
CVE explainers
New CVEs explained in plain English: severity, who is affected, patch guidance, and a step-by-step response runbook for each one.
337 entries
CVE-2022-4995: Unauthenticated File Upload in Weaver E-cology
CVE-2022-4995 is a critical unauthenticated file upload in Weaver E-cology before 10.52 that can lead to JSP webshell RCE.
CVE-2026-11976: MonsterInsights Pro Supply-Chain Compromise
CVE-2026-11976 is a critical MonsterInsights Pro supply-chain compromise affecting versions 10.2.0 and 10.2.2 via a backdoored update path.
CVE-2026-14364: TrueBooker WordPress Plugin Vulnerability
CVE-2026-14364 is a critical TrueBooker WordPress flaw allowing unauthenticated password resets and possible admin takeover.
CVE-2026-14365: Unauthenticated Password Change in TrueBooker Plugin
CVE-2026-14365 is a critical auth bypass in the TrueBooker WordPress plugin that can let attackers reset arbitrary user passwords.
CVE-2026-9169: DLL Search Order Hijacking in Arena SDK
CVE-2026-9169 is a high severity local code execution flaw in LUCID Arena SDK for Windows. Affected users should upgrade to 1.0.85.11.
CVE-2026-15991: Authenticated arbitrary file deletion in WordPress File Manager
CVE-2026-15991 affects WordPress File Manager 6.0-6.9, allowing subscriber-level users to read or delete files and risk site takeover.
CVE-2026-5430: WSO2 JWT Authentication Bypass
CVE-2026-5430 is a critical WSO2 JWT auth bypass that can enable unauthorized access and account takeover. See affected versions and mitigations.
CVE-2026-55978: SecureAge CatchPulse Access Control Flaw
CVE-2026-55978 is a high severity SecureAge CatchPulse flaw allowing local policy bypass via a kernel filter port. Patch exists, versions unclear.
CVE-2026-67863: open62541 server-side use-after-free denial of service
CVE-2026-67863 is a high-severity open62541 use-after-free in 1.5.5 that can let remote attackers crash vulnerable OPC UA servers.
CVE-2026-10090: Red Hat ACM Application Subscription Escalation
CVE-2026-10090 allows namespace editors in Red Hat ACM to escalate to cluster-admin via Subscription abuse. Upgrade to 2.13.9.
CVE-2026-45100: OpenSIPS Buffer Overflow Vulnerability
CVE-2026-45100 is a critical OpenSIPS buffer overflow in {s.b64encode}, affecting 3.4.0-beta through 3.6.5 and 4.0.0-beta.
CVE-2026-48168: PraisonAI GitHub Actions Command Injection
CVE-2026-48168 is a critical PraisonAI workflow command injection flaw fixed in 4.6.40 that can enable repository compromise.
CVE-2026-71268: OpenPLC Runtime v3 arbitrary file write leading to RCE
CVE-2026-71268 is a critical OpenPLC Runtime v3 path traversal flaw enabling arbitrary file write and possible remote code execution.
CVE-2026-7329: Progress MarkLogic Server Privilege Escalation
CVE-2026-7329 is a critical MarkLogic Server privilege escalation flaw in REST query interfaces. Affected versions should upgrade now.
CVE-2026-9273: Password Reset Link Poisoning in Kadence Memberships
CVE-2026-9273 is a critical WordPress plugin flaw enabling unauthenticated password reset link poisoning and account takeover.
CVE-2025-29296: H3C /api/esps Command Injection
CVE-2025-29296 is a critical H3C command injection flaw in /api/esps that can lead to unauthenticated root RCE on affected devices.
CVE-2026-14175: Critical Unrestricted File Upload in HUMANIST
CVE-2026-14175 is a critical file upload flaw in HUMANIST Digital Human Resources affecting 26.0 before 26.1. Patch to 26.1.
CVE-2026-15721: Critical SQL Injection in HUMANIST HR
CVE-2026-15721 is a critical SQL injection flaw in HUMANIST Digital Human Resources 26.0. Learn affected versions, detection, and upgrade guidance.
CVE-2026-42169: GIMP Heap Buffer Overflows in APNG and DDS
CVE-2026-42169 is a GIMP heap overflow bug in APNG and DDS parsing that may allow code execution when a user opens a crafted image.
CVE-2026-48323: Adobe Campaign Classic template engine RCE
CVE-2026-48323 is a critical Adobe Campaign Classic RCE. Learn impact, detection, exploitation status, and what to do while version data remains unconfirmed.
CVE-2026-61514: Puwell IP Camera authentication bypass over TCP/23456
CVE-2026-61514 is a critical unauthenticated access flaw in Puwell IP Camera firmware 2.x through 4.x on TCP port 23456.
CVE-2026-18602: Unauthenticated command injection in GL.iNet GL-MT3000
CVE-2026-18602 is a critical unauthenticated RCE in GL.iNet GL-MT3000 up to 4.4.5 via /cgi-bin/glc ovpn-client handling.
CVE-2026-21548: UNISOC nr modem improper input validation DoS
CVE-2026-21548 is a high severity UNISOC nr modem flaw enabling remote denial of service on affected Android 13 to 16 devices.
CVE-2026-3245: Canon PRISMAproduction RCE Risk
CVE-2026-3245 is a high-severity deserialization flaw in Canon PRISMAproduction 6.5 or earlier that may allow adjacent-network RCE.
CVE-2026-69083: Critical unauthenticated SQL injection in SiYuan
CVE-2026-69083 is a critical SQL injection in SiYuan before 3.7.3 that can allow unauthenticated database access under exposed token conditions.
CVE-2026-69084: Critical SQL Injection in SiYuan API
CVE-2026-69084 is a critical SQL injection in SiYuan <= 3.7.2 that can expose and modify cleartext notebooks. Fixed in 3.7.3.
CVE-2026-10848: Zephyr RTOS OCPP Client Parser Issue
CVE-2026-10848 is a Zephyr OCPP 1.6 client parsing flaw that can cause out-of-bounds memory access via malicious websocket RPC frames.
CVE-2026-65321: PyAthena SQL Injection Flaw
CVE-2026-65321 is a critical SQL injection in PyAthena fixed in 3.35.4. Upgrade now to secure your applications.
CVE-2026-8457: WooCommerce Social Login Authentication Bypass
CVE-2026-8457 lets attackers bypass login in WooCommerce Social Login through forged Apple tokens, enabling account takeover.
CVE-2026-15964: Unauthenticated Password Reset in Single Sign On For TNG
CVE-2026-15964 is a critical WordPress plugin flaw enabling unauthenticated password resets and possible admin takeover.
CVE-2026-16635: Pronamic Pay Gravity Forms Privilege Escalation
CVE-2026-16635 is a high-severity Pronamic Pay flaw that can let low-privilege WordPress users escalate privileges via Gravity Forms.
CVE-2026-3141: Unauthenticated file deletion in FormGent WordPress plugin
CVE-2026-3141 is a critical FormGent WordPress flaw enabling unauthenticated file deletion and possible wp-config.php removal.
CVE-2026-34641: Adobe Premiere Pro Out-of-Bounds Write Vulnerability
CVE-2026-34641 is a high-severity Adobe Premiere Pro flaw triggered by a malicious file. Learn about detection and patching.
CVE-2026-67308: Wazuh Workflows Shell Injection
CVE-2026-67308 is a critical Wazuh workflows shell injection flaw enabling command execution and secret theft through crafted pull requests.
CVE-2026-17561: Critical code injection in Logsign SIEM
CVE-2026-17561 is a critical Logsign SIEM code injection flaw affecting versions before 6.4.108. Here is what defenders need to know.
CVE-2026-17566: pgAdmin 4 Import/Export Command Injection Risk
CVE-2026-17566 is a critical pgAdmin 4 flaw in Import/Export Data that can let authenticated users break psql command context.
CVE-2026-18452: Hard-coded API key in Rich Source DMS+
CVE-2026-18452 is a critical hard-coded credentials flaw in Rich Source DMS+ that may allow unauthenticated remote takeover.
CVE-2026-52855: Pterodactyl Wings Template Vulnerability
CVE-2026-52855 affects Pterodactyl Wings before 1.12.3, allowing low-privileged users to disclose daemon tokens and registry config.
CVE-2026-63223: CodeIgniter4 File Upload Vulnerability
CVE-2026-63223 is a critical CodeIgniter4 upload validation flaw fixed in 4.7.4 that can lead to executable file uploads and possible RCE.
CVE-2026-66421: OpenClaw Dashboard stored XSS via agent transcript messages
CVE-2026-66421 is a critical stored XSS in OpenClaw Dashboard that can let unauthenticated attackers run JavaScript in admin sessions.
CVE-2026-13435: IBM Langflow OSS PythonREPL Sandbox Bypass
CVE-2026-13435 is a critical IBM Langflow OSS sandbox bypass that can expose secrets and enable token forgery in affected versions.
CVE-2026-15435: IBM App Connect Enterprise arbitrary file write
CVE-2026-15435 is a critical IBM App Connect flaw enabling remote arbitrary file write via path traversal in crafted URL requests.
