer, or useRequestContext data from a different in-fligh=
t request to be used after an await in an async component. This issue is fi= xed in version 4.12.27.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59896" target=3D= "_blank" rel=3D"noopener">CVE-2026-59896</a></td>
</tr>
<td class=3D"vendor-product">honojs--hono</td>
<td>Hono is a Web application framework that provides support for any JavaS= cript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter ca=
n drop a distinct repeated request header value because it de-duplicates va= lues using a substring comparison instead of an exact match, so middleware =
or application logic that depends on the complete X-Forwarded-For chain, ra=
te limiting, audit logging, or proxy-chain validation can receive incomplet=
e data. This issue is fixed in version 4.12.27.</td>
<td>2026-07-08</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59897" target=3D= "_blank" rel=3D"noopener">CVE-2026-59897</a></td>
</tr>
<td class=3D"vendor-product">IceHRM--IceHRM</td>
<td>A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown f= unction of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.= php of the component UserReport Endpoint. Executing a manipulation of the a= rgument employeeList can lead to sql injection. The attack can be launched = remotely. The exploit has been published and may be used. The project was i= nformed of the problem early through an issue report but has not responded = yet.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15478" target=3D= "_blank" rel=3D"noopener">CVE-2026-15478</a></td>
</tr>
<td class=3D"vendor-product">idocoh--Sympl Repeater for ACF and Elementor</=
<td>The Sympl Repeater for ACF and Elementor plugin for WordPress is vulner= able to Stored Cross-Site Scripting via ACF repeater field values in all ve= rsions up to, and including, 2.3. This is due to insufficient input sanitiz= ation and output escaping in the symp_arfe_replace_content() function, whic=
h uses str_replace() to substitute raw ACF field values (retrieved via get_= field()) directly into Elementor-rendered HTML without any escaping. This m= akes it possible for authenticated attackers, with Author-level access and = above, to inject arbitrary web scripts in pages that will execute whenever =
a user accesses an injected page.</td>
<td>2026-07-08</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10570" target=3D= "_blank" rel=3D"noopener">CVE-2026-10570</a></td>
</tr>
<td class=3D"vendor-product">igweze--wizgrade</td>
<td>A security vulnerability has been detected in igweze wizgrade up to b1d= 55f22b90cd7e7a6e5002f006d7c649e8086d6. This vulnerability affects unknown c= ode of the file dashboard/studentConductManager.php. Such manipulation lead=
s to cross site scripting. The attack may be performed from remote. The exp= loit has been disclosed publicly and may be used. This product utilizes a r= olling release system for continuous delivery, and as such, version informa= tion for affected or updated releases is not disclosed. The vendor was cont= acted early about this disclosure but did not respond in any way.</td> <td>2026-07-12</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15492" target=3D= "_blank" rel=3D"noopener">CVE-2026-15492</a></td>
</tr>
<td class=3D"vendor-product">imhamzaazam--ecommerceFlask</td>
<td>A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d= 9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown fu= nction. This manipulation causes cross-site request forgery. The attack may=
be initiated remotely. The exploit has been made available to the public a=
nd could be used for attacks. This product uses a rolling release model to = deliver continuous updates. As a result, specific version information for a= ffected or updated releases is not available. The project was informed of t=
he problem early through an issue report but has not responded yet.</td> <td>2026-07-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14800" target=3D= "_blank" rel=3D"noopener">CVE-2026-14800</a></td>
</tr>
<td class=3D"vendor-product">Inrove Software and Internet Services--BiEtica= ret</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Inrove Software and Internet Services BiEtic= aret allows Reflected XSS. This issue affects BiEticaret: before v3.3.57.</=
<td>2026-07-09</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5793" target=3D"= _blank" rel=3D"noopener">CVE-2026-5793</a></td>
</tr>
<td class=3D"vendor-product">iqonicdesign--KiviCare Clinic & Patient Ma= nagement System (EHR)</td>
<td>The KiviCare - Clinic & Patient Management System (EHR) plugin for = WordPress is vulnerable to generic SQL Injection via the 'orderby' paramete=
r in all versions up to, and including, 4.5.0 due to insufficient escaping =
on the user supplied parameter and lack of sufficient preparation on the ex= isting SQL query. This makes it possible for authenticated attackers, with = doctor-level access and above, to append additional SQL queries into alread=
y existing queries that can be used to extract sensitive information from t=
he database. This requires that the attacker hold at minimum a KiviCare Doc= tor-level account, or a Receptionist or Clinic Admin role that grants the d= octor_session_list capability.</td>
<td>2026-07-11</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15072" target=3D= "_blank" rel=3D"noopener">CVE-2026-15072</a></td>
</tr>
<td class=3D"vendor-product">iqonicdesign--KiviCare Clinic & Patient Ma= nagement System (EHR)</td>
<td>The KiviCare - Clinic & Patient Management System (EHR) plugin for = WordPress is vulnerable to generic SQL Injection via the 'orderby' paramete=
r in all versions up to, and including, 4.5.0 due to insufficient escaping =
on the user supplied parameter and lack of sufficient preparation on the ex= isting SQL query. This makes it possible for authenticated attackers, with = Doctor-level access and above, to append additional SQL queries into alread=
y existing queries that can be used to extract sensitive information from t=
he database. Exploitation requires a KiviCare Doctor, Receptionist, or Clin=
ic Admin role at minimum, as the vulnerable REST endpoint is restricted to = authenticated users with custom plugin-level access.</td>
<td>2026-07-11</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15073" target=3D= "_blank" rel=3D"noopener">CVE-2026-15073</a></td>
</tr>
<td class=3D"vendor-product">iqonicdesign--KiviCare Clinic & Patient Ma= nagement System (EHR)</td>
<td>The KiviCare - Clinic & Patient Management System (EHR) plugin for = WordPress is vulnerable to authorization bypass in all versions up to, and = including, 4.4.0. This is due to the plugin not properly verifying that a u= ser is authorized to perform an action. This makes it possible for unauthen= ticated attackers to mark arbitrary pending appointments as Confirmed and f= orge an associated completed payment record in wp_kc_payments_appointment_m= appings using an attacker-supplied payment ID, bypassing payment entirely. = This exploit is achievable on a default installation because the gateway re= solution logic returns all registered gateways regardless of admin-enabled = status, making the manual (KCPayLater) gateway always selectable.</td> <td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11990" target=3D= "_blank" rel=3D"noopener">CVE-2026-11990</a></td>
</tr>
<td class=3D"vendor-product">isaacs--node-tar</td>
<td>node-tar is a tar archive manipulation library for Node.js. Prior to 7.= 5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts=
to JavaScript numbers, causing downstream path handling such as normalizeW= indowsPath(entry.path).split('/') to throw an uncaught TypeError. This issu=
e is fixed in version 7.5.18.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59871" target=3D= "_blank" rel=3D"noopener">CVE-2026-59871</a></td>
</tr>
<td class=3D"vendor-product">isaacs--node-tar</td>
<td>node-tar is a tar archive manipulation library for Node.js. Prior to 7.= 5.17, node-tar does not strip NUL bytes from PAX path and linkpath records =
in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or = fs.open and terminate the process with an uncaught exception. This issue is=
fixed in version 7.5.17.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59875" target=3D= "_blank" rel=3D"noopener">CVE-2026-59875</a></td>
</tr>
<td class=3D"vendor-product">iscpcolissimo--Colissimo shipping methods for = WooCommerce</td>
<td>The Colissimo Officiel : M=C3=83=C2=A9thodes de livraison pour WooComme= rce plugin for WordPress is vulnerable to unauthorized modification of data=
due to a missing capability check on the updateShippingMethod() function (= registered to the wp_ajax_lpc_order_affect AJAX action) in versions up to, = and including, 2.9.0. This is due to the handler performing no current_user= _can() capability check and no nonce verification before reading an attacke= r-supplied order_id and modifying that order's shipping method, pickup-poin=
t meta, and shipping address. This makes it possible for authenticated atta= ckers, with Subscriber-level access and above, to create or modify the ship= ment information (shipping method, pickup relay data, and shipping address)=
of arbitrary WooCommerce orders, including orders placed by other users.</=
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9240" target=3D"= _blank" rel=3D"noopener">CVE-2026-9240</a></td>
</tr>
<td class=3D"vendor-product">ivole--Customer Reviews for WooCommerce</td> <td>The Customer Reviews for WooCommerce plugin for WordPress is vulnerable=
to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all vers= ions up to, and including, 5.113.0 due to insufficient input sanitization a=
nd output escaping. This makes it possible for authenticated attackers, wit=
h contributor-level access and above, to inject arbitrary web scripts in pa= ges that will execute whenever a user accesses an injected page.</td> <td>2026-07-09</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13771" target=3D= "_blank" rel=3D"noopener">CVE-2026-13771</a></td>
</tr>
<td class=3D"vendor-product">jegtheme--Jeg Kit for Elementor Powerful Addon=
s for Elementor, Widgets & Templates for WordPress</td>
<td>The Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets &=
; Templates for WordPress plugin for WordPress is vulnerable to Stored Cros= s-Site Scripting via the Image Box widget's 'sg_body_description' parameter=
in versions up to, and including, 3.2.6. This is due to insufficient input=
sanitization and output escaping on the description attribute in the rende= r_body() method of the Image_Box_View class - every other attribute used by=
the method is wrapped in esc_attr(), but the description value is concaten= ated directly into HTML body context. This makes it possible for authentica= ted attackers, with Contributor-level access and above, to inject arbitrary=
web scripts in pages that will execute whenever a user accesses an injecte=
d page.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13710" target=3D= "_blank" rel=3D"noopener">CVE-2026-13710</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Unchecked Input for Loop Condition vulnerability in the Packet Forwa= rding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unau= thenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD=
session flaps generate respective up/down events which are queued by PFEMA=
N for processing. Especially in a Virtual-Chassis (VC) scenario with=C2=A0l= ocality-bias configured,=C2=A0processing takes a significant amount of time=
for each event.=C2=A0If these sessions keep flapping, new events are const= antly added, and in turn PFEMAN never completes processing these events. Th=
is results in the PFEMAN watchdog timer expiring, which causes the FPC to c= rash and restart, representing a complete service outage. This issue only a= ffects MX series FPCs up to and including MPC9. It does not affect MPC10/11=
, LC4800/9600 and MX304. This issue affects Junos OS on MX Series: * all ve= rsions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions = before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before = 25.2R2.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33800" target=3D= "_blank" rel=3D"noopener">CVE-2026-33800</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Check for Unusual or Exceptional Conditions vulnerability i=
n the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos =
OS Evolved allows an adjacent, unauthenticated attacker sending a specific = BGP update over an established BGP session to cause a Denial-of-Service (Do= S). Upon receipt of a specifically malformed non-inet/inet6 unicast BGP upd= ate, an RPD crash and restart is triggered, which will cause a complete ser= vice outage until routing has reconverged. The rpd crash occurs before the = update can be readvertised, so there is no downstream propagation. This iss=
ue affects: * Junos OS versions 25.2 before 25.2R2; * Junos OS Evolved vers= ions 25.2 before 25.2R2-EVO. This issue doesn't affect Junos OS versions be= fore 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.</td> <td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33801" target=3D= "_blank" rel=3D"noopener">CVE-2026-33801</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Validation of Specified Quantity in Input vulnerability in = the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Serie=
s allows an unauthenticated, adjacent attacker to cause a Denial-of-Service=
(DoS). When a specific packet is received from device in the same broadcas=
t domain, an affected system calculates the packet size incorrectly. This c= auses further packet processing to fail, which triggers an FPC major error,=
resulting in a FPC reset impacting traffic until the FPC has automatically=
recovered. Affected scenarios are: MAP-T, or non-IP traffic encapsulated i=
n IP (e.g. MPLS over GRE). When this issue happens the following logs can b=
e observed: fpc<#> CMError: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_= LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb), scope: pfe, category: functio= nal, severity: major, module: MQSS(0), type: LI: Unroll TAIL length overflo=
w, oc_category: default fpc<#> Performing action reset-fru for error = /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF = (0x2205eb) in module: MQSS(0) with scope: pfe category: functional level: m= ajor, oc_category: default This issue affects Junos OS on MX Series: * all = versions before 23.2R2-S6, * 23.4 versions before 23.4R2-S7, * 24.2 version=
s before 24.2R2-S4, * 24.4 versions before 24.4R2-S4, * 25.2 versions befor=
e 25.2R2.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57019" target=3D= "_blank" rel=3D"noopener">CVE-2026-57019</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Check for Unusual or Exceptional Conditions vulnerability i=
n the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX100=
00 Series allows an unauthenticated, adjacent attacker to cause a Denial-of= -Service (DoS). On all QFX10000 platforms in an EVPN-VxLAN scenario, if an = attacker sends IPv6 multicast traffic and these packets reach the non-IRB i= nterface of a spine switch it floods the packet to other spines and all Eth= ernet Segment Identifier (ESI)=C2=A0leaf switches. This flooding causes the=
packet to be forwarded in a endless loop, which can lead to saturation of = the involved links and in turn impact to legitimate traffic. This issue aff= ects Junos OS on QFX10000 Series: * all versions before 23.2R2-S7, * 23.4 v= ersions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions=
before 24.4R2-S4. This issue does not affect Junos version after 24.4 as t=
he QFX10000 Series devices are not supported on newer versions anymore.</td=
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57020" target=3D= "_blank" rel=3D"noopener">CVE-2026-57020</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>A Missing Release of Memory after Effective Lifetime vulnerability in t=
he packet forwarding engine (pfe) of Juniper Networks Junos OS on specific =
EX Series devices allows an unauthenticated adjacent attacker to cause a De= nial-of-Service (DoS).When sFlow is configured in a Virtual Chassis (VC) sc= enario with EX4100 Series or EX4400 Series devices, multicast traffic which=
is received on one VC member and sent out on another member leads to a mem= ory leak and ultimately an FPC crash and restart. The leak can be monitored=
by watching the continuous increase of the buffer values in the output of:=
user@host> show chassis fpc This issue affects Junos OS on=C2=A0EX4100 = Series and EX4400: * all versions before 23.2R2-S7, * 23.4 versions before = 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2.= </td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57027" target=3D= "_blank" rel=3D"noopener">CVE-2026-57027</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Handling of Undefined Parameters vulnerability in the packe=
t forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices=
allows an authenticated attacker with low privileges to cause a Denial-of-= Service (DoS). If an attempt is made to subscribe to an unsupported telemet=
ry sensor path on EX2300,=C2=A0EX3400,=C2=A0EX4000, EX4100 and EX4400 via g= RPC, this causes the FPC to crash. This leads to a complete service outage = until the module has automatically restarted.=C2=A0 The following log messa=
ge can be seen when this issue happens: agentd[<PID>]: AGENTD_RESOURC= E_NOT_FOUND: No resource name found for <sensor> This issue affects J= unos OS on EX2300, EX3400, EX4000, EX4100 and EX4400 devices: * all version=
s before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions befor=
e 24.2R2-S5, * 24.4 versions before 24.4R2.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57032" target=3D= "_blank" rel=3D"noopener">CVE-2026-57032</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>A Missing Authorization vulnerability in the CLI of Juniper Networks Ju= nos OS on EX Series allows a local, authenticated attacker to cause a Denia= l-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and=
EX4400 switches, an authenticated, local attacker with no specific permiss= ions or class can execute a specific, privileged CLI 'request' command whic=
h will cause complete traffic impact until the system automatically recover=
s. This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multig= igabit) and EX4400: * 23.2R2 versions before 23.2R2-S6, * 23.4 versions bef= ore 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.= 4R2-S3, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1.</t=
<td>2026-07-09</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33802" target=3D= "_blank" rel=3D"noopener">CVE-2026-33802</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) o=
f Juniper Networks Junos OS on SRX Series allows an unauthenticated, networ= k-based attacker to cause a Denial-of-Service (DoS). If an SRX Series devic=
e is configured for remote-access VPN with pre-logon compliance check, a ne= twork-based attacker sending specifically formatted requests can trigger an=
out of bounds write leading to an http-gk process crash. This crash leads =
to unavailability of all services depending on the [ system services web-ma= nagement ] configuration (like J-Web, remote access VPN and firewall authen= tication) until the process automatically restarts. This issue affects=C2= =A0Junos OS on SRX Series: * 23.2 versions before 23.2R2-S7, * 23.4 version=
s before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions befor=
e 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S=
1, 25.4R2.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57021" target=3D= "_blank" rel=3D"noopener">CVE-2026-57021</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Check for Unusual or Exceptional Conditions vulnerability i=
n the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX wit=
h SPC3 and SRX Series allows an unauthenticated, network-based attacker to = cause a Denial-of-Service (DoS). When an affected device initiates a TCP co= nnection to an attacker-controlled system that responds with a specific pac= ket, this causes a PFE crash and restart, which affects all services until = the system has automatically recovered. This issue can happen among others =
in the following scenarios: ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAM=
W, ICAP, URL filtering. This issue affects Junos OS on MX Series with SPC3,=
SRX5k Series with=C2=A0SPC3, SRX1600 Series, SRX2300 Series, SRX4000 Serie=
s, and vSRX Series: * all versions before 23.2R2-S4, * 23.4 versions before=
23.4R2-S5, * 24.2 versions before 24.2R2.</td>
<td>2026-07-09</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57022" target=3D= "_blank" rel=3D"noopener">CVE-2026-57022</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>A Use of Multiple Resources with Duplicate Identifier vulnerability in = the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX = Series allows an unauthenticated, network-based attacker to cause a Denial-= of-Service (DoS). On an MX with SPC3 and SRX devices configured for VPN ser= vice, when a large number of VPN negotiations fail=C2=A0a peer index rollov=
er will eventually occur. As a result, new peers are assigned index values = that are already in use and the iked process starts to crash repeatedly. Th=
is results in failure to establish new VPN connections and rekeying existin=
g ones. To restore service the system must be rebooted. Please note that th=
e index value can't be monitored, so customers should monitor tunnel up and=
down events and if a lot of events occur over an extended period of time i=
t becomes likely that this issue occurs. To be exposed to this issue the sy= stem needs to run iked (vs. kmd which is not affected), which can be verifi=
ed with: user@host> show system processes extensive | match "KMD|IKED" T= his issue affects Junos OS on MX with SPC3, SRX Series: * all versions befo=
re 23.2R2-S7, * 23.4 versions before 23.4R2-S6, * 24.2 versions before 24.2= R2-S3, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R1-S1.<=
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57024" target=3D= "_blank" rel=3D"noopener">CVE-2026-57024</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>A Return of Pointer Value Outside of Expected Range vulnerability in th=
e fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a=
local, low-privilged attacker to cause a Denial-of-Service (DoS). On EX Se= ries, QFX Series and MX Series a=C2=A0low-privileged attacker issuing a spe= cific 'show l2-learning' command will cause an l2ald crash which will lead =
to a temporary service impact for all layer 2 services until the process ha=
s automatically restarted. This issue affects EX Series, QFX Series, MX Ser= ies: Junos OS: * all versions before 23.2R2-S7, * 23.4 versions before 23.4= R2-S7, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2. Jun=
os OS Evolved: * all versions before 23.2R2-S7-EVO, * 23.4 versions before = 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-EVO, * 24.4 versions before 24= .4R1-S3-EVO.</td>
<td>2026-07-09</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57025" target=3D= "_blank" rel=3D"noopener">CVE-2026-57025</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>A Concurrent Execution using Shared Resource with Improper Synchronizat= ion ('Race Condition') vulnerability in the packet forwarding engine (PFE) =
of Juniper Networks Junos OS on SRX Series allows an unauthenticated, netwo= rk-based attacker to cause a Denial-of-Service (DoS). As part of the statef=
ul traffic processing on SRX Series devices flows are being established, an=
d removed when not needed anymore. During the removal process the timeout o=
f a flow should be set to 3 seconds and consequentially the flow should be = removed shortly after. Due to a race condition occurring when setting the t= imeout there is a chance (the exact conditions are outside the attackers co= ntrol) that the timeout is instead set to a very high value of larger than = 10,000 seconds: user@host> show security flow session | match timeout Se= ssion ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout:=
85250, Session State: Valid This will lead to an accumulation of flows whi=
ch can be observed by an ever-increasing value of invalidated sessions in t=
he output of 'show security flow session summary': user@host> show secur= ity flow session summary | match invalid Invalidated sessions: 216931These = sessions can't be cleared manually with the 'clear security flow session' c= ommand, which will either lead to forwarding to stop (and the system needs =
to be manually recovered with a reboot) or to a flowd core and automatic re= boot. This issue affects Junos OS on SRX Series: * 24.2 versions before 24.= 2R2-S3, * 24.4 versions before 24.4R2-S1, 24.4R2-S2, * 25.2=C2=A0versions= =C2=A0before 25.2R1-S2, 25.2R2. This issue does not affect releases earlier=
than 24.2R1;</td>
<td>2026-07-09</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57030" target=3D= "_blank" rel=3D"noopener">CVE-2026-57030</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>A Use of Incorrectly-Resolved Name or Reference vulnerability in the UR=
L filtering plugin of Juniper Networks Junos OS on MX Series allows an unau= thenticated, network-based attacker to bypass web filtering and access down= stream resources that should be unreachable. If an MX Series device is conf= igured with web filtering, and an attacker sends a request with a specifica= lly formatted URL, this request will get forwarded despite the system being=
configured to block it. In turn, an attacker can access downstream resourc=
es that are expected to be unreachable. This issue affects=C2=A0Junos OS on=
MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-= S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before 24.4R2-S4, * 2= 5.2 versions before 25.2R2-S1, * 25.4 versions before 25.4R1-S2, 25.4R2.</t=
<td>2026-07-09</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57054" target=3D= "_blank" rel=3D"noopener">CVE-2026-57054</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>A NULL Pointer Dereference vulnerability in the management daemon (mgd)=
of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-pri= vileged attacker setting or deactivating a=C2=A0specific SSH configuration = parameter to create a Denial of Service (DoS). A local high-privileged user=
configuring or deactivating a specific 'system services ssh' configuration=
parameter=C2=A0can exploit a null pointer dereference in one of the functi= ons used by SSH. The function attempts to dereference a null pointer when a= ccessing certain configuration data, resulting in an mgd process crash and = restart.=C2=A0Continued execution of these configuration commands will crea=
te a sustained Denial of Service (DoS) condition. This issue affects: Junos=
OS: * from 22.3 before 22.3R3-S5; * from 22.4 before 22.4R3-S10; * from 23=
.2 before 23.2R2-S7; * from 23.4 before 23.4R2-S8. This issue does not affe=
ct Junos OS before 22.3R1. Junos OS Evolved: * from 22.3R1-EVO before 23.2R= 2-S7-EVO; * from 23.4 before 23.4R2-S8-EVO. This issue does not affect Juno=
s OS Evolved before 22.3R1-EVO.</td>
<td>2026-07-09</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21901" target=3D= "_blank" rel=3D"noopener">CVE-2026-21901</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juni= per Networks Junos OS and Junos OS Evolved allows an authenticated network-= based attacker sending specific valid SNMPv3 queries to trigger a memory le= ak. Over time, continuous receipt of these queries will result in snmpd pro= cess memory exhaustion, resulting in a process crash and restart, impacting=
the ability to monitor the system via SNMP. Memory usage can be monitored = using the following command: user@device> show system processes extensiv=
e | match snmpd This issue affects: Junos OS: * all versions before 21.2R3-= S8; * from 21.4 before 21.4R3-S7; * from 22.1 before 22.1R3-S6; * from 22.2=
before 22.2R3-S4; * from 22.3 before 22.3R3-S3; * from 22.4 before 22.4R3-= S2; * from 23.2 before 23.2R2; * from 23.4 before 23.4R2. Junos OS Evolved:=
* all versions before 21.2R3-S8-EVO; * from 21.4 before 21.4R3-S7-EVO; * a=
ll versions of 22.1-EVO, * from 22.2 before 22.2R3-S4-EVO; * from 22.3 befo=
re 22.3R3-S3-EVO; * all versions of 22.4-EVO, * from 23.2 before 23.2R2-EVO=
; * from 23.4 before 23.4R2-EVO.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33799" target=3D= "_blank" rel=3D"noopener">CVE-2026-33799</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS</td>
<td>An Improper Check for Unusual or Exceptional Conditions vulnerability i=
n the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Ser= ies allows adjacent subscribers to bypass configured firewall filters. On M=
X Series devices with=C2=A0MPC10/11, LC4800/9600, and MX304 with=C2=A0subsc= ribers configured on static interfaces, ingress firewall filters are not en= forced, so that neither protocol level nor upstream bandwidth limitation ar=
e in effect.=C2=A0 This issue affects Junos OS on MX with=C2=A0MPC10/11, LC= 4800/9600/4802, and MX304: * 23.2 versions from 23.2R2-S1 before 23.2R2-S7,=
* 23.4 versions from 23.4R2 before 23.4R2-S7, * 24.2 versions before 24.2R= 2-S3, * 24.4 versions before 24.4R2-S2, * 25.2 versions before 25.2R2.</td> <td>2026-07-09</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57031" target=3D= "_blank" rel=3D"noopener">CVE-2026-57031</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS Evolved</td>
<td>An Improper Restriction of Communication Channel to Intended Endpoints = vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticate=
d, network-based attacker to cause a limited information disclosure and ava= ilability impact to the device. Due to a wrong initialization, a process wh= ich should only be able to communicate internally within the device can be = reached over the network via an open port. This leads to a device being ina= dvertently exposed and increased CPU cycles spent processing ingress packet=
s. This issue affects Junos OS Evolved: * all versions before 23.2R2-S7-EVO=
, * 23.4 versions before 23.4R2-S8-EVO, * 24.2 versions before 24.2R2-S5-EV=
O, * 24.4 versions before 24.4R2-S4-EVO, * 25.2 versions before 25.2R2-S1-E= VO, * 25.4 versions before 25.4R1-S2-EVO.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33803" target=3D= "_blank" rel=3D"noopener">CVE-2026-33803</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS Evolved</td>
<td>An Improper Check for Unusual or Exceptional Conditions vulnerability i=
n the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos O=
S Evolved on PTX Series allows an unauthenticated network-based attacker ge= nerating continuous routing updates, resulting in unilist ECMP routes, to c= rash the evo-aftmand process on the PFE, leading to a Denial-of-Service (Do= S). The conditions required for successful exploitation are=C2=A0based on a=
sequence of events that are outside an attacker's direct control. Unified = list (unilist) ECMP routes are a specific ECMP behavior where multiple equa= l-cost routes share a single logical next-hop list entry. The router treats=
them as one route with multiple next hops and load balances traffic across=
that unified list. Due to an issue processing unilist ECMP routing updates=
, internal state corruption may occur, especially in large-scale ECMP unili=
st deployments, leading to the evo-aftmand process crashing, resulting in a=
n evo-aftmand-bx core. Manual intervention is required to recover by reboot= ing the system or=C2=A0restarting the FPC. This issue affects Junos OS Evol= ved on PTX : * from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.= 2R2-EVO.</td>
<td>2026-07-09</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33794" target=3D= "_blank" rel=3D"noopener">CVE-2026-33794</a></td>
</tr>
<td class=3D"vendor-product">Juniper Networks--Junos OS Evolved</td> <td>A=C2=A0Missing Synchronization vulnerability in the flow collector hand= ler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, = unauthenticated attacker to cause a Denial-of-Service (DoS). When the reach= ability of an sFlow collector changes, the corresponding next-hop entry is = updated.=C2=A0If this update occurs simultaneously with the sFlow thread ac= cessing the next-hop data (which is outside the attackers control), it caus=
es the evo-pfemand process to crash, impacting all traffic forwarding until=
the automatic process restart has completed. This issue affects Junos OS E= volved on QFX Series: * all 23.2 versions,=C2=A0 * 23.4 versions before 23.= 4R2-S7-EVO, * 24.2 versions before 24.2R2-S5-EVO, * 24.4 versions before 24= .4R2-S3-EVO, * 25.2 versions before 25.2R2-EVO.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57029" target=3D= "_blank" rel=3D"noopener">CVE-2026-57029</a></td>
</tr>
<td class=3D"vendor-product">kingaddons--King Addons for Elementor 80+ Elem= entor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Bu= ilder</td>
<td>The King Addons for Elementor plugin for WordPress is vulnerable to Sto= red Cross-Site Scripting via the 'form_page_id' parameter in versions up to=
, and including, 51.1.62 This is due to insufficient input sanitization in = the add_to_submissions() function, which applies sanitize_text_field() (whi=
ch preserves double-quote characters) before storing the value in post meta=
, combined with missing output escaping in the king_addons_submissions_cust= om_column_content() function, which concatenates the stored value into an H= TML href attribute via admin_url() without wrapping the result in esc_url()=
. This makes it possible for authenticated attackers, with subscriber-level=
access and above, to inject arbitrary web scripts in pages that will execu=
te whenever a user accesses an injected page.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15284" target=3D= "_blank" rel=3D"noopener">CVE-2026-15284</a></td>
</tr>
<td class=3D"vendor-product">kitae-park--Mang Board WP</td>
<td>The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross= -Site Scripting via the 'stag' parameter in all versions up to, and includi= ng, 2.3.4 due to insufficient input sanitization and output escaping. This = makes it possible for unauthenticated attackers to inject arbitrary web scr= ipts in pages that execute if they can successfully trick a user into perfo= rming an action such as clicking on a link.</td>
<td>2026-07-09</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13334" target=3D= "_blank" rel=3D"noopener">CVE-2026-13334</a></td>
</tr>
<td class=3D"vendor-product">labring--FastGPT</td>
<td>FastGPT is an open source AI knowledge base platform. From 4.14.17 to b= efore 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POS=
T /api/core/dataset/collection/create/reTrainingCollection in a way that pe= rsists a server-owned datasetId value from another tenant. This creates mix=
ed dataset objects and downstream dataset, collection, and training endpoin=
ts then make authorization decisions from inconsistent ownership anchors, a= llowing cross-tenant read, update, and delete access when mixed object ids = are known. This issue is fixed in version 4.15.0-beta4.</td> <td>2026-07-07</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54601" target=3D= "_blank" rel=3D"noopener">CVE-2026-54601</a></td>
</tr>
<td class=3D"vendor-product">langchain-ai--langsmith-sdk</td>
<td>LangSmith Client SDKs provide SDK's for interacting with the LangSmith = platform. Prior to 0.8.18, an attacker who can send an HTTP request to a se= rver running the LangSmith SDK's TracingMiddleware can cause that server to=
read an arbitrary file from its local filesystem and upload the contents t=
o LangSmith as a trace attachment. Depending on how the distributed trace s= ystem is deployed, triggering a read may not require authentication. Retrie= ving the contents requires read access to the LangSmith workspace the trace=
s are sent to. The net effect is a trust-boundary crossing: a party with wo= rkspace trace-read access (for example a low-privilege workspace member, a = contractor, or a compromised teammate account) gains the ability to read fi= les from any server running TracingMiddleware, a capability outside that wo= rkspace's intended trust boundary. This vulnerability is fixed in 0.8.18.</=
<td>2026-07-06</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59152" target=3D= "_blank" rel=3D"noopener">CVE-2026-59152</a></td>
</tr>
<td class=3D"vendor-product">Leantime--Leantime</td>
<td>A vulnerability has been found in Leantime up to 3.8.0. This impacts th=
e function editUser/addUser of the component JSON-RPC Endpoint. The manipul= ation of the argument role leads to improper authorization. The attack is p= ossible to be carried out remotely. The exploit has been disclosed to the p= ublic and may be used. The vendor was contacted early about this disclosure=
but did not respond in any way.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15509" target=3D= "_blank" rel=3D"noopener">CVE-2026-15509</a></td>
</tr>
<td class=3D"vendor-product">Leantime--Leantime</td>
<td>A vulnerability was found in Leantime up to 3.8.0. Affected is the func= tion Setting::saveSetting of the component API. The manipulation results in=
improper authorization. The attack may be performed from remote. The explo=
it has been made public and could be used. The vendor was contacted early a= bout this disclosure but did not respond in any way.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15510" target=3D= "_blank" rel=3D"noopener">CVE-2026-15510</a></td>
</tr>
<td class=3D"vendor-product">leap13--Premium Addons for Elementor Powerful = Elementor Templates & Widgets</td>
<td>The Premium Addons for Elementor - Powerful Elementor Templates & W= idgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi=
a the 'premium_tooltip_text' parameter in all versions up to, and including=
, 4.11.84 due to insufficient input sanitization and output escaping. This = makes it possible for authenticated attackers, with contributor-level acces=
s and above, to inject arbitrary web scripts in pages that will execute whe= never a user accesses an injected page. The injected payload is specificall=
y triggered when an administrator or higher-privileged user opens the affec= ted post in the Elementor editor, as the raw unescaped output occurs via th=
e print_template() method registered on the 'elementor/section/print_templa= te' hook rather than on the public-facing frontend.</td>
<td>2026-07-11</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12141" target=3D= "_blank" rel=3D"noopener">CVE-2026-12141</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript = URIs, allowing attacker-supplied Markdown links or images to bypass URL pro= tections and execute script in rendered HTML. This issue is fixed in versio=
n 3.3.0.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59923" target=3D= "_blank" rel=3D"noopener">CVE-2026-59923</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only j= avascript:, vbscript:, file:, and data: schemes, allowing legacy or chained=
schemes such as feed:, view-source:, jar:, livescript:, mocha:, ms-its:, m= k:, and res: to reach rendered href and src attributes and potentially exec= ute script in affected user agents. This issue is fixed in version 3.3.0.</=
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59929" target=3D= "_blank" rel=3D"noopener">CVE-2026-59929</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, Include.parse() joins and normalizes user-supplied include paths w= ithout verifying that the result remains within the intended markdown direc= tory, allowing crafted include paths to access files outside that directory=
when markdown files are processed using md.read(). This issue is fixed in = version 3.3.0.</td>
<td>2026-07-08</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59924" target=3D= "_blank" rel=3D"noopener">CVE-2026-59924</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, the Include directive in src/mistune/directives/include.py detects=
only direct self-includes and not indirect cycles, allowing two markdown f= iles that include each other to trigger unbounded recursion, raise Recursio= nError, and crash the rendering request. This issue is fixed in version 3.3= .0.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59927" target=3D= "_blank" rel=3D"noopener">CVE-2026-59927</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.3.0, the toc plugin and TableOfContents directive generate heading IDs =
as predictable toc_N values without slugifying the heading text, allowing a= ttacker-controlled id=3D"toc_N" content to collide with generated anchors a=
nd redirect same-page navigation, CSS selectors, or JavaScript handlers. Th=
is issue is fixed in version 3.3.0.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59930" target=3D= "_blank" rel=3D"noopener">CVE-2026-59930</a></td>
</tr>
<td class=3D"vendor-product">Limatek System Inc.--LimRAD NAC</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Limatek System Inc. LimRAD NAC allows Stored=
XSS. This issue affects LimRAD NAC: through 08072026.=C2=A0NOTE: The vendo=
r was contacted early about this disclosure but did not respond in any way.= </td>
<td>2026-07-08</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6371" target=3D"= _blank" rel=3D"noopener">CVE-2026-6371</a></td>
</tr>
<td class=3D"vendor-product">logichunt--Logo Slider WP Responsive Logo Caro= usel, Logo Gallery & Logo Showcase</td>
<td>The Logo Slider - Logo Carousel, Client Logo Slider & Brand Showcas=
e for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr= ipting via the 'lgx_tooltip_position' parameter in all versions up to, and = including, 5.5 due to insufficient input sanitization and output escaping. = This makes it possible for authenticated attackers, with contributor-level = access and above, to inject arbitrary web scripts in pages that will execut=
e whenever a user accesses an injected page.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13247" target=3D= "_blank" rel=3D"noopener">CVE-2026-13247</a></td>
</tr>
<td class=3D"vendor-product">logto-io--logto</td>
<td>Logto is the modern, open-source auth infrastructure for SaaS and AI ap= ps. Prior to 1.41.0, @logto/core reflected the SAML RelayState, SAMLRespons=
e, and actionUrl into a Logto-origin auto-submit HTML form in packages/core= /src/saml-application/SamlApplication/utils.ts without HTML-attribute escap= ing. A SAML application flow with a crafted RelayState from GET or POST /ap= i/saml/:id/authn could inject script that runs on the Logto tenant origin a= fter the user completes login. This issue is fixed in version 1.41.0.</td> <td>2026-07-10</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54714" target=3D= "_blank" rel=3D"noopener">CVE-2026-54714</a></td>
</tr>
<td class=3D"vendor-product">logto-io--logto</td>
<td>Logto is the modern, open-source auth infrastructure for SaaS and AI ap= ps. Prior to 1.41.0, Logto's existing TOTP verification accepted a successf= ully used TOTP code again while the code remained inside the RFC 6238 accep= tance window because the verifier used otplib's stateless check with window=
=3D 1 and did not persist or compare the accepted TOTP time-step counter. =
An attacker who has the victim's first factor and captures a live TOTP valu=
e can replay that value to satisfy MFA during the same acceptance window. T= his issue is fixed in version 1.41.0.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55370" target=3D= "_blank" rel=3D"noopener">CVE-2026-55370</a></td>
</tr>
<td class=3D"vendor-product">looswebstudio--Highlighting Code Block</td> <td>The Highlighting Code Block plugin for WordPress is vulnerable to Store=
d Cross-Site Scripting via admin settings in all versions up to, and includ= ing, 2.2.0 due to insufficient input sanitization and output escaping. This=
makes it possible for authenticated attackers, with administrator-level pe= rmissions and above, to inject arbitrary web scripts in pages that will exe= cute whenever a user accesses an injected page. This only affects multi-sit=
e installations and installations where unfiltered_html has been disabled.<=
<td>2026-07-10</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12108" target=3D= "_blank" rel=3D"noopener">CVE-2026-12108</a></td>
</tr>
<td class=3D"vendor-product">lustmored--Lockme calendars integration</td> <td>The Lockme OAuth2 calendars integration plugin for WordPress is vulnera= ble to Stored Cross-Site Scripting via the 'App ID' setting in all versions=
up to, and including, 2.11.0. This is due to insufficient input sanitizati=
on and output escaping. The register_setting() call on line 197 lacks a san= itize callback, allowing unsanitized data to be stored via update_option().=
When the settings page is rendered, the stored value is echoed directly in=
to an HTML input's value attribute without esc_attr() on line 212. This mak=
es it possible for authenticated attackers, with administrator-level access=
and above, to inject arbitrary web scripts in the settings page that will = execute whenever a user accesses the plugin settings page. Multiple fields = are affected: App ID (client_id), App Secret (client_secret), Bookings ID p= refix (id_prefix), and API domain (api_domain). This vulnerability is parti= cularly impactful in WordPress multisite installations where administrators=
of individual sites should not be able to execute JavaScript affecting oth=
er users.</td>
<td>2026-07-11</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3367" target=3D"= _blank" rel=3D"noopener">CVE-2026-3367</a></td>
</tr>
<td class=3D"vendor-product">macrozheng--mall</td>
<td>A vulnerability was identified in macrozheng mall up to 1.0.3. This imp= acts an unknown function of the file /returnApply/create of the component P= ortal Endpoint. The manipulation of the argument orderId leads to improper = control of resource identifiers. The attack can be initiated remotely. The = exploit is publicly available and might be used. The vendor deleted the Git= Hub issue for this vulnerability without any explanation.</td> <td>2026-07-09</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15186" target=3D= "_blank" rel=3D"noopener">CVE-2026-15186</a></td>
</tr>
<td class=3D"vendor-product">manjurulhoque--django-job-portal</td>
<td>A weakness has been identified in manjurulhoque django-job-portal up to=
dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability i=
s the function EditEmployeeProfileAPIView of the file accounts/api/views.py=
of the component Employee Dashboard Endpoint. This manipulation of the arg= ument role causes improper access controls. The attack may be initiated rem= otely. The exploit has been made available to the public and could be used = for attacks. This product uses a rolling release model to deliver continuou=
s updates. As a result, specific version information for affected or update=
d releases is not available. The project was informed of the problem early = through an issue report but has not responded yet.</td>
<td>2026-07-09</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15188" target=3D= "_blank" rel=3D"noopener">CVE-2026-15188</a></td>
</tr>
<td class=3D"vendor-product">matrixaddons--Easy Invoice Invoice Generator, = PDF Quotes & Payments</td>
<td>The Easy Invoice plugin for WordPress is vulnerable to Missing Authoriz= ation in versions up to, and including, 2.1.19. This is due to the plugin r= egistering the easy_invoice_accept_quote and easy_invoice_decline_quote AJA=
X actions via wp_ajax_nopriv_ hooks and relying solely on a quote-scoped no= nce that is rendered into the publicly accessible single quote template, co= mbined with an ownership check that is gated behind an off-by-default Pro o= ption (easy_invoice_pro_restrict_quote_to_client). This makes it possible f=
or unauthenticated attackers to accept or decline arbitrary published quote=
s - and, depending on the configured accept action, automatically convert t= hem into invoices (and even email them to the client) - by harvesting the p= er-quote nonce from the public quote page and submitting it to admin-ajax.<=
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9021" target=3D"= _blank" rel=3D"noopener">CVE-2026-9021</a></td>
</tr>
<td class=3D"vendor-product">mdempfle--Advanced iFrame</td>
<td>The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-= Site Scripting via the 'additional' parameter in all versions up to, and in= cluding, 2026.1 due to insufficient input sanitization and output escaping.=
This makes it possible for authenticated attackers, with contributor-level=
access and above, to inject arbitrary web scripts in pages that will execu=
te whenever a user accesses an injected page.</td>
<td>2026-07-08</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6742" target=3D"= _blank" rel=3D"noopener">CVE-2026-6742</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authori= zes deletion of issue dependencies. The DELETE dependency route accepts eit= her endpoint of a dependency edge and checks delete permission only against=
the caller-selected URL issue. A workspace member who cannot delete a depe= ndency through an owner-created issue endpoint (which returns 403) can dele=
te the same dependency edge by targeting a related member-owned issue endpo= int, because permission is validated against the member-owned issue's owner=
. This allows members to bypass owner/admin authorization and remove owner-= created issue dependencies.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61441" target=3D= "_blank" rel=3D"noopener">CVE-2026-61441</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 4.6.78 contains a prompt injection defense bypass vuln= erability where the injection defense only blocks threats classified as CRI= TICAL, requiring three or more detector families to match simultaneously. A= ttackers can craft single or double-vector prompt injections that are class= ified as HIGH threat level and pass through unblocked to reach the model.</=
<td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60086" target=3D= "_blank" rel=3D"noopener">CVE-2026-60086</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 4.6.78 fails to validate file path references in custo=
m command templates, allowing attackers to read files outside the workspace=
. Attackers can include path traversal sequences like @../outside_secret.tx=
t or absolute paths in project command files to exfiltrate process-readable=
files into model prompts.</td>
<td>2026-07-11</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60088" target=3D= "_blank" rel=3D"noopener">CVE-2026-60088</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loa=
ds defaults from a project-local .praisonai/config.toml when constructing a=
n Agent, and does not validate the defaults.output.output_file path. A repo= sitory-controlled config file can set output_file to an absolute or '..' tr= aversal path; when the developer subsequently calls agent.start() without e= xplicitly passing an output parameter, PraisonAI writes the agent response =
to that path (creating parent directories as needed), allowing an untrusted=
checked-out project to overwrite files outside the project root with the p= rivileges of the user running PraisonAI.</td>
<td>2026-07-10</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60089" target=3D= "_blank" rel=3D"noopener">CVE-2026-60089</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI before 4.6.78 contains a path traversal vulnerability in Cont= extGatherer that fails to validate include paths in .praisoncontext and .pr= aisoninclude files. Attackers can supply absolute paths or parent directory=
traversal sequences to read arbitrary files outside the workspace and incl= ude their contents in the generated context bundle.</td>
<td>2026-07-10</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61431" target=3D= "_blank" rel=3D"noopener">CVE-2026-61431</a></td>
</tr>
<td class=3D"vendor-product">MervinPraison--PraisonAI</td>
<td>PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vul= nerability in the FastContext feature (praisonaiagents.context.fast). FastC= ontextAgent.execute_tool() prepends the configured workspace_path only for = relative paths and neither rejects absolute paths nor canonicalizes joined = paths before enforcing workspace containment. As a result, tool arguments o=
r model-generated function calls to grep_search, glob_search, read_file, or=
list_directory can supply absolute paths or '../' traversal sequences to r= ead, search, and enumerate files outside the intended workspace directory, = with file contents returned to the caller or injected into the model's tool= -result context.</td>
<td>2026-07-10</td>
<td>5.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61432" target=3D= "_blank" rel=3D"noopener">CVE-2026-61432</a></td>
</tr>
<td class=3D"vendor-product">metagauss--Memberships and User Profiles for W= ooCommerce ProfileGrid WooCommerce Integration</td>
<td>The Memberships and User Profiles for WooCommerce - ProfileGrid WooComm= erce Integration plugin for WordPress is vulnerable to unauthorized plugin = installation and activation in versions up to, and including, 3.4. This is = due to a missing capability check and missing nonce validation on the pg_in= stall_profilegrid() AJAX handler registered via wp_ajax_pg_install_profileg= rid. This makes it possible for authenticated attackers, with Subscriber-le= vel access and above, to install and activate the ProfileGrid plugin from w= ordpress.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11359" target=3D= "_blank" rel=3D"noopener">CVE-2026-11359</a></td>
</tr>
<td class=3D"vendor-product">mettle--sendportal</td>
<td>A flaw has been found in mettle sendportal up to 3.0.1. This vulnerabil= ity affects unknown code of the file vendor/mettle/sendportal-core/src/Http= /Requests/CampaignStoreRequest.php of the component Campaign Creation Endpo= int. Executing a manipulation can lead to authorization bypass. The attack = can be executed remotely. The exploit has been published and may be used. T=
he project was informed of the problem early through an issue report but ha=
s not responded yet.</td>
<td>2026-07-09</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15191" target=3D= "_blank" rel=3D"noopener">CVE-2026-15191</a></td>
</tr>
<td class=3D"vendor-product">mettle--sendportal</td>
<td>A vulnerability has been found in mettle sendportal up to 3.0.1. This i= ssue affects the function sendgrid/postmark/postal/mailjet of the component=
APIv1 Webhooks. The manipulation leads to missing authentication. The atta=
ck is possible to be carried out remotely. The exploit has been disclosed t=
o the public and may be used. The project was informed of the problem early=
through an issue report but has not responded yet.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15192" target=3D= "_blank" rel=3D"noopener">CVE-2026-15192</a></td>
</tr>
<td class=3D"vendor-product">MiniTool--Partition Wizard</td>
<td>A weakness has been identified in MiniTool Partition Wizard up to 13.6.=
The affected element is an unknown function in the library pwdrvio.sys of = the component Signed Kernel Driver. This manipulation causes improper acces=
s controls. The attack can only be executed locally. The exploit has been m= ade available to the public and could be used for attacks. Upgrading to ver= sion 13.9 is sufficient to fix this issue. The affected component should be=
upgraded. The vendor was contacted early about this disclosure.</td> <td>2026-07-12</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15475" target=3D= "_blank" rel=3D"noopener">CVE-2026-15475</a></td>
</tr>
<td class=3D"vendor-product">mlfactory--DSGVO All in one for WP</td>
<td>The DSGVO All in one for WP plugin for WordPress is vulnerable to Missi=
ng Authorization in all versions up to and including 4.9. This is due to th=
e dsgvo_reset_policy_service_func() function lacking both capability checks=
and nonce verification while processing user-supplied parameters to reset = plugin options. This makes it possible for authenticated attackers, with Su= bscriber-level access and above, to reset all customized privacy policy con= tent including cookie notices, Google Analytics policies, Facebook policies=
, and YouTube policies to their default values.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4298" target=3D"= _blank" rel=3D"noopener">CVE-2026-4298</a></td>
</tr>
<td class=3D"vendor-product">mockoon--mockoon</td>
<td>Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FIL=
E response whose filePath embeds request data is confined by getSafeFilePat=
h in packages/commons-server/src/libs/server/server.ts with resolvedPath.st= artsWith(staticBaseDir). That prefix test has no path-separator boundary, s=
o a ../-escaped path whose absolute form string-prefixes the base directory=
passes, allowing an unauthenticated client to read files from sibling path=
s outside the served directory through HTTP sendFile, WebSocket, or callbac= ks. This issue is fixed in version 9.7.0.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59149" target=3D= "_blank" rel=3D"noopener">CVE-2026-59149</a></td>
</tr>
<td class=3D"vendor-product">mvantellingen--python-zeep</td>
<td>Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_= external is defined but not enforced when parsing WSDL or XSD documents, al= lowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or = DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is f= ixed in version 4.3.3.</td>
<td>2026-07-08</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58501" target=3D= "_blank" rel=3D"noopener">CVE-2026-58501</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization by= pass in the Public API execution retry endpoint, which authorizes access us= ing the workflow:read scope instead of workflow:execute. An authenticated u= ser with read-only access to a shared workflow can use the Public API to re= try executions of that workflow, bypassing the intended permission boundary=
between read and execute access. This affects instances where workflows ar=
e shared with other users or across projects.</td>
<td>2026-07-08</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56778" target=3D= "_blank" rel=3D"noopener">CVE-2026-56778</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 2.8.0 contains a cross-site scripting vulnerability in the c= redential management flow where authenticated users can inject malicious Ja= vaScript URLs into OAuth2 credential Authorization URL fields. Attackers ca=
n craft malicious credentials and trick victims into clicking the OAuth aut= horization button, executing arbitrary scripts in their browser session wit=
h the victim's privileges.</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56359" target=3D= "_blank" rel=3D"noopener">CVE-2026-56359</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulne= rability in three mutating evaluation test-run endpoints that authorize sta= te-changing actions using the workflow:read scope instead of the action-app= ropriate workflow:execute scope. On instances using Advanced Permissions (E= nterprise/Cloud) with projects and viewer roles, an authenticated user with=
the project:viewer role can start new evaluation test runs, cancel in-flig=
ht runs, and delete run records for workflows they only have read access to= .</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56775" target=3D= "_blank" rel=3D"noopener">CVE-2026-56775</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branche=
s) contains cross-site scripting and open redirect vulnerabilities in the F= orm Node due to unsanitized HTML description fields and overly permissive i= frame sandbox policies. Authenticated users with workflow creation permissi= ons can inject malicious scripts or redirect parameters to perform stored X=
SS attacks or phishing redirects against end users.</td>
<td>2026-07-10</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56354" target=3D= "_blank" rel=3D"noopener">CVE-2026-56354</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 sign= atures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know t=
he webhook URL can send unsigned POST requests to trigger workflows with ar= bitrary malicious data.</td>
<td>2026-07-08</td>
<td>4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56360" target=3D= "_blank" rel=3D"noopener">CVE-2026-56360</a></td>
</tr>
<td class=3D"vendor-product">nandhiniwp--GW AI Website Builder</td>
<td>The GW AI Website Builder plugin for WordPress is vulnerable to unautho= rized modification of data due to a missing capability check on the gwaiweb= u_gravitywrite_disconnect_handler() function in all versions up to, and inc= luding, 1.0.1. This makes it possible for authenticated attackers, with Sub= scriber-level access and above, to disconnect the plugin from GravityWrite = via the 'gwaiwebu_gravitywrite_disconnect' AJAX action.</td> <td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1946" target=3D"= _blank" rel=3D"noopener">CVE-2026-1946</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listene=
r could route requests for the MQTT-over-WebSocket path into MQTT handling = even when MQTT was not configured, allowing an unauthenticated client with = access to the WebSocket listener to reach uninitialized MQTT state and cras=
h the server process. This issue is fixed in versions 2.14.3 and 2.12.12.</=
<td>2026-07-08</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58208" target=3D= "_blank" rel=3D"noopener">CVE-2026-58208</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authent= icated user with subscription deny permissions could bypass a plain subject=
deny rule by using a queue subscription, because queue-specific deny evalu= ation could override the plain subject deny result when the queue name itse=
lf was not denied. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11= .16.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58251" target=3D= "_blank" rel=3D"noopener">CVE-2026-58251</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authent= icated user could receive messages on denied subjects when a wildcard subsc= ription overlapped with a configured wildcard deny rule but was not a subse=
t of it, and queue subscriptions could also affect delivery to legitimate q= ueue consumers. This issue is fixed in versions 2.14.0, 2.12.7, and 2.11.16= .</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58252" target=3D= "_blank" rel=3D"noopener">CVE-2026-58252</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.3 and 2.12.12, a client could be r= egistered as the configured no_auth_user through a parser path used when th=
e first client operation was not CONNECT, bypassing user-level connection r= estrictions such as allowed_connection_types or proxy_required that normal = authentication would apply. This issue is fixed in versions 2.14.3 and 2.12= .12.</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58211" target=3D= "_blank" rel=3D"noopener">CVE-2026-58211</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained messa=
ge delivery and QoS1+ durable replay could deliver messages whose original = topics matched a subscriber configured subscribe deny rule because these de= livery paths did not consistently recheck the concrete original topic befor=
e sending the MQTT PUBLISH to the subscriber. This issue is fixed in versio=
ns 2.14.3 and 2.12.12.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58209" target=3D= "_blank" rel=3D"noopener">CVE-2026-58209</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQ=
TT client could subscribe to the internal $MQTT.deliver.pubrel subject fami= ly, bypassing configured subscribe permissions and exposing MQTT QoS2 proto= col metadata for sessions in the account. This issue is fixed in versions 2= .14.3 and 2.12.12.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58214" target=3D= "_blank" rel=3D"noopener">CVE-2026-58214</a></td>
</tr>
<td class=3D"vendor-product">neeraj_slit--Brevo Email, SMS, Web Push, Chat,=
and more.</td>
<td>The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (for= mely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site=
Scripting via the page parameter in all versions up to, and including, 3.1= .77 due to insufficient input sanitization and output escaping. This makes =
it possible for unauthenticated attackers to inject arbitrary web scripts i=
n pages that execute if they can successfully trick a user into performing =
an action such as clicking on a link.</td>
<td>2026-07-10</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15297" target=3D= "_blank" rel=3D"noopener">CVE-2026-15297</a></td>
</tr>
<td class=3D"vendor-product">nocobase--nocobase</td>
<td>NocoBase through 2.1.20 contains a server-side request forgery vulnerab= ility in the serverRequest wrapper that allows authenticated administrators=
to issue arbitrary outbound HTTP requests by supplying malicious URLs to w= orkflow request nodes, custom request action buttons, or the AI plugin. Att= ackers can target loopback addresses, RFC-1918 private ranges, and cloud in= stance metadata endpoints to perform internal network port enumeration, hos=
t discovery, and retrieval of IAM role credentials from the instance metada=
ta service. v2.1.18 added a warning message for when SERVER_REQUEST_WHITELI=
ST is not configured.</td>
<td>2026-07-07</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58468" target=3D= "_blank" rel=3D"noopener">CVE-2026-58468</a></td>
</tr>
<td class=3D"vendor-product">nodeca--js-yaml</td>
<td>js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0=
, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing=
a document whose size grows only linearly when a chain of mappings uses me= rge keys where each mapping merges the previous one. This issue is fixed in=
version 5.2.0.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59868" target=3D= "_blank" rel=3D"noopener">CVE-2026-59868</a></td>
</tr>
<td class=3D"vendor-product">nodeca--js-yaml</td>
<td>js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1=
, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses=
omapTag.addItem() to perform a linear duplicate-key scan on every insertio=
n, causing O(n^2) CPU consumption when yaml.load() parses a crafted ordered= -map document. This issue is fixed in version 5.2.1.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59870" target=3D= "_blank" rel=3D"noopener">CVE-2026-59870</a></td>
</tr>
<td class=3D"vendor-product">NOMYSOFT Informatics Education and Consulting = Inc.--Nomysem</td>
<td>Exposure of sensitive information due to incompatible policies vulnerab= ility in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows = Accessing Functionality Not Properly Constrained by ACLs. This issue affect=
s Nomysem: through 08072026.=C2=A0NOTE: The vendor was contacted early abou=
t this disclosure but did not respond in any way.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6280" target=3D"= _blank" rel=3D"noopener">CVE-2026-6280</a></td>
</tr>
<td class=3D"vendor-product">Nozomi Networks--Guardian</td>
<td>A Stored HTML Injection vulnerability was discovered in the Diagram tab=
and Graph view due to a shared input validation function being insufficien= tly restrictive. An authenticated user with administrative privileges can i= nject malicious HTML tags into N2OS configuration data through multiple inp=
ut vectors. When a victim views the affected data in the Diagram tab and Gr= aph view, the injected HTML renders in their browser, enabling phishing and=
possibly open redirect attacks. Full XSS exploitation and direct informati=
on disclosure are prevented by the existing input validation and Content Se= curity Policy configuration.</td>
<td>2026-07-09</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31981" target=3D= "_blank" rel=3D"noopener">CVE-2026-31981</a></td>
</tr>
<td class=3D"vendor-product">Nozomi Networks--Guardian</td>
<td>A Missing Authentication vulnerability was discovered in the SSH keys s= ynchronization endpoint. An unauthenticated attacker can send a request to = the SSH keys synchronization endpoint and obtain the list of users that hav=
e uploaded their public SSH keys, their groups, and the uploaded public SSH=
keys.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31983" target=3D= "_blank" rel=3D"noopener">CVE-2026-31983</a></td>
</tr>
<td class=3D"vendor-product">onnx--onnx</td>
<td>Open Neural Network Exchange (ONNX) is an open standard for machine lea= rning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.co= nvert_version() can dereference a null pointer in Upsample_6_7::adapt_upsam= ple_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing=
an untrusted model with an Upsample node that has zero inputs, causing an = unrecoverable denial of service. This issue is fixed in version 1.22.0.</td=
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44512" target=3D= "_blank" rel=3D"noopener">CVE-2026-44512</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 3.21.0 and prior to version 4.11.0, the=
ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one e= rror that can cause a massive heap overflow that corrupts all TEE kernel me= mory following the hash state. This affects all platforms built with `CFG_C= RYPTO_WITH_CE82=3Dy` (ARMv8.2+ with SHA3 Crypto Extensions). Version 4.11.0=
contains a patch. As a workaround, disable SHA3 Crypto Extensions with `CF= G_CRYPTO_WITH_CE82=3Dn`.</td>
<td>2026-07-06</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40257" target=3D= "_blank" rel=3D"noopener">CVE-2026-40257</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 3.20.0 and prior to version 4.11.0, a v= ulnerability in OP-TEE's subkey rollback protection allows the use of revok=
ed or older subkey versions because the system fails to propagate versionin=
g data during the Trusted Application (TA) loading process. In `core/crypto= /signed_hdr.c`, the function `shdr_load_pub_key()` parses subkey headers bu=
t does not assign the `subkey_version` to the runtime `shdr_pub_key` struct= ure. As a result, the `key->version` field remains at zero regardless of=
the version specified in the header. When `ree_fs_ta_open()` in `core/kern= el/ree_fs_ta.c` calls `check_update_version()`, it passes this zeroed versi=
on to the rollback database. Because the database never receives a non-zero=
version to record, it never advances, effectively bypassing the rollback c= heck and allowing TAs signed with downgraded subkey chains to load successf= ully. This impacts OP-TEE mainline configurations that utilize subkey-based=
signing chains for Trusted Application (TA) authentication. Version 4.11.0=
contains a patch. No known workarounds are available.</td>
<td>2026-07-06</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44362" target=3D= "_blank" rel=3D"noopener">CVE-2026-44362</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re = regular expressions in backend/open_webui/utils/middleware.py parsed <$s= killId|label> skill mentions with overlapping quantifiers, allowing an a= uthenticated chat message containing <$ without a closing > to trigge=
r quadratic backtracking and block the asyncio event loop. This issue is fi= xed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59220" target=3D= "_blank" rel=3D"noopener">CVE-2026-59220</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only=
checked read access while file write and delete routes later trusted objec= t-derived access through writable model meta.knowledge entries, allowing a = user with read-only knowledge file access to upgrade to file write or delet=
e operations. This issue is fixed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59212" target=3D= "_blank" rel=3D"noopener">CVE-2026-59212</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked us= ers up by email and only ran bcrypt password verification when a credential=
existed, making registered-account attempts measurably slower than missing= -email attempts and allowing unauthenticated account enumeration. This issu=
e is fixed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59218" target=3D= "_blank" rel=3D"noopener">CVE-2026-59218</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user w= ith read access to an arena wrapper model can reach a restricted underlying=
model through task endpoints such as /api/v1/tasks/moa/completions. The no= rmal chat route resolves arena models before the final chat dispatch and th= erefore re-checks the selected underlying model. The task routes call utils= .chat.generate_chat_completion() directly. In that direct path, arena fallb= ack resolution happens after the wrapper access check and then recurses wit=
h bypass_filter=3DTrue, skipping the selected submodel's access check. This=
issue is fixed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59225" target=3D= "_blank" rel=3D"noopener">CVE-2026-59225</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, the file upload path accepted metadata.know= ledge_id and auto-linked uploaded files to a target knowledge base without = applying the write-access check used by /api/v1/knowledge//file/add, allowi=
ng read-only knowledge-base users to add arbitrary files. This issue is fix=
ed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59217" target=3D= "_blank" rel=3D"noopener">CVE-2026-59217</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, WEB_FETCH_FILTER_LIST matching compared con= figured host entries against URL strings and non-label-boundary suffixes, a= llowing path-based blocklist bypasses such as !internal.example.com in a UR=
L path and sibling-domain matches that did not reflect the intended hostnam=
e policy. This issue is fixed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59223" target=3D= "_blank" rel=3D"noopener">CVE-2026-59223</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required=
only a verified account and did not enforce the global image-edit switch o=
