All PoCs
subscribe (RSS)All proof-of-concept entries in the archive.
Entries
773
in the archive
CISA KEV
119
exploited in the wild
Ransomware
33
known campaign use
Unpatched
322
no vendor fix
Critical
378
49% of listed
773 entries
Category:
Severity
Exploitation signals
Patch status
Date range
→
Sort
773 result(s)
POC LIST
773 shown · 773 indexed
| PoC title | CVE | Category | Severity | Patch | Date |
|---|---|---|---|---|---|
| WordPress Divi Ajax Filter LFI (CVE-2026-11613)
CVE-2026-11613
web
Unverified | CVE-2026-11613 | web | CRITICAL 9.8 | Unverified | 2026-09-05 |
| PaperCut MF/NG Auth Bypass + RCE Chain (CVE-2026-81578 / CVE-2026-82078)
CVE-2026-81578, CVE-2026-82078
web
Unverified | CVE-2026-81578, CVE-2026-82078 | web | CRITICAL 9.8 | Unverified | 2026-09-05 |
| Linux XFRM nat_keepalive Double-Free LPE (CVE-2026-72137)
CVE-2026-72137
binary
Unverified | CVE-2026-72137 | binary | HIGH 7.8 | Unverified | 2026-09-04 |
| Linux SCTP Stream Rollback UAF LPE (CVE-2026-52929)
CVE-2026-52929
binary
Unverified | CVE-2026-52929 | binary | HIGH 7.8 | Unverified | 2026-09-04 |
| Linux SCTP Stale COOKIE-ECHO UAF LPE (CVE-2026-52924)
CVE-2026-52924
binary
Unverified | CVE-2026-52924 | binary | CRITICAL 9.8 | Unverified | 2026-09-04 |
| Linux SCTP auth_enable Sysctl UAF LPE (CVE-2026-68162)
CVE-2026-68162
binary
Unverified | CVE-2026-68162 | binary | HIGH 7.8 | Unverified | 2026-09-04 |
| Linux Open vSwitch Tunnel Netdev UAF LPE (CVE-2026-31678)
CVE-2026-31678
binary
Unverified | CVE-2026-31678 | binary | HIGH 7.8 | Unverified | 2026-09-04 |
| Linux Netfilter nf_queue Bridge Device UAF LPE (CVE-2026-72255)
CVE-2026-72255
binary
Unverified | CVE-2026-72255 | binary | HIGH 7.8 | Unverified | 2026-09-04 |
| Linux IPVS One-Packet Flag Propagation UAF LPE (CVE-2026-80714)
CVE-2026-80714
binary
Unverified | CVE-2026-80714 | binary | CRITICAL 9.8 | Unverified | 2026-09-04 |
| Linux IPv6 fib6 Rule Suppression UAF LPE (CVE-2026-74581)
CVE-2026-74581
binary
Unverified | CVE-2026-74581 | binary | HIGH 7.8 | Unverified | 2026-09-04 |
| Linux io_uring Poll Signed Comparison LPE (CVE-2026-52933)
CVE-2026-52933
binary
Unverified | CVE-2026-52933 | binary | HIGH 7.8 | Unverified | 2026-09-04 |
| Linux Bridge Fast-Leave Port Deletion UAF LPE (CVE-2026-74480)
CVE-2026-74480
binary
Unverified | CVE-2026-74480 | binary | CRITICAL 9.8 | Unverified | 2026-09-04 |
| WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970
web
Unverified | CVE-2026-82970 | web | CRITICAL 10 | Unverified | 2026-09-03 |
| React Router Session Path Traversal (CVE-2025-61686)
CVE-2025-61686
web
Unverified | CVE-2025-61686 | web | CRITICAL 9.1 | Unverified | 2026-09-03 |
| Node.js Permission Model Symlink Escape (CVE-2025-55130)
CVE-2025-55130
binary
Unverified | CVE-2025-55130 | binary | CRITICAL 9.1 | Unverified | 2026-09-03 |
| Nginx HTTP/3 QUIC Pool Corruption RCE (CVE-2026-42530)
CVE-2026-42530
binary
Unverified | CVE-2026-42530 | binary | HIGH 8.1 | Unverified | 2026-09-03 |
| Next.js Windows Cache Path Traversal RCE (CVE-2026-75604)
CVE-2026-75604
web
Unverified | CVE-2026-75604 | web | CRITICAL 9 | Unverified | 2026-09-03 |
| Linux Netfilter xt_IDLETIMER UAF LPE (CVE-2026-23274)
CVE-2026-23274
binary
Unverified | CVE-2026-23274 | binary | HIGH 7.8 | Unverified | 2026-09-03 |
| Linux Netfilter nf_queue UAF LPE (CVE-2026-52912)
CVE-2026-52912
binary
Unverified | CVE-2026-52912 | binary | HIGH 7.8 | Unverified | 2026-09-03 |
| Linux MPLS Subsystem UAF LPE (CVE-2026-43042)
CVE-2026-43042
binary
Unverified | CVE-2026-43042 | binary | HIGH 7.1 | Unverified | 2026-09-03 |
| Linux Kernel posix-cpu-timers Use-After-Free LPE (CVE-2026-64560)
CVE-2026-64560
binary
Unverified | CVE-2026-64560 | binary | HIGH 7.8 | Unverified | 2026-09-03 |
| Linux Kernel IPC msg_msg Use-After-Free LPE (CVE-2026-52923)
CVE-2026-52923
binary
Unverified | CVE-2026-52923 | binary | HIGH 7.8 | Unverified | 2026-09-03 |
| Linux Kernel eventpoll Use-After-Free LPE (CVE-2026-43074)
CVE-2026-43074
binary
Unverified | CVE-2026-43074 | binary | HIGH 7.8 | Unverified | 2026-09-03 |
| Linux IPv6 RPL Routing UAF LPE (CVE-2026-43501)
CVE-2026-43501
binary
Unverified | CVE-2026-43501 | binary | CRITICAL 9.8 | Unverified | 2026-09-03 |
| Kestra Authentication Bypass to RCE (CVE-2026-49869)
CVE-2026-49869, CVE-2026-53576
web
Unverified | CVE-2026-49869, CVE-2026-53576 | web | CRITICAL 10 | Unverified | 2026-09-03 |
| Firefox SpiderMonkey JIT Type Confusion (CVE-2026-10702)
CVE-2026-10702
binary
Unverified | CVE-2026-10702 | binary | MEDIUM 4.3 | Unverified | 2026-09-03 |
| Chrome V8 Type Confusion RCE (CVE-2026-5865)
CVE-2026-5865
binary
Unverified | CVE-2026-5865 | binary | HIGH 8.8 | Unverified | 2026-09-03 |
| Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)