CVE-2026-48449: Adobe Campaign Classic Flaw Leads to Code Execution
CVE-2026-48449 is a critical Adobe Campaign Classic flaw with RCE impact. What is known, how to detect risk, and how to patch safely.
CVE-2026-58046: Blind SQL Injection in Plesk XML-RPC API
CVE-2026-58046 is a critical Plesk XML-RPC API SQL injection flaw affecting Plesk Obsidian 18.x before fixed releases.
CVE-2026-59309: VMware vCenter Authentication Bypass
CVE-2026-59309 is a critical VMware vCenter authentication bypass. Learn impact, affected products, detection ideas, and patch guidance.
CVE-2026-67595: Malicious JavaScript in VaahCMS OTP Email Template
CVE-2026-67595 affects VaahCMS 2.0.0 through 2.3.4 with embedded malicious JavaScript in OTP email templates. Patch immediately.
CVE-2026-16326: HashiCorp consul-mcp-server Token Isolation Flaw
CVE-2026-16326 affects consul-mcp-server 0.1.0 to 0.1.3, allowing cross-client Consul token reuse in stateless mode. Fixed in 0.1.4.
CVE-2026-18072: Hardcoded backdoor enables admin takeover in WordPress ARVE plugin
CVE-2026-18072 is a critical auth bypass in the WordPress ARVE plugin that can let attackers log in as admin. Impact, detection, and fixes.
CVE-2026-33267: Apache Traffic Server Input Validation Flaw
CVE-2026-33267 is a critical Apache Traffic Server flaw affecting versions 9.2.0-9.2.14 and 10.1.0-10.1.3. Upgrade to 9.2.15 or 10.1.4.
CVE-2026-54658: Critical SQL Injection in Hypequery
CVE-2026-54658 is a critical SQL injection flaw in @hypequery/clickhouse before 2.0.2. Learn affected versions, detection, and patching steps.
CVE-2026-54735: Prebid Server SSRF in Bidder Adapter URL Handling
CVE-2026-54735 is a critical Prebid Server SSRF affecting versions before 4.4.0. Learn impact, detection steps, and how to patch now.
CVE-2026-58162: Apache Traffic Server certifier plugin flaw
CVE-2026-58162 is a critical Apache Traffic Server certifier plugin flaw tied to attacker-controlled SNI. Affected versions and fixes inside.
CVE-2026-11756: Unauthenticated RCE in 3DEXPERIENCE Station Launcher App
CVE-2026-11756 is a critical unauthenticated RCE in Dassault Systemes 3DEXPERIENCE Station Launcher App affecting R2023x through R2026x.
CVE-2026-16462: SQL Injection in Weidmüller PROCON-WEB SCADA
CVE-2026-16462 is a critical unauthenticated SQL injection in Weidmüller PROCON-WEB SCADA via GetGridData.
CVE-2026-16498: Cross-tenant Credential Reuse in HashiCorp
CVE-2026-16498 is a critical token reuse flaw in terraform-mcp-server fixed in 1.1.0. Learn affected versions, detection, and mitigation.
CVE-2026-17524: zip-lib Directory Traversal Vulnerability
CVE-2026-17524 affects zip-lib before 1.1.0, enabling directory traversal during ZIP extraction via cached path validation logic.
CVE-2026-61953: Unauthenticated SSRF in Simple Link Directory Pro
CVE-2026-61953 is an unauthenticated SSRF in Simple Link Directory Pro for WordPress affecting versions up to 15.0.6.
CVE-2026-66713: Apache Axis2/Java Tomcat Tribes deserialization RCE
CVE-2026-66713 is a critical Apache Axis2/Java deserialization flaw enabling remote code execution when Tomcat Tribes clustering is enabled.
CVE-2026-14837: Lenze SSH Signature Verification Bypass
CVE-2026-14837 affects multiple Lenze products via improper SSH enablement signature verification, risking admin access and full compromise.
CVE-2026-16812: VeloCloud Orchestrator on-prem exposure
CVE-2026-16812 is a critical VeloCloud Orchestrator flaw with active exploitation and potential full orchestrator compromise.
CVE-2026-48030: Authenticated Command Injection in Pheditor
CVE-2026-48030 is a critical authenticated RCE in Pheditor 2.0.1 through 2.0.3, fixed in 2.0.4. Here's impact, detection, and patching.
CVE-2026-61511: Unauthenticated vBulletin eval injection RCE
CVE-2026-61511 is a critical vBulletin RCE affecting 5.x through 5.7.5 and 6.x through 6.2.1 via unauthenticated template rendering.
CVE-2026-15962: Fluent Forms Pro Add On Pack PHP Object Injection
CVE-2026-15962 is a high-severity PHP object injection flaw in Fluent Forms Pro Add On Pack affecting versions through 6.2.6.
CVE-2026-17497: NoteGen Tauri Shell Exposure Leads to Remote Code Execution
CVE-2026-17497 is a high severity NoteGen RCE fixed in 0.32.0. Learn affected versions, detection steps, and mitigation guidance.
CVE-2026-57989: Microsoft Edge origin validation error information disclosure
CVE-2026-57989 is a Microsoft Edge origin validation flaw causing network-based information disclosure. What defenders know and what to patch.
CVE-2026-63720: datamodel-code-generator Code Injection
CVE-2026-63720 is a high-severity RCE issue in datamodel-code-generator before 0.70.0 triggered by malicious schema input.
CVE-2026-10818: Unauthenticated File Upload in WPForms Pro
CVE-2026-10818 is a high-severity WPForms Pro flaw enabling unauthenticated arbitrary file upload and possible RCE on WordPress sites.
CVE-2026-60134: Weintek cMT3092X Cookie Manipulation Vulnerability
CVE-2026-60134 affects Weintek cMT3092X and EasyWeb V2, allowing privilege escalation via cookie manipulation. Versions and mitigations inside.
CVE-2026-10033: Unauthenticated Authorization Bypass in EventON Action User
CVE-2026-10033 lets unauthenticated attackers change non-admin capabilities in EventON Action User through 2.5.14. Patch to 2.5.15.
CVE-2026-15704: Authorization Bypass in Eclipse BaSyx Go Components
CVE-2026-15704 is a critical BaSyx Go Components ABAC bypass fixed in 1.0.1. Learn affected versions, detection steps, and mitigation.
CVE-2026-16870: Snowflake libsnowflakeclient RCE and Credential Exfiltration Flaws
CVE-2026-16870 affects Snowflake libsnowflakeclient before 2.9.2, enabling possible RCE, memory corruption, and credential exfiltration.
CVE-2026-42933: OT Segmentation Bypass in Panduit IntraVUE
CVE-2026-42933 is a critical Panduit IntraVUE flaw that may let attackers proxy through the product and bypass OT segmentation.
CVE-2026-56163: Azure Kubernetes Service Missing Authentication Elevation of Privilege
CVE-2026-56163 is a critical AKS elevation of privilege flaw caused by missing authentication. What is known, detection steps, and mitigation guidance.
CVE-2026-62835: Azure Portal Authorization Flaw
CVE-2026-62835 is a high-severity Azure Portal flaw due to improper authorization. Learn what defenders should do now.
CVE-2026-14282: Unauthenticated arbitrary file upload in rtCamp GoDAM
CVE-2026-14282 is a critical GoDAM WordPress plugin file upload flaw affecting versions through 1.12.2, with possible RCE impact.
CVE-2026-15074: @fastify/static Route Guard Bypass
CVE-2026-15074 affects @fastify/static through 10.1.0, allowing route guard bypass inside the static root. Upgrade to 10.1.1.
CVE-2026-46512: Frogman Dialplan Code Injection
CVE-2026-46512 is a critical Frogman code injection flaw fixed in 1.6.2 that can let low-privilege users inject Asterisk directives.
CVE-2026-47668: Critical DbGate RCE Vulnerability
CVE-2026-47668 is a critical DbGate RCE in dbgate-serve up to 7.1.8. Learn affected versions, exploitation status, detection, and patching.
CVE-2026-50522: SharePoint Deserialization RCE Under Active Exploitation
CVE-2026-50522 is a critical SharePoint deserialization flaw (CVSS 9.8) under active exploitation, letting attackers steal machine keys after a public PoC.
CVE-2026-59555: Unauthenticated Arbitrary File Deletion
CVE-2026-59555 is a critical unauthenticated arbitrary file deletion flaw in Participants Database up to 2.7.8.3, fixed in 2.7.8.4.
CVE-2026-63030: "wp2shell" WordPress Core RCE Chain, Now on CISA KEV
CVE-2026-63030 chains with CVE-2026-60137 for unauthenticated RCE in WordPress Core. Both are on CISA's KEV catalog with a July 24, 2026 patch deadline.
CVE-2026-65687: Bold Reports File Read Vulnerability
CVE-2026-65687 is a critical unauthenticated file read flaw in Bold Reports Standalone Report Designer before 14.1.12.