r the per-user image-generation permission, allowing a non-admin user to in= voke server-side image editing with administrator-configured provider crede= ntials. This issue is fixed in version 0.10.0.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59227" target=3D= "_blank" rel=3D"noopener">CVE-2026-59227</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>sshd in OpenSSH before 10.4 does not always honor the minimum authentic= ation delay.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60001" target=3D= "_blank" rel=3D"noopener">CVE-2026-60001</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>In sshd in OpenSSH before 10.4, DisableForwarding=3Dyes was supposed to=
take precedence over PermitTunnel=3Dyes, but did not.</td>
<td>2026-07-08</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59999" target=3D= "_blank" rel=3D"noopener">CVE-2026-59999</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>sftp in OpenSSH before 10.4 does not properly constrain the location of=
downloaded files when "sftp server:/path ." is used with an attacker-contr= olled server.</td>
<td>2026-07-08</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59995" target=3D= "_blank" rel=3D"noopener">CVE-2026-59995</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>scp in OpenSSH before 10.4 may place a file in the parent directory of =
an intended directory when the copy occurs between two remote destinations.= </td>
<td>2026-07-08</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59996" target=3D= "_blank" rel=3D"noopener">CVE-2026-59996</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first =
9 command-line arguments, which can be important if a later command-line ar= gument would have helped to ensure the intended security properties of an S= FTP connection.</td>
<td>2026-07-08</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59997" target=3D= "_blank" rel=3D"noopener">CVE-2026-59997</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>sshd in OpenSSH before 10.4 has an undocumented security-relevant behav= ior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Act= ive Directory.</td>
<td>2026-07-08</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59998" target=3D= "_blank" rel=3D"noopener">CVE-2026-59998</a></td>
</tr>
<td class=3D"vendor-product">OpenCTI-Platform--opencti</td>
<td>OpenCTI is an open source platform for managing cyber threat intelligen=
ce knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API = exposes a script filter operator in its FilterOperator enum that allows any=
authenticated user with the KNOWLEDGE capability to pass user-supplied Ela= sticsearch Painless script values directly into search queries without vali= dation or sanitization, allowing computationally expensive scripts to consu=
me cluster CPU resources and degrade or deny service for all users. This is= sue is fixed in version 7.260401.0.</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35211" target=3D= "_blank" rel=3D"noopener">CVE-2026-35211</a></td>
</tr>
<td class=3D"vendor-product">openfga--openfga</td>
<td>OpenFGA is an authorization/permission engine built for developers. Pri=
or to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation = when authn.method was set to oidc, authn.oidc.issuer was configured, and au= thn.oidc.audience was not set, allowing a token minted for an unrelated ser= vice by the same identity provider to authenticate to OpenFGA. This issue i=
s fixed in 1.18.0.</td>
<td>2026-07-09</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55689" target=3D= "_blank" rel=3D"noopener">CVE-2026-55689</a></td>
</tr>
<td class=3D"vendor-product">openreplay--openreplay</td>
<td>OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the = session search and analytics API in enterprise editions with multi-tenancy = enabled built ClickHouse queries by inserting user input into the query str= ing, including two positions that took input without escaping, allowing an = authenticated member to read any ClickHouse table through blind boolean and=
time-based exfiltration and to break the project's session search for all = viewers until the stored key is removed. This issue is fixed in version 1.2= 7.0.</td>
<td>2026-07-10</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57230" target=3D= "_blank" rel=3D"noopener">CVE-2026-57230</a></td>
</tr>
<td class=3D"vendor-product">OpenStack--Ironic</td>
<td>OpenStack Ironic through before 37.0.1 allows creation or modification =
of nodes cross-project without authorization.</td>
<td>2026-07-10</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44918" target=3D= "_blank" rel=3D"noopener">CVE-2026-44918</a></td>
</tr>
<td class=3D"vendor-product">openwrt--openwrt</td>
<td>OpenWrt is a Linux operating system targeting embedded devices. Before = v25.12.5, an integer underflow in handle_send_a() of the Emergency Access D= aemon allows any unauthenticated attacker on the local network to crash the=
daemon by sending a single crafted UDP packet. The message length underflo=
ws before a bounds check and is then passed to memcpy as a very large size.=
This issue is fixed v25.12.5.</td>
<td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55490" target=3D= "_blank" rel=3D"noopener">CVE-2026-55490</a></td>
</tr>
<td class=3D"vendor-product">osquery--osquery</td>
<td>osquery is a SQL powered operating system instrumentation, monitoring, = and analytics framework. Prior to 5.23.1, an unprivileged attacker can read=
the contents of an osquery file carve until the carve completes and the te= mporary files are deleted because in-progress carve directories are not cre= ated with private permissions. If the carve targets a directory that the at= tacker controls, arbitrary file reads are possible, such as sensitive local=
files. This issue is fixed in version 5.23.1.</td>
<td>2026-07-10</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46388" target=3D= "_blank" rel=3D"noopener">CVE-2026-46388</a></td>
</tr>
<td class=3D"vendor-product">owasp-modsecurity--ModSecurity</td> <td>ModSecurity is an open source, cross platform web application firewall = (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:ut= f8toUnicode transformation in src/actions/transformations/utf8_to_unicode.c=
c produces wrong output on i386 architecture because snprintf uses sizeof o=
n a char pointer rather than the length of the unicode buffer, allowing rul=
es that use this transformation to be bypassed on i386 architecture. This i= ssue is fixed in version 3.0.16.</td>
<td>2026-07-10</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52761" target=3D= "_blank" rel=3D"noopener">CVE-2026-52761</a></td>
</tr>
<td class=3D"vendor-product">phpMyFAQ--phpMyFAQ</td>
<td>phpMyFAQ before 4.1.5 applies inconsistent active=3Dyes and publication= -date filtering across its public FAQ API endpoints, allowing unauthenticat=
ed attackers to retrieve inactive (draft or review-only) FAQ content. Speci= fically, GET /api/v3.1/faq/{categoryId}/{faqId} returns the inactive FAQ ti= tle and full answer, while GET /api/v3.1/faqs/tags/{tagId} and GET /api/v4.= 0/faqs/tags/{tagId} return the inactive FAQ title and answer preview, discl= osing non-public content.</td>
<td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57994" target=3D= "_blank" rel=3D"noopener">CVE-2026-57994</a></td>
</tr>
<td class=3D"vendor-product">pig-mesh--Pig</td>
<td>A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by=
this issue is some unknown functionality of the file \pig-master\pig-visua= l\pig-codegen\src\main\java\com\pig4cloud\pig\codegen\service\impl\Generato= rServiceImpl.java of the component pig-codegen. Such manipulation leads to = code injection. It is possible to launch the attack remotely. The exploit i=
s publicly available and might be used. The vendor was contacted early abou=
t this disclosure but did not respond in any way.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15512" target=3D= "_blank" rel=3D"noopener">CVE-2026-15512</a></td>
</tr>
<td class=3D"vendor-product">plugins360--All-in-One Video Gallery</td>
<td>The All-in-One Video Gallery plugin for WordPress is vulnerable to Serv= er-Side Request Forgery in all versions up to, and including, 4.8.5 via the=
'vdl' parameter. This makes it possible for authenticated attackers, with = subscriber-level access and above, to make web requests to arbitrary locati= ons originating from the web application and can be used to query and modif=
y information from internal services. A Subscriber-level attacker can plant=
an internal or loopback URL in the `mp4` post meta of a newly created `aio= vg_videos` post via XML-RPC `wp.newPost`, then trigger the unauthenticated = `?vdl=3D<post_id>` endpoint to force the server to fetch that URL and=
stream the full response body back to the requester.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12123" target=3D= "_blank" rel=3D"noopener">CVE-2026-12123</a></td>
</tr>
<td class=3D"vendor-product">pluginsGLPI--datainjection</td>
<td>The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates = user-supplied CSV field values directly into SQL queries during CSV import,=
without parameterization or escaping, resulting in authenticated SQL injec= tion. An authenticated user with access to the Data injection feature can e= mbed SQL expressions such as SLEEP() in a mapped field (for example Serial = Number) to manipulate the generated query and extract database information = via time-based blind injection.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11321" target=3D= "_blank" rel=3D"noopener">CVE-2026-11321</a></td>
</tr>
<td class=3D"vendor-product">posimyththemes--Nexter Blocks Gutenberg Blocks=
, Page Builder & AI Website Builder</td>
<td>The Nexter Blocks - Gutenberg Blocks, Page Builder & AI Website Bui= lder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via = the 'commentIcon' parameter in all versions up to, and including, 4.7.4 due=
to insufficient input sanitization and output escaping. This makes it poss= ible for authenticated attackers, with contributor-level access and above, =
to inject arbitrary web scripts in pages that will execute whenever a user = accesses an injected page.</td>
<td>2026-07-08</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6740" target=3D"= _blank" rel=3D"noopener">CVE-2026-6740</a></td>
</tr>
<td class=3D"vendor-product">posimyththemes--The Plus Addons for Elementor = Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce</td> <td>The Plus Addons for Elementor plugin for WordPress was vulnerable to Au= thenticated (Contributor+) Stored Cross-Site Scripting via the Button widge= t's `custom_attributes` setting in versions up to and including 6.4.11. The=
`render` function in `modules/widgets/tp_button.php` passed the raw `custo= m_attributes` string through `tp_senitize_js_input()`. This filter is bypas= sable. The issue is patched in version 6.4.12.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15285" target=3D= "_blank" rel=3D"noopener">CVE-2026-15285</a></td>
</tr>
<td class=3D"vendor-product">postmagthemes--Context Blog</td>
<td>The Context Blog theme for WordPress is vulnerable to Sensitive Informa= tion Exposure in all versions up to, and including, 1.3.5 via the context_b= log_modal_popup. This makes it possible for unauthenticated attackers to ex= tract the content of password-protected posts.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6801" target=3D"= _blank" rel=3D"noopener">CVE-2026-6801</a></td>
</tr>
<td class=3D"vendor-product">prasunsen--Hostel</td>
<td>The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scri= pting via the 'wphostel-book' shortcode in all versions up to and including=
1.1.7. This is due to insufficient input sanitization and output escaping =
on user-supplied shortcode attributes. Specifically, the second shortcode a= ttribute (used as button text) is passed to the `$text` variable without sa= nitization at line 79 and then output directly into an HTML `value` attribu=
te at line 91 without `esc_attr()` or any other escaping. This makes it pos= sible for authenticated attackers, with Contributor-level access and above,=
to inject arbitrary web scripts in pages that will execute whenever a user=
accesses an injected page.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3907" target=3D"= _blank" rel=3D"noopener">CVE-2026-3907</a></td>
</tr>
<td class=3D"vendor-product">printfriendly--Print, PDF & Email by Print= Friendly</td>
<td>The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerab=
le to Stored Cross-Site Scripting via the 'content_position_css' parameter =
in all versions up to, and including, 5.5.10 due to insufficient input sani= tization and output escaping. This makes it possible for authenticated atta= ckers, with administrator-level access and above, to inject arbitrary web s= cripts in pages that will execute whenever a user accesses an injected page= .</td>
<td>2026-07-11</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9738" target=3D"= _blank" rel=3D"noopener">CVE-2026-9738</a></td>
</tr>
<td class=3D"vendor-product">priyanshuchaudhary--FlowForms Conversational F= orm Builder</td>
<td>The FlowForms - Conversational Form Builder plugin for WordPress is vul= nerable to Insecure Direct Object Reference in all versions up to, and incl= uding, 1.1.1 via the update_form due to missing validation on a user contro= lled key. This makes it possible for authenticated attackers, with contribu= tor-level access and above, to modify the content, design, and settings of,=
as well as publish or revert, any form on the site - including forms owned=
by administrators - by supplying an arbitrary form ID in the REST URL.</td=
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12400" target=3D= "_blank" rel=3D"noopener">CVE-2026-12400</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Improper Neutralization of Special Elements in Data Query Logic vulnera= bility in Progress MOVEit Transfer (Custom Reports modules). This issue aff= ects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.</td> <td>2026-07-08</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8649" target=3D"= _blank" rel=3D"noopener">CVE-2026-8649</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Relative path traversal vulnerability in Progress MOVEit Transfer (Admi=
n Settings module). This issue affects MOVEit Transfer: before 2025.0.7, fr=
om 2025.1.0 before 2025.1.3.</td>
<td>2026-07-08</td>
<td>4.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8650" target=3D"= _blank" rel=3D"noopener">CVE-2026-8650</a></td>
</tr>
<td class=3D"vendor-product">protobufjs--protobuf.js</td>
<td>protobufjs compiles protobuf definitions into JavaScript (JS) functions=
. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing thr= ough schema tokens until reaching an =3D token without checking for end of = input, so a crafted .proto schema that opens an option declaration and ends=
prematurely can cause parse, Root.load, or Root.loadSync to loop indefinit= ely. This issue is fixed in versions 7.6.5 and 8.6.6.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59877" target=3D= "_blank" rel=3D"noopener">CVE-2026-59877</a></td>
</tr>
<td class=3D"vendor-product">protobufjs--protobuf.js</td>
<td>protobufjs compiles protobuf definitions into JavaScript (JS) functions=
. From 8.2.0 until 8.6.5, the protobufjs Text Format extension parsed strin= g-keyed map entries using ordinary property assignment, allowing a map entr=
y with key __proto__ to change the prototype of the returned map object ins= tead of creating an own map entry in protobufjs/ext/textformat. This issue =
is fixed in version 8.6.5.</td>
<td>2026-07-08</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59876" target=3D= "_blank" rel=3D"noopener">CVE-2026-59876</a></td>
</tr>
<td class=3D"vendor-product">pydantic--pydantic-settings</td> <td>pydantic-settings provides settings management using Pydantic. From 2.1= 2.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from file=
s in a configured secrets_dir. When secrets_nested_subdir=3DTrue, a directo=
ry entry inside secrets_dir that is a symbolic link pointing outside secret= s_dir is followed, so files outside the configured directory are read into = settings values. The same code path bypasses the documented secrets_dir_max= _size protection. An attacker or lower-privileged component able to influen=
ce entries in the configured secrets directory (for example, a writable or = shared secrets mount) can turn this into an unintended local file read into=
settings and can defeat the advertised loading-size cap. This vulnerabilit=
y is fixed in 2.14.2.</td>
<td>2026-07-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58203" target=3D= "_blank" rel=3D"noopener">CVE-2026-58203</a></td>
</tr>
<td class=3D"vendor-product">pypa--setuptools</td>
<td>setuptools is a package that allows users to download, build, install, = upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied M= ANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives=
by matching compiled glob patterns against on-disk file names without Unic= ode normalization, so on macOS APFS or HFS+ an NFD file name could bypass a=
n NFC exclusion rule and be packed into a source distribution. This issue i=
s fixed in version 83.0.0.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59890" target=3D= "_blank" rel=3D"noopener">CVE-2026-59890</a></td>
</tr>
<td class=3D"vendor-product">python-pillow--Pillow</td>
<td>Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_= command() constructed a cmd.exe shell command by directly embedding a file = path into an f-string without escaping and passed the result to subprocess.= Popen(..., shell=3DTrue), allowing shell metacharacters in the file path to=
inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.<=
<td>2026-07-06</td>
<td>4.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55798" target=3D= "_blank" rel=3D"noopener">CVE-2026-55798</a></td>
</tr>
<td class=3D"vendor-product">QILING--Disk Master</td>
<td>A security vulnerability has been detected in QILING Disk Master 6.0.0.=
0. The impacted element is an unknown function in the library diskbckp.sys =
of the component Kernel Driver. Such manipulation leads to improper access = controls. The attack can only be performed from a local environment. The ex= ploit has been disclosed publicly and may be used. It is suggested to upgra=
de the affected component.</td>
<td>2026-07-12</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15476" target=3D= "_blank" rel=3D"noopener">CVE-2026-15476</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when invoking device input/output control operations = for mapping and unmapping persistent memory buffers due to improper synchro= nization.</td>
<td>2026-07-06</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59615" target=3D= "_blank" rel=3D"noopener">CVE-2025-59615</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when processing multiple IOCTL calls with the same bu= ffer file descriptor input due to accessing already freed memory.</td> <td>2026-07-06</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59616" target=3D= "_blank" rel=3D"noopener">CVE-2025-59616</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when processing multiple IOCTL calls with the same bu= ffer file descriptor input.</td>
<td>2026-07-06</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-59617" target=3D= "_blank" rel=3D"noopener">CVE-2025-59617</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when parsing jpeg commands due to unaccounted extra w= rites to the buffer during validation checks.</td>
<td>2026-07-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21368" target=3D= "_blank" rel=3D"noopener">CVE-2026-21368</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when handling flash commands due to outdated LED coun=
t values being used after userspace modification.</td>
<td>2026-07-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21369" target=3D= "_blank" rel=3D"noopener">CVE-2026-21369</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when validating input batch size and buffer plane cou=
nt exceeds maximum allowed values.</td>
<td>2026-07-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21370" target=3D= "_blank" rel=3D"noopener">CVE-2026-21370</a></td>
</tr>
<td class=3D"vendor-product">Qualcomm, Inc.--Snapdragon</td>
<td>Memory Corruption when updating prepared commands with invalid port ind= ices based on user space input exceeds supported read client limits.</td> <td>2026-07-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21384" target=3D= "_blank" rel=3D"noopener">CVE-2026-21384</a></td>
</tr>
<td class=3D"vendor-product">QuantumNous--new-api</td>
<td>New API is a large language mode (LLM) gateway and artificial intellige= nce (AI) asset management system. Prior to 0.12.0-alpha.1, the email and We= Chat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth= /wechat/bind used GET requests for state-changing account operations, allow= ing an attacker to trigger a logged-in user's browser to bind an attacker-c= ontrolled email address or OAuth identity in deployments where session cook= ies could be sent on cross-site navigations. This issue is fixed in version=
0.12.0-alpha.1.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44342" target=3D= "_blank" rel=3D"noopener">CVE-2026-44342</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6=
on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt= _wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_in=
fo before path validation when multiple management extension plugins are en= abled, causing outbound DNS and SMB requests to attacker-controlled UNC pat= hs. This issue is fixed in versions 4.1.11 and 4.2.6.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57211" target=3D= "_blank" rel=3D"noopener">CVE-2026-57211</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20,=
4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authenticatio=
n can allow a loopback-restricted user such as guest to connect remotely wh=
en traffic is accepted through a trusted PROXY-protocol path and the backen=
d listener is loopback-bound because the loopback check uses the listener-s= ide socket address instead of the real client source. This issue is fixed i=
n versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.</td>
<td>2026-07-10</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57216" target=3D= "_blank" rel=3D"noopener">CVE-2026-57216</a></td>
</tr>
<td class=3D"vendor-product">rainafarai--Notification for Telegram</td>
<td>The Notification for Telegram plugin for WordPress is vulnerable to aut= horization bypass in all versions up to, and including, 3.5.1. This is due =
to the plugin not properly verifying that a user is authorized to perform a=
n action. This makes it possible for authenticated attackers, with subscrib= er-level access and above, to create, modify, or reschedule the nftb_cron_h= ook WordPress cron event, enabling unauthorized manipulation of the plugin'=
s background task scheduling logic.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7620" target=3D"= _blank" rel=3D"noopener">CVE-2026-7620</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Directory Server 11</td>
<td>A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-b= ase). When normalizing a Distinguished Name (DN) that contains a legacy-quo= ted value encoding a multivalued nested Relative Distinguished Name (RDN), = the server can write past the end of a heap allocation while sorting RDN at= tribute-value pairs. An unauthenticated remote attacker can trigger this co= ndition by sending an LDAP operation whose DN reaches the DN normalization = routine, such as a search with a crafted base DN. This can corrupt heap mem= ory and may cause denial of service.</td>
<td>2026-07-07</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14940" target=3D= "_blank" rel=3D"noopener">CVE-2026-14940</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Directory Server 11</td>
<td>A flaw was found in 389-ds-base where the LDBM backend attribute encryp= tion uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC=
operations, allowing an attacker with privileged filesystem access to dete=
ct plaintext equality across encrypted entries by comparing ciphertext bloc= ks.</td>
<td>2026-07-07</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14969" target=3D= "_blank" rel=3D"noopener">CVE-2026-14969</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 6</td>
<td>A flaw was found in GIMP. The PlayStation TIM loader, responsible for h= andling PlayStation image files, incorrectly calculates the size of the Col=
or Look-Up Table (CLUT) due to an integer overflow. This occurs when multip= lying num_colors and num_cluts, both 16-bit unsigned short integers, result= ing in a value exceeding the maximum integer limit. An attacker could explo=
it this by providing a specially crafted image file, leading to undefined b= ehavior and causing the GIMP plug-in to abort, effectively resulting in a d= enial of service.</td>
<td>2026-07-06</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59089" target=3D= "_blank" rel=3D"noopener">CVE-2026-59089</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat JBoss Enterprise Application = Platform 8.1</td>
<td>A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scriptin=
g (XSS) attack. If using a set of combined configuration to allow unescaped=
characters in URL with embedded Undertow and Jastow, a server might be vul= nerable to improper input handling.</td>
<td>2026-07-07</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-12799" target=3D= "_blank" rel=3D"noopener">CVE-2025-12799</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat OpenShift AI (RHOAI)</td>
<td>A flaw was found in the TrustyAI Service Operator. When deploying servi= ces like gorch or NemoGuardrails, if a specific security setting is not ena= bled, these services can expose their communication channels without requir= ing users to prove their identity. This allows any other program within the=
cluster to access the AI guardrails and orchestrator without proper author= ization. An attacker could exploit this to gain unauthorized access to sens= itive information and potentially make limited changes to the AI models.</t=
<td>2026-07-08</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15044" target=3D= "_blank" rel=3D"noopener">CVE-2026-15044</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat OpenShift AI (RHOAI)</td>
<td>A flaw was found in the gorch service template, which is part of the tr= ustyai-service-operator. Even when authentication is enabled, the gorch ser= vice exposes unproxied orchestrator and detector metrics ports. This allows=
any pod on the cluster network to directly access these ports, bypassing t=
he kube-rbac-proxy and its authentication mechanisms. This could lead to un= authorized access to the orchestrator and detector metrics.</td> <td>2026-07-08</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15063" target=3D= "_blank" rel=3D"noopener">CVE-2026-15063</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat OpenShift AI (RHOAI)</td>
<td>A flaw was found in `guardrails-detectors`, a component of Red Hat Open= Shift AI. This vulnerability, known as Regular Expression Denial of Service=
(ReDoS), allows a remote attacker to provide specially crafted regular exp= ressions to the public detection API. This can cause catastrophic backtrack= ing, leading to a worker process consuming 100% CPU indefinitely and result= ing in a denial of service for the entire guardrails-mediated LLM pipeline.= </td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15154" target=3D= "_blank" rel=3D"noopener">CVE-2026-15154</a></td>
</tr>
<td class=3D"vendor-product">redefiningtheweb--Affiliate Program & Refe= rral Tracking for WooCommerce & WordPress Affilia</td>
<td>The Affilia - Affiliate Program & Referral Tracking for WordPress p= lugin for WordPress is vulnerable to unauthorized access in all versions up=
to, and including, 3.3.3. This is due to the plugin not properly verifying=
that a user is authorized to perform an action. This makes it possible for=
authenticated attackers, with subscriber-level access and above, to approv=
e or reject affiliate referrals, credit commissions to affiliate wallets, d= elete referral records, and modify custom banner plugin options, enabling f= inancial fraud. The nonce required to pass the only authentication check is=
embedded in every frontend page load via rtwalwm_global_params.rtwalwm_non= ce, making it trivially accessible to any authenticated user regardless of = role.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7559" target=3D"= _blank" rel=3D"noopener">CVE-2026-7559</a></td>
</tr>
<td class=3D"vendor-product">reputeinfosystems--ARMember Membership Plugin,=
Content Restriction, Member Levels, User Profile & User signup</td> <td>The ARMember plugin for WordPress is vulnerable to Directory Traversal =
in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP head= er. This makes it possible for unauthenticated attackers to upload and over= write certain files (e.g., CSS) to directories outside the 'wp-content/uplo= ads/armember' directory.</td>
<td>2026-07-10</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15302" target=3D= "_blank" rel=3D"noopener">CVE-2026-15302</a></td>
</tr>
<td class=3D"vendor-product">revmakx--Backup and Staging by WP Time Capsule= </td>
<td>The Backup and Staging by WP Time Capsule plugin for WordPress is vulne= rable to Sensitive Information Exposure in all versions up to, and includin=
g, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possi= ble for authenticated attackers, with subscriber-level access and above, to=
extract download the most recently admin-decrypted SQL database backup, wh= ich typically contains password hashes, user credentials, and other sensiti=
ve site configuration data stored in the 'recent_decrypted_file' option. Ex= ploitation requires that an administrator has previously performed a decryp=
t action, causing the decrypted SQL backup file to exist in the plugin's up= load directory; without this prior admin action, there is no file to serve.= </td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8996" target=3D"= _blank" rel=3D"noopener">CVE-2026-8996</a></td>
</tr>
<td class=3D"vendor-product">richardperdaan--MyParcel</td>
<td>The MyParcel plugin for WordPress is vulnerable to authorization bypass=
in all versions up to, and including, 4.25.1. This is due to the plugin no=
t properly verifying that a user is authorized to perform an action. This m= akes it possible for authenticated attackers, with subscriber-level access = and above, to view and modify shipment options - including carrier, deliver=
y type, package type, number of labels, weight, signature requirement, and = insurance - on any arbitrary order.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8678" target=3D"= _blank" rel=3D"noopener">CVE-2026-8678</a></td>
</tr>
<td class=3D"vendor-product">robin-w--bbp style pack</td>
<td>The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-S= ite Scripting in versions up to, and including, 6.4.5 via the Topic Form Ad= ditional Fields feature. This is due to insufficient input sanitization in = bsp_topic_fields_form_save() (which writes $_POST['bsp_topic_fields_label{n= }'] directly to post meta via update_post_meta() with no filtering) and mis= sing output escaping in bsp_topic_content_append_topic_fields() (which conc= atenates the stored meta value into an HTML <span> and echoes it via = apply_filters/echo without esc_html()). This makes it possible for authenti= cated attackers, with Subscriber-level access and above (who have bbPress t= opic-creation privileges), to inject arbitrary web scripts in pages that wi=
ll execute whenever a user accesses an injected page, including unauthentic= ated visitors.</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15010" target=3D= "_blank" rel=3D"noopener">CVE-2026-15010</a></td>
</tr>
<td class=3D"vendor-product">ronf--asyncssh</td>
<td>AsyncSSH is a Python package which provides an asynchronous client and = server implementation of the SSHv2 protocol on top of the Python asyncio fr= amework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SS= HServerConfig._set_tokens that blocks /, , and .. before %u substitution in=
AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing late=
r expansion in _expand_val and Path(filename).expanduser() to escape the in= tended authorized-keys directory. This issue is fixed in version 2.23.1.</t=
<td>2026-07-08</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54590" target=3D= "_blank" rel=3D"noopener">CVE-2026-54590</a></td>
</tr>
<td class=3D"vendor-product">room34--ICS Calendar</td>
<td>The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-= Site Scripting via the 'htmltagtitle' parameter in all versions up to, and = including, 12.0.9 due to insufficient input sanitization and output escapin=
g. This makes it possible for unauthenticated attackers to inject arbitrary=
web scripts in pages that execute if they can successfully trick a user in=
to performing an action such as clicking on a link. The vulnerability is re= achable via the unauthenticated wp_ajax_nopriv_r34ics_ajax AJAX action, whi=
ch accepts attacker-controlled js_args values merged over stored shortcode = configuration without nonce verification, allowing the htmltagtitle key to = bypass the normal shortcode allowlist check.</td>
<td>2026-07-10</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9838" target=3D"= _blank" rel=3D"noopener">CVE-2026-9838</a></td>
</tr>
<td class=3D"vendor-product">rtcamp--rtMedia for WordPress, BuddyPress and = bbPress</td>
<td>The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress =
is vulnerable to time-based SQL Injection via the order_by parameter in all=
versions up to, and including, 4.6.18 due to insufficient escaping on the = user supplied parameter and lack of sufficient preparation on the existing = SQL query. This makes it possible for authenticated attackers, with subscri= ber access and above, to append additional SQL queries into already existin=
g queries that can be used to extract sensitive information from the databa= se.</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15287" target=3D= "_blank" rel=3D"noopener">CVE-2026-15287</a></td>
</tr>
<td class=3D"vendor-product">rubengc--GamiPress Gamification plugin to rewa=
rd points, achievements, badges & ranks in WordPress</td>
<td>The GamiPress - Gamification plugin to reward points, achievements, bad= ges & ranks in WordPress plugin for WordPress is vulnerable to Insecure=
Direct Object Reference in all versions up to, and including, 7.9.4 via th=
e 'access' parameter due to missing validation on a user controlled key. Th=
is makes it possible for unauthenticated attackers to view private GamiPres=
s activity log entries belonging to any user, including badge earnings, poi= nts balance changes, and event records from integrated plugins such as WooC= ommerce, LearnDash, and BuddyPress. This is exploitable by any unauthentica= ted visitor because the required 'gamipress' nonce is broadcast to all fron= t-end users via wp_localize_script on the wp_enqueue_scripts hook, making t=
he sole authentication barrier trivially bypassable.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13450" target=3D= "_blank" rel=3D"noopener">CVE-2026-13450</a></td>
</tr>
<td class=3D"vendor-product">saadiqbal--User Management</td>
<td>The User Management plugin for WordPress is vulnerable to authorization=
bypass in all versions up to, and including, 1.2. This is due to the plugi=
n not properly verifying that a user is authorized to perform an action. Th=
is makes it possible for unauthenticated attackers to modify the plugin's e= xport field configuration stored in the uiewp_export_field option, controll= ing which user fields such as password hashes are included in CSV exports a=
nd how columns are mapped during imports.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12097" target=3D= "_blank" rel=3D"noopener">CVE-2026-12097</a></td>
</tr>
<td class=3D"vendor-product">saadiqbal--WP Easy Pay Payment and Donation fo=
rm Builder for Square</td>
<td>The WP Easy Pay - Payment and Donation form Builder for Square plugin f=
or WordPress is vulnerable to authorization bypass in all versions up to, a=
nd including, 4.5.0. This is due to the plugin not properly verifying that =
a user is authorized to perform an action. This makes it possible for authe= nticated attackers, with subscriber-level access and above, to set the stat=
us of arbitrary posts and pages to 'draft', effectively unpublishing arbitr= ary site content.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12738" target=3D= "_blank" rel=3D"noopener">CVE-2026-12738</a></td>
</tr>
<td class=3D"vendor-product">safistudio--Bookero.pl system rezerwacji onlin= e</td>
<td>The Bookero.pl - system rezerwacji online plugin for WordPress is vulne= rable to Stored Cross-Site Scripting via the `bookero_products` shortcode's=
`hide_products` (and `filter_products`) attributes in versions up to and i= ncluding 2.2. This is due to insufficient input sanitization and output esc= aping in the `bookero_products()` function - the raw attribute value is con= catenated directly into an inline `<script>` block without any escapi= ng. This makes it possible for authenticated attackers with contributor-lev=
el access and above to inject arbitrary web scripts into pages that will ex= ecute whenever a user accesses the injected page.</td>
<td>2026-07-09</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6910" target=3D"= _blank" rel=3D"noopener">CVE-2026-6910</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--Escargot</td>
<td>Stack-based buffer overflow vulnerability in Samsung Open Source Escarg=
ot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b= 403907d8137da1c65aaa4521fe74e.</td>
<td>2026-07-09</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58303" target=3D= "_blank" rel=3D"noopener">CVE-2026-58303</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--Escargot</td> <td>Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open S= ource Escargot allows Overflow Buffers. This issue affects Escargot: before=
779f6bedf58f334dec64b0a51ebb724b4708b84a.</td>
<td>2026-07-09</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58304" target=3D= "_blank" rel=3D"noopener">CVE-2026-58304</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--Escargot</td>
<td>Access of resource using incompatible type ('type confusion') vulnerabi= lity in Samsung Open Source Escargot allows Pointer Manipulation. This issu=
e affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.</td> <td>2026-07-09</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58305" target=3D= "_blank" rel=3D"noopener">CVE-2026-58305</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--Escargot</td>
<td>Heap-based buffer overflow vulnerability in Samsung Open Source Escargo=
t allows Overflow Buffers. This issue affects Escargot: before ef525f337faf= ddecde77a3c426212a84bb20cb98.</td>
<td>2026-07-09</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58306" target=3D= "_blank" rel=3D"noopener">CVE-2026-58306</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--Escargot</td> <td>Out-of-bounds read, Reachable assertion vulnerability in Samsung Open S= ource Escargot allows Overread Buffers, Input Data Manipulation. This issue=
affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.</td> <td>2026-07-09</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58307" target=3D= "_blank" rel=3D"noopener">CVE-2026-58307</a></td>
</tr>
<td class=3D"vendor-product">saskaita123--Invoice123</td>
<td>The Invoice123 plugin for WordPress is vulnerable to authorization bypa=
ss in all versions up to, and including, 1.7.0. This is due to the plugin n=
ot properly verifying that a user is authorized to perform an action. This = makes it possible for authenticated attackers, with subscriber-level access=
and above, to overwrite the plugin's API key stored in wp_options, modify = invoice plugin settings, and alter WooCommerce tax rate data in the wp_wooc= ommerce_tax_rates table.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9857" target=3D"= _blank" rel=3D"noopener">CVE-2026-9857</a></td>
</tr>
<td class=3D"vendor-product">sayantandas20--Bulk Order Update for WooCommer= ce</td>
<td>The Bulk Order Update for WooCommerce plugin for WordPress is vulnerabl=
e to Arbitrary File Read in versions up to, and including, 1.6. This is due=
to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_= nopriv_ hook with no capability or nonce check, and passing the attacker-su= pplied csv_url POST parameter - filtered only by esc_url_raw() (which leave=
s absolute filesystem paths intact) and validate_file() (which only rejects=
'..' traversal patterns) - directly into fopen()/fgetcsv() and reflecting = the first parsed line in the JSON response. This makes it possible for unau= thenticated attackers to read the first line of arbitrary files on the serv=
er (such as /etc/passwd) and to use the handler as a file-existence oracle.= </td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14500" target=3D= "_blank" rel=3D"noopener">CVE-2026-14500</a></td>
</tr>
<td class=3D"vendor-product">Sayax Energy Technologies Inc.--OSOS</td> <td>Insertion of sensitive information into sent data vulnerability in Saya=
x Energy Technologies Inc. OSOS allows Authentication Bypass. This issue af= fects OSOS: through 09072026.=C2=A0NOTE: The vendor was contacted early abo=
ut this disclosure but did not respond in any way.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1365" target=3D"= _blank" rel=3D"noopener">CVE-2026-1365</a></td>
</tr>
<td class=3D"vendor-product">seaweedfs--seaweedfs</td>
<td>SeaweedFS is a distributed storage system. In versions 4.08 through 4.3=
3, requests signed with SigV4 service s3tables are routed to the S3Tables m= anagement API where authorization collapses account-less S3 identities into=
the shared admin account and fails open, allowing an authenticated low-pri= vileged S3 user to enumerate administrator-owned table bucket names and ARN=
s. This issue is fixed in version 4.34.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55873" target=3D= "_blank" rel=3D"noopener">CVE-2026-55873</a></td>
</tr>
<td class=3D"vendor-product">seedprod--Website Builder by SeedProd Theme Bu= ilder, Landing Page Builder, Coming Soon Page, Maintenance Mode</td>
<td>The Website Builder by SeedProd - Theme Builder, Landing Page Builder, = Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to St= ored Cross-Site Scripting via the plugin's `seedprodnestedmenuwidget` short= code in all versions up to, and including, 6.20.2 due to insufficient input=
sanitization and output escaping on user supplied attributes. This makes i=
t possible for authenticated attackers, with contributor level access and a= bove, to inject arbitrary web scripts in pages that will execute whenever a=
user accesses an injected page.</td>
<td>2026-07-08</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14785" target=3D= "_blank" rel=3D"noopener">CVE-2025-14785</a></td>
</tr>
<td class=3D"vendor-product">showdown--showdown</td>
<td>showdown contains a stored cross-site scripting vulnerability in the pa= rseHeaders function of src/subParsers/makehtml/tables.js that fails to prop= erly escape table header ID attributes. Attackers can inject arbitrary HTML=
and script-executing SVG elements through double-quote characters in markd= own table headers, achieving stored XSS when untrusted markdown is rendered=
with the default github flavor configuration.</td>
<td>2026-07-06</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59710" target=3D= "_blank" rel=3D"noopener">CVE-2026-59710</a></td>
</tr>
<td class=3D"vendor-product">showdown--showdown</td>
<td>showdown contains a cross-site scripting vulnerability in metadata titl=
e handling that allows attackers to inject arbitrary HTML and JavaScript. W= hen completeHTMLDocument option is enabled, unescaped less-than and greater= -than characters in markdown frontmatter metadata are inserted directly int=
o HTML title tags, enabling attackers to break out of the title context and=
execute malicious scripts in the rendered page.</td>
<td>2026-07-06</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59711" target=3D= "_blank" rel=3D"noopener">CVE-2026-59711</a></td>
</tr>
<td class=3D"vendor-product">Siemens--CPCI85 Central Processing/Communicati= on</td>
<td>A vulnerability has been identified in CPCI85 Central Processing/Commun= ication (All versions < V26.20), SICORE Base system (All versions < V= 26.20.0). The affected application includes a debugging interface that is a= ccessible through HTTP endpoints. This could allow an authenticated attacke=
r to disrupt the system by crashing the web process causing denial of servi=
ce conditions.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54798" target=3D= "_blank" rel=3D"noopener">CVE-2026-54798</a></td>
</tr>
<td class=3D"vendor-product">Siemens--CPCI85 Central Processing/Communicati= on</td>
<td>A vulnerability has been identified in CPCI85 Central Processing/Commun= ication (All versions < V26.20), SICORE Base system (All versions < V= 26.20.0). The affected application contains a vulnerability in its firmware=
update mechanism's signature validation process. This could allow an attac= ker to install malicious firmware, leading to persistent code execution and=
system compromise.</td>
<td>2026-07-09</td>
<td>6.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54799" target=3D= "_blank" rel=3D"noopener">CVE-2026-54799</a></td>
</tr>
<td class=3D"vendor-product">Siemens--CPCI85 Central Processing/Communicati= on</td>
<td>A vulnerability has been identified in CPCI85 Central Processing/Commun= ication (All versions < V26.20), SICORE Base system (All versions < V= 26.20.0). The affected application ships with a default configuration that = disables all OPC UA security mechanisms. This could allow an attacker to ga=
in unauthorized access and control over critical system functions.</td> <td>2026-07-09</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54800" target=3D= "_blank" rel=3D"noopener">CVE-2026-54800</a></td>
</tr>
<td class=3D"vendor-product">Sipeed--PicoClaw</td>
<td>A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Aff= ected by this vulnerability is the function WebFetchTool.Execute of the fil=
e pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. The=
manipulation results in server-side request forgery. The attack can be exe= cuted remotely. The exploit has been released to the public and may be used=
for attacks. The reported GitHub issue was closed automatically due to ina= ctivity.</td>
<td>2026-07-10</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15317" target=3D= "_blank" rel=3D"noopener">CVE-2026-15317</a></td>
</tr>
<td class=3D"vendor-product">Sipeed--PicoClaw</td>
<td>A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected=
by this issue is some unknown functionality of the file pkg/channels/mqtt/= mqtt.go of the component MQTT Channel Handler. This manipulation of the arg= ument client_id causes incorrect authorization. The attack is possible to b=
e carried out remotely. The exploit has been made available to the public a=
nd could be used for attacks. The reported GitHub issue was closed automati= cally due to inactivity.</td>
<td>2026-07-10</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15318" target=3D= "_blank" rel=3D"noopener">CVE-2026-15318</a></td>
</tr>
<td class=3D"vendor-product">Sipeed--PicoClaw</td>
<td>A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulne= rability affects the function rt.ReloadConfig of the file pkg/channels/pico= /pico.go. Performing a manipulation of the argument message.send results in=
missing authorization. It is possible to initiate the attack remotely. The=
exploit is now public and may be used. The reported GitHub issue was close=
d automatically due to inactivity.</td>
<td>2026-07-10</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15320" target=3D= "_blank" rel=3D"noopener">CVE-2026-15320</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan is an open-source personal knowledge management system. Prior to=
3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria=
from data/storage/criteria.json without the publish-access filtering used =
by sibling storage endpoints, allowing a publish-mode Reader to read privat=
e document paths, notebook, document, and block IDs, and search and replace=
keywords for unpublished documents. This issue is fixed in versions 3.7.1.= </td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59853" target=3D= "_blank" rel=3D"noopener">CVE-2026-59853</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan is an open-source personal knowledge management system. Prior to=
3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute s= ource paths and relies on util.IsSensitivePath in kernel/util/path.go, whos=
e denylist misses common home-directory credential files such as .git-crede= ntials, .netrc, .pgpass, .kube/config, .docker/config.json, and .gnupg, all= owing an authenticated administrator or API-token user to copy those files = into the workspace and exfiltrate them through the file API. This issue is = fixed in versions 3.7.1-alpha.2 and 3.7.1.</td>
<td>2026-07-09</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59854" target=3D= "_blank" rel=3D"noopener">CVE-2026-59854</a></td>
</tr>
<td class=3D"vendor-product">smub--Smash Balloon Social Photo Feed Easy Soc= ial Feeds Plugin</td>
<td>The Smash Balloon Social Photo Feed - Easy Social Feeds Plugin plugin f=
or WordPress is vulnerable to Cross-Site Request Forgery in all versions up=
to, and including, 6.11.1. This is due to missing or incorrect nonce valid= ation on the maybe_connection_data function. This makes it possible for una= uthenticated attackers to overwrite the site's Instagram and Facebook oEmbe=
d access tokens via a forged request granted they can trick a site administ= rator into performing an action such as clicking on a link.</td> <td>2026-07-08</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12002" target=3D= "_blank" rel=3D"noopener">CVE-2026-12002</a></td>
</tr>
<td class=3D"vendor-product">solacewp--Solace Extra</td>
<td>The Solace Extra plugin for WordPress is vulnerable to authorization by= pass in all versions up to, and including, 1.5.3. This is due to the plugin=
not properly verifying that a user is authorized to perform an action. Thi=
s makes it possible for unauthenticated attackers to permanently delete all=
content previously imported via the Starter Template feature, including po= sts, pages, media attachments, WooCommerce products, taxonomy terms, and si= tebuilder templates. The required nonce is emitted on every wp-admin page v=
ia wp_localize_script() hooked to admin_enqueue_scripts without a page guar=
d, meaning any Subscriber visiting /wp-admin/profile.php can obtain it; the=
handler is additionally registered via wp_ajax_nopriv_, making it reachabl=
e by fully unauthenticated users as well.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13250" target=3D= "_blank" rel=3D"noopener">CVE-2026-13250</a></td>
</tr>
<td class=3D"vendor-product">SonicCloudOrg--sonic-agent</td>
<td>A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2=
. The affected element is an unknown function of the file AndroidWSServer.j= ava of the component Android WebSocket Server. The manipulation of the argu= ment path leads to os command injection. The attack can be initiated remote= ly. The exploit has been disclosed to the public and may be used. The vendo=
r was contacted early about this disclosure but did not respond in any way.=
This vulnerability only affects products that are no longer supported by t=
he maintainer.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15495" target=3D= "_blank" rel=3D"noopener">CVE-2026-15495</a></td>
</tr>
<td class=3D"vendor-product">SonicCloudOrg--sonic-agent</td>
<td>A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The=
impacted element is the function evalIsFailed of the file sonic-agent/src/= main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the c= omponent Groovy Script Handler. The manipulation results in os command inje= ction. The attack can be launched remotely. The exploit has been made publi=
c and could be used. The vendor was contacted early about this disclosure b=
ut did not respond in any way. This vulnerability only affects products tha=
t are no longer supported by the maintainer.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15496" target=3D= "_blank" rel=3D"noopener">CVE-2026-15496</a></td>
</tr>
<td class=3D"vendor-product">sovlix--GoodMeet Google Meet Integration for W= ebinar, Meeting & Video Conference</td>
<td>The GoodMeet - Google Meet Integration for Webinar, Meeting & Video=
Conference plugin for WordPress is vulnerable to Cross-Site Request Forger=
y in versions up to and including 1.1.8. This is due to a missing nonce ver= ification in the reset_credential() function, which handles the wp_ajax_goo= dmeet_reset_google_meet_credential AJAX action. While the function does ver= ify the user's capability (manage_options), it does not validate a nonce, m= aking it susceptible to CSRF attacks. This makes it possible for unauthenti= cated attackers to trick a site administrator into clicking a malicious lin=
k that will reset (delete) the plugin's stored Google Meet API credentials = (goodmeet_google_credentials) and OAuth tokens (goodmeet_google_token), eff= ectively disabling the Google Meet integration on the site.</td> <td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6440" target=3D"= _blank" rel=3D"noopener">CVE-2026-6440</a></td>
</tr>
<td class=3D"vendor-product">SQLite--SQLite</td>
<td>An issue in SQLite before Fossil check-in 869a51ae84df allows a local a= ttacker to obtain sensitive information via the Session Extension changeset=
concat/changegroup merge path</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50813" target=3D= "_blank" rel=3D"noopener">CVE-2026-50813</a></td>
</tr>
<td class=3D"vendor-product">starboardsuite--Starboard Suite Reservation Ca= lendars</td>
<td>The Starboard Suite Reservation Calendars plugin for WordPress is vulne= rable to Stored Cross-Site Scripting via shortcode attributes in the [starb= oard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 = due to insufficient input sanitization and output escaping. This makes it p= ossible for authenticated attackers, with Contributor-level access and abov=
e, to inject arbitrary web scripts in pages that will execute whenever a us=
er accesses an injected page.</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-13968" target=3D= "_blank" rel=3D"noopener">CVE-2025-13968</a></td>
</tr>
<td class=3D"vendor-product">stellarwp--Kadence Blocks Page Builder Toolkit=
for Gutenberg Editor</td>
<td>The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plug=
in for WordPress is vulnerable to unauthorized post publication in all vers= ions up to, and including, 3.5.32 due to a misconfigured capability check o=
n the 'get_items_permission_check' function permission callback of the 'pro= cess_pattern' REST API endpoint. This makes it possible for authenticated a= ttackers, with Contributor-level access and above, to create and immediatel=
y publish posts of any type (including pages), bypassing the standard WordP= ress review workflow where contributors must submit posts for administrator=
approval.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15286" target=3D= "_blank" rel=3D"noopener">CVE-2026-15286</a></td>
</tr>
<td class=3D"vendor-product">stylemix--Cost Calculator Builder</td>
<td>The Cost Calculator Builder plugin for WordPress is vulnerable to Sensi= tive Information Exposure in all versions up to, and including, 4.0.11 via = the (template body). This makes it possible for unauthenticated attackers t=
o extract the plaintext Stripe secret key, Razorpay secret key, and PayPal = client_secret embedded in the page source of any page containing a calculat= or, enabling full control of the merchant's payment gateway accounts. This = exposure only occurs when the 'use in all calculators' option is enabled fo=
r one or more payment gateways in the plugin's global settings.</td> <td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10865" target=3D= "_blank" rel=3D"noopener">CVE-2026-10865</a></td>
</tr>
<td class=3D"vendor-product">subratamal--Wallet for WooCommerce</td>
<td>The Wallet for WooCommerce plugin for WordPress is vulnerable to author= ization bypass in all versions up to, and including, 1.6.4. This is due to = the plugin not properly verifying that a user is authorized to perform an a= ction. This makes it possible for authenticated attackers, with subscriber-= level access and above, to enumerate the login name, email address, and use=
r ID of all WordPress accounts - including administrators - by submitting a= rbitrary search terms to the AJAX handler. The required 'search-user' nonce=
is localized into the wallet_param object on the standard WooCommerce My A= ccount page, which is accessible to any authenticated user, making it trivi= ally obtainable by a Subscriber.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12103" target=3D= "_blank" rel=3D"noopener">CVE-2026-12103</a></td>
</tr>
<td class=3D"vendor-product">supercleanse--Members Membership & User Ro=
le Editor Plugin</td>
<td>The Members - Membership & User Role Editor Plugin plugin for WordP= ress is vulnerable to Sensitive Information Exposure in all versions up to,=
and including, 3.2.22 via the members_filter_protected_posts_for_rest. Thi=
s makes it possible for unauthenticated attackers to extract determine the = existence and exact count of access-restricted posts, and use per-page pagi= nation as a boolean oracle to infer keywords and content contained within t= hose hidden restricted posts.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12426" target=3D= "_blank" rel=3D"noopener">CVE-2026-12426</a></td>
</tr>
<td class=3D"vendor-product">Superior Court of California, County of Los An= geles--Hearing Reminder Service</td>
<td>The Superior Court of California Hearing Reminder Service at
https://ww= w.hrs.courts.ca.gov exposes an API endpoint that returns court reminder rec= ords containing potentially sensitive information without authentication.</=
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61344" target=3D= "_blank" rel=3D"noopener">CVE-2026-61344</a></td>
</tr>
<td class=3D"vendor-product">surflabtech--SurfLink Link Manager & Backu=
p Restore</td>
<td>The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable=
to unauthorized data modification due to a missing capability check on the=
ajax_import_410() function in all versions up to 2.6.0. This is due to a m= issing capability check (current_user_can()) and missing nonce verification=
(check_ajax_referer()) in the ajax_import_410() function, while all other = AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410=
, ajax_delete_410, ajax_bulk_410_delete, ajax_empty_410, ajax_export_410) p= roperly implement both authorization and nonce checks. This makes it possib=
le for authenticated attackers, with Subscriber-level access and above, to = import arbitrary URLs into the 410 Gone database table via the surfl_import= _410 AJAX action. Injected URLs will cause the site to return HTTP 410 Gone=
responses to all visitors accessing those paths, potentially causing denia=
l of service for legitimate pages and SEO damage through search engine deli= sting.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3552" target=3D"= _blank" rel=3D"noopener">CVE-2026-3552</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>Missing filtering when the helmRepoURLRegex field isn't set on a GitRep=
o resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.1=
4 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm = authentication credentials (BasicAuth) to any URL specified in the helm.rep=
o field of a fleet.yaml file, allowing attackers able to push to fleet moni= tored git repos to leak helm access credentials.</td>
<td>2026-07-06</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44936" target=3D= "_blank" rel=3D"noopener">CVE-2026-44936</a></td>
</tr>
<td class=3D"vendor-product">symfony--ux</td>
<td>Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.= 36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_= safe=3D['html'] and Icon::toHtml() inlines SVG source verbatim, allowing un= sanitized local SVG files or Iconify on-demand JSON body responses containi=
ng nested script elements, on* event handlers, or dangerous URL schemes to = execute cross-site scripting. This issue is fixed in versions 2.36.1 and 3.= 2.0.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55877" target=3D= "_blank" rel=3D"noopener">CVE-2026-55877</a></td>
</tr>
<td class=3D"vendor-product">Tag plugin--GLPI 11</td>
<td>The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HT=
ML sanitization and renders it into the Kanban badge markup via PluginTagTa= g::preKanbanContent() without output escaping, resulting in stored cross-si=
te scripting. An authenticated user with TAG MANAGEMENT create or update ri= ghts can set a tag name containing HTML, which then executes in the browser=
of any user who opens the Kanban view of a ticket, problem, change, or pro= ject the tag is attached to.</td>
<td>2026-07-09</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53987" target=3D= "_blank" rel=3D"noopener">CVE-2026-53987</a></td>
</tr>
<td class=3D"vendor-product">the_champ--Social Share, Social Login and Soci=
al Comments Plugin Super Socializer</td>
<td>The Social Share, Social Login and Social Comments Plugin - Super Socia= lizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting = via the 'heateor_mastodon_share' parameter in all versions up to, and inclu= ding, 7.14.5 due to insufficient input sanitization and output escaping. Th=
is makes it possible for unauthenticated attackers to inject arbitrary web = scripts in pages that execute if they can successfully trick a user into pe= rforming an action such as clicking on a link.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11798" target=3D= "_blank" rel=3D"noopener">CVE-2026-11798</a></td>
</tr>
<td class=3D"vendor-product">themefic--Hydra Booking Appointment Scheduling=
& Booking Calendar</td>
<td>The Hydra Booking - Appointment Scheduling & Booking Calendar plugi=
n for WordPress is vulnerable to Insecure Direct Object Reference in versio=
ns up to, and including, 1.2.1 via the /wp-json/hydra-booking/v1/booking/de= tails/{id} REST endpoint. This is due to the getBookingDetails() callback o= nly enforcing the tfhb_manage_options capability via tfhb_manage_options_pe= rmission(), without verifying that the requested booking belongs to the cur= rently authenticated host (the lookup in getBookingDetailsData() filters so= lely on the booking id supplied in the URL). This makes it possible for aut= henticated attackers, with Hydra Host-level access and above (a role create=
d by the plugin which grants tfhb_manage_options), to view sensitive bookin=
g records belonging to other hosts, including attendee names, emails, phone=
numbers, addresses, meeting details, payment method and status, transactio=
n history, and internal notes by iterating booking IDs.</td> <td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12433" target=3D= "_blank" rel=3D"noopener">CVE-2026-12433</a></td>
</tr>
<td class=3D"vendor-product">themehunk--TH Login Registration</td>
<td>The Themehunk Login Registration plugin for WordPress is vulnerable to = privilege escalation in versions up to, and including, 1.0.2. This is due t=
o the handle_frontend_register() function in the unauthenticated /thlogin/v= 1/register REST endpoint accepting a user-controlled 'role' parameter and v= alidating it only against get_editable_roles() - which returns every define=
d editable site role, including 'editor' - before passing it to wp_insert_u= ser(). This makes it possible for unauthenticated attackers, when public us=
er registration is enabled, to create new accounts with the editor role.</t=
<td>2026-07-08</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14250" target=3D= "_blank" rel=3D"noopener">CVE-2026-14250</a></td>
</tr>
<td class=3D"vendor-product">themifyme--Themify Builder</td>
<td>The Themify Builder plugin for WordPress is vulnerable to Stored Cross-= Site Scripting via Map Module 'b_width_map' Field in all versions up to, an=
d including, 7.7.6 due to insufficient input sanitization and output escapi= ng. This makes it possible for authenticated attackers, with contributor-le= vel access and above, to inject arbitrary web scripts in pages that will ex= ecute whenever a user accesses an injected page.</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15096" target=3D= "_blank" rel=3D"noopener">CVE-2026-15096</a></td>
</tr>
<td class=3D"vendor-product">themifyme--Themify Builder</td>
<td>The Themify Builder plugin for WordPress is vulnerable to Stored Cross-= Site Scripting via 'height_slider' Slider Module Field in all versions up t=
o, and including, 7.7.6 due to insufficient input sanitization and output e= scaping. This makes it possible for authenticated attackers, with contribut= or-level access and above, to inject arbitrary web scripts in pages that wi=
ll execute whenever a user accesses an injected page.</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15097" target=3D= "_blank" rel=3D"noopener">CVE-2026-15097</a></td>
</tr>
<td class=3D"vendor-product">thimpress--WP Hotel Booking</td>
<td>The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cr= oss-Site Scripting via the 'check_in_date' and 'check_out_date' parameters =
in all versions up to, and including, 2.3.1 due to insufficient input sanit= ization and output escaping. This makes it possible for unauthenticated att= ackers to inject arbitrary web scripts in pages that execute if they can su= ccessfully trick a user into performing an action such as clicking on a lin= k.</td>
<td>2026-07-10</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11392" target=3D= "_blank" rel=3D"noopener">CVE-2026-11392</a></td>
</tr>
<td class=3D"vendor-product">thimpress--WP Hotel Booking</td>
<td>The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient=
Verification of Data Authenticity in all versions up to, and including, 2.= 3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler se= lecting its PayPal validation endpoint from the attacker-controlled `$_REQU= EST['test_ipn']` parameter, force-upgrading any `pending` transaction to `c= ompleted` when `test_ipn=3D1`, and omitting post-verification checks on `re= ceiver_email`, `mc_currency`, and `txn_id` uniqueness after receiving a `VE= RIFIED` response from PayPal. This makes it possible for unauthenticated at= tackers to mark arbitrary hotel bookings as fully paid without submitting g= enuine payment to the merchant - either by routing IPN validation through P= ayPal's sandbox using a free sandbox account, or by replaying a previously = verified IPN from a nominal payment to an attacker-controlled PayPal accoun=
t. An attacker requires only a free PayPal sandbox account (or any PayPal a= ccount) to obtain a `VERIFIED` response; no site credentials or special con= figuration are needed.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11901" target=3D= "_blank" rel=3D"noopener">CVE-2026-11901</a></td>
</tr>
<td class=3D"vendor-product">thrivedesk--Agentic Help Desk Plugin for WordP= ress Live Chat, AI Chatbot & Ticketing ThriveDesk</td>
<td>The ThriveDesk - Live Chat, AI Chatbot, Helpdesk & Knowledge Base p= lugin for WordPress is vulnerable to unauthorized cache deletion due to a m= issing capability check on the 'thrivedesk_clear_cache' AJAX action in all = versions up to, and including, 2.1.7. This makes it possible for authentica= ted attackers, with Subscriber-level access and above, to clear the plugin'=
s cache.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1832" target=3D"= _blank" rel=3D"noopener">CVE-2026-1832</a></td>
</tr>
<td class=3D"vendor-product">tibouille--Sudoku Shortcode</td>
<td>The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross= -Site Scripting via the 'background' parameter in the 'sudoku-sc' shortcode=
in all versions up to, and including, 1.0.0 due to insufficient input sani= tization and output escaping. This makes it possible for authenticated atta= ckers, with Contributor-level access and above, to inject arbitrary web scr= ipts in pages that will execute whenever a user accesses an injected page.<=
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15292" target=3D= "_blank" rel=3D"noopener">CVE-2026-15292</a></td>
</tr>
<td class=3D"vendor-product">timstrifler--Exclusive Addons for Elementor</t=
<td>The Exclusive Addons for Elementor plugin for WordPress is vulnerable t=
o Stored Cross-Site Scripting via the post title parameter in all versions =
up to, and including, 2.7.9.8 due to insufficient input sanitization and ou= tput escaping. This makes it possible for authenticated attackers, with Con= tributor-level access and above, to inject arbitrary web scripts in pages t= hat will execute whenever a user accesses an injected page.</td> <td>2026-07-07</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11328" target=3D= "_blank" rel=3D"noopener">CVE-2026-11328</a></td>
</tr>
<td class=3D"vendor-product">tokenoftrust--Age Verification & Identity = Verification by Token of Trust</td>
<td>The Age Verification & Identity Verification by Token of Trust plug=
in for WordPress is vulnerable to unauthorized access in all versions up to=
and including 4.0.2. This is due to the handle_export_table() function bei=
ng registered on the WordPress 'init' hook, which fires for all requests, i= ncluding those from unauthenticated visitors, without any capability check.=
This makes it possible for unauthenticated attackers to download a CSV fil=
e containing sensitive WooCommerce donation data, including order dates, or= der IDs, charitable donation amounts, and admin-only order edit URLs, simpl=
y by visiting any page on the site with the 'tot_export_table' GET paramete=
r set to a numeric value (0-3).</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7558" target=3D"= _blank" rel=3D"noopener">CVE-2026-7558</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet is an open-source low-code platform for building internal tools=
. Prior to 3.20.180, ToolJet's render preview deployment workflow interpola= tes github.event.comment.body directly into a bash conditional in a run ste=
p, allowing any GitHub user who can comment on an open pull request with a = deploy command to execute shell commands on the CI runner and exfiltrate de= ployment secrets. This issue is reported as fixed in version 3.20.180.</td> <td>2026-07-08</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54344" target=3D= "_blank" rel=3D"noopener">CVE-2026-54344</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--X5000R</td>
<td>A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/= 9.1.0cu.2350_B20230313. Affected by this vulnerability is the function expo= rtOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export=
. The manipulation results in path traversal. The attack may be launched re= motely.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15204" target=3D= "_blank" rel=3D"noopener">CVE-2026-15204</a></td>
</tr>
<td class=3D"vendor-product">TRENDnet--TEW-821DAP</td>
<td>A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted elem= ent is the function sub_43F2C4 of the file /goform/tools_nslookup of the co= mponent DNS Lookup Handler. This manipulation of the argument nslookup_targ= et/dns_server causes os command injection. The attack can be initiated remo= tely. The vendor explains: "We are unable to confirm the existence of the v= ulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "=
This vulnerability only affects products that are no longer supported by t=
he maintainer.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15485" target=3D= "_blank" rel=3D"noopener">CVE-2026-15485</a></td>
</tr>
<td class=3D"vendor-product">TRENDnet--TEW-821DAP</td>
<td>A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This aff= ects the function sub_42026C of the file /goform/tools_ddns of the componen=
t Firmware Update Handler. Such manipulation of the argument hostname/usern= ame/password leads to os command injection. The attack can be launched remo= tely. The vendor explains: "We are unable to confirm the existence of the v= ulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. "=
This vulnerability only affects products that are no longer supported by t=
he maintainer.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15486" target=3D= "_blank" rel=3D"noopener">CVE-2026-15486</a></td>
</tr>
<td class=3D"vendor-product">TRENDnet--TEW-821DAP</td>
<td>A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts = the function sub_41FBD0 of the file /goform/system_ntp of the component Fir= mware Update Handler. Performing a manipulation of the argument Hostname re= sults in os command injection. The attack may be initiated remotely. The ve= ndor explains: "We are unable to confirm the existence of the vulnerabiliti=
es for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulner= ability only affects products that are no longer supported by the maintaine= r.</td>
<td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15487" target=3D= "_blank" rel=3D"noopener">CVE-2026-15487</a></td>
</tr>
<td class=3D"vendor-product">trustindex--Widgets for Google Reviews</td> <td>The Widgets for Google Reviews plugin for WordPress is vulnerable to St= ored Cross-Site Scripting via admin settings in all versions up to, and inc= luding, 13.3 due to insufficient input sanitization and output escaping. Th=
