
CVE explainers
New CVEs explained in plain English within hours of disclosure: CVSS severity, whether it is actively exploited (CISA KEV), affected and fixed versions, and a response runbook.
328 entries
CVE-2026-100740: D-Link DIR-895L Flaw
CVE-2026-100740 affects D-Link DIR-895L firmware A1_102b07 with a critical remote L2TP parser flaw and no confirmed fix.
CVE-2026-100741: hMailServer JScript RCE
CVE-2026-100741 affects hMailServer 6.0.0–6.3.3 on Windows. Review JScript event scripting and upgrade to 6.3.4 or later.
CVE-2026-100870: Sylius Host Header Flaw
CVE-2026-100870 affects Sylius password-reset links and may enable administrator takeover. Upgrade to the fixed release for your branch.
CVE-2026-100520: Laranode Path Traversal
CVE-2026-100520 affects Laranode before 1.2.1, enabling authenticated path traversal and cross-tenant PHP file placement.
CVE-2026-100706: Kyverno Privilege Escalation
CVE-2026-100706 affects Kyverno before 1.19.1 and may enable cluster-wide privilege escalation through encoded apiCall URL paths.
CVE-2026-18143: WooCommerce File Upload Flaw
CVE-2026-18143 affects Request a Quote for WooCommerce through 2.9.2, allowing unauthenticated file uploads and possible site takeover.
CVE-2026-82901: Ultra Addons File Upload
CVE-2026-82901 affects Ultra Addons for Contact Form 7 through 3.5.50. Disable PDF Generator and monitor exposed WordPress sites.
CVE-2026-85984: WordPress OTP Bypass
CVE-2026-85984 affects miniOrange OTP Login for WordPress through 5.5.5, enabling administrator login bypass under specific settings.
CVE-2026-100075: Linux RDMA SRPT Flaw
CVE-2026-100075 affects Linux kernels using RDMA SRPT and is rated CVSS 9.8. Verify vendor fixes and disable unused SRPT services.
CVE-2026-14281: WordPress Privilege Escalation
CVE-2026-14281 affects a WordPress plugin through unauthenticated role metadata changes and OTP bypass. Upgrade to 4.8.7 or later.
CVE-2026-97063: X-SpringBoot Login Code Exposure
CVE-2026-97063 exposes X-SpringBoot login codes through unauthenticated endpoints. Review affected versions, detection, and mitigations.
CVE-2026-97730: pfSense Dashboard LFI
CVE-2026-97730 is a high-severity pfSense Dashboard LFI flaw that can enable PHP code execution. Upgrade or apply Netgate's fix.
CVE-2026-13249: Honeywell PD45 RCE
CVE-2026-13249 affects Honeywell PD45 printers through unauthenticated file upload and RCE. Upgrade F10.19.010040 to F10.22.030745.
CVE-2026-89078: Critical GitLab CI/CD Flaw
CVE-2026-89078 affects GitLab CE and EE through a CI/CD regex parsing flaw, enabling authenticated code execution. Upgrade to fixed releases.
CVE-2026-97359: HFS2 Filename Injection
CVE-2026-97359 enables unauthenticated RCE in HFS2 2.4.0 and earlier through crafted upload filenames. Learn detection and mitigation.
CVE-2026-18169: IBM FTM symbolic-link validation vulnerability
CVE-2026-18169 affects IBM Financial Transaction Manager on OpenShift and may expose sensitive data to authenticated remote attackers.
CVE-2026-59167: SunEditor Stored XSS
CVE-2026-59167 affects SunEditor before 2.47.11 with critical stored XSS risk. Upgrade, review stored content, and validate browser defenses.
CVE-2026-77602: Critical OpenC3 COSMOS Code Execution
CVE-2026-77602 affects OpenC3 COSMOS 5.1.0 through 7.2.x, enabling authenticated non-admin code execution. Upgrade to 7.3.0 or later.
CVE-2026-91798: Foxit PDF local privilege escalation
CVE-2026-91798 affects Foxit PDF update components. Learn the local privilege-escalation impact, detection steps, and patch status.
CVE-2026-75745: Adobe AEM Forms JEE Flaw
CVE-2026-75745 affects Adobe Experience Manager Forms JEE. Learn exposure, detection, mitigation, and urgent remediation for its critical authorization flaw.
CVE-2026-94493: Gigatech PDV5701 WebSocket Bypass
CVE-2026-94493 affects Gigatech PDV5701 firmware. Learn the WebSocket risk, exposure checks, and mitigation while no fixed version is known.
CVE-2026-77521: MaxKB Command Execution
CVE-2026-77521 enables critical command execution in MaxKB before 2.10.5-lts. Learn how to detect, remediate, and investigate the flaw.
CVE-2026-79920: Ajenti Root Code Execution
CVE-2026-79920 lets low-privileged Ajenti users run plugin management as root. Upgrade to Ajenti 2.2.16 or later and review access.
CVE-2026-90692: D-Link DIR-878 Vulnerability
CVE-2026-90692 affects D-Link DIR-878 firmware 120B05 through a critical remote stack overflow. Isolate management and plan replacement.
CVE-2026-94097: Netcore NBR200V2 RCE Risk
CVE-2026-94097 affects Netcore NBR200V2 firmware with remote command injection. Learn exposure, detection, mitigation, and patch status.
CVE-2026-94146: BioStar BIOS Driver Flaw
CVE-2026-94146 affects BioStar BIOS Update Utility 1.9.7.3 through a vulnerable kernel driver. Inventory, isolate, and monitor affected Windows systems.
CVE-2026-93962: Kamailio Heap Overflow
CVE-2026-93962 is a remote heap overflow in Kamailio's CDP Diameter Receiver. Review impact, detection, exploitation status, and patches.
CVE-2026-94003: Comfast CF-N1-S Buffer Overflow
CVE-2026-94003 affects Comfast CF-N1-S firmware 2.6.0.1 with a critical remote buffer overflow. Learn exposure, detection, and mitigation.
CVE-2026-94036: D-Link Router Authentication Bypass
CVE-2026-94036 lets local-network attackers change D-Link router admin passwords. Learn affected versions, detection, patching, and response steps.
CVE-2026-94083: Suricata DoH2 Type Confusion
CVE-2026-94083 affects Suricata before 8.0.7 through a DoH2 type confusion. Learn exposure, detection, mitigation, and upgrade steps.
CVE-2026-94089: D-Link DIR-868L Buffer Overflow
CVE-2026-94089 affects D-Link DIR-868L firmware 2.01b05. Review the public PoC, exposure risks, detection steps, and mitigation guidance.
CVE-2026-93741: Totolink A3002MU Buffer Overflow
CVE-2026-93741 affects Totolink A3002MU firmware with a remotely triggerable buffer overflow and public exploit disclosure.
CVE-2026-93922: SiYuan Stored XSS Risk
CVE-2026-93922 affects SiYuan through 3.8.4, enabling stored XSS and possible host command execution. Learn impact, detection, and mitigation.
CVE-2026-93985: OpenPanel Sandbox Escape
CVE-2026-93985 is a critical OpenPanel js-runtime sandbox escape enabling code execution through malicious webhook templates.
CVE-2025-15399: IBM Common Licensing CSRF Vulnerability
CVE-2025-15399 affects IBM Common Licensing administration tools through CSRF. Review affected versions, detection, mitigation, and IBM remediation guidance.
CVE-2026-61781: Critical pg_partman Privilege Escalation and RCE
CVE-2026-61781 affects pg_partman before 5.5.0, enabling privileged SQL execution through partition configuration. Upgrade and audit now.
CVE-2026-67100: HCL BigFix SQL Injection
CVE-2026-67100 affects HCL BigFix Service Management with SQL injection and cross-tenant PII exposure. Review detection and remediation.
CVE-2026-69865: Microsoft Registry Bypass
CVE-2026-69865 is a critical Microsoft Container Registry authorization bypass. Review exposure, restrict access, and monitor Microsoft guidance.
CVE-2026-93603: vm2 Sandbox Escape
CVE-2026-93603 is a critical vm2 sandbox escape affecting versions through 3.12.0. Upgrade to vm2 3.12.1 or later.
CVE-2026-54734: Critical SSRF in Prebid Server Java
CVE-2026-54734 is a critical SSRF in Prebid Server Java before 3.43.0. Learn affected versions, detection, mitigation, and patch guidance.
CVE-2026-62104: Migratico Lite RCE
CVE-2026-62104 affects Migratico Lite 2.6.8 and earlier with unauthenticated RCE. Learn detection, mitigation, patching, and response.
CVE-2026-87796: Unauthenticated Arbitrary File Upload in Multi Uploader for Gravity Forms
CVE-2026-87796 affects Multi Uploader for Gravity Forms through 1.1.9 with unauthenticated file upload risk. Disable the plugin pending a fix.