CVE-2026-16242: HyperShift Konnectivity Proxy Vulnerability
CVE-2026-16242 affects HyperShift Konnectivity listener auth, allowing rogue agent joins and possible traffic interception.
CVE-2026-44359: Meshtastic GitHub Actions Supply Chain Flaw
CVE-2026-44359 is a critical Meshtastic CI flaw that exposed secrets and elevated GitHub token access via untrusted pull request workflow execution.
CVE-2026-10130: FalkorDB QueryWeaver Authentication Bypass
CVE-2026-10130 is a high severity QueryWeaver auth bypass that can issue victim session tokens from a signup request.
CVE-2026-12484: Keras Unsafe Deserialization Vulnerability
CVE-2026-12484 is a high-severity Keras unsafe deserialization flaw in version 3.15.0 that can lead to arbitrary code execution.
CVE-2026-16209: Gerapy Project Upload Endpoint Vulnerability
CVE-2026-16209 is a high severity Gerapy auth bypass affecting versions up to 0.9.13, with public exploit disclosure and a patch commit available.
CVE-2026-16221: fast-uri Host Confusion Vulnerability
CVE-2026-16221 is a fast-uri host confusion flaw that can bypass SSRF and host validation in Node.js apps. Fixed in 2.4.3, 3.1.4, and 4.1.1.
CVE-2026-16227: SQL Injection in SourceCodester Timetabling System
CVE-2026-16227 is a high severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 via edit_subject.php ID.
CVE-2026-16117: Fastify http-proxy Prefix Escape
CVE-2026-16117 is a critical Fastify http-proxy flaw allowing prefix rewrite bypass via encoded paths. Upgrade to 11.6.0.
CVE-2026-47865: Authentication Bypass in VMware Avi Load Balancer
CVE-2026-47865 is a critical VMware Avi Load Balancer auth bypass affecting control-plane access. Review affected versions, detection, and fixes.
CVE-2026-47871: VMware Avi Load Balancer Directory Traversal
CVE-2026-47871 is a high severity VMware Avi Load Balancer directory traversal flaw affecting multiple branches. Fixes are available.
CVE-2026-49485: HAPI FHIR FHIRPathEngine ReDoS Vulnerability
CVE-2026-49485 is a high severity HAPI FHIR ReDoS flaw that can exhaust CPU via crafted regex input. Fixed in 6.9.9 and 6.9.4.2.
CVE-2026-53994: ProFTPD mod_sftp Heap Buffer Overflow
CVE-2026-53994 is a high severity ProFTPD mod_sftp flaw enabling authenticated SFTP DoS and possible memory corruption.
CVE-2024-23564: HCL Aftermarket EPC Password Recovery Flaw
CVE-2024-23564 is a critical HCL Aftermarket EPC flaw that may let invalid users redirect password emails. What to know, detect, and do.
CVE-2026-14956: Bricksforge WordPress Plugin Vulnerability
CVE-2026-14956 is a critical Bricksforge WordPress flaw that can let unauthenticated attackers create admin accounts on exposed sites.
CVE-2026-15982: Unauthenticated Privilege Escalation in Aimogen Pro / Aiomatic
CVE-2026-15982 is a critical WordPress plugin flaw in Aimogen Pro / Aiomatic allowing unauthenticated admin creation. Patch to 2.8.5.
CVE-2026-62241: Hard-Coded JWT Secret Enables Session Forgery
CVE-2026-62241 affects clawvet apps/api before 0.7.5, allowing unauthenticated session forgery and exposure of user email and API keys.
CVE-2026-7189: Proliz's OBS Sensitive Information Exposure Vulnerability
CVE-2026-7189 affects Proliz's OBS before v3.6.0, exposing sensitive data over the network. Learn impact, detection, and patch steps.
CVE-2026-9135: IBM Langflow OSS ToolGuard Code Injection Bypass
CVE-2026-9135 is a critical Langflow OSS code injection flaw that can bypass custom component restrictions and execute Python server-side.
CVE-2023-49899: Unauthenticated Remote Command Execution Risk
CVE-2023-49899 is a critical unauthenticated RCE. What is known, what is missing, and how defenders should detect and mitigate risk.
CVE-2026-13741: Digits WordPress Plugin Privilege Escalation
CVE-2026-13741 allows authenticated users to escalate to admin in vulnerable Digits WordPress plugin installs under specific configurations.
CVE-2026-15013: miniOrange WordPress SAML SSO Bypass
CVE-2026-15013 is a critical auth bypass in miniOrange SAML SSO for WordPress. Affected sites should upgrade from 5.4.3 to 5.4.4.
CVE-2026-1609: Keycloak Disabled Users Can Obtain Tokens
CVE-2026-1609 is a Keycloak access control flaw fixed in 26.5.3 that can let disabled users obtain tokens through JWT authorization grant.
CVE-2026-45336: HireFlow Authentication Bypass via Hard-Coded Flask Secret
CVE-2026-45336 is a critical HireFlow auth bypass in versions 1.2 and earlier. Learn affected versions, detection steps, and mitigation.
CVE-2026-45695: Unauthenticated RCE in Kopia via SSH ProxyCommand Injection
CVE-2026-45695 is a critical Kopia RCE in passwordless server mode. Learn affected versions, detection steps, exploitation status, and fixes.
CVE-2026-15804: Authenticated SQL Injection in MetaGuru HCM
CVE-2026-15804 is a high severity authenticated SQL injection in MetaGuru HCM. Learn impact, detection, mitigation, and patch status.
CVE-2026-48334: Adobe Illustrator Improper Input Validation
CVE-2026-48334 is a critical Adobe Illustrator flaw that can allow code execution when a user opens a malicious file.
CVE-2026-50148: Metabase Snowflake Connection RCE
CVE-2026-50148 is a critical Metabase RCE tied to Snowflake connection handling. Learn affected versions, detection steps, and patch guidance.
CVE-2026-53513: Better Auth SSO SSRF in OIDC endpoint handling
CVE-2026-53513 is a critical Better Auth SSRF flaw in @better-auth/sso fixed in 1.6.11. Learn affected versions, detection, and mitigation.
CVE-2026-56699: Wazuh Manager NDJSON Injection Vulnerability
CVE-2026-56699 is a critical Wazuh Manager flaw allowing enrolled agents to inject OpenSearch bulk actions before 5.0.0-beta3.
CVE-2026-12375: Backdoored Uncanny Automator Pro update enables unauthenticated admin access
CVE-2026-12375 is a critical supply-chain compromise in Uncanny Automator Pro before 7.3.0.6. Here is impact, detection, and remediation.
CVE-2026-15701: TOTOLINK NR1800X Remote Stack Buffer Overflow
CVE-2026-15701 is a critical TOTOLINK NR1800X router flaw with public exploit availability. Learn affected versions, detection, and mitigation steps.
CVE-2026-56451: Siemens Opcenter X JWT Authentication Bypass
CVE-2026-56451 is a critical Siemens Opcenter X auth bypass via JWT algorithm validation flaws. Affected versions are all releases before V2604.
CVE-2026-57898: Unauthenticated File Write in Eclipse BaSyx
CVE-2026-57898 allows remote attackers to write files via the AAS thumbnail API in MongoDB-backed Eclipse BaSyx deployments.
CVE-2026-62390: Apache Kylin SQL Injection in Catalog Cache Refresh API
CVE-2026-62390 is a critical Apache Kylin SQL injection affecting 4.x through 5.0.3. Upgrade to 5.0.4 and review refresh API exposure.
CVE-2025-6784: Authenticated RCE in WordPress Code Engine Plugin
CVE-2025-6784 is a high-severity authenticated RCE in the WordPress Code Engine plugin affecting versions through 0.3.5.
CVE-2026-1359: Genolve Toolkit WordPress Privilege Escalation
CVE-2026-1359 lets authenticated WordPress contributors modify options in Genolve Toolkit and potentially escalate to admin.
CVE-2026-13756: WP Grid Builder Privilege Escalation
CVE-2026-13756 allows low-privilege WordPress users to escalate to admin in WP Grid Builder through 2.3.3. Upgrade now!
CVE-2026-14480: OpenPLC Runtime v3 Arbitrary File Write
CVE-2026-14480 is a critical OpenPLC v3 flaw that allows authenticated arbitrary file write and possible code execution. Learn impact and fixes.
CVE-2026-61447: PraisonAI prompt injection to remote code execution
CVE-2026-61447 is a critical PraisonAI RCE affecting versions before 1.6.78. Learn impacted versions, detection steps, and patch guidance.
CVE-2026-14894: Unauthenticated file upload in Super Forms WordPress plugin
CVE-2026-14894 is a critical Super Forms WordPress flaw enabling unauthenticated file upload and possible RCE on versions through 6.3.313.
CVE-2026-15378: Blind SSRF and Local File Read Flaw
CVE-2026-15378 is a critical guardrails-detectors flaw enabling blind SSRF and local file reads via crafted XSD input.
CVE-2026-2397: Critical SQL Injection in MobilMen 20T
CVE-2026-2397 is a critical SQL injection in MobilMen 20T affecting v3 through 10072026, with no confirmed patch or active exploitation.