is makes it possible for authenticated attackers, with editor-level permiss= ions and above, to inject arbitrary web scripts in pages that will execute = whenever a user accesses an injected page. This only affects multi-site ins= tallations and installations where unfiltered_html has been disabled.</td> <td>2026-07-11</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11591" target=3D= "_blank" rel=3D"noopener">CVE-2026-11591</a></td>
</tr>
<td class=3D"vendor-product">TryGhost--Ghost</td>
<td>Ghost is a Node.js content management system. From 6.27.0 before 6.44.0=
, Ghost's public donation checkout flow allowed an unauthenticated attacker=
to control donation checkout metadata and obtain full paid gift membership=
s for a minimal payment without exposing customer or member data or stealin=
g money from a site or its members. This issue is fixed in version 6.44.0.<=
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59817" target=3D= "_blank" rel=3D"noopener">CVE-2026-59817</a></td>
</tr>
<td class=3D"vendor-product">tumf--mcp-text-editor</td>
<td>A security vulnerability has been detected in tumf mcp-text-editor up t=
o 1.0.2. This issue affects the function _validate_file_path of the file mc= p_text_editor/text_editor.py. Such manipulation of the argument file_path l= eads to path traversal. The attack can be launched remotely. The exploit ha=
s been disclosed publicly and may be used. The vendor closed the GitHub iss=
ue for this vulnerability without any explanation.</td>
<td>2026-07-09</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15138" target=3D= "_blank" rel=3D"noopener">CVE-2026-15138</a></td>
</tr>
<td class=3D"vendor-product">Twiser Informatics Technology Consulting, Trad=
e and Education Inc.--OKRs & Goals</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Twiser Informatics Technology Consulting, Tr= ade and Education Inc. OKRs & Goals allows Stored XSS. This issue affec=
ts OKRs & Goals: from 28220 before 28398.</td>
<td>2026-07-09</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5005" target=3D"= _blank" rel=3D"noopener">CVE-2026-5005</a></td>
</tr>
<td class=3D"vendor-product">u-boot--u-boot</td>
<td>U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability=
in tcp_rx_state_machine() (net/tcp.c) when CONFIG_PROT_TCP is enabled, all= owing remote attackers to read beyond TCP segment boundaries by crafting a = malicious packet with a mismatched IP total length and TCP data offset fiel=
d. Attackers can send a packet with an IP total length of 40 bytes and a TC=
P data offset claiming 60 bytes of header to cause tcp_parse_options() to r= ead 40 bytes past the end of the TCP segment, potentially corrupting connec= tion state variables such as rmt_win_scale and rmt_timestamp to disrupt TCP=
window calculations.</td>
<td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-29007" target=3D= "_blank" rel=3D"noopener">CVE-2026-29007</a></td>
</tr>
<td class=3D"vendor-product">videousermanuals--White Label CMS</td>
<td>The White Label CMS plugin for WordPress is vulnerable to Stored Cross-= Site Scripting via admin settings in all versions up to, and including, 2.7= .12 due to insufficient input sanitization and output escaping. This makes =
it possible for authenticated attackers, with administrator-level permissio=
ns and above, to inject arbitrary web scripts in pages that will execute wh= enever a user accesses an injected page. This only affects multi-site insta= llations and installations where unfiltered_html has been disabled.</td> <td>2026-07-11</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11898" target=3D= "_blank" rel=3D"noopener">CVE-2026-11898</a></td>
</tr>
<td class=3D"vendor-product">Vinchin--Backup & Recovery 9.0</td> <td>Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffe=
r overflow vulnerability that allows unauthenticated remote attackers to ca= use process crash or memory corruption by sending a malformed TCP packet wi=
th an unchecked body_len field to the agentlink_server service. Attackers c=
an craft a malicious packet that passes an attacker-controlled length direc= tly to recv(), triggering a heap overflow of up to approximately 4 GiB and = resulting in process crash or potential memory corruption.</td> <td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60094" target=3D= "_blank" rel=3D"noopener">CVE-2026-60094</a></td>
</tr>
<td class=3D"vendor-product">Vinchin--Backup & Recovery 9.0</td> <td>Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buff=
er overflow vulnerability in the ModuleHandShake function of the agentlink_= server service that allows unauthenticated remote attackers to overwrite th=
e saved return address by supplying an oversized _listen_uuid field that is=
measured via strlen() and copied without bounds checking into a fixed-leng=
th stack buffer using strcpy(). Attackers can send a crafted request with a=
malicious _listen_uuid value to corrupt the stack and achieve process cras=
h or potential control flow hijack without requiring authentication.</td> <td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60095" target=3D= "_blank" rel=3D"noopener">CVE-2026-60095</a></td>
</tr>
<td class=3D"vendor-product">vllm-project--vllm</td>
<td>vLLM is an inference and serving engine for large language models. From=
0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations = routes call request.file.read() to fully materialize an uploaded audio file=
into memory before vLLM checks the documented VLLM_MAX_AUDIO_CLIP_FILESIZE= _MB compressed upload size limit (default 25 MB) later in the speech-to-tex=
t preprocessing step, so an API caller who can reach those routes can submi=
t an oversized multipart upload and cause vLLM to allocate memory proportio= nal to the uploaded file size before the request is rejected as too large, = creating memory pressure or terminating the process depending on deployment=
resource limits. This issue is fixed in version 0.24.0.</td> <td>2026-07-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55646" target=3D= "_blank" rel=3D"noopener">CVE-2026-55646</a></td>
</tr>
<td class=3D"vendor-product">vxcontrol--PentAGI</td>
<td>A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This a= ffects an unknown function of the file backend/pkg/docker/client.go of the = component Docker API. The manipulation leads to sandbox issue. The attack m=
ay be initiated remotely. The pull request to fix this issue awaits accepta= nce.</td>
<td>2026-07-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14784" target=3D= "_blank" rel=3D"noopener">CVE-2026-14784</a></td>
</tr>
<td class=3D"vendor-product">Wavlink--WL-NU516U1</td>
<td>A security flaw has been discovered in Wavlink WL-NU516U1 260515. This = affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Perf= orming a manipulation of the argument lan_ip results in os command injectio=
n. The attack can be initiated remotely. The exploit has been released to t=
he public and may be used for attacks. You should upgrade the affected comp= onent. The vendor was contacted early, responded in a very professional man= ner and quickly released a fixed version of the affected product.</td> <td>2026-07-12</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15513" target=3D= "_blank" rel=3D"noopener">CVE-2026-15513</a></td>
</tr>
<td class=3D"vendor-product">Wazuh--Wazuh</td>
<td>Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer derefer= ence vulnerability in inventory_sync FlatBuffer DataValue handling. An enro= lled agent can send a verifier-valid DataValue message omitting the optiona=
l id field, causing wazuh-modulesd to crash when dereferencing data->id(= )->string_view() without null validation, resulting in denial of service= .</td>
<td>2026-07-08</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56401" target=3D= "_blank" rel=3D"noopener">CVE-2026-56401</a></td>
</tr>
<td class=3D"vendor-product">wclovers--WCFM Frontend Manager for WooCommerc= e</td>
<td>The WCFM - Frontend Manager for WooCommerce plugin for WordPress is vul= nerable to authorization bypass in all versions up to, and including, 6.7.2=
7. This is due to the plugin not properly verifying that a user is authoriz=
ed to perform an action. This makes it possible for unauthenticated attacke=
rs to inject arbitrary reply content into any store inquiry, overwrite the = main inquiry record in wp_wcfm_enquiries, and trigger unsolicited notificat= ion emails to customers and vendors. Unlike sibling controller branches (wc= fm-enquiry and wcfm-enquiry-manage), the wcfm-my-account-enquiry-manage bra= nch performs no is_user_logged_in() or current_user_can() check, and the no= nce that serves as the sole barrier is embedded into every public page load=
without any login gate.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12994" target=3D= "_blank" rel=3D"noopener">CVE-2026-12994</a></td>
</tr>
<td class=3D"vendor-product">wclovers--WCFM Frontend Manager for WooCommerc= e</td>
<td>The WCFM - Frontend Manager for WooCommerce plugin for WordPress is vul= nerable to Insecure Direct Object Reference in all versions up to, and incl= uding, 6.7.27 via the wcfm_product_archive due to missing validation on a u= ser controlled key. This makes it possible for authenticated attackers, wit=
h subscriber-level access and above, to archive arbitrary vendors' products=
, toggle the featured status on arbitrary listings, mark arbitrary WooComme= rce orders as completed, and permanently delete arbitrary enquiries and bul=
k messages belonging to other vendors.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10041" target=3D= "_blank" rel=3D"noopener">CVE-2026-10041</a></td>
</tr>
<td class=3D"vendor-product">wclovers--WCFM Marketplace Multivendor Marketp= lace for WooCommerce</td>
<td>The WCFM Marketplace - Multivendor Marketplace for WooCommerce plugin f=
or WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'p= ost_title' in all versions up to, and including, 3.7.3 due to insufficient = input sanitization and output escaping. This makes it possible for authenti= cated attackers, with Vendor-level access and above, to inject arbitrary we=
b scripts in pages that will execute whenever a user accesses an injected p= age. An attacker can plant the payload by uploading a media attachment with=
a crafted title via the WordPress REST API (/wp-json/wp/v2/media), without=
ever invoking the AJAX endpoint themselves, as the unescaped title is late=
r emitted inside DataTables JSON and inserted as innerHTML upon any privile= ged user loading the media dashboard.</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12126" target=3D= "_blank" rel=3D"noopener">CVE-2026-12126</a></td>
</tr>
<td class=3D"vendor-product">wealcoder--Animation Addons for Elementor GSAP=
Motion Elementor Addons & Website Templates</td>
<td>The Animation Addons for Elementor plugin for WordPress is vulnerable t=
o Stored Cross-Site Scripting via the 'weather_style' and 'move_direction' = parameters of the Weather widget in all versions up to, and including, 2.6.=
3. This is due to insufficient output escaping in the Weather widget's rend= er() function at widgets/weather.php:1246, where both settings values are p= laced into an HTML class attribute without esc_attr(). Elementor does not s= erver-side validate widget SELECT control values against allowed options on=
save, so an authenticated attacker with Contributor-level access or above = can submit a crafted save_builder AJAX request storing arbitrary values in = the _elementor_data post meta. The stored payload renders unescaped on ever=
y frontend visit to the affected page (the Weather widget requires an OpenW= eatherMap API key to reach the vulnerable output, which is the normal opera= tional state for sites using this widget).</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15299" target=3D= "_blank" rel=3D"noopener">CVE-2026-15299</a></td>
</tr>
<td class=3D"vendor-product">web-infra-dev--midscene</td>
<td>Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contain=
s a missing authentication and CORS misconfiguration vulnerability that all= ows unauthenticated remote attackers to hijack active bridge sessions by op= ening a cross-origin WebSocket connection to the local Socket.IO server, wh= ich performs no Origin header validation and requires no authentication tok= en. Attackers can connect from any web page visited by the victim to seize = the single-client slot, intercept and inject automation commands, exfiltrat=
e command-payload data, or unconditionally terminate the server by supplyin=
g the MIDSCENE_BRIDGE_SIGNAL_KILL query parameter.</td>
<td>2026-07-08</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59804" target=3D= "_blank" rel=3D"noopener">CVE-2026-59804</a></td>
</tr>
<td class=3D"vendor-product">webaways--NEX-Forms Ultimate Forms Plugin for = WordPress</td>
<td>The NEX-Forms - Ultimate Forms Plugin for WordPress plugin for WordPres=
s is vulnerable to authorization bypass in all versions up to, and includin=
g, 9.2.2. This is due to the plugin not properly verifying that a user is a= uthorized to perform an action. This makes it possible for unauthenticated = attackers to overwrite the saved_admin_email, saved_user_email, and saved_u= ser_email_address fields of arbitrary form entries belonging to other users=
, and cause the site to dispatch attacker-controlled email content to attac= ker-chosen recipient addresses.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9017" target=3D"= _blank" rel=3D"noopener">CVE-2026-9017</a></td>
</tr>
<td class=3D"vendor-product">Webbeyaz Web Design--Medikm Web</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Webbeyaz Web Design Medik=C3=83=C2=BCm Web a= llows Reflected XSS. This issue affects Medik=C3=83=C2=BCm Web: through 080= 72026.=C2=A0NOTE: The vendor was contacted and it was learned that the prod= uct is not supported.</td>
<td>2026-07-08</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8310" target=3D"= _blank" rel=3D"noopener">CVE-2026-8310</a></td>
</tr>
<td class=3D"vendor-product">Webbeyaz Web Design--Medikm Web</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Webbeyaz Web Design Medik=C3=83=C2=BCm Web a= llows Stored XSS. This issue affects Medik=C3=83=C2=BCm Web: through 080720= 26.=C2=A0NOTE: The vendor was contacted and it was learned that the product=
is not supported.</td>
<td>2026-07-08</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8315" target=3D"= _blank" rel=3D"noopener">CVE-2026-8315</a></td>
</tr>
<td class=3D"vendor-product">WebFactory--Under Construction Page (Pro)</td> <td>The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arb= itrary File Read in all versions up to, and including, 5.76. This is due to=
the plugin accepting arbitrary local file paths in the template_thumbnail = parameter and copying their contents into a publicly accessible uploads fil=
e. This makes it possible for authenticated attackers, with Subscriber-leve=
l access and above, to read arbitrary files on the server, which can contai=
n sensitive information.</td>
<td>2026-07-11</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11426" target=3D= "_blank" rel=3D"noopener">CVE-2026-11426</a></td>
</tr>
<td class=3D"vendor-product">Webkul--Bagisto</td>
<td>Bagisto before 2.4.4 contains a stored cross-site scripting vulnerabili=
ty via client-side template injection that allows unauthenticated attackers=
to execute arbitrary JavaScript in administrator browsers by registering a=
customer account with malicious payload in the first or last name field. T=
he create.blade.php template renders customer name fields without the Vue.j=
s v-pre directive, causing Vue.js to evaluate stored template expressions a=
s live JavaScript when an administrator opens the Create Order page for the=
affected customer.</td>
<td>2026-07-09</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60120" target=3D= "_blank" rel=3D"noopener">CVE-2026-60120</a></td>
</tr>
<td class=3D"vendor-product">Webremium Istanbul Web Design--Mezunum Satiyor= um</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyo= rum allows Stored XSS. This issue affects Mezunum Satiyorum: from 1.2.504 t= hrough 10072026.=C2=A0NOTE: The vendor was contacted early about this discl= osure but did not respond in any way.</td>
<td>2026-07-10</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3251" target=3D"= _blank" rel=3D"noopener">CVE-2026-3251</a></td>
</tr>
<td class=3D"vendor-product">wedevs--ERP: Complete HR, Accounting & CRM=
Suite Built for WooCommerce</td>
<td>The ERP: Complete HR, Accounting & CRM Suite with Recruitment and W= ooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL In= jection via the 'orderby' parameter in all versions up to, and including, 1= .17.5 due to insufficient escaping on the user supplied parameter and lack =
of sufficient preparation on the existing SQL query. This makes it possible=
for authenticated attackers, with custom-level access and above, to append=
additional SQL queries into already existing queries that can be used to e= xtract sensitive information from the database. Exploitation requires the e= rp_list_employee capability, which is granted to HR Manager-level users and=
above within the WP ERP plugin.</td>
<td>2026-07-09</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13011" target=3D= "_blank" rel=3D"noopener">CVE-2026-13011</a></td>
</tr>
<td class=3D"vendor-product">wedevs--User Frontend: AI Powered Frontend Pos= ting, User Directory, Profile Builder, Membership & User Registration</=
<td>The User Frontend: AI Powered Frontend Posting, User Directory, Profile=
, Membership & User Registration plugin for WordPress is vulnerable to = authorization bypass in all versions up to, and including, 4.3.7. This is d=
ue to the plugin not properly verifying that a user is authorized to perfor=
m an action. This makes it possible for unauthenticated attackers to delete=
arbitrary media attachments whose post_author is 0, such as guest and regi= stration-form uploads, via the wpuf_file_del AJAX action. This is exploitab=
le by unauthenticated visitors on any site where a WPUF shortcode is render=
ed on a front-end page, as this causes the valid wpuf_nonce value to be loc= alized into publicly accessible JavaScript objects (wpuf_upload and wpuf_fr= ontend), satisfying the sole access control gate.</td>
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12406" target=3D= "_blank" rel=3D"noopener">CVE-2026-12406</a></td>
</tr>
<td class=3D"vendor-product">wedevs--User Frontend: AI Powered Frontend Pos= ting, User Directory, Profile Builder, Membership & User Registration</=
<td>The User Frontend: AI Powered Frontend Posting, User Directory, Profile=
, Membership & User Registration plugin for WordPress is vulnerable to = Insecure Direct Object Reference in all versions up to, and including, 4.3.=
7 via the 'wpuf_files_data' parameter due to missing validation on a user c= ontrolled key. This makes it possible for unauthenticated attackers to over= write the post_title, post_content, and post_excerpt of any arbitrary post =
on the site, including posts authored by administrators. Exploitation requi= res access to any WPUF post submission form; this is achievable by users wi=
th no WordPress role, as the wpuf_submit_post AJAX action is gated only by =
a nonce with no capability check for the downstream post-edit operation.</t=
<td>2026-07-09</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12418" target=3D= "_blank" rel=3D"noopener">CVE-2026-12418</a></td>
</tr>
<td class=3D"vendor-product">wedevs--User Frontend: AI Powered Frontend Pos= ting, User Directory, Profile Builder, Membership & User Registration</=
<td>The User Frontend: AI Powered Frontend Posting, User Directory, Profile=
, Membership & User Registration plugin for WordPress is vulnerable to = Insecure Direct Object Reference in all versions up to, and including, 4.3.=
1 via the payment_page() function due to missing validation on the 'user_id=
' user controlled key. This makes it possible for unauthenticated attackers=
to activate a free subscription pack for any user on the site, overwriting=
their existing paid subscription and causing loss of paid features.</td> <td>2026-07-08</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5459" target=3D"= _blank" rel=3D"noopener">CVE-2026-5459</a></td>
</tr>
<td class=3D"vendor-product">wekan--wekan</td>
<td>Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has=
a cross-board authorization bypass in the direct Meteor collection allow r= ules for Checklists and ChecklistItems because updates are authorized only = against the current source doc.cardId and do not inspect the destination ca= rdId or boardId in the update modifier, allowing a low-privileged authentic= ated user with write access to one board and knowledge of a target private = card id to create checklist data on an accessible card and move it into a p= rivate board where they are not a member. This issue is fixed in version 9.= 64.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59154" target=3D= "_blank" rel=3D"noopener">CVE-2026-59154</a></td>
</tr>
<td class=3D"vendor-product">widgetpack--Reviews Widgets for Google, TripAd= visor, Yelp & Recommendations</td>
<td>The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordP= ress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortco=
de attribute of the [fbrev] shortcode in versions up to and including 2.7.3=
. This is due to insufficient input sanitization and output escaping in the=
Feed_Shortcode::fbrev() method, which passes the raw shortcode attribute t= hrough Feed_Old::get_feed() into the View::render() method, where it is ech= oed directly into the data-id HTML attribute without esc_attr(). This makes=
it possible for authenticated attackers, with contributor-level access and=
above, to inject arbitrary web scripts in pages that will execute whenever=
a user accesses an injected page.</td>
<td>2026-07-06</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12154" target=3D= "_blank" rel=3D"noopener">CVE-2026-12154</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--ciscodump</td>
<td>Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of = service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15164" target=3D= "_blank" rel=3D"noopener">CVE-2026-15164</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 = and 4.4.0 to 4.4.16 allow denial of service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15163" target=3D= "_blank" rel=3D"noopener">CVE-2026-15163</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of se= rvice</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15165" target=3D= "_blank" rel=3D"noopener">CVE-2026-15165</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.= 4.0 to 4.4.16 allows denial of service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15166" target=3D= "_blank" rel=3D"noopener">CVE-2026-15166</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 =
to 4.4.16 allows denial of service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15169" target=3D= "_blank" rel=3D"noopener">CVE-2026-15169</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 t=
o 4.4.16 allows denial of service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15170" target=3D= "_blank" rel=3D"noopener">CVE-2026-15170</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4= .4.16 allows denial of service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15171" target=3D= "_blank" rel=3D"noopener">CVE-2026-15171</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td> <td>FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4=
.0 to 4.4.16 allows denial of service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15172" target=3D= "_blank" rel=3D"noopener">CVE-2026-15172</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 a=
nd 4.4.0 to 4.4.16 allows denial of service</td>
<td>2026-07-08</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15174" target=3D= "_blank" rel=3D"noopener">CVE-2026-15174</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of s= ervice</td>
<td>2026-07-08</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15173" target=3D= "_blank" rel=3D"noopener">CVE-2026-15173</a></td>
</tr>
<td class=3D"vendor-product">wpdevart--Booking calendar, Appointment Bookin=
g System</td>
<td>The Booking calendar, Appointment Booking System plugin for WordPress i=
s vulnerable to time-based SQL Injection via the 'wpdevart_id' parameter in=
all versions up to, and including, 3.2.17 due to insufficient escaping on = the user supplied parameter and lack of sufficient preparation on the exist= ing SQL query. This makes it possible for unauthenticated attackers to appe=
nd additional SQL queries into already existing queries that can be used to=
extract sensitive information from the database. In order to exploit the v= ulnerability, the Pro version of the plugin must be installed and activated=
, with the 'Delete previous dates' option checked.</td>
<td>2026-07-10</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15289" target=3D= "_blank" rel=3D"noopener">CVE-2026-15289</a></td>
</tr>
<td class=3D"vendor-product">wpdevteam--BetterDocs AI Documentation, Knowle= dge Base, Docs, Wikis, FAQ with Chatbot</td>
<td>The BetterDocs - AI Documentation, Knowledge Base, Docs, Wikis, FAQ wit=
h Chatbot plugin for WordPress is vulnerable to generic SQL Injection via t=
he 'lang' parameter in all versions up to, and including, 4.6.0 due to insu= fficient escaping on the user supplied parameter and lack of sufficient pre= paration on the existing SQL query. This makes it possible for authenticate=
d attackers, with custom-level access and above, to append additional SQL q= ueries into already existing queries that can be used to extract sensitive = information from the database. Exploitation requires a supported multilingu=
al plugin (WPML, Polylang, qTranslate, Weglot, or TranslatePress) to be act= ive on the site, as the vulnerable code path is gated by Helper::is_multili= ngual_active().</td>
<td>2026-07-10</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15104" target=3D= "_blank" rel=3D"noopener">CVE-2026-15104</a></td>
</tr>
<td class=3D"vendor-product">wpdevteam--Essential Addons for Elementor Popu= lar Elementor Templates & Widgets</td>
<td>The Essential Addons for Elementor - Popular Elementor Templates & = Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting v=
ia the Event Calendar widget in all versions up to, and including, 6.6.2 du=
e to insufficient input sanitization and output escaping on event titles so= urced from The Events Calendar. This makes it possible for authenticated at= tackers, with Author-level access and above, to inject arbitrary web script=
s in pages that will execute whenever a user accesses an injected page.</td=
<td>2026-07-08</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6459" target=3D"= _blank" rel=3D"noopener">CVE-2026-6459</a></td>
</tr>
<td class=3D"vendor-product">wpkuf--Wp Js Detect</td>
<td>The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Reque=
st Forgery in all versions up to, and including, 1.0.9. This is due to miss= ing or incorrect nonce validation on the plugin_settings function. This mak=
es it possible for unauthenticated attackers to update the plugin's notific= ation text and CSS settings (wp_non_js_notification_text and wp_non_js_noti= fication_css), injecting arbitrary content that is echoed unescaped on the = frontend via a forged request granted they can trick a site administrator i= nto performing an action such as clicking on a link.</td>
<td>2026-07-08</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9731" target=3D"= _blank" rel=3D"noopener">CVE-2026-9731</a></td>
</tr>
<td class=3D"vendor-product">wplegalpages--Cookie Banner for GDPR / CCPA WP=
LP Cookie Consent</td>
<td>The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthori= zed modification of data due to a missing capability check and missing nonc=
e verification on the gdpr_cookie_consent_ajax_save_schedule_scan() functio=
n (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and i= ncluding, 4.3.6. This makes it possible for authenticated attackers, with S= ubscriber-level access and above, to modify the plugin's cookie scan schedu=
le configuration stored in the gdpr_scan_schedule_data option, which is an = administrative function intended to be limited to users with the manage_opt= ions capability.</td>
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12955" target=3D= "_blank" rel=3D"noopener">CVE-2026-12955</a></td>
</tr>
<td class=3D"vendor-product">wplegalpages--Cookie Banner for GDPR / CCPA WP=
LP Cookie Consent</td>
<td>The Cookie Banner for GDPR / CCPA - WPLP Cookie Consent plugin for Word= Press is vulnerable to generic SQL Injection via the 'scan_id' parameter in=
all versions up to, and including, 4.3.6 due to insufficient escaping on t=
he user supplied parameter and lack of sufficient preparation on the existi=
ng SQL query. This makes it possible for authenticated attackers, with admi= nistrator-level access and above, to append additional SQL queries into alr= eady existing queries that can be used to extract sensitive information fro=
m the database.</td>
<td>2026-07-10</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14475" target=3D= "_blank" rel=3D"noopener">CVE-2026-14475</a></td>
</tr>
<td class=3D"vendor-product">wpmanageninja--Fluent Forms Customizable Conta=
ct Forms, Survey, Quiz, & Conversational Form Builder</td>
<td>The Fluent Forms plugin for WordPress is vulnerable to incorrect author= ization via the 'subscription_id' parameter in versions up to, and includin=
g, 6.2.1. This is due to insufficient ownership authorization checks in the=
payment cancellation AJAX flow. This makes it possible for authenticated a= ttackers, with subscriber-level access and above, to submit cancellation re= quests for other users' subscriptions.</td>
<td>2026-07-10</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5069" target=3D"= _blank" rel=3D"noopener">CVE-2026-5069</a></td>
</tr>
<td class=3D"vendor-product">wpovernight--PDF Invoices & Packing Slips = for WooCommerce</td>
<td>The PDF Invoices & Packing Slips for WooCommerce plugin for WordPre=
ss is vulnerable to Insecure Direct Object Reference in all versions up to,=
and including, 5.14.0 via the generate_document_shortcode due to missing v= alidation on a user controlled key. This makes it possible for authenticate=
d attackers, with contributor-level access and above, to mint publicly acce= ssible, session-free download links for arbitrary third-party orders, expos= ing customer names, billing and shipping addresses, email addresses, phone = numbers, order and invoice numbers, line items, totals, payment details, an=
d customer notes contained in those orders' invoices and packing slips. Exp= loitation requires the plugin's Document link access type setting to be con= figured to 'full'; with the default 'logged_in' value, generated URLs are s= igned with a per-session nonce rather than the order_key, making the shortc= ode path unexploitable for unauthorized access to third-party orders.</td> <td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13116" target=3D= "_blank" rel=3D"noopener">CVE-2026-13116</a></td>
</tr>
<td class=3D"vendor-product">wpswings--Points and Rewards for WooCommerce</=
<td>The Points and Rewards for WooCommerce plugin for WordPress is vulnerab=
le to authorization bypass in all versions up to, and including, 2.10.0. Th=
is is due to the plugin not properly verifying that a user is authorized to=
perform an action. This makes it possible for authenticated attackers, wit=
h subscriber-level access and above, to convert and drain any user's reward=
points into wallet balance, exfiltrate all users' emails and point balance=
s to an attacker-controlled Klaviyo account, overwrite the site's Klaviyo p= ublic API key, block or unblock arbitrary users from the points system, and=
modify campaign banner and heading settings. The nonce used for authentica= tion of these requests (wps-wpr-verify-nonce) is injected into every public= -facing page via wp_localize_script(), and the wps_wpr_generate_custom_wall=
et handler is additionally registered on the wp_ajax_nopriv_ hook, meaning = unauthenticated visitors can also obtain a valid nonce and exploit that spe= cific action.</td>
<td>2026-07-11</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10628" target=3D= "_blank" rel=3D"noopener">CVE-2026-10628</a></td>
</tr>
<td class=3D"vendor-product">wpvividplugins--WPvivid Backup for MainWP</td> <td>The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Sto= red Cross-Site Scripting via admin settings in all versions up to, and incl= uding, 0.9.33 due to insufficient input sanitization and output escaping. T= his makes it possible for authenticated attackers, with administrator-level=
permissions and above, to inject arbitrary web scripts in pages that will = execute whenever a user accesses an injected page. This only affects multi-= site installations and installations where unfiltered_html has been disable= d.</td>
<td>2026-07-10</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15283" target=3D= "_blank" rel=3D"noopener">CVE-2026-15283</a></td>
</tr>
<td class=3D"vendor-product">wpxpo--Post Grid Gutenberg Blocks PostX</td> <td>The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Si=
te Scripting via the 'moreResultsText' block attribute of the ultimate-post= /advanced-search block in versions up to and including 5.0.31. This is due =
to insufficient input sanitization and output escaping in the Advanced_Sear= ch::content() render callback: the attribute value is filtered with wp_kses= (), which strips disallowed HTML tags but does NOT escape HTML special char= acters such as double quotes in plain text, and the result is then concaten= ated directly into the data-viewmoretext HTML attribute without esc_attr().=
This makes it possible for authenticated attackers, with contributor-level=
access and above, to inject arbitrary web scripts in pages that will execu=
te whenever a user accesses an injected page.</td>
<td>2026-07-09</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13253" target=3D= "_blank" rel=3D"noopener">CVE-2026-13253</a></td>
</tr>
<td class=3D"vendor-product">WSO2--WSO2 Identity Server</td>
<td>The software accepts user-supplied input via a URL parameter without ad= equate output encoding before reflecting it back to the user's browser. Thi=
s condition allows an attacker to inject malicious script content into page=
s served by the application. By leveraging this weakness, an attacker can c= ause the user's browser to redirect to a malicious website, modify the UI o=
f the webpage, or retrieve information from the browser. However, the impac=
t is mitigated by the use of httpOnly flags on session-related cookies, pre= venting session hijacking.</td>
<td>2026-07-06</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-8591" target=3D"= _blank" rel=3D"noopener">CVE-2025-8591</a></td>
</tr>
<td class=3D"vendor-product">wupsales--AI Copilot Content Generator</td> <td>The AI Chatbot & Workflow Automation by AIWU plugin for WordPress i=
s vulnerable to Missing Authorization in all versions up to, and including,=
1.4.12. This is due to missing capability checks and nonce verification on=
AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as = the base controller's getPermissions() returns an empty array and neither r= emoveGroup nor clear are added to getNoncedMethods(), causing the authoriza= tion gate to unconditionally return true for these actions. This makes it p= ossible for unauthenticated attackers to delete specific records by ID or d= elete all records from any module's database table by unauthenticated attac= kers.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6803" target=3D"= _blank" rel=3D"noopener">CVE-2026-6803</a></td>
</tr>
<td class=3D"vendor-product">wupsales--AI Copilot Content Generator</td> <td>The AI Chatbot & Workflow Automation by AIWU plugin for WordPress i=
s vulnerable to authorization bypass in all versions up to, and including, = 1.4.12. This is due to the plugin not properly verifying that a user is aut= horized to perform an action. This makes it possible for unauthenticated at= tackers to publish draft WordPress posts, exposing unpublished content, or = unpublish live content, causing service disruption, by supplying arbitrary = scenario IDs.</td>
<td>2026-07-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6804" target=3D"= _blank" rel=3D"noopener">CVE-2026-6804</a></td>
</tr>
<td class=3D"vendor-product">YzmCMS--YzmCMS</td>
<td>A security vulnerability has been detected in YzmCMS up to 7.5. Affecte=
d is the function get_url of the file /yzmphp/yzmphp.php of the component H= eader Handler. The manipulation of the argument HTTP_HOST leads to cross si=
te scripting. The attack may be initiated remotely. The exploit has been di= sclosed publicly and may be used. The vendor was contacted early about this=
disclosure but did not respond in any way.</td>
<td>2026-07-09</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15202" target=3D= "_blank" rel=3D"noopener">CVE-2026-15202</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/a= udio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State d= ata into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE= _LEN =3D 512 bytes) shared by all connection instances, while the BUSY flag=
, long-read handle, and reset/offset state were per-connection. When the de= vice acts as a Broadcast Assistant connected to multiple Scan Delegator per= ipherals, notification and long-read callbacks from different connections i= nterleave on the shared buffer: the append in notify_handler (net_buf_simpl= e_add_mem at the not-busy branch) performs no tailroom check, so receive-st= ate notifications from two or more delegators accumulate on the same 512-by=
te buffer and, with a sufficiently large configured ATT MTU (BT_L2CAP_TX_MT=
U up to 2000) and two-to-three concurrent connections, write past the buffe=
r into adjacent .bss (net_buf_simple_add only asserts in debug builds). Eve=
n below the overflow threshold, one connection's net_buf_simple_reset zeroe=
s the shared length while another connection's reassembly and GATT read off= set are in flight, mixing one peer's data into another's parse. A malicious=
or compromised Scan Delegator (or two colluding peers) over BLE can trigge=
r this, causing out-of-bounds writes (memory corruption / denial of service=
) and cross-connection data corruption. The fix moves the buffer into the p= er-connection instance struct so each connection reassembles into its own b= uffer. Affects Zephyr releases shipping the Broadcast Assistant with the sh= ared buffer, including v4.4.0 and earlier.</td>
<td>2026-07-11</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10660" target=3D= "_blank" rel=3D"noopener">CVE-2026-10660</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_d= evice_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_devic=
e slab object without clearing the cached pointer ctx->root. The bus rem= oval handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides wh=
at to tear down solely from ctx->root, checking only that it is non-NULL=
. Because UHC controller drivers (e.g. uhc_max3421e, uhc_mcux_common) synth= esize UHC_EVT_DEV_REMOVED directly from physical bus line state with no deb= ounce or state guard, an attacker with physical USB access (or a rogue devi=
ce that bounces its connection) can deliver a second device-removed event a= fter a root device disconnect. The handler then re-enters usbh_device_disco= nnect() with the dangling pointer, locking a mutex inside the freed object = (use-after-free), removing the freed node from the device list, and calling=
k_mem_slab_free() on the already-freed block (double-free). If the slab bl= ock has been reissued to a newly attached device in between, this corrupts =
a live object. Impact is denial of service (crash) and memory corruption; t=
he attack vector is physical/local. The flaw was introduced in v4.4.0 by th=
e connect/disconnect refactor and is fixed by clearing ctx->root in usbh= _device_disconnect() before freeing.</td>
<td>2026-07-12</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10663" target=3D= "_blank" rel=3D"noopener">CVE-2026-10663</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_g= et_power_save_info() in drivers/wifi/nrf_wifi/src/wifi_mgmt.c copied TWT (T= arget Wake Time) flow entries from an nrf_wifi_umac_event_power_save_info e= vent into the fixed-size twt_flows[WIFI_MAX_TWT_FLOWS] (8-element) array of=
a caller-supplied struct wifi_ps_config, looping over event-provided num_t= wt_flows without validating it against WIFI_MAX_TWT_FLOWS or checking event= _len. When num_twt_flows exceeds 8, the handler writes past the destination=
array (which is typically on the caller's stack, e.g. the wifi ps shell co= mmand) -- an out-of-bounds write of ~40-byte TWT entries -- and reads twt_f= low_info[i] past the event buffer. The event is delivered by the nRF70 co-p= rocessor firmware in response to a host-initiated power-save GET, so reachi=
ng the overflow requires the firmware to emit a malformed or out-of-range e= vent; the trust boundary is host-to-trusted-coprocessor rather than a direc=
t remote-AP write, with over-the-air influence on the flow count being indi= rect and bounded by the 3-bit TWT flow-id space. Affected: builds with CONF= IG_NRF70_STA_MODE on releases through v4.4.0. The fix rejects events with n= um_twt_flows > WIFI_MAX_TWT_FLOWS or with event_len shorter than the cla= imed entries, and adds a NULL check on the caller buffer.</td> <td>2026-07-12</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10664" target=3D= "_blank" rel=3D"noopener">CVE-2026-10664</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c=
) implemented the dhara_nand_ callbacks so that, on a flash error, the erro=
r code was written unconditionally through the caller-supplied dhara_error_=
t err pointer (e.g. *err =3D DHARA_E_ECC in dhara_nand_read, and similar in=
dhara_nand_erase/prog/copy). The upstream Dhara library calls these callba= cks with err =3D=3D NULL along its journal-resume binary search: find_last_= checkblock() invokes find_checkblock(j, mid, &found, NULL), which forwa= rds the NULL pointer into dhara_nand_read(). This path runs during disk_ftl= _access_init() -> dhara_map_resume() whenever the FTL disk is mounted/in= itialised. If a flash read error (uncorrectable ECC, bad block, controller = error) occurs on one of the probed checkpoint pages, the driver dereference=
s and writes to NULL, faulting the kernel (denial of service). The trigger =
is conditioned on the NAND medium content/health, which can be influenced b=
y media wear, induced faults, or a corrupted/crafted on-flash image. The fi=
x routes all error assignments through the library's NULL-safe dhara_set_er= ror() helper. Affects Zephyr v4.4.0, where the driver was introduced.</td> <td>2026-07-07</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10659" target=3D= "_blank" rel=3D"noopener">CVE-2026-10659</a></td>
</tr>
<td class=3D"vendor-product">zhayujie--CowAgent</td>
<td>A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. T=
he impacted element is an unknown function of the file channel/channel.py o=
f the component Message Endpoint. The manipulation results in missing autho= rization. The attack may be launched remotely. The exploit has been release=
d to the public and may be used for attacks. The project was informed of th=
e problem early through an issue report but has not responded yet.</td> <td>2026-07-10</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15332" target=3D= "_blank" rel=3D"noopener">CVE-2026-15332</a></td>
</tr>
<td class=3D"vendor-product">zhayujie--CowAgent</td>
<td>A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The af= fected element is the function _add_url/_add_package of the file agent/skil= ls/service.py of the component Skill Installation Handler. The manipulation=
of the argument Name leads to path traversal. The attack may be initiated = remotely. Upgrading to version 2.1.2 is sufficient to fix this issue. The i= dentifier of the patch is e85290cddcbb5ffc9c235927f4c92e5b4c3ec264. It is a= dvisable to upgrade the affected component.</td>
<td>2026-07-10</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15331" target=3D= "_blank" rel=3D"noopener">CVE-2026-15331</a></td>
</tr>
<td class=3D"vendor-product">zhayujie--CowAgent</td>
<td>A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue = affects the function BrowserTool._do_navigate of the file agent/tools/brows= er/browser_tool.py of the component Browser Tool. Performing a manipulation=
results in information disclosure. The attack can be initiated remotely. T=
he exploit has been made public and could be used. The project was informed=
of the problem early through an issue report but has not responded yet.</t=
<td>2026-07-10</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15329" target=3D= "_blank" rel=3D"noopener">CVE-2026-15329</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 3.4.12=
and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's s= ignature and issuer (iss) but not the audience (aud) claim, allowing a vali= dly signed token from a trusted issuer for another relying party to be acce= pted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.</td> <td>2026-07-10</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55669" target=3D= "_blank" rel=3D"noopener">CVE-2026-55669</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 3.4.12=
and 4.15.2, ZITADEL's external JWT Identity Provider validation in interna= l/idp/providers/jwt/session.go skips the maximum token age freshness check = when an incoming token omits the iat claim, allowing arbitrarily old tokens=
from a trusted issuer to pass authentication. This issue is fixed in versi= ons 3.4.12 and 4.15.2.</td>
<td>2026-07-10</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56664" target=3D= "_blank" rel=3D"noopener">CVE-2026-56664</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 3.4.12=
and 4.15.2, ZITADEL is an open source identity management platform. From 3= .0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's exte= rnal JWT Identity Provider validation in internal/idp/providers/jwt/session= .go skips expiration handling when an incoming token omits the exp claim, a= llowing a token from a trusted issuer to be treated as valid without an aut= omatic expiration window. This issue is fixed in versions 3.4.12 and 4.15.2= .</td>
<td>2026-07-10</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56665" target=3D= "_blank" rel=3D"noopener">CVE-2026-56665</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 4.15.3=
, ZITADEL's external identity provider handler checks that the local user's=
email is verified but does not verify that the external IdP confirmed owne= rship of the same email before auto-linking by email, allowing a permissive=
provider account with a victim email address to be linked to the victim's = local account. This issue is fixed in version 4.15.3.</td>
<td>2026-07-10</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56666" target=3D= "_blank" rel=3D"noopener">CVE-2026-56666</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"low_v">
<h2 id=3D"low_v_title">Low Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Low Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">Akpali9--Attendance-Management-System</td>
<td>A vulnerability was detected in Akpali9 Attendance-Management-System up=
to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unkno=
wn processing of the file absent.php. Performing a manipulation of the argu= ment export_date results in cross site scripting. It is possible to initiat=
e the attack remotely. This product is using a rolling release to provide c= ontinious delivery. Therefore, no version details for affected nor updated = releases are available. The vendor was contacted early about this disclosur=
e but did not respond in any way.</td>
<td>2026-07-12</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15493" target=3D= "_blank" rel=3D"noopener">CVE-2026-15493</a></td>
</tr>
<td class=3D"vendor-product">Black Lantern Security--BBOT</td>
<td>BBOT's unarchive module rejects archives containing symlink entries bef= ore extraction, but for zip and 7z archives it failed to detect symlinks wh= ose listing carries a DOS-attribute prefix before the unix mode, as produce=
d by legacy versions of p7zip. Such an archive, downloaded and extracted du= ring a scan (for example via filedownload), bypassed the guard and caused a=
n attacker-controlled symlink to be written into the extraction directory. = The effect is limited to planting the symlink (its target is not written th= rough), and only hosts using such a legacy p7zip build are affected; curren=
t mainline 7-Zip is not.</td>
<td>2026-07-08</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14966" target=3D= "_blank" rel=3D"noopener">CVE-2026-14966</a></td>
</tr>
<td class=3D"vendor-product">Black Lantern Security--BBOT</td>
<td>BBOT's `github_workflows` module could be induced to write a downloaded=
artifact outside its configured output directory: its path-containment che=
ck did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse = out of the intended folder. The write is bounded to two directory levels ab= ove the output location and its target is determined by the operator's conf= iguration, not the attacker.</td>
<td>2026-07-08</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14967" target=3D= "_blank" rel=3D"noopener">CVE-2026-14967</a></td>
</tr>
<td class=3D"vendor-product">body-parser--body-parser</td>
<td>Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2=
.x line), when the parser is configured with an invalid limit option value = such as an unparseable string or NaN, bytes.parse returns null and the requ= est body size check is silently skipped. Applications that rely on limit as=
their primary safeguard against oversized request bodies will accept arbit= rarily large payloads, leading to excessive memory and CPU usage and denial=
of service. Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. = After the fix, invalid limit values throw a clear error at parser construct= ion time instead of silently disabling enforcement, while null and undefine=
d continue to fall back to the default limit of 100kb. Workarounds: Validat=
e the limit value before passing it to body-parser. For example, parse the = value at startup and reject any configuration where the result is null or a=
non-finite number.</td>
<td>2026-07-09</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12590" target=3D= "_blank" rel=3D"noopener">CVE-2026-12590</a></td>
</tr>
<td class=3D"vendor-product">Capgo--Capgo</td>
<td>Capgo before 12.128.2 contains a sql injection vulnerability in the POS=
T /private/admin_stats endpoint where the limit parameter is destructured f= rom unvalidated request body and interpolated directly into Cloudflare Anal= ytics Engine SQL queries via template literals. An attacker with platform a= dmin credentials can inject SQL fragments to enumerate dataset schemas, ext= ract analytics data, or cause denial-of-service against the analytics backe= nd.</td>
<td>2026-07-12</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56281" target=3D= "_blank" rel=3D"noopener">CVE-2026-56281</a></td>
</tr>
<td class=3D"vendor-product">caronc--apprise</td>
<td>Apprise is an open source library which allows you to send a notificati=
on to almost all of the most popular notification services available. Prior=
to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and=
config loaders in apprise/attachment/http.py and apprise/config/http.py fo= llow HTTP redirects by default and resend user-configured auth headers and = query parameters on the redirected request, allowing a compromised trusted = destination or on-path attacker to receive secrets such as Authorization he= aders, bearer tokens, custom headers, and service keys. This issue is fixed=
in version 1.11.0.</td>
<td>2026-07-10</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59180" target=3D= "_blank" rel=3D"noopener">CVE-2026-59180</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, da= tabase backup handling for MongoDB collection names did not fully validate = shell metacharacters, allowing a highly privileged attacker who can configu=
re backup inputs to inject commands. This issue is fixed in version 4.0.0-b= eta.471.</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34049" target=3D= "_blank" rel=3D"noopener">CVE-2026-34049</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob int= erpolates user-controlled database credentials and MongoDB collection exclu= sion names into backup shell commands without adequate escaping, allowing a=
n authenticated user with database management permissions to execute comman=
ds on managed servers. This issue is fixed in version 4.0.0-beta.471.</td> <td>2026-07-07</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34149" target=3D= "_blank" rel=3D"noopener">CVE-2026-34149</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, the file upload endpo= int (app/Http/Controllers/UploadController.php) for database backup restore=
uploads did not enforce file type or size validation, allowing an authenti= cated user to upload unexpected or oversized files that could affect servic=
e availability. This issue is fixed in version 4.0.0-beta.474.</td> <td>2026-07-07</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42145" target=3D= "_blank" rel=3D"noopener">CVE-2026-42145</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage = method in app/Livewire/Settings/Index.php constructs a Docker build command=
using the dev_helper_version field without shell escaping, allowing an att= acker who can set the helper version and trigger the helper image build in =
a development environment to execute arbitrary commands on the server. This=
issue is fixed in version 4.0.0-beta.474.</td>
<td>2026-07-06</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42148" target=3D= "_blank" rel=3D"noopener">CVE-2026-42148</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens di=
d not expire, allowing a leaked token to retain access indefinitely until m= anually revoked. This issue is fixed in version 4.0.0-beta.474.</td> <td>2026-07-07</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42172" target=3D= "_blank" rel=3D"noopener">CVE-2026-42172</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify is an open-source and self-hostable tool for managing servers, = applications, and databases. Prior to 4.0.0-beta.474, database credential f= ields (redis_password, keydb_password, dragonfly_password, clickhouse_admin= _user, clickhouse_admin_password, postgres_user, mysql_user) are validated = only as 'string' at the API layer, with zero shell-safety checks. These val= ues are then interpolated directly into Docker Compose YAML command: string=
s without any escaping. This issue is fixed in version 4.0.0-beta.474.</td> <td>2026-07-07</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42201" target=3D= "_blank" rel=3D"noopener">CVE-2026-42201</a></td>
</tr>
<td class=3D"vendor-product">CoreWCF--CoreWCF</td>
<td>CoreWCF is a port of the service side of Windows Communication Foundati=
on (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.=
0 receive pipeline validates ds:SignedInfo SignatureMethod against the conf= igured SecurityAlgorithmSuite but does not validate each ds:Reference Diges= tMethod, allowing a sender to use a rejected digest algorithm such as SHA-1=
while the message is still accepted. This issue is fixed in versions 1.8.1=
and 1.9.1.</td>
<td>2026-07-08</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54780" target=3D= "_blank" rel=3D"noopener">CVE-2026-54780</a></td>
</tr>
<td class=3D"vendor-product">crater-invoice-inc--crater</td>
<td>A weakness has been identified in crater-invoice-inc crater up to 6.0.6=
. This affects the function getFormattedString of the file app/Http/Request= s/InvoicesRequest.php of the component Invoice Note Handler. Executing a ma= nipulation of the argument notes can lead to cross site scripting. The atta=
ck may be launched remotely. The exploit has been made available to the pub= lic and could be used for attacks. The project was informed of the problem = early through an issue report but has not responded yet.</td> <td>2026-07-06</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14791" target=3D= "_blank" rel=3D"noopener">CVE-2026-14791</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Domain</td>
<td>Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 re= lease version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 thr= ough 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain =
an improper limitation of a pathname to a restricted directory ('path trave= rsal') vulnerability. A high privileged attacker with remote access could p= otentially exploit this vulnerability, leading to unauthorized file modific= ation.</td>
<td>2026-07-08</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53480" target=3D= "_blank" rel=3D"noopener">CVE-2026-53480</a></td>
</tr>
<td class=3D"vendor-product">filebrowser--filebrowser</td>
<td>filebrowser versions before 2.63.17 fail to normalize paths before quer= ying the share index in DeleteWithPathPrefix, allowing authenticated users =
to leave stale public shares behind. Attackers can delete a shared director=
y using a trailing-slash path, then recreate the same directory to expose n=
ew contents through the dormant public share URL.</td>
<td>2026-07-12</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61874" target=3D= "_blank" rel=3D"noopener">CVE-2026-61874</a></td>
</tr>
<td class=3D"vendor-product">Gallagher--Controller 7000 and 6000</td> <td>Uncaught Exception (CWE-248)=C2=A0in the Controller 6000 and Controller=
7000 diagnostic web interface allows an authenticated and authorized opera= tor to trigger a Controller restart by sending specific requests, resulting=
in a temporary denial of service.=C2=A0 Version of Command Centre affected=
: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 pr= ior to vCR9.40.260616a (distributed in=C2=A09.40.3130(MR3)) * 9.30 prior to=
vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.26= 0616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.</td=
<td>2026-07-07</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27844" target=3D= "_blank" rel=3D"noopener">CVE-2026-27844</a></td>
</tr>
<td class=3D"vendor-product">Gallagher--T-20 Readers</td>
<td>Uncaught Exception (CWE-248)=C2=A0in=C2=A0the T20 Readers=C2=A0allows a=
n authenticated and authorized operator to trigger a restart by sending spe= cific requests, resulting in a temporary denial of service.=C2=A0Version of=
Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9= .50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in=C2=A09.40.31= 30(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * = 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all version=
s of 9.10 and prior.</td>
<td>2026-07-07</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27790" target=3D= "_blank" rel=3D"noopener">CVE-2026-27790</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that un= der certain conditions could have allowed an authenticated user to create a=
repository where the content displayed in the web interface differed from = the content available for download, due to improper handling of Git referen=
ce name resolution.</td>
<td>2026-07-08</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-12506" target=3D= "_blank" rel=3D"noopener">CVE-2025-12506</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab EE affecting all versions from=
16.10 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that unde=
r certain conditions could have allowed an authenticated user to modify gro= up-level settings beyond their intended permissions due to improper authori= zation controls.</td>
<td>2026-07-08</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13151" target=3D= "_blank" rel=3D"noopener">CVE-2026-13151</a></td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab EE affecting all versions from=
18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under=
certain conditions could have allowed an authenticated user with auditor-l= evel access to modify compliance violation records due to improper authoriz= ation on certain GraphQL operations.</td>
<td>2026-07-08</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6352" target=3D"= _blank" rel=3D"noopener">CVE-2026-6352</a></td>
</tr>
<td class=3D"vendor-product">GNU--LibreDWG</td>
<td>A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted el= ement is the function dwg_next_entity of the file src/dwg.c of the componen=
t DWG File Handler. Performing a manipulation of the argument next_obj resu= lts in null pointer dereference. The attack must be initiated from a local = position. The exploit has been made public and could be used. Upgrading to = version 0.14 is sufficient to resolve this issue. The patch is named dde45d= ac3c4d902e4d8fed150a8017b9732019c9. Upgrading the affected component is rec= ommended. Different than CVE-2026-9503.</td>
<td>2026-07-09</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15184" target=3D= "_blank" rel=3D"noopener">CVE-2026-15184</a></td>
</tr>
<td class=3D"vendor-product">GPAC--GPAC</td>
<td>A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerabilit=
y affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia= /avc_ext.c of the component MP4Box. This manipulation of the argument nalu_= out_bs causes double free. It is possible to launch the attack on the local=
host. The exploit has been publicly disclosed and may be utilized. Patch n= ame: f29f955f2a3b5e8e507caad3e52319f961bf37bf. To fix this issue, it is rec= ommended to deploy a patch.</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15667" target=3D= "_blank" rel=3D"noopener">CVE-2025-15667</a></td>
</tr>
<td class=3D"vendor-product">GPAC--GPAC</td>
<td>A vulnerability was identified in GPAC up to b40ce70f5. This issue affe= cts the function sgpd_del_entry of the file src/isomedia/box_code_base.c of=
the component MP4Box. Such manipulation of the argument data leads to heap= -based buffer overflow. Local access is required to approach this attack. T=
he exploit is publicly available and might be used. The name of the patch i=
s f29f955f2a3b5e8e507caad3e52319f961bf37bf. It is advisable to implement a = patch to correct this issue.</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15668" target=3D= "_blank" rel=3D"noopener">CVE-2025-15668</a></td>
</tr>
<td class=3D"vendor-product">GPAC--GPAC</td>
<td>A flaw has been found in GPAC 26.02.0. This affects the function nhmldu= mp_send_frame of the file src/filters/write_nhml.c of the component Media F= ile Handler. Executing a manipulation can lead to null pointer dereference.=
The attack requires local access. The exploit has been published and may b=
e used. This patch is called bd1d94e70e3bef364c07c5a1d94eca5c9f56e160. A pa= tch should be applied to remediate this issue. The project explains: "I wou=
ld consider most of these more as bugs than vulns but anyway they're good t=
o fix".</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14790" target=3D= "_blank" rel=3D"noopener">CVE-2026-14790</a></td>
</tr>
<td class=3D"vendor-product">GPAC--GPAC</td>
<td>A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80= 071f700-master. The impacted element is the function txtin_probe_duration o=
f the file src/filters/load_text.c of the component TeXML File Handler. Suc=
h manipulation of the argument txml_timescale leads to divide by zero. An a= ttack has to be approached locally. The name of the patch is 86a5191f2e750c= 767253e27ed6cfd6d547afebc2. A patch should be applied to remediate this iss= ue.</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14801" target=3D= "_blank" rel=3D"noopener">CVE-2026-14801</a></td>
</tr>
<td class=3D"vendor-product">GPAC--GPAC</td>
<td>A vulnerability was determined in GPAC 26.03-DEV. This affects the func= tion vobsub_read_idx of the file /src/media_tools/vobsub.c of the component=
MP4Box. Executing a manipulation of the argument num_langs can lead to out= -of-bounds read. The attack needs to be launched locally. The exploit has b= een publicly disclosed and may be utilized. This patch is called 5320970847= 29a936bcdf6a27c41003f3bd7dc3ff. It is best practice to apply a patch to res= olve this issue. Two different commits were applied to fix this issue.</td> <td>2026-07-09</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15185" target=3D= "_blank" rel=3D"noopener">CVE-2026-15185</a></td>
</tr>
<td class=3D"vendor-product">Grafana--Grafana Enterprise</td>
<td>The public dashboard deletion endpoint does not enforce organization is= olation, allowing an Org Admin in one organization to delete public dashboa= rds belonging to a different organization by supplying the target dashboard=
's identifiers.</td>
<td>2026-07-07</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-28378" target=3D= "_blank" rel=3D"noopener">CVE-2026-28378</a></td>
</tr>
<td class=3D"vendor-product">halo-dev--halo</td>
<td>A vulnerability was identified in halo-dev halo up to 2.24.2. This affe= cts the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the=
component Theme Installation. Such manipulation of the argument metadata.n= ame leads to path traversal. The attack may be launched remotely. The explo=
it is publicly available and might be used. The project closed the issue as=
"duplicate" but did not reference any other issue, report, or CVE.</td> <td>2026-07-10</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15326" target=3D= "_blank" rel=3D"noopener">CVE-2026-15326</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulner= ability in GetPixelIndex caused by OpenPixelCache updating image channel me= tadata before pixel cache memory allocation. Attackers can trigger memory a=
nd disk allocation failures to cause a heap-buffer-overflow read affecting = any writer calling GetPixelIndex.</td>
<td>2026-07-08</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56362" target=3D= "_blank" rel=3D"noopener">CVE-2026-56362</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the=
META reader when processing APP1JPEG input paths. Attackers can trigger th=
is memory leak by providing specially crafted APP1JPEG image files, causing=
denial of service through resource exhaustion.</td>
<td>2026-07-10</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56366" target=3D= "_blank" rel=3D"noopener">CVE-2026-56366</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerabili=
ty in the magnify operation that allows attackers to read out of bounds mem= ory. An unrecognized magnify:method value triggers an out of bounds read, p= otentially exposing sensitive information or causing denial of service.</td=
<td>2026-07-11</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56372" target=3D= "_blank" rel=3D"noopener">CVE-2026-56372</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in = the PDB decoder that uses a stale pointer when memory allocation fails. Att= ackers can trigger this vulnerability by processing malicious PDB files to = cause crashes or write a single zero byte to freed memory.</td> <td>2026-07-10</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56373" target=3D= "_blank" rel=3D"noopener">CVE-2026-56373</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerabili=
ty in the FTXT encoder due to missing boundary checks when parsing ftxt:for= mat. Remote attackers can trigger an out of bounds read by crafting malicio=
us FTXT image files to cause denial of service or information disclosure.</=
<td>2026-07-08</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56374" target=3D= "_blank" rel=3D"noopener">CVE-2026-56374</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the al= lowed memory allocation limit in matrix-backed operations such as -canny. A=
n attacker can supply a crafted image that causes ImageMagick to allocate m= ore memory than permitted by the configured policy, resulting in a denial o=
f service.</td>
<td>2026-07-11</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61465" target=3D= "_blank" rel=3D"noopener">CVE-2026-61465</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerabilit=
y caused by missing null check when parsing XMP profiles. Attackers can cra=
ft malicious image files with specially crafted XMP data to trigger the vul= nerability and cause application crashes.</td>
<td>2026-07-11</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61857" target=3D= "_blank" rel=3D"noopener">CVE-2026-61857</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in t=
he APNG encoder and external delegates due to missing validation checks. At= tackers can write files to disallowed paths by bypassing configured policy = restrictions through the APNG encoding process.</td>
<td>2026-07-11</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61858" target=3D= "_blank" rel=3D"noopener">CVE-2026-61858</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in = the FormatMagickCaption method when memory allocation fails. Attackers can = trigger memory allocation failures to cause a dangling pointer to reference=
freed memory, potentially enabling denial of service or code execution.</t=
<td>2026-07-11</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61861" target=3D= "_blank" rel=3D"noopener">CVE-2026-61861</a></td>
</tr>
<td class=3D"vendor-product">ImageMagick--ImageMagick</td>
<td>ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the=
VIFF encoder when memory allocation fails. Attackers can trigger allocatio=
n failures by processing specially crafted VIFF images to exhaust available=
memory and cause denial of service.</td>
<td>2026-07-11</td>
<td>2.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61870" target=3D= "_blank" rel=3D"noopener">CVE-2026-61870</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--YouTrack</td>
<td>In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid dia= gram rendering was possible</td>
<td>2026-07-10</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59791" target=3D= "_blank" rel=3D"noopener">CVE-2026-59791</a></td>
</tr>
<td class=3D"vendor-product">JetBrains--YouTrack</td>
<td>In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles=
in digest emails was possible</td>
<td>2026-07-10</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61492" target=3D= "_blank" rel=3D"noopener">CVE-2026-61492</a></td>
</tr>
<td class=3D"vendor-product">lissy93--dashy</td>
<td>Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's wo= rkspace view trusts the url query parameter and assigns it directly to an i= frame source without scheme validation. If a logged-in user opens a crafted=
workspace link containing a javascript: URL, JavaScript runs on the Dashy = origin and can read same-origin browser data, interact with the Dashy DOM, = and send requests as the victim. This issue is fixed in version 4.3.7.</td> <td>2026-07-07</td>
<td>3.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55592" target=3D= "_blank" rel=3D"noopener">CVE-2026-55592</a></td>
</tr>
<td class=3D"vendor-product">lo48576--fbxcel</td>
<td>A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affect=
s an unknown part of the file src/pull_parser/v7400/parser.rs of the compon= ent Node Header Handler. The manipulation results in denial of service. The=
attack must be initiated from a local position. The exploit is now public = and may be used. The pull request to fix this issue awaits acceptance.</td> <td>2026-07-09</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15274" target=3D= "_blank" rel=3D"noopener">CVE-2026-15274</a></td>
</tr>
<td class=3D"vendor-product">MyEMS--MyEMS</td>
<td>A vulnerability was found in MyEMS up to 6.4.0. The affected element is=
the function on_post of the file myems-api/core/svg.py of the component Ad= min Backend. The manipulation of the argument new_values['data'] results in=
cross site scripting. The attack can be launched remotely. The exploit has=
been made public and could be used. Upgrading to version 6.5.0 is sufficie=
nt to fix this issue. The patch is identified as 4a97edfbd786c779d032205483= 3b21ddf54d5b06. It is suggested to upgrade the affected component. The issu=
e report remains open even though there is an official fix for it.</td> <td>2026-07-10</td>
<td>2.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15321" target=3D= "_blank" rel=3D"noopener">CVE-2026-15321</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>A vulnerability was identified in NousResearch hermes-agent up to 2026.= 5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_h= tml of the file gateway/platforms/matrix.py of the component Matrix Adapter=
. Such manipulation leads to cross site scripting. The attack can be execut=
ed remotely. The exploit is publicly available and might be used. The pull = request to fix this issue awaits acceptance.</td>
<td>2026-07-09</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15311" target=3D= "_blank" rel=3D"noopener">CVE-2026-15311</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 3.10.0 and prior to version 4.11.0, an = unbounded recursion can crash the PKCS#11 TA. Version 4.11.0 contains a pat= ch. No known workarounds are available.</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41434" target=3D= "_blank" rel=3D"noopener">CVE-2026-41434</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 3.3.0 and prior to version 4.11.0, a re= source leak exists in OP-TEE's shared memory cleanup logic because the func= tion `cleanup_shm_refs()` in `core/tee/entry_std.c` fails to apply a requir=
ed bitmask (`OPTEE_MSG_ATTR_TYPE_MASK`) to parameter attributes. When proce= ssing non-contiguous memory parameters from a normal-world caller, the syst=
em fails to match the attribute type in its internal switch statement and s= kips the necessary mobj_put() call. This results in a persistent reference = leak of `mobj_reg_shm` objects, which remain on internal lists with danglin=