CVE-2026-92838: GeoVision DLL Hijacking
CVE-2026-92838 enables local code execution through DLL hijacking in GeoVision GV-Remote E-Map. Learn exposure, detection, and mitigation steps.
CVE-2026-27546: Authentication Bypass
CVE-2026-27546 is a critical unauthenticated authentication bypass affecting industrial devices. Product scope and fixed firmware remain unconfirmed.
CVE-2026-69486: Microsoft Edge Buffer Overflow
CVE-2026-69486 is a High-severity Microsoft Edge heap overflow with potential remote code execution. Review exposure, detection, and patch guidance.
CVE-2026-73456: Arista EOS gNPSI RCE
CVE-2026-73456 is a critical unauthenticated RCE in Arista EOS gNPSI. Learn affected configurations, detection steps, and safe mitigation.
CVE-2026-91843: Check Point Stack Overflow
CVE-2026-91843 is a critical Check Point stack overflow that may enable unauthenticated root-level remote code execution. Review exposure and patches.
CVE-2026-59971: MySQL MCP Server SQL Flaw
CVE-2026-59971 enables unauthenticated SQL execution in MySQL MCP Server SSE deployments. Upgrade to 0.4.2 and restrict access.
CVE-2026-71133: Oracle Access Manager Flaw
CVE-2026-71133 is a CVSS 10.0 unauthenticated Oracle Access Manager flaw. Identify affected versions and restrict access while patching.
CVE-2026-90847: ipTIME C200E OS Injection
CVE-2026-90847: Remote OS command injection in ipTIME C200E 1.094 firmware. Affected versions, detection, and mitigation guidance.
CVE-2026-91001: D-Link DI-8400 Buffer Overflow
CVE-2026-91001 affects D-Link DI-8400 firmware 16.07 with a critical remote buffer overflow and public exploit. Restrict access and replace.
CVE-2022-4995: Unauthenticated File Upload in Weaver E-cology
CVE-2022-4995 is a critical unauthenticated file upload in Weaver E-cology before 10.52 that can lead to JSP webshell RCE.
CVE-2026-11976: MonsterInsights Pro Supply-Chain Compromise
CVE-2026-11976 is a critical MonsterInsights Pro supply-chain compromise affecting versions 10.2.0 and 10.2.2 via a backdoored update path.
CVE-2026-14364: TrueBooker WordPress Plugin Vulnerability
CVE-2026-14364 is a critical TrueBooker WordPress flaw allowing unauthenticated password resets and possible admin takeover.
CVE-2026-14365: Unauthenticated Password Change in TrueBooker Plugin
CVE-2026-14365 is a critical auth bypass in the TrueBooker WordPress plugin that can let attackers reset arbitrary user passwords.
CVE-2026-9169: DLL Search Order Hijacking in Arena SDK
CVE-2026-9169 is a high severity local code execution flaw in LUCID Arena SDK for Windows. Affected users should upgrade to 1.0.85.11.
CVE-2026-15991: Authenticated arbitrary file deletion in WordPress File Manager
CVE-2026-15991 affects WordPress File Manager 6.0-6.9, allowing subscriber-level users to read or delete files and risk site takeover.
CVE-2026-5430: WSO2 JWT Authentication Bypass
CVE-2026-5430 is a critical WSO2 JWT auth bypass that can enable unauthorized access and account takeover. See affected versions and mitigations.
CVE-2026-55978: SecureAge CatchPulse Access Control Flaw
CVE-2026-55978 is a high severity SecureAge CatchPulse flaw allowing local policy bypass via a kernel filter port. Patch exists, versions unclear.
CVE-2026-67863: open62541 server-side use-after-free denial of service
CVE-2026-67863 is a high-severity open62541 use-after-free in 1.5.5 that can let remote attackers crash vulnerable OPC UA servers.
CVE-2026-10090: Red Hat ACM Application Subscription Escalation
CVE-2026-10090 allows namespace editors in Red Hat ACM to escalate to cluster-admin via Subscription abuse. Upgrade to 2.13.9.
CVE-2026-45100: OpenSIPS Buffer Overflow Vulnerability
CVE-2026-45100 is a critical OpenSIPS buffer overflow in {s.b64encode}, affecting 3.4.0-beta through 3.6.5 and 4.0.0-beta.
CVE-2026-48168: PraisonAI GitHub Actions Command Injection
CVE-2026-48168 is a critical PraisonAI workflow command injection flaw fixed in 4.6.40 that can enable repository compromise.
CVE-2026-71268: OpenPLC Runtime v3 arbitrary file write leading to RCE
CVE-2026-71268 is a critical OpenPLC Runtime v3 path traversal flaw enabling arbitrary file write and possible remote code execution.
CVE-2026-7329: Progress MarkLogic Server Privilege Escalation
CVE-2026-7329 is a critical MarkLogic Server privilege escalation flaw in REST query interfaces. Affected versions should upgrade now.
CVE-2026-9273: Password Reset Link Poisoning in Kadence Memberships
CVE-2026-9273 is a critical WordPress plugin flaw enabling unauthenticated password reset link poisoning and account takeover.
CVE-2025-29296: H3C /api/esps Command Injection
CVE-2025-29296 is a critical H3C command injection flaw in /api/esps that can lead to unauthenticated root RCE on affected devices.
CVE-2026-14175: Critical Unrestricted File Upload in HUMANIST
CVE-2026-14175 is a critical file upload flaw in HUMANIST Digital Human Resources affecting 26.0 before 26.1. Patch to 26.1.
CVE-2026-15721: Critical SQL Injection in HUMANIST HR
CVE-2026-15721 is a critical SQL injection flaw in HUMANIST Digital Human Resources 26.0. Learn affected versions, detection, and upgrade guidance.
CVE-2026-42169: GIMP Heap Buffer Overflows in APNG and DDS
CVE-2026-42169 is a GIMP heap overflow bug in APNG and DDS parsing that may allow code execution when a user opens a crafted image.
CVE-2026-48323: Adobe Campaign Classic template engine RCE
CVE-2026-48323 is a critical Adobe Campaign Classic RCE. Learn impact, detection, exploitation status, and what to do while version data remains unconfirmed.
CVE-2026-61514: Puwell IP Camera authentication bypass over TCP/23456
CVE-2026-61514 is a critical unauthenticated access flaw in Puwell IP Camera firmware 2.x through 4.x on TCP port 23456.
CVE-2026-18602: Unauthenticated command injection in GL.iNet GL-MT3000
CVE-2026-18602 is a critical unauthenticated RCE in GL.iNet GL-MT3000 up to 4.4.5 via /cgi-bin/glc ovpn-client handling.
CVE-2026-21548: UNISOC nr modem improper input validation DoS
CVE-2026-21548 is a high severity UNISOC nr modem flaw enabling remote denial of service on affected Android 13 to 16 devices.
CVE-2026-3245: Canon PRISMAproduction RCE Risk
CVE-2026-3245 is a high-severity deserialization flaw in Canon PRISMAproduction 6.5 or earlier that may allow adjacent-network RCE.
CVE-2026-69083: Critical unauthenticated SQL injection in SiYuan
CVE-2026-69083 is a critical SQL injection in SiYuan before 3.7.3 that can allow unauthenticated database access under exposed token conditions.
CVE-2026-69084: Critical SQL Injection in SiYuan API
CVE-2026-69084 is a critical SQL injection in SiYuan <= 3.7.2 that can expose and modify cleartext notebooks. Fixed in 3.7.3.
CVE-2026-10848: Zephyr RTOS OCPP Client Parser Issue
CVE-2026-10848 is a Zephyr OCPP 1.6 client parsing flaw that can cause out-of-bounds memory access via malicious websocket RPC frames.
CVE-2026-65321: PyAthena SQL Injection Flaw
CVE-2026-65321 is a critical SQL injection in PyAthena fixed in 3.35.4. Upgrade now to secure your applications.
CVE-2026-8457: WooCommerce Social Login Authentication Bypass
CVE-2026-8457 lets attackers bypass login in WooCommerce Social Login through forged Apple tokens, enabling account takeover.
CVE-2026-15964: Unauthenticated Password Reset in Single Sign On For TNG
CVE-2026-15964 is a critical WordPress plugin flaw enabling unauthenticated password resets and possible admin takeover.
CVE-2026-16635: Pronamic Pay Gravity Forms Privilege Escalation
CVE-2026-16635 is a high-severity Pronamic Pay flaw that can let low-privilege WordPress users escalate privileges via Gravity Forms.
CVE-2026-3141: Unauthenticated file deletion in FormGent WordPress plugin
CVE-2026-3141 is a critical FormGent WordPress flaw enabling unauthenticated file deletion and possible wp-config.php removal.