CVE-2026-54769: Langroid Sandbox Escape to RCE
CVE-2026-54769 is a critical Langroid RCE fixed in 0.65.2. Learn affected versions, exploitation status, detection ideas, and patch steps.
CVE-2026-55500: Unauthenticated database export and overwrite in 9Router
CVE-2026-55500 lets attackers export or overwrite the full 9Router database without proper auth. Fixed in version 0.4.80.
CVE-2026-56688: Dell PowerFlex Manager OS command injection
CVE-2026-56688 affects Dell PowerFlex Manager before 5.1.0.1 and can allow root command execution during OS Repository processing.
CVE-2026-12116: Xerte Online Toolkits antivirus path RCE
CVE-2026-12116 is a critical Xerte Online Toolkits RCE tied to antivirus path abuse. Learn affected versions, detection, and mitigation steps.
CVE-2026-14245: miniOrange OTP Verification WordPress Auth Bypass
CVE-2026-14245 is a critical auth bypass in the miniOrange OTP Verification WordPress plugin that can lead to admin takeover.
CVE-2026-4275: Divi Torque Lite CSRF to Arbitrary Plugin Installation
CVE-2026-4275 is a high-severity CSRF flaw in Divi Torque Lite for WordPress that can let attackers install plugins via an admin session.
CVE-2026-54782: CoreWCF SAML Token Validation Vulnerability
CVE-2026-54782 is a critical CoreWCF SAML validation flaw that can enable unauthenticated impersonation in federated bindings.
CVE-2026-5523: Divi Form Builder missing authorization enables account takeover
CVE-2026-5523 is a high-severity Divi Form Builder flaw letting low-privilege WordPress users take over other accounts, including admins.
CVE-2026-59726: Unauthenticated MCP Bridge Access in Ruflo
CVE-2026-59726 is a critical Ruflo flaw exposing unauthenticated MCP endpoints that can lead to container shell access and API key theft.
CVE-2026-12153: Unauthenticated Plugin Installation in WP Learn Manager
CVE-2026-12153 lets unauthenticated attackers install and activate WordPress plugins via WP Learn Manager up to 1.1.8.
CVE-2026-56843: Plesk XML API Authorization Flaw Exposes FTP Credentials
CVE-2026-56843 is a critical Plesk XML API flaw that exposes FTP credentials and enables cross-tenant code execution.
CVE-2026-58480: Unauthenticated File Upload in Blocksy Companion Pro
CVE-2026-58480 is a critical Blocksy Companion Pro flaw enabling unauthenticated file upload and possible WordPress RCE before 2.1.47.
CVE-2026-60102: Horde VFS SMB Command Injection
CVE-2026-60102 is a high severity command injection in Horde VFS SMB handling before 3.0.1. Learn affected versions, detection, and patching.
CVE-2026-8307: Critical SQL Injection in Mediküm Web
CVE-2026-8307 is a critical SQL injection in Mediküm Web with no known patch. Learn affected versions, detection steps, and mitigation actions.
CVE-2026-9701: Eventer WordPress Plugin Vulnerability
CVE-2026-9701 is a critical Eventer WordPress plugin flaw that stores plaintext reset keys, enabling account takeover when chained with data exposure.
CVE-2026-11610: Authenticated Heap Overflow in 389 Directory Server
CVE-2026-11610 is a high severity flaw in 389 Directory Server that allows authenticated users to crash servers via crafted SASL UNBIND.
CVE-2026-13019: Unauthenticated API Access in Esri Portal for ArcGIS
CVE-2026-13019 is a critical unauthenticated API flaw in Esri Portal for ArcGIS 12.1 and earlier. A patch is available.
CVE-2026-34037: Critical Improper Authorization in Coolify
CVE-2026-34037 is a critical Coolify authorization flaw allowing authenticated cross-tenant cloning before 4.0.0-beta.464.
CVE-2026-48277: Adobe ColdFusion RCE Vulnerability
CVE-2026-48277 is a critical ColdFusion RCE affecting 2025 Update 9 and earlier, and 2023 Update 20 and earlier. Patch now.
CVE-2026-53481: Unauthenticated Path Traversal in Dell PowerProtect
CVE-2026-53481 is a critical remote unauthenticated path traversal in Dell PowerProtect Data Domain DD OS. Affected versions and fixes.
CVE-2026-59800: Unauthenticated Command Injection in 9Router
CVE-2026-59800 is a critical 9Router flaw enabling unauthenticated remote command execution before version 0.4.44. Patch urgently.
CVE-2026-14778: Improper Authorization in SourceCodester LMS
CVE-2026-14778 is a high severity IDOR in SourceCodester Online Examination & Learning Management System 1.0 with public exploit details.
CVE-2026-14807: Hard-coded credentials in PROG MIS ERP App
CVE-2026-14807 is a critical PROG MIS ERP App flaw that allows unauthenticated login and database credential exposure. What defenders should do now.
CVE-2026-48316: Adobe ColdFusion RCE Vulnerability
CVE-2026-48316 is a critical Adobe ColdFusion RCE affecting 2025 Update 9 and 2023 Update 20 and earlier. What to patch and how to detect.
CVE-2026-57572: Critical Remote Code Execution in Crawl4AI
CVE-2026-57572 is a critical unauthenticated RCE in Crawl4AI before 0.9.0. Learn affected versions, detection, mitigation, and patching.
CVE-2026-58380: GIMP PNM Parser Buffer Overflow
CVE-2026-58380 is a high severity GIMP PNM parser flaw that can crash GIMP and may enable code execution via a crafted image file.
CVE-2026-14660: SQL Injection in Online Job Portal
CVE-2026-14660 is a high-severity SQL injection in Online Job Portal 1.0. Here is what is affected, how to detect it, and how to mitigate risk.
CVE-2026-14700: SQL Injection in Internship Management System
CVE-2026-14700 is a high-severity SQL injection in Internship Management System 1.0 with public exploit disclosure and no confirmed fix.
CVE-2026-14721: UTT HiPER 1250GW Buffer Overflow
CVE-2026-14721 is a high-severity remote buffer overflow in UTT HiPER 1250GW web management, with public exploit disclosure.
CVE-2026-14734: SQL Injection in SourceCodester System
CVE-2026-14734 is a high-severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 with a public exploit and no confirmed patch.
CVE-2026-14763: Remote SQL Injection in PHP Reservations
CVE-2026-14763 is a remote SQL injection in Hotel and Tourism Reservation in PHP 1.0 with a public PoC and no confirmed fixed version.
CVE-2026-9085: DNS Spoofing Risk in Pardus-Parental-Control
CVE-2026-9085 is a high-severity Pardus-Parental-Control flaw that can enable DNS spoofing. Learn affected versions, detection, and patching.
CVE-2025-71380: Authenticated Command Execution in n8n
CVE-2025-71380 allows authenticated n8n users to run host commands via Execute Command. Learn impact, detection, and mitigation.
CVE-2026-14534: Unsafe Pickle Validation Bypass
CVE-2026-14534 affects Trail of Bits fickling, allowing malicious pickle payloads to bypass safety checks and execute code.
CVE-2026-14622: Missing Authentication in Restaurant-Website-PHP-MySQL
CVE-2026-14622 is a high-severity remote auth bypass in restaurant-website-php-mysql. Learn affected versions, detection steps, and mitigations.
CVE-2026-14637: Remote Deserialization in Ecommerce-CodeIgniter-Bootstrap
CVE-2026-14637 is a high-severity remote deserialization flaw in Ecommerce-CodeIgniter-Bootstrap. Learn affected commits, detection, and patching.
CVE-2026-13768: Gardyn IoT Hub Key Exposure
CVE-2026-13768 is a critical Gardyn firmware flaw exposing an IoT Hub owner key, enabling remote device control and possible network pivoting.
CVE-2026-14459: Pardus Software Argument Injection Vulnerability
CVE-2026-14459 affects pardus-software up to 1.0.4. Learn impact, detection steps, and how to upgrade to the fixed 1.0.5 release.
CVE-2026-14544: HPLIP hpcups Integer Overflow Incomplete Fix
CVE-2026-14544 is a critical HPLIP flaw tied to an incomplete fix, enabling possible code execution via crafted print data.
CVE-2026-14605: Buffer Overflow in RT-Thread CAN Handler
CVE-2026-14605 is a high-severity RT-Thread buffer overflow in ls1c CAN handling, affecting versions through 5.0.2.
CVE-2026-4321: Critical SQL Injection Vulnerability in Destekz
CVE-2026-4321 is a critical SQL injection in Destekz affecting versions through 02062026, with no confirmed patch and no KEV listing.
CVE-2026-9725: Unauthenticated File Deletion in Printcart Plugin
CVE-2026-9725 is a critical Printcart WooCommerce plugin flaw allowing unauthenticated file deletion in versions through 2.5.2.
CVE-2026-13125: GeoVision GeoWebPlayer WebSocket Vulnerability
CVE-2026-13125 is a high severity GeoVision GeoWebPlayer flaw that can let malicious websites access local APIs and capture screens.