g refcounts. This affects non-FF-A configurations that support non-contiguo= us, non-secure shared memory. Over time, these accumulated leaks progressiv= ely consume the secure-world heap, degrading the system's ability to servic=
e trusted application operations and eventually requiring a reboot to recov= er. Version 4.11.0 contains a patch. No known workarounds are available.</t=
<td>2026-07-06</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42546" target=3D= "_blank" rel=3D"noopener">CVE-2026-42546</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 4.5.0 and prior to version 4.11.0, the = RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses=
non-constant-time `memcmp()` for label hash verification and has multiple = distinguishable error paths. This creates a Manger-style padding oracle tha=
t allows an attacker to recover RSA-OAEP plaintext with approximately 1000-= 2000 adaptive chosen ciphertext queries. Only affects plat-d06 with `CFG_HI= SILICON_ACC_V3=3Dy`, which seems to be disabled by default. Version 4.11.0 = contains a patch. As a workaround, disable Hisilicon HPRE RSA driver with `= CFG_HISILICON_ACC_V3=3Dn`.</td>
<td>2026-07-06</td>
<td>2.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41514" target=3D= "_blank" rel=3D"noopener">CVE-2026-41514</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 3.9.0 and prior to version 4.11.0, the = RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-c= onstant-time `memcmp()` for label hash verification and has multiple distin= guishable error paths. This creates a Manger-style padding oracle that allo=
ws an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 a= daptive chosen ciphertext queries. Version 4.11.0 contains a patch. As a wo= rkaround, disable the NXP CAAM RSA driver with `CFG_CRYPTO_DRV_RSA=3Dn`.</t=
<td>2026-07-06</td>
<td>2.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41515" target=3D= "_blank" rel=3D"noopener">CVE-2026-41515</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 4.5.0 and prior to version 4.11.0, the = RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driv=
er uses non-constant-time `memcmp()` for label hash verification and has mu= ltiple distinguishable error paths. This creates a Bleichenbacher-style pad= ding oracle that allows an attacker to recover RSA PKCS#1 v1.5 plaintext. V= ersion 4.11.0 contains a patch. As a workaround, disable Hisilicon HPRE RSA=
driver with `CFG_HISILICON_ACC_V3=3Dn`.</td>
<td>2026-07-06</td>
<td>2.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41516" target=3D= "_blank" rel=3D"noopener">CVE-2026-41516</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in router= s/openai.py and routers/ollama.py passed a lambda to aiocache key instead o=
f key_builder, causing permission-filtered per-user model lists to share a = static cache entry and exposing one user's model list to another caller dur= ing the TTL window. This issue is fixed in version 0.10.0.</td> <td>2026-07-09</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59213" target=3D= "_blank" rel=3D"noopener">CVE-2026-59213</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. Prior to 0.10.0, channel thread parent and reply handling di=
d not bind parent_id to the channel in the URL, allowing an authenticated u= ser to reference a message from another private or DM channel and disclose = thread context across channels. This issue is fixed in version 0.10.0.</td> <td>2026-07-09</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59215" target=3D= "_blank" rel=3D"noopener">CVE-2026-59215</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated auto= mation owners without rechecking that they were still active or still had f= eatures.automations, and check_model_access only enforced private-model gra= nts for the exact user role, allowing deactivated pending users to continue=
scheduled model execution. This issue is fixed in version 0.10.0.</td> <td>2026-07-09</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59226" target=3D= "_blank" rel=3D"noopener">CVE-2026-59226</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configure=
d with always_connect=3DTrue. The ydoc:awareness:update and ydoc:document:l= eave Socket.IO handlers accepted collaborative-document events without requ= iring an authenticated user, allowing unauthorized manipulation of document=
collaboration state. This issue is fixed in version 0.10.0.</td> <td>2026-07-09</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59715" target=3D= "_blank" rel=3D"noopener">CVE-2026-59715</a></td>
</tr>
<td class=3D"vendor-product">Open5GS--Open5GS</td>
<td>A security flaw has been discovered in Open5GS 2.7.7. This affects the = function amf_context_final of the file src/amf/context.c of the component A= MF. Performing a manipulation results in use after free. The attack is only=
possible with local access. The exploit has been released to the public an=
d may be used for attacks.</td>
<td>2026-07-09</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15194" target=3D= "_blank" rel=3D"noopener">CVE-2026-15194</a></td>
</tr>
<td class=3D"vendor-product">OpenBSD--OpenSSH</td>
<td>sshd in OpenSSH before 10.4 allows remote attackers to cause a denial o=
f service (resource consumption from excessive authentication attempts) bec= ause MaxAuthTries was mishandled for GSSAPIAuthentication.</td> <td>2026-07-08</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60000" target=3D= "_blank" rel=3D"noopener">CVE-2026-60000</a></td>
</tr>
<td class=3D"vendor-product">pdeljanov--Symphonia</td>
<td>A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerab= ility affects unknown code of the component Metadata Handler. This manipula= tion causes denial of service. The attack needs to be launched locally. The=
exploit has been published and may be used. The pull request to fix this i= ssue awaits acceptance.</td>
<td>2026-07-09</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15276" target=3D= "_blank" rel=3D"noopener">CVE-2026-15276</a></td>
</tr>
<td class=3D"vendor-product">phpMyFAQ--phpMyFAQ</td>
<td>phpMyFAQ before 4.1.5 contains a potential authenticated path traversal=
vulnerability in the concatenatePaths() function within src/phpMyFAQ/Expor= t/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML contai= ning crafted image paths that are processed during PDF generation. The path=
resolution logic locates the substring "content" within a user-controlled = path using strpos(); when "content" is absent, strpos() returns false, whic=
h becomes 0 when cast to an integer, preserving the entire attacker-control= led path. This path is later passed to file_get_contents() without canonica= lization or root-directory containment validation, which may allow reading =
of files outside the intended content directory.</td>
<td>2026-07-10</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57961" target=3D= "_blank" rel=3D"noopener">CVE-2026-57961</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Limited authentication bypass by spoofing vulnerability in Progress MOV= Eit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 202= 5.0.7, from 2025.1.0 before 2025.1.3.</td>
<td>2026-07-08</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8651" target=3D"= _blank" rel=3D"noopener">CVE-2026-8651</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Path equivalence: vulnerability in Progress MOVEit Transfer (File Uploa=
d modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.= 1.0 before 2025.1.4.</td>
<td>2026-07-08</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8801" target=3D"= _blank" rel=3D"noopener">CVE-2026-8801</a></td>
</tr>
<td class=3D"vendor-product">Progress--MOVEit Transfer</td>
<td>Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audi=
t User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2= 025.1.0 before 2025.1.3.</td>
<td>2026-07-08</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8800" target=3D"= _blank" rel=3D"noopener">CVE-2026-8800</a></td>
</tr>
<td class=3D"vendor-product">radareorg--radare2</td>
<td>A security flaw has been discovered in radareorg radare2 up to 6.1.6. T= his impacts the function r_str_word_get0set of the file libr/util/str.c. Th=
e manipulation results in integer overflow. The attack must be initiated fr=
om a local position. The exploit has been released to the public and may be=
used for attacks. The patch is identified as 11ac224c0eb8d57830fccc99e1c1c= d8e5d958813. It is best practice to apply a patch to resolve this issue.</t=
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14786" target=3D= "_blank" rel=3D"noopener">CVE-2026-14786</a></td>
</tr>
<td class=3D"vendor-product">radareorg--radare2</td>
<td>A weakness has been identified in radareorg radare2 up to 6.1.6. Affect=
ed is the function cmd_print in the library libr/core/cmd_print.inc of the = component pb Print Command Handler. This manipulation causes integer overfl= ow. The attack needs to be launched locally. The exploit has been made avai= lable to the public and could be used for attacks. Patch name: 2b6265476c75= 567006b0fcbb749f4ae7b189c5df. It is recommended to apply a patch to fix thi=
s issue.</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14787" target=3D= "_blank" rel=3D"noopener">CVE-2026-14787</a></td>
</tr>
<td class=3D"vendor-product">radareorg--radare2</td>
<td>A security vulnerability has been detected in radareorg radare2 up to 6= .1.6. Affected by this vulnerability is the function r_core_bin_load of the=
file libr/core/cfile.c. Such manipulation leads to use after free. The att= ack needs to be performed locally. The exploit has been disclosed publicly = and may be used. The name of the patch is 635ab1eeb30340c26076722a90cb91fb2= 272130b. Applying a patch is advised to resolve this issue.</td> <td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14788" target=3D= "_blank" rel=3D"noopener">CVE-2026-14788</a></td>
</tr>
<td class=3D"vendor-product">radareorg--radare2</td>
<td>A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected=
by this issue is some unknown functionality of the file libr/bin/format/md= mp/mdmp.c of the component Memory64ListStream Parser. Performing a manipula= tion results in stack-based buffer overflow. The attack requires a local ap= proach. The exploit is now public and may be used. The patch is named 175d4= addb68981331c85b10681c2161c38fb5762. It is suggested to install a patch to = address this issue.</td>
<td>2026-07-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14789" target=3D= "_blank" rel=3D"noopener">CVE-2026-14789</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Directory Server 11</td>
<td>A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password ve= rification function uses standard memcmp() for comparing password hashes in= stead of a constant-time comparison function. A remote attacker could poten= tially use timing measurements of LDAP bind attempts to infer partial hash = information, though practical exploitation is extremely difficult due to PB= KDF2 computational overhead.</td>
<td>2026-07-08</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15041" target=3D= "_blank" rel=3D"noopener">CVE-2026-15041</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A logic vulnerability was found in GStreamer's webrtcbin component. The=
_check_sdp_crypto() function contains an inverted boolean condition that c= auses it to accept remote SDP offers or answers that lack the required a=3D= fingerprint attribute, while incorrectly rejecting those that include it. A=
n attacker with the ability to intercept and modify WebRTC signaling messag=
es could exploit this to bypass the SDP-level DTLS certificate fingerprint = binding, weakening defenses against man-in-the-middle attacks on media stre= ams.</td>
<td>2026-07-07</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14935" target=3D= "_blank" rel=3D"noopener">CVE-2026-14935</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Hardened Images</td>
<td>A flaw was found in libarchive. This vulnerability allows a remote atta= cker to trigger a heap overflow by providing a specially crafted tar archiv=
e. The issue occurs during the parsing of a PAX extended header containing =
a malformed SUN.holesdata sparse-file attribute. Successful exploitation co= uld lead to a denial of service, making the system unavailable, or potentia= lly allow for arbitrary code execution, giving the attacker control over th=
e affected system.</td>
<td>2026-07-10</td>
<td>3.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15028" target=3D= "_blank" rel=3D"noopener">CVE-2026-15028</a></td>
</tr>
<td class=3D"vendor-product">VMware--Pinniped</td>
<td>A user authenticating to Kubernetes clusters via the Pinniped Superviso=
r could potentially gain elevated permissions in the clusters, only if all = the following conditions were true: the Pinniped Supervisor server is runni=
ng with an ActiveDirectoryIdentityProvider resource configured; the ActiveD= irectoryIdentityProvider.spec.groupSearch.attributes.groupName is empty; th=
e attacker gains the ability to edit some part of the distinguished name (D=
N) of group entries in the Active Directory (AD) server's database for grou=
ps to which they belong; the configured group search parameters cause the e= dited group to be included in the group search results for the user; and th=
e attacker knows the password for an AD user who belongs to the edited AD g= roup. Affected versions: Pinniped (go.pinniped.dev) v0.11.0 through v0.46.0=
inclusive; fixed in v0.47.0.</td>
<td>2026-07-09</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59269" target=3D= "_blank" rel=3D"noopener">CVE-2026-59269</a></td>
</tr>
<td class=3D"vendor-product">vnotex--vnote</td>
<td>A weakness has been identified in vnotex vnote up to 3.20.1. Impacted i=
s an unknown function of the file /src/data/extra/web/js/markdownit.js of t=
he component YAML Frontmatter. This manipulation of the argument p_metaData=
causes cross site scripting. The attack may be initiated remotely. The ven= dor was contacted early about this disclosure but did not respond in any wa= y.</td>
<td>2026-07-12</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15505" target=3D= "_blank" rel=3D"noopener">CVE-2026-15505</a></td>
</tr>
<td class=3D"vendor-product">Wireshark Foundation--Wireshark</td>
<td>BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows = possible information disclosure</td>
<td>2026-07-08</td>
<td>2.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15168" target=3D= "_blank" rel=3D"noopener">CVE-2026-15168</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/ud= c/udc_numaker.c) armed the control Data IN stage unconditionally (base->= CEPTXCNT =3D len in numaker_hsusbd_ep_trigger). Because the HSUSBD hardware=
cannot disarm a control Data IN already armed for a previous transfer, a U=
SB host that cancels an in-flight control transfer (timeout) and then issue=
s a new SETUP packet can drive the driver out of sync: stale data may be tr= ansmitted in the new transfer and the control endpoint can become permanent=
ly stuck NAK'ing every subsequent control transfer. A malicious or buggy ho=
st (physical/adjacent attacker driving the bus) can repeatedly cancel-and-r= e-SETUP to wedge the device's USB control endpoint, denying service to the = device's USB function (the device stops enumerating/responding on the contr=
ol pipe) until a USB reset or re-plug. The flaw is an availability-only den= ial of service; the FIFO copy loops (bounded by net_buf length and the hard= ware BUFFULL flag) and the net_buf lifecycle are independent of the arming = desync, so there is no out-of-bounds access, use-after-free, or information=
leak. The fix monitors the IN-token and new-SETUP events (k_event) and onl=
y arms control Data IN when an IN token is present and no new SETUP has arr= ived, cancelling the current transfer on a new SETUP. Affects boards using = the Nuvoton NuMaker HSUSBD controller (CONFIG_UDC_NUMAKER with DT_HAS_NUVOT= ON_NUMAKER_HSUSBD_ENABLED); shipped in v4.4.0.</td>
<td>2026-07-12</td>
<td>2.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10668" target=3D= "_blank" rel=3D"noopener">CVE-2026-10668</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"snya_v">
<h2 id=3D"snya_v_title">Severity Not Yet Assigned</h2>
<table id=3D"table_severity_not_yet_assigned" class=3D"table no-tablesaw" s= tyle=3D"table-layout: fixed; width: 100%;" border=3D"1" summary=3D"Severity=
Not Yet Assigned">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">actualbudget--actual</td>
<td>Actual is an open-source personal finance application. Prior to 26.7.0,=
a missing authorization issue allows a shared user with user_access on a b= udget file to perform owner-only file management actions. A non-owner share=
d user can call file-management endpoints intended for higher-privilege use= rs, including /delete-user-file, /reset-user-file, and /user-create-key, be= cause requireFileAccess treats ordinary shared access as sufficient for fil= e-management operations that should be restricted to the file owner or an a= dministrator. This issue is fixed in version 26.7.0.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50007" target=3D= "_blank" rel=3D"noopener">CVE-2026-50007</a></td>
</tr>
<td class=3D"vendor-product">acymailing.com--acymailing.com AcyMailing exte= nsion for Joomla</td>
<td>A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla wa=
s discovered. Exploiting this flaw can lead to unauthorized database access=
and data leakage.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56292" target=3D= "_blank" rel=3D"noopener">CVE-2026-56292</a></td>
</tr>
<td class=3D"vendor-product">Adalo No-Code App Builder--App Builder</td>
<td>In Adalo's no-code app builder, (Versions 1 and 2) the attackers may ex= tract full user records and correlate user behavior across multiple applica= tions via dbId enumeration. The platform does not implement data minimizati= on, privacy by design, or implement appropriate technical safeguards, allow= ing sensitive information to be exposed to unauthorized parties.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10706" target=3D= "_blank" rel=3D"noopener">CVE-2026-10706</a></td>
</tr>
<td class=3D"vendor-product">Adalo No-Code App Builder--App Builder</td> <td>This vulnerability enables large-scale data harvesting without requirin=
g app-specific secrets. A single request to a minimal leaderboard component=
may return user records containing emails, UUIDs, and custom fields. The c= ombination of wildcard CORS behavior, long-lived twenty-day JWTs, and the a= bsence of token revocation allows attackers to gather sensitive personal in= formation from any Adalo application.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10708" target=3D= "_blank" rel=3D"noopener">CVE-2026-10708</a></td>
</tr>
<td class=3D"vendor-product">Adiss--Biloop</td>
<td>An authenticated user could manipulate a company ID parameter in a POST=
request to the backend to gain unauthorised access to other companies host=
ed within the same subdomain environment. The application does not adequate=
ly verify whether the requested company ID belongs to the authenticated use= r's session, resulting in a cross-tenant authorisation bypass. If this vuln= erability is successfully exploited, it allows unauthorised access to sensi= tive customer information, including billing data, and may enable the unaut= horised modification of third-party data.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12686" target=3D= "_blank" rel=3D"noopener">CVE-2026-12686</a></td>
</tr>
<td class=3D"vendor-product">adm-zip--adm-zip</td>
<td>adm-zip before 0.5.18 is vulnerable to denial of service via a crafted = ZIP file with a manipulated uncompressed size header field. In zipEntry.js = line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the d= eclared uncompressed size from the ZIP central directory header without val= idating it against the actual compressed data size or imposing any upper bo= und. The size value is read directly from the binary header at entryHeader.=
js line 266 with no bounds check. An attacker can craft a ~120-byte ZIP fil=
e that declares ~4GB uncompressed size, causing a memory allocation amplifi= cation ratio of over 33 million to 1. The allocation occurs before CRC vali= dation, so the malicious payload cannot be rejected early. All extraction a=
nd read methods are affected: readFile(), readAsText(), extractEntryTo(), e= xtractAllTo(), extractAllToAsync(), test(), and entry.getData(). Any applic= ation accepting untrusted ZIP files via adm-zip is vulnerable to immediate = process crash.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39244" target=3D= "_blank" rel=3D"noopener">CVE-2026-39244</a></td>
</tr>
<td class=3D"vendor-product">ajenti--ajenti</td>
<td>ajenti through v2.2.13 has a clickjacking weakness in the browser-facin=
g login and administrative UI. In ajenti-core/aj/http.py, the core HTTP res= ponse path initializes an empty header list, forwards handler-added headers=
verbatim, and finalizes responses through WSGI start_response() without ad= ding anti-framing protections such as X-Frame-Options or a Content-Security= -Policy frame-ancestors restriction.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38979" target=3D= "_blank" rel=3D"noopener">CVE-2026-38979</a></td>
</tr>
<td class=3D"vendor-product">ankitects--anki</td>
<td>Anki is a program for creating and reviewing flashcards. Prior to 25.09= .3, Anki launches a local HTTP server to serve media files and web pages fo=
r parts of its interface, but requests from other origins were not sufficie= ntly blocked. A malicious website could potentially trigger side-effecting = requests to the local server, with severity varying by browser depending on=
Private Network Access protections. This issue is fixed in version 25.09.3= .</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59153" target=3D= "_blank" rel=3D"noopener">CVE-2026-59153</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow</td=
<td>A bug in `BaseSerialization.deserialize()` allowed unrestricted `import= _string()` of attacker-controlled class paths when the Scheduler / API Serv=
er loaded a serialized DAG: a DAG author could embed a malicious trigger in=
to a DAG to gain remote code execution on the API Server / Scheduler proces=
s, crossing the Airflow security boundary that DAG-author code must never e= xecute in those processes. Users are advised to upgrade to `apache-airflow`=
3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-au= thor trust is limited can restrict the `[core] allowed_deserialization_clas= ses` config to a narrow allowlist.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33264" target=3D= "_blank" rel=3D"noopener">CVE-2026-33264</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow</td=
<td>The Bulk Variables API in Apache Airflow called the redactor without pa= ssing the variable's key, so the key-based `should_hide_value_for_key` chec=
k (which triggers on secret-suffixed key names like `*_password` / `*_token=
` / `*_secret`) could not fire for JSON-decodable variable values. An authe= nticated UI/API user with bulk Variable read permission could retrieve plai= ntext values from JSON variables whose key would otherwise trigger redactio=
n. Affects deployments that store sensitive values in JSON-typed Airflow Va= riables under secret-suffixed key names. Users are advised to upgrade to `a= pache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2=
.x backport).</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48828" target=3D= "_blank" rel=3D"noopener">CVE-2026-48828</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow</td=
<td>A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint = applied the caller's readable-Dag filter to the top-level serialized Dag ke=
y but still emitted referenced Dag IDs through the `dep.source` and `dep.ta= rget` fields of trigger / sensor dependency entries. An authenticated UI us=
er with read permission on some Dags could enumerate the identifiers of oth=
er Dags they were not authorized to read by inspecting the dependency graph=
for trigger / sensor references. Affects deployments that rely on per-Dag = read scoping to keep Dag identifiers private across teams. This is a residu=
al gap in the fix for CVE-2026-28563, which filtered the top-level Dag key = but did not propagate the filter into the trigger / sensor dep-source / dep= -target fields. Users who already upgraded for CVE-2026-28563 should additi= onally upgrade to `apache-airflow` 3.3.0 or later to cover the residual tri= gger / sensor dependency leak.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48891" target=3D= "_blank" rel=3D"noopener">CVE-2026-48891</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow</td=
<td>The Config API in Apache Airflow surfaced per-key secrets-backend overr= ides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_I=
D` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic c= onfig options whose option names were not in `sensitive_config_values`, so = the masker did not redact them. An authenticated UI/API user with Config re=
ad permission could retrieve plaintext secrets-backend credentials (Vault `= role_id` / `secret_id`, etc.) from the Config API output. Affects deploymen=
ts that configure secrets backends via per-key environment overrides. Users=
are advised to upgrade to `apache-airflow` 3.3.0 or later.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48892" target=3D= "_blank" rel=3D"noopener">CVE-2026-48892</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow</td=
<td>Before apache-airflow 3.3.0, a user authorized to read one Dag could di= sclose the source of other Dags co-located in the same source file. `GET /a= pi/v2/dagSources/{dag_id}` - and the equivalent Dag-source view in the UI -=
returned the entire source file without redacting Dags the caller was not = authorized to read, bypassing per-DAG read authorization. Deployments that = co-locate multiple Dags in a single file and rely on per-DAG access control=
to limit source visibility are affected; single-Dag-per-file deployments a=
re not. Upgrade to apache-airflow 3.3.0 or later.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49296" target=3D= "_blank" rel=3D"noopener">CVE-2026-49296</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow</td=
<td>In Apache Airflow before 3.3.0, the REST API task-instance detail and l= ist endpoints returned a deferred task's trigger kwargs without masking. Wh=
en a deferred operator passed a secret (for example a provider API key) int=
o its trigger, any authenticated user with DAG-scoped task-instance read ac= cess for that DAG could read that secret in clear text while the task was d= eferred. Users should upgrade to apache-airflow 3.3.0 or later, which masks=
sensitive values in trigger kwargs returned by the API.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49487" target=3D= "_blank" rel=3D"noopener">CVE-2026-49487</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Airflow Goo= gle provider</td>
<td>Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCS= TimeSpanFileTransformOperator` joined GCS object names returned by the buck=
et listing API directly to a destination filesystem path without normalisat= ion or containment check. A user with write access to the source GCS bucket=
(typically a different trust principal than the DAG author - partner uploa= ds, ingest-only service accounts, public-data buckets) could create an obje=
ct whose name contains `..` segments and cause the DAG run to write the dow= nloaded blob outside the configured destination (the SFTP `destination_path=
` for `GCSToSFTPOperator`; the worker-local temp directory for `GCSTimeSpan= FileTransformOperator`), enabling overwrite of arbitrary files on the SFTP = server or the worker host. Affects deployments that ingest from buckets wri= table by less-trusted principals. Users are advised to upgrade to `apache-a= irflow-providers-google` 22.2.1 or later.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49297" target=3D= "_blank" rel=3D"noopener">CVE-2026-49297</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Neutralization of Argument Delimiters in a Command ('Argument = Injection') vulnerability in Apache Camel Docling component. The camel-docl= ing component invokes the external `docling` command-line tool by assemblin=
g an argument list in DoclingProducer and executing it through java.lang.Pr= ocessBuilder. Custom CLI arguments supplied through the `CamelDoclingCustom= Arguments` exchange header (a List<String>) were appended to that arg= ument list with insufficient validation: the original implementation relied=
on a denylist of disallowed flags and only rejected path values that conta= ined a literal `../` sequence. As a result, a Camel route that forwards ext= ernally-influenced data into the `CamelDoclingCustomArguments` header (or i= nto the path-bearing headers used to build the invocation) could cause the = producer to pass unrecognized or unintended `docling` CLI flags to the subp= rocess, and could supply path-like argument values that resolved outside th=
e intended directory through traversal sequences not caught by the literal = `../` check. Because Camel itself builds the `docling` invocation from thes=
e values, the component is responsible for constraining them, and the weak = validation allowed CLI-argument injection and directory traversal in the ar= guments passed to the external tool. The invocation uses the list-based for=
m of ProcessBuilder, so a shell does not interpret the argument values; OS = command injection through shell metacharacters was not possible, and the me= tacharacter rejection added by the fix is defense-in-depth. This issue affe= cts Apache Camel: from 4.15.0 before 4.18.3. Users are recommended to upgra=
de to a release that contains the CAMEL-23212 fix. On the mainline the fix =
is included from Apache Camel 4.19.0 (and later releases such as 4.20.0). F=
or users on the 4.18.x LTS releases stream, upgrade to 4.18.3. The fix repl= aces the denylist with a strict allowlist of recognized `docling` CLI flags=
(rejecting any unrecognized flag, and rejecting producer-managed flags suc=
h as the output-directory flags), defensively rejects shell metacharacters =
in argument values, and normalizes path-like values with Path.normalize() b= efore validating them so that traversal sequences which bypass a literal `.= ./` check are detected. As defence in depth, route authors should avoid map= ping untrusted message content into the `CamelDoclingCustomArguments` heade=
r and the path-bearing headers, and should strip Camel-internal headers fro=
m messages that arrive from untrusted producers.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40047" target=3D= "_blank" rel=3D"noopener">CVE-2026-40047</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Deserialization of Untrusted Data vulnerability in Apache Camel. The ca= mel-vertx-http component deserializes HTTP response bodies carrying the Con= tent-Type application/x-java-serialized-object using a raw java.io.ObjectIn= putStream, without applying any ObjectInputFilter (VertxHttpHelper.deserial= izeJavaObjectFromStream) This deserialization path is reached only when the=
producer endpoint is configured with transferException=3Dtrue (or the comp= onent-level allowJavaSerializedObject=3Dtrue) and throwExceptionOnFailure i=
s left at its default value of true; in that case a backend HTTP response w= ith a 5xx status and the application/x-java-serialized-object content type = has its body deserialized with no class restrictions. An attacker who contr= ols the backend the Camel producer talks to - through a man-in-the-middle p= osition on an unencrypted (plain HTTP) connection, or by compromising the b= ackend service - can return a crafted serialized Java object and, if a suit= able gadget chain is present on the classpath, achieve remote code executio=
n on the Camel application host. The path is not reachable in the default c= onfiguration, where transferException is false. This issue affects Apache C= amel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 befo=
re 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes = the issue. If users are on the 4.14.x LTS releases stream, then they are su= ggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, t= hen they are suggested to upgrade to 4.18.3. After upgrading, the deseriali= zation performed by both helper utilities is constrained by a default Objec= tInputFilter (allow-list java.**;javax.**;org.apache.camel.**;!*), which ca=
n be customised through the new deserializationFilter endpoint option or th=
e JVM-wide -Djdk.serialFilter system property. For deployments that cannot = upgrade immediately: do not enable transferException=3Dtrue (or allowJavaSe= rializedObject=3Dtrue) on producers that talk to untrusted or network-reach= able backends; ensure producer connections use TLS (https) so that a respon=
se cannot be substituted by a man-in-the-middle; and, where the option is r= equired, set an explicit -Djdk.serialFilter allow-list (for example java.**= ;org.apache.camel.**;!*) to constrain deserialization.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40859" target=3D= "_blank" rel=3D"noopener">CVE-2026-40859</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Deserialization of Untrusted Data vulnerability in Apache Camel. The de= fault ObjectInputFilter pattern shipped with several Apache Camel component=
s for defense-in-depth deserialization filtering ('java.**;javax.**;org.apa= che.camel.**;!*', or the no-'javax.**' variant in the aggregation-repositor=
y components) uses a recursive 'java.**' glob that admits classes whose has= hCode/equals/readObject methods perform network I/O, notably java.net.URL a=
nd java.net.InetAddress. When an attacker can deliver a Java-serialized pay= load to an affected Camel consumer, deserialization of a HashMap (or any co= llection that calls hashCode on its elements) containing java.net.URL keys = causes the JVM to issue DNS queries to the attacker-supplied host during th=
e deserialization side-effect. The class-level filter check passes because = the resulting object's class (HashMap) is allow-listed; the DNS query is ob= servable on an attacker-controlled DNS server, providing an out-of-band sid=
e channel. The exposure is highest on the camel-jms family because JmsBindi= ng.extractBodyFromJms invokes ObjectMessage.getObject() unconditionally whe=
n mapJmsMessage=3Dtrue (default). Affected components: camel-jms, camel-sjm=
s, camel-amqp, camel-mina, camel-netty, camel-netty-http, camel-vertx-http,=
camel-infinispan, and the aggregation repository components camel-leveldb,=
camel-cassandraql, camel-consul, camel-sql (JDBC aggregation repository). = This issue affects Apache Camel: from 4.14.0 before 4.14.8, from 4.15.0 bef= ore 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to =
a version that contains the CAMEL-23372 fix once available: 4.21.0 for the = 4.21.x line, 4.18.3 for the 4.18.x line, and 4.14.8 for the 4.14.x line. Fo=
r deployments that cannot upgrade immediately, configure a JMS-provider-sid=
e allow-list (Apache ActiveMQ Artemis 'deserializationAllowList' / 'deseria= lizationDenyList', Apache ActiveMQ Classic 'org.apache.activemq.SERIALIZABL= E_PACKAGES') as the primary mitigation, and/or override the in-code default=
via the endpoint-level 'deserializationFilter' option or the JVM-wide '-Dj= dk.serialFilter' system property with an explicit deny: '!java.net.**;java.= **;javax.**;org.apache.camel.**;!*' (or '!java.net.**;java.**;org.apache.ca= mel.**;!*' for the aggregation-repository components, which do not include = javax.**).</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42527" target=3D= "_blank" rel=3D"noopener">CVE-2026-42527</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Deserialization of Untrusted Data vulnerability in Apache Camel Hazelca=
st component. The camel-hazelcast component creates and manages Hazelcast i= nstances using a default configuration that applies no Java deserialization=
filter. When Camel builds the Hazelcast Config itself - that is, when no u= ser-supplied HazelcastInstance, hazelcastConfigUri, or referenced Config be=
an is provided - neither Hazelcast's JavaSerializationFilterConfig nor a Ca= mel-side ObjectInputFilter is configured, so objects received over the Haze= lcast cluster protocol are deserialized inside Hazelcast's own serializatio=
n layer (ObjectInputStream.readObject) before Camel ever processes them. An=
attacker who can join or otherwise reach the Hazelcast cluster can publish=
a crafted serialized Java object that is then deserialized on every Camel = node, resulting in remote code execution. The exposure is present by defaul=
t and requires no opt-in endpoint configuration: any route using a hazelcas=
t consumer (hazelcast-topic, hazelcast-queue, hazelcast-seda, hazelcast-map=
, hazelcast-multimap, hazelcast-replicatedmap, hazelcast-list, hazelcast-se= t), as well as the HazelcastAggregationRepository and HazelcastIdempotentRe= pository, is affected whenever the managed instance is created from Camel's=
default configuration. This issue affects Apache Camel: from 4.0.0 before = 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are rec= ommended to upgrade to version 4.21.0, which fixes the issue. If users are =
on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.= 14.8. If users are on the 4.18.x releases stream, then they are suggested t=
o upgrade to 4.18.3. The fix makes Camel apply a default Hazelcast JavaSeri= alizationFilterConfig (whitelisting the java., javax. and org.apache.camel.=
class-name prefixes and blacklisting java.net.) to instances it creates fr=
om its own default configuration, while leaving any user-supplied Config or=
HazelcastInstance untouched. For deployments that cannot upgrade immediate= ly, configure a deserialization filter on the Hazelcast instance (Hazelcast=
JavaSerializationFilterConfig, or the JVM-wide system property -Djdk.seria= lFilter=3D!java.net.**;java.**;javax.**;org.apache.camel.**;!*) and enable = Hazelcast cluster authentication and TLS to restrict who can reach the clus= ter.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43865" target=3D= "_blank" rel=3D"noopener">CVE-2026-43865</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Deserialization of Untrusted Data vulnerability in Apache Camel, Apache=
Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and th=
e equivalent JmsBinding in camel-sjms - deserializes the payload of an inco= ming JMS ObjectMessage via jakarta.jms.ObjectMessage.getObject() whenever t=
he mapJmsMessage option is enabled (the default) and Camel acts as a JMS co= nsumer. The CVE-2026-40860 hardening added a post-deserialization class che=
ck that rejects classes outside the default allow-list java.**;javax.**;org= .apache.camel.**;!*. However org.apache.camel.support.DefaultExchangeHolder=
itself lives in the allow-listed org.apache.camel.** namespace, so an Obje= ctMessage whose top-level object is a DefaultExchangeHolder passes the chec=
k. The receiving side then calls DefaultExchangeHolder.unmarshal() on it wi= thout requiring the transferExchange option to be enabled - an asymmetric t= rust boundary, since the sending side gates ObjectMessage and transferExcha= nge handling but the receiving side did not - writing every non-null field =
of the holder into the Exchange: the message body, the IN and OUT headers, = the exchange properties, the variables, the exchange id and the exception. =
An attacker who can publish an ObjectMessage to a queue or topic consumed b=
y an affected Camel application can therefore inject arbitrary Exchange sta=
te using only universally-trusted java.lang and java.util types, with no de= serialization gadget chain required, to manipulate routing and headers, exc= hange properties and error handling. The same handling applies to camel-sjm=
s and camel-sjms2, and to the JMS-family components built on JmsComponent a=
nd JmsBinding: camel-amqp, camel-activemq and camel-activemq6. This is a by= pass of the CVE-2026-40860 fix rather than a flaw in it. This issue affects=
Apache Camel: from 3.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.= 19.0 before 4.21.0; Apache Camel: from 3.0.0 before 4.14.8, from 4.15.0 bef= ore 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to = version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS relea= ses stream, then they are suggested to upgrade to 4.14.8. If users are on t=
he 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. Af= ter upgrading, JMS ObjectMessage handling is disabled by default in camel-j= ms, camel-sjms and the JMS-family components (a new objectMessageEnabled op= tion defaults to false at the component and endpoint level), so an incoming=
ObjectMessage - including a DefaultExchangeHolder payload - is no longer d= eserialized unless the option is explicitly enabled; only set objectMessage= Enabled=3Dtrue when the consumed JMS destination is fed exclusively by trus= ted producers. For deployments that cannot upgrade immediately, restrict pu= blish access to the queues and topics consumed by Camel to trusted producer=
s via JMS broker authorization, and do not expose JMS consumers that map Ob= jectMessage bodies to untrusted networks; a JMS-provider deserialization al= low-list does not mitigate this specific bypass because the crafted payload=
uses only universally-trusted classes.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43866" target=3D= "_blank" rel=3D"noopener">CVE-2026-43866</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Deserialization of Untrusted Data vulnerability in Apache Camel PQC Com= ponent. The camel-pqc component persists post-quantum key metadata (KeyMeta= data) through pluggable KeyLifecycleManager implementations. AwsSecretsMana= gerKeyLifecycleManager.deserializeMetadata() reads that metadata back from = the configured AWS Secrets Manager secret by Base64-decoding the stored val=
ue and deserializing it with a raw java.io.ObjectInputStream.readObject() a=
nd no ObjectInputFilter or class allow-list; the cast to KeyMetadata happen=
s only after readObject() returns, so any readObject() side effects in a cr= afted object run before the type check. A principal who can write to the AW=
S Secrets Manager secret that holds this metadata (requiring secretsmanager= :PutSecretValue on that secret) could store a crafted serialized object tha=
t is deserialized during normal key-lifecycle operations, potentially leadi=
ng to code execution in the context of the application that manages the key=
s. This is the same underlying defect, in the same code path and remediated=
by the same fix, as CVE-2026-46590, which was reported independently and a= dditionally covers the HashiCorp Vault and file-based sibling managers; bot=
h are incomplete-remediation follow-ons to CVE-2026-40048 (CAMEL-23200). Th=
is issue affects Apache Camel: from 4.18.0 before 4.18.3, from 4.19.0 befor=
e 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes t=
he issue. If users are on the 4.18.x LTS releases stream, then they are sug= gested to upgrade to 4.18.3. For deployments that cannot upgrade immediatel=
y, restrict write access to the AWS Secrets Manager secret that holds the c= amel-pqc key metadata so that only the application's own identity holds sec= retsmanager:PutSecretValue on it (least-privilege IAM), and keep the PQC ke=
y material in a secret separate from any data that less-trusted principals = can write.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43867" target=3D= "_blank" rel=3D"noopener">CVE-2026-43867</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation, Authorization Bypass Through User-Controlled=
Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-ela= sticsearch-rest-client component reads several Exchange headers to control = its behaviour - SEARCH_QUERY (an advanced query body), OPERATION (which Ela= sticsearch operation to run), INDEX_NAME, INDEX_SETTINGS and ID. The string=
values of these header constants, defined in ElasticSearchRestClientConsta= nt, are plain unprefixed names ('SEARCH_QUERY', 'OPERATION', 'INDEX_NAME', = 'INDEX_SETTINGS', 'ID') rather than the 'Camel'-prefixed names used by ever=
y other Camel component (for example CamelSqlQuery, CamelMongoDbCriteria, C= amelCqlQuery). Camel's inbound HTTP header filter, HttpHeaderFilterStrategy=
, blocks only header names that begin with 'Camel' or 'camel'. Because the = Elasticsearch header names do not carry that prefix, they pass through the = inbound filter unchanged. When a Camel route exposes an HTTP entry point (f=
or example platform-http) in front of an elasticsearch-rest-client producer=
, an untrusted HTTP client can set these headers directly on its request an=
d override the query and operation that the route author configured: readin=
g every document in the index (SEARCH_QUERY with a match_all query), deleti=
ng documents (OPERATION set to Delete together with ID), or exfiltrating se= lected fields. No credentials are required and the producer reads the heade=
rs unconditionally. This issue affects Apache Camel: from 4.3.0 before 4.14= .8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recomme= nded to upgrade to version 4.21.0, which fixes the issue. If users are on t=
he 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8=
. If users are on the 4.18.x releases stream, then they are suggested to up= grade to 4.18.3. The fix renames the camel-elasticsearch-rest-client Exchan=
ge header constant string values (ID, SEARCH_QUERY, INDEX_SETTINGS, INDEX_N= AME, OPERATION) to carry the Camel prefix (CamelElasticsearchId, CamelElast= icsearchSearchQuery, CamelElasticsearchIndexSettings, CamelElasticsearchInd= exName, CamelElasticsearchOperation) so that they are blocked by the inboun=
d HttpHeaderFilterStrategy; the Java field names are unchanged. For deploym= ents that cannot upgrade immediately, strip the affected headers from untru= sted inbound messages before they reach the producer (for example removeHea= der('SEARCH_QUERY'), removeHeader('OPERATION'), removeHeader('INDEX_NAME'),=
removeHeader('INDEX_SETTINGS') and removeHeader('ID') in front of the elas= ticsearch-rest-client endpoint), or apply a custom HeaderFilterStrategy tha=
t blocks these names.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46453" target=3D= "_blank" rel=3D"noopener">CVE-2026-46453</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation vulnerability in Apache Camel Cometd Componen=
t. The camel-cometd component maps inbound Bayeux (CometD) message headers = into the Camel Exchange without applying a HeaderFilterStrategy. CometdBind= ing.populateExchangeFromMessage copies the entire ext.CamelHeaders map supp= lied by the CometD client directly onto the Camel message (message.setHeade= rs), so any header name - including Camel-internal control headers such as = CamelHttpUri, CamelFileName or CamelJmsDestinationName - is accepted unmodi= fied. Because a CometdComponent installs no Bayeux SecurityPolicy by defaul=
t, any client that can complete the Bayeux handshake against the CometD end= point can publish such a message without authentication. An attacker can th= erefore inject arbitrary Camel control headers that influence the behaviour=
of downstream producers in the route (for example redirecting an HTTP prod= ucer, changing a file name, or overriding a JMS destination); the injected = headers also persist across internal direct, seda and vm hops. The concrete=
downstream impact depends on which producers the route uses. This issue af= fects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, fr=
om 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0=
, which fixes the issue. If users are on the 4.14.x LTS releases stream, th=
en they are suggested to upgrade to 4.14.8. If users are on the 4.18.x rele= ases stream, then they are suggested to upgrade to 4.18.3. The fix implemen=
ts a HeaderFilterStrategy in the camel-cometd binding (a long-standing TODO=
in the code) that filters the Camel header namespace case-insensitively on=
inbound mapping, so client-supplied Camel* / camel* headers are no longer = copied into the Exchange. For deployments that cannot upgrade immediately, = strip the Camel control headers from inbound CometD messages before they re= ach any downstream producer (for example removeHeaders('Camel*') and remove= Headers('camel*') at the start of the route), and install an explicit Bayeu=
x SecurityPolicy on the CometdComponent so that only authenticated clients = can publish.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46454" target=3D= "_blank" rel=3D"noopener">CVE-2026-46454</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Insufficient Session Expiration vulnerability in Apache Camel Keycloak = Component. The camel-keycloak security helper KeycloakSecurityHelper.parseA= ndVerifyAccessToken builds a Keycloak TokenVerifier using withChecks(...) w= ith only the subject-exists check and the realm-URL (issuer) check. Keycloa= k's TokenVerifier.withChecks(...) appends to an initially empty check list =
- the upstream default checks are installed only when withDefaultChecks() i=
s called - so the built-in IS_ACTIVE predicate, which validates the token's=
exp (expiration) and nbf (not-before) claims, is never applied. As a resul=
t the helper verifies the token signature, subject and issuer but does not = enforce the token's validity window: an access token that is expired, or no=
t yet valid, is accepted as valid. Routes that rely on this helper to authe= nticate inbound requests therefore accept access tokens that are outside th= eir intended lifetime. This issue affects Apache Camel: from 4.18.0 before = 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to vers= ion 4.21.0, which fixes the issue. If users are on the 4.18.x releases stre= am, then they are suggested to upgrade to 4.18.3. The fix makes KeycloakSec= urityHelper.parseAndVerifyAccessToken include the TokenVerifier.IS_ACTIVE c= heck so that expired or not-yet-valid access tokens are rejected, aligning = the helper with Keycloak's default check set. For deployments that cannot u= pgrade immediately, enforce token expiration outside the helper - for examp=
le validate the access token's exp/nbf claims in the route before trusting = it, keep Keycloak access-token lifetimes short, and ensure any upstream gat= eway or resource server also validates the token validity window.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46455" target=3D= "_blank" rel=3D"noopener">CVE-2026-46455</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation vulnerability in Apache Camel AWS2-SQS Compon= ent. The camel-aws2-sqs component map inbound message attributes into the C= amel Exchange through a component-specific HeaderFilterStrategy. Sqs2Header= FilterStrategy configured only an outbound filter (setOutFilterPattern, whi=
ch blocks Camel*, breadcrumbId and org.apache.camel.* headers being written=
to the broker) but did not configure an inbound filter. As a result, when = Sqs2Consumer copies each SQS MessageAttribute into the Exchange via HeaderF= ilterStrategy.applyFilterToExternalHeaders, DefaultHeaderFilterStrategy app= lied no inbound rule and treated every header name as not filtered - includ= ing Camel-internal control headers such as CamelHttpUri, CamelFileName or C= amelSqlQuery - copying them unmodified onto the Camel message. Any principa=
l able to send messages to the consumed SQS queue (for example a cross-acco= unt sender or a lower-privileged in-account component holding sqs:SendMessa= ge) could therefore set arbitrary Camel control headers that influence the = behaviour of downstream producers in the route (for example redirecting an = HTTP producer, changing a file name, or overriding a query); the injected h= eaders also persist across internal direct, seda and vm hops. The concrete = downstream impact depends on which producers the route uses. This issue aff= ects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, fro=
m 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0,=
which fixes the issue. If users are on the 4.14.x LTS releases stream, the=
n they are suggested to upgrade to 4.14.8. If users are on the 4.18.x relea= ses stream, then they are suggested to upgrade to 4.18.3. The fix adds an i= nbound HeaderFilterStrategy rule to Sqs2HeaderFilterStrategy that filters t=
he Camel header namespace case-insensitively on inbound mapping, so sender-= supplied Camel* / camel* headers are no longer copied into the Exchange. Fo=
r deployments that cannot upgrade immediately, strip the Camel control head= ers from inbound messages before they reach any downstream producer (for ex= ample removeHeaders('Camel*') and removeHeaders('camel*') at the start of t=
he route), and restrict who may send to the consumed SQS queue by applying = least-privilege sqs:SendMessage permissions on the queue resource policy.</=
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46456" target=3D= "_blank" rel=3D"noopener">CVE-2026-46456</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation vulnerability in Apache Camel NATS component.=
The camel-nats component maps inbound NATS message headers into the Camel = Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeader= FilterStrategy() with no inbound rules configured (NatsConfiguration). With=
no inFilter, inFilterPattern or inFilterStartsWith set, DefaultHeaderFilte= rStrategy.applyFilterToExternalHeaders returns not filtered for every heade=
r name, so NatsConsumer copies every NATS message header - including Camel-= internal control headers such as CamelHttpUri, CamelFileName or CamelSqlQue=
ry - unmodified onto the Camel message. A client able to publish to the con= sumed NATS subject can therefore inject arbitrary Camel control headers tha=
t influence the behaviour of downstream producers in the route (for example=
redirecting an HTTP producer, changing a file name, or overriding a query)=
; the injected headers also persist across internal direct, seda and vm hop=
s. The concrete downstream impact depends on which producers the route uses=
. NATS message headers require NATS 2.2 or later, and the issue is reachabl=
e without credentials when the NATS server is configured without authentica= tion (the NATS server default). This issue affects Apache Camel: from 4.0.0=
before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users=
are recommended to upgrade to version 4.21.0, which fixes the issue. If us= ers are on the 4.14.x LTS releases stream, then they are suggested to upgra=
de to 4.14.8. If users are on the 4.18.x releases stream, then they are sug= gested to upgrade to 4.18.3. The fix makes camel-nats default to a dedicate=
d NatsHeaderFilterStrategy that filters the Camel header namespace case-ins= ensitively on inbound mapping, so client-supplied Camel* / camel* headers a=
re no longer copied into the Exchange. For deployments that cannot upgrade = immediately, strip the Camel control headers from inbound NATS messages bef= ore they reach any downstream producer (for example removeHeaders('Camel*')=
and removeHeaders('camel*') at the start of the route), and enable authent= ication on the NATS server so that only trusted clients can publish to the = consumed subject.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46457" target=3D= "_blank" rel=3D"noopener">CVE-2026-46457</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation vulnerability in Apache Camel. This issue aff= ects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 = through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3,=
4.21.0, which fixes the issue.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46587" target=3D= "_blank" rel=3D"noopener">CVE-2026-46587</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation vulnerability in Apache Camel. This issue aff= ects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 = through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3,=
4.21.0, which fixes the issue.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46588" target=3D= "_blank" rel=3D"noopener">CVE-2026-46588</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Deserialization of Untrusted Data vulnerability in Apache Camel PQC com= ponent. The camel-pqc component persists post-quantum key metadata (KeyMeta= data) through pluggable KeyLifecycleManager implementations. HashicorpVault= KeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that meta= data back from the configured secret backend by deserializing a Base64-wrap= ped value with a raw java.io.ObjectInputStream.readObject() and no ObjectIn= putFilter or class allow-list; the cast to KeyMetadata happens only after r= eadObject() returns, so any readObject() side effects in a crafted object r=
un before the type check. The same unfiltered legacy-migration read also re= mained in FileBasedKeyLifecycleManager (for the stored KeyPair and KeyMetad= ata). A principal who can write to the operator-controlled backend that hol=
ds these values - the HashiCorp Vault KV path, or the AWS Secrets Manager s= ecret (requiring a Vault token or secretsmanager:PutSecretValue) - could st= ore a crafted serialized object that is deserialized during normal key-life= cycle operations, potentially leading to code execution in the context of t=
he application that manages the keys. This is an incomplete-remediation fol= low-on to CVE-2026-40048 (CAMEL-23200), which changed FileBasedKeyLifecycle= Manager to store metadata as JSON / PKCS#8 / X.509 but did not add an Objec= tInputFilter, did not cover the Vault and AWS sibling managers, and left Fi= leBasedKeyLifecycleManager's own legacy-migration deserialization unfiltere=
d. This issue affects Apache Camel: from 4.18.0 before 4.18.3, from 4.19.0 = before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fi= xes the issue. If users are on the 4.18.x LTS releases stream, then they ar=
e suggested to upgrade to 4.18.3. For deployments that cannot upgrade immed= iately, restrict write access to the key backend so that only the applicati= on's own identity can write the camel-pqc secrets (least-privilege HashiCor=
p Vault policies and secretsmanager:PutSecretValue IAM), and keep the PQC k=
ey material in a backend separate from any data that less-trusted principal=
s can write.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46590" target=3D= "_blank" rel=3D"noopener">CVE-2026-46590</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Neutralization of Special Elements in Data Query Logic vulnera= bility in Apache Camel Neo4J component. The camel-neo4j producer builds the=
Cypher WHERE clause for its match/retrieve and delete operations from the = CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection th= rough the property values by binding them as query parameters ($paramN), bu=
t the property names (the JSON keys of that map) were still concatenated in=
to the query string verbatim in Neo4jProducer.retrieveNodes() and deleteNod= e(). A property name containing Cypher syntax therefore alters the structur=
e of the executed query. Where a route maps untrusted input into the CamelN= eo4jMatchProperties map - for example by passing a request body as the matc=
h map, or from a consumer that does not filter inbound Camel* headers - an = attacker who controls the JSON key names can inject arbitrary Cypher and re= ad, modify or delete any node or relationship in the Neo4j database. The Ca= melNeo4jMatchProperties header is itself Camel-prefixed and is filtered by = the HTTP header-filter strategy, so a plain HTTP client cannot set it direc= tly; the issue is reachable through routes that deliberately or inadvertent=
ly carry untrusted data into that header. This issue affects Apache Camel: = from 4.10.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.= 21.0. Users are recommended to upgrade to version 4.21.0, which fixes the i= ssue. If users are on the 4.14.x LTS releases stream, then they are suggest=
ed to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then t= hey are suggested to upgrade to 4.18.3. For deployments that cannot upgrade=
immediately, do not populate the CamelNeo4jMatchProperties map from untrus= ted input: validate or allow-list the property names (for example against ^= [A-Za-z_][A-Za-z0-9_]*$) before the Neo4j producer, and ensure that any con= sumer feeding such a route filters inbound Camel* / camel* headers so the m= atch header cannot be supplied by an external sender.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46591" target=3D= "_blank" rel=3D"noopener">CVE-2026-46591</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation, Unintended Proxy or Intermediary ('Confused = Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf pr= oducer selects which SOAP operation to invoke on the backend service from t=
he operationName (and operationNamespace) Exchange header, whose constant v= alues (CxfConstants.OPERATION_NAME / OPERATION_NAMESPACE) were the plain st= rings operationName / operationNamespace. Because these names do not start = with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only=
the Camel header namespace on the HTTP boundary - let them pass from an in= bound HTTP request straight into the Exchange. In a route that bridges an H= TTP consumer (for example platform-http) into a cxf: producer, any HTTP cli= ent could therefore set the operationName header and have CxfProducer resol=
ve and invoke a different WSDL operation than the route intended - for exam= ple replacing a read operation with a destructive one - against the backend=
SOAP service (a confused-deputy redirection). The constant is defined in t=
he shared camel-cxf-common module, so the same non-prefixed names also appl= ied to camel-cxfrs. No credentials are required when the bridging consumer =
is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14= .8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recomme= nded to upgrade to version 4.21.0, which fixes the issue. If users are on t=
he 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8=
. If users are on the 4.18.x releases stream, then they are suggested to up= grade to 4.18.3. After upgrading, the operation-selection headers are named=
CamelCxfOperationName / CamelCxfOperationNamespace and are filtered at tra= nsport boundaries; see the 4.21 upgrade guide for the cross-transport carri= er-header pattern. For deployments that cannot upgrade immediately, do not = select the CXF operation from untrusted input: strip the operationName and = operationNamespace headers from any untrusted ingress before the cxf: produ= cer and set the operation from a trusted source in the route.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46592" target=3D= "_blank" rel=3D"noopener">CVE-2026-46592</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Neutralization of Special Elements in Output Used by a Downstr= eam Component ('Injection'), Improper Input Validation, Server-Side Request=
Forgery (SSRF) vulnerability in Apache Camel Solr component. The camel-sol=
r producer copies Exchange message headers whose names begin with the SolrP= aram. prefix into the parameters of the Solr request, and headers whose nam=
es begin with the SolrField. prefix into the fields of the indexed Solr doc= ument. The prefix constants (SolrConstants.HEADER_PARAM_PREFIX / HEADER_FIE= LD_PREFIX) were the plain strings SolrParam. / SolrField.. Because these na= mes do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - = which blocks only the Camel header namespace on the HTTP boundary - let the=
m pass from an inbound HTTP request straight into the Exchange. In a route = that bridges an HTTP consumer (for example platform-http) into a solr: prod= ucer, any HTTP client could therefore set SolrParam.* headers to inject arb= itrary Solr request parameters - including shards or stream.url, which caus=
e the Solr server to issue server-side requests to an attacker-chosen URL (= server-side request forgery, for example to an internal service or a cloud = metadata endpoint), or qt to reach administrative request handlers - and se=
t SolrField.* headers to inject arbitrary fields into indexed documents. No=
credentials are required when the bridging consumer is unauthenticated. Th=
is issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before=
4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to ver= sion 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases=
stream, then they are suggested to upgrade to 4.14.8. If users are on the = 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After=
upgrading, routes that set Solr parameters or fields via the raw header pr= efixes must use CamelSolrParam. / CamelSolrField. instead of SolrParam. / S= olrField.. For deployments that cannot upgrade immediately, strip the SolrP= aram.* and SolrField.* headers from any untrusted ingress before the solr: = producer, and set the required Solr parameters and fields from a trusted so= urce in the route.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48203" target=3D= "_blank" rel=3D"noopener">CVE-2026-48203</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation, Improper Access Control vulnerability in Apa= che Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produ= cer selects the GridFS operation to perform from the gridfs.operation Excha= nge header when the endpoint's operation parameter is not set - which is th=
e default. The control-header constants (GridFsConstants.GRIDFS_OPERATION, = GRIDFS_OBJECT_ID, GRIDFS_METADATA, GRIDFS_CHUNKSIZE, GRIDFS_FILE_ID_PRODUCE=
D) were the plain strings gridfs.operation, gridfs.objectid, gridfs.metadat=
a, gridfs.chunksize and gridfs.fileid. Because these names do not start wit=
h the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only th=
e Camel header namespace on the HTTP boundary - let them pass from an inbou=
nd HTTP request straight into the Exchange. In a route that bridges an HTTP=
consumer (for example platform-http) into a mongodb-gridfs: producer with =
no explicit operation, any HTTP client could therefore set the gridfs.opera= tion header to override the route's intended operation - switching, for exa= mple, a file upload to remove (deleting a file identified by the attacker-s= upplied gridfs.objectid), listAll (enumerating every file in the bucket) or=
findOne (reading a file) - and supply a gridfs.metadata value that is pars=
ed as a MongoDB document, enabling NoSQL operator injection. No credentials=
are required when the bridging consumer is unauthenticated. This issue aff= ects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, fro=
m 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0,=
which fixes the issue. If users are on the 4.14.x LTS releases stream, the=
n they are suggested to upgrade to 4.14.8. If users are on the 4.18.x relea= ses stream, then they are suggested to upgrade to 4.18.3. After upgrading, = routes that drive GridFS operations or metadata via the raw header names mu=
st use CamelGridFsOperation / CamelGridFsObjectId / CamelGridFsMetadata / C= amelGridFsChunkSize / CamelGridFsFileId instead of the gridfs.* names. For = deployments that cannot upgrade immediately, set an explicit operation on t=
he mongodb-gridfs: endpoint so the operation is not taken from a header, an=
d strip the gridfs.* headers from any untrusted ingress before the producer= .</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48204" target=3D= "_blank" rel=3D"noopener">CVE-2026-48204</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation vulnerability in Apache Camel. This issue aff= ects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. U= sers are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the = issue.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49042" target=3D= "_blank" rel=3D"noopener">CVE-2026-49042</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation, Improper Neutralization of Special Elements =
in Output Used by a Downstream Component ('Injection') vulnerability in Apa= che Camel IRC component. The camel-irc producer chooses the destination of =
an outgoing IRC message from the irc.sendTo Exchange header (the constant I= rcConstants.IRC_SEND_TO, value irc.sendTo); when that header is present it = overrides the channel list configured on the endpoint, and the message is s= ent only to the specified destination. This and the component's other contr=
ol headers (irc.target, irc.messageType, irc.user.*, irc.num, irc.value) us=
ed plain, non-Camel-prefixed values. Because these names do not start with = the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the = Camel header namespace on the HTTP boundary - let them pass from an inbound=
HTTP request straight into the Exchange. In a route that bridges an HTTP c= onsumer (for example platform-http) into an irc: producer, any HTTP client = could therefore set the irc.sendTo header and redirect a message that the r= oute intended for a configured channel to an arbitrary IRC channel or user =
- exfiltrating the message content to an attacker-chosen nickname, leaking =
it into a public channel, or delivering messages that appear to come from t=
he bot. No credentials are required when the bridging consumer is unauthent= icated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.1= 5.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgr= ade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LT=
S releases stream, then they are suggested to upgrade to 4.14.8. If users a=
re on the 4.18.x releases stream, then they are suggested to upgrade to 4.1= 8.3. After upgrading, routes that set IRC headers via the raw header names = must use the CamelIrc* names (for example CamelIrcSendTo) instead of the ol=
d irc.* values. For deployments that cannot upgrade immediately, strip the = irc.* headers from any untrusted ingress before the irc: producer (for exam= ple removeHeaders('irc.*') at the start of the route), and set the IRC dest= ination from a trusted source.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49097" target=3D= "_blank" rel=3D"noopener">CVE-2026-49097</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Improper Input Validation, Improper Neutralization of Special Elements =
in Output Used by a Downstream Component ('Injection') vulnerability in Apa= che Camel Kafka Component. The camel-kafka producer can override its config= ured target topic at runtime from the kafka.OVERRIDE_TOPIC Exchange header:=
KafkaProducer.evaluateTopic() returns the header value in preference to th=
e topic configured on the endpoint. The control-header constants in KafkaCo= nstants (for example OVERRIDE_TOPIC =3D kafka.OVERRIDE_TOPIC, OVERRIDE_TIME= STAMP =3D kafka.OVERRIDE_TIMESTAMP, PARTITION_KEY =3D kafka.PARTITION_KEY) = used plain, non-Camel-prefixed values. camel-kafka's own KafkaHeaderFilterS= trategy does filter the kafka.* namespace, but only on the Kafka-to-Exchang=
e serialization boundary (reading Kafka record headers into the Exchange, a=
nd writing Exchange headers into a Kafka record); it does not apply to head= ers that arrive from an upstream consumer in a multi-component route. The u= pstream HTTP consumer uses HttpHeaderFilterStrategy, which blocks only the = Camel / camel namespace, so a kafka.* header passes through unfiltered. As =
a result, in a route that bridges an HTTP consumer (for example platform-ht= tp) into a kafka: producer, any HTTP client could set the kafka.OVERRIDE_TO= PIC header and cause the message to be published to an arbitrary Kafka topi=
c instead of the configured one - redirecting it to a sensitive internal to= pic, or injecting attacker-crafted messages into a topic consumed by a crit= ical downstream service. The related kafka.OVERRIDE_TIMESTAMP and kafka.PAR= TITION_KEY headers could likewise be injected to backdate messages or targe=
t specific partitions. No credentials are required when the bridging consum=
er is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4= .14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are reco= mmended to upgrade to version 4.21.0, which fixes the issue. If users are o=
n the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.1= 4.8. If users are on the 4.18.x releases stream, then they are suggested to=
upgrade to 4.18.3. After upgrading, routes that set or read Kafka headers = via the raw header names must use the CamelKafka* names (for example CamelK= afkaOverrideTopic and CamelKafkaTopic) instead of the old kafka.* values. F=
or deployments that cannot upgrade immediately, strip the kafka.* headers f= rom any untrusted ingress before the kafka: producer (for example removeHea= ders('kafka.*') at the start of the route), and set the target topic from a=
trusted source.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49098" target=3D= "_blank" rel=3D"noopener">CVE-2026-49098</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel</td> <td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in Apache Camel Netty HTTP component. The camel-netty-http HTTP server = consumer exposes a muteException option that controls what is returned to t=
he client when a route processing error occurs. This option defaulted to fa= lse because the backing field was an uninitialised primitive boolean (Java'=
s default of false), whereas the other Camel HTTP server components (camel-= http / camel-jetty / camel-servlet and camel-platform-http) default it to t= rue. With muteException=3Dfalse, when a request triggers an exception durin=
g route processing the consumer writes the full Throwable stack trace into = the HTTP response body as text/plain (via DefaultNettyHttpBinding) instead =
of returning an empty body. Any unauthenticated client that can reach the e= ndpoint and cause a processing error - for example by sending a malformed r= equest body, an invalid parameter, or otherwise triggering a route-internal=
failure - therefore receives a complete Java stack trace. Such a stack tra=
ce can disclose sensitive internal information, including credentials embed= ded in exception messages, internal host names and IP addresses, filesystem=