CVE-2026-34641: Adobe Premiere Pro Out-of-Bounds Write Vulnerability
CVE-2026-34641 is a high-severity Adobe Premiere Pro flaw triggered by a malicious file. Learn about detection and patching.
CVE-2026-67308: Wazuh Workflows Shell Injection
CVE-2026-67308 is a critical Wazuh workflows shell injection flaw enabling command execution and secret theft through crafted pull requests.
CVE-2026-17561: Critical code injection in Logsign SIEM
CVE-2026-17561 is a critical Logsign SIEM code injection flaw affecting versions before 6.4.108. Here is what defenders need to know.
CVE-2026-17566: pgAdmin 4 Import/Export Command Injection Risk
CVE-2026-17566 is a critical pgAdmin 4 flaw in Import/Export Data that can let authenticated users break psql command context.
CVE-2026-18452: Hard-coded API key in Rich Source DMS+
CVE-2026-18452 is a critical hard-coded credentials flaw in Rich Source DMS+ that may allow unauthenticated remote takeover.
CVE-2026-52855: Pterodactyl Wings Template Vulnerability
CVE-2026-52855 affects Pterodactyl Wings before 1.12.3, allowing low-privileged users to disclose daemon tokens and registry config.
CVE-2026-63223: CodeIgniter4 File Upload Vulnerability
CVE-2026-63223 is a critical CodeIgniter4 upload validation flaw fixed in 4.7.4 that can lead to executable file uploads and possible RCE.
CVE-2026-66421: OpenClaw Dashboard stored XSS via agent transcript messages
CVE-2026-66421 is a critical stored XSS in OpenClaw Dashboard that can let unauthenticated attackers run JavaScript in admin sessions.
CVE-2026-13435: IBM Langflow OSS PythonREPL Sandbox Bypass
CVE-2026-13435 is a critical IBM Langflow OSS sandbox bypass that can expose secrets and enable token forgery in affected versions.
CVE-2026-15435: IBM App Connect Enterprise arbitrary file write
CVE-2026-15435 is a critical IBM App Connect flaw enabling remote arbitrary file write via path traversal in crafted URL requests.
CVE-2026-48449: Adobe Campaign Classic Flaw Leads to Code Execution
CVE-2026-48449 is a critical Adobe Campaign Classic flaw with RCE impact. What is known, how to detect risk, and how to patch safely.
CVE-2026-58046: Blind SQL Injection in Plesk XML-RPC API
CVE-2026-58046 is a critical Plesk XML-RPC API SQL injection flaw affecting Plesk Obsidian 18.x before fixed releases.
CVE-2026-59309: VMware vCenter Authentication Bypass
CVE-2026-59309 is a critical VMware vCenter authentication bypass. Learn impact, affected products, detection ideas, and patch guidance.
CVE-2026-67595: Malicious JavaScript in VaahCMS OTP Email Template
CVE-2026-67595 affects VaahCMS 2.0.0 through 2.3.4 with embedded malicious JavaScript in OTP email templates. Patch immediately.
CVE-2026-16326: HashiCorp consul-mcp-server Token Isolation Flaw
CVE-2026-16326 affects consul-mcp-server 0.1.0 to 0.1.3, allowing cross-client Consul token reuse in stateless mode. Fixed in 0.1.4.
CVE-2026-18072: Hardcoded backdoor enables admin takeover in WordPress ARVE plugin
CVE-2026-18072 is a critical auth bypass in the WordPress ARVE plugin that can let attackers log in as admin. Impact, detection, and fixes.
CVE-2026-33267: Apache Traffic Server Input Validation Flaw
CVE-2026-33267 is a critical Apache Traffic Server flaw affecting versions 9.2.0-9.2.14 and 10.1.0-10.1.3. Upgrade to 9.2.15 or 10.1.4.
CVE-2026-54658: Critical SQL Injection in Hypequery
CVE-2026-54658 is a critical SQL injection flaw in @hypequery/clickhouse before 2.0.2. Learn affected versions, detection, and patching steps.
CVE-2026-54735: Prebid Server SSRF in Bidder Adapter URL Handling
CVE-2026-54735 is a critical Prebid Server SSRF affecting versions before 4.4.0. Learn impact, detection steps, and how to patch now.
CVE-2026-58162: Apache Traffic Server certifier plugin flaw
CVE-2026-58162 is a critical Apache Traffic Server certifier plugin flaw tied to attacker-controlled SNI. Affected versions and fixes inside.
CVE-2026-11756: Unauthenticated RCE in 3DEXPERIENCE Station Launcher App
CVE-2026-11756 is a critical unauthenticated RCE in Dassault Systemes 3DEXPERIENCE Station Launcher App affecting R2023x through R2026x.
CVE-2026-16462: SQL Injection in Weidmüller PROCON-WEB SCADA
CVE-2026-16462 is a critical unauthenticated SQL injection in Weidmüller PROCON-WEB SCADA via GetGridData.
CVE-2026-16498: Cross-tenant Credential Reuse in HashiCorp
CVE-2026-16498 is a critical token reuse flaw in terraform-mcp-server fixed in 1.1.0. Learn affected versions, detection, and mitigation.
CVE-2026-17524: zip-lib Directory Traversal Vulnerability
CVE-2026-17524 affects zip-lib before 1.1.0, enabling directory traversal during ZIP extraction via cached path validation logic.
CVE-2026-61953: Unauthenticated SSRF in Simple Link Directory Pro
CVE-2026-61953 is an unauthenticated SSRF in Simple Link Directory Pro for WordPress affecting versions up to 15.0.6.
CVE-2026-66713: Apache Axis2/Java Tomcat Tribes deserialization RCE
CVE-2026-66713 is a critical Apache Axis2/Java deserialization flaw enabling remote code execution when Tomcat Tribes clustering is enabled.
CVE-2026-14837: Lenze SSH Signature Verification Bypass
CVE-2026-14837 affects multiple Lenze products via improper SSH enablement signature verification, risking admin access and full compromise.
CVE-2026-16812: VeloCloud Orchestrator on-prem exposure
CVE-2026-16812 is a critical VeloCloud Orchestrator flaw with active exploitation and potential full orchestrator compromise.
CVE-2026-48030: Authenticated Command Injection in Pheditor
CVE-2026-48030 is a critical authenticated RCE in Pheditor 2.0.1 through 2.0.3, fixed in 2.0.4. Here's impact, detection, and patching.
CVE-2026-61511: Unauthenticated vBulletin eval injection RCE
CVE-2026-61511 is a critical vBulletin RCE affecting 5.x through 5.7.5 and 6.x through 6.2.1 via unauthenticated template rendering.
CVE-2026-15962: Fluent Forms Pro Add On Pack PHP Object Injection
CVE-2026-15962 is a high-severity PHP object injection flaw in Fluent Forms Pro Add On Pack affecting versions through 6.2.6.
CVE-2026-17497: NoteGen Tauri Shell Exposure Leads to Remote Code Execution
CVE-2026-17497 is a high severity NoteGen RCE fixed in 0.32.0. Learn affected versions, detection steps, and mitigation guidance.
CVE-2026-57989: Microsoft Edge origin validation error information disclosure
CVE-2026-57989 is a Microsoft Edge origin validation flaw causing network-based information disclosure. What defenders know and what to patch.
CVE-2026-63720: datamodel-code-generator Code Injection
CVE-2026-63720 is a high-severity RCE issue in datamodel-code-generator before 0.70.0 triggered by malicious schema input.
CVE-2026-10818: Unauthenticated File Upload in WPForms Pro
CVE-2026-10818 is a high-severity WPForms Pro flaw enabling unauthenticated arbitrary file upload and possible RCE on WordPress sites.
CVE-2026-60134: Weintek cMT3092X Cookie Manipulation Vulnerability
CVE-2026-60134 affects Weintek cMT3092X and EasyWeb V2, allowing privilege escalation via cookie manipulation. Versions and mitigations inside.
CVE-2026-10033: Unauthenticated Authorization Bypass in EventON Action User
CVE-2026-10033 lets unauthenticated attackers change non-admin capabilities in EventON Action User through 2.5.14. Patch to 2.5.15.
CVE-2026-15704: Authorization Bypass in Eclipse BaSyx Go Components
CVE-2026-15704 is a critical BaSyx Go Components ABAC bypass fixed in 1.0.1. Learn affected versions, detection steps, and mitigation.
CVE-2026-16870: Snowflake libsnowflakeclient RCE and Credential Exfiltration Flaws
CVE-2026-16870 affects Snowflake libsnowflakeclient before 2.9.2, enabling possible RCE, memory corruption, and credential exfiltration.
CVE-2026-42933: OT Segmentation Bypass in Panduit IntraVUE
CVE-2026-42933 is a critical Panduit IntraVUE flaw that may let attackers proxy through the product and bypass OT segmentation.