CVE-2026-14336: OIDC issuer allowlist bypass in Eclipse CSI PIA
CVE-2026-14336 is a high severity unauthenticated SSRF and token trust bypass in Eclipse CSI PIA OIDC issuer validation.
CVE-2026-44935: Multi-tenant Isolation Flaw in SUSE Rancher Fleet
CVE-2026-44935 is a critical Rancher Fleet tenant isolation flaw that can expose cross-tenant credentials. Affected versions and fixes inside.
CVE-2026-50746: Critical Command Injection in UniFi Connect
CVE-2026-50746 is a critical UniFi Connect flaw affecting 3.4.16 and earlier. Learn impact, detection, and how to upgrade to 3.4.20+.
CVE-2026-57624: Critical Unauthenticated RCE in Blocksy Companion Pro
CVE-2026-57624 is a critical unauthenticated RCE in Blocksy Companion Pro for WordPress affecting up to 2.1.46, fixed in 2.1.47.
CVE-2026-24270: Critical Authentication Bypass in NVIDIA AIStore
CVE-2026-24270 is a critical NVIDIA AIStore auth bypass affecting versions 0 through 4.4, fixed in 4.5. What defenders should patch and monitor.
CVE-2026-50160: Critical unauthenticated mass assignment in Hoppscotch backend
CVE-2026-50160 lets unauthenticated attackers overwrite Hoppscotch secrets during onboarding. Affects 2026.4.1 and earlier.
CVE-2026-54592: Oj Ruby Gem Buffer Overflow DoS
CVE-2026-54592 affects Oj before 3.17.3, enabling a crash via deeply nested JSON and recursive each_child handling.
CVE-2026-57692: Critical Privilege Escalation in LCweb PrivateContent
CVE-2026-57692 is a critical privilege escalation flaw in LCweb PrivateContent affecting versions through 9.9.2. What defenders should do now.
CVE-2026-7840: UltraVNC Repeater Buffer Overflow
CVE-2026-7840 is a critical UltraVNC Repeater flaw enabling pre-auth remote code execution via the embedded HTTP admin server.
CVE-2026-10134: Unauthenticated RCE in IBM Langflow OSS
CVE-2026-10134 is a critical Langflow OSS RCE affecting versions 1.0.0 through 1.9.3, enabling secret theft, persistence, and lateral movement.
CVE-2026-12073: ProfileGrid WordPress Plugin Vulnerability
CVE-2026-12073 is a critical ProfileGrid WordPress plugin flaw enabling unauthenticated admin takeover on versions through 5.9.9.5.
CVE-2026-14162: API Documentation Exposure in Advantech Queuing Management
CVE-2026-14162 exposes API documentation in Advantech Hospital Queuing Management to unauthenticated users. Learn more.
CVE-2026-48276: Critical Adobe ColdFusion RCE
CVE-2026-48276 is a critical Adobe ColdFusion RCE tied to dangerous file uploads affecting 2025.9 and 2023.20 and earlier.
CVE-2026-58302: LinuxCNC rtapi_app Local Privilege Escalation
CVE-2026-58302 is a high severity LinuxCNC local privilege escalation in rtapi_app. Affected versions are before 2.9.9.
CVE-2026-9711: Critical SQL Injection in EventON Plugin
CVE-2026-9711 is a critical unauthenticated SQL injection in EventON for WordPress affecting versions through 5.0.11.
CVE-2026-12856: Command Injection in vscode-java JavaDoc Hovers
CVE-2026-12856 is a high severity vscode-java flaw that can execute VS Code commands via JavaDoc hovers when a user clicks a crafted link.
CVE-2026-13515: Tenda JD12L Buffer Overflow Risk
CVE-2026-13515 impacts Tenda JD12L 16.03.53.23 via /goform/SetPptpServerCfg, enabling remote stack overflow exploitation.
CVE-2026-13539: Wavlink WL-NU516U1-A Guest_ssid Buffer Overflow
CVE-2026-13539 is a remote buffer overflow in Wavlink WL-NU516U1-A firmware M16U1_V240425 with public exploit code and a vendor fix.
CVE-2026-56782: Critical Authentication Bypass in Gorse
CVE-2026-56782 lets unauthenticated attackers dump or overwrite Gorse data before 0.5.10 when admin_api_key is empty.
CVE-2026-57331: Critical File Deletion in Videochat Plugin
CVE-2026-57331 is a critical WordPress plugin file deletion flaw affecting Paid Videochat Turnkey Site versions through 7.4.8.
CVE-2026-10646: Zephyr RTOS DNS Memory Corruption
CVE-2026-10646 is a high-severity Zephyr RTOS DNS memory corruption bug in getaddrinfo(). Learn impact, detection, and mitigation steps.
CVE-2026-13485: SQL Injection in SourceCodester System
CVE-2026-13485 is a high severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 via preview.php.
CVE-2026-13486: SQL Injection in SourceCodester System
CVE-2026-13486 is a high severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 via preview6.php.
CVE-2026-13498: SQL Injection in Password Reset Flow
CVE-2026-13498 is a remote SQL injection in forgotpassword.php via the email parameter, with a public exploit and no confirmed upstream fix.
CVE-2026-58053: Gitea act_runner Container Escape
CVE-2026-58053 lets workflow authors escape Docker-backed Gitea act_runner jobs and gain host root. Detection, mitigation, and risk guidance.
CVE-2026-12415: Critical Privilege Escalation in WordPress Plugin
CVE-2026-12415 is a critical WordPress plugin flaw enabling unauthenticated account takeover in Invoice Generator up to 1.0.0.
CVE-2026-28701: Daktronics Controller Firmware Path Traversal
CVE-2026-28701 is a critical Daktronics controller firmware path traversal flaw affecting VFC-DMP-5000, DMP-5000, and DMP-8000.
CVE-2026-13325: KubeVirt Migration Proxy Vulnerability
CVE-2026-13325 exposes an unauthenticated migration proxy in KubeVirt, risking VM access and disruption.
CVE-2026-50741: Revive Adserver Fix Bypass
CVE-2026-50741 is a high-severity Revive Adserver fix bypass tied to PHP code injection. What defenders know, how to detect, and what to do now.
CVE-2026-54350: Budibase NoSQL Injection Vulnerability
CVE-2026-54350 is a critical Budibase flaw that can expose or modify backend data in published apps. Affected versions are before 3.39.12.
CVE-2026-56028: Unauthenticated Privilege Escalation in Easy Elements
CVE-2026-56028 is a critical WordPress plugin flaw affecting Easy Elements for Elementor up to 1.4.9 with no auth required.
CVE-2026-57878: GeoVision thttpd Buffer Overflow
CVE-2026-57878 is a critical remote flaw in GeoVision GV-LPC2011 and GV-LPC2211 devices running 1.12 and earlier. What defenders should do now.
CVE-2026-10086: GitLab EE Client-Side Code Execution
CVE-2026-10086 is a high-severity GitLab EE flaw that lets a developer-role user trigger client-side code in another user's session.
CVE-2026-12937: SQL Injection in Tourfic Plugin
CVE-2026-12937 is a high-severity unauthenticated SQL injection in Tourfic for WordPress affecting versions through 2.22.7.
CVE-2026-39938: Critical Unauthenticated LFI in Cacti
CVE-2026-39938 is a critical unauthenticated LFI in Cacti 1.2.30 and earlier. Learn affected versions, detection, and how to patch.
CVE-2026-41120: Critical RCE Vulnerability in Dell Wyse Management Suite
CVE-2026-41120 is a critical Dell Wyse Management Suite RCE affecting versions before 5.5 HF1. What defenders should know and do now.
CVE-2026-54836: SQL Injection in YMC Filter
CVE-2026-54836 is a critical SQL injection flaw in the YMC Filter WordPress plugin through 3.11.5. Here is what defenders should do.
CVE-2026-57700: Critical Arbitrary File Upload Vulnerability
CVE-2026-57700 is a critical arbitrary file upload flaw in OMGF Pro through 5.2.6. What defenders know, how to detect it, and what to do now.
CVE-2026-12416: Unauthenticated Account Takeover in Invoice Generator
CVE-2026-12416 is a critical WordPress plugin flaw enabling unauthenticated password resets and possible admin takeover.
CVE-2026-12485: GeoVision GV-I/O Box 4E DVRSearch Stack Overflow
CVE-2026-12485 is a critical unauthenticated UDP stack overflow in GeoVision GV-I/O Box 4E DVRSearch on port 10001.
CVE-2026-52813: Gogs Path Traversal to RCE
CVE-2026-52813 is a critical Gogs flaw fixed in 0.14.3 that can lead to path traversal, hook overwrite, and remote code execution.
CVE-2026-54588: Critical Account Takeover Vulnerability in Poweradmin
CVE-2026-54588 is a critical Poweradmin flaw that can poison SSO redirect URIs and enable account takeover. Upgrade to 4.2.4 or 4.3.3.
CVE-2026-56121: Critical Remote Code Execution in Feast
CVE-2026-56121 is a critical Feast RCE affecting versions before 0.63.0 via unsafe gRPC deserialization. Patch to 0.63.0 now.