paths, dependency and version details, database and class names, and the a= pplication's internal structure, which an attacker can use to plan further = attacks. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.= 15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upg= rade to version 4.21.0, which fixes the issue. If users are on the 4.14.x L=
TS releases stream, then they are suggested to upgrade to 4.14.8. If users = are on the 4.18.x releases stream, then they are suggested to upgrade to 4.= 18.3. For deployments that cannot upgrade immediately, set muteException=3D= true explicitly on the camel-netty-http consumer (for example netty-http: h= ttp://0.0.0.0:8080/api?muteException=3Dtrue , or globally via the camel.com= ponent.netty-http.configuration.mute-exception=3Dtrue property), so that pr= ocessing errors no longer return the stack trace to the client.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49365" target=3D= "_blank" rel=3D"noopener">CVE-2026-49365</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Atmos= phere Websocket</td>
<td>Improper Input Validation, Exposure of Sensitive Information to an Unau= thorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache = Camel in Atmosphere Websocket Component. The camel-atmosphere-websocket con= sumer mapped inbound WebSocket query parameters into the Camel Exchange hea= der map without applying any HeaderFilterStrategy (WebsocketConsumer.sendEv= entNotification() iterates the query-string map collected in WebsocketConsu= mer.service() and copies each entry into the Exchange). Because nothing blo= cked the Camel header namespace, a client connecting to the WebSocket endpo= int could set Camel-internal control headers - including CamelHttpUri (Exch= ange.HTTP_URI) - simply by supplying them as query parameters. In a route w= here the WebSocket consumer feeds a downstream HTTP producer, the injected = CamelHttpUri redirects the server-side HTTP request to an attacker-chosen d= estination (server-side request forgery - for example to an internal servic=
e or a cloud metadata endpoint). In addition, the HTTP producer resolves Ca= mel property placeholders on the resulting (attacker-controlled) URI, so pl= aceholders embedded in the injected value - such as an environment-variable=
reference, an application property, or a vault reference - are resolved to=
their real values and sent to the attacker, disclosing environment variabl= es, application properties and vault secrets. When the WebSocket endpoint i=
s exposed without authentication, this is reachable by an unauthenticated r= emote attacker. This issue affects Apache Camel: from 4.0.0 before 4.14.8, = from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended=
to upgrade to version 4.21.0, which fixes the issue. If users are on the 4= .14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If=
users are on the 4.18.x releases stream, then they are suggested to upgrad=
e to 4.18.3. The fix makes the consumer apply the HeaderFilterStrategy it a= lready inherits from the HTTP/servlet stack, filtering the Camel header nam= espace case-insensitively on inbound mapping, so externally-supplied Camel*=
/ camel* headers are no longer copied into the Exchange. For deployments t= hat cannot upgrade immediately, strip the Camel control headers from the in= bound message before they reach any downstream producer (for example remove= Headers('Camel*') and removeHeaders('camel*') at the start of the route), r= equire authentication on the WebSocket endpoint, and avoid bridging an untr= usted consumer directly into an HTTP producer whose target URI can be drive=
n from message headers.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55993" target=3D= "_blank" rel=3D"noopener">CVE-2026-55993</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel AWS2 = SNS</td>
<td>Improper Input Validation vulnerability in Apache Camel AWS SNS compone= nt. The camel-aws2-sns component filters Camel headers through a component-= specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling S= qs2HeaderFilterStrategy, it originally configured only an outbound filter (= setOutFilterPattern, which blocks Camel*, breadcrumbId and org.apache.camel=
.* headers from being written out) and did not configure an inbound filter = rule. For the related camel-aws2-sqs component this inbound gap was exploit= able, because the Sqs2Consumer maps inbound SQS message attributes into the=
Camel Exchange via HeaderFilterStrategy.applyFilterToExternalHeaders, allo= wing a message sender to inject Camel control headers (tracked as CVE-2026-= 46456). camel-aws2-sns, by contrast, is producer-only: Sns2Endpoint does no=
t support consumers (createConsumer throws UnsupportedOperationException, '= You cannot receive messages from this endpoint'), so no externally-supplied=
message attributes are ever mapped inbound into a Camel Exchange through S= NS, and the missing inbound filter rule on Sns2HeaderFilterStrategy was the= refore not reachable by an attacker. As part of the same fix (CAMEL-23506),=
an inbound filter rule (setInFilterStartsWith for the Camel namespace) was=
added to Sns2HeaderFilterStrategy so that its configuration matches the co= rrected Sqs2HeaderFilterStrategy and the other sibling strategies. This is =
a defense-in-depth alignment with no known exploit path in camel-aws2-sns. = This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 befo=
re 4.18.3, from 4.19.0 before 4.21.0. This is a defense-in-depth hardening = change with no known exploit path in camel-aws2-sns, which is producer-only=
, so no urgent action or workaround is required. Users who want the aligned=
behaviour can upgrade to version 4.21.0, or to 4.14.8 on the 4.14.x LTS re= leases stream, or to 4.18.3 on the 4.18.x releases stream, which contain th=
e change. As a general best practice, operators should continue to apply le= ast-privilege IAM permissions on their SNS topics.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56140" target=3D= "_blank" rel=3D"noopener">CVE-2026-56140</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Dapr<=
<td>Improper Input Validation, Unintended Proxy or Intermediary ('Confused = Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr = Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound C= loudEvent - its Pub/Sub component name and its topic - into the CamelDaprPu= bSubName and CamelDaprTopic Exchange headers. These two headers are produce= r-direction routing headers: when the route republishes through a Dapr prod= ucer, DaprConfigurationOptionsProxy reads them back and prefers them over t=
he destination configured on the endpoint. As a result, in a route that con= sumes from one Dapr Pub/Sub topic and republishes to another (for example f= rom('dapr-pubsub:p:t').to('dapr-pubsub:p:other')), an actor able to publish=
a message to the subscribed topic could set the CloudEvent's pub/sub-name = and topic to values of their choosing and cause the re-published message to=
be delivered to an arbitrary Dapr Pub/Sub component and topic instead of t=
he configured destination - redirecting or exfiltrating the message and byp= assing the route's intended routing and any topic-level access controls in = the underlying broker. Exploitation requires the ability to publish to the = topic the route subscribes to; no other authentication or user interaction =
is needed. This issue affects Apache Camel: from 4.12.0 before 4.14.8, from=
4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to = upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.=
x LTS releases stream, then they are suggested to upgrade to 4.14.8. If use=
rs are on the 4.18.x releases stream, then they are suggested to upgrade to=
4.18.3. For deployments that cannot upgrade immediately, remove the CamelD= aprPubSubName and CamelDaprTopic headers from the Exchange between the Dapr=
consumer and any Dapr producer in the route (for example removeHeaders('Ca= melDaprPubSubName', 'CamelDaprTopic')), and restrict who can publish to the=
subscribed Dapr Pub/Sub topic so that only trusted producers can send to i= t.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49086" target=3D= "_blank" rel=3D"noopener">CVE-2026-49086</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel DNS</=
<td>Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerabi= lity in Apache Camel DNS component. The camel-dns producers read DNS operat= ion parameters - the resolver to query, the name or domain to look up, the = record type and class, and the search term - from Exchange message headers = whose constant values (DnsConstants.DNS_SERVER, DNS_NAME, DNS_DOMAIN, DNS_T= YPE, DNS_CLASS, TERM) were the plain strings dns.server, dns.name, dns.doma= in, dns.type, dns.class and term. Because these names do not start with the=
Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Cam=
el header namespace on the HTTP boundary - let them pass from an inbound HT=
TP request straight into the Exchange. In a route that bridges an HTTP cons= umer (for example platform-http) into a dns: producer, any HTTP client coul=
d therefore set the dns.server header to make the dig producer build a Simp= leResolver pointing at an attacker-controlled DNS server - a server-side re= quest forgery via DNS, through which the attacker observes the queried name=
and can return poisoned responses - and set the dns.name / dns.domain head= ers to resolve arbitrary internal hostnames, disclosing whether they exist = (internal network reconnaissance). No credentials are required when the bri= dging consumer is unauthenticated. This issue affects Apache Camel: from 4.= 0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Us= ers are recommended to upgrade to version 4.21.0, which fixes the issue. If=
users are on the 4.14.x LTS releases stream, then they are suggested to up= grade to 4.14.8. If users are on the 4.18.x releases stream, then they are = suggested to upgrade to 4.18.3. After upgrading, routes that drive DNS oper= ations via the raw header names must use CamelDnsServer / CamelDnsName / Ca= melDnsDomain / CamelDnsType / CamelDnsClass / CamelDnsTerm instead of the d= ns.* / term names. For deployments that cannot upgrade immediately, strip t=
he dns.* and term headers from any untrusted ingress before the dns: produc= er, and set the DNS server and lookup parameters from a trusted source in t=
he route.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48205" target=3D= "_blank" rel=3D"noopener">CVE-2026-48205</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Iggy<=
<td>Improper Input Validation, Exposure of Sensitive Information to an Unau= thorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache = Camel in Iggy component. The camel-iggy consumer mapped the user-headers of=
inbound Iggy messages into the Camel Exchange header map without applying = any HeaderFilterStrategy (IggyFetchRecords copied the message user-headers = straight into the Exchange). Because nothing blocked the Camel header names= pace, an actor able to publish to the consumed Iggy stream/topic could set = Camel-internal control headers - including CamelHttpUri (Exchange.HTTP_URI)=
- simply by supplying them as message user-headers. In a route where the I= ggy consumer feeds a downstream HTTP producer, the injected CamelHttpUri re= directs the server-side HTTP request to an attacker-chosen destination (ser= ver-side request forgery - for example to an internal service or a cloud me= tadata endpoint). In addition, the HTTP producer resolves Camel property pl= aceholders on the resulting (attacker-controlled) URI, so placeholders embe= dded in the injected value - such as an environment-variable reference, an = application property, or a vault reference - are resolved to their real val= ues and sent to the attacker, disclosing environment variables, application=
properties and vault secrets. This issue affects Apache Camel: from 4.17.0=
before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade=
to version 4.21.0, which fixes the issue. If users are on the 4.18.x relea= ses stream, then they are suggested to upgrade to 4.18.3. The fix adds a de= dicated IggyHeaderFilterStrategy (and a headerFilterStrategy endpoint optio=
n) that filters the Camel header namespace case-insensitively on inbound ma= pping, so externally-supplied Camel* / camel* headers are no longer copied = into the Exchange. For deployments that cannot upgrade immediately, strip t=
he Camel control headers from the inbound message before they reach any dow= nstream producer (for example removeHeaders('Camel*') and removeHeaders('ca= mel*') at the start of the route), restrict who can publish to the consumed=
Iggy stream/topic, and avoid bridging an untrusted consumer directly into =
an HTTP producer whose target URI can be driven from message headers.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55994" target=3D= "_blank" rel=3D"noopener">CVE-2026-55994</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel JIRA<=
<td>Improper Input Validation, Authorization Bypass Through User-Controlled=
Key vulnerability in Apache Camel JIRA component. The camel-jira producers=
read their operation parameters - the issue key, project key, transition i=
d, summary, type, assignee, components, watchers, link type, work-log minut=
es and others - from Exchange message headers. The header constants defined=
in JiraConstants (for example ISSUE_KEY =3D IssueKey, ISSUE_PROJECT_KEY =
=3D ProjectKey, ISSUE_TRANSITION_ID =3D IssueTransitionId, LINK_TYPE =3D li= nkType) used plain, non-Camel-prefixed values. Because these names do not s= tart with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks=
only the Camel header namespace on the HTTP boundary - let them pass from =
an inbound HTTP request straight into the Exchange. In a route that bridges=
an HTTP consumer (for example platform-http) into a jira: producer, any HT=
TP client could therefore supply these headers and override the values the = route intended, driving JIRA operations against the configured JIRA instanc=
e with the endpoint's configured service-account credentials - for example = deleting or transitioning an arbitrary issue (via IssueKey / IssueTransitio= nId), creating an issue in a different project (via ProjectKey), modifying = issue fields, adding or removing watchers, or logging work. The operations = are bounded by what the configured service account is permitted to do. No c= redentials are required from the attacker when the bridging consumer is una= uthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, fr=
om 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended t=
o upgrade to version 4.21.0, which fixes the issue. If users are on the 4.1= 4.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If u= sers are on the 4.18.x releases stream, then they are suggested to upgrade =
to 4.18.3. After upgrading, routes that drive JIRA operations via the raw h= eader names must use the CamelJira* names (for example CamelJiraIssueKey) i= nstead of the old values. For deployments that cannot upgrade immediately, = strip the camel-jira control headers from any untrusted ingress before the = jira: producer (for example removing the IssueKey, ProjectKey, IssueTransit= ionId and related headers at the start of the route), and set the required = JIRA operation parameters from a trusted source.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48206" target=3D= "_blank" rel=3D"noopener">CVE-2026-48206</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Keycl= oak</td>
<td>Improper Authentication, Missing Authentication for Critical Function, = Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloa=
k Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by=
running KeycloakSecurityProcessor.beforeProcess(), which performs three ch= ecks in sequence: it rejects a request that carries no access token, then -=
only if requiredRoles is non-empty - validates the roles, and - only if re= quiredPermissions is non-empty - validates the permissions. The actual cryp= tographic verification of the bearer access token (signature, issuer and ex= piry for a local JWT, or active-state and issuer for token introspection) i=
s performed exclusively inside those role and permission checks. KeycloakSe= curityPolicy defaults requiredRoles and requiredPermissions to empty - whic=
h is the documented 'Basic Setup' - so on a route configured that way the r= ole and permission checks are skipped and the access token is therefore nev=
er verified. The token-presence check still rejects a missing token, but an=
invalid token is accepted: any non-null value in the Authorization: Bearer=
header - including an arbitrary string or a forged, unsigned JWT - passes = the policy and the request reaches the protected route, with no signature, = issuer or expiry check and no request to Keycloak. The token is read from t=
he inbound request header because allowTokenFromHeader defaults to true. Be= cause the normal reason to place a route behind this policy is that the rou=
te performs server-side work, the bypass results in unauthenticated access =
to that work; where the protected route forwards to a code-execution-capabl=
e producer, it can result in unauthenticated remote code execution. This de= fect is independent of CVE-2026-23552: that issue concerned the issuer clai=
m and was fixed by adding a check inside the verification routine, but here=
the verification routine is not reached at all in the default configuratio=
n, so the defect remains. This issue affects Apache Camel: from 4.15.0 befo=
re 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to v= ersion 4.21.0, which fixes the issue. If users are on the 4.18.x releases s= tream, then they are suggested to upgrade to 4.18.3. For deployments that c= annot upgrade immediately, configure a non-empty requiredRoles or requiredP= ermissions on every KeycloakSecurityPolicy so that the token-verification p= ath is exercised, set allowTokenFromHeader to false where the token is not = expected from the request header, or perform token verification at the fram= ework layer ahead of the policy.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53913" target=3D= "_blank" rel=3D"noopener">CVE-2026-53913</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Lucen= e</td>
<td>Improper Input Validation, Authorization Bypass Through User-Controlled=
Key vulnerability in Apache Camel Lucene Component. The camel-lucene produ= cer reads the search phrase from an Exchange header (LuceneConstants.HEADER= _QUERY) whose value was the plain string QUERY (and RETURN_LUCENE_DOCS for = HEADER_RETURN_LUCENE_DOCS). Because these names do not start with the Camel=
/ camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel hea= der namespace on the HTTP boundary - let them pass from an inbound HTTP req= uest straight into the Exchange. In a route that exposes a Lucene query ope= ration behind an HTTP consumer (for example platform-http), any HTTP client=
could therefore set the QUERY header and have its value executed against t=
he full-text index, overriding the query the route intended to run. Dependi=
ng on what is indexed, this allows reading documents the request should not=
have access to (for example a match-all query returns the entire index, or=
the route's intended per-user filter can be replaced), and expensive regul= ar-expression queries can consume significant CPU. No credentials are requi= red when the HTTP consumer is unauthenticated. This issue affects Apache Ca= mel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 befor=
e 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes t=
he issue. If users are on the 4.14.x LTS releases stream, then they are sug= gested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, th=
en they are suggested to upgrade to 4.18.3. After upgrading, routes that se=
t the query via the raw header name must use CamelLuceneQuery (and CamelLuc= eneReturnLuceneDocs) instead of QUERY / RETURN_LUCENE_DOCS. For deployments=
that cannot upgrade immediately, strip the attacker-controllable headers b= efore the Lucene producer and set the query from a trusted source (for exam= ple removeHeader('QUERY') and removeHeader('RETURN_LUCENE_DOCS'), then setH= eader('QUERY', constant(...)) at the start of the route).</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46585" target=3D= "_blank" rel=3D"noopener">CVE-2026-46585</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Mail<=
<td>Improper Input Validation, Exposure of Sensitive Information to an Unau= thorized Actor vulnerability in Apache Camel Mail Component. The camel-mail=
producer (MailProducer.getSender) scanned the outgoing Exchange for messag=
e headers in the mail.smtp. / mail.smtps. namespace and, when any were pres= ent, built a per-message JavaMail sender with those values applied as JavaM= ail session properties, overriding the endpoint configuration. This namespa=
ce is Camel-internal - only MailProducer interprets it - and was not blocke=
d by any HeaderFilterStrategy, so the values could originate from any inbou=
nd protocol (for example platform-http query parameters or request headers,=
or JMS / Kafka messages from untrusted producers) that feeds a route endin=
g in an smtp / smtps producer without an intervening removeHeaders. The max= imal impact is version-dependent: on releases before 4.19.0, setting mail.s= mtp.host redirects the SMTP connection to a server under the attacker's con= trol, and because the producer then authenticates with the endpoint's confi= gured username and password those credentials are transmitted to the attack= er; on 4.19.0 and later the producer connects to the endpoint's configured = host explicitly, so the reachable impact is limited to weakening transport = security (for example mail.smtp.ssl.trust, mail.smtp.starttls.enable or mai= l.smtp.socks.host) and interception of the outgoing message rather than hos=
t redirect. Exploitation requires a route that channels untrusted input int=
o the mail producer without stripping the namespace. This issue affects Apa= che Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0=
before 4.21.0. Users are recommended to upgrade to version 4.21.0, which f= ixes the issue. If users are on the 4.14.x LTS releases stream, then they a=
re suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stre= am, then they are suggested to upgrade to 4.18.3. After upgrading, the per-= message override is disabled by default; enable it only on trusted endpoint=
s with useJavaMailSessionPropertiesFromHeaders=3Dtrue. For deployments that=
cannot upgrade immediately, strip the namespace before the mail producer w= ith removeHeaders('mail.smtp.*') and removeHeaders('mail.smtps.*') between = any untrusted ingress and the smtp / smtps producer. Even with the opt-in e= nabled, route authors should still strip the namespace on any path that car= ries untrusted input.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46584" target=3D= "_blank" rel=3D"noopener">CVE-2026-46584</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Sales= force</td>
<td>Improper Neutralization of Special Elements in Output Used by a Downstr= eam Component ('Injection'), Authorization Bypass Through User-Controlled K=
ey vulnerability in Apache Camel Salesforce Component. The camel-salesforce=
producer resolves its operation parameters - the SOQL query, the SOSL sear= ch, the target SObject name and id, the Apex REST URL and method, and the A= pex query parameters - from Exchange message headers, reading the header in=
preference to the value configured on the endpoint (AbstractSalesforceProc= essor.getParameter() reads the header first and uses the endpoint configura= tion only as a fallback). The control-header constants in SalesforceEndpoin= tConfig (for example SOBJECT_QUERY =3D sObjectQuery, SOBJECT_SEARCH =3D sOb= jectSearch, SOBJECT_NAME =3D sObjectName, SOBJECT_ID =3D sObjectId, APEX_UR=
L =3D apexUrl, APEX_METHOD =3D apexMethod, and the apexQueryParam. prefix) = used plain, non-Camel-prefixed values. Because these names do not start wit=
h the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only th=
e Camel header namespace on the HTTP boundary - let them pass from an inbou=
nd HTTP request straight into the Exchange. In a route that bridges an HTTP=
consumer (for example platform-http) into a salesforce: producer, any HTTP=
client could therefore set these headers and override what the route inten= ded - supplying its own SOQL query or SOSL search to read data from any SOb= ject the connected Salesforce user can access, overriding the target SObjec=
t name and id for CRUD operations, or redirecting an Apex REST call to a di= fferent endpoint and HTTP method (including destructive methods) with injec= ted query parameters. All such operations run with the full permissions of = the Salesforce connected (integration) user, which is typically broad. No c= redentials are required from the attacker when the bridging consumer is una= uthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, fr=
om 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended t=
o upgrade to version 4.21.0, which fixes the issue. If users are on the 4.1= 4.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If u= sers are on the 4.18.x releases stream, then they are suggested to upgrade =
to 4.18.3. After upgrading, routes that set Salesforce operation parameters=
via the raw header names must use the CamelSalesforce* names (for example = CamelSalesforceSObjectQuery and CamelSalesforceApexUrl) instead of the old = sObject* / apex* values; the endpoint-option spelling is unchanged. For dep= loyments that cannot upgrade immediately, strip the Salesforce control head= ers from any untrusted ingress before the salesforce: producer (for example=
removeHeaders('sObject*') and removeHeaders('apex*') at the start of the r= oute), and set the query, SObject and Apex parameters from a trusted source= .</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49099" target=3D= "_blank" rel=3D"noopener">CVE-2026-49099</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Under= tow</td>
<td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in Apache Camel Undertow Component. The camel-undertow HTTP server cons= umer exposes a muteException option that controls what is returned to the c= lient when a route processing error occurs. This option defaulted to false,=
whereas the other Camel HTTP server components (camel-http / camel-jetty /=
camel-servlet and camel-platform-http) default it to true. With muteExcept= ion=3Dfalse, when a request triggers an exception during route processing t=
he consumer writes the full Throwable stack trace into the HTTP response bo=
dy as text/plain instead of returning an empty body. Any unauthenticated cl= ient that can reach the endpoint and cause a processing error - for example=
by sending a malformed request body, an invalid parameter, or otherwise tr= iggering a route-internal failure - therefore receives a complete Java stac=
k trace. Such a stack trace can disclose sensitive internal information, in= cluding credentials embedded in exception messages, internal host names and=
IP addresses, filesystem paths, dependency and version details, database a=
nd class names, and the application's internal structure, which an attacker=
can use to plan further attacks. In addition, for Rest DSL consumers the m= uteException option was not honoured at all: the RestUndertowHttpBinding wa=
s created with a hard-coded false, so the stack trace was returned even whe=
n muteException=3Dtrue had been configured. This issue affects Apache Camel=
: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4= .21.0. Users are recommended to upgrade to version 4.21.0, which fixes the = issue. If users are on the 4.14.x LTS releases stream, then they are sugges= ted to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then = they are suggested to upgrade to 4.18.3. For deployments that cannot upgrad=
e immediately, set muteException=3Dtrue explicitly on the camel-undertow co= nsumer (for example undertow:
http://0.0.0.0:8080/api?muteException=3Dtrue =
, or globally via the camel.component.undertow.mute-exception=3Dtrue proper= ty), so that processing errors no longer return the stack trace to the clie= nt; note that on affected releases this workaround does not cover Rest DSL = consumers, whose binding ignores the option until the fix is applied.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56139" target=3D= "_blank" rel=3D"noopener">CVE-2026-56139</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Camel Vertx=
Websocket</td>
<td>Improper Input Validation, Exposure of Sensitive Information to an Unau= thorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache = Camel in Vertx Websocket component. The camel-vertx-websocket consumer mapp=
ed inbound WebSocket query and path parameters into the Camel Exchange head=
er map without applying any HeaderFilterStrategy (VertxWebsocketConsumer.po= pulateExchangeHeaders()). Because nothing blocked the Camel header namespac=
e, a client connecting to the WebSocket endpoint could set Camel-internal c= ontrol headers - including CamelHttpUri (Exchange.HTTP_URI) - simply by sup= plying them as query parameters. In a route where the WebSocket consumer fe= eds a downstream HTTP producer, the injected CamelHttpUri redirects the ser= ver-side HTTP request to an attacker-chosen destination (server-side reques=
t forgery - for example to an internal service or a cloud metadata endpoint=
). In addition, the HTTP producer resolves Camel property placeholders on t=
he resulting (attacker-controlled) URI, so placeholders embedded in the inj= ected value - such as an environment-variable reference, an application pro= perty, or a vault reference - are resolved to their real values and sent to=
the attacker, disclosing environment variables, application properties and=
vault secrets. When the WebSocket endpoint is exposed without authenticati= on, this is reachable by an unauthenticated remote attacker. This issue aff= ects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, fro=
m 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0,=
which fixes the issue. If users are on the 4.14.x LTS releases stream, the=
n they are suggested to upgrade to 4.14.8. If users are on the 4.18.x relea= ses stream, then they are suggested to upgrade to 4.18.3. The fix makes the=
affected consumers apply a HeaderFilterStrategy that filters the Camel hea= der namespace case-insensitively on inbound mapping, so externally-supplied=
Camel* / camel* headers are no longer copied into the Exchange. For deploy= ments that cannot upgrade immediately, strip the Camel control headers from=
the inbound message before they reach any downstream producer (for example=
removeHeaders('Camel*') and removeHeaders('camel*') at the start of the ro= ute), require authentication on the WebSocket endpoint, and avoid bridging =
an untrusted consumer directly into an HTTP producer whose target URI can b=
e driven from message headers.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46726" target=3D= "_blank" rel=3D"noopener">CVE-2026-46726</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Gravitino</=
<td>Unauthenticated callers can supply a malicious H2 JDBC URL through the = testConnection API, which executes arbitrary Java code on the server via H2=
's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Ap= ache Gravitino: before 1.2.1. Users are recommended to upgrade to version 1= .2.1, which fixes the issue. This issue only happens when using H2, and H2 =
is mainly used for testing and local development. Also, Gravitino is typica= lly deployed in the internal environment, so the severity is low.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41042" target=3D= "_blank" rel=3D"noopener">CVE-2026-41042</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Helix REST<=
<td>Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-= rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix thro= ugh 2.0.0 on all platforms allows a remote attacker controlling a web page = visited by an authorized user to read responses from and issue cross-origin=
requests to administrative REST endpoints via a cross-origin request from =
an arbitrary origin, since the filter unconditionally returns Access-Contro= l-Allow-Origin: * together with Access-Control-Allow-Credentials: true and = reflects arbitrary Access-Control-Request-Method / Access-Control-Request-H= eaders values in preflight responses. Users are recommended to upgrade to v= ersion 2.0.1, which fixes this issue.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57111" target=3D= "_blank" rel=3D"noopener">CVE-2026-57111</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Uncontrolled Resource Consumption vulnerability in Apache IoTDB.=C2=A0 = Some interface=C2=A0fails to impose reasonable limits on the time span and = aggregation interval of the query.=C2=A0An attacker can construct a request=
with extreme parameters (e.g., a very large time range combined with a min= imal interval).=C2=A0This forces the DataNode to build an enormous result s=
et in memory, which exhausts the Java heap and causes the DataNode process =
to crash. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users a=
re recommended to upgrade to version 2.0.8, which fixes the issue.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24012" target=3D= "_blank" rel=3D"noopener">CVE-2026-24012</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certai=
n Thrift RPC query handlers lack strict validation of the sessionId paramet= er. An attacker can construct requests with a forged sessionId and, without=
performing openSession authentication, receive valid query results. This a= llows authentication bypass and unauthorized reading of time-series data. T= his issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommen= ded to upgrade to version 2.0.8, which fixes the issue.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24013" target=3D= "_blank" rel=3D"noopener">CVE-2026-24013</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Apache IoTDB DataNode's internal RPC interface for creating Trigger ins= tances uses the uploaded Trigger JAR name to build a file path without suff= icient validation. If the internal DataNode RPC port is exposed to an untru= sted network, an attacker may use path traversal sequences in the JAR name =
to write files outside the intended Trigger installation directory. This co= uld allow arbitrary file write with the permissions of the IoTDB process. T= his issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommen= ded to upgrade to version 2.0.8, which fixes the issue.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24014" target=3D= "_blank" rel=3D"noopener">CVE-2026-24014</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Insufficient Session Expiration, Authentication Bypass by Capture-repla=
y vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Ca= ched Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.=
Users are recommended to upgrade to version 2.0.10, which fixes the issue.= </td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-28564" target=3D= "_blank" rel=3D"noopener">CVE-2026-28564</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') vulnerability in Apache IoTDB. An attacker can write arbitrary file=
s anywhere the IoTDB process has write permissions with unsafe API. This is= sue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended t=
o upgrade to version 2.0.10, which fixes the issue.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40005" target=3D= "_blank" rel=3D"noopener">CVE-2026-40005</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Memory Allocation with Excessive Size Value, Allocation of Resources Wi= thout Limits or Throttling, Missing Authentication for Critical Function vu= lnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=3Dtrue, the=
IoTDB AirGap pipe receiver accepts raw TCP connections on port 9780 with n=
o authentication. The readLength method reads an attacker-controlled 32-bit=
integer from the socket and readData passes it directly to new byte[length=
] with no upper-bound check. An unauthenticated attacker can cause the JVM =
to attempt an allocation of up to 2,147,483,647 bytes per connection, exhau= sting heap memory and crashing or severely degrading the DataNode process. = This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recomm= ended to upgrade to version 2.0.10, which fixes the issue.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40006" target=3D= "_blank" rel=3D"noopener">CVE-2026-40006</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability=
in Apache IoTDB. When pipe_air_gap_receiver_enabled=3Dtrue, the IoTDB AirG=
ap receiver's readLength method calls itself recursively each time it recog= nises the E-language prefix in socket data, with no depth limit. An unauthe= nticated attacker can send a stream of repeated E-language prefixes that dr= ives the recursion arbitrarily deep, exhausting the receiver thread's JVM s= tack and raising StackOverflowError. This issue affects Apache IoTDB: from = 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, wh= ich fixes the issue.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40007" target=3D= "_blank" rel=3D"noopener">CVE-2026-40007</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Use of Externally-Controlled Input to Select Classes or Code ('Unsafe R= eflection') vulnerability in Apache IoTDB. The pipe processor reads a fully=
qualified Java class name and instantiates it using Class.forName().newIns= tance() without any validation or allowlisting. This issue affects Apache I= oTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version=
2.0.10, which fixes the issue.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40008" target=3D= "_blank" rel=3D"noopener">CVE-2026-40008</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Improper Privilege Management, Improper Access Control vulnerability in=
Apache IoTDB. Authenticated users can escalate to full tree-path access by=
renaming themselves to __internal_auditor. This issue affects Apache IoTDB=
: from 2.0.8 before 2.0.10. Users are recommended to upgrade to version 2.0= .10, which fixes the issue.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40009" target=3D= "_blank" rel=3D"noopener">CVE-2026-40009</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB</td> <td>Incorrect Authorization, Improper Access Control vulnerability in Apach=
e IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value = data to unauthorized authenticated users. This issue affects Apache IoTDB: = from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users are recommended to=
upgrade to version 2.0.10, which fixes the issue.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40452" target=3D= "_blank" rel=3D"noopener">CVE-2026-40452</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache IoTDB C++ c= lient</td>
<td>Out-of-bounds Read, Improper Input Validation vulnerability in Apache I= oTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializ=
er crash client process on malformed server data. This issue affects Apache=
IoTDB C++ client: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users=
are recommended to upgrade to version 2.0.10, which fixes the issue.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40454" target=3D= "_blank" rel=3D"noopener">CVE-2026-40454</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Log4j API</=
<td>Improper encoding of non-finite floating-point values during MapMessage=
JSON serialization in Apache Log4j API produces output that is not valid J= SON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and=
version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: w= hen a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -I= nfinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 = does not permit these tokens, so a conformant parser rejects the resulting = document. The defect is reachable only when both of the following condition=
s hold: * The application uses the message resolver
https://logging.apache.= org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-mess= age of JsonTemplateLayout or any other layout that relies on MapMessage.asJ= son() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The applic= ation logs a MapMessage that contains an attacker-controlled floating-point=
value. An attacker who can supply a non-finite value can cause the affecte=
d layout to emit malformed JSON, which may corrupt the enclosing log record=
or disrupt downstream log ingestion and parsing. Users are advised to upgr= ade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compl= iant JSON for non-finite values.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49844" target=3D= "_blank" rel=3D"noopener">CVE-2026-49844</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache OpenNLP :: = Core :: ML :: LibSVM</td>
<td>Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Version=
s Affected: =C2=A0 before 3.0.0-M4 (libsvm document categorization module; = introduced in =C2=A0 OPENNLP-1808 and only present on the 3.x line) Descrip= tion: SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled = stream with java.io.ObjectInputStream and calls readObject() without an Obj= ectInputFilter installed. ObjectInputStream materialises every class refere= nced in the stream before the resulting object is cast to SvmDoccatModel, s=
o the cast that follows readObject() executes only after the foreign object=
graph has already been deserialised in full. If a Java deserialization gad= get chain is available on the consumer's classpath, a crafted payload suppl= ied to deserialize() executes arbitrary code in the JVM that loads it. Apac=
he OpenNLP itself does not ship a known gadget chain, so the realistic risk=
is to downstream applications that embed the libsvm module alongside vulne= rable transitive dependencies. The method is public and static, so any call=
er can pass an untrusted stream to it directly. The practical impact is rem= ote code execution against processes that load SvmDoccatModel instances fro=
m untrusted or semi-trusted origins. Mitigation: 3.x users should upgrade t=
o 3.0.0-M4. Users who cannot upgrade immediately should treat all serialize=
d SvmDoccatModel streams as untrusted input unless their provenance is veri= fied, and should avoid invoking SvmDoccatModel.deserialize() on streams sup= plied by end users or fetched from third-party sources without integrity ch= ecks.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43825" target=3D= "_blank" rel=3D"noopener">CVE-2026-43825</a></td>
</tr>
<td class=3D"vendor-product">arcinfo--PcVue</td>
<td>Credentials of built-in users are insecurely stored in the User directo=
ry of PcVue projects, all=C2=A0versions prior to 17.0.0. A local attacker c= ould retrieve users' credentials.=C2=A0 Active Directory accounts are not a= ffected by this vulnerability.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14867" target=3D= "_blank" rel=3D"noopener">CVE-2026-14867</a></td>
</tr>
<td class=3D"vendor-product">arcinfo--PcVue</td>
<td>The encryption algorithm used to protect the configuration of user acco= unts, stored in the built-in user directory of PcVue projects, all=C2=A0ver= sions prior to 17.0.0, is not strong enough for the level of protection req= uired. A local attacker could alter the existing configuration and ultimate=
ly gain privileged access to the PcVue application.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14868" target=3D= "_blank" rel=3D"noopener">CVE-2026-14868</a></td>
</tr>
<td class=3D"vendor-product">Artifex--Artifex</td>
<td>An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artif=
ex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a = crafted input.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38076" target=3D= "_blank" rel=3D"noopener">CVE-2026-38076</a></td>
</tr>
<td class=3D"vendor-product">BAKERSCOT--String::Util</td>
<td>String::Util versions before 1.36 for Perl are susceptible to a regular=
expression denial of service. The trim and rtrim functions stripped traili=
ng whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor=
fails whenever a non-whitespace character follows the whitespace, the rege=
x engine retries the match at each offset of a long whitespace run, produci=
ng quadratic backtracking. The fix replaces \s*$ with \s+$. Any caller that=
passes untrusted input to trim or rtrim can trigger CPU exhaustion with a = string containing a long run of whitespace.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14895" target=3D= "_blank" rel=3D"noopener">CVE-2026-14895</a></td>
</tr>
<td class=3D"vendor-product">balbooa.com--balbooa.com Balbooa Forms extensi=
on for Joomla</td>
<td>The Joomla extension Balbooa Forms is vulnerable to an unauthenticated = arbitrary file upload that allows uploading executable files and leads to f= ull RCE.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56291" target=3D= "_blank" rel=3D"noopener">CVE-2026-56291</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or n= ative) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection e= ndpoint resolved request-supplied environment and OIDC file references in l= itellm_params, allowing a proxy administrator or another privileged caller = with permission to test model connections to read files from the local file= system via an oidc/file/ reference. This issue is fixed in version 1.83.10-= stable.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59819" target=3D= "_blank" rel=3D"noopener">CVE-2026-59819</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or n= ative) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction di=
d not sufficiently validate file paths from uploaded skill ZIP archives, al= lowing an authenticated user with access to LiteLLM LLM API routes or a key=
whose allowed_routes includes /v1/skills, anthropic_routes, or llm_api_rou= tes to upload a crafted skill archive containing path traversal entries tha=
t could be written outside the intended extraction or staging directory. Th=
is issue is fixed in version 1.83.7-stable.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59820" target=3D= "_blank" rel=3D"noopener">CVE-2026-59820</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or n= ative) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails pro= duction create and update paths did not apply the same sandboxing and valid= ation used by the test endpoint, allowing a privileged user with access to = create or update guardrails to submit custom Python code that executed in t=
he LiteLLM proxy environment and could expose secrets available to the proc= ess. This issue is fixed in version 1.82.0-stable.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59821" target=3D= "_blank" rel=3D"noopener">CVE-2026-59821</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or n= ative) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allo= wed an unauthenticated attacker to use a fabricated Authorization header to=
trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM k=
ey validation with an empty UserAPIKeyAuth() object, allowing requests to r= each MCP tooling without a valid LiteLLM key. This issue is fixed in versio=
n 1.84.0.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59822" target=3D= "_blank" rel=3D"noopener">CVE-2026-59822</a></td>
</tr>
<td class=3D"vendor-product">BeyondTrust--Remote Support</td>
<td>A critical pre-authentication vulnerability exists in the authenticatio=
n subsystem of BeyondTrust Remote Support and Privileged Remote Access. Imp= roper validation of authentication data may allow a network-positioned atta= cker to bypass access controls and gain unauthorized access to the applianc=
e, including accounts with elevated privileges. Exploitation requires a spe= cific authentication configuration to be enabled</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40138" target=3D= "_blank" rel=3D"noopener">CVE-2026-40138</a></td>
</tr>
<td class=3D"vendor-product">BeyondTrust--Remote Support</td>
<td>A critical pre-authentication vulnerability exists in the authenticatio=
n subsystem of BeyondTrust Remote Support.=C2=A0Improper processing of auth= entication requests may allow an unauthenticated remote attacker to bypass = access controls and gain unauthorized access to the appliance, including ac= counts with elevated privileges. Exploitation requires a specific authentic= ation configuration to be enabled.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40139" target=3D= "_blank" rel=3D"noopener">CVE-2026-40139</a></td>
</tr>
<td class=3D"vendor-product">BeyondTrust--Remote Support</td>
<td>BeyondTrust Remote Support and Privileged Remote Access contain a high-= severity pre-authentication vulnerability in the network communication subs= ystem.=C2=A0Insufficient validation of client-supplied input may allow an u= nauthenticated remote attacker to trigger a denial-of-service condition aff= ecting appliance availability.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40140" target=3D= "_blank" rel=3D"noopener">CVE-2026-40140</a></td>
</tr>
<td class=3D"vendor-product">BeyondTrust--Remote Support</td>
<td>A high-severity vulnerability exists in a web application component of = BeyondTrust Remote Support and Privileged Remote Access related to the proc= essing of certain input parameters.=C2=A0Insufficient validation of user-su= pplied input may allow an authenticated attacker with limited privileges to=
access unintended resources or data beyond their authorization scope. Expl= oitation is restricted to accounts with specific permissions.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40141" target=3D= "_blank" rel=3D"noopener">CVE-2026-40141</a></td>
</tr>
<td class=3D"vendor-product">BINGOS--Module::Load</td>
<td>Module::Load versions before 0.22 for Perl allow arbitrary modules outs= ide of @INC to be loaded. Module names starting with "::" could be passed t=
o the load function to specify arbitrary module paths. Attackers able to in= fluence module names passed to load could use that bug to execute arbitrary=
code.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2011-10043" target=3D= "_blank" rel=3D"noopener">CVE-2011-10043</a></td>
</tr>
<td class=3D"vendor-product">BitWizard--mtr</td>
<td>mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup()=
function. An attacker who can influence the TXT response used for AS looku=
ps can trigger this bug by returning a DNS response that is larger than 512=
bytes and uses a crafted compression pointer in the answer NAME field.=C2= =A0ipinfo_lookup() function uses the length of the response as the=C2=A0end= -of-message boundary for dn_expand() function.=C2=A0The result is a reliabl=
e crash. This issue exists in the mtr through version 0.96 and it was fixed=
in commit=C2=A048e1794414d338ce47abc0f27c25ade8788af9c3.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14461" target=3D= "_blank" rel=3D"noopener">CVE-2026-14461</a></td>
</tr>
<td class=3D"vendor-product">BOSH-Ecosystem / BOSH (bosh-cli)--bosh-cli</td=
<td>During bosh create-env and bosh delete-env, the CLI uploads compiled CP=
I packages and rendered job templates to the new VM's DAV blobstore over HT= TPS without verifying the server certificate, even though a CA certificate = for that endpoint is available in the installation manifest. A network atta= cker can terminate the TLS connection, harvest the Basic-auth credentials, = and read the rendered-templates archive containing every bootstrap secret f=
or the new BOSH Director, then replay the credentials against the real VM's=
agent for root code execution. Affected versions: bosh-cli versions prior =
to v7.10.4.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47828" target=3D= "_blank" rel=3D"noopener">CVE-2026-47828</a></td>
</tr>
<td class=3D"vendor-product">cakephp--authentication</td>
<td>CakePHP Authentication is an authentication plugin for CakePHP that can=
also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.=
1, the getLoginRedirect() method contains a weakness to backslash bypasses = that allows redirect targets with attacker-controlled hostnames through the=
redirect query string parameter. This issue is fixed in versions 2.11.1, 3= .3.6, and 4.1.1.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55590" target=3D= "_blank" rel=3D"noopener">CVE-2026-55590</a></td>
</tr>
<td class=3D"vendor-product">CAXperts--UPVWebServices/UDiTH Portal</td>
<td>In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal = 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an admin= istrative API endpoint intended for privileged users. Due to missing author= ization checks, this allows the attacker to deactivate the application's li= cense.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35552" target=3D= "_blank" rel=3D"noopener">CVE-2026-35552</a></td>
</tr>
<td class=3D"vendor-product">chevereto--chevereto</td>
<td>Chevereto is a self-hosted media-sharing platform. Starting in version = 3.7.5 and prior to version 4.5.4, when a user enables the private profile o= ption, visiting their profile HTML route (`/username`) correctly returns 40=
4. However, the `/json` AJAX listing endpoint does not apply the same check=
. An unauthenticated caller who knows the target's user ID can retrieve all=
of that user's publicly-scoped images, revealing the username (which shoul=
d be private). This is patched in Chevereto v4.5.4. No known workarounds ar=
e available.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55417" target=3D= "_blank" rel=3D"noopener">CVE-2026-55417</a></td>
</tr>
<td class=3D"vendor-product">Chocobozzz--PeerTube</td>
<td>PeerTube is an ActivityPub-federated video streaming platform. Prior to=
8.2.2, server-side-rendered video watch pages embed a schema.org JSON-LD b= lock by JSON.stringify-ing video metadata without escaping less-than, great= er-than, or slash characters, allowing a value containing the byte sequence=
that closes a script element to inject arbitrary HTML or JavaScript that e= xecutes in the instance origin for visitors to the attacker's videos. This = issue is fixed in version 8.2.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57167" target=3D= "_blank" rel=3D"noopener">CVE-2026-57167</a></td>
</tr>
<td class=3D"vendor-product">CIENA--6500 S-Series</td>
<td>An authentication bypass vulnerability exists in the default SFTP serve=
r component utilized across the Ciena products listed. This vulnerability a= llows a remote, unauthenticated attacker to bypass security controls and ga=
in unauthorized access to the underlying filesystem. Successful exploitatio=
n could allow an attacker to read or modify system files.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5268" target=3D"= _blank" rel=3D"noopener">CVE-2026-5268</a></td>
</tr>
<td class=3D"vendor-product">Cisco--RV130/RV130W</td>
<td>An OS command injection vulnerability exists in the start_bonjour() fun= ction of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and R= V110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configurati=
on parameter is not properly sanitized, which could allow an authenticated = remote attacker to execute arbitrary OS commands with root privileges.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24697" target=3D= "_blank" rel=3D"noopener">CVE-2026-24697</a></td>
</tr>
<td class=3D"vendor-product">Cisco--RV130/RV130W</td>
<td>An OS command injection vulnerability exists in the save_syslog_to_file=
() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3= .55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name conf= iguration parameter is not properly sanitized, which could allow an authent= icated remote attacker to execute arbitrary OS commands with root privilege= s.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24698" target=3D= "_blank" rel=3D"noopener">CVE-2026-24698</a></td>
</tr>
<td class=3D"vendor-product">Cisco--RV130/RV130W</td>
<td>An OS command injection vulnerability exists in the sub_34984() functio=
n of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110=
W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configura= tion parameter is not properly sanitized, which could allow an authenticate=
d remote attacker to execute arbitrary OS commands with root privileges.</t=
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24699" target=3D= "_blank" rel=3D"noopener">CVE-2026-24699</a></td>
</tr>
<td class=3D"vendor-product">Cisco--RV130/RV130W</td>
<td>An OS command injection vulnerability exists in the start_lltd() functi=
on of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV11=
0W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration = parameter is not properly sanitized, which could allow an authenticated rem= ote attacker to execute arbitrary OS commands with root privileges.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-24700" target=3D= "_blank" rel=3D"noopener">CVE-2026-24700</a></td>
</tr>
<td class=3D"vendor-product">Claris--FileMaker Server</td>
<td>An authenticated administrator may be able to achieve arbitrary code ex= ecution on the host system by uploading a malicious file through the Open S= ource LLM setup feature in the Admin Console. This vulnerability has been a= ddressed in FileMaker Server 26.0.1.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43752" target=3D= "_blank" rel=3D"noopener">CVE-2026-43752</a></td>
</tr>
<td class=3D"vendor-product">Cloud Foundry Foundation--bosh-windows-stemcel= l-builder</td>
<td>Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bo= sh-windows-stemcell-builder allows low-privilege authenticated users to ove= rwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AU= THORITY\SYSTEM on the next service restart or reboot. This can lead to full=
host control. Affected versions: bosh-windows-stemcell-builder versions pr= ior to v2019.98.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47830" target=3D= "_blank" rel=3D"noopener">CVE-2026-47830</a></td>
</tr>
<td class=3D"vendor-product">Cloud Foundry Foundation--bosh-windows-stemcel= l-builder</td>
<td>Use of a cryptographically weak random number generator in the Generate= RandomPassword function in bosh-windows-stemcell-builder allows a remote at= tacker to brute-force the resulting SSH login via TCP/22. Affected versions=
: bosh-windows-stemcell-builder versions prior to v2019.98.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47831" target=3D= "_blank" rel=3D"noopener">CVE-2026-47831</a></td>
</tr>
<td class=3D"vendor-product">CloudFoundry BOSH--BOSH CLI</td>
<td>A compromised or malicious BOSH Director can execute arbitrary shell co= mmands on the operator's workstation when the operator runs bosh ssh (or bo=
sh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versio=
ns prior to 7.10.5.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41857" target=3D= "_blank" rel=3D"noopener">CVE-2026-41857</a></td>
</tr>
<td class=3D"vendor-product">CloudFoundry Foundation--BOSH CLI tool</td> <td>The blobs.yml path key traversal vulnerability in the BOSH CLI tool all= ows an attacker to write arbitrary files and exfiltrate sensitive informati= on. Affected versions: BOSH CLI tool versions prior to v7.10.4.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47826" target=3D= "_blank" rel=3D"noopener">CVE-2026-47826</a></td>
</tr>
<td class=3D"vendor-product">CloudFoundry Foundation--bosh-cli</td> <td>Argument Injection in bosh-cli allows a compromised BOSH Director to in= ject arbitrary OpenSSH options into the locally-spawned ssh process when an=
operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH path=
s, leading to local command execution on the operator's workstation. Affect=
ed versions: bosh-cli versions prior to v7.10.4.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47829" target=3D= "_blank" rel=3D"noopener">CVE-2026-47829</a></td>
</tr>
<td class=3D"vendor-product">Code27--Companion Hub</td>
<td>An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically=
proximate attacker to execute arbitrary code via the USB debugging (ADB) a=
nd Android Debug Bridge components</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36027" target=3D= "_blank" rel=3D"noopener">CVE-2026-36027</a></td>
</tr>
<td class=3D"vendor-product">Code27--Companion Hub</td>
<td>A protection mechanism failure in the Code 27 Companion Hub allows an a= ttacker with physical access to completely bypass kiosk restrictions via a = factory reset</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36028" target=3D= "_blank" rel=3D"noopener">CVE-2026-36028</a></td>
</tr>
<td class=3D"vendor-product">copier-org--copier</td>
<td>Copier is a library and CLI app for rendering project templates. In ver= sions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_se= ttings.py`) compares the template URL against a trusted prefix with a raw `= str.startswith` and no path normalization, while the URL is normalized when=
the template is actually fetched (`Path.resolve()` for local paths; libcur=
l dot-segment removal for `https`). A template reference that textually sta= rts with a trusted prefix but contains `..` is therefore granted trust yet = resolves to a different, attacker-controlled template, whose `tasks` / `mig= rations` / `jinja_extensions` then run without the `--trust` prompt - arbit= rary command execution. Version 9.15.2 patches the issue.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53951" target=3D= "_blank" rel=3D"noopener">CVE-2026-53951</a></td>
</tr>
<td class=3D"vendor-product">CycloneDX--cyclonedx-node-npm</td> <td>@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials f= rom npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --w= orkspace values to a subshell without proper sanitization when npm_execpath=
is unset or empty, allowing arbitrary OS command execution with the privil= eges of the invoking user. This issue is fixed in version 5.0.0.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55849" target=3D= "_blank" rel=3D"noopener">CVE-2026-55849</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, the /de2api/share/proxyInfo share interface generates and retur=
ns X-DE-LINK-TOKEN before validating the share password or ticket, allowing=
unauthenticated attackers who know a protected share UUID to obtain a vali=
d link token for subsequent share-related API calls even with missing or in= valid credentials. This issue is fixed in version 2.10.24.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50529" target=3D= "_blank" rel=3D"noopener">CVE-2026-50529</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, a share mode chart data interface only validates that sceneId m= atches the resourceId in the link token and fails to validate whether table=
Id and field IDs in the request body belong to the shared resource, allowin=
g an attacker with a valid share link token to replace dataset identifiers = and retrieve unauthorized data through POST /de2api/chartData/getData. This=
issue is fixed in version 2.10.24.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50530" target=3D= "_blank" rel=3D"noopener">CVE-2026-50530</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, any authenticated user can download (/exportCenter/download/{id= }), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or gen= erate download links (/exportCenter/generateDownloadUri/{id}) for export ta= sks belonging to other users by manipulating the task ID parameter, and the=
/exportCenter/download/{id} endpoint is whitelisted from authentication, a= llowing unauthenticated access to exported files. This issue is fixed in ve= rsion 2.10.24.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53729" target=3D= "_blank" rel=3D"noopener">CVE-2026-53729</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory=
@DePermit permission validation annotation, allowing any authenticated use=
r to specify datasourceId=3D-1, access the built-in engine database, execut=
e arbitrary SQL statements, and read sensitive core data. This issue is fix=
ed in version 2.10.24.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53730" target=3D= "_blank" rel=3D"noopener">CVE-2026-53730</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with = special Unicode characters whose case-conversion behavior differs between D= ataEase validation and H2 parsing, allowing attackers to smuggle dangerous = parameters such as init in malicious H2 JDBC connection strings and achieve=
arbitrary code execution. This issue is fixed in version 2.10.24.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53751" target=3D= "_blank" rel=3D"noopener">CVE-2026-53751</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, the font management module allows authenticated users to submit=
an arbitrary fileTransName when creating a font record; when the record is=
later deleted, the backend concatenates that stored value with the font st= orage directory and passes it to FileUtils.deleteFile() without path traver= sal sanitization, allowing deletion of arbitrary writable files in the appl= ication container. This issue is fixed in version 2.10.24.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55631" target=3D= "_blank" rel=3D"noopener">CVE-2026-55631</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an = authenticated attacker to upload a zip archive disguised with a .ttf extens= ion through FontManage.saveFile and then exploit it through the zip protoco=
l to achieve remote code execution. This issue is fixed in version 2.10.24.= </td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55633" target=3D= "_blank" rel=3D"noopener">CVE-2026-55633</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter=
values directly into generated SQL in Quota2SQLObj.getYWheres() without ap= plying the SQL literal validation and escaping used by other filter paths, = allowing an authenticated user who can create or modify chart definitions o=
r submit chart data requests containing quota filters to inject SQL into qu= eries executed against configured datasources. This issue is fixed in versi=
on 2.10.24.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55635" target=3D= "_blank" rel=3D"noopener">CVE-2026-55635</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, dashboard text components render stored component content with = Vue v-html without server-side HTML sanitization, allowing an authenticated=
user who can edit dashboard component data to inject HTML with executable = event handlers that execute when another user or shared-link visitor views = the dashboard. This issue is fixed in version 2.10.24.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55647" target=3D= "_blank" rel=3D"noopener">CVE-2026-55647</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase is an open source data visualization and analysis tool. Prior =
to 2.10.24, ShareSecretManage uses a hardcoded default share link signature=
key, allowing an attacker who can obtain a passwordless share for a resour=
ce and user to use the known key link-pwd-fit2cloud to forge linkToken JWTs=
, bypass TokenFilter verification, and access backend resources as the shar=
e creator even if the original share has been revoked. This issue is fixed =
in version 2.10.24.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57172" target=3D= "_blank" rel=3D"noopener">CVE-2026-57172</a></td>
</tr>
<td class=3D"vendor-product">decompress--decompress</td>
<td>decompress before 4.2.2 allows arbitrary hardlink creation during archi=
ve extraction, enabling file read disclosure and file corruption. When proc= essing hardlink entries (type =3D=3D=3D 'link'), the x.linkname field from = the archive is passed directly to fs.link() without validation (index.js li=
ne 113). An attacker can craft an archive with a hardlink entry whose linkn= ame is an absolute path to any file on the same filesystem. This creates a = hardlink inside the extraction directory that shares the same inode as the = target file, enabling both reading and overwriting the original file's cont= ent. Hardlinks are limited to files on the same filesystem and cannot targe=
t directories.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39243" target=3D= "_blank" rel=3D"noopener">CVE-2026-39243</a></td>
</tr>
<td class=3D"vendor-product">decompress--decompress</td>
<td>decompress before 4.2.2 contains an improper path containment check tha=
t enables directory traversal and arbitrary file write. The safeMakeDir fun= ction (index.js line 29) and the extraction path validation (index.js line = 106) use String.indexOf() to verify the resolved path is within the output = directory: realDestinationDir.indexOf(realOutputPath) !=3D=3D 0. This check=
is flawed because it does not enforce a path separator boundary. For examp= le, "/tmp/app_config".indexOf("/tmp/app") returns 0, incorrectly passing th=
e check even though /tmp/app_config is outside /tmp/app. Combined with the = unvalidated symlink creation in the same package, an attacker can write arb= itrary files to directories adjacent to the extraction target. This is a by= pass of the fix for CVE-2020-12265. The correct check requires appending a = path separator: realParentPath.indexOf(realOutputPath + path.sep) !=3D=3D 0= .</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39245" target=3D= "_blank" rel=3D"noopener">CVE-2026-39245</a></td>
</tr>
<td class=3D"vendor-product">decompress--decompress</td>
<td>decompress before 4.2.2 allows arbitrary symlink creation during archiv=
e extraction. When processing symlink entries (type =3D=3D=3D 'symlink'), t=
he x.linkname field from the archive is passed directly to fs.symlink() wit= hout validation (index.js line 121). The preventWritingThroughSymlink check=
on line 98 only applies to file entries, not symlink creation. An attacker=
can craft an archive with symlink entries pointing to sensitive files outs= ide the extraction directory (e.g., /etc/passwd), enabling information disc= losure when the application reads the extracted contents.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39246" target=3D= "_blank" rel=3D"noopener">CVE-2026-39246</a></td>
</tr>
<td class=3D"vendor-product">Devolutions--Server</td>
<td>Improper enforcement of a mandatory multi-factor authentication policy =
in Devolutions Server 2026.2.9.0 allows an attacker with valid user credent= ials to bypass the MFA Required policy and authenticate without completing = multi-factor authentication. The problem occurs when DVLS encounters an inv= alid default MFA value.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14536" target=3D= "_blank" rel=3D"noopener">CVE-2026-14536</a></td>
</tr>
<td class=3D"vendor-product">Digi International--Digi PortServer TS</td>
<td>A stored cross-site scripting (XSS) vulnerability in the web management=
interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi=
One IA allows a remote, authenticated administrator to inject script into = certain system configuration fields. The script subsequently executes in th=
e browser of a user who views the affected pages (CWE-79).</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12948" target=3D= "_blank" rel=3D"noopener">CVE-2026-12948</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotl= inked_images when an attacker knew the secured upload URL and the secure_up= loads site setting was enabled. This issue is fixed in versions 2026.6.0, 2= 026.5.1, 2026.4.2, and 2026.1.5.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45788" target=3D= "_blank" rel=3D"noopener">CVE-2026-45788</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached =
to publicly readable categories as allowed_tags, allowed_tag_groups, or req= uired tag groups could leak to anonymous and unauthorized users through cat= egory and group endpoints. This issue is fixed in versions 2026.6.0, 2026.5= .1, 2026.4.2, and 2026.1.5.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49256" target=3D= "_blank" rel=3D"noopener">CVE-2026-49256</a></td>
</tr>
<td class=3D"vendor-product">discourse--discourse</td>
<td>Discourse is an open-source discussion platform. Prior to 2026.6.0, 202= 6.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently=
normalized and escaped before being rendered in the topic list, allowing a=
user who can set a featured link to inject JavaScript when default Content=
Security Policy protections were modified or disabled. This issue is fixed=
in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55424" target=3D= "_blank" rel=3D"noopener">CVE-2026-55424</a></td>
</tr>
<td class=3D"vendor-product">docuForm--GmbH Client v.11.11c</td>
<td>An Insecure Direct Object Reference (IDOR) vulnerability exists in docu= Form GmbH Client v.11.11c allowing a remote attacker to execute arbitrary c= ode via the user settings component, and modify or retrieve sensitive data = associated with other users' accounts.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51923" target=3D= "_blank" rel=3D"noopener">CVE-2026-51923</a></td>
</tr>
<td class=3D"vendor-product">docuForm--GmbH Client v.11.11c</td>
<td>An issue in docuForm GmbH Client v.11.11c allows a remote attacker to e= xecute arbitrary code via the file upload and report.php component</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51924" target=3D= "_blank" rel=3D"noopener">CVE-2026-51924</a></td>
</tr>
<td class=3D"vendor-product">docuForm--GmbH Client v.11.11c</td>
<td>A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Clie=
nt v.11.11c that allows a remote attacker to execute arbitrary code via the=
dfm-menu_report.php component. Attackers can exploit this flaw to read arb= itrary files on the server, including sensitive configuration files, source=
code or system files.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51925" target=3D= "_blank" rel=3D"noopener">CVE-2026-51925</a></td>
</tr>
<td class=3D"vendor-product">docuForm--GmbH FSM Client v.11.11c</td>
<td>An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker =
to obtain sensitive information via the login.php component. A vulnerabilit=