CVE-2026-56163: Azure Kubernetes Service Missing Authentication Elevation of Privilege
CVE-2026-56163 is a critical AKS elevation of privilege flaw caused by missing authentication. What is known, detection steps, and mitigation guidance.
CVE-2026-62835: Azure Portal Authorization Flaw
CVE-2026-62835 is a high-severity Azure Portal flaw due to improper authorization. Learn what defenders should do now.
CVE-2026-14282: Unauthenticated arbitrary file upload in rtCamp GoDAM
CVE-2026-14282 is a critical GoDAM WordPress plugin file upload flaw affecting versions through 1.12.2, with possible RCE impact.
CVE-2026-15074: @fastify/static Route Guard Bypass
CVE-2026-15074 affects @fastify/static through 10.1.0, allowing route guard bypass inside the static root. Upgrade to 10.1.1.
CVE-2026-46512: Frogman Dialplan Code Injection
CVE-2026-46512 is a critical Frogman code injection flaw fixed in 1.6.2 that can let low-privilege users inject Asterisk directives.
CVE-2026-47668: Critical DbGate RCE Vulnerability
CVE-2026-47668 is a critical DbGate RCE in dbgate-serve up to 7.1.8. Learn affected versions, exploitation status, detection, and patching.
CVE-2026-50522: SharePoint Deserialization RCE Under Active Exploitation
CVE-2026-50522 is a critical SharePoint deserialization flaw (CVSS 9.8) under active exploitation, letting attackers steal machine keys after a public PoC.
CVE-2026-59555: Unauthenticated Arbitrary File Deletion
CVE-2026-59555 is a critical unauthenticated arbitrary file deletion flaw in Participants Database up to 2.7.8.3, fixed in 2.7.8.4.
CVE-2026-63030: "wp2shell" WordPress Core RCE Chain, Now on CISA KEV
CVE-2026-63030 chains with CVE-2026-60137 for unauthenticated RCE in WordPress Core. Both are on CISA's KEV catalog with a July 24, 2026 patch deadline.
CVE-2026-65687: Bold Reports File Read Vulnerability
CVE-2026-65687 is a critical unauthenticated file read flaw in Bold Reports Standalone Report Designer before 14.1.12.
CVE-2026-16242: HyperShift Konnectivity Proxy Vulnerability
CVE-2026-16242 affects HyperShift Konnectivity listener auth, allowing rogue agent joins and possible traffic interception.
CVE-2026-44359: Meshtastic GitHub Actions Supply Chain Flaw
CVE-2026-44359 is a critical Meshtastic CI flaw that exposed secrets and elevated GitHub token access via untrusted pull request workflow execution.
CVE-2026-10130: FalkorDB QueryWeaver Authentication Bypass
CVE-2026-10130 is a high severity QueryWeaver auth bypass that can issue victim session tokens from a signup request.
CVE-2026-12484: Keras Unsafe Deserialization Vulnerability
CVE-2026-12484 is a high-severity Keras unsafe deserialization flaw in version 3.15.0 that can lead to arbitrary code execution.
CVE-2026-16209: Gerapy Project Upload Endpoint Vulnerability
CVE-2026-16209 is a high severity Gerapy auth bypass affecting versions up to 0.9.13, with public exploit disclosure and a patch commit available.
CVE-2026-16221: fast-uri Host Confusion Vulnerability
CVE-2026-16221 is a fast-uri host confusion flaw that can bypass SSRF and host validation in Node.js apps. Fixed in 2.4.3, 3.1.4, and 4.1.1.
CVE-2026-16227: SQL Injection in SourceCodester Timetabling System
CVE-2026-16227 is a high severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 via edit_subject.php ID.
CVE-2026-16117: Fastify http-proxy Prefix Escape
CVE-2026-16117 is a critical Fastify http-proxy flaw allowing prefix rewrite bypass via encoded paths. Upgrade to 11.6.0.
CVE-2026-47865: Authentication Bypass in VMware Avi Load Balancer
CVE-2026-47865 is a critical VMware Avi Load Balancer auth bypass affecting control-plane access. Review affected versions, detection, and fixes.
CVE-2026-47871: VMware Avi Load Balancer Directory Traversal
CVE-2026-47871 is a high severity VMware Avi Load Balancer directory traversal flaw affecting multiple branches. Fixes are available.
CVE-2026-49485: HAPI FHIR FHIRPathEngine ReDoS Vulnerability
CVE-2026-49485 is a high severity HAPI FHIR ReDoS flaw that can exhaust CPU via crafted regex input. Fixed in 6.9.9 and 6.9.4.2.
CVE-2026-53994: ProFTPD mod_sftp Heap Buffer Overflow
CVE-2026-53994 is a high severity ProFTPD mod_sftp flaw enabling authenticated SFTP DoS and possible memory corruption.
CVE-2024-23564: HCL Aftermarket EPC Password Recovery Flaw
CVE-2024-23564 is a critical HCL Aftermarket EPC flaw that may let invalid users redirect password emails. What to know, detect, and do.
CVE-2026-14956: Bricksforge WordPress Plugin Vulnerability
CVE-2026-14956 is a critical Bricksforge WordPress flaw that can let unauthenticated attackers create admin accounts on exposed sites.
CVE-2026-15982: Unauthenticated Privilege Escalation in Aimogen Pro / Aiomatic
CVE-2026-15982 is a critical WordPress plugin flaw in Aimogen Pro / Aiomatic allowing unauthenticated admin creation. Patch to 2.8.5.
CVE-2026-62241: Hard-Coded JWT Secret Enables Session Forgery
CVE-2026-62241 affects clawvet apps/api before 0.7.5, allowing unauthenticated session forgery and exposure of user email and API keys.
CVE-2026-7189: Proliz's OBS Sensitive Information Exposure Vulnerability
CVE-2026-7189 affects Proliz's OBS before v3.6.0, exposing sensitive data over the network. Learn impact, detection, and patch steps.
CVE-2026-9135: IBM Langflow OSS ToolGuard Code Injection Bypass
CVE-2026-9135 is a critical Langflow OSS code injection flaw that can bypass custom component restrictions and execute Python server-side.
CVE-2026-13741: Digits WordPress Plugin Privilege Escalation
CVE-2026-13741 allows authenticated users to escalate to admin in vulnerable Digits WordPress plugin installs under specific configurations.
CVE-2026-15013: miniOrange WordPress SAML SSO Bypass
CVE-2026-15013 is a critical auth bypass in miniOrange SAML SSO for WordPress. Affected sites should upgrade from 5.4.3 to 5.4.4.
CVE-2026-1609: Keycloak Disabled Users Can Obtain Tokens
CVE-2026-1609 is a Keycloak access control flaw fixed in 26.5.3 that can let disabled users obtain tokens through JWT authorization grant.
CVE-2026-45336: HireFlow Authentication Bypass via Hard-Coded Flask Secret
CVE-2026-45336 is a critical HireFlow auth bypass in versions 1.2 and earlier. Learn affected versions, detection steps, and mitigation.
CVE-2026-45695: Unauthenticated RCE in Kopia via SSH ProxyCommand Injection
CVE-2026-45695 is a critical Kopia RCE in passwordless server mode. Learn affected versions, detection steps, exploitation status, and fixes.
CVE-2026-15804: Authenticated SQL Injection in MetaGuru HCM
CVE-2026-15804 is a high severity authenticated SQL injection in MetaGuru HCM. Learn impact, detection, mitigation, and patch status.
CVE-2026-48334: Adobe Illustrator Improper Input Validation
CVE-2026-48334 is a critical Adobe Illustrator flaw that can allow code execution when a user opens a malicious file.
CVE-2026-50148: Metabase Snowflake Connection RCE
CVE-2026-50148 is a critical Metabase RCE tied to Snowflake connection handling. Learn affected versions, detection steps, and patch guidance.
CVE-2026-53513: Better Auth SSO SSRF in OIDC endpoint handling
CVE-2026-53513 is a critical Better Auth SSRF flaw in @better-auth/sso fixed in 1.6.11. Learn affected versions, detection, and mitigation.
CVE-2026-12375: Backdoored Uncanny Automator Pro update enables unauthenticated admin access
CVE-2026-12375 is a critical supply-chain compromise in Uncanny Automator Pro before 7.3.0.6. Here is impact, detection, and remediation.
CVE-2026-15701: TOTOLINK NR1800X Remote Stack Buffer Overflow
CVE-2026-15701 is a critical TOTOLINK NR1800X router flaw with public exploit availability. Learn affected versions, detection, and mitigation steps.
CVE-2026-56451: Siemens Opcenter X JWT Authentication Bypass
CVE-2026-56451 is a critical Siemens Opcenter X auth bypass via JWT algorithm validation flaws. Affected versions are all releases before V2604.