CVE-2026-21508
binary
Patched | CVE-2026-21508 | binary | HIGH 7.8 | Patched | 2026-08-16 |
| UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)
KEV
EPSS 87% CVE-2026-34910, CVE-2026-34909, CVE-2026-34908
network
Patched | CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 | network | CRITICAL 10 | Patched | 2026-08-16 |
| Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)
CVE-2026-68398
binary
Patched | CVE-2026-68398 | binary | HIGH 7.8 | Patched | 2026-08-16 |
| PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 / GHSA-x692-q9x7-8c3f
web
Unverified | CVE-2026-17544 / GHSA-x692-q9x7-8c3f | web | CRITICAL 9.8 | Unverified | 2026-08-16 |
| nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533
web
Patched | CVE-2026-42533 | web | CRITICAL 9.8 | Patched | 2026-08-16 |
| Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)
CVE-2026-23111
binary
Patched | CVE-2026-23111 | binary | HIGH 7.8 | Patched | 2026-08-16 |
| Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)
CVE-2026-53361
binary
Patched | CVE-2026-53361 | binary | CRITICAL 9.8 | Patched | 2026-08-16 |
| Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)
CVE-2026-2764 / MFSA 2026-13
binary
Unverified | CVE-2026-2764 / MFSA 2026-13 | binary | HIGH 8.8 | Unverified | 2026-08-16 |
| Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)
KEV CVE-2026-8452
network
Patched | CVE-2026-8452 | network | CRITICAL 9.8 | Patched | 2026-08-16 |
| Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)
CVE-2026-20200 / NSIDE-SA-2026-003
network
Patched | CVE-2026-20200 / NSIDE-SA-2026-003 | network | CRITICAL 9.9 | Patched | 2026-08-16 |
| Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7
web
Patched | CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 | web | CRITICAL 10 | Patched | 2026-08-16 |
| Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301
network
Unverified | CVE-2026-47301 | network | CRITICAL 9.8 | Unverified | 2026-08-15 |
| Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)
CVE-2026-64564
binary
Patched | CVE-2026-64564 | binary | HIGH 7.8 | Patched | 2026-08-15 |
| Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)
CVE-2026-68138
binary
Patched | CVE-2026-68138 | binary | HIGH 7.8 | Patched | 2026-08-15 |
| Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)
CVE-2026-64531
binary
Patched | CVE-2026-64531 | binary | HIGH 7.8 | Patched | 2026-08-15 |
| Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106
binary
Unverified | CVE-2026-17106 | binary | CRITICAL 9.8 | Unverified | 2026-08-15 |
| Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912
network
Unverified | CVE-2026-27912 | network | HIGH 8 | Unverified | 2026-08-11 |
| Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks
EPSS 11% Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11
binary
Unpatched | Bypass of CVE-2026-50656 | binary | HIGH 7.8 | Unpatched | 2026-08-11 |
| Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177
network
Patched | CVE-2026-25177 | network | HIGH 8.8 | Patched | 2026-08-11 |
| Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)
CVE-2026-64561
binary
Patched | CVE-2026-64561 | binary | HIGH 8.8 | Patched | 2026-08-09 |
| WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")
EPSS 31% CVE-2026-64638
web
Unverified | CVE-2026-64638 | web | HIGH 8.9 | Unverified | 2026-08-09 |
| TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077)
KEV
EPSS 88% CVE-2026-63077
web
Patched | CVE-2026-63077 | web | CRITICAL 9.8 | Patched | 2026-08-09 |
| Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)
KEV
RW
EPSS 100% CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025)
web
Patched | CVE-2025-61882 | web | CRITICAL 9.8 | Patched | 2026-08-09 |
| MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free
MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet
binary
Unpatched | MDEV-40328 | binary | CRITICAL 8.8 | Unpatched | 2026-08-09 |
| Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)
KEV
RW
EPSS 100% CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD)
network
Unverified | CVE-2023-35078 | network | CRITICAL 9.8 | Unverified | 2026-08-09 |
| Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)
KEV
RW
EPSS 100% CVE-2025-22457
network
Unpatched | CVE-2025-22457 | network | CRITICAL 9 | Unpatched | 2026-08-09 |
| GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)
KEV
RW
EPSS 100% CVE-2021-22205 (chains CVE-2021-22204 in ExifTool)
web
Patched | CVE-2021-22205 | web | CRITICAL 10 | Patched | 2026-08-09 |
| Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004)
KEV
EPSS 85% CVE-2026-60004
web
Patched | CVE-2026-60004 | web | HIGH 8.8 | Patched | 2026-08-09 |
| Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)
CVE-