y was identified in the authentication mechanism that allows user enumerati=
on through the login interface. An attacker can differentiate between valid=
and invalid usernames based on variations in server responses. This inform= ation can be leveraged to identify existing accounts and facilitate further=
attacks, including brute-force or credential stuffing.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51926" target=3D= "_blank" rel=3D"noopener">CVE-2026-51926</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Advanced Content Feedback (aka admin_f= eedback)</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_= feedback) allows Stored XSS. This issue affects Advanced Content Feedback (= aka admin_feedback) versions: from 0.0.0 to 2.8.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13231" target=3D= "_blank" rel=3D"noopener">CVE-2026-13231</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Advanced Content Feedback (aka admin_f= eedback)</td>
<td>Incorrect Authorization vulnerability in Drupal Advanced Content Feedba=
ck (aka admin_feedback) allows Forceful Browsing. This issue affects Advanc=
ed Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0.</td=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13232" target=3D= "_blank" rel=3D"noopener">CVE-2026-13232</a></td>
</tr>
<td class=3D"vendor-product">Drupal--AI (Artificial Intelligence)</td> <td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows C= ross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) = versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.</=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13234" target=3D= "_blank" rel=3D"noopener">CVE-2026-13234</a></td>
</tr>
<td class=3D"vendor-product">Drupal--AI (Artificial Intelligence)</td> <td>Missing Authorization vulnerability in Drupal AI (Artificial Intelligen= ce) allows Forceful Browsing. This issue affects AI (Artificial Intelligenc=
e) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3= .</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13235" target=3D= "_blank" rel=3D"noopener">CVE-2026-13235</a></td>
</tr>
<td class=3D"vendor-product">Drupal--AI Agents</td>
<td>Missing Authorization vulnerability in Drupal AI Agents allows Forceful=
Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from=
1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13236" target=3D= "_blank" rel=3D"noopener">CVE-2026-13236</a></td>
</tr>
<td class=3D"vendor-product">Drupal--AI Agents</td>
<td>Incorrect Authorization vulnerability in Drupal AI Agents allows Forcef=
ul Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, fr=
om 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13237" target=3D= "_blank" rel=3D"noopener">CVE-2026-13237</a></td>
</tr>
<td class=3D"vendor-product">Drupal--AI SEO/GEO Analyzer</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS=
. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3.</td=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15085" target=3D= "_blank" rel=3D"noopener">CVE-2026-15085</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Anti-Spam by CleanTalk</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflect=
ed XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9= .7.1.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10770" target=3D= "_blank" rel=3D"noopener">CVE-2026-10770</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Brute force attack protection</td> <td>vulnerability in Drupal Brute force attack protection allows . This iss=
ue affects Brute force attack protection versions: *.*.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11915" target=3D= "_blank" rel=3D"noopener">CVE-2026-11915</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Clean RESTful</td>
<td>vulnerability in Drupal Clean RESTful allows . This issue affects Clean=
RESTful versions: *.*.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15087" target=3D= "_blank" rel=3D"noopener">CVE-2026-15087</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Colorbox</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting = (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.=
0 to 2.2.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58591" target=3D= "_blank" rel=3D"noopener">CVE-2026-58591</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Commerce Core</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This=
issue affects Commerce Core versions: from 3.3.0 to 3.3.6.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10769" target=3D= "_blank" rel=3D"noopener">CVE-2026-10769</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Commerce guest registration</td> <td>vulnerability in Drupal Commerce guest registration allows . This issue=
affects Commerce guest registration versions: *.*.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15089" target=3D= "_blank" rel=3D"noopener">CVE-2026-15089</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Commerce Realex / Global Payments</td> <td>Incorrect Authorization vulnerability in Drupal Commerce Realex / Globa=
l Payments allows Forceful Browsing. This issue affects Commerce Realex / G= lobal Payments versions: from 0.0.0 to 3.0.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13238" target=3D= "_blank" rel=3D"noopener">CVE-2026-13238</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Composer</td>
<td>vulnerability in Drupal Composer allows . This issue affects Composer v= ersions: *.*.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11914" target=3D= "_blank" rel=3D"noopener">CVE-2026-11914</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal AlternativeCommerce (Basket)</t=
<td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows = Object Injection. This issue affects Drupal AlternativeCommerce (Basket) ve= rsions: from 0.0.0 to 2.1.17.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9726" target=3D"= _blank" rel=3D"noopener">CVE-2026-9726</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal Canvas</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scrip= ting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2,=
from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58587" target=3D= "_blank" rel=3D"noopener">CVE-2026-58587</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal Canvas</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scrip= ting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2,=
from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58588" target=3D= "_blank" rel=3D"noopener">CVE-2026-58588</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal core</td>
<td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Drupal core allows Object Injection. This i= ssue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10= .6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*=
, from 0.0.0 to 11.1.*.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55803" target=3D= "_blank" rel=3D"noopener">CVE-2026-55803</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal core</td>
<td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Drupal core allows Object Injection. This i= ssue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10= .6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*=
, from 0.0.0 to 11.1.*.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55804" target=3D= "_blank" rel=3D"noopener">CVE-2026-55804</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal core</td>
<td>URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dr= upal Drupal core allows Content Spoofing. This issue affects Drupal core ve= rsions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.= 14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.</td=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55806" target=3D= "_blank" rel=3D"noopener">CVE-2026-55806</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal core</td>
<td>Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core = allows Server Side Request Forgery. This issue affects Drupal core versions=
: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, fr=
om 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55807" target=3D= "_blank" rel=3D"noopener">CVE-2026-55807</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Drupal core</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripti=
ng (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, f= rom 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from=
0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55808" target=3D= "_blank" rel=3D"noopener">CVE-2026-55808</a></td>
</tr>
<td class=3D"vendor-product">Drupal--ECA: Event - Condition - Action</td> <td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal ECA: Event - Condition - Action allows Obje=
ct Injection. This issue affects ECA: Event - Condition - Action versions: = from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15083" target=3D= "_blank" rel=3D"noopener">CVE-2026-15083</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Examples for Developers</td>
<td>Missing Authorization vulnerability in Drupal Examples for Developers a= llows Forceful Browsing. This issue affects Examples for Developers version=
s: from 0.0.0 to 4.0.6.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11909" target=3D= "_blank" rel=3D"noopener">CVE-2026-11909</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Flag attendance field</td>
<td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Flag attendance field allows Object Injecti= on. This issue affects Flag attendance field versions: from 0.0.0 to 1.2.</=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55809" target=3D= "_blank" rel=3D"noopener">CVE-2026-55809</a></td>
</tr>
<td class=3D"vendor-product">Drupal--FlowDrop</td>
<td>Missing Authorization vulnerability in Drupal FlowDrop allows Forceful = Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58589" target=3D= "_blank" rel=3D"noopener">CVE-2026-58589</a></td>
</tr>
<td class=3D"vendor-product">Drupal--FlowDrop</td>
<td>Missing Authorization vulnerability in Drupal FlowDrop allows Forceful = Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58590" target=3D= "_blank" rel=3D"noopener">CVE-2026-58590</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Formatter Field</td>
<td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Formatter Field allows Object Injection. Th=
is issue affects Formatter Field versions: from 0.0.0 to 2.0.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12535" target=3D= "_blank" rel=3D"noopener">CVE-2026-12535</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Geolocation Field</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in Drupal Geolocation Field allows SQL Injectio=
n. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.</td=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13242" target=3D= "_blank" rel=3D"noopener">CVE-2026-13242</a></td>
</tr>
<td class=3D"vendor-product">Drupal--LocalGov Workflows</td>
<td>Missing Authorization vulnerability in Drupal LocalGov Workflows allows=
Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.= 0.0 to 1.6.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10768" target=3D= "_blank" rel=3D"noopener">CVE-2026-10768</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Location Selector</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in Drupal Location Selector allows SQL Injectio=
n. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15081" target=3D= "_blank" rel=3D"noopener">CVE-2026-15081</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Login Disable</td>
<td>Improper Restriction of Excessive Authentication Attempts vulnerability=
in Drupal Login Disable allows Brute Force. This issue affects Login Disab=
le versions: from 0.0.0 to 2.1.4.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15079" target=3D= "_blank" rel=3D"noopener">CVE-2026-15079</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Mother May I</td>
<td>vulnerability in Drupal Mother May I allows . This issue affects Mother=
May I versions: *.*.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11913" target=3D= "_blank" rel=3D"noopener">CVE-2026-11913</a></td>
</tr>
<td class=3D"vendor-product">Drupal--OpenAI Provider</td>
<td>Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provi= der allows Server Side Request Forgery. This issue affects OpenAI Provider = versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13233" target=3D= "_blank" rel=3D"noopener">CVE-2026-13233</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Paragraphs</td>
<td>Missing Authorization vulnerability in Drupal Paragraphs allows Forcefu=
l Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.</=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13240" target=3D= "_blank" rel=3D"noopener">CVE-2026-13240</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Paragraphs</td>
<td>Missing Authorization vulnerability in Drupal Paragraphs allows Forcefu=
l Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.</=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13241" target=3D= "_blank" rel=3D"noopener">CVE-2026-13241</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Plotly.js Graphing</td>
<td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Plotly.js Graphing allows Object Injection.=
This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55810" target=3D= "_blank" rel=3D"noopener">CVE-2026-55810</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Raw Formatter [Meta Tag Formatter]</td=
<td>vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . Thi=
s issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15086" target=3D= "_blank" rel=3D"noopener">CVE-2026-15086</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Ray Enterprise Translation</td> <td>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterpris=
e Translation allows Cross Site Request Forgery. This issue affects Ray Ent= erprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, fro=
m 11.0.0 to 11.0.4.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15080" target=3D= "_blank" rel=3D"noopener">CVE-2026-15080</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Salesforce Suite</td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Su= ite allows Cross Site Request Forgery. This issue affects Salesforce Suite = versions: from 0.0.0 to 5.1.3.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13243" target=3D= "_blank" rel=3D"noopener">CVE-2026-13243</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Siteimprove Analytics</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Siteimprove Analytics allows Cross-Si=
te Scripting (XSS). This issue affects Siteimprove Analytics versions: from=
0.0.0 to 2.0.1.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15082" target=3D= "_blank" rel=3D"noopener">CVE-2026-15082</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Tagify</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Tagify allows Stored XSS. This issue = affects Tagify versions: from 0.0.0 to 1.2.52.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11908" target=3D= "_blank" rel=3D"noopener">CVE-2026-11908</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Tealium iQ Tag Management</td> <td>Improperly Controlled Modification of Dynamically-Determined Object Att= ributes vulnerability in Drupal Tealium iQ Tag Management allows Object Inj= ection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 t=
o 2.4.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13244" target=3D= "_blank" rel=3D"noopener">CVE-2026-13244</a></td>
</tr>
<td class=3D"vendor-product">Drupal--UI Patterns (SDC in Drupal UI)</td> <td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal UI Patterns (SDC in Drupal UI) allows=
Stored XSS. This issue affects UI Patterns (SDC in Drupal UI) versions: fr=
om 2.0.0 to 2.0.17.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15084" target=3D= "_blank" rel=3D"noopener">CVE-2026-15084</a></td>
</tr>
<td class=3D"vendor-product">Drupal--WissKI</td>
<td>Missing Authorization vulnerability in Drupal WissKI allows Forceful Br= owsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13239" target=3D= "_blank" rel=3D"noopener">CVE-2026-13239</a></td>
</tr>
<td class=3D"vendor-product">elixir-ecto--postgrex</td>
<td>SQL Injection vulnerability in elixir-ecto postgrex allows an attacker = who can influence a LISTEN channel name to inject SQL into the reconnect re= play query, causing a denial of service of the notification connection. Pos= tgrex.Notifications sanitizes channel names with quote_channel/1, which dou= bles double quotes so the name is safe inside a double-quoted identifier. T= his protects the single-statement LISTEN and UNLISTEN paths. On every (re)c= onnect, however, handle_connect/1 replays all registered channels at once b=
y concatenating their LISTEN statements and wrapping them in a dollar-quote=
d anonymous code block (DO $$BEGIN ... END$$). quote_channel/1 does not esc= ape the $$ dollar-quote delimiter that opens and closes this block. The lis= ten/3 guards only reject null bytes and names longer than 63 bytes, so a ch= annel name containing $$ passes validation unchanged. Once such a name is e= mbedded, its $$ prematurely terminates the outer dollar-quoted string and P= ostgreSQL parses the remainder as additional top-level statements. Because = handle_connect/1 runs on every (re)connect, the malformed replay query is r= ejected each time and the notification connection never re-establishes its = subscriptions, silently dropping notifications for every channel sharing th=
at connection. An application is affected when it passes untrusted input (f=
or example a tenant or user identifier) as a channel name to Postgrex.Notif= ications.listen/3. The double-quote doubling prevents forming a fully valid=
injected statement, so arbitrary SQL execution is not possible, but the co= rrupted query reliably breaks the shared notification connection for all te= nants, resulting in denial of service. This issue affects postgrex: from 0.= 16.0 before 0.22.3.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58225" target=3D= "_blank" rel=3D"noopener">CVE-2026-58225</a></td>
</tr>
<td class=3D"vendor-product">elixir-mint--hpax</td>
<td>Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax al= lows unauthenticated denial-of-service via unbounded HPACK integer decoding=
. hpax decodes HPACK variable-length integers with no upper bound on the de= coded value or the number of continuation octets. 'Elixir.HPAX.Types':decod= e_remaining_integer/3 accumulates the integer as int + (value <<< = m), shifting by 7 more bits for each continuation octet and stopping only o=
n a terminating octet or truncated input, never because the integer grew to=
o large. Because BEAM integers are arbitrary precision, a run of N continua= tion octets builds an O(N)-bit bignum and re-adds into an ever-larger bignu=
m on each step, so the total decoding cost is superlinear (about O(N^2)). A=
n unauthenticated attacker who can send an HTTP/2 header block to a server = using this decoder (reached through the 'Elixir.HPAX':decode/2 entry point)=
can supply a small header block that forces a large, attacker-controlled a= mount of CPU (and transient memory), a denial-of-service amplification. Thi=
s issue affects hpax from 0.1.1 before 1.0.4.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58226" target=3D= "_blank" rel=3D"noopener">CVE-2026-58226</a></td>
</tr>
<td class=3D"vendor-product">elixir-mint--mint</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in e= lixir-mint mint (Mint.HTTP1 module) allows a denial of service via an overs= ized chunked transfer-encoded response. This vulnerability is associated wi=
th program files lib/mint/http1.ex and program routines 'Elixir.Mint.HTTP1'= :decode_body/5, 'Elixir.Mint.HTTP1':add_body_to_buffer/2. When Mint decodes=
a chunked HTTP response body, it accumulates each partial fragment of the = current chunk in the connection's data_buffer (an unbounded iolist) via add= _body_to_buffer/2 and does not emit the data to the caller until the full d= eclared chunk length has been received. The chunk size is taken directly fr=
om the server and parsed with no upper bound, so a malicious or compromised=
server can announce one enormous chunk (for example a size line of 7FFFFFF=
F, about 2 GiB) and then send the body bytes slowly without ever completing=
the chunk. The client buffers every received byte while it waits for a com= pletion that never arrives, and because no data responses are produced unti=
l the chunk finishes, a caller that otherwise streams large content-length = bodies safely gains no protection. An unauthenticated remote server (reacha= ble whenever a client follows redirects, fetches user-supplied URLs, or pro= cesses webhooks) can drive the client's memory arbitrarily high and trigger=
an out-of-memory condition. This issue affects mint: from 0.5.0 before 1.9= .1.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56810" target=3D= "_blank" rel=3D"noopener">CVE-2026-56810</a></td>
</tr>
<td class=3D"vendor-product">elixir-plug--plug</td>
<td>Improper Neutralization of Parameter/Argument Delimiters vulnerability =
in elixir-plug plug allows an attacker to inject or override HTTP cookie at= tributes. The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.=
ex builds the Set-Cookie response header by interpolating the cookie value = and its path, domain, same_site, and extra attributes directly into the hea= der without neutralizing the ';' delimiter that separates cookie attributes=
. An application that places attacker-controlled data into a cookie value o=
r attribute (for example via Plug.Conn.put_resp_cookie/4 when reflecting a = username or preference) lets an attacker inject a ';' to append or override=
cookie attributes (such as Domain and Path scope, or dropping the Secure a=
nd HttpOnly flags), enabling cookie tossing and session fixation. Carriage = return, line feed, and null bytes are rejected by Plug.Conn header validati= on, so HTTP response splitting is not possible, but attribute injection thr= ough ';' is not prevented. This issue affects plug: from 0.1.0 before 1.16.=
6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.0 before=
1.19.5, from 1.20.0 before 1.20.3.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56813" target=3D= "_blank" rel=3D"noopener">CVE-2026-56813</a></td>
</tr>
<td class=3D"vendor-product">elixir-plug--plug</td>
<td>Plug.Parsers.MULTIPART, the multipart request-body parser used to handl=
e file uploads and multipart forms, does not enforce its :length budget aga= inst all consumed resources, allowing an unauthenticated remote attacker to=
cause denial of service. The parser charges the :length limit only for par=
t body bytes; part header bytes are never counted, and a part with an empty=
body costs zero. Because every part whose Content-Disposition carries a no= n-empty filename creates a fresh temporary file (via Plug.Upload) and retai=
ns a Plug.Upload struct for the duration of the request, an attacker can se=
nd a single request composed of many empty-body file parts. Such a request = stays well under the configured :length limit (8,000,000 bytes by default) = while creating one temporary file per part, leading to inode and disk exhau= stion and unbounded memory growth. Any application using Plug.Parsers with = the :multipart parser is affected, and no authentication is required, only = reachability of a multipart endpoint over HTTP. This vulnerability is assoc= iated with program files lib/plug/parsers/multipart.ex and program routines=
Plug.Parsers.MULTIPART.parse_multipart/2, Plug.Parsers.MULTIPART.parse_mul= tipart_headers/5, Plug.Parsers.MULTIPART.parse_multipart_body/4, and Plug.P= arsers.MULTIPART.parse_multipart_file/4. This issue affects plug: from 1.4.=
0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from=
1.19.0 before 1.19.5, and from 1.20.0 before 1.20.3.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56814" target=3D= "_blank" rel=3D"noopener">CVE-2026-56814</a></td>
</tr>
<td class=3D"vendor-product">FireBoltt--Smartwatch FB BGS001</td> <td>Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable =
to Improper Authentication, The device accepts GATT Write Request commands = without sufficient authentication or strong session validation. Under speci= fic conditions, previously captured BLE packets can be replayed from a near=
by device to trigger functionality on the smartwatch.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-37271" target=3D= "_blank" rel=3D"noopener">CVE-2026-37271</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `M= assmailer` module filter functionality. An authenticated administrator can = supply crafted filter values when updating a mass email message, causing un= trusted input to be interpolated directly into SQL in the recipient selecti=
on query. Version 0.8.0 patches the issue. Some workarounds are available. = Restrict administrator access to trusted users only, disable the `Massmaile=
r` module if it is not required, audit existing records in the `mod_massmai= ler` table for suspicious filter values, and/or review administrator activi=
ty related to `Massmailer` message updates.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33734" target=3D= "_blank" rel=3D"noopener">CVE-2026-33734</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing =
an authorization check present in other invoice-related endpoints, allowing=
an unauthenticated user with knowledge of an invoice hash to modify the pa= yment gateway associated with an unpaid invoice. An attacker who obtains an=
invoice hash, which may leak through shared URLs, referrer headers, or ema=
il links, can change the `gateway_id` on an unpaid invoice to any payment g= ateway configured in the system. This does not allow redirecting payments t=
o an arbitrary external endpoint, as the gateway must already be installed = and configured by an administrator. The practical impact is further limited=
by the `invoice_accessible_from_hash` system setting. Version 0.8.0 contai=
ns a patch. No known workarounds are available.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42331" target=3D= "_blank" rel=3D"noopener">CVE-2026-42331</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulne= rability in FOSSBilling's IPN callback endpoint. When the Custom payment ad= apter is enabled, an attacker can mark any unpaid invoice as paid and credi=
t the associated client account without making an actual payment, by sendin=
g a single crafted HTTP request. Version 0.8.0 patches the issue. Some work= arounds are available. Disable the Custom payment gateway if not actively n= eeded and/or restrict access to `/ipn.php` at the web server level (e.g., v=
ia IP allowlisting), noting that this may interfere with legitimate payment=
callback processing.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42341" target=3D= "_blank" rel=3D"noopener">CVE-2026-42341</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Prior to version 0.8.0, when a client or staff/admin account is suspended=
or marked inactive, existing authenticated sessions are not invalidated. T=
he session identity loaders in src/di.php (loggedin_client and loggedin_adm= in) only reject sessions if the backing account record no longer exists in = the database. They do not verify that the account's status is still active.=
This allows a suspended or deactivated user to retain full access until th= eir session naturally expires. This issue has been fixed in version 0.8.0.<=
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43918" target=3D= "_blank" rel=3D"noopener">CVE-2026-43918</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in = FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration = values are updated, string values are written into `config.php` without esc= aping single quotes. Because `config.php` is loaded via a bare `include` on=
every HTTP request, an attacker with admin privileges can inject arbitrary=
PHP code that executes on every subsequent request. Version 0.8.0 contains=
a patch. Some workarounds are available. Restrict admin access to trusted = personnel only; audit `config.php` for unexpected PHP code; and/ or at the = reverse proxy/WAF level, restrict access to admin API endpoints that modify=
configuration.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43921" target=3D= "_blank" rel=3D"noopener">CVE-2026-43921</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability =
in the client self-registration endpoint allows any visitor to assign thems= elves to an arbitrary client group during sign-up. Because client groups ca=
n gate promo code eligibility, an attacker may apply group-restricted disco= unt codes and receive unauthorized discounts. Version 0.8.0 contains a patc=
h. As a workaround, administrators can either remove group restrictions fro=
m promo codes or disable client self-registration (Settings =C3=A2=E2=80=A0= =E2=80=99 Clients =C3=A2=E2=80=A0=E2=80=99 Disable signup).</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43925" target=3D= "_blank" rel=3D"noopener">CVE-2026-43925</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Prior to version 0.8.0, a race condition in the cart checkout flow allows=
an authenticated client to apply a promo code beyond its configured maximu=
m uses. By sending concurrent checkout requests before any single request c= ompletes the usage increment, a client can obtain unlimited discounted or f= ree orders from a single-use or limited-use promo code. Version 0.8.0 patch=
es the issue. Some workarounds are available. Disable promo codes entirely = until a patch is available or monitor the `promo` table for `used` values e= xceeding `maxuses` and manually review affected orders.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43927" target=3D= "_blank" rel=3D"noopener">CVE-2026-43927</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IP=
N callbacks and credits the IPN-supplied amount (`mc_gross`) to the client'=
s balance without validating it against the invoice total. Combined with a = $0.05 floating-point epsilon tolerance in the invoice credit-payment logic,=
this allows a client to underpay an invoice by up to $0.04 and still have =
it marked as fully paid. Version 0.8.0 patches the issue. There is no effec= tive workaround without modifying the source code. Merchants using the PayP= alEmail adapter should monitor IPN transactions for amounts that do not mat=
ch their corresponding invoice totals, and manually review and refund suspi= cious payments.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-43928" target=3D= "_blank" rel=3D"noopener">CVE-2026-43928</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Prior to version 0.8.0, low-privileged staff accounts may read sensitive = data via admin API endpoints that lack permission checks. While sibling wri=
te endpoints correctly enforce fine-grained permissions, the corresponding = read endpoints have no authorization guards. Version 0.8.0 contains a fix. = Some workarounds are available. Restrict staff accounts to only those who n= eed access to sensitive data and/or use a reverse proxy or WAF to restrict = access to the affected endpoints.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53640" target=3D= "_blank" rel=3D"noopener">CVE-2026-53640</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Versions 0.6.0 through 0.7.2 have a stored cross-site scripting (XSS) vul= nerability in the client-facing email history views of FOSSBilling. Email H= TML content (`content_html`) is rendered into a JavaScript template literal=
using the `|raw` filter, bypassing all output escaping. An attacker with a= dmin access can inject malicious JavaScript payloads into email content tha=
t execute in the browser of any client who views their email history. Versi=
on 0.8.0 contains a fix. Some workarounds are available. Restrict admin acc= ount access, audit email content in the database for suspicious payloads, a= nd/or monitor client accounts for unusual activity.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53641" target=3D= "_blank" rel=3D"noopener">CVE-2026-53641</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" se= tting is enabled, a logged-in client with an unverified email address (`ema= il_approved =3D 0`) can access all client-area pages (e.g. `/client/balance=
`, `/client/order/list`, `/client/invoice`) and read real account data, inc= luding wallet balances and transaction history. The API-side enforcement co= rrectly restricts unverified clients to only profile-related endpoints, but=
the page-side enforcement is overly permissive, allowing any request whose=
path starts with `/client`. Version 0.8.0 contains a fix. No known workaro= unds that don't involve modifying the source code are available.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53642" target=3D= "_blank" rel=3D"noopener">CVE-2026-53642</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Versions prior to 0.8.0 allow low-privileged staff accounts to perform un= authorized actions via admin API endpoints. The root cause is a combination=
of the `can_always_access` module flag (which grants all staff access to c= ertain modules) and insufficient permission checks or unsafe parameter hand= ling on individual endpoints. Version 0.8.0 contains a fix. Some workaround=
s are available. Restrict staff accounts to only those who need access to s= ensitive settings and/or use a reverse proxy or WAF to restrict access to t=
he affected endpoints to trusted IP addresses or higher-privilege roles.</t=
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53643" target=3D= "_blank" rel=3D"noopener">CVE-2026-53643</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and=
reset API key service secrets for orders that are no longer in an `active`=
state (e.g., `suspended`, `canceled`). The root cause is missing order-sta=
te validation in two client API endpoints, despite an `isActive()` helper a= lready existing in the `Serviceapikey` module and the frontend UI correctly=
gating access on `order.status =3D=3D 'active'`. Version 0.8.0 contains a = fix. Some workarounds are available. If the `Serviceapikey` module is not n= eeded, uninstall it to remove the affected endpoints. One may also use a re= verse proxy or WAF to restrict access to `/api/client/order/service` and `/= api/client/serviceapikey/reset` based on application-level order-state logi= c.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53644" target=3D= "_blank" rel=3D"noopener">CVE-2026-53644</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Versions prior to 0.8.0 allow a low-privileged staff account to grant arb= itrary module permissions to itself through the admin API, resulting in per= sistent privilege escalation. A staff user that only has `staff.create_and_= edit_staff` can call `/api/admin/staff/permissions_update` targeting their = own account and write any permission structure, bypassing the intended role= -based access control boundary. Version 0.8.0 patches the issue. Some worka= rounds are available. Restrict the `staff.create_and_edit_staff` permission=
to only highly trusted staff members and/or use a reverse proxy or WAF to = restrict access to `/api/admin/staff/permissions_update` to specific truste=
d roles.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53645" target=3D= "_blank" rel=3D"noopener">CVE-2026-53645</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record alre= ady exists for a client (from a previous unexpired reset request), subseque=
nt calls to the `reset_password` guest API endpoint reuse the existing toke=
n instead of generating a new one. The 15-minute validity window is anchore=
d to the first request's `created_at` timestamp, not the time of the most r= ecent email. An attacker who obtained the original reset link remains able =
to use it even after the victim requests a new reset, because the original = token is never invalidated or rotated. Version 0.8.0 patches the issue. Som=
e workarounds are available. Configure a reverse proxy (e.g., Nginx, Apache=
, Cloudflare) to apply per-IP rate limiting to the `/client/reset-password`=
endpoint to minimize the window of opportunity, and/or manually clear expi= red `client_password_reset` records from the database after a client report=
s a suspected compromise.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53646" target=3D= "_blank" rel=3D"noopener">CVE-2026-53646</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API e= ndpoint is accessible without authentication. Any caller with a valid API k=
ey can retrieve all custom configuration parameters (`custom_*` fields) sto= red in the key's database record. These custom fields are populated by bill= ing administrators and can contain business-sensitive data such as pricing = tiers, feature flags, rate limits, expiry overrides, or access scope data. = Version 0.8.0 patches the issue. Some workarounds are available. Administra= tors can avoid storing sensitive data in `custom_*` API key configuration f= ields, monitor API logs for suspicious calls to `/api/guest/serviceapikey/g= et_info`, and/or disable the Serviceapikey module if not in active use.</td=
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53647" target=3D= "_blank" rel=3D"noopener">CVE-2026-53647</a></td>
</tr>
<td class=3D"vendor-product">FOSSBilling--FOSSBilling</td>
<td>FOSSBilling is a free, open-source billing and client management system=
. Prior to version 0.8.1, downloadable product files are stored using a det= erministic filename-derived path. When an administrator uploads a file for =
a downloadable product, FOSSBilling stores the file as `md5(<original fi= lename>)` under the uploads directory. Because the stored path depends o= nly on the client-supplied filename, two different downloadable products, o=
r product/order files, uploaded with the same original filename will resolv=
e to the same stored file path. A later upload can overwrite an earlier upl= oad, causing customers or administrators downloading the earlier product to=
receive the later file instead. Version 0.8.1 patches the issue. Some work= arounds are available. Restrict the `servicedownloadable.manage` permission=
to fully trusted administrators only. As an operational mitigation, ensure=
downloadable product files use unique filenames before upload. This reduce=
s accidental collisions but does not fully address the underlying issue.</t=
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53648" target=3D= "_blank" rel=3D"noopener">CVE-2026-53648</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 16.18.3, pos= sible path traversal and local file inclusion were possible through secure = local resource access in the Chrome PDF Generator. This issue is fixed in v= ersion 16.18.3.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41482" target=3D= "_blank" rel=3D"noopener">CVE-2026-41482</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 16.19.0 and = 15.109.0, path traversal via download_backups was possible due to lack of h= ardening. This issue is fixed in versions 16.19.0 and 15.109.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42219" target=3D= "_blank" rel=3D"noopener">CVE-2026-42219</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 16.18.3 and = 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which=
could potentially work on self-hosted sites if database permissions are no=
t well aligned and MySQL FILE privileges are available. This issue is fixed=
in versions 16.18.3 and 15.108.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47199" target=3D= "_blank" rel=3D"noopener">CVE-2026-47199</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 15.107.5 and=
16.18.2, an endpoint in reportview lacked appropriate permission checks an=
d that has since been fixed. This vulnerability is fixed in 15.107.5 and 16= .18.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-47422" target=3D= "_blank" rel=3D"noopener">CVE-2026-47422</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 16.20.0 and = 15.110.0, users without write access could attach files to any doctype thro= ugh file-handling API endpoints such as add_attachments. This issue is fixe=
d in versions 16.20.0 and 15.110.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48127" target=3D= "_blank" rel=3D"noopener">CVE-2026-48127</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 16.19.0, aut= horization bypass was possible via the update_page endpoint in Workspace be= cause public workspaces did not receive the required Workspace Manager edit=
check. This issue is fixed in version 16.19.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49394" target=3D= "_blank" rel=3D"noopener">CVE-2026-49394</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 16.23.0 and = 15.112.0, TarSlip RCE was possible in Package Import because tarfile member=
s were not sufficiently checked before extraction. This issue is fixed in v= ersions 16.23.0 and 15.112.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55852" target=3D= "_blank" rel=3D"noopener">CVE-2026-55852</a></td>
</tr>
<td class=3D"vendor-product">frappe--frappe</td>
<td>Frappe is a full-stack web application framework. Prior to 16.16.0 and = 15.106.0, user enumeration could be performed via the reset_password endpoi= nt. This issue is fixed in versions 16.16.0 and 15.106.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58503" target=3D= "_blank" rel=3D"noopener">CVE-2026-58503</a></td>
</tr>
<td class=3D"vendor-product">FreeRDP--FreeRDP</td>
<td>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior =
to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in = update_read_delta_points in libfreerdp/core/orders.c when multiplying an at= tacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious = RDP peer to allocate an undersized heap buffer and then write beyond it dur= ing initialization. This issue is fixed in version 3.28.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57156" target=3D= "_blank" rel=3D"noopener">CVE-2026-57156</a></td>
</tr>
<td class=3D"vendor-product">FreeRDP--FreeRDP</td>
<td>FreeRDP is a free implementation of the Remote Desktop Protocol. From 3= .21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an inco= mplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfre= erdp/codec/planar.c, allowing a malicious RDP server to send a truncated RD= PGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the inpu=
t buffer. This issue is fixed in version 3.28.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57158" target=3D= "_blank" rel=3D"noopener">CVE-2026-57158</a></td>
</tr>
<td class=3D"vendor-product">FreeType--FreeType 2.14.3</td>
<td>An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versi= ons before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/= ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Desig= n_Coordinates</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50811" target=3D= "_blank" rel=3D"noopener">CVE-2026-50811</a></td>
</tr>
<td class=3D"vendor-product">Fuji Electric Co.,Ltd.--Pupsman</td> <td>Uncontrolled search path element issue exists in Pupsman versions prior=
to 3.9.0. If a crafted DLL file is placed in the same folder as the affect=
ed installer and the installer is executed, arbitrary code may be executed = with SYSTEM privilege.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56437" target=3D= "_blank" rel=3D"noopener">CVE-2026-56437</a></td>
</tr>
<td class=3D"vendor-product">Fuji Electric Co.,Ltd.--Pupsman</td>
<td>Incorrect default permissions issue exists in Pupsman versions prior to=
3.9.0. An attacker can place a malicious executable in the installation fo= lder, which results in arbitrary code execution with SYSTEM privilege</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57895" target=3D= "_blank" rel=3D"noopener">CVE-2026-57895</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav=
allows an unauthenticated visitor to exhaust server memory and CPU by requ= esting image derivatives with oversized dimensions through URL query image = actions such as forceResize in Grav::fallbackUrl, which passes request para= meters to ImageMedium magic actions without a dimension or pixel ceiling. T= his issue is fixed in versions 1.7.53 and 2.0.0-rc.8.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53653" target=3D= "_blank" rel=3D"noopener">CVE-2026-53653</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.=
0, the PDO::tableExists method interpolates its table argument directly int=
o a raw SQL query string without sanitization, escaping, quoting, or whitel= isting, allowing attacker-controlled table names passed by consuming plugin=
or developer code to execute arbitrary SQL against the configured database=
. This issue is fixed in version 1.2.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58492" target=3D= "_blank" rel=3D"noopener">CVE-2026-58492</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.=
0, Database::__call builds PDO DSN strings by directly concatenating user-c= onfigurable YAML values from fields such as host, dbname, charset, server, = database, directory, and filename without sanitization or validation, allow= ing an administrator with plugin configuration access to inject DSN attribu= tes or path traversal values. This issue is fixed in version 1.2.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58493" target=3D= "_blank" rel=3D"noopener">CVE-2026-58493</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>grav-plugin-admin is an HTML user interface that provides a way to conf= igure Grav and create and modify pages. In 1.10.52 and earlier, an authenti= cated attacker with admin.users permission can change the password of any u= ser account, including the super administrator, by sending a direct POST re= quest to /admin/user/{username}?task=3Dsave with data[password] because sav= eUser authorizes the caller's user-management permission but does not verif=
y whether the caller may edit the target user. This issue is expected to be=
fixed in version 1.10.53.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59190" target=3D= "_blank" rel=3D"noopener">CVE-2026-59190</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav is a file-based Web platform. Prior to 2.0.0, an authenticated adm= in.super user can crash Grav or fill the disk by uploading a specially craf= ted ZIP archive through the Direct Install tool because Installer::unZip ca= lls ZipArchive::extractTo without limits on uncompressed size, entry count,=
or directory depth. This issue is fixed in version 2.0.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59193" target=3D= "_blank" rel=3D"noopener">CVE-2026-59193</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.4 and 5= .4.4, Kirby sites using the pages field with roles that have the pages.acce=
ss permission disabled allowed authenticated users to provide an inaccessib=
le parent page or site to the page picker backend and confirm arbitrary pag=
e existence and retrieve title field values. This issue is fixed in version=
s 4.9.4 and 5.4.4.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49274" target=3D= "_blank" rel=3D"noopener">CVE-2026-49274</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.4 and 5= .4.4, Kirby sites using the writer field in any blueprint allowed a scripti=
ng link to be included as the target of a link or email link in writer mark=
components, making the target clickable by the user who entered it and ena= bling self cross-site scripting in the Panel. This issue is fixed in versio=
ns 4.9.4 and 5.4.4.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49276" target=3D= "_blank" rel=3D"noopener">CVE-2026-49276</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.4 and 5= .4.4, Kirby sites and plugins using the Kirby Http Remote class, including = Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP=
requests with untrusted data in the headers option could allow newline cha= racters in a header value to inject a separate unintended request header to=
the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50188" target=3D= "_blank" rel=3D"noopener">CVE-2026-50188</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.4 and 5= .4.4, Kirby sites and plugins that use the writer or list fields or call Do= m::sanitize(), Sane::sanitize(), Sane::Html::sanitize(), Sane::Svg::sanitiz= e(), Sane::Xml::sanitize(), Sane::sanitizeFile(), or file sanitizeContents(=
) with untrusted input allow malicious markup injected as children of an un= known HTML or XML tag to pass through Dom::sanitize() without being correct=
ly sanitized, causing stored cross-site scripting. This issue is fixed in v= ersions 4.9.4 and 5.4.4.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54002" target=3D= "_blank" rel=3D"noopener">CVE-2026-54002</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.4 and f= rom 5.4.4, Kirby sites with no configured user accounts that run on publicl=
y accessible servers behind a reverse proxy setting the Forwarded, X-Client= -IP, or X-Real-IP request header could allow remote attackers to install th=
e Panel and create the first admin user because local-IP checks trusted tho=
se headers incorrectly. This issue is fixed in versions 4.9.4 and 5.4.4.</t=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54003" target=3D= "_blank" rel=3D"noopener">CVE-2026-54003</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.4 and 5= .4.4, Kirby sites with content.fileRedirects enabled could redirect unauthe= nticated clean file URL requests for files stored in top-level draft pages =
to physical media URLs without checking page access permissions or preview = tokens, leading to disclosure of draft file contents. This issue is fixed i=
n versions 4.9.4 and 5.4.4.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54004" target=3D= "_blank" rel=3D"noopener">CVE-2026-54004</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.4 and 5= .4.4, Kirby sites where a role has the pages.access permission disabled all= owed authenticated users who know or guess page IDs or UUIDs to retrieve pa=
ge information, including full content and metadata, for arbitrary publishe=
d pages through the /api/site/find route without authorization to access th= ose pages. This issue is fixed in versions 4.9.4 and 5.4.4.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54005" target=3D= "_blank" rel=3D"noopener">CVE-2026-54005</a></td>
</tr>
<td class=3D"vendor-product">GNU wget--Wget</td>
<td>GNU Wget does not validate the IP address provided by an FTP PASV respo= nse while operating in FTP passive mode. A malicious FTP server, or an HTTP=
server that redirects to an FTP URL, can exploit this behavior to redirect=
Wget's data connection to an arbitrary IP address and port. This allows an=
attacker to forge server-side requests (SSRF) from the machine running Wge=
t, potentially accessing localhost services or internal network resources.<=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15146" target=3D= "_blank" rel=3D"noopener">CVE-2026-15146</a></td>
</tr>
<td class=3D"vendor-product">GNU--patch</td>
<td>GNU patch is vulnerable to a NULL pointer dereference when processing a=
specially crafted unified-diff patch file. Improper handling of consecutiv=
e end-of-file newline markers can corrupt internal hunk (single block of ch= anges in diff) data structures, causing the application to pass a NULL poin= ter to fwrite() during patch processing. An attacker can trigger this condi= tion with a malicious patch file, causing the utility to crash and resultin=
g in a denial of service. This issue has been fixed in the commit e6d6a4e02= 1660679d7fc9150f981d4920f722313</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56288" target=3D= "_blank" rel=3D"noopener">CVE-2026-56288</a></td>
</tr>
<td class=3D"vendor-product">GNU--patch</td>
<td>GNU patch is vulnerable to a denial of service (DoS) due to improper va= lidation of hunk (single block of changes in diff) line offsets in unified-= diff input. A specially crafted patch can specify an extremely large line n= umber, causing the application to enter an effectively infinite processing = loop while attempting to locate the requested position. This results in exc= essive CPU consumption and prevents the process from completing. An attacke=
r can trigger this behavior by supplying a malicious patch file, causing th=
e utility to become unresponsive and require manual termination. This issue=
has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56289" target=3D= "_blank" rel=3D"noopener">CVE-2026-56289</a></td>
</tr>
<td class=3D"vendor-product">Go standard library--crypto/tls</td> <td>Handshakes which used Encrypted Client Hello could be de-anonymized by =
a passive network observer due to a disclosure of pre-shared key identities=
in the unencrypted client hello.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42505" target=3D= "_blank" rel=3D"noopener">CVE-2026-42505</a></td>
</tr>
<td class=3D"vendor-product">Go standard library--os</td>
<td>On Unix systems, opening a file in an os.Root improperly follows symlin=
ks to locations outside of the Root when the final path component of the a = path is a symbolic link and the path ends in /. For example, 'root.Open("sy= mlink/")' will open "symlink" even when "symlink" is a symbolic link pointi=
ng outside of the root.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39822" target=3D= "_blank" rel=3D"noopener">CVE-2026-39822</a></td>
</tr>
<td class=3D"vendor-product">gohugoio--hugo</td>
<td>Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content=
files in several markup formats. Files mapped to the text/html media type = (typically .html files under /content, or pages produced by a content adapt=
er that sets content.mediaType =3D "text/html") had their body emitted verb= atim into the rendered page. A site that ingests HTML content from an untru= sted source could therefore be served stored cross-site scripting. This vul= nerability is fixed in 0.162.0.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50133" target=3D= "_blank" rel=3D"noopener">CVE-2026-50133</a></td>
</tr>
<td class=3D"vendor-product">gohugoio--hugo</td>
<td>Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.G= etRemote enforces security.http.urls on the URL it is called with, but it d=
id not re-validate intermediate URLs on HTTP 3xx redirects. An allowed serv=
er (or an attacker controlling its DNS or response) could therefore redirec=
t the request to a host that the policy was meant to forbid and Hugo would = fetch from the redirected target. The same bypass also lifted any host-shap=
e restriction the operator had put in place. This vulnerability is fixed in=
0.162.0.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50134" target=3D= "_blank" rel=3D"noopener">CVE-2026-50134</a></td>
</tr>
<td class=3D"vendor-product">gohugoio--hugo</td>
<td>Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression = made =C2=A0RootMappingFs.statRoot=C2=A0 use =C2=A0Stat=C2=A0 (follows symli= nks) instead of =C2=A0Lstat=C2=A0, so a direct =C2=A0resources.Get=C2=A0 of=
a symlink pointing outside its mount returned the target's contents - lett= ing a symlink planted in a local mount (e.g. a vendored =C2=A0themes/=C2=A0=
theme) read arbitrary files accessible to the Hugo user. Go-module themes = from GitHub (symlinks stripped) and directory walks were unaffected. Fixed =
in 0.162.0.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50135" target=3D= "_blank" rel=3D"noopener">CVE-2026-50135</a></td>
</tr>
<td class=3D"vendor-product">gohugoio--hugo</td>
<td>Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's defa= ult code-block renderer wrote the Markdown code-fence language or info-stri=
ng into the code class=3D"language-=C2=A6" data-lang=3D"=C2=A6" wrapper wit= hout HTML escaping. A fence info-string containing a quote and a script pay= load breaks out of the attribute and injects a live script element. This is= sue is fixed in 0.163.3.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58402" target=3D= "_blank" rel=3D"noopener">CVE-2026-58402</a></td>
</tr>
<td class=3D"vendor-product">gohugoio--hugo</td>
<td>Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's=
virtual filesystem is designed so that files under a mount cannot reach ou= tside the mount tree, but a regression caused RootMappingFs.statRoot to cal=
l Stat, which follows symlinks, instead of Lstat, so a direct os.ReadFile "= somefile" where somefile was a symlink pointing outside the mount would ret= urn the target's contents. This effectively let a symlink planted inside a = theme or local mount read arbitrary files reachable to the user running hug=
o. This issue is fixed in v0.163.1.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58403" target=3D= "_blank" rel=3D"noopener">CVE-2026-58403</a></td>
</tr>
<td class=3D"vendor-product">gohugoio--hugo</td>
<td>Hugo is a static site generator. From v0.162.0 through v0.163.0, the de= fault security.http.urls policy denies requests to loopback, internal, and = cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal=
notation, so alternate IPv4 encodings of the same addresses, including int= eger, hex, or octal, passed the policy. When a template passes an untrusted=
or data-derived URL to resources.GetRemote and the host platform uses the = cgo system resolver, these encodings resolve to the blocked address, allowi=
ng build-time server-side requests to loopback and internal services, inclu= ding the cloud-metadata endpoint in hosted or CI builds; the same check is = reused on redirects, so the gap also applies to each redirect hop. This iss=
ue is fixed in v0.163.1.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58404" target=3D= "_blank" rel=3D"noopener">CVE-2026-58404</a></td>
</tr>
<td class=3D"vendor-product">Google Cloud--Apigee</td>
<td>An Improper Input Validation vulnerability in BigQuery DAO in Google Cl= oud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an = authenticated attacker to exfiltrate cross-tenant data. This vulnerability = was patched on 12 June 2026 on the Apigee Servers, and no customer action i=
s needed.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12879" target=3D= "_blank" rel=3D"noopener">CVE-2026-12879</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 al= lowed a remote attacker to execute arbitrary code inside a sandbox via a cr= afted HTML page. (Chromium security severity: Medium)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15107" target=3D= "_blank" rel=3D"noopener">CVE-2026-15107</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Integer overflow in Extensions API in Google Chrome prior to 150.0.7871= .115 allowed an attacker who convinced a user to install a malicious extens= ion to perform an out of bounds memory read via a crafted Chrome Extension.=
(Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15108" target=3D= "_blank" rel=3D"noopener">CVE-2026-15108</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 all= owed a remote attacker to obtain potentially sensitive information from pro= cess memory via a crafted HTML page. (Chromium security severity: High)</td=
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15109" target=3D= "_blank" rel=3D"noopener">CVE-2026-15109</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Extensions in Google Chrome prior to 150.0.7871.115 a= llowed an attacker who convinced a user to install a malicious extension to=
potentially exploit heap corruption via a crafted Chrome Extension. (Chrom= ium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15110" target=3D= "_blank" rel=3D"noopener">CVE-2026-15110</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Views in Google Chrome prior to 150.0.7871.115 allowe=
d a remote attacker who convinced a user to engage in specific UI gestures =
to potentially exploit heap corruption via a crafted HTML page. (Chromium s= ecurity severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15111" target=3D= "_blank" rel=3D"noopener">CVE-2026-15111</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowe=
d a remote attacker to potentially exploit heap corruption via a crafted HT=
ML page. (Chromium security severity: Critical)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15112" target=3D= "_blank" rel=3D"noopener">CVE-2026-15112</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Autofill in Google Chrome on Android prior to 150.0.7= 871.115 allowed a remote attacker to potentially perform a sandbox escape v=
ia a crafted HTML page. (Chromium security severity: High)</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15113" target=3D= "_blank" rel=3D"noopener">CVE-2026-15113</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Out of bounds read and write in Codecs in Google Chrome prior to 150.0.= 7871.115 allowed a remote attacker to potentially exploit heap corruption v=
ia a crafted video file. (Chromium security severity: High)</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15114" target=3D= "_blank" rel=3D"noopener">CVE-2026-15114</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Insufficient validation of untrusted input in WebAppInstalls in Google = Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypas=
s same origin policy via a crafted HTML page. (Chromium security severity: = High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15115" target=3D= "_blank" rel=3D"noopener">CVE-2026-15115</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowe=
d a remote attacker to execute arbitrary code inside a sandbox via a crafte=
d HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15116" target=3D= "_blank" rel=3D"noopener">CVE-2026-15116</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Payments in Google Chrome prior to 150.0.7871.115 all= owed a remote attacker who convinced a user to engage in specific UI gestur=
es to potentially exploit heap corruption via a crafted HTML page. (Chromiu=
m security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15117" target=3D= "_blank" rel=3D"noopener">CVE-2026-15117</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Input in Google Chrome prior to 150.0.7871.115 allowe=
d a remote attacker to execute arbitrary code inside a sandbox via a crafte=
d HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15118" target=3D= "_blank" rel=3D"noopener">CVE-2026-15118</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a=
remote attacker who had compromised the renderer process to potentially pe= rform a sandbox escape via a crafted HTML page. (Chromium security severity=
: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15119" target=3D= "_blank" rel=3D"noopener">CVE-2026-15119</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Core in Google Chrome on Windows prior to 150.0.7871.= 115 allowed a remote attacker who had compromised the renderer process to p= otentially perform a sandbox escape via a crafted HTML page. (Chromium secu= rity severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15120" target=3D= "_blank" rel=3D"noopener">CVE-2026-15120</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allow=
ed a remote attacker to execute arbitrary code inside a sandbox via a craft=
ed HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15121" target=3D= "_blank" rel=3D"noopener">CVE-2026-15121</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Insufficient validation of untrusted input in Codecs in Google Chrome o=
n Windows prior to 150.0.7871.115 allowed a remote attacker who had comprom= ised the renderer process to potentially perform a sandbox escape via a cra= fted HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15122" target=3D= "_blank" rel=3D"noopener">CVE-2026-15122</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in DOM in Google Chrome prior to 150.0.787= 1.115 allowed a remote attacker to potentially exploit heap corruption via =
a crafted HTML page. (Chromium security severity: High)</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15123" target=3D= "_blank" rel=3D"noopener">CVE-2026-15123</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Insufficient policy enforcement in Passwords in Google Chrome prior to = 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a=
crafted HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15124" target=3D= "_blank" rel=3D"noopener">CVE-2026-15124</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Forms in Google Chrome prior to 150.0.7= 871.115 allowed a remote attacker to execute arbitrary code inside a sandbo=
x via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15125" target=3D= "_blank" rel=3D"noopener">CVE-2026-15125</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowe=
d a remote attacker to execute arbitrary code inside a sandbox via a crafte=
d HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15126" target=3D= "_blank" rel=3D"noopener">CVE-2026-15126</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7= 871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS=
) via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15127" target=3D= "_blank" rel=3D"noopener">CVE-2026-15127</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Forms in Google Chrome prior to 150.0.7= 871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS=
) via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15128" target=3D= "_blank" rel=3D"noopener">CVE-2026-15128</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Views in Google Chrome prior to 150.0.7871.115 allowe=
d a remote attacker to potentially exploit heap corruption via a crafted HT=
ML page. (Chromium security severity: Critical)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15129" target=3D= "_blank" rel=3D"noopener">CVE-2026-15129</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Insufficient policy enforcement in Navigation in Google Chrome prior to=
150.0.7871.115 allowed a remote attacker to bypass site isolation via a cr= afted HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15130" target=3D= "_blank" rel=3D"noopener">CVE-2026-15130</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Inappropriate implementation in Navigation in Google Chrome prior to 15= 0.0.7871.115 allowed a remote attacker to bypass site isolation via a craft=
ed HTML page. (Chromium security severity: Medium)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15131" target=3D= "_blank" rel=3D"noopener">CVE-2026-15131</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowe=
d a remote attacker to execute arbitrary code inside a sandbox via a crafte=
d HTML page. (Chromium security severity: High)</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15132" target=3D= "_blank" rel=3D"noopener">CVE-2026-15132</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in InterestGroups in Google Chrome prior to 150.0.7871.1=
15 allowed a remote attacker to execute arbitrary code inside a sandbox via=
a crafted HTML page. (Chromium security severity: High)</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15133" target=3D= "_blank" rel=3D"noopener">CVE-2026-15133</a></td>
</tr>
<td class=3D"vendor-product">GPAC--GPAC</td>
<td>A NULL pointer dereference in smooth_parse_stream_index() in src/media_= tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5= d2ef70845b5 allows attackers to cause a denial of service</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50810" target=3D= "_blank" rel=3D"noopener">CVE-2026-50810</a></td>
</tr>
<td class=3D"vendor-product">gristlabs--grist-core</td>
<td>Grist is spreadsheet software using Python as its formula language. Pri=
or to 1.7.15, Grist contained two cross-site scripting vulnerabilities wher=
e an attacker-controlled value reached a link's href without scheme validat= ion, so a javascript URL could run in a victim's Grist origin on a single c= lick. On the account-selection page, /welcome/select-account used its next = query parameter as the account buttons' link target. In document tours, the=
GristDocTour table's Link_URL column became a clickable button, allowing a=
n editor of a shared document to store a javascript URL there that ran when=
another user opened the document and clicked the tour link. Because the sc= ript runs in the victim's authenticated session, it can call Grist APIs as = the victim, reading or modifying data and changing sharing settings and acc= ess rules. A document editor could therefore escalate to owner-level access=
. This issue is fixed in version 1.7.15.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55665" target=3D= "_blank" rel=3D"noopener">CVE-2026-55665</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to version 8.6= .1, the GET /api/v1/{object}/selectlist API endpoint is missing an authoriz= ation check. Any user who can log into Snipe-IT - regardless of permissions=
- can retrieve a paginated list of all user accounts using only their web = session cookie. No API token or elevated permissions are required. This exp= oses usernames, display names, employee numbers, and user IDs for every act= ive account in the system if FMCS is not enabled, and within the company th=
ey belong to if FMCS is enabled. Version 8.6.1 contains a patch.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48492" target=3D= "_blank" rel=3D"noopener">CVE-2026-48492</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Acti= onlog::logaction() stores the request User-Agent header and ReportsControll= er::postActivityReport() writes that value to the Activity Report CSV witho=
ut formula escaping, allowing a low-privileged authenticated user to store =
a formula-like User-Agent that may execute when a report viewer opens the e= xported CSV in spreadsheet software. This issue is fixed in version 8.5.0.<=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55452" target=3D= "_blank" rel=3D"noopener">CVE-2026-55452</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, Comm= onMark escapes raw HTML but does not sanitize javascript: URIs in Markdown = hyperlinks, allowing a user with assets.edit permission to place a maliciou=
s link in a markdown-textarea custom field that executes arbitrary JavaScri=
pt when another user opens the asset detail page and clicks the link. This = issue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55464" target=3D= "_blank" rel=3D"noopener">CVE-2026-55464</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, Uplo= adFileRequest sanitizes SVG content only when PHP finfo reports image/svg+x=
ml and UploadedFilesController serves attachments inline without using Stor= ageHelper::allowSafeInline(), allowing a low-privilege user to upload activ=
e XHTML or XML content that is later served same-origin and executes JavaSc= ript in a viewer's browser. This issue is fixed in version 8.6.2.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55466" target=3D= "_blank" rel=3D"noopener">CVE-2026-55466</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Acti= onlogController::displaySig concatenates the route filename parameter into =
a private upload-directory path without sanitization, allowing an authentic= ated attacker to traverse outside the intended directory and read arbitrary=
files accessible to the web server process. This issue is fixed in version=
8.5.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55474" target=3D= "_blank" rel=3D"noopener">CVE-2026-55474</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST=
/account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} = accepts cancel_by_admin as a URL path segment without sufficient authorizat= ion, allowing an authenticated user to supply a victim user ID and silently=
cancel that user's pending asset requests. This issue is fixed in version = 8.6.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55476" target=3D= "_blank" rel=3D"noopener">CVE-2026-55476</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST=
/api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but=
does not authorize access to the referenced license object, allowing a low= -privilege user with predefined-kit permissions to bind a license they shou=
ld not be able to access or manage into a kit. This issue is fixed in versi=
on 8.6.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55478" target=3D= "_blank" rel=3D"noopener">CVE-2026-55478</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the = legacy single-seat license checkin flow authorizes the action with the chec= kout permission instead of the checkin permission, allowing a user who can = assign licenses but not unassign them to directly access the old checkin en= dpoint and reclaim a license seat assigned to another user or asset. This i= ssue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55479" target=3D= "_blank" rel=3D"noopener">CVE-2026-55479</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.2, defa= ult.blade.php renders header_color and related branding color settings insi=
de a CSS style block with HTML escaping that is insufficient for the CSS co= ntext, allowing a superadmin to inject arbitrary CSS that affects authentic= ated users on subsequent page loads when Content Security Policy is disable=
d. This issue is fixed in version 8.6.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55481" target=3D= "_blank" rel=3D"noopener">CVE-2026-55481</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to version 8.6= .1, Snipe-IT S3 signature image retrieval lacks authorization before tempor= ary URL. On S3-backed deployments, authenticated users who know a signature=
filename can obtain a 5-minute signed S3 URL because the S3 branch returns=
before the `authorize()` call used by the local-file branch. Version 8.6.1=
contains a patch.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55542" target=3D= "_blank" rel=3D"noopener">CVE-2026-55542</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT is an IT asset/license management system. Prior to 8.6.0, User= sController::update() passes a missing permission request field through Nor= malizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermission= sAction in a way that can overwrite a target user's permissions with a spar=