CVE-2026-57898: Unauthenticated File Write in Eclipse BaSyx
CVE-2026-57898 allows remote attackers to write files via the AAS thumbnail API in MongoDB-backed Eclipse BaSyx deployments.
CVE-2026-62390: Apache Kylin SQL Injection in Catalog Cache Refresh API
CVE-2026-62390 is a critical Apache Kylin SQL injection affecting 4.x through 5.0.3. Upgrade to 5.0.4 and review refresh API exposure.
CVE-2025-6784: Authenticated RCE in WordPress Code Engine Plugin
CVE-2025-6784 is a high-severity authenticated RCE in the WordPress Code Engine plugin affecting versions through 0.3.5.
CVE-2026-1359: Genolve Toolkit WordPress Privilege Escalation
CVE-2026-1359 lets authenticated WordPress contributors modify options in Genolve Toolkit and potentially escalate to admin.
CVE-2026-13756: WP Grid Builder Privilege Escalation
CVE-2026-13756 allows low-privilege WordPress users to escalate to admin in WP Grid Builder through 2.3.3. Upgrade now!
CVE-2026-14480: OpenPLC Runtime v3 Arbitrary File Write
CVE-2026-14480 is a critical OpenPLC v3 flaw that allows authenticated arbitrary file write and possible code execution. Learn impact and fixes.
CVE-2026-61447: PraisonAI prompt injection to remote code execution
CVE-2026-61447 is a critical PraisonAI RCE affecting versions before 1.6.78. Learn impacted versions, detection steps, and patch guidance.
CVE-2026-14894: Unauthenticated file upload in Super Forms WordPress plugin
CVE-2026-14894 is a critical Super Forms WordPress flaw enabling unauthenticated file upload and possible RCE on versions through 6.3.313.
CVE-2026-15378: Blind SSRF and Local File Read Flaw
CVE-2026-15378 is a critical guardrails-detectors flaw enabling blind SSRF and local file reads via crafted XSD input.
CVE-2026-2397: Critical SQL Injection in MobilMen 20T
CVE-2026-2397 is a critical SQL injection in MobilMen 20T affecting v3 through 10072026, with no confirmed patch or active exploitation.
CVE-2026-54769: Langroid Sandbox Escape to RCE
CVE-2026-54769 is a critical Langroid RCE fixed in 0.65.2. Learn affected versions, exploitation status, detection ideas, and patch steps.
CVE-2026-55500: Unauthenticated database export and overwrite in 9Router
CVE-2026-55500 lets attackers export or overwrite the full 9Router database without proper auth. Fixed in version 0.4.80.
CVE-2026-56688: Dell PowerFlex Manager OS command injection
CVE-2026-56688 affects Dell PowerFlex Manager before 5.1.0.1 and can allow root command execution during OS Repository processing.
CVE-2026-12116: Xerte Online Toolkits antivirus path RCE
CVE-2026-12116 is a critical Xerte Online Toolkits RCE tied to antivirus path abuse. Learn affected versions, detection, and mitigation steps.
CVE-2026-14245: miniOrange OTP Verification WordPress Auth Bypass
CVE-2026-14245 is a critical auth bypass in the miniOrange OTP Verification WordPress plugin that can lead to admin takeover.
CVE-2026-4275: Divi Torque Lite CSRF to Arbitrary Plugin Installation
CVE-2026-4275 is a high-severity CSRF flaw in Divi Torque Lite for WordPress that can let attackers install plugins via an admin session.
CVE-2026-54782: CoreWCF SAML Token Validation Vulnerability
CVE-2026-54782 is a critical CoreWCF SAML validation flaw that can enable unauthenticated impersonation in federated bindings.
CVE-2026-5523: Divi Form Builder missing authorization enables account takeover
CVE-2026-5523 is a high-severity Divi Form Builder flaw letting low-privilege WordPress users take over other accounts, including admins.
CVE-2026-59726: Unauthenticated MCP Bridge Access in Ruflo
CVE-2026-59726 is a critical Ruflo flaw exposing unauthenticated MCP endpoints that can lead to container shell access and API key theft.
CVE-2026-12153: Unauthenticated Plugin Installation in WP Learn Manager
CVE-2026-12153 lets unauthenticated attackers install and activate WordPress plugins via WP Learn Manager up to 1.1.8.
CVE-2026-56843: Plesk XML API Authorization Flaw Exposes FTP Credentials
CVE-2026-56843 is a critical Plesk XML API flaw that exposes FTP credentials and enables cross-tenant code execution.
CVE-2026-58480: Unauthenticated File Upload in Blocksy Companion Pro
CVE-2026-58480 is a critical Blocksy Companion Pro flaw enabling unauthenticated file upload and possible WordPress RCE before 2.1.47.
CVE-2026-60102: Horde VFS SMB Command Injection
CVE-2026-60102 is a high severity command injection in Horde VFS SMB handling before 3.0.1. Learn affected versions, detection, and patching.
CVE-2026-8307: Critical SQL Injection in Mediküm Web
CVE-2026-8307 is a critical SQL injection in Mediküm Web with no known patch. Learn affected versions, detection steps, and mitigation actions.
CVE-2026-9701: Eventer WordPress Plugin Vulnerability
CVE-2026-9701 is a critical Eventer WordPress plugin flaw that stores plaintext reset keys, enabling account takeover when chained with data exposure.
CVE-2026-11610: Authenticated Heap Overflow in 389 Directory Server
CVE-2026-11610 is a high severity flaw in 389 Directory Server that allows authenticated users to crash servers via crafted SASL UNBIND.
CVE-2026-13019: Unauthenticated API Access in Esri Portal for ArcGIS
CVE-2026-13019 is a critical unauthenticated API flaw in Esri Portal for ArcGIS 12.1 and earlier. A patch is available.
CVE-2026-34037: Critical Improper Authorization in Coolify
CVE-2026-34037 is a critical Coolify authorization flaw allowing authenticated cross-tenant cloning before 4.0.0-beta.464.
CVE-2026-48277: Adobe ColdFusion RCE Vulnerability
CVE-2026-48277 is a critical ColdFusion RCE affecting 2025 Update 9 and earlier, and 2023 Update 20 and earlier. Patch now.
CVE-2026-53481: Unauthenticated Path Traversal in Dell PowerProtect
CVE-2026-53481 is a critical remote unauthenticated path traversal in Dell PowerProtect Data Domain DD OS. Affected versions and fixes.
CVE-2026-59800: Unauthenticated Command Injection in 9Router
CVE-2026-59800 is a critical 9Router flaw enabling unauthenticated remote command execution before version 0.4.44. Patch urgently.
CVE-2026-14778: Improper Authorization in SourceCodester LMS
CVE-2026-14778 is a high severity IDOR in SourceCodester Online Examination & Learning Management System 1.0 with public exploit details.
CVE-2026-14807: Hard-coded credentials in PROG MIS ERP App
CVE-2026-14807 is a critical PROG MIS ERP App flaw that allows unauthenticated login and database credential exposure. What defenders should do now.
CVE-2026-48316: Adobe ColdFusion RCE Vulnerability
CVE-2026-48316 is a critical Adobe ColdFusion RCE affecting 2025 Update 9 and 2023 Update 20 and earlier. What to patch and how to detect.
CVE-2026-57572: Critical Remote Code Execution in Crawl4AI
CVE-2026-57572 is a critical unauthenticated RCE in Crawl4AI before 0.9.0. Learn affected versions, detection, mitigation, and patching.
CVE-2026-58380: GIMP PNM Parser Buffer Overflow
CVE-2026-58380 is a high severity GIMP PNM parser flaw that can crash GIMP and may enable code execution via a crafted image file.
CVE-2026-14660: SQL Injection in Online Job Portal
CVE-2026-14660 is a high-severity SQL injection in Online Job Portal 1.0. Here is what is affected, how to detect it, and how to mitigate risk.
CVE-2026-14700: SQL Injection in Internship Management System
CVE-2026-14700 is a high-severity SQL injection in Internship Management System 1.0 with public exploit disclosure and no confirmed fix.
CVE-2026-14721: UTT HiPER 1250GW Buffer Overflow
CVE-2026-14721 is a high-severity remote buffer overflow in UTT HiPER 1250GW web management, with public exploit disclosure.
CVE-2026-14734: SQL Injection in SourceCodester System
CVE-2026-14734 is a high-severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 with a public exploit and no confirmed patch.
CVE-2026-14763: Remote SQL Injection in PHP Reservations
CVE-2026-14763 is a remote SQL injection in Hotel and Tourism Reservation in PHP 1.0 with a public PoC and no confirmed fixed version.
CVE-2026-9085: DNS Spoofing Risk in Pardus-Parental-Control
CVE-2026-9085 is a high-severity Pardus-Parental-Control flaw that can enable DNS spoofing. Learn affected versions, detection, and patching.