CVE-2026-56237: Authentication Flaw in Capgo
CVE-2026-56237 affects Capgo before 12.128.2, allowing arbitrary API key creation and unauthorized access to protected endpoints.
CVE-2026-12866: Unverified Vulnerability Record
CVE-2026-12866 is not in CISA KEV, but public technical details, affected versions, and fixes were not verifiable as of 2026-06-23.
CVE-2026-48746: Critical Authentication Bypass in vLLM
CVE-2026-48746 is a critical vLLM auth bypass affecting 0.3.0 through before 0.22.0. Learn impact, detection, and patch steps.
CVE-2026-56274: Critical OS Command Injection in FlowiseAI Flowise
CVE-2026-56274 is a critical Flowise RCE affecting versions before 3.1.2. Learn impact, detection, mitigation, and patch guidance.
CVE-2026-10561: Unauthenticated Remote Code Execution in IBM Langflow OSS
CVE-2026-10561 is a critical unauthenticated RCE in IBM Langflow OSS 1.0.0 through 1.9.3. Here is what defenders need to know.
CVE-2026-10789: Autodesk Fusion Desktop MCP Extension Risk
CVE-2026-10789 is a critical Autodesk Fusion Desktop flaw in the MCP extension that may allow code execution via a malicious webpage.
CVE-2026-12778: Local Privilege Escalation in AOMEI Partition Assistant
CVE-2026-12778 is a high severity local privilege escalation in AOMEI Partition Assistant via ampa10.sys raw disk access.
CVE-2026-12806: Remote Buffer Overflow in Edimax BR-6478AC V2
CVE-2026-12806 is a high severity remote buffer overflow in Edimax BR-6478AC V2 firmware 1.23 via formWlSiteSurvey.
CVE-2026-56265: Critical Authentication Bypass in Crawl4AI
CVE-2026-56265 lets attackers forge JWTs against Crawl4AI before 0.8.7. Learn affected versions, detection steps, and exact mitigation.
CVE-2026-5366: Prefect GitRepository Argument Injection RCE
CVE-2026-5366 is a critical Prefect RCE in GitRepository handling. Learn affected versions, exploitation status, detection, and mitigation steps.
CVE-2026-56340: vLLM Multimodal Embeddings Flaw
CVE-2026-56340 affects vLLM 0.10.2 through 0.12.x before 0.13.0, enabling DoS and possible memory corruption when prompt-embeds is enabled.
CVE-2026-11837: Local Privilege Escalation in ansible.posix authorized_key
CVE-2026-11837 is a high-severity local privilege escalation in ansible.posix authorized_key caused by unsafe symlink handling.
CVE-2026-45328: ESP-IDF Out-of-bounds Write Vulnerability
CVE-2026-45328 impacts ESP-IDF 5.5.4 and 6.0. Upgrade to 5.5.5 or 6.0.1 to address a high severity security flaw.
CVE-2026-45552: Critical Authorization Bypass in Roxy-WI
CVE-2026-45552 lets authenticated Roxy-WI users bypass tenant and role checks on /install endpoints, risking cross-server privileged changes.
CVE-2017-20251: WordPress Insert PHP Plugin Vulnerability
CVE-2017-20251 affects WordPress Insert PHP before 3.3.1, enabling unauthenticated PHP execution via the REST API and shortcode injection.
CVE-2026-10520: Ivanti Sentry unauthenticated root RCE
CVE-2026-10520 is a critical Ivanti Sentry command injection flaw enabling unauthenticated root RCE. Affected versions must be upgraded now.
CVE-2026-11616: Privilege Escalation in Events Calendar
CVE-2026-11616 allows low-privilege WordPress users to gain admin rights in Events Calendar for GeoDirectory. Upgrade to 2.3.30.
CVE-2026-44748: SAP NetWeaver ABAP XML Flaw
CVE-2026-44748 is a critical SAP NetWeaver ABAP flaw enabling tampered signed XML acceptance. What defenders know, how to detect, and next steps.
CVE-2026-47938: Critical SSRF Vulnerability in Adobe Campaign Classic
CVE-2026-47938 is a critical Adobe Campaign Classic SSRF flaw that can lead to code execution. See affected versions, detection, and mitigation.
CVE-2026-5067: Critical Memory Corruption in Zephyr RTOS
CVE-2026-5067 is a CVSS 9.8 memory corruption flaw in Zephyr RTOS WebSocket upgrade handling. See which configs are affected, detection steps, and patch guidance.
CVE-2023-54352: Critical RCE in WordPress Seotheme
CVE-2023-54352 is a critical unauthenticated RCE in WordPress Seotheme via arbitrary PHP upload. What to know, detect, and do now.
CVE-2026-11483: SQL Injection in SourceCodester System
CVE-2026-11483 is a high-severity SQL injection in SourceCodester Class and Exam Timetabling System 1.0 with public exploit code.
CVE-2026-11504: Tenda CX12L Wi-Fi Schedule Vulnerability
CVE-2026-11504 affects Tenda CX12L 16.03.53.12 via /goform/openSchedWifi, enabling remote stack overflow with public exploit availability.
CVE-2026-25555: Authentication Bypass in OpenBullet2
CVE-2026-25555 lets unauthenticated attackers gain OpenBullet2 admin access via an empty X-Api-Key header. Affected versions include 0.3.2.
CVE-2026-52778: YesWiki Calculator Eval and ReDoS Vulnerability
CVE-2026-52778 affects YesWiki before 4.6.6, enabling ReDoS and possible PHP code execution in the Bazar calculator field.
CVE-2026-11450: Remote Command Injection in GL.iNet GL-MT3000
CVE-2026-11450 is a high-severity remote command injection flaw in GL.iNet GL-MT3000 firmware 4.4.5, fixed in version 4.7.
CVE-2026-11451: Remote Command Injection in GL.iNet GL-MT3000 Firmware
CVE-2026-11451 lets remote attackers inject commands via GL.iNet GL-MT3000 firmware 4.4.5. Upgrade to 4.8.1 now.
CVE-2026-11456: SQL Injection in Chanjet CRM 1.0
CVE-2026-11456 is a remote SQL injection in Chanjet CRM 1.0 with a public exploit and no verified fix version yet.
CVE-2026-11460: Boost Serialization Insecure Deserialization
CVE-2026-11460 affects Boost Serialization up to 1.91, with public exploit details and no patch currently available.
CVE-2026-49494: Comodo Internet Security IPv6 parser kernel DoS
CVE-2026-49494 is a remote IPv6 packet parsing flaw in Comodo Internet Security that can crash Windows systems before firewall rules apply.
CVE-2026-11413: Buffer Overflow in JD Cloud Box AX6600
CVE-2026-11413 is a high-severity remote buffer overflow in JingDong JD Cloud Box AX6600 4.5.3.r4546 with public exploit disclosure.
CVE-2026-11437: SSRF in go-fastdfs-web-go Installation
CVE-2026-11437 is a high severity SSRF in go-fastdfs-web-go up to 1.3.7, with a published exploit and no confirmed fixed version.
CVE-2026-7537: Arbitrary File Upload in MDJM Plugin
CVE-2026-7537 affects MDJM Event Management for WordPress through 1.7.8.3, enabling admin-level arbitrary file upload and possible RCE.
CVE-2026-7654: Admin Columns WordPress Plugin Vulnerability
CVE-2026-7654 is a high-severity Admin Columns flaw that can let Contributor-level users reach RCE. Affected versions include 7.0.18.
CVE-2026-11262: Google Chrome TabStrip use-after-free
CVE-2026-11262 is a high-severity Chrome TabStrip use-after-free fixed in 149.0.7827.53. Here is what defenders need to patch and monitor.
CVE-2026-46389: Critical Authentication Bypass in Defense Unicorns UDS Identity Config
CVE-2026-46389 lets attackers bypass client secret checks in UDS Identity Config. Affected versions 0.11.0 through 0.26.0 should upgrade.
CVE-2026-50256: Stack-Based Buffer Overflow in X.Org X Server
CVE-2026-50256 is a high-severity X.Org buffer overflow. Learn affected versions, detection tips, and patch guidance.
CVE-2026-50593: Graphite Integer Underflow Vulnerability
CVE-2026-50593 affects Graphite before 1.3.15, causing an integer underflow and out-of-bounds write. Upgrade and hunt for crashes now.
CVE-2026-6207: HAVELSAN Geographic Tracking System Vulnerability
CVE-2026-6207 is a critical HAVELSAN Geographic Tracking System flaw before v0.0.2 that enables system footprinting via response discrepancies.
CVE-2025-67447: Critical OS Command Injection in Neterbit NW-431F Router
CVE-2025-67447 is a critical command injection flaw in Neterbit NW-431F routers affecting 20241014-IR03 and earlier.
CVE-2026-4104: Critical SQL Injection Vulnerability in TeknoPass
CVE-2026-4104 is a critical TeknoPass SQL injection flaw affecting versions 20210501 through 20260429, with no confirmed fix version yet.
CVE-2026-41860: Missing TLS Verification in BOSH Monitor
CVE-2026-41860 is a high severity BOSH flaw that lets local MITM attackers intercept credentials or redirect UAA token requests.
CVE-2026-43986: Critical SSRF Vulnerability in Tautulli
CVE-2026-43986 is a critical SSRF flaw in Tautulli before 2.17.1 that can turn a guest action into unauthenticated server-side fetches.
CVE-2026-10694: File Inclusion in SourceCodester System
CVE-2026-10694 is a high severity file inclusion flaw in SourceCodester Online Food Ordering System 2.0 with public exploit material.
CVE-2026-35075: Hard-coded password exposure in MBS UGW web GUI
CVE-2026-35075 is a critical unauthenticated flaw in MBS UGW web GUI that can expose a hard-coded password and enable full device access.
CVE-2026-42061: Local Privilege Escalation in Acronis DeviceLock DLP
CVE-2026-42061 is a local privilege escalation flaw in Acronis DeviceLock DLP for Windows before build 9.0.15051.93227.
CVE-2026-5076: ARMember Premium Password Reset Key Exposure
CVE-2026-5076 is a critical ARMember Premium flaw enabling account takeover via plaintext reset keys stored through version 7.3.1.
CVE-2026-7312: Progress Sitefinity credential exposure
CVE-2026-7312 is a critical Sitefinity flaw exposing Insight credentials to remote attackers. Affected versions and mitigation steps.
CVE-2026-10206: D-Link DI-8400 Remote Buffer Overflow
CVE-2026-10206 is a high-severity D-Link DI-8400 remote overflow with public exploit availability and no confirmed fixed version.
CVE-2026-40965: EC Private Key Exposure in Cloud Foundry UAA
CVE-2026-40965 exposes EC private keys via Cloud Foundry UAA /token_keys. Learn affected versions, detection, mitigation, and patch guidance.
CVE-2026-45131: GitHub Actions Vulnerability in CloudPirates
CVE-2026-45131 is a critical GitHub Actions flaw in CloudPirates Helm Charts that can expose secrets from forked pull requests.
CVE-2026-7858: Unauthenticated RCE in Teamwork Cloud
CVE-2026-7858 is a critical unauthenticated RCE in Teamwork Cloud and Magic Collaboration Studio affecting 2022x through 2026x releases.
CVE-2026-10158: TRENDnet TEW-432BRP Stack Overflow
CVE-2026-10158 is a high-severity remote stack overflow in TRENDnet TEW-432BRP 3.10B20. No patch exists; replace or isolate the device.
CVE-2026-10163: Buffer Overflow in Edimax Router
CVE-2026-10163 is a high-severity buffer overflow in Edimax BR-6478AC V2 firmware 1.23. Public exploit disclosure exists; fix version is unknown.
CVE-2026-10179: TRENDnet TEW-432BRP Buffer Overflow
CVE-2026-10179 is a high-severity buffer overflow in TRENDnet TEW-432BRP 3.10B20 with a public PoC and no vendor fix.
CVE-2026-10187: TOTOLINK N300RH Web Management Buffer Overflow
CVE-2026-10187 is a critical remote buffer overflow in TOTOLINK N300RH firmware. Affected version, exploitation status, detection, and mitigation.
CVE-2026-10192: Tenda W12 Buffer Overflow Vulnerability
CVE-2026-10192 is a stack-based buffer overflow in Tenda W12 3.0.0.7(4763). Public exploit material exists; patch status is unverified.
CVE-2018-25412: Delta Sql File Upload Vulnerability
Exploring CVE-2018-25412, a critical file upload flaw in Delta Sql 1.8.2 leading to RCE.
CVE-2026-10110: SQL Injection in Student Details Management System
CVE-2026-10110 is a high-severity SQL injection in Student Details Management System 1.0 via /index.php roll parameter.
CVE-2026-10126: Edimax BR-6478AC Buffer Overflow
CVE-2026-10126 is a high-severity buffer overflow in Edimax BR-6478AC 1.23. Here’s what defenders know, how to detect it, and what to do now.
CVE-2026-42960: Unbound DNS Cache Poisoning Vulnerability
CVE-2026-42960 is a critical Unbound cache poisoning flaw affecting versions through 1.25.0. Upgrade to 1.25.1 or apply the vendor patch.
CVE-2026-7465: Authenticated RCE in Spectra Gutenberg Blocks
CVE-2026-7465 is a high-severity authenticated RCE in the Spectra Gutenberg Blocks WordPress plugin affecting versions through 2.19.25.
CVE-2026-45625: SQL Injection in Atak Domain order_detail.php
CVE-2026-45625 is a high-severity SQL injection in Atak Domain/Hosting through 5.4.1. Learn affected versions, detection, and upgrade steps.
CVE-2026-45631: Linux Kernel MPTCP Race Condition Use-After-Free
CVE-2026-45631 is a high-severity Linux kernel MPTCP use-after-free affecting versions before 6.14.8. Here's what defenders should do.
CVE-2026-8732: Authentication Rate-Limit Bypass in Mitto
CVE-2026-8732 is a critical Mitto rate-limit bypass that allows brute-force attempts via username case changes. Fixed in 1.22.4.
CVE-2026-8809: Unauthenticated RCE in Acme Corp Widget Server import endpoint
CVE-2026-8809 is a critical unauthenticated RCE in Acme Corp Widget Server before 4.2.1 via crafted tar uploads to /api/import.
CVE-2026-9558: Untrusted Search Path in Apache NetBeans
CVE-2026-9558 is a high-severity untrusted search path flaw in Apache NetBeans 28.x before 29. Here's impact, detection, and patch guidance.
CVE-2026-9559: High-severity RCE in Wazuh DistributedAPI
CVE-2026-9559 is a Wazuh DistributedAPI RCE affecting 4.4.0 through 4.13.0. Learn impact, detection, and how to upgrade to 4.13.1.
CVE-2026-32999: Unpublished CVE Entry with No NVD Record
CVE-2026-32999 currently has no NVD record and is not on CISA KEV. What defenders can verify, what remains unknown, and how to respond safely.
CVE-2026-43898: Apple Pointer Authentication bypass
CVE-2026-43898 is a high-severity Apple Pointer Authentication bypass fixed in macOS 15.6, iOS 18.6, and related releases.
CVE-2026-4408: Aim Password Encryption Vulnerability
CVE-2026-4408 affects Aim before 3.25.27, exposing encrypted local passwords to dictionary attacks due to a hardcoded AES-CBC IV.
CVE-2026-46414: Pterodactyl Panel Password Reset Vulnerability
CVE-2026-46414 is a critical Pterodactyl Panel account takeover flaw in password reset logic. Affects up to 1.11.11; fixed in 1.11.12.
CVE-2026-46840: SQL Injection in PHPGurukul System
CVE-2026-46840 affects PHPGurukul Nipah Virus Testing Management System via /register.php SQL injection. PoC exists; no fix identified.
CVE-2026-49238: Critical Remote Code Execution in Langflow
CVE-2026-49238 is a critical Langflow RCE affecting versions before 1.7.0. Learn impact, detection, mitigation, and patch steps.
CVE-2026-44327: Unsafe Redirect Handling in Apache Traffic Server
CVE-2026-44327 is a high-severity Apache Traffic Server open redirect flaw enabling phishing and cache poisoning. Affected versions and fixes.
CVE-2026-45087: Unauthenticated SQL Injection in FastForum
CVE-2026-45087 is a high-severity unauthenticated SQL injection in FastForum search. Affects versions before 4.2.1.
CVE-2026-8760: Path traversal in CGI::Application load_tmpl()
CVE-2026-8760 affects CGI::Application before 4.70, enabling path traversal and unauthorized file reads via load_tmpl().
CVE-2026-9627: Reflected XSS in Kanboard
CVE-2026-9627 is a reflected XSS in Kanboard before 1.2.47. Learn affected versions, detection, mitigation, and exploitation status.
CVE-2026-44450: Critical SQL Injection in phpIPAM
CVE-2026-44450 is a critical unauthenticated SQL injection in phpIPAM through 1.7.3. Learn affected versions, detection, and mitigation.
CVE-2026-46624: Local Privilege Escalation in Aiven aiven-extras
CVE-2026-46624 is a critical Aiven aiven-extras privilege escalation flaw affecting Aiven for PostgreSQL and Valkey before fixed versions.
CVE-2025-71210: Gluu Server Unauthenticated Account Takeover
CVE-2025-71210 is a critical Gluu Server flaw in resetPassword that can enable unauthenticated account takeover. Affected: <4.5.7 and 4.6.0-4.6.8.
CVE-2026-40165: Command Injection in Acme SecureVault
CVE-2026-40165 affects Acme SecureVault 4.2.0-4.2.7, enabling root RCE via /api/v1/diag/ping. Fixed in 4.2.8.
CVE-2026-44050: XML parser validation bypass in Acme Gateway Manager and Edge Controller
CVE-2026-44050 is a high-severity authenticated XML parser flaw in Acme products. Affects 4.2.0-4.2.6 and 3.9.0-3.9.11.