se result, allowing an administrator updating another administrator, or a u= ser with users.edit updating a regular account, to remove the target's admi= nistrative or granular permissions. This issue is fixed in version 8.6.0.</=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55843" target=3D= "_blank" rel=3D"noopener">CVE-2026-55843</a></td>
</tr>
<td class=3D"vendor-product">HAARG--HTTP::Tiny</td>
<td>HTTP::Tiny versions before 0.095 for Perl forward credential headers to=
cross-origin redirect targets. When the server returns a 3xx redirect, `_m= aybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb`=
re-merges the caller's `headers` argument into the new request, without ch= ecking whether the redirect target shares an origin with the original URL. = Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers=
are therefore re-sent to whatever host the redirect names, across scheme, = host or port boundaries, and including `https` to `http` downgrades that ex= pose them in plaintext on the wire. The HTTP::Tiny POD note that "Authoriza= tion headers will not be included in a redirected request" applied only to = the URL-userinfo Basic-auth path, not to headers passed explicitly by the c= aller.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7017" target=3D"= _blank" rel=3D"noopener">CVE-2026-7017</a></td>
</tr>
<td class=3D"vendor-product">hapifhir--org.hl7.fhir.core</td>
<td>HAPI FHIR is a complete implementation of the HL7 FHIR standard for hea= lthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.X= sltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon= .TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_ST= YLESHEET restrictions, allowing an attacker who controls or can tamper with=
transformed XML to trigger XML External Entity injection for local file di= sclosure and blind XXE or SSRF to arbitrary URLs reachable from the host. T= his issue is fixed in version 6.9.10.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55471" target=3D= "_blank" rel=3D"noopener">CVE-2026-55471</a></td>
</tr>
<td class=3D"vendor-product">harttle--liquidjs</td>
<td>LiquidJS is a Shopify / GitHub Pages compatible template engine in pure=
JavaScript. Prior to 10.27.1, the pop array filter at src/filters/array.ts=
allocated a full clone of its input array via [...toArray(v)] without call= ing this.context.memoryLimit.use(...), allowing a template render such as {=
{ huge_array | pop }} to allocate an O(N) clone of an attacker-influenced a= rray outside the configured memoryLimit budget. This issue is fixed in vers= ion 10.27.1.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55575" target=3D= "_blank" rel=3D"noopener">CVE-2026-55575</a></td>
</tr>
<td class=3D"vendor-product">hasura--graphql-engine</td>
<td>Hasura is an open-source product that provides users GraphQL or REST AP= Is. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table co= mputed field (returning SETOF some_table) to infer row values that ought to=
be filtered for their role based on some_table's row-level permissions. Wh= ile such rows cannot be returned directly, like predicates on strings for i= nstance allow values to be brute forced efficiently with the where clause a=
s an oracle. This issue is fixed in versions 2.49.2 and 2.45.5.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54698" target=3D= "_blank" rel=3D"noopener">CVE-2026-54698</a></td>
</tr>
<td class=3D"vendor-product">HMBRAND--DBI</td>
<td>DBI versions before 1.650 for Perl are vulnerable to code injection via=
caller-influenced Profile. When a string is assigned to a DBI handle's Pro= file attribute, DBI splits it into path, package and arguments, and interpo= lates the package part in a string eval with no validation of the package n= ame. Any caller-influenced value that reaches the Profile attribute is ther= efore arbitrary Perl code execution, including calls to run system commands=
. The Profile attribute can be set from three different sources that can ca= rry untrusted data: the DBI_PROFILE environment variable, a direct attribut=
e assignment, and a DSN driver-attribute clause dbi:Driver(Profile=3D>SP= EC):db. An attacker controlling any of those inputs runs arbitrary Perl in = the host process. The strongest remote position is a network-exposed DBI::G= ofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute=
, letting a client execute code on the broker host.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14380" target=3D= "_blank" rel=3D"noopener">CVE-2026-14380</a></td>
</tr>
<td class=3D"vendor-product">HMBRAND--DBI</td>
<td>DBI versions before 1.650 for Perl have a heap overflow when preparsing=
SQL statements with an extreme number of placeholders. The fix for CVE-202= 6-10879 did not allocate enough memory to handle approximately 1.2-million = placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.</=
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14739" target=3D= "_blank" rel=3D"noopener">CVE-2026-14739</a></td>
</tr>
<td class=3D"vendor-product">HMBRAND--DBI</td>
<td>DBI versions before 1.650 for Perl read one byte out-of-bounds in prepa= rse when deleting an initial SQL comment. The preparse method normalises SQ=
L and removes comments. When the SQL starts with a comment line, the deleti=
on of that line during normalisation led to an out-of-bounds read by one by= te. The result is a fault on memory-hardened builds and nondeterministic ne= wline retention on normal builds.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14740" target=3D= "_blank" rel=3D"noopener">CVE-2026-14740</a></td>
</tr>
<td class=3D"vendor-product">HP Inc.--HP 2800 Printer Series</td>
<td>A missing authorization vulnerability exists in the embedded webserver =
of HP Deskjet 2800 Series Printers running firmware version <=3DTBP1CN26= 12AR. An unauthenticated attacker with network access can send GET requests=
to multiple exposed administrative API endpoints and retrieve sensitive co= nfiguration data such as plaintext Wi-Fi Direct credentials, unique device = identity information, and other administrative security state details. When=
accessed through the web interface, these setting pages explicitly require=
administrator credentials before sensitive information is displayed.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13753" target=3D= "_blank" rel=3D"noopener">CVE-2026-13753</a></td>
</tr>
<td class=3D"vendor-product">HP Inc.--Poly CCX</td>
<td>The IP phone might use malicious input stored in configuration paramete=
rs and render it as content for the WebUI's webpage.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5922" target=3D"= _blank" rel=3D"noopener">CVE-2026-5922</a></td>
</tr>
<td class=3D"vendor-product">HP Inc.--Poly CCX</td>
<td>Malicious use of a stolen cookie might allow modifications to the conte= nts of the IP phone's webpage.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5923" target=3D"= _blank" rel=3D"noopener">CVE-2026-5923</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td> <td>Software installed and run as a non-privileged user may conduct imprope=
r GPU system calls to cause an integer overflow and map two GPU virtual add= resses to the same physical address. One of these virutal mappings can be f= reed along with the physical page, allowing for a read/write UAF via the se= cond mapping The second virtual mapping references a physical address that = has been freed after the first virtual mapping has been freed. This allows = the physical memory to be allocated (for example) by another process and re= ad/written to.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-34196" target=3D= "_blank" rel=3D"noopener">CVE-2026-34196</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td> <td>Software installed and run as a non-privileged user may cause OOB kerne=
l memory reads or writes through GPU API calls. When indexing pages larger = than 4kB in the page freeing logic of the sparse memory implementation, inc= orrect buffer indexing leads to OOB access.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41154" target=3D= "_blank" rel=3D"noopener">CVE-2026-41154</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td> <td>Kernel software installed and running inside a Host VM may post imprope=
r commands to the GPU Firmware to trigger a GPU register access which can l= ead to privilege escalation.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45196" target=3D= "_blank" rel=3D"noopener">CVE-2026-45196</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td> <td>Kernel software installed and running inside a Host VM may post imprope=
r commands to the GPU Firmware to trigger a memory write outside the permit= ted range of memory for the host kernel. A TOCTOU bug existed where a malic= ious driver could modify values in memory after firmware validation but bef= ore use.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45203" target=3D= "_blank" rel=3D"noopener">CVE-2026-45203</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td> <td>Software installed and run as a non-privileged user may conduct a seque= nce of improper GPU system calls causing use after free, which helps in fac= ilitating unprivileged memory access from a shader code. Triggering failure=
path in the MMU mapping logic by a malicious code could lead to incomplete=
cleanup of an internal driver state, allowing for future unauthorized acce=
ss to the contents of the physical memory.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7639" target=3D"= _blank" rel=3D"noopener">CVE-2026-7639</a></td>
</tr>
<td class=3D"vendor-product">immutable-js--immutable-js</td>
<td>Immutable.js provides many Persistent Immutable data structures. Prior =
to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and = the functional set, setIn, and updateIn mishandle an index or size in the r= ange 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty L= ist to enter an uncatchable infinite loop, a populated List to allocate wit= hout bound until process abort, or setSize to silently wrap large values. T= his issue is fixed in versions 4.3.9 and 5.1.8.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59879" target=3D= "_blank" rel=3D"noopener">CVE-2026-59879</a></td>
</tr>
<td class=3D"vendor-product">immutable-js--immutable-js</td>
<td>Immutable.js provides many Persistent Immutable data structures. Prior =
to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share th=
e same 32-bit hash in a HashCollisionNode collision bucket that is scanned = linearly, allowing an attacker who controls keys inserted into a Map, such =
as through Immutable.Map(obj), Immutable.fromJS(obj), state.merge(userObjec= t), or mergeDeep, to craft many colliding keys and degrade insertion and lo= okup to consume disproportionate CPU. This issue is fixed in versions 4.3.9=
and 5.1.8.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59880" target=3D= "_blank" rel=3D"noopener">CVE-2026-59880</a></td>
</tr>
<td class=3D"vendor-product">Invixium--IXM WEB v.2.3.85.25</td>
<td>An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate=
privileges via the /SystemUsers/CreateAppUser components</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51119" target=3D= "_blank" rel=3D"noopener">CVE-2026-51119</a></td>
</tr>
<td class=3D"vendor-product">isaacs--node-tar</td>
<td>node-tar is a tar archive manipulation library for Node.js. Prior to 7.= 5.19, node-tar does not enforce hard upper bounds on total decompressed dat=
a, entry counts, or decompression ratio in extraction and parsing paths suc=
h as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk spa=
ce and CPU. This issue is fixed in version 7.5.19.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59873" target=3D= "_blank" rel=3D"noopener">CVE-2026-59873</a></td>
</tr>
<td class=3D"vendor-product">isaacs--node-tar</td>
<td>node-tar is a tar archive manipulation library for Node.js. Prior to 7.= 5.18, tar.replace accepts a checksum-valid tar header with a negative base-= 256 encoded entry size, causing the archive scanner to make no progress whi=
le repeatedly parsing the same header. This issue is fixed in version 7.5.1= 8.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59874" target=3D= "_blank" rel=3D"noopener">CVE-2026-59874</a></td>
</tr>
<td class=3D"vendor-product">jg-rp--liquid</td>
<td>Python Liquid is a Python engine for the Liquid template language. Prio=
r to 2.2.1, given a malformed {% case %} tag without an associated {% when =
%} or {% else %} block and no terminating {% endcase %} tag, Python Liquid = hangs in an infinite loop at parse time because liquid.TokenStream.eof did = not give the EOF token matching kind and value fields, allowing malicious t= emplate authors to craft templates for a denial of service attack. This iss=
ue is fixed in version 2.2.1.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55865" target=3D= "_blank" rel=3D"noopener">CVE-2026-55865</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>An improper access check allows privileged users to overwrite media fil=
es without editing permissions.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48947" target=3D= "_blank" rel=3D"noopener">CVE-2026-48947</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>An improper access check allows user to download vcard exports of com_c= ontact contacts that are inaccessible.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48948" target=3D= "_blank" rel=3D"noopener">CVE-2026-48948</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>Lack of validation leads to an XSS vulnerability in the MFA management = views.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48949" target=3D= "_blank" rel=3D"noopener">CVE-2026-48949</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>Lack of escaping leads to an XSS vulnerability in the file management v= iew of com_templates.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48950" target=3D= "_blank" rel=3D"noopener">CVE-2026-48950</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of=
various components.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48951" target=3D= "_blank" rel=3D"noopener">CVE-2026-48951</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>Lack of escaping leads to an XSS vulnerability in the update list view =
of com_installer.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48952" target=3D= "_blank" rel=3D"noopener">CVE-2026-48952</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>Lack of escaping leads to an XSS vulnerability in the generic image out= put layout.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48953" target=3D= "_blank" rel=3D"noopener">CVE-2026-48953</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>Improper validation leads to a generic XSS vector in the language overr= ide feature.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48954" target=3D= "_blank" rel=3D"noopener">CVE-2026-48954</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>An improper access check allows unauthorized users to access workflow s= tage and transition information.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48955" target=3D= "_blank" rel=3D"noopener">CVE-2026-48955</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>An improper access check allows users to display a list of modules in t=
he frontend.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48956" target=3D= "_blank" rel=3D"noopener">CVE-2026-48956</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>An improper access check allows unauthorized users to access com_privac=
y datasets.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48957" target=3D= "_blank" rel=3D"noopener">CVE-2026-48957</a></td>
</tr>
<td class=3D"vendor-product">Joomla! Project--Joomla! CMS</td>
<td>An improper access check allows unauthorized users to create custom fie= lds via webservices endpoints.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48958" target=3D= "_blank" rel=3D"noopener">CVE-2026-48958</a></td>
</tr>
<td class=3D"vendor-product">jupyterlab--jupyterlab-git</td>
<td>JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before = 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames dir= ectly to innerHTML when rendering renamed files in commit history, allowing=
a crafted filename to execute JavaScript when a victim views the rename di=
ff in the Git History tab. This issue is fixed in version 0.54.0.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54527" target=3D= "_blank" rel=3D"noopener">CVE-2026-54527</a></td>
</tr>
<td class=3D"vendor-product">koodo-reader--koodo-reader</td>
<td>Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Re= ader is vulnerable to remote code execution through malicious EPUB files be= cause the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB=
chapter content is rendered with unsanitized innerHTML. An attacker can cr= aft an EPUB book that, when imported and opened by the victim, instantiates=
a hidden iframe with Node.js API access and executes arbitrary operating s= ystem commands with the victim user's privileges. This issue is fixed in ve= rsion 2.3.1.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55408" target=3D= "_blank" rel=3D"noopener">CVE-2026-55408</a></td>
</tr>
<td class=3D"vendor-product">kovidgoyal--calibre</td>
<td>calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, o=
r PDF file can execute arbitrary Python code when its metadata is read by c= alibre, including through Add books or Edit books, by embedding a custom co= lumn definition with a python: template in calibre:user_metadata that is pa= ssed unsanitized to exec() in the template formatter. This issue is fixed i=
n version 9.10.0.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53511" target=3D= "_blank" rel=3D"noopener">CVE-2026-53511</a></td>
</tr>
<td class=3D"vendor-product">Kyocera--Command Center RX</td>
<td>Unauthorized use of Kyocera printers, allows all information stored in = the Kyocera address book to be exported. The security measure that encrypts=
incoming data ian be bypassed with this vulnerability, allowing encrypted = data to be decrypted. Passwords and other sensitive information can be obta= ined. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252= ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TAS= Kalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7= 353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.</td=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-63579" target=3D= "_blank" rel=3D"noopener">CVE-2025-63579</a></td>
</tr>
<td class=3D"vendor-product">Labcenter--Proteus</td>
<td>The application contains an out-of-bounds write vulnerability that can =
be exploited by an attacker to cause the program to write data past the end=
of an allocated memory buffer. This can lead to arbitrary code execution.<=
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42953" target=3D= "_blank" rel=3D"noopener">CVE-2026-42953</a></td>
</tr>
<td class=3D"vendor-product">labring--FastGPT</td>
<td>FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, = GET /api/core/ai/record/getRecord authenticates the caller but loads LLM re= quest and response traces only by requestId without team scoping, allowing = any authenticated user to read another team's prompts, retrieved RAG chunks=
, and completions if the requestId is known. This issue is fixed in version=
4.15.0.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54602" target=3D= "_blank" rel=3D"noopener">CVE-2026-54602</a></td>
</tr>
<td class=3D"vendor-product">Lamaper--LTE Router V3.4.3</td>
<td>An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote=
attacker to execute arbitrary code via the /ajax web management API endpoi=
nt in MifiService.apk</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52200" target=3D= "_blank" rel=3D"noopener">CVE-2026-52200</a></td>
</tr>
<td class=3D"vendor-product">langroid--langroid</td>
<td>Langroid is a framework for building large-language-model-powered appli= cations. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_va= lidate_query` defense-in-depth layer whose `_DANGEROUS_SQL_PATTERNS` regex = blocklist enumerates dangerous SQL primitives by specific function name. Th=
e list misses the canonical PostgreSQL filesystem-disclosure family `pg_rea= d_file()`, `pg_stat_file()`, `pg_ls_logdir()`, `pg_ls_waldir()`, `pg_curren= t_logfile()` (and similar `SELECT`-shaped functions in the same family). It=
also leaves SQL Server `OPENDATASOURCE` and SQLite `ATTACH '<file>' =
AS x` (DATABASE keyword omitted) unblocked. An attacker able to shape the L= LM's generated SQL (directly via prompt input or transitively via prompt-in= jection in data the LLM ingests) can read arbitrary files from the PostgreS=
QL host through ordinary `SELECT` queries, even with the agent's strict def= ault configuration (`allow_dangerous_operations=3DFalse`, `allowed_statemen= t_types=3D['SELECT']`). The payloads survive the statement-type allowlist (= each is a `SELECT`) and pass through the regex blocklist (none of the funct= ion names match), then reach the live SQLAlchemy engine via `SQLChatAgent.r= un_query`. Version 0.64.0 contains a patch for the issue.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50180" target=3D= "_blank" rel=3D"noopener">CVE-2026-50180</a></td>
</tr>
<td class=3D"vendor-product">langroid--langroid</td>
<td>Langroid is a framework for building large-language-model-powered appli= cations. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigati= on, with default `allow_dangerous_operations=3DFalse`, combines a raw-text = regex blocklist (`_DANGEROUS_SQL_PATTERNS`) with a `sqlglot` SELECT-only st= atement allowlist. The blocklist entries that target callable functions req= uire the function name to be immediately followed by `\s*\(`. PostgreSQL ac= cepts the same call with the name separated from `(` by a quoted identifier=
, an inline comment, or schema qualification. These forms evade the regex, = still parse as `SELECT`, and execute the same PostgreSQL function. This res= tores the `pg_read_file` server-side file-read primitive that the prior CVE= -2026-25879 / GHSA-pmch-g965-grmr fix was meant to block: the parent adviso=
ry fixed a missing `pg_read_file` blocklist entry, while this report shows = that the added regex is bypassable. Version 0.65.1 fixes the issue.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54760" target=3D= "_blank" rel=3D"noopener">CVE-2026-54760</a></td>
</tr>
<td class=3D"vendor-product">langroid--langroid</td>
<td>Langroid is a framework for building large-language-model-powered appli= cations. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cyphe=
r queries straight to the Neo4j driver with no validation, no statement-typ=
e allowlist, and no opt-out gate. The query text is influenceable by prompt=
injection (direct user input or indirect content the agent reads back via = RAG), so an attacker who can influence the prompt can read or destroy all g= raph data and, when APOC or dbms.security procedures are enabled on the ser= ver, achieve OS-command and filesystem access. This is the same defect clas=
s and threat model as the SQLChatAgent prompt-to-SQL-to-RCE issue fixed in = version 0.63.0 (CVE-2026-25879); that fix did not extend to the neo4j modul=
e. Version 0.65.5 contains a fix for the neo4j module.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55615" target=3D= "_blank" rel=3D"noopener">CVE-2026-55615</a></td>
</tr>
<td class=3D"vendor-product">lepture--mistune</td>
<td>Mistune is a Python Markdown parser with renderers and plugins. Prior t=
o 3.2.1, render_admonition() in src/mistune/directives/admonition.py concat= enates the Admonition directive :class: option into the HTML class attribut=
e without escaping, allowing attribute injection and cross-site scripting e= ven when HTMLRenderer escape mode is enabled. This issue is fixed in versio=
n 3.2.1.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59926" target=3D= "_blank" rel=3D"noopener">CVE-2026-59926</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfr=
m: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consum= e_frags() transfers paged fragments from one socket buffer to another but f= ails to propagate the SKBFL_SHARED_FRAG flag. This is the same class of bug=
that was fixed in skb_try_coalesce() for CVE-2026-46300: when fragments ba= cked by read-only page-cache pages are merged, the marker indicating their = shared nature must be preserved so that ESP can decide correctly whether in= -place encryption is safe. Apply the same two-line fix used in skb_try_coal= esce() to iptfs_consume_frags().</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53363" target=3D= "_blank" rel=3D"noopener">CVE-2026-53363</a></td>
</tr>
<td class=3D"vendor-product">LiquidFiles--LiquidFiles v4.2.7</td>
<td>An authenticated stored cross-site scripting (XSS) vulnerability in the=
Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute a= rbitrary Javascript or HTML via injecting a crafted payload into the Name p= arameter.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36162" target=3D= "_blank" rel=3D"noopener">CVE-2026-36162</a></td>
</tr>
<td class=3D"vendor-product">LiquidFiles--LiquidFiles v4.2.7</td>
<td>An HTML injection vulnerability in the file view endpoint of LiquidFile=
s v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in = the context of the victim's browser via the uploading of and user interacti=
on with a crafted HTML file.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-36163" target=3D= "_blank" rel=3D"noopener">CVE-2026-36163</a></td>
</tr>
<td class=3D"vendor-product">M2Team--NanaZip</td>
<td>NanaZip is the 7-Zip derivative intended for the modern Windows experie= nce. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in Nana= Zip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from th=
e bundle entry Size field, which is only checked for sign and is not valida= ted against the real file size. A crafted bundle can cause an attacker-chos=
en allocation inside Extract, where std::bad_alloc or std::length_error can=
escape across the COM STDMETHODCALLTYPE boundary and crash the process. Th=
is issue is fixed in version 6.5.1749.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55780" target=3D= "_blank" rel=3D"noopener">CVE-2026-55780</a></td>
</tr>
<td class=3D"vendor-product">M2Team--NanaZip</td>
<td>NanaZip is the 7-Zip derivative intended for the modern Windows experie= nce. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Co= decs.Archive.Ufs.cpp validates the superblock block size only against the M= INBSIZE lower bound and does not validate the fs_fsize fragment size, allow= ing attacker-controlled 32-bit fields to flow into indirect-block, director=
y, and extraction buffer allocations. A tiny crafted UFS image can force mu= lti-gigabyte allocations during open or extraction, causing memory exhausti=
on or process termination. This issue is fixed in version 6.5.1749.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55781" target=3D= "_blank" rel=3D"noopener">CVE-2026-55781</a></td>
</tr>
<td class=3D"vendor-product">M2Team--NanaZip</td>
<td>NanaZip is the 7-Zip derivative intended for the modern Windows experie= nce. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.= Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 3= 2-bit section and custom-name length fields without validating them against=
the data present in the file. A tiny crafted module can force multi-gigaby=
te allocations during listing or extraction through NameSize, Information.S= ize, and std::string or vector allocation paths, causing memory exhaustion =
or process termination. This issue is fixed in version 6.5.1749.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55782" target=3D= "_blank" rel=3D"noopener">CVE-2026-55782</a></td>
</tr>
<td class=3D"vendor-product">M2Team--NanaZip</td>
<td>NanaZip is the 7-Zip derivative intended for the modern Windows experie= nce. Prior to 6.5.1749.0, NanaZip's seven in-house IInArchive handlers in N= anaZip.Codecs unconditionally dereference the caller-supplied Indices array=
inside Extract when the archive engine signals extract everything by passi=
ng Indices as NULL and NumItems as 0xFFFFFFFF. This causes a NULL pointer d= ereference in the standard Test archive or Extract all code path for WebAss= embly, ElectronAsar, Zealfs, Romfs, Ufs, Littlefs, and DotNetSingleFile arc= hives, resulting in a process crash. This issue is fixed in version 6.5.174= 9.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55783" target=3D= "_blank" rel=3D"noopener">CVE-2026-55783</a></td>
</tr>
<td class=3D"vendor-product">Mercury--MIPC252W IP Camera</td>
<td>MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not impl= ement nonce expiration in RTSP Digest authentication. An adjacent network a= ttacker can capture a legitimate authentication exchange and replay the non=
ce and response values in a new connection to bypass authentication without=
knowledge of the device credentials, gaining unauthorized access to the li=
ve video stream.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51597" target=3D= "_blank" rel=3D"noopener">CVE-2026-51597</a></td>
</tr>
<td class=3D"vendor-product">Mercury--MIPC252W IP Camera</td>
<td>An input validation vulnerability in the RTSP service of MERCURY MIPC25=
2W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, net= work-adjacent attacker to cause a denial of service via a crafted DESCRIBE = request with a malformed URL in the request line.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51598" target=3D= "_blank" rel=3D"noopener">CVE-2026-51598</a></td>
</tr>
<td class=3D"vendor-product">Mercury--MIPC252W IP Camera</td>
<td>An insufficient input validation vulnerability in the RTSP service of M= ERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated re= mote attacker to render an individual TCP connection temporarily unusable v=
ia sending an RTSP request with a Content-Length header but no correspondin=
g message body. The affected RTSP parser enters a body-waiting state instea=
d of rejecting the malformed request, causing all subsequent data on the co= nnection to be silently consumed as body content until a server-side timeou=
t closes the connection.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51599" target=3D= "_blank" rel=3D"noopener">CVE-2026-51599</a></td>
</tr>
<td class=3D"vendor-product">Mercusys--MW302R/MW302R(EU)</td>
<td>Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buff=
er Overflow in the administrative web interface. A stack buffer overflow vu= lnerability in the administrative web interface allows an authenticated att= acker with administrative privileges to trigger a system crash by sending a=
specially crafted request. The vulnerability results in denial of service = through control flow manipulation to an arbitrary instruction address.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31267" target=3D= "_blank" rel=3D"noopener">CVE-2026-31267</a></td>
</tr>
<td class=3D"vendor-product">MicroRealEstate--MicroRealEstate</td> <td>MicroRealEstate allows adversaries to bypass authentication due to a la=
ck of token state management. This would permit adversaries targeting Micro= RealEstate deployments to brute-force One-Time Passwords (OTP) to log in as=
any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57867" target=3D= "_blank" rel=3D"noopener">CVE-2026-57867</a></td>
</tr>
<td class=3D"vendor-product">MicroRealEstate--MicroRealEstate</td> <td>MicroRealEstate is affected by broken object-level access controls in P=
DF generator functionality. This issue affects MicroRealEstate: through 1.0= .0-alpha3.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57868" target=3D= "_blank" rel=3D"noopener">CVE-2026-57868</a></td>
</tr>
<td class=3D"vendor-product">MicroRealEstate--MicroRealEstate</td>
<td>Broken object-level access controls and the use of a deterministic patt= ern during random ID generation in MicroRealEstate allows attackers to acce=
ss documents uploaded by landlords or tenants without authorization. This i= ssue affects MicroRealEstate: through 1.0.0-alpha3.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57869" target=3D= "_blank" rel=3D"noopener">CVE-2026-57869</a></td>
</tr>
<td class=3D"vendor-product">MicroRealEstate--MicroRealEstate</td>
<td>Broken object-level access control on the Template API in MicroRealEsta=
te allows attackers to retrieve document templates used by other organizati= ons without authorization. This issue affects MicroRealEstate: through 1.0.= 0-alpha3.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57870" target=3D= "_blank" rel=3D"noopener">CVE-2026-57870</a></td>
</tr>
<td class=3D"vendor-product">MicroRealEstate--MicroRealEstate</td>
<td>Relative path traversal vulnerability in MicroRealEstate file upload fu= nctionality allows attackers to potentially overwrite system files. This is= sue affects MicroRealEstate: through 1.0.0-alpha3.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57871" target=3D= "_blank" rel=3D"noopener">CVE-2026-57871</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>An authorization bypass in MISP's EventsController::importModule() allo= wed authenticated users or read-only API keys with event view access to per= sist data to events they were not allowed to modify. When an import module = returned results in the misp_standard format, the write path did not verify=
event modification rights before saving the module output. This could allo=
w a view-only user to inject or alter event data, impacting the integrity o=
f MISP event content. The issue was fixed by enforcing the same modificatio= n-rights check used by related module result handling paths before processi=
ng misp_standard imports.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60124" target=3D= "_blank" rel=3D"noopener">CVE-2026-60124</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>MISP's importModule() path used getEnabledModule() to resolve a single = import module by name, but this lookup did not enforce the per-organisation=
module restriction checked by getEnabledModules(). As a result, an authent= icated user from an organisation that was not allowed to use a module restr= icted via Plugin.Import_<module>_restrict could still invoke that imp= ort module directly if they knew its name. This could allow unauthorised ac= cess to restricted import-module functionality and, depending on the module=
and the user's event permissions, may allow unauthorised import or modific= ation of event data through a module that should have been unavailable to t=
he user's organisation.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-60125" target=3D= "_blank" rel=3D"noopener">CVE-2026-60125</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>An improper authorization check in MISP's attribute creation endpoint a= llowed an authenticated user with permission to add attributes to submit a = sharing_group_id without triggering the corresponding sharing group authori= zation check, as long as the attribute distribution value was not explicitl=
y set to 4 - "sharing group". As a result, a user could reference or associ= ate an attribute with a sharing group they were not authorized to use. This=
could lead to an access-control bypass affecting the integrity of attribut=
e sharing metadata and potentially expose or misuse restricted sharing grou=
p relationships. The patch changes the authorization logic so that the shar= ing group permission check is performed whenever a non-empty sharing_group_=
id is provided, regardless of the selected distribution value.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61474" target=3D= "_blank" rel=3D"noopener">CVE-2026-61474</a></td>
</tr>
<td class=3D"vendor-product">misskey-dev--misskey</td>
<td>Misskey is an open source, federated social media platform. Prior to 20= 26.6.0, Misskey contains a vulnerability in Time-based One-Time Password (T= OTP) authentication in UserAuthService where insufficient validation of use=
d tokens allows the reuse of a single-use code within its valid time step. =
If both credentials and a TOTP code are obtained concurrently, an attacker = may reuse the code to perform unauthorized actions, potentially leading to = account takeover. This issue is fixed in version 2026.6.0.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57574" target=3D= "_blank" rel=3D"noopener">CVE-2026-57574</a></td>
</tr>
<td class=3D"vendor-product">misskey-dev--misskey</td>
<td>Misskey is an open source, federated social media platform. Prior to 20= 26.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability=
in URL preview functionality in UrlPreviewService. Due to missing network = restrictions before establishing outbound connections, a remote attacker ca=
n cause the Misskey server to initiate HTTP requests to loopback, private, =
or link-local services. Because IP address validation takes place after the=
request has been sent and the process is subsequently rejected, no sensiti=
ve internal data is believed to be transmitted back or exposed to the attac= ker. This issue is fixed in version 2026.6.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57575" target=3D= "_blank" rel=3D"noopener">CVE-2026-57575</a></td>
</tr>
<td class=3D"vendor-product">miurahr--py7zr</td>
<td>py7zr is a Python-based library and utility to support 7zip archive com= pression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's=
Worker.decompress() extracted archive entries without tracking total decom= pressed size, allowing a crafted .7z file such as a 15.6 KB archive that ex= pands to 100 MB to exhaust disk or memory before extraction completes. This=
issue is fixed in version 1.1.3.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55195" target=3D= "_blank" rel=3D"noopener">CVE-2026-55195</a></td>
</tr>
<td class=3D"vendor-product">miurahr--py7zr</td>
<td>py7zr is a Python-based library and utility to support 7zip archive com= pression, decompression, encryption and decryption. Prior to 1.1.3, PackInf= o._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attac= ker-controlled numstreams values parsed from archive headers, allowing a cr= afted .7z archive to cause excessive CPU consumption during SevenZipFile.in= it() before extraction. This issue is fixed in version 1.1.3.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55206" target=3D= "_blank" rel=3D"noopener">CVE-2026-55206</a></td>
</tr>
<td class=3D"vendor-product">Mozilla--Firefox for iOS</td>
<td>A malicious webpage could interrupt a pending navigation by enqueuing a=
synchronous JavaScript dialog, causing the browser UI to display the desti= nation origin in the address bar while continuing to render attacker-contro= lled content. This vulnerability was fixed in Firefox for iOS 152.3.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13356" target=3D= "_blank" rel=3D"noopener">CVE-2026-13356</a></td>
</tr>
<td class=3D"vendor-product">mrubyc--mrubyc</td>
<td>mrubyc through release3.4.1 was found to contain an out-of-bounds read =
in builtin missing-method lookup inside mrbc_find_method().</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38973" target=3D= "_blank" rel=3D"noopener">CVE-2026-38973</a></td>
</tr>
<td class=3D"vendor-product">mrubyc--mrubyc</td>
<td>mrubyc through 3.4.1 was found to contain a NULL pointer dereference in=
src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-l= evel super.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38976" target=3D= "_blank" rel=3D"noopener">CVE-2026-38976</a></td>
</tr>
<td class=3D"vendor-product">Mysterium--Mysterium</td>
<td>Improper authorization in the /tequilapi/config/user endpoint of Myster= ium Node before v1.36.0 allows unauthenticated attackers to arbitrarily ove= rwrite the node's configuration and achieve a full node takeover via supply= ing a crafted POST request.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31309" target=3D= "_blank" rel=3D"noopener">CVE-2026-31309</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a di=
sk space exhaustion vulnerability in the data-table file upload endpoint. T=
he per-request quota check does not account for files already written to th=
e shared temporary directory, allowing an authenticated user to repeatedly = upload files that accumulate on disk until the periodic cleanup runs, poten= tially exhausting available disk space on the host.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58661" target=3D= "_blank" rel=3D"noopener">CVE-2026-58661</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 2.28.0 contains an improper authorization vulnerability allo= wing authenticated users to assign workflows to folders in other projects. = Attackers can bypass project and folder authorization boundaries by supplyi=
ng crafted request payloads during workflow creation, causing logical integ= rity violations in target project folder structures.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59253" target=3D= "_blank" rel=3D"noopener">CVE-2026-59253</a></td>
</tr>
<td class=3D"vendor-product">n8n--n8n</td>
<td>n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contai=
ns a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery=
operation. The operation substitutes evaluated {{ ... }} expression values=
directly into the raw SQL string without parameterization. When a workflow=
uses this operation with expression-sourced values and is connected to an = externally-reachable trigger (such as a Webhook node), attacker-controlled = input reaching those expressions results in SQL injection, allowing executi=
on of arbitrary SQL with the configured MySQL credentials' privileges. The = MySQL v2 node, which uses parameterized queries, is not affected.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59257" target=3D= "_blank" rel=3D"noopener">CVE-2026-59257</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n is an open source workflow automation platform. Prior to 1.123.61, = 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create=
permission could pollute Object.prototype through a crafted workflow saved=
, updated, or imported via the workflow API, allowing unauthenticated reque= sts to be treated as a privileged user and exposing user and project listin=
g endpoints. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.<=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59206" target=3D= "_blank" rel=3D"noopener">CVE-2026-59206</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n is an open source workflow automation platform. Prior to 2.27.4 and=
2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Dom= ains restriction configured on credentials when an MCP tool was pointed at =
an arbitrary URL, allowing a member-level user with use-only access to a sh= ared credential to send its secret to an external server they control. This=
issue is fixed in versions 2.27.4 and 2.28.1.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59207" target=3D= "_blank" rel=3D"noopener">CVE-2026-59207</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n is an open source workflow automation platform. Prior to 2.27.4 and=
from 2.28.0 prior to 2.28.1, n8n instances configured with more than one t= rusted token-exchange issuer resolved external identities to local accounts=
using only the JWT sub claim and ignored the iss claim, allowing an attack=
er with a valid token from one trusted issuer and a sub matching a victim u= nder another issuer to authenticate as that victim. This issue is fixed in = versions 2.27.4 and 2.28.1.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59208" target=3D= "_blank" rel=3D"noopener">CVE-2026-59208</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n is an open source workflow automation platform. Prior to 1.123.61, = 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to=
a shared workflow could read credential-populated headers exposed via the = $request object inside an HTTP Request node's pagination expression and exf= iltrate the secret through item data. This issue is fixed in versions 1.123= .61, 2.27.4, and 2.28.1.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59209" target=3D= "_blank" rel=3D"noopener">CVE-2026-59209</a></td>
</tr>
<td class=3D"vendor-product">nats-io--nats-server</td>
<td>NATS Server is a high-performance server for NATS.io, the cloud and edg=
e native messaging system. Prior to 2.14.3 and 2.12.8, message trace destin= ation checks were applied to ordinary client connections but not consistent=
ly to messages arriving through leafnode connections, allowing a leafnode o= perator to send trace events to subjects that would not otherwise be permit= ted and to use trace-only behavior to prevent normal delivery or storage of=
affected messages. This issue is fixed in versions 2.14.3 and 2.12.8.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58254" target=3D= "_blank" rel=3D"noopener">CVE-2026-58254</a></td>
</tr>
<td class=3D"vendor-product">nezhahq--nezha</td>
<td>Nezha Monitoring is a self-hostable, lightweight, servers and websites = monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /= api/v1/notification endpoints return full resource objects including plaint= ext third-party API credentials, including Cloudflare API tokens, TencentCl= oud SecretKeys, Slack, Discord, and Telegram webhook URLs with embedded bot=
tokens, and Authorization header values, without any field-level redaction=
. Any authenticated admin or PAT with nezha:ddns:read or nezha:notification= :read scope can receive stored credentials through the listDDNS and listNot= ification handlers in a single API response. This issue is fixed in version=
2.2.5.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59155" target=3D= "_blank" rel=3D"noopener">CVE-2026-59155</a></td>
</tr>
<td class=3D"vendor-product">NT-ware--uniFLOW ULM (Universal Login Manager)=
Standalone</td>
<td>uniFLOW Universal Login Manager (ULM) Standalone contains an informatio=
n disclosure vulnerability that may allow an authenticated administrator to=
access sensitive configuration information through the ULM Remote User Int= erface (RUI). Exploitation requires administrative privileges and may discl= ose configuration data associated with SMTP or LDAP integrations. ULM deplo= yments connected to uniFLOW Server or uniFLOW Online are not affected.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-1433" target=3D"= _blank" rel=3D"noopener">CVE-2026-1433</a></td>
</tr>
<td class=3D"vendor-product">Oneblog--Oneblog V2.3.9</td>
<td>An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive=
information via the RestApiController.java, JsApiTicketComponent.java, and=
the GetAccessTokenComponent.java component</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51937" target=3D= "_blank" rel=3D"noopener">CVE-2026-51937</a></td>
</tr>
<td class=3D"vendor-product">OP-TEE--optee_os</td>
<td>OP-TEE is a Trusted Execution Environment (TEE) designed as companion t=
o a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZ= one technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-b=
it integer overflows in OP-TEE core's AES-GCM implementation cause the auth= entication tag to be computed with incorrect bit-length values after proces= sing more than 512 megabytes of payload or Additional Authenticated Data (A= AD). Version 4.11.0 contains a patch. No known workarounds are available.</=
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53763" target=3D= "_blank" rel=3D"noopener">CVE-2026-53763</a></td>
</tr>
<td class=3D"vendor-product">open-webui--open-webui</td>
<td>Open WebUI is an extensible, feature-rich, and user-friendly self-hoste=
d AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members retu= rned full UserModelResponse objects for channel members, including settings= .ui.toolServers[].key and webhook configuration, allowing a normal channel = participant to retrieve other users' sensitive settings. This issue is fixe=
d in version 0.10.0.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59222" target=3D= "_blank" rel=3D"noopener">CVE-2026-59222</a></td>
</tr>
<td class=3D"vendor-product">OpenAI--Codex desktop app for macOS</td>
<td>The OpenAI Codex desktop app for macOS rendered remote images from Mark= down in model responses. An attacker who could place an indirect prompt inj= ection in content processed by Codex, such as a connected-tool result or an= other untrusted source, could induce the model to construct a remote image = URL containing sensitive data. The app automatically fetched that URL when = rendering the response, sending the embedded data to an attacker-controlled=
server without a separate user click. Successful exploitation could exfilt= rate secrets and other information accessible in the Codex session, includi=
ng API keys, source code, and data returned by connected tools. No direct i= ntegrity or availability impact was demonstrated, and there is no known exp= loitation in the wild.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14898" target=3D= "_blank" rel=3D"noopener">CVE-2026-14898</a></td>
</tr>
<td class=3D"vendor-product">OpENer--OpENer 2.3.0</td>
<td>In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Serv= ice) vulnerability exists in its network processing loop.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51535" target=3D= "_blank" rel=3D"noopener">CVE-2026-51535</a></td>
</tr>
<td class=3D"vendor-product">openfga--openfga</td>
<td>OpenFGA is an authorization/permission engine built for developers. Pri=
or to 1.18.0, when MySQL is being used as the datastore and authorization d= ecisions rely on case-sensitive user strings, the tuple, changelog, and aut= horization_model identifier columns can compare case-distinct values such a=
s user:Alice and user:alice as equivalent, causing two distinct check reque= sts to return the same response. This issue is fixed in 1.18.0.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55170" target=3D= "_blank" rel=3D"noopener">CVE-2026-55170</a></td>
</tr>
<td class=3D"vendor-product">openreplay--openreplay</td>
<td>OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.= 27.0, getFirstMob returned 15-second presigned S3 download URLs for a sessi= on's DOM-replay recording based solely on the session path parameter, while=
validateProjectAccess checked only that the project belonged to the reques= ter's tenant and did not verify that the session belonged to that project, = allowing any authenticated low-privilege user to read another tenant's firs=
t 15 seconds of session-replay recording data. This issue is fixed in versi=
on 1.27.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55881" target=3D= "_blank" rel=3D"noopener">CVE-2026-55881</a></td>
</tr>
<td class=3D"vendor-product">OpenVPN--Access Server</td>
<td>OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequen= ces inside HTTP header values, allowing remote attackers to perform HTTP re= quest smuggling when deployed behind a reverse proxy</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-3110" target=3D"= _blank" rel=3D"noopener">CVE-2025-3110</a></td>
</tr>
<td class=3D"vendor-product">OpenVPN--OpenVPN</td>
<td>A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.= 6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-= crypt-v2 client key to potentially cause a denial of service</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13698" target=3D= "_blank" rel=3D"noopener">CVE-2026-13698</a></td>
</tr>
<td class=3D"vendor-product">Openvpn--OpenVPN</td>
<td>OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allow=
s remote attackers to cause a denial of service via a malformed authenticat= ion token that triggers a reachable assertion when external-auth is enabled= </td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13122" target=3D= "_blank" rel=3D"noopener">CVE-2026-13122</a></td>
</tr>
<td class=3D"vendor-product">osquery--osquery</td>
<td>osquery is a SQL powered operating system instrumentation, monitoring, = and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged = attacker can cause a heap buffer out-of-bounds write if there is a query of=
the processes table targeting a maliciously crafted process, due to unchec= ked PEB string lengths in process command-line and current-directory reads.=
If exploited successfully, this could allow a potential local privilege es= calation from standard user to SYSTEM. This issue is fixed in version 5.23.= 1.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54000" target=3D= "_blank" rel=3D"noopener">CVE-2026-54000</a></td>
</tr>
<td class=3D"vendor-product">osquery--osquery</td>
<td>osquery is a SQL powered operating system instrumentation, monitoring, = and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged = attacker can cause a heap buffer out-of-bounds write if there is a query of=
the authenticode table targeting a maliciously crafted binary, due to publ= isher information parsing in getOriginalProgramName. If exploited successfu= lly, this could allow a potential local privilege escalation from standard = user to SYSTEM. This issue is fixed in version 5.23.1.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54001" target=3D= "_blank" rel=3D"noopener">CVE-2026-54001</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>Multiple cross site scripting vulnerabilities in the User-ID=C3=A2=E2= =80=9E=C2=A2 Authentication Portal (aka Captive Portal) service, GlobalProt= ect=C3=A2=E2=80=9E=C2=A2 gateway/portal features and Clientless VPN of Palo=
Alto Networks PAN-OS=C3=82=C2=AE software enables a malicious unauthentica= ted user to store or execute malicious JavaScript payload. The security ris=
k posed by this issue is minimized when the management interface and access=
to the User-ID=C3=A2=E2=80=9E=C2=A2 Authentication Portal is restricted to=
only trusted internal IP addresses according to our recommended best pract= ice deployment guidelines
https://live.paloaltonetworks.com/t5/community-bl= ogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/4= 64431 . This issue is applicable to PAN-OS software on PA-Series and VM-Ser= ies firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not aff= ected by this vulnerability.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0279" target=3D"= _blank" rel=3D"noopener">CVE-2026-0279</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>An IPv6 packet processing vulnerability in the dataplane of Palo Alto N= etworks PAN-OS=C3=82=C2=AE software enables an unauthenticated attacker to = bypass firewall security policy enforcement, allowing network traffic that = should be blocked to reach protected services. Cloud NGFW and Panorama are = not impacted by this vulnerability.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0280" target=3D"= _blank" rel=3D"noopener">CVE-2026-0280</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>An information disclosure vulnerability in Palo Alto Networks PAN-OS=C3= =82=C2=AE software enables an unauthenticated attacker with network access =
to the management web interface to obtain web session tokens. This requires=
a legitimate user to first click on a malicious link provided by the attac= ker. The security risk posed by this issue is minimized by restricting acce=
ss to the management web interface to only trusted internal IP addresses ac= cording to our recommended best practice deployment guidelines
https://live= .paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-= management-access-of-your-palo/ba-p/464431 . This issue is applicable to PA= N-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual=
and M-Series). Cloud NGFW and Prisma=C3=82=C2=AE Access are not impacted b=
y this vulnerability.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0281" target=3D"= _blank" rel=3D"noopener">CVE-2026-0281</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>A file deletion vulnerability in Palo Alto Networks PAN-OS=C3=82=C2=AE = software enables an unauthenticated attacker with network access to the man= agement web interface to delete files from a temporary directory. The secur= ity risk posed by this issue is minimized by restricting access to the mana= gement web interface to only trusted internal IP addresses according to our=
recommended best practice deployment guidelines
https://live.paloaltonetwo= rks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-acc= ess-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software =
on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series)=
. Cloud NGFW and Prisma=C3=82=C2=AE Access are not impacted by this vulnera= bility.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0282" target=3D"= _blank" rel=3D"noopener">CVE-2026-0282</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>An authentication bypass vulnerability in Large Scale VPN ( LSVPN) func= tionality of Palo Alto Networks PAN-OS software allows an attacker with net= work access to bypass security restrictions and establish an unauthorized s= ite-to-site VPN connection. Panorama, Cloud NGFW, and Prisma=C3=82=C2=AE Ac= cess are not impacted by this vulnerability.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0283" target=3D"= _blank" rel=3D"noopener">CVE-2026-0283</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>An XML injection vulnerability in the Large Scale VPN (LSVPN) functiona= lity of Palo Alto Networks PAN-OS=C3=82=C2=AE software enables an unauthent= icated attacker with network access to inject malicious XML content, potent= ially leading to information disclosure or corruption of internal LSVPN sat= ellite data. Panorama, Cloud NGFW, and Prisma=C3=82=C2=AE Access are not im= pacted by this vulnerability.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0284" target=3D"= _blank" rel=3D"noopener">CVE-2026-0284</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>A server-side request forgery (SSRF) vulnerability in Palo Alto Network=
s PAN-OS software enables an authenticated administrator with network acces=
s to the management web interface to make unauthorized requests from the fi= rewall to internal services. The security risk posed by this issue is minim= ized when the management interface is restricted to only trusted internal I=
P addresses according to our recommended=C2=A0 best practice deployment gui= delines
https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-trick= s-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .=C2=A0 Pano= rama, Cloud NGFW, and Prisma=C3=82=C2=AE Access are not impacted by this vu= lnerability.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0285" target=3D"= _blank" rel=3D"noopener">CVE-2026-0285</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>A command injection vulnerability in the management plane of Palo Alto = Networks PAN-OS=C3=82=C2=AE software enables an authenticated administrator=
to execute arbitrary OS commands as root. The security risk posed by this = issue is significantly minimized when CLI access is restricted to a limited=
group of administrators. This issue is applicable to PAN-OS software on PA= -Series and VM-Series firewalls and on Panorama (virtual and M-Series). Clo=
ud NGFW and Prisma Access=C3=82=C2=AE are not impacted by this vulnerabilit= y.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0286" target=3D"= _blank" rel=3D"noopener">CVE-2026-0286</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS= =C3=82=C2=AE software allow an unauthenticated attacker with network access=
to cause a denial of service (DoS) condition by sending specially crafted = network traffic to or through a dataplane interface. Repeated attempts to t= rigger this condition result in the firewall entering maintenance mode. Pan= orama is not impacted by these vulnerabilities.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0287" target=3D"= _blank" rel=3D"noopener">CVE-2026-0287</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cloud NGFW</td>
<td>Multiple buffer overflow vulnerabilities in the User-ID Terminal Server=
Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unaut= henticated attacker with network access to cause a denial of service (DoS) = condition or potentially execute arbitrary code by sending specially crafte=
d network traffic. The security risk posed by this issue is minimized when = the User-ID Terminal Server Agent connectivity is restricted to only truste=
d internal IP addresses according to our recommended best practice deployme=
nt guidelines
https://docs.paloaltonetworks.com/ngfw/help/10-2/user-identif= ication/device-user-identification-terminal-services-agents#:~:text=3DTo%20= minimize%20security%20risk%2C%20restrict%20TS%20Agent%20connectivity%20to%2= 0trusted%20internal%20IP%20addresses%20only. . Panorama is not impacted by = this vulnerability.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0288" target=3D"= _blank" rel=3D"noopener">CVE-2026-0288</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Cortex XDR Broker VM</td> <td>A privilege escalation vulnerability in Palo Alto Networks Cortex=C3=82= =C2=AE XDR Broker VM enables a locally authenticated user to perform action=
s as the root user.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0276" target=3D"= _blank" rel=3D"noopener">CVE-2026-0276</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Prisma Access Agent</td> <td>An improper certificate validation vulnerability in the Prisma=C3=82=C2= =AE Access Agent for iOS enables an attacker to perform a man-in-the-middle=
(MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows=
, macOS, Linux, Android and ChromeOS are not affected.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0277" target=3D"= _blank" rel=3D"noopener">CVE-2026-0277</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Prisma Access Agent</td> <td>Multiple protection mechanism failures in the Prisma Access Agent Data = Loss Prevention (DLP) component for Windows allow a local user to bypass DL=
P policy enforcement controls. The Prisma Access Agent on macOS is not affe= cted.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0278" target=3D"= _blank" rel=3D"noopener">CVE-2026-0278</a></td>
</tr>
<td class=3D"vendor-product">Palo Alto Networks--Prisma Browser</td>
<td>A local privilege escalation vulnerability in Palo Alto Networks Prisma= =C3=82=C2=AE Browser allows a locally authenticated administrator with acce=
ss to the macOS local filesystem to perform actions on the device with root=
privileges. This issue only affects Prisma=C3=82=C2=AE Browser on macOS.</=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0275" target=3D"= _blank" rel=3D"noopener">CVE-2026-0275</a></td>
</tr>
<td class=3D"vendor-product">parse-community--parse-server</td>
<td>Parse Server is an open source backend that can be deployed to any infr= astructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the de= fault fileUpload.fileExtensions blocklist could be bypassed by uploading a = file with a non-standard or compound extension and dangerous content type, = allowing storage adapters such as S3 and GCS to serve attacker-supplied act= ive content and enable stored cross-site scripting. This issue is fixed in = versions 9.9.1-alpha.11 and 8.6.81.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55778" target=3D= "_blank" rel=3D"noopener">CVE-2026-55778</a></td>
</tr>
<td class=3D"vendor-product">parse-community--parse-server</td>
<td>Parse Server is an open source backend that can be deployed to any infr= astructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply=
nested $or, $and, and $nor query condition operators in the REST API or Li= veQuery query handling could trigger exponential-time processing in the int= ernal query-traversal helper and block the Node.js event loop. This issue i=
s fixed in versions 9.9.1-alpha.12 and 8.6.82.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57480" target=3D= "_blank" rel=3D"noopener">CVE-2026-57480</a></td>
</tr>
<td class=3D"vendor-product">parse-community--parse-server</td>
<td>Parse Server is an open source backend that can be deployed to any infr= astructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a Live= Query subscriber could receive object field values they were not authorized=
to read when a single save changed both an object field and the subscriber=
's ACL read access, because leave and enter events included the wrong objec=
t state. This issue is fixed in versions 9.9.1-alpha.13 and 8.6.83.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57481" target=3D= "_blank" rel=3D"noopener">CVE-2026-57481</a></td>
</tr>
<td class=3D"vendor-product">parse-community--parse-server</td>
<td>Parse Server is affected by a stored cross-site scripting (XSS) vulnera= bility in versions >=3D 9.0.0, < 9.10.0-alpha.2 and <=3D 8.6.83. W= hen an uploaded file's extension is not recognized by the mime package, Par=
se Server preserves the client-supplied Content-Type. A malformed Content-T= ype that is not a valid type/subtype media type (e.g., 'image', 'image/', o=
r 'image//svg+xml') bypasses the fileUpload.fileExtensions blocklist and is=
stored unchanged. On storage adapters that persist and serve the uploaded = Content-Type (such as Amazon S3, Google Cloud Storage, or Azure Blob Storag= e), a browser cannot parse the malformed value and falls back to MIME-sniff= ing; a file whose body begins with HTML is rendered as HTML, executing embe= dded script in the application's origin against other users who open the fi=
le URL. The default GridFS storage adapter is not affected. Fixed in 9.10.0= -alpha.2 and 8.6.84.</td>
<td>2026-07-11</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61448" target=3D= "_blank" rel=3D"noopener">CVE-2026-61448</a></td>
</tr>
<td class=3D"vendor-product">PayRange--PayRange</td>
<td>When coupled with the SSL bypass vulnerability, JavaScript can be injec= ted into a WebView in the PayRange version 7.0.7 app. The injection of spec= ific JavaScript function calls allows the attacker to escape the WebView sa= ndbox and perform a number of dangerous actions on the user's device.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13461" target=3D= "_blank" rel=3D"noopener">CVE-2026-13461</a></td>
</tr>
<td class=3D"vendor-product">PayRange--PayRange</td>
<td>PayRange Android app, version 7.0.7 and below, contains an SSL bypass v= ulnerability that allows invalid certificates to be accepted in application=
webviews. A remote and unauthenticated attacker can steal information that=
the user sends.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13462" target=3D= "_blank" rel=3D"noopener">CVE-2026-13462</a></td>
</tr>
<td class=3D"vendor-product">PETDANCE--App::Ack</td>
<td>App::Ack versions through 3.10.0 for Perl read arbitrary files via --fi= les-from in a project .ackrc. ack searches up the directory hierarchy from = the current directory for a project .ackrc and loads its options. The proje= ct-source option blocklist in App::Ack::ConfigLoader does not include --fil= es-from, so a project .ackrc can set it to a path whose listed files ack th=
en reads and searches. Version 3.10.0 added --follow to the blocklist; --fi= les-from remains accepted. A project .ackrc committed to an untrusted repos= itory can make ack read files outside the project and print their matching = lines.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49145" target=3D= "_blank" rel=3D"noopener">CVE-2026-49145</a></td>
</tr>
<td class=3D"vendor-product">PETDANCE--App::Ack</td>
<td>App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an=
unbounded context value in a project .ackrc. ack searches up the directory=
hierarchy from the current directory for a project .ackrc and loads its op= tions. The -B and -C context options accepted any positive integer, and ack=
sized the before-context buffer to that value, so a project .ackrc setting=
--before-context=3D100000000 made ack allocate a buffer of 100 million ele= ments. A project .ackrc committed to an untrusted repository can abort ack = with an out-of-memory condition.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49146" target=3D= "_blank" rel=3D"noopener">CVE-2026-49146</a></td>
</tr>
<td class=3D"vendor-product">PETDANCE--App::Ack</td>
<td>App::Ack versions through 3.10.0 for Perl print unsanitised terminal es= cape sequences from filenames in several output modes. When ack prints a fi= lename whose basename contains terminal control bytes such as ANSI escape s= equences, those bytes reach the terminal unchanged. Version 3.10.0 added a = _safe_filename helper that sanitises the filenames printed by -f, -g, the c= olored match heading, and per-match lines, but the --show-types, -l/-L, and=
-c paths still emit the raw filename. A file whose name embeds cursor-move= ment or color escapes can overwrite or recolor earlier terminal output, or =
be passed unchanged to a downstream consumer.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49147" target=3D= "_blank" rel=3D"noopener">CVE-2026-49147</a></td>
</tr>
<td class=3D"vendor-product">pgjdbc--pgjdbc</td>
<td>pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 thr= ough 42.7.11, channelBinding=3Drequire connections can be silently downgrad=
ed from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 with= out it, losing the man-in-the-middle protection the setting is meant to gua= rantee. An attacker who can intercept the TLS connection can trigger the do= wngrade with a certificate whose signature algorithm has no tls-server-end-= point channel-binding hash, because the bundled com.ongres.scram:scram-clie=
nt returns an empty byte array instead of failing and pgJDBC ScramAuthentic= ator checks only that the server advertised a PLUS mechanism, without rejec= ting the empty binding or checking that the negotiated mechanism uses chann=
el binding. This issue is fixed in version 42.7.12.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54291" target=3D= "_blank" rel=3D"noopener">CVE-2026-54291</a></td>
</tr>
<td class=3D"vendor-product">phalcon--cphalcon</td>
<td>Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.=
1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC ta=
g against the freshly computed HMAC using PHP/Zephir identity comparison, w= hich lowers to a byte-wise comparison that returns early on the first diffe= ring byte. This observable timing discrepancy can allow an attacker to reco= ver a valid tag byte-by-byte and attach it to a chosen IV and ciphertext so=
that decrypt() accepts tampered encrypted content as authentic. This issue=
is fixed in version 5.14.1.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54736" target=3D= "_blank" rel=3D"noopener">CVE-2026-54736</a></td>
</tr>
<td class=3D"vendor-product">phalcon--cphalcon</td>
<td>Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.=
0, every Phalcon MVC application built with a default router registers a bu= ilt-in route whose compiled PCRE pattern contains the nested quantifier (/.=
), and the same construct is produced by the /:params placeholder and the C=
LI router. Phalcon\Mvc\Router::handle() matches this pattern against the at= tacker-controlled request URI on every request, so a crafted path such as o=
ne containing repeated slashes followed by decoded newlines can trigger cat= astrophic backtracking and cause CPU exhaustion or route-matching failure. = This issue is fixed in version 5.15.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57584" target=3D= "_blank" rel=3D"noopener">CVE-2026-57584</a></td>
</tr>
<td class=3D"vendor-product">phoca.cz--phoca.cz Phoca Download extension fo=
r Joomla</td>
<td>The Joomla extension Phoca Downloads is vulnerable to an authenticated = arbitrary file upload that allows registered users uploading executable fil=
es and leads to full RCE.</td>
<td>2026-07-11</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57828" target=3D= "_blank" rel=3D"noopener">CVE-2026-57828</a></td>
</tr>
<td class=3D"vendor-product">phoenixframework--phoenix</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in p= hoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated a= ttacker to cause a denial of service against any endpoint that mounts a Pho= enix socket with a reachable channel transport (WebSocket or LongPoll). Thi=
s vulnerability is associated with program files lib/phoenix/socket.ex and = program routine 'Elixir.Phoenix.Socket':handle_in/4. Phoenix transports do = not limit the number of channels that a single transport process may join. = Every phx_join message a client sends over one connection starts a persiste=
nt channel process, and the socket process accepts an unbounded number of t= hem. A single unauthenticated client can therefore open one WebSocket or Lo= ngPoll connection and stream a large number of phx_join messages, spawning = hundreds of thousands of channel processes over that one connection and eve= ntually reaching the BEAM maximum process limit. Once the process table is = exhausted the virtual machine can no longer start new processes, denying se= rvice to legitimate traffic across the whole node. Because the amplificatio=
n happens inside a single connection, network-layer connection caps and rat=
e limiting do not mitigate it. The fix adds a :max_channels_per_transport o= ption (default 100) that bounds the number of channels a single transport p= rocess can join, forcing abusive clients to open many connections instead, = where external load balancers and reverse proxies can throttle them. This i= ssue affects phoenix: from 0.11.0 before 1.5.15, from 1.6.0-rc.0 before 1.6= .17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56811" target=3D= "_blank" rel=3D"noopener">CVE-2026-56811</a></td>
</tr>
<td class=3D"vendor-product">phoenixframework--phoenix</td>
<td>Improper Check for Unusual or Exceptional Conditions vulnerability in p= hoenixframework phoenix (Presence JavaScript client) allows an attacker wit=
h ordinary channel access to cause a persistent client-side denial of servi=
ce against every viewer of a presence channel topic. This vulnerability is = associated with program files assets/js/phoenix/presence.js and program rou= tines Presence.syncState and Presence.syncDiff. The Phoenix JavaScript pres= ence client checks whether a presence already exists with a bare truthiness=