CVE-2025-71380: Authenticated Command Execution in n8n
CVE-2025-71380 allows authenticated n8n users to run host commands via Execute Command. Learn impact, detection, and mitigation.
CVE-2026-14534: Unsafe Pickle Validation Bypass
CVE-2026-14534 affects Trail of Bits fickling, allowing malicious pickle payloads to bypass safety checks and execute code.
CVE-2026-14622: Missing Authentication in Restaurant-Website-PHP-MySQL
CVE-2026-14622 is a high-severity remote auth bypass in restaurant-website-php-mysql. Learn affected versions, detection steps, and mitigations.
CVE-2026-14637: Remote Deserialization in Ecommerce-CodeIgniter-Bootstrap
CVE-2026-14637 is a high-severity remote deserialization flaw in Ecommerce-CodeIgniter-Bootstrap. Learn affected commits, detection, and patching.
CVE-2026-13768: Gardyn IoT Hub Key Exposure
CVE-2026-13768 is a critical Gardyn firmware flaw exposing an IoT Hub owner key, enabling remote device control and possible network pivoting.
CVE-2026-14459: Pardus Software Argument Injection Vulnerability
CVE-2026-14459 affects pardus-software up to 1.0.4. Learn impact, detection steps, and how to upgrade to the fixed 1.0.5 release.
CVE-2026-14544: HPLIP hpcups Integer Overflow Incomplete Fix
CVE-2026-14544 is a critical HPLIP flaw tied to an incomplete fix, enabling possible code execution via crafted print data.
CVE-2026-14605: Buffer Overflow in RT-Thread CAN Handler
CVE-2026-14605 is a high-severity RT-Thread buffer overflow in ls1c CAN handling, affecting versions through 5.0.2.
CVE-2026-4321: Critical SQL Injection Vulnerability in Destekz
CVE-2026-4321 is a critical SQL injection in Destekz affecting versions through 02062026, with no confirmed patch and no KEV listing.
CVE-2026-9725: Unauthenticated File Deletion in Printcart Plugin
CVE-2026-9725 is a critical Printcart WooCommerce plugin flaw allowing unauthenticated file deletion in versions through 2.5.2.
CVE-2026-13125: GeoVision GeoWebPlayer WebSocket Vulnerability
CVE-2026-13125 is a high severity GeoVision GeoWebPlayer flaw that can let malicious websites access local APIs and capture screens.
CVE-2026-14336: OIDC issuer allowlist bypass in Eclipse CSI PIA
CVE-2026-14336 is a high severity unauthenticated SSRF and token trust bypass in Eclipse CSI PIA OIDC issuer validation.
CVE-2026-44935: Multi-tenant Isolation Flaw in SUSE Rancher Fleet
CVE-2026-44935 is a critical Rancher Fleet tenant isolation flaw that can expose cross-tenant credentials. Affected versions and fixes inside.
CVE-2026-50746: Critical Command Injection in UniFi Connect
CVE-2026-50746 is a critical UniFi Connect flaw affecting 3.4.16 and earlier. Learn impact, detection, and how to upgrade to 3.4.20+.
CVE-2026-57624: Critical Unauthenticated RCE in Blocksy Companion Pro
CVE-2026-57624 is a critical unauthenticated RCE in Blocksy Companion Pro for WordPress affecting up to 2.1.46, fixed in 2.1.47.
CVE-2026-24270: Critical Authentication Bypass in NVIDIA AIStore
CVE-2026-24270 is a critical NVIDIA AIStore auth bypass affecting versions 0 through 4.4, fixed in 4.5. What defenders should patch and monitor.
CVE-2026-50160: Critical unauthenticated mass assignment in Hoppscotch backend
CVE-2026-50160 lets unauthenticated attackers overwrite Hoppscotch secrets during onboarding. Affects 2026.4.1 and earlier.
CVE-2026-54592: Oj Ruby Gem Buffer Overflow DoS
CVE-2026-54592 affects Oj before 3.17.3, enabling a crash via deeply nested JSON and recursive each_child handling.
CVE-2026-57692: Critical Privilege Escalation in LCweb PrivateContent
CVE-2026-57692 is a critical privilege escalation flaw in LCweb PrivateContent affecting versions through 9.9.2. What defenders should do now.
CVE-2026-7840: UltraVNC Repeater Buffer Overflow
CVE-2026-7840 is a critical UltraVNC Repeater flaw enabling pre-auth remote code execution via the embedded HTTP admin server.
CVE-2026-10134: Unauthenticated RCE in IBM Langflow OSS
CVE-2026-10134 is a critical Langflow OSS RCE affecting versions 1.0.0 through 1.9.3, enabling secret theft, persistence, and lateral movement.
CVE-2026-12073: ProfileGrid WordPress Plugin Vulnerability
CVE-2026-12073 is a critical ProfileGrid WordPress plugin flaw enabling unauthenticated admin takeover on versions through 5.9.9.5.
CVE-2026-14162: API Documentation Exposure in Advantech Queuing Management
CVE-2026-14162 exposes API documentation in Advantech Hospital Queuing Management to unauthenticated users. Learn more.
CVE-2026-48276: Critical Adobe ColdFusion RCE
CVE-2026-48276 is a critical Adobe ColdFusion RCE tied to dangerous file uploads affecting 2025.9 and 2023.20 and earlier.
CVE-2026-58302: LinuxCNC rtapi_app Local Privilege Escalation
CVE-2026-58302 is a high severity LinuxCNC local privilege escalation in rtapi_app. Affected versions are before 2.9.9.
CVE-2026-9711: Critical SQL Injection in EventON Plugin
CVE-2026-9711 is a critical unauthenticated SQL injection in EventON for WordPress affecting versions through 5.0.11.
CVE-2026-12856: Command Injection in vscode-java JavaDoc Hovers
CVE-2026-12856 is a high severity vscode-java flaw that can execute VS Code commands via JavaDoc hovers when a user clicks a crafted link.
CVE-2026-13515: Tenda JD12L Buffer Overflow Risk
CVE-2026-13515 impacts Tenda JD12L 16.03.53.23 via /goform/SetPptpServerCfg, enabling remote stack overflow exploitation.
CVE-2026-13539: Wavlink WL-NU516U1-A Guest_ssid Buffer Overflow
CVE-2026-13539 is a remote buffer overflow in Wavlink WL-NU516U1-A firmware M16U1_V240425 with public exploit code and a vendor fix.
CVE-2026-56782: Critical Authentication Bypass in Gorse
CVE-2026-56782 lets unauthenticated attackers dump or overwrite Gorse data before 0.5.10 when admin_api_key is empty.
CVE-2026-57331: Critical File Deletion in Videochat Plugin
CVE-2026-57331 is a critical WordPress plugin file deletion flaw affecting Paid Videochat Turnkey Site versions through 7.4.8.
CVE-2026-10646: Zephyr RTOS DNS Memory Corruption
CVE-2026-10646 is a high-severity Zephyr RTOS DNS memory corruption bug in getaddrinfo(). Learn impact, detection, and mitigation steps.
CVE-2026-13485: SQL Injection in SourceCodester System
CVE-2026-13485 is a high severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 via preview.php.
CVE-2026-13486: SQL Injection in SourceCodester System
CVE-2026-13486 is a high severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 via preview6.php.
CVE-2026-13498: SQL Injection in Password Reset Flow
CVE-2026-13498 is a remote SQL injection in forgotpassword.php via the email parameter, with a public exploit and no confirmed upstream fix.
CVE-2026-58053: Gitea act_runner Container Escape
CVE-2026-58053 lets workflow authors escape Docker-backed Gitea act_runner jobs and gain host root. Detection, mitigation, and risk guidance.
CVE-2026-12415: Critical Privilege Escalation in WordPress Plugin
CVE-2026-12415 is a critical WordPress plugin flaw enabling unauthenticated account takeover in Invoice Generator up to 1.0.0.
CVE-2026-28701: Daktronics Controller Firmware Path Traversal
CVE-2026-28701 is a critical Daktronics controller firmware path traversal flaw affecting VFC-DMP-5000, DMP-5000, and DMP-8000.
CVE-2026-50741: Revive Adserver Fix Bypass
CVE-2026-50741 is a high-severity Revive Adserver fix bypass tied to PHP code injection. What defenders know, how to detect, and what to do now.
CVE-2026-54350: Budibase NoSQL Injection Vulnerability
CVE-2026-54350 is a critical Budibase flaw that can expose or modify backend data in published apps. Affected versions are before 3.39.12.
CVE-2026-56028: Unauthenticated Privilege Escalation in Easy Elements
CVE-2026-56028 is a critical WordPress plugin flaw affecting Easy Elements for Elementor up to 1.4.9 with no auth required.
CVE-2026-57878: GeoVision thttpd Buffer Overflow
CVE-2026-57878 is a critical remote flaw in GeoVision GV-LPC2011 and GV-LPC2211 devices running 1.12 and earlier. What defenders should do now.
CVE-2026-10086: GitLab EE Client-Side Code Execution
CVE-2026-10086 is a high-severity GitLab EE flaw that lets a developer-role user trigger client-side code in another user's session.
CVE-2026-12937: SQL Injection in Tourfic Plugin
CVE-2026-12937 is a high-severity unauthenticated SQL injection in Tourfic for WordPress affecting versions through 2.22.7.
CVE-2026-39938: Critical Unauthenticated LFI in Cacti
CVE-2026-39938 is a critical unauthenticated LFI in Cacti 1.2.30 and earlier. Learn affected versions, detection, and how to patch.
CVE-2026-41120: Critical RCE Vulnerability in Dell Wyse Management Suite
CVE-2026-41120 is a critical Dell Wyse Management Suite RCE affecting versions before 5.5 HF1. What defenders should know and do now.
CVE-2026-54836: SQL Injection in YMC Filter
CVE-2026-54836 is a critical SQL injection flaw in the YMC Filter WordPress plugin through 3.11.5. Here is what defenders should do.
CVE-2026-57700: Critical Arbitrary File Upload Vulnerability
CVE-2026-57700 is a critical arbitrary file upload flaw in OMGF Pro through 5.2.6. What defenders know, how to detect it, and what to do now.
CVE-2026-12416: Unauthenticated Account Takeover in Invoice Generator
CVE-2026-12416 is a critical WordPress plugin flaw enabling unauthenticated password resets and possible admin takeover.
CVE-2026-12485: GeoVision GV-I/O Box 4E DVRSearch Stack Overflow
CVE-2026-12485 is a critical unauthenticated UDP stack overflow in GeoVision GV-I/O Box 4E DVRSearch on port 10001.
CVE-2026-52813: Gogs Path Traversal to RCE
CVE-2026-52813 is a critical Gogs flaw fixed in 0.14.3 that can lead to path traversal, hook overwrite, and remote code execution.
CVE-2026-54588: Critical Account Takeover Vulnerability in Poweradmin
CVE-2026-54588 is a critical Poweradmin flaw that can poison SSO redirect URIs and enable account takeover. Upgrade to 4.2.4 or 4.3.3.
CVE-2026-56121: Critical Remote Code Execution in Feast
CVE-2026-56121 is a critical Feast RCE affecting versions before 0.63.0 via unsafe gRPC deserialization. Patch to 0.63.0 now.
CVE-2026-56237: Authentication Flaw in Capgo
CVE-2026-56237 affects Capgo before 12.128.2, allowing arbitrary API key creation and unauthorized access to protected endpoints.
CVE-2026-48746: Critical Authentication Bypass in vLLM
CVE-2026-48746 is a critical vLLM auth bypass affecting 0.3.0 through before 0.22.0. Learn impact, detection, and patch steps.
CVE-2026-56274: Critical OS Command Injection in FlowiseAI Flowise
CVE-2026-56274 is a critical Flowise RCE affecting versions before 3.1.2. Learn impact, detection, mitigation, and patch guidance.
CVE-2026-10561: Unauthenticated Remote Code Execution in IBM Langflow OSS
CVE-2026-10561 is a critical unauthenticated RCE in IBM Langflow OSS 1.0.0 through 1.9.3. Here is what defenders need to know.
CVE-2026-10789: Autodesk Fusion Desktop MCP Extension Risk
CVE-2026-10789 is a critical Autodesk Fusion Desktop flaw in the MCP extension that may allow code execution via a malicious webpage.
CVE-2026-12778: Local Privilege Escalation in AOMEI Partition Assistant
CVE-2026-12778 is a high severity local privilege escalation in AOMEI Partition Assistant via ampa10.sys raw disk access.
CVE-2026-12806: Remote Buffer Overflow in Edimax BR-6478AC V2
CVE-2026-12806 is a high severity remote buffer overflow in Edimax BR-6478AC V2 firmware 1.23 via formWlSiteSurvey.
CVE-2026-56265: Critical Authentication Bypass in Crawl4AI
CVE-2026-56265 lets attackers forge JWTs against Crawl4AI before 0.8.7. Learn affected versions, detection steps, and exact mitigation.
CVE-2026-5366: Prefect GitRepository Argument Injection RCE
CVE-2026-5366 is a critical Prefect RCE in GitRepository handling. Learn affected versions, exploitation status, detection, and mitigation steps.
CVE-2026-56340: vLLM Multimodal Embeddings Flaw
CVE-2026-56340 affects vLLM 0.10.2 through 0.12.x before 0.13.0, enabling DoS and possible memory corruption when prompt-embeds is enabled.
CVE-2026-11837: Local Privilege Escalation in ansible.posix authorized_key
CVE-2026-11837 is a high-severity local privilege escalation in ansible.posix authorized_key caused by unsafe symlink handling.
CVE-2026-45328: ESP-IDF Out-of-bounds Write Vulnerability
CVE-2026-45328 impacts ESP-IDF 5.5.4 and 6.0. Upgrade to 5.5.5 or 6.0.1 to address a high severity security flaw.
CVE-2026-45552: Critical Authorization Bypass in Roxy-WI
CVE-2026-45552 lets authenticated Roxy-WI users bypass tenant and role checks on /install endpoints, risking cross-server privileged changes.
CVE-2017-20251: WordPress Insert PHP Plugin Vulnerability
CVE-2017-20251 affects WordPress Insert PHP before 3.3.1, enabling unauthenticated PHP execution via the REST API and shortcode injection.
CVE-2026-10520: Ivanti Sentry unauthenticated root RCE
CVE-2026-10520 is a critical Ivanti Sentry command injection flaw enabling unauthenticated root RCE. Affected versions must be upgraded now.
CVE-2026-11616: Privilege Escalation in Events Calendar
CVE-2026-11616 allows low-privilege WordPress users to gain admin rights in Events Calendar for GeoDirectory. Upgrade to 2.3.30.
CVE-2026-44748: SAP NetWeaver ABAP XML Flaw
CVE-2026-44748 is a critical SAP NetWeaver ABAP flaw enabling tampered signed XML acceptance. What defenders know, how to detect, and next steps.
CVE-2026-47938: Critical SSRF Vulnerability in Adobe Campaign Classic
CVE-2026-47938 is a critical Adobe Campaign Classic SSRF flaw that can lead to code execution. See affected versions, detection, and mitigation.
CVE-2026-5067: Critical Memory Corruption in Zephyr RTOS
CVE-2026-5067 is a CVSS 9.8 memory corruption flaw in Zephyr RTOS WebSocket upgrade handling. See which configs are affected, detection steps, and patch guidance.
CVE-2023-54352: Critical RCE in WordPress Seotheme
CVE-2023-54352 is a critical unauthenticated RCE in WordPress Seotheme via arbitrary PHP upload. What to know, detect, and do now.
CVE-2026-11483: SQL Injection in SourceCodester System
CVE-2026-11483 is a high-severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 with public exploit code.
CVE-2026-11504: Tenda CX12L Wi-Fi Schedule Vulnerability
CVE-2026-11504 affects Tenda CX12L 16.03.53.12 via /goform/openSchedWifi, enabling remote stack overflow with public exploit availability.
CVE-2026-25555: Authentication Bypass in OpenBullet2
CVE-2026-25555 lets unauthenticated attackers gain OpenBullet2 admin access via an empty X-Api-Key header. Affected versions include 0.3.2.
CVE-2026-52778: YesWiki Calculator Eval and ReDoS Vulnerability
CVE-2026-52778 affects YesWiki before 4.6.6, enabling ReDoS and possible PHP code execution in the Bazar calculator field.
CVE-2026-11450: Remote Command Injection in GL.iNet GL-MT3000
CVE-2026-11450 is a high-severity remote command injection flaw in GL.iNet GL-MT3000 firmware 4.4.5, fixed in version 4.7.
CVE-2026-11451: Remote Command Injection in GL.iNet GL-MT3000 Firmware
CVE-2026-11451 lets remote attackers inject commands via GL.iNet GL-MT3000 firmware 4.4.5. Upgrade to 4.8.1 now.
CVE-2026-11456: SQL Injection in Chanjet CRM 1.0
CVE-2026-11456 is a remote SQL injection in Chanjet CRM 1.0 with a public exploit and no verified fix version yet.
CVE-2026-11460: Boost Serialization Insecure Deserialization
CVE-2026-11460 affects Boost Serialization up to 1.91, with public exploit details and no patch currently available.
CVE-2026-49494: Comodo Internet Security IPv6 parser kernel DoS
CVE-2026-49494 is a remote IPv6 packet parsing flaw in Comodo Internet Security that can crash Windows systems before firewall rules apply.
CVE-2026-11413: Buffer Overflow in JD Cloud Box AX6600
CVE-2026-11413 is a high-severity remote buffer overflow in JingDong JD Cloud Box AX6600 4.5.3.r4546 with public exploit disclosure.
CVE-2026-11437: SSRF in go-fastdfs-web-go Installation
CVE-2026-11437 is a high severity SSRF in go-fastdfs-web-go up to 1.3.7, with a published exploit and no confirmed fixed version.
CVE-2026-7537: Arbitrary File Upload in MDJM Plugin
CVE-2026-7537 affects MDJM Event Management for WordPress through 1.7.8.3, enabling admin-level arbitrary file upload and possible RCE.
CVE-2026-7654: Admin Columns WordPress Plugin Vulnerability
CVE-2026-7654 is a high-severity Admin Columns flaw that can let Contributor-level users reach RCE. Affected versions include 7.0.18.
CVE-2026-11262: Google Chrome TabStrip use-after-free
CVE-2026-11262 is a high-severity Chrome TabStrip use-after-free fixed in 149.0.7827.53. Here is what defenders need to patch and monitor.
CVE-2026-46389: Critical Authentication Bypass in Defense Unicorns UDS Identity Config
CVE-2026-46389 lets attackers bypass client secret checks in UDS Identity Config. Affected versions 0.11.0 through 0.26.0 should upgrade.
CVE-2026-50256: Stack-Based Buffer Overflow in X.Org X Server
CVE-2026-50256 is a high-severity X.Org buffer overflow. Learn affected versions, detection tips, and patch guidance.
CVE-2026-50593: Graphite Integer Underflow Vulnerability
CVE-2026-50593 affects Graphite before 1.3.15, causing an integer underflow and out-of-bounds write. Upgrade and hunt for crashes now.
CVE-2025-67447: Critical OS Command Injection in Neterbit NW-431F Router
CVE-2025-67447 is a critical command injection flaw in Neterbit NW-431F routers affecting 20241014-IR03 and earlier.
CVE-2026-4104: Critical SQL Injection Vulnerability in TeknoPass
CVE-2026-4104 is a critical TeknoPass SQL injection flaw affecting versions 20210501 through 20260429, with no confirmed fix version yet.
CVE-2026-41860: Missing TLS Verification in BOSH Monitor
CVE-2026-41860 is a high severity BOSH flaw that lets local MITM attackers intercept credentials or redirect UAA token requests.
CVE-2026-43986: Critical SSRF Vulnerability in Tautulli
CVE-2026-43986 is a critical SSRF flaw in Tautulli before 2.17.1 that can turn a guest action into unauthenticated server-side fetches.
CVE-2026-10694: File Inclusion in SourceCodester System
CVE-2026-10694 is a high severity file inclusion flaw in SourceCodester Online Food Ordering System 2.0 with public exploit material.
CVE-2026-35075: Hard-coded password exposure in MBS UGW web GUI
CVE-2026-35075 is a critical unauthenticated flaw in MBS UGW web GUI that can expose a hard-coded password and enable full device access.
CVE-2026-42061: Local Privilege Escalation in Acronis DeviceLock DLP
CVE-2026-42061 is a local privilege escalation flaw in Acronis DeviceLock DLP for Windows before build 9.0.15051.93227.
CVE-2026-5076: ARMember Premium Password Reset Key Exposure
CVE-2026-5076 is a critical ARMember Premium flaw enabling account takeover via plaintext reset keys stored through version 7.3.1.
CVE-2026-7312: Progress Sitefinity credential exposure
CVE-2026-7312 is a critical Sitefinity flaw exposing Insight credentials to remote attackers. Affected versions and mitigation steps.
CVE-2026-10206: D-Link DI-8400 Remote Buffer Overflow
CVE-2026-10206 is a high-severity D-Link DI-8400 remote overflow with public exploit availability and no confirmed fixed version.
CVE-2026-40965: EC Private Key Exposure in Cloud Foundry UAA
CVE-2026-40965 exposes EC private keys via Cloud Foundry UAA /token_keys. Learn affected versions, detection, mitigation, and patch guidance.
CVE-2026-45131: GitHub Actions Vulnerability in CloudPirates
CVE-2026-45131 is a critical GitHub Actions flaw in CloudPirates Helm Charts that can expose secrets from forked pull requests.
CVE-2026-7858: Unauthenticated RCE in Teamwork Cloud
CVE-2026-7858 is a critical unauthenticated RCE in Teamwork Cloud and Magic Collaboration Studio affecting 2022x through 2026x releases.
CVE-2026-10158: TRENDnet TEW-432BRP Stack Overflow
CVE-2026-10158 is a high-severity remote stack overflow in TRENDnet TEW-432BRP 3.10B20. No patch exists; replace or isolate the device.
CVE-2026-10163: Buffer Overflow in Edimax Router
CVE-2026-10163 is a high-severity buffer overflow in Edimax BR-6478AC V2 firmware 1.23. Public exploit disclosure exists; fix version is unknown.
CVE-2026-10179: TRENDnet TEW-432BRP Buffer Overflow
CVE-2026-10179 is a high-severity buffer overflow in TRENDnet TEW-432BRP 3.10B20 with a public PoC and no vendor fix.
CVE-2026-10187: TOTOLINK N300RH Web Management Buffer Overflow
CVE-2026-10187 is a critical remote buffer overflow in TOTOLINK N300RH firmware. Affected version, exploitation status, detection, and mitigation.
CVE-2026-10192: Tenda W12 Buffer Overflow Vulnerability
CVE-2026-10192 is a stack-based buffer overflow in Tenda W12 3.0.0.7(4763). Public exploit material exists; patch status is unverified.
CVE-2018-25412: Delta Sql File Upload Vulnerability
Exploring CVE-2018-25412, a critical file upload flaw in Delta Sql 1.8.2 leading to RCE.
CVE-2026-10110: SQL Injection in Student Details Management System
CVE-2026-10110 is a high-severity SQL injection in Student Details Management System 1.0 via /index.php roll parameter.
CVE-2026-10126: Edimax BR-6478AC Buffer Overflow
CVE-2026-10126 is a high-severity buffer overflow in Edimax BR-6478AC 1.23. Here’s what defenders know, how to detect it, and what to do now.
CVE-2026-42960: Unbound DNS Cache Poisoning Vulnerability
CVE-2026-42960 is a critical Unbound cache poisoning flaw affecting versions through 1.25.0. Upgrade to 1.25.1 or apply the vendor patch.
CVE-2026-7465: Authenticated RCE in Spectra Gutenberg Blocks
CVE-2026-7465 is a high-severity authenticated RCE in the Spectra Gutenberg Blocks WordPress plugin affecting versions through 2.19.25.
CVE-2025-29635: D-Link DIR-823X Command Injection (RCE)
CVE-2025-29635 in D-Link DIR-823X firmware 240126/240802 is a command injection RCE via /goform/set_prohibiting. KEV-listed; act now.
CVE-2026-0300: Unauthenticated RCE via PAN-OS Buffer Overflow
CVE-2026-0300 is a critical PAN-OS vulnerability allowing unauthenticated root RCE via buffer overflow in the User-ID Authentication Portal.
CVE-2026-31431: Linux Kernel AEAD Bug Fix
Guide to CVE-2026-31431 (Linux kernel algif_aead). KEV-listed, exploited in the wild. Detection and mitigation steps.
CVE-2026-41940: Authentication Bypass in cPanel & WHM
Explainer for CVE-2026-41940 (CVSS 9.8): cPanel & WHM auth bypass exploited in the wild. Detection, mitigation, and patch guidance.
CVE-2026-42208: Critical SQL Injection in BerriAI LiteLLM
CVE-2026-42208 is a critical LiteLLM SQLi (CVSS 9.8) exploited in the wild. Affects 1.81.16–1.83.6; fixed in 1.83.7.
CVE-2026-42897: Exchange Server XSS Spoofing Vulnerability
Guide for CVE-2026-42897 (Exchange Server XSS/spoofing). KEV-listed, exploited in the wild. Detection and mitigation steps.
CVE-2026-6973: Ivanti EPMM RCE via Input Validation
CVE-2026-6973 is a high-severity Ivanti EPMM flaw enabling authenticated admin RCE. Upgrade to 12.6.1.1/12.7.0.1/12.8.0.1.
CVE-2026-34253: Mastodon Rate-Limit Bypass
CVE-2026-34253 is a high-severity Mastodon flaw that can bypass rate limits via HTTP parser discrepancies. Affected versions and fixes inside.
CVE-2026-20182: Cisco Smart Licensing Utility flaw
CVE-2026-20182 is a Cisco Smart Licensing Utility flaw that may expose sensitive data via a hardcoded cryptographic key.