CVE-2026-47114: Pterodactyl Panel Admin Settings Bypass
CVE-2026-47114 affects Pterodactyl Panel before 1.11.11, allowing low-privileged users to change admin settings via crafted requests.
CVE-2026-5118: Critical Authorization Bypass in Otelier HUB OTA Sync
Practitioner explainer for CVE-2026-5118, a critical Otelier HUB OTA Sync authorization bypass fixed in 1.0.0-beta.43-hotfix.2 and 1.0.0-18-hotfix.8.
CVE-2026-6279: HTTP/2 Rapid Reset DoS in Curve
CVE-2026-6279 affects Curve 0.4.1 and earlier, enabling unauthenticated HTTP/2 Rapid Reset DoS. Fixed in 0.5.0.
CVE-2026-20223: Critical authentication bypass in Sitecore Experience Platform
CVE-2026-20223 is a critical Sitecore XP 10.4 auth bypass affecting /sitecore/admin before KB1003667. Learn impact, detection, and mitigation.
CVE-2026-24207: Apple ImageIO Out-of-Bounds Write Vulnerability
CVE-2026-24207 is a high-severity Apple ImageIO flaw that can lead to code execution via crafted media. Affected versions and patch guidance.
CVE-2026-34234: BuddyBoss Platform Unauthenticated SQL Injection
CVE-2026-34234 is a critical unauthenticated SQL injection in BuddyBoss Platform before 2.9.30. Learn affected versions, detection, and mitigation.
CVE-2026-45444: MLflow pyfunc predict() remote code execution
CVE-2026-45444 is a critical MLflow RCE affecting versions 2.17.0 to before 2.18.0. Learn impact, detection, and exact upgrade steps.
CVE-2026-5200: Acme Portal Password Reset Token Exposure
CVE-2026-5200 affects Acme Portal before 4.2.7, exposing reset tokens via /api/debug/reset and enabling account takeover.
CVE-2026-27648: Canonical apport TOCTOU race condition enables arbitrary file overwrite
CVE-2026-27648 affects Canonical apport through 2.32.0, enabling local arbitrary file overwrite via PID reuse and namespaces.
CVE-2026-33642: Critical Zip Slip in Acme File Transfer Server
CVE-2026-33642 is a critical unauthenticated Zip Slip flaw in Acme File Transfer Server 5.0.0-5.4.1. Upgrade to 5.4.2 now.
CVE-2026-43633: Roxio Easy VHS to DVD FTP Information Disclosure
CVE-2026-43633 is a medium-severity FTP information disclosure in Roxio Easy VHS to DVD exposing source paths, memory, and line details.
CVE-2026-4885: Unpublished CVE Entry with Unverified Details
Practitioner explainer for CVE-2026-4885 based on currently available data: no NVD record, not in CISA KEV, and key details remain unverified.
CVE-2026-41948: Linux kernel s390 AP driver race condition
Analysis of CVE-2026-41948, a Linux kernel s390 AP driver race condition affecting queue reset handling.
CVE-2026-42822: Public details not yet available
Practitioner-grade explainer for CVE-2026-42822. No NVD record, no KEV listing, and no confirmed affected versions or patch details yet.
CVE-2026-7301: PyGraphDB /api/render unauthenticated RCE
CVE-2026-7301 is a critical PyGraphDB RCE in /api/render affecting versions before 2.4.7. Here’s impact, detection, and mitigation.
CVE-2026-8775: Command Injection in Artifactory_cpp_ce Uploads
CVE-2026-8775 affects artifactory_cpp_ce before 4.0.5, enabling authenticated command execution via crafted package metadata during upload.
CVE-2026-8785: Apache JSPWiki XSS via crafted RSS feed content
CVE-2026-8785 is an XSS flaw in Apache JSPWiki 2.12.0-2.12.2. Learn affected versions, exploitation status, detection, and upgrade steps.
CVE-2018-25320: Critical buffer overflow in ADSL2+ WiFi modem firmware update handler
Practitioner guide to CVE-2018-25320, a critical modem firmware update buffer overflow with public PoC and high-impact RCE risk.
CVE-2026-8719: Buffer Overflow in Acme Gateway HTTP/2
CVE-2026-8719 is a high-severity Acme Gateway flaw in HTTP/2 HPACK decoding. Affects 4.0.0-4.2.6; fixed in 4.2.7.
CVE-2026-8725: Unpublished CVE Record with No NVD Details Yet
Practitioner guide to CVE-2026-8725: what is known, what is missing, detection assumptions, and interim mitigation steps.
CVE-2026-8751: Unpublished or Unresolved CVE Record
CVE-2026-8751 has no NVD record or KEV listing. What defenders can verify, what remains unknown, and how to respond safely.
CVE-2025-29635: D-Link DIR-823X Command Injection (RCE)
CVE-2025-29635 in D-Link DIR-823X firmware 240126/240802 is a command injection RCE via /goform/set_prohibiting. KEV-listed; act now.
CVE-2026-0300: Unauthenticated RCE via PAN-OS Buffer Overflow
CVE-2026-0300 is a critical PAN-OS vulnerability allowing unauthenticated root RCE via buffer overflow in the User-ID Authentication Portal.
CVE-2026-31431: Linux Kernel AEAD Bug Fix
Guide to CVE-2026-31431 (Linux kernel algif_aead). KEV-listed, exploited in the wild. Detection and mitigation steps.
CVE-2026-41940: Authentication Bypass in cPanel & WHM
Explainer for CVE-2026-41940 (CVSS 9.8): cPanel & WHM auth bypass exploited in the wild. Detection, mitigation, and patch guidance.
CVE-2026-42208: Critical SQL Injection in BerriAI LiteLLM
CVE-2026-42208 is a critical LiteLLM SQLi (CVSS 9.8) exploited in the wild. Affects 1.81.16–1.83.6; fixed in 1.83.7.
CVE-2026-42897: Exchange Server XSS Spoofing Vulnerability
Guide for CVE-2026-42897 (Exchange Server XSS/spoofing). KEV-listed, exploited in the wild. Detection and mitigation steps.
CVE-2026-6973: Ivanti EPMM RCE via Input Validation
CVE-2026-6973 is a high-severity Ivanti EPMM flaw enabling authenticated admin RCE. Upgrade to 12.6.1.1/12.7.0.1/12.8.0.1.
CVE-2026-34253: Mastodon Rate-Limit Bypass
CVE-2026-34253 is a high-severity Mastodon flaw that can bypass rate limits via HTTP parser discrepancies. Affected versions and fixes inside.
CVE-2026-41964: rizin DoS via Uninitialized Variable
CVE-2026-41964 affects rizin 0.8.0-0.8.2 and can crash the app via a crafted binary due to an uninitialized variable.
CVE-2026-44717: Unpublished or Unverified CVE Record
CVE-2026-44717 has no retrievable NVD record yet. Learn what is verified, what is unknown, and how defenders should track it safely.
CVE-2026-5229: OPA path traversal in package_index
CVE-2026-5229 is a high-severity OPA path traversal flaw fixed in v1.4.1. Learn affected versions, detection, and mitigation steps.
CVE-2025-11024: Better Search Replace flaw
CVE-2025-11024 affects Better Search Replace through 1.4.11 and may let low-privilege users expose sensitive files in WordPress.
CVE-2026-20182: Cisco Smart Licensing Utility flaw
CVE-2026-20182 is a Cisco Smart Licensing Utility flaw that may expose sensitive data via a hardcoded cryptographic key.
CVE-2026-38567: Pimcore Datahub SVG upload stored XSS
CVE-2026-38567 is a high-severity Pimcore Datahub SVG upload flaw that can trigger stored JavaScript execution in browsers.
CVE-2026-40636: Argo CD token leakage risk
CVE-2026-40636 affects Argo CD and may leak repository or project-scope tokens via path traversal. Versions, detection, and patching.
CVE-2026-42613 in ArcSight ESM: Patch and Mitigate
CVE-2026-42613 is a high-severity ArcSight ESM DoS flaw. Learn affected versions, impact, detection steps, and how to patch fast.
CVE-2026-42869: NetPilot Login Page XSS
CVE-2026-42869 is a reflected XSS in NetPilot 7.4.2 and below via the login page returnUrl parameter.
CVE-2026-42882: openHAB 5.0.0 DoS Explained
CVE-2026-42882 affects openHAB 5.0.0 via controller endpoint command injection that can cause DoS. Impact, detection, and mitigation steps.
CVE-2026-44643: CKAN Privilege Escalation
CVE-2026-44643 is a high-severity CKAN privilege escalation flaw via groups parameter pollution. Affected versions and fixes inside.
CVE-2026-7813: Apache IoTDB SQL Injection
CVE-2026-7813 is a high-severity Apache IoTDB blind SQL injection in SELECT INTO affecting 0.10.0 through 1.3.4.
CVE-2026-7816 in htmly 3.0.6 Explained
CVE-2026-7816 in htmly 3.0.6 may allow file overwrite and possible RCE when registration and posting are enabled.