test (state[key]) instead of an own-property check. Presence keys can be a= ttacker-controlled, because applications track presences under a username o=
r id supplied by the client. A user who joins a channel choosing a key that=
is an Object.prototype member name (__proto__, constructor, toString, hasO= wnProperty, and similar) makes that lookup return JavaScript's built-in Obj= ect.prototype instead of undefined. Because the prototype is truthy, the co=
de treats it as an existing presence and reads .metas.map(...) off it, whic=
h throws an uncaught TypeError. The exception propagates out of the presenc=
e message handler, so the local state is never updated and onSync() never f= ires. Because the malicious key is tracked on the server, it is re-pushed o=
n every presence update and keeps re-throwing, so presence sync stays broke=
n for every viewer of that channel topic until the attacker leaves. Both sy= ncState and syncDiff use the same unsafe existence-check pattern. The impac=
t is limited to the affected topic and is a read-time confusion of the prot= otype object, not a mutation of Object.prototype (it is not prototype pollu= tion). This issue affects phoenix: from 1.2.0-rc.0 before 1.5.15, from 1.6.= 0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 be= fore 1.8.9.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56812" target=3D= "_blank" rel=3D"noopener">CVE-2026-56812</a></td>
</tr>
<td class=3D"vendor-product">portainer--portainer</td>
<td>Portainer Community Edition is a lightweight service delivery platform = for containerized applications that can be used to manage Docker, Swarm, Ku= bernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0=
until 2.43.0, unauthenticated restore and administrator initialization end= points (/api/restore and /api/users/admin/init) remain accessible during th=
e five-minute setup window for uninitialized instances, allowing a network = attacker to restore a crafted backup or create the first administrator acco= unt and gain full administrative access. This issue is fixed in versions 2.= 39.4 and 2.43.0.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55761" target=3D= "_blank" rel=3D"noopener">CVE-2026-55761</a></td>
</tr>
<td class=3D"vendor-product">Proximus--b-box v8c.725A</td>
<td>Incorrect access control in Proximus b-box v8c.725A allows authenticate=
d attackers to bypass normal restrictions and make arbitrary changes to por=
t forwarding rules.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-45422" target=3D= "_blank" rel=3D"noopener">CVE-2025-45422</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.14.=
2, an attacker can craft a PDF with a page content stream containing a not = terminated inline image that uses the ASCII85 or ASCIIHex filters, causing =
an infinite loop during parsing such as when extracting page text. This iss=
ue is fixed in version 6.14.2.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59935" target=3D= "_blank" rel=3D"noopener">CVE-2026-59935</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.14.=
1, an attacker can craft a PDF with a page content stream containing a not = terminated inline image, causing an infinite loop during inline image end m= arker detection such as when extracting page text. This issue is fixed in v= ersion 6.14.1.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59936" target=3D= "_blank" rel=3D"noopener">CVE-2026-59936</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.14.=
0, an attacker can craft a PDF with repeated malformed cross-reference stre= ams that cause pypdf to spend long runtimes recovering broken cross-referen=
ce table entries. This issue is fixed in version 6.14.0.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59937" target=3D= "_blank" rel=3D"noopener">CVE-2026-59937</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.14.=
0, an attacker can craft a PDF with declared image size values that are muc=
h too large compared to the actual data, causing large memory usage in pypd=
f image parsing. This issue is fixed in version 6.14.0.</td> <td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59938" target=3D= "_blank" rel=3D"noopener">CVE-2026-59938</a></td>
</tr>
<td class=3D"vendor-product">Python Software Foundation--CPython</td>
<td>The incremental HTML parser (html.parser.HTMLParser) allows for CPU den= ial-of-service through repeated unterminated markup declarations when proce= ssing uncontrolled data.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15308" target=3D= "_blank" rel=3D"noopener">CVE-2026-15308</a></td>
</tr>
<td class=3D"vendor-product">qax-os--excelize</td>
<td>Excelize is a Go language library for reading and writing Microsoft Exc=
el spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Ro=
ws and GetRows does not enforce the TotalRows limit on the row r attribute,=
allowing a small XLSX file with a row number above 1048576 and no cell coo= rdinate to make GetRows append empty rows up to the attacker-controlled ind=
ex and consume excessive memory and CPU. This issue is fixed in version 2.1= 1.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59161" target=3D= "_blank" rel=3D"noopener">CVE-2026-59161</a></td>
</tr>
<td class=3D"vendor-product">qax-os--excelize</td>
<td>Excelize is a Go language library for reading and writing Microsoft Exc=
el spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values=
with strconv.Atoi and checks only the upper bound before indexing the shar=
ed string slice, allowing an XLSX file containing a shared-string cell with=
-1 to trigger sharedStrings[-1] and panic when read through GetCellValue o=
r GetRows. This issue is fixed in version 2.11.0.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59162" target=3D= "_blank" rel=3D"noopener">CVE-2026-59162</a></td>
</tr>
<td class=3D"vendor-product">Qt--Axivion</td>
<td>The implementation of an internal=C2=A0and=C2=A0undocumented=C2=A0Dashb= oard=C2=A0API endpoint=C2=A0(POST /api/users/~/{user}/tokens)=C2=A0forgot= =C2=A0to ensure an HTTP=C2=A0request for creating an=C2=A0API=C2=A0Token fo=
r another=C2=A0user had sufficient permission to do so. Precondition for su= ccessful exploitation was a preexisting internal user (with more privileges=
than the attacker),=C2=A0the attacker knowing=C2=A0its login name and the = attacker being able to authenticate to the Dashboard via OAuth/OIDC. The at= tacker=C2=A0would then have=C2=A0had=C2=A0to forge a token creation=C2=A0AP= I=C2=A0request=C2=A0on behalf of the=C2=A0other user and could have authent= icated=C2=A0and=C2=A0finalized=C2=A0the token creation=C2=A0with their own= =C2=A0OAuth/OIDC=C2=A0credentials. In the worst case, this would mean an at= tacker could=C2=A0have=C2=A0become Dashboard Administrator=C2=A0and=C2=A0be= en=C2=A0able to=C2=A0perform=C2=A0all=C2=A0administrative actions=C2=A0if t=
he preexisting internal user had administrative=C2=A0privileges.=C2=A0In co= mbination with a separate weakness,=C2=A0this could have=C2=A0further=C2=A0= led=C2=A0to code execution on the=C2=A0host=C2=A0system running the Dashboa=
rd with the privileges of the OS-User running the Dashboard=C2=A0server.</t=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12593" target=3D= "_blank" rel=3D"noopener">CVE-2026-12593</a></td>
</tr>
<td class=3D"vendor-product">R-SOFT SERWIS--DMS</td>
<td>R-SOFT DMS is vulnerable to=C2=A0OS Command Injection in konwertujActio= n() function.=C2=A0The document converter executes shell commands using uns= anitized file paths and format parameters.=C2=A0This allows an authenticate=
d attacker to execute arbitrary system commands with the privileges of the = web server user. This issue was fixed in version=C2=A0v3.19-2752 and v3.17-= 2580.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41876" target=3D= "_blank" rel=3D"noopener">CVE-2026-41876</a></td>
</tr>
<td class=3D"vendor-product">R-SOFT SERWIS--DMS</td>
<td>R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Au= thenticated attacker can inject arbitrary HTML and JS into the name=C2=A0of=
the file being uploaded, which will be executed when visiting file list or=
upload status by other users. This issue was fixed in version v3.19-2832= =C2=A0and v3.17-2580.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41877" target=3D= "_blank" rel=3D"noopener">CVE-2026-41877</a></td>
</tr>
<td class=3D"vendor-product">R-SOFT SERWIS--DMS</td>
<td>R-SOFT DMS is vulnerable to=C2=A0Insecure Direct Object Reference (IDOR=
) attack in multiple file download endpoints. The application fetches files=
from the database by ID and serves them to whoever requests them, relying = only on session authentication, meaning any valid user can access any file.=
This issue was fixed in version v3.19-2862=C2=A0and v3.17-2580.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41878" target=3D= "_blank" rel=3D"noopener">CVE-2026-41878</a></td>
</tr>
<td class=3D"vendor-product">R-SOFT SERWIS--DMS</td>
<td>R-SOFT DMS=C2=A0stores superadmin credentials using a non-salted nested=
MD5 hash. This allows an attacker who obtain password hash to decode super= admin credentials. Critically, this password cannot be changed=C2=A0except =
by modifying the configuration file. This issue was fixed in version=C2=A0v= 3.17-2000.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41879" target=3D= "_blank" rel=3D"noopener">CVE-2026-41879</a></td>
</tr>
<td class=3D"vendor-product">R-SOFT SERWIS--DMS</td>
<td>R-SOFT DMS is vulnerable to=C2=A0OS Command Injection in the Optical Ch= aracter Recognition (OCR) module. Multiple command execution functions acce=
pt user-controllable file paths without proper sanitization before passing = them to the system shell via SSH. In current infrastructure the URL encodin=
g neutralizes the injection during the standard web upload flow. An authent= icated attacker who=C2=A0is able to trigger the OCR functionality for the u= ploaded file can execute OS commands within the context of a root user. Thi=
s issue was fixed in version=C2=A0v3.19-2862=C2=A0and v3.17-2580.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-41880" target=3D= "_blank" rel=3D"noopener">CVE-2026-41880</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19,=
4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized vali=
d JSON bodies on with_decode and direct_request paths because read_complete= _body checks the accumulated size before the final chunk but not the final = combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and=
4.2.5.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57212" target=3D= "_blank" rel=3D"noopener">CVE-2026-57212</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19,=
4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the c= onsumer_tag field on the Federation Status page without HTML escaping, allo= wing a user who can configure a federation upstream or policy to execute Ja= vaScript in the browser of a user viewing that page. This issue is fixed in=
versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57213" target=3D= "_blank" rel=3D"noopener">CVE-2026-57213</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the Rabbi= tMQ management UI renders the x-internal-purpose queue or exchange argument=
into an HTML title attribute without proper escaping on the Queues and Exc= hanges pages, allowing a user with permission to declare a queue or exchang=
e to execute JavaScript in another user's browser. This issue is fixed in v= ersion 4.2.5.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57214" target=3D= "_blank" rel=3D"noopener">CVE-2026-57214</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20,=
4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-=
to destinations because volatile direct-reply-to queues can be accepted at = bind and route time but are missing from Khepri-backed deletion checks, lea= ving persistent route entries after unbind. This issue is fixed in versions=
3.13.15, 4.0.20, 4.1.11, and 4.2.6.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57215" target=3D= "_blank" rel=3D"noopener">CVE-2026-57215</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21,=
4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic=
writes and binds during metadata-store failures because topic-permission l= ookup errors from Khepri can collapse to undefined, which the internal back= end treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.1=
1, and 4.2.6.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57217" target=3D= "_blank" rel=3D"noopener">CVE-2026-57217</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ = AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAu=
th token expiry or connection.update_secret refresh to reduced scopes becau=
se existing consumers are not canceled or reauthorized at delivery time aft=
er the channel user state changes. This issue is fixed in version 4.2.6.</t=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57218" target=3D= "_blank" rel=3D"noopener">CVE-2026-57218</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20,=
4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OA= uth 2 client secret on RabbitMQ installations configured with management.oa= uth_client_secret, exposing credentials to unauthenticated callers when the=
management plugin and that OAuth configuration are enabled. This issue is = fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57219" target=3D= "_blank" rel=3D"noopener">CVE-2026-57219</a></td>
</tr>
<td class=3D"vendor-product">rabbitmq--rabbitmq-server</td>
<td>RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20,=
4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passi=
ve queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any a= uthenticated user who can connect to a virtual host to enumerate queue and = exchange names and read queue message and consumer counts. This issue is fi= xed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57221" target=3D= "_blank" rel=3D"noopener">CVE-2026-57221</a></td>
</tr>
<td class=3D"vendor-product">Raspberry Pi--Raspberry Pi 5 and Compute Modul=
e 5</td>
<td>EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced=
non-random KASLR and RNG seed values. This resulted in consistent kernel a= ddresses across boots and devices, potentially making it easier to exploit = other vulnerabilities. Additionally, the low-quality RNG seed may affect th=
e quality of random numbers or delay booting while sufficient entropy is ac= cumulated from other sources.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13199" target=3D= "_blank" rel=3D"noopener">CVE-2026-13199</a></td>
</tr>
<td class=3D"vendor-product">rsjoomla.com--rsjoomla.com RSFiles extension f=
or Joomla</td>
<td>The Joomla extension RSFiles is vulnerable to an unauthenticated arbitr= ary file upload that allows uploading executable files and leads to full RC= E.</td>
<td>2026-07-11</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57827" target=3D= "_blank" rel=3D"noopener">CVE-2026-57827</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Bixby</td>
<td>Improper export of android application components in Bixby prior to ver= sion 4.0.70.8 allows local attackers to execute arbitrary commands with Bix=
by privilege.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21055" target=3D= "_blank" rel=3D"noopener">CVE-2026-21055</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--InputSharing</td>
<td>Improper export of android application components in InputSharing prior=
to version 2.7.01.4 allows local attackers to access sharing data.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21054" target=3D= "_blank" rel=3D"noopener">CVE-2026-21054</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Email</td>
<td>Improper input validation in Samsung Email prior to version 6.2.13.1 al= lows local attackers to create arbitrary files within the application sandb= ox.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21053" target=3D= "_blank" rel=3D"noopener">CVE-2026-21053</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Health</td>
<td>Improper authorization in Samsung Health prior to version 7.00.0.107 al= lows local attackers to access connected device information.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21056" target=3D= "_blank" rel=3D"noopener">CVE-2026-21056</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Improper access control in Settings prior to SMR Jul-2026 Release 1 all= ows local attackers to configure Theft protection settings.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21039" target=3D= "_blank" rel=3D"noopener">CVE-2026-21039</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Improper access control in IAFDService prior to SMR Jul-2026 Release 1 = allows local privileged attackers to use the privileged APIs.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21040" target=3D= "_blank" rel=3D"noopener">CVE-2026-21040</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Improper access control in SamsungSEAgentService prior to SMR Jul-2026 = Release 1 allows local attackers to access sensitive information.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21041" target=3D= "_blank" rel=3D"noopener">CVE-2026-21041</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 all= ows local attackers to execute arbitrary code.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21042" target=3D= "_blank" rel=3D"noopener">CVE-2026-21042</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 all= ows local privileged attackers to access files with system server privilege= .</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21043" target=3D= "_blank" rel=3D"noopener">CVE-2026-21043</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Releas=
e 1 allows local attackers to bypass the persistence configuration of the a= pplication.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21044" target=3D= "_blank" rel=3D"noopener">CVE-2026-21044</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram= .so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of= -bounds memory.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21045" target=3D= "_blank" rel=3D"noopener">CVE-2026-21045</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Time-of-check time-of-use race condition in fabricKeymaster trustlet pr= ior to SMR Jul-2026 Release 1 allows local privileged attackers to execute = arbitrary code.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21046" target=3D= "_blank" rel=3D"noopener">CVE-2026-21046</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.=
so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-= bounds memory.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21048" target=3D= "_blank" rel=3D"noopener">CVE-2026-21048</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release=
1 allows local attackers to execute arbitrary code.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21049" target=3D= "_blank" rel=3D"noopener">CVE-2026-21049</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Improper access control in SmartThingsKit prior to SMR Jul-2026 Release=
1 allows local attackers to access sensitive information.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21050" target=3D= "_blank" rel=3D"noopener">CVE-2026-21050</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Incorrect default permissions in WLAN security prior to SMR Jul-2026 Re= lease 1 allows local attackers to configure TencentWifiSecurity settings.</=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21051" target=3D= "_blank" rel=3D"noopener">CVE-2026-21051</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Mobile Devices</td> <td>Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 a= llows local privileged attackers to access files with system privilege.</td=
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21052" target=3D= "_blank" rel=3D"noopener">CVE-2026-21052</a></td>
</tr>
<td class=3D"vendor-product">Samsung Mobile--Samsung Pass</td>
<td>Improper input validation in Samsung Pass prior to version 5.2.10.3 all= ows local privileged attackers to write out-of-bounds memory.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21057" target=3D= "_blank" rel=3D"noopener">CVE-2026-21057</a></td>
</tr>
<td class=3D"vendor-product">SEIKO EPSON CORPORATION--Web Config</td> <td>Cross-site request forgery vulnerability exists in SEIKO EPSON Web Conf= ig. If a user views a malicious page while logged into Web Config, unintend=
ed operations may be performed.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58315" target=3D= "_blank" rel=3D"noopener">CVE-2026-58315</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan is an open-source personal knowledge management system. Prior to=
3.7.1, SiYuan renders note and package content to HTML through the Lute en= gine with sanitization enabled, but Lute's dangerous javascript scheme bloc=
k does not check form action or SVG xlink:href attributes, allowing stored = cross-site scripting in document export-preview and Bazaar package README r= ender paths that can execute OS commands in the Electron desktop renderer. = This issue is fixed in versions 3.7.1.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59833" target=3D= "_blank" rel=3D"noopener">CVE-2026-59833</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan is an open-source personal knowledge management system. Prior to=
3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized=
this.path value into HTML assigned to innerHTML, allowing a crafted asset = link containing a double quote to break out of the src attribute, inject an=
event handler, and execute JavaScript that can run OS commands in the Elec= tron renderer. This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1.</td=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59855" target=3D= "_blank" rel=3D"noopener">CVE-2026-59855</a></td>
</tr>
<td class=3D"vendor-product">SOGo--SOGo</td>
<td>A SQL injection vulnerability in SOGo before 5.12.7 allows authenticate=
d users to execute arbitrary SQL statements via the search parameter of the=
allContactSearch endpoint.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39178" target=3D= "_blank" rel=3D"noopener">CVE-2026-39178</a></td>
</tr>
<td class=3D"vendor-product">SOGo--SOGo</td>
<td>A SQL injection vulnerability in SOGo before 5.12.7 allows authenticate=
d users to execute arbitrary SQL statements via the newPassword parameter i=
n the password change functionality.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-39179" target=3D= "_blank" rel=3D"noopener">CVE-2026-39179</a></td>
</tr>
<td class=3D"vendor-product">SOPlanning--SOPlanning</td>
<td>SOPlanning is vulnerable to SQL injection in the audit retention config= uration. An attacker holding=C2=A0parameters_all rights can inject SQL comm= ands into the audit configuration form which is then saved. The execution i= s=C2=A0triggered when the audit functionality is accessed (by the attacker =
or another user). This issue was fixed in version=C2=A01.56.01.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50644" target=3D= "_blank" rel=3D"noopener">CVE-2026-50644</a></td>
</tr>
<td class=3D"vendor-product">SQLite--SQLite</td>
<td>A NULL pointer dereference in the SQLite Session Extension in SQLite 3.= 53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an att= acker who can supply a malformed changeset blob to cause a denial of servic=
e. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt chan= geset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.</=
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50812" target=3D= "_blank" rel=3D"noopener">CVE-2026-50812</a></td>
</tr>
<td class=3D"vendor-product">SRI--Mojo::JSON</td>
<td>Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via un= bounded recursion in the pure-Perl decoder. The pure-Perl decode path (`_de= code_value` dispatching to `_decode_array` and `_decode_object`) recurses w= ith no depth limit, so a small deeply nested JSON document can consume exce= ssive memory. This path is the default when Cpanel::JSON::XS is not install=
ed or `MOJO_NO_JSON_XS=3D1` is set; the Cpanel::JSON::XS fast path is not a= ffected. Any caller that decodes an untrusted JSON body, for example `Mojo:= :Message::json` reached through `$c->req->json`, can exhaust process = memory and cause denial of service.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14803" target=3D= "_blank" rel=3D"noopener">CVE-2026-14803</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A information disclosure when DEBUG loglevel is set in SUSE Rancher AI = Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potent= ial sensitive data into logfiles, allowing local attackers to misuse respec= tive gained data or credentials.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44934" target=3D= "_blank" rel=3D"noopener">CVE-2026-44934</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>Potential forgery of webhook requests when using a unauthenticated webh= ook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 befo=
re 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to caus=
e a denial of service or a downgrade attack on other repositories on the sy= stem.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44937" target=3D= "_blank" rel=3D"noopener">CVE-2026-44937</a></td>
</tr>
<td class=3D"vendor-product">swoosh--swoosh</td>
<td>URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Ada= pters.MsGraph builds its Microsoft Graph API request URL by interpolating t=
he sender's email address into the URL path (/users/{from}/sendMail) withou=
t percent-encoding or validation. In applications that derive the from addr= ess from untrusted or user-influenced input (for example a relay, a contact=
form, or a "send as" feature), an attacker can place URL-special character=
s such as /, ?, or # in the local part of the address to escape the intende=
d path segment and rewrite the path and query string of the request. Becaus=
e the same authenticated POST is sent with the application's Microsoft Grap=
h bearer token, the attacker can redirect it to other Graph endpoints withi=
n the token's scopes and control the request's query string. Applications t= hat always use a fixed, trusted from address are not affected. This issue a= ffects swoosh from 1.12.0 before 1.26.3.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54893" target=3D= "_blank" rel=3D"noopener">CVE-2026-54893</a></td>
</tr>
<td class=3D"vendor-product">T-Systems--Archivo</td>
<td>A validation vulnerability has been identified in certain web features = related to file management or upload in several products of the TAO 2.0 sui= te. This vulnerability could allow an attacker capable of interacting with = the affected feature to attempt to access file system resources outside the=
scope intended by the application.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7185" target=3D"= _blank" rel=3D"noopener">CVE-2026-7185</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 V3.0</td>
<td>Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length=
header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods=
). When a request carrying a Content-Length header is received without a co= rresponding message body, the RTSP parser enters a persistent body-awaiting=
state, causing the affected TCP connection to become permanently non-funct= ional. The device does not actively close the connection, resulting in a TC=
P resource leak. This issue can be exploited by an unauthenticated remote a= ttacker to cause a denial-of-service condition.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51600" target=3D= "_blank" rel=3D"noopener">CVE-2026-51600</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 V3.0</td>
<td>Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overfl=
ow in the RTSP service. The device fails to validate the length of the cloc= k=3D value in the Range header field when processing a PLAY request. An una= uthenticated remote attacker who has completed a standard RTSP session hand= shake can send a PLAY request with an excessively long clock=3D value to ca= use the RTSP service to crash.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51601" target=3D= "_blank" rel=3D"noopener">CVE-2026-51601</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 V3.0</td>
<td>A stack-based buffer overflow vulnerability in the RTSP service of Tend=
a CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker =
to cause a denial of service via a crafted SETUP request. The RTSP service'=
s second-stage URL routing parser fails to validate the length of the URL f= ield in the first SETUP request. By supplying a URL consisting of exactly f= our consecutive repetitions of a valid RTSP URL, an attacker can bypass fir= st-stage format validation and trigger a stack buffer overflow, causing an = immediate crash of the RTSP service process and rendering the device inacce= ssible to all clients on the local network.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51602" target=3D= "_blank" rel=3D"noopener">CVE-2026-51602</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 V3.0</td>
<td>A stack-based buffer overflow vulnerability in the RTSP service of Tend=
a CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker =
to cause a denial of service via a crafted second SETUP request. After comp= leting the OPTIONS, DESCRIBE, and a legitimate first SETUP request to obtai=
n a valid session ID, the RTSP service's second-stage URL routing parser fa= ils to validate the length of the URL field in the subsequent SETUP request=
. By supplying a URL consisting of exactly four consecutive repetitions of =
a valid RTSP URL, an attacker can bypass first-stage format validation and = trigger a stack buffer overflow, causing an immediate crash of the RTSP ser= vice process and rendering the device inaccessible to all clients on the lo= cal network.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51603" target=3D= "_blank" rel=3D"noopener">CVE-2026-51603</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 V3.0</td>
<td>A stack-based buffer overflow vulnerability in the RTSP service of Tend=
a CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker =
to cause a denial of service via a crafted PLAY request.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51604" target=3D= "_blank" rel=3D"noopener">CVE-2026-51604</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 V3.0</td>
<td>A stack-based buffer overflow vulnerability in the RTSP service of Tend=
a CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker=
to cause a denial of service via a crafted TEARDOWN request.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51605" target=3D= "_blank" rel=3D"noopener">CVE-2026-51605</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 V3.0</td>
<td>An improper input handling vulnerability in the RTSP service of Tenda C=
P3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the T=
CP connection with a RST packet when a request containing an oversized fiel=
d value is received, without returning any RFC 2326-compliant error respons=
e. This behavior affects the request-line URL field and header field values=
across multiple RTSP request types.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51606" target=3D= "_blank" rel=3D"noopener">CVE-2026-51606</a></td>
</tr>
<td class=3D"vendor-product">Tenda--firmware</td>
<td>The web server binary /bin/httpd contains a hidden backdoor authenticat= ion mechanism in the login() function at 004c88b8. - The function contains =
a normal authentication path using MD5/hash-based password verification (pr= od_encode64/PasswordToMd5/check_rand_key). - After normal authentication fa= ils, it calls GetValue("sys.rzadmin.password") to read a backdoor password = from the device configuration. - It performs a direct strcmp() comparison (= plaintext, not hashed) between the config value and the user-supplied passw= ord. A successful match grants role=3D2 (admin-level access) and creates a = valid session. The rzadmin username is never checked - any username works w= ith the backdoor</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11405" target=3D= "_blank" rel=3D"noopener">CVE-2026-11405</a></td>
</tr>
<td class=3D"vendor-product">tilt-dev--tilt</td>
<td>Tilt defines dev environments as code for microservice apps on Kubernet= es. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/ppro=
f handlers under /debug with no access control. When the HUD or apiserver l= istener is network-exposed, an unauthenticated caller can read process memo=
ry through /debug/pprof/heap and /debug/pprof/goroutine, including session = and apiserver tokens, and degrade performance through /debug/pprof/profile =
or /debug/pprof/trace. This issue is fixed in version 0.37.4.</td> <td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55882" target=3D= "_blank" rel=3D"noopener">CVE-2026-55882</a></td>
</tr>
<td class=3D"vendor-product">tilt-dev--tilt</td>
<td>Tilt defines dev environments as code for microservice apps on Kubernet= es. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated=
by a CSRF token, but the token is served by the unauthenticated /api/webso= cket_token endpoint and the upgrader accepts clients that omit an Origin he= ader. When the HUD is network-exposed, an attacker who can reach the listen=
er can open the HUD WebSocket and receive the full view stream, including s= ession state, Tiltfile contents, resource statuses, and continued updates. = This issue is fixed in version 0.37.4.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55883" target=3D= "_blank" rel=3D"noopener">CVE-2026-55883</a></td>
</tr>
<td class=3D"vendor-product">tilt-dev--tilt</td>
<td>Tilt defines dev environments as code for microservice apps on Kubernet= es. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers=
on a gorilla/mux router with no authenticating middleware. When the HUD is=
bound to a non-loopback address, an unauthenticated network caller can tri= gger developer-defined resources, tamper with Tiltfile arguments, read full=
engine state including the session token, and invoke apiserver resources t= hrough the token-attaching /proxy handler. This issue is fixed in version 0= .37.4.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55884" target=3D= "_blank" rel=3D"noopener">CVE-2026-55884</a></td>
</tr>
<td class=3D"vendor-product">TONYC--Imager</td>
<td>Imager versions before 1.032 for Perl have a heap out-of-bounds read in=
the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_= rgb_16_rle. read_rgb_16_rle guards each literal run with if (count > dat= a_left), but count is a pixel count while every 16-bit sample consumes two = bytes. The copy loop reads inp[0] * 256 + inp[1] and advances two bytes per=
pixel, so a run with data_left / 2 < count <=3D data_left passes the=
guard yet consumes 2 * count bytes and reads past the end of the buffer. T=
he 8-bit path is unaffected because there one pixel is one byte. Reading a = crafted SGI image through Imager->read triggers the over-read before the=
parser rejects the malformed image, which can crash the process.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13705" target=3D= "_blank" rel=3D"noopener">CVE-2026-13705</a></td>
</tr>
<td class=3D"vendor-product">TONYC--Imager</td>
<td>Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry cou= nts as signed. Imager mishandled large EXIF IFD entry count values, treatin=
g them as negative numbers. This could lead to an attempt to allocate a blo=
ck nearly the size of the address space, which fails and kills the process.=
An attacker could craft an image with EXIF data that terminates a worker p= rocess.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14454" target=3D= "_blank" rel=3D"noopener">CVE-2026-14454</a></td>
</tr>
<td class=3D"vendor-product">TONYC--Imager::File::JPEG</td> <td>Imager::File::JPEG versions before 1.003 for Perl leak heap memory when=
reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_= wiol walks the marker list libjpeg returns and, for each APP13 marker, allo= cates a new buffer with *iptc_itext =3D mymalloc(...) and overwrites the pr= evious pointer without freeing it. Only the final payload is later turned i= nto a Perl scalar and freed, so a JPEG with N such markers leaks the first = N-1 payloads on every read. In a long-lived process, such as an upload or t= humbnailing service, repeated reads accumulate these leaks and exhaust avai= lable memory, a denial of service. The same handler ships bundled in the Im= ager distribution, where versions before 1.032 are affected and the fix shi=
ps in 1.032.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13708" target=3D= "_blank" rel=3D"noopener">CVE-2026-13708</a></td>
</tr>
<td class=3D"vendor-product">traefik--traefik</td>
<td>Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, = v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middl= ewares strip canonical-cased spoofed identity headers before writing Traefi= k's own value, but do not account for underscore-variant header names, whic=
h many backends normalize identically to dashed forms. An attacker able to = reach a protected route can inject an underscore-variant header that surviv=
es Traefik's stripping and reaches the backend alongside, or on the unauthe= nticated ForwardAuth authResponseHeaders path instead of, the value Traefik=
intended to set, spoofing identity or authorization context. This issue is=
fixed in versions v2.11.51, v3.6.22, and v3.7.6.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54763" target=3D= "_blank" rel=3D"noopener">CVE-2026-54763</a></td>
</tr>
<td class=3D"vendor-product">traefik--traefik</td>
<td>Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, = v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured=
with trustForwardHeader: false, derives the X-Forwarded-Port header sent t=
o the authentication service from the original incoming request instead of = the sanitized forwarded request. As a result, an unauthenticated remote att= acker can inject an X-Forwarded-Proto: https header over a plain HTTP conne= ction and cause Traefik to forward X-Forwarded-Port: 443 to the authenticat= ion service, bypassing port-based authorization checks. This issue is fixed=
in versions v2.11.51, v3.6.22, and v3.7.6.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54764" target=3D= "_blank" rel=3D"noopener">CVE-2026-54764</a></td>
</tr>
<td class=3D"vendor-product">traefik--traefik</td>
<td>Traefik is an open source HTTP reverse proxy and load balancer. From v3= .7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve=
two accepted HTTPRoutes that target the same backend Service:port but conf= igure different backendRef filters to the same child service and apply only=
one route's filter set to all requests reaching that backend. In Gateway d= eployments where backendRef filters set security-sensitive headers, such as=
tenant identity, authorization context, or values the backend trusts, an a= ttacker who can create an accepted HTTPRoute sharing the same backend Servi= ce:port may cause their route's filter context to be applied to another rou= te's requests, potentially crossing namespace boundaries when a ReferenceGr= ant permits cross-namespace targeting. This issue is fixed in version v3.7.= 6.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54765" target=3D= "_blank" rel=3D"noopener">CVE-2026-54765</a></td>
</tr>
<td class=3D"vendor-product">Trueview--T18161-AF</td>
<td>Trueview Security camera T18161- AF v4.9.60.0 contains an authenticatio=
n bypass vulnerability caused by improper password validation and the prese= nce of hard-coded credentials in the firmware.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-37270" target=3D= "_blank" rel=3D"noopener">CVE-2026-37270</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Admin and Site Enhancements (ASE)</td=
<td>The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, ad= min-site-enhancements-pro WordPress plugin before 8.8.4 does not perform au= thentication, authorization, or nonce checks on a role-restoration request = handler, allowing unauthenticated attackers to restore a previously demoted=
administrator account back to the administrator role. This is an incomplet=
e fix of CVE-2024-43333 / CVE-2025-24648, which closed the issue for only o=
ne of the demotion paths the WordPress role API exposes.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12083" target=3D= "_blank" rel=3D"noopener">CVE-2026-12083</a></td>
</tr>
<td class=3D"vendor-product">Unknown--AllCoach</td>
<td>The AllCoach WordPress plugin before 1.0.2 does not verify that an emai=
l address submitted to a public account-registration endpoint is not alread=
y associated with an existing user before overwriting that user's password,=
allowing unauthenticated attackers to reset the password of arbitrary acco= unts, including administrators, and take over the site.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10830" target=3D= "_blank" rel=3D"noopener">CVE-2026-10830</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Appointment Booking Calendar Plugin a=
nd Scheduling Plugin</td>
<td>The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress=
plugin through 1.1.28 does not validate data before passing it to a PHP de= serialization function, allowing unauthenticated attackers to inject arbitr= ary PHP objects; where a suitable gadget chain is present on the site this = can be leveraged to achieve remote code execution.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12378" target=3D= "_blank" rel=3D"noopener">CVE-2026-12378</a></td>
</tr>
<td class=3D"vendor-product">Unknown--DoLeads Integrator</td>
<td>The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress=
plugin through 0.65 have been seen to be used to achieve RCE, once they ar=
e added adding to a blog, for example using a vulnerability where unclosed = extensions from wordpress.org can be installed by unauthorized users.</td> <td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4375" target=3D"= _blank" rel=3D"noopener">CVE-2026-4375</a></td>
</tr>
<td class=3D"vendor-product">Unknown--escortwp</td>
<td>The EscortWP escortwp WordPress theme through 3.6.2 was distributed wit=
h a vendor-authored, obfuscated backdoor that lets an unauthenticated attac= ker who supplies a hard-coded, per-build key permanently delete all of the = site's content, and that covertly transmits the site URL, administrator ema=
il address, and license key to a third-party server.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12685" target=3D= "_blank" rel=3D"noopener">CVE-2026-12685</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Everest Forms</td>
<td>The Everest Forms WordPress plugin before 3.5.0 does not reliably delet=
e temporary CSV files generated during email-notification processing and le= aves them publicly accessible in the uploads directory, allowing unauthenti= cated attackers to retrieve other users' form submission records via predic= table, enumerable filenames.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11571" target=3D= "_blank" rel=3D"noopener">CVE-2026-11571</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Everest Forms</td>
<td>The Everest Forms WordPress plugin before 3.5.0 does not correctly rest= rict access to several REST API endpoints belonging to its onboarding assis= tant: the capability check is only applied when an attacker-controllable re= quest header holds a specific value, so it can be bypassed by omitting or c= hanging that header. This makes it possible for unauthenticated attackers t=
o read onboarding status information, modify the related Everest Forms Word= Press plugin before 3.5.0 options, and trigger an email from the site to an=
arbitrary address.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12270" target=3D= "_blank" rel=3D"noopener">CVE-2026-12270</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Fediverse Embeds</td>
<td>The Fediverse Embeds WordPress plugin before 1.5.8 does not validate th=
e destination of the server-side request performed by an unauthenticated me= dia-proxying endpoint, allowing anonymous users to make the site fetch arbi= trary URLs, including internal and private-network addresses, and read back=
the response body. This results in a full-read Server-Side Request Forgery=
and open proxy.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12516" target=3D= "_blank" rel=3D"noopener">CVE-2026-12516</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Fediverse Embeds</td>
<td>The Fediverse Embeds WordPress plugin before 1.5.8 does not validate th=
e destination of the server-side request performed by an unauthenticated si= te-info endpoint before fetching it, allowing anonymous users (the gating n= once is exposed on public pages carrying an embed) to make the site request=
internal and private-network URLs and read back the parsed page metadata. = This is a Server-Side Request Forgery.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12517" target=3D= "_blank" rel=3D"noopener">CVE-2026-12517</a></td>
</tr>
<td class=3D"vendor-product">Unknown--FileOrganizer</td>
<td>The FileOrganizer WordPress plugin before 1.2.0 does not validate the f= ile type on several of its file-management operations, allowing authenticat=
ed users who have been granted file-manager access - which its premium add-=
on can extend to sub-administrator roles - to upload arbitrary PHP files an=
d achieve remote code execution. This is an incomplete fix of CVE-2024-7985=
, which only added file-type validation to the upload operation.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11962" target=3D= "_blank" rel=3D"noopener">CVE-2026-11962</a></td>
</tr>
<td class=3D"vendor-product">Unknown--FileOrganizer</td>
<td>The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager = WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.= 1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a pa= rameter before passing it to a shell command when processing image operatio= ns, allowing authenticated users to perform OS Command Injection. This requ= ires the server to have the ImageMagick convert CLI available without eithe=
r the PHP imagick or GD extensions.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6382" target=3D"= _blank" rel=3D"noopener">CVE-2026-6382</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Frontend File Manager Plugin</td>
<td>The Frontend File Manager Plugin WordPress plugin through 23.6 does not=
validate a file path derived from user input before deleting the reference=
d file, allowing unauthenticated users to delete arbitrary files on the ser= ver (such as wp-config.php) when guest upload mode is enabled. Deleting wp-= config.php forces the site into its setup routine, which can be leveraged t= oward a full site takeover.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12277" target=3D= "_blank" rel=3D"noopener">CVE-2026-12277</a></td>
</tr>
<td class=3D"vendor-product">Unknown--LA-Studio Element Kit for Elementor</=
<td>The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 d= oes not check whether user registration is enabled on the site before creat= ing an account through one of its unauthenticated AJAX actions, allowing un= authenticated attackers to register new accounts even when registration has=
been disabled site-wide.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12276" target=3D= "_blank" rel=3D"noopener">CVE-2026-12276</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Notifications for Forms & WordPre=
ss Actions</td>
<td>The Notifications for Forms & WordPress Actions WordPress plugin be= fore 2.6 does not validate a user-supplied value before using it to build a=
server-side file inclusion path, allowing authenticated users with subscri= ber-level access and above to include and execute arbitrary local PHP files=
on the server.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-6228" target=3D"= _blank" rel=3D"noopener">CVE-2024-6228</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Simple Membership</td>
<td>The Simple Membership WordPress plugin before 4.7.5 does not verify the=
authenticity of Stripe webhook requests when no signing secret is configur= ed, nor escape a value taken from them before outputting it in an administr= ator notice, allowing unauthenticated attackers to inject arbitrary web scr= ipts that execute in the context of a logged-in administrator.</td> <td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11855" target=3D= "_blank" rel=3D"noopener">CVE-2026-11855</a></td>
</tr>
<td class=3D"vendor-product">Unknown--Ultimate Member</td>
<td>The Ultimate Member WordPress plugin before 2.12.0 does not properly sa= nitise and escape the value of custom textarea profile fields before output= ting it on user profiles, allowing authenticated users with Subscriber-leve=
l access and above to store JavaScript that executes when any user, includi=
ng an administrator, views the affected profile.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11766" target=3D= "_blank" rel=3D"noopener">CVE-2026-11766</a></td>
</tr>
<td class=3D"vendor-product">Unknown--uncanny-automator-pro</td>
<td>The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distribut=
ed with malicious code after the vendor's uncanny-automator-pro WordPress p= lugin before 7.3.0.6 update/distribution infrastructure was compromised; th=
e injected backdoor grants unauthenticated attackers an administrator sessi=
on on affected sites and beacons the site's secret keys and administrator d= etails to attacker-controlled servers.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12375" target=3D= "_blank" rel=3D"noopener">CVE-2026-12375</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP DSGVO Tools (GDPR)</td>
<td>The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perfo=
rm an authorization check on the immediate-processing path of its data subj= ect access request feature, allowing unauthenticated attackers to generate = and download the full personal-data export (including name, postal address,=
phone number, email, and comment content) of any user, customer, or commen= ter by supplying their email address.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11869" target=3D= "_blank" rel=3D"noopener">CVE-2026-11869</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP Support Plus Responsive Ticket Sys= tem</td>
<td>The WP Support Plus Responsive Ticket System WordPress plugin through 9= .1.2 does not sign or verify its guest-session cookie, allowing unauthentic= ated attackers to forge it and impersonate any ticket owner (identified by = email address) to read, reply to, and close that person's support tickets.<=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11875" target=3D= "_blank" rel=3D"noopener">CVE-2026-11875</a></td>
</tr>
<td class=3D"vendor-product">Unknown--WP Travel Engine</td>
<td>The WP Travel Engine WordPress plugin before 6.8.1 does not properly va= lidate the source of a user-supplied profile image path before moving the f= ile, allowing authenticated users with subscriber-level access and above to=
relocate arbitrary files within the WordPress uploads directory into their=
own profile-image path. This removes the targeted media from its original = location and can break content across the site.</td>
<td>2026-07-07</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10834" target=3D= "_blank" rel=3D"noopener">CVE-2026-10834</a></td>
</tr>
<td class=3D"vendor-product">vim--vim</td>
<td>Vim is an open source, command line text editor. Prior to 9.2.0736, the=
PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolate=
s a class or trait name, taken from the contents of the edited buffer, into=
a search() pattern that is run via win_execute() without escaping. A name = containing a single quote can terminate the search() string argument early,=
and because the bar is honored as an Ex command separator, the remainder o=
f the name is run as Ex commands; via the :! command this allows arbitrary = operating-system command execution when a victim opens a crafted PHP file a=
nd invokes omni-completion. This issue is fixed in version 9.2.0736.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59856" target=3D= "_blank" rel=3D"noopener">CVE-2026-59856</a></td>
</tr>
<td class=3D"vendor-product">vim--vim</td>
<td>Vim is an open source, command line text editor. Prior to 9.2.0725, the=
single-byte branch of spell_soundfold_sal() in src/spell.c translates a wo=
rd through a spell file's SAL sound-folding rules into a caller-owned resul=
t buffer, but its result writes are guarded with reslen < MAXWLEN, allow= ing reslen to reach MAXWLEN before res[reslen] =3D NUL writes one byte past=
the end of the MAXWLEN-element stack buffer. A boundary-length word passed=
to soundfold(), or reached via sound-based spell suggestion while a SAL-ba= sed spell language is active under a non-multibyte 8-bit encoding, can corr= upt the eval_soundfold() stack frame and crash the editor. This issue is fi= xed in version 9.2.0725.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59857" target=3D= "_blank" rel=3D"noopener">CVE-2026-59857</a></td>
</tr>
<td class=3D"vendor-product">vim--vim</td>
<td>Vim is an open source, command line text editor. Prior to 9.2.0735, the=
C omni-completion script in runtime/autoload/ccomplete.vim interpolates th=
e typeref: or typename: extension field of a tags entry, without escaping, = into a :vimgrep pattern that is run through :execute. Because :vimgrep hono=
rs the bar as a command separator, a crafted tag field can close the search=
pattern and append an arbitrary Ex command; opening a hostile .c file whos=
e project tags file contains such an entry and invoking C omni-completion r= uns that command as the editing user. This issue is fixed in version 9.2.07= 35.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59858" target=3D= "_blank" rel=3D"noopener">CVE-2026-59858</a></td>
</tr>
<td class=3D"vendor-product">vllm-project--vllm</td>
<td>vLLM is a library for LLM inference and serving. From 0.12.0 to before = 0.24.0, sending a pure prompt embeds payload in a /v1/completions request w= ith a model using M-RoPE causes EngineCore to fail an assertion and fatally=
crash, shutting down the entire server application. Any remote user who is=
authorized to make a /v1/completions request can make such a request and i= nduce a crash. This issue is fixed in version 0.24.0.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55514" target=3D= "_blank" rel=3D"noopener">CVE-2026-55514</a></td>
</tr>
<td class=3D"vendor-product">vllm-project--vllm</td>
<td>vLLM is a high-throughput and memory-efficient inference and serving en= gine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter = passes a user-supplied regular expression string directly to the grammar co= mpiler backends with no compilation timeout; in the xgrammar backend the st= ring reaches the regex compiler with no guard, and in the outlines backend = the validation step blocks structural issues such as lookarounds and backre= ferences but performs no complexity analysis, so a pattern with nested quan= tifiers passes all checks and causes exponential state-space expansion, all= owing a single request containing an adversarial regex to hang an inference=
worker indefinitely and deny service. This issue is fixed in version 0.24.= 0.</td>
<td>2026-07-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55574" target=3D= "_blank" rel=3D"noopener">CVE-2026-55574</a></td>
</tr>
<td class=3D"vendor-product">Wireless Technology, Inc.--Wireless Technology=
, Inc.</td>
<td>An unauthenticated path traversal vulnerability exists in the web manag= ement interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 2024/05/=
24 00:00:00. An unauthenticated attacker can craft malicious HTTP requests = containing traversal sequences to access files outside of the intended web = root directory. This may allow disclosure of sensitive system files and con= figuration data</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-70796" target=3D= "_blank" rel=3D"noopener">CVE-2025-70796</a></td>
</tr>
<td class=3D"vendor-product">X.Org--xorg-x11-server</td>
<td>Local attackers with a X connection able to provide GLX commit to the X=
server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause =
a Heap Use After Free, due to=C2=A0CommonMakeCurrent() pointing into potent= ially reallocated memory.</td>
<td>2026-07-08</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56000" target=3D= "_blank" rel=3D"noopener">CVE-2026-56000</a></td>
</tr>
<td class=3D"vendor-product">Xen--oxenstored</td>
<td>When oxenstored is tearing a domain down, the node data is cleaned up b=
ut the usage counts are leaked. When the domain ID is eventually reused, th=
e new domain can create fewer nodes before beeing deemed to be over quota.<=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23556" target=3D= "_blank" rel=3D"noopener">CVE-2026-23556</a></td>
</tr>
<td class=3D"vendor-product">Xen--varstored</td>
<td>varstored is a component of the Xapi toolstack handling UEFI Variables = for a VM. It has a communication path with OVMF inside the VM involving map= ping a buffer prepared by OVMF. Within varstored, there were insufficient c= ompiler barriers, creating TOCTOU issues with data in the shared buffer. Th=
e exact vulnerable behaviour depends on the code generated by the compiler.=
In a build of varstored using default settings, the attacker can control a=
n index used in a jump table.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-58151" target=3D= "_blank" rel=3D"noopener">CVE-2025-58151</a></td>
</tr>
<td class=3D"vendor-product">Xen--Windows PV drivers</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] The Windows PV dr= ivers expose various facilities to userspace. Several of these have no secu= rity descriptor, and are therefore fully accessible to unprivileged users. = These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus=
, CVE-2025-27464</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27462" target=3D= "_blank" rel=3D"noopener">CVE-2025-27462</a></td>
</tr>
<td class=3D"vendor-product">Xen--Windows PV drivers</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] The Windows PV dr= ivers expose various facilities to userspace. Several of these have no secu= rity descriptor, and are therefore fully accessible to unprivileged users. = These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus=
, CVE-2025-27464</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27463" target=3D= "_blank" rel=3D"noopener">CVE-2025-27463</a></td>
</tr>
<td class=3D"vendor-product">Xen--Windows PV drivers</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] The Windows PV dr= ivers expose various facilities to userspace. Several of these have no secu= rity descriptor, and are therefore fully accessible to unprivileged users. = These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus=
, CVE-2025-27464</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27464" target=3D= "_blank" rel=3D"noopener">CVE-2025-27464</a></td>
</tr>
<td class=3D"vendor-product">Xen--XAPI</td>
<td>There are multiple issues. 1. Updates to the XAPI database sanitise inp=
ut strings, but try generating the notification using the unsanitised input=
. This causes the database's event thread to terminate and cease further pr= ocessing. 2. XAPI's UTF-8 encoder implements v3.0 of the Unicode spec, but = XAPI uses libraries which conform to the stricter v3.1 of the Unicode spec.=
This causes some strings to be accepted as valid UTF-8 by XAPI, but reject=
ed by other libraries in use. Notably, such strings can be entered into the=
database, after which the database can no longer be loaded. 3. There is no=
input sanitisation for Map/Set updates on objects in the XAPI database.</t=
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-58146" target=3D= "_blank" rel=3D"noopener">CVE-2025-58146</a></td>
</tr>
<td class=3D"vendor-product">Xen--XAPI</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] XAPI can configur=
e different users with different roles, using Role Based Access Control. Fo=
r more details, see:
https://docs.xenserver.com/en-us/xencenter/current-rel= ease/rbac-overview.html#rbac-roles The pool-admin role is fully privileged.=
Notably, users with this role can also SSH into the host as root. The othe=
r administrator roles are pool-operator, vm-power-admin and vm-admin, each =
of which are authorised to configure and manage various aspects of the syst= em. Some settings are inadequately restricted, and can be set by a lower pr= ivilege of administrator than expected. * CVE-2026-23559: A vm-admin can se=
t VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs=
(virtual disks) and give said disks to a VM they control. This is an arbit= rary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can = set VM.other-config:is_system_domain and mark a VM as a system domain. Syst=
em domains are ignored and left running during certain other host/pool oper= ations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admi=
n can set VM.other_config:storage_driver_domain and mark a VM as the storag=
e domain for a particular host storage connection (PBD). Shutting down the =
VM can cause the PBD to be erroneously marked as unplugged when it is not. =
* CVE-2026-23562: Configuration of PCI passthrough is normally restricted t=
o the pool-admin role. However one API was missing this check, allowing a v= m-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin ca=
n set the VM.platform:hvm_serial parameter, which should be restricted to t=
he pool-admin role, as it can allow arbitrary dom0 file write.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23559" target=3D= "_blank" rel=3D"noopener">CVE-2026-23559</a></td>
</tr>
<td class=3D"vendor-product">Xen--XAPI</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] XAPI can configur=
e different users with different roles, using Role Based Access Control. Fo=
r more details, see:
https://docs.xenserver.com/en-us/xencenter/current-rel= ease/rbac-overview.html#rbac-roles The pool-admin role is fully privileged.=
Notably, users with this role can also SSH into the host as root. The othe=
r administrator roles are pool-operator, vm-power-admin and vm-admin, each =
of which are authorised to configure and manage various aspects of the syst= em. Some settings are inadequately restricted, and can be set by a lower pr= ivilege of administrator than expected. * CVE-2026-23559: A vm-admin can se=
t VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs=
(virtual disks) and give said disks to a VM they control. This is an arbit= rary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can = set VM.other-config:is_system_domain and mark a VM as a system domain. Syst=
em domains are ignored and left running during certain other host/pool oper= ations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admi=
n can set VM.other_config:storage_driver_domain and mark a VM as the storag=
e domain for a particular host storage connection (PBD). Shutting down the =
VM can cause the PBD to be erroneously marked as unplugged when it is not. =
* CVE-2026-23562: Configuration of PCI passthrough is normally restricted t=
o the pool-admin role. However one API was missing this check, allowing a v= m-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin ca=
n set the VM.platform:hvm_serial parameter, which should be restricted to t=
he pool-admin role, as it can allow arbitrary dom0 file write.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23560" target=3D= "_blank" rel=3D"noopener">CVE-2026-23560</a></td>
</tr>
<td class=3D"vendor-product">Xen--XAPI</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] XAPI can configur=
e different users with different roles, using Role Based Access Control. Fo=
r more details, see:
https://docs.xenserver.com/en-us/xencenter/current-rel= ease/rbac-overview.html#rbac-roles The pool-admin role is fully privileged.=
Notably, users with this role can also SSH into the host as root. The othe=
r administrator roles are pool-operator, vm-power-admin and vm-admin, each =
of which are authorised to configure and manage various aspects of the syst= em. Some settings are inadequately restricted, and can be set by a lower pr= ivilege of administrator than expected. * CVE-2026-23559: A vm-admin can se=
t VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs=
(virtual disks) and give said disks to a VM they control. This is an arbit= rary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can = set VM.other-config:is_system_domain and mark a VM as a system domain. Syst=
em domains are ignored and left running during certain other host/pool oper= ations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admi=
n can set VM.other_config:storage_driver_domain and mark a VM as the storag=
e domain for a particular host storage connection (PBD). Shutting down the =
VM can cause the PBD to be erroneously marked as unplugged when it is not. =
* CVE-2026-23562: Configuration of PCI passthrough is normally restricted t=
o the pool-admin role. However one API was missing this check, allowing a v= m-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin ca=
n set the VM.platform:hvm_serial parameter, which should be restricted to t=
he pool-admin role, as it can allow arbitrary dom0 file write.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23561" target=3D= "_blank" rel=3D"noopener">CVE-2026-23561</a></td>
</tr>
<td class=3D"vendor-product">Xen--XAPI</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] XAPI can configur=
e different users with different roles, using Role Based Access Control. Fo=
r more details, see:
https://docs.xenserver.com/en-us/xencenter/current-rel= ease/rbac-overview.html#rbac-roles The pool-admin role is fully privileged.=
Notably, users with this role can also SSH into the host as root. The othe=
r administrator roles are pool-operator, vm-power-admin and vm-admin, each =
of which are authorised to configure and manage various aspects of the syst= em. Some settings are inadequately restricted, and can be set by a lower pr= ivilege of administrator than expected. * CVE-2026-23559: A vm-admin can se=
t VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs=
(virtual disks) and give said disks to a VM they control. This is an arbit= rary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can = set VM.other-config:is_system_domain and mark a VM as a system domain. Syst=
em domains are ignored and left running during certain other host/pool oper= ations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admi=
n can set VM.other_config:storage_driver_domain and mark a VM as the storag=
e domain for a particular host storage connection (PBD). Shutting down the =
VM can cause the PBD to be erroneously marked as unplugged when it is not. =
* CVE-2026-23562: Configuration of PCI passthrough is normally restricted t=
o the pool-admin role. However one API was missing this check, allowing a v= m-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin ca=
n set the VM.platform:hvm_serial parameter, which should be restricted to t=
he pool-admin role, as it can allow arbitrary dom0 file write.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-23562" target=3D= "_blank" rel=3D"noopener">CVE-2026-23562</a></td>
</tr>
<td class=3D"vendor-product">Xen--XAPI</td>
<td>[This CNA information record relates to multiple CVEs; the text explain=
s which aspects/vulnerabilities correspond to which CVE.] XAPI can configur=
e different users with different roles, using Role Based Access Control. Fo=
r more details, see:
https://docs.xenserver.com/en-us/xencenter/current-rel= ease/rbac-overview.html#rbac-roles The pool-admin role is fully privileged.=
Notably, users with this role can also SSH into the host as root. The othe=
r administrator roles are pool-operator, vm-power-admin and vm-admin, each =
of which are authorised to configure and manage various aspects of the syst= em. Some settings are inadequately restricted, and can be set by a lower pr= ivilege of administrator than expected. * CVE-2026-23559: A vm-admin can se=
t VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs=
(virtual disks) and give said disks to a VM they control. This is an arbit= rary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can = set VM.other-config:is_system_domain and mark a VM as a system domain. Syst=
em domains are ignored and left running during certain other host/pool oper= ations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admi=
n can set VM.other_config:storage_driver_domain and mark a VM as the storag=
e domain for a particular host storage connection (PBD). Shutting down the =
VM can cause the PBD to be erroneously marked as unplugged when it is not. =
* CVE-2026-23562: Configuration of PCI passthrough is normally restricted t=
o the pool-admin role. However one API was missing this check, allowing a v= m-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin ca=
n set the VM.platform:hvm_serial parameter, which should be restricted to t=
he pool-admin role, as it can allow arbitrary dom0 file write.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-42486" target=3D= "_blank" rel=3D"noopener">CVE-2026-42486</a></td>
</tr>
<td class=3D"vendor-product">Xerte--Xerte Online Tools</td>
<td>A vulnerability in the Xerte Online Tools allows for RCE through the an= tivirus binary path in the tools server settings, which can be changed to a=
PHP interpreter, allowing an attacker to upload PHP data that will then be=
executed.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12116" target=3D= "_blank" rel=3D"noopener">CVE-2026-12116</a></td>
</tr>
<td class=3D"vendor-product">Xerte--Xerte Online Tools</td>
<td>A vulnerability in the Xerte Online Tools allows for authentication byp= ass and remote code execution via reinstallation through the /setup/ folder=
, enabling attackers to reinstall the service to a remote database they con= trol.</td>
<td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14261" target=3D= "_blank" rel=3D"noopener">CVE-2026-14261</a></td>
</tr>
<td class=3D"vendor-product">zen-browser--desktop</td>
<td>Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and spli= t-view context-menu actions, Open link in glance and Split link in new tab,=
load a page-controlled link URL with the System principal instead of the o= riginating page's principal, allowing a malicious web page to place a link =
to a file URL that can load with System privileges when opened through eith=
er context-menu item and bypass the content-to-file security check that blo= cks an ordinary click. This issue is fixed in version 1.21.5b.</td> <td>2026-07-09</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57501" target=3D= "_blank" rel=3D"noopener">CVE-2026-57501</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. Prior to 4.15.1=
, ZITADEL's event store validation can retain the original resource owner f=
or a deleted user identifier, causing a later user recreated with the same = identifier in another organization to be provisioned under the original org= anization and exposed to that organization's administrator. This issue is f= ixed in version 4.15.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55670" target=3D= "_blank" rel=3D"noopener">CVE-2026-55670</a></td>
</tr>
<td class=3D"vendor-product">zitadel--zitadel</td>
<td>ZITADEL is an open source identity management platform. From 4.0.0-rc.1=
through 4.15.1, ZITADEL's HTTP notification channels, OIDC BackChannel Log= out, and SAML metadata URL fetches do not consistently validate user-define=
d URLs against protected denylist handling, allowing server-side requests t=
o loopback, internal IP, link-local, or redirected endpoints through DNS re= binding, redirects, or protocol downgrades. This issue is fixed in version = 4.15.2.</td>
<td>2026-07-10</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55671" target=3D= "_blank" rel=3D"noopener">CVE-2026-55671</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
</div>
</div>
<style>body {
font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
l; font-style: normal; color: #333333;
}
</style>
=20
<div id=3D"mail_footer">
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/4205501" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"
https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"
https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"
https://www.cisa.gov/privacy-policy=
" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"
https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"
https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"
https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
: #757575;">=C2=A0 |=C2=A0 </span><a href=3D"
https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"
https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"
https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"
https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>
</div>
<div id=3D"tagline">
<hr>
<table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=
<tbody>
<td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to
cisa@toolazy.synchro.net using Granicus Commun= ications Cloud, on behalf of: Cybersecurity and Infrastructure Security Age= ncy =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
<td align=3D"right" width=3D"11%"><a href=3D"
https://granicus.com/solution/= digital-communication-engagement/" target=3D"_blank" rel=3D"noopener"><img = src=3D"
https://content.govdelivery.com/images/govd-logo-dark.png" border=3D= "0" alt=3D"GovDelivery logo" width=3D"115"></a></td>
</tr>
</tbody>
</table>
<style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
img {margin-left:0px; margin-right:0px;}</style>
</div>
</td>
</tr>
</table>
<img alt=3D"" src=3D"
https://links-2.govdelivery.com/CI0/0101019f5c43a29c-5= ce72583-893c-489d-9323-f67b131f8185-000000/lEFJspjAsX4VUptBgc9lAwo_m9h3lxif= TTdgOsHK-qU=3D452" style=3D"display: none; width: 1px; height: 1px;">
</body>
</html>
--===============2360347132490274785==--
--===============2652101280670941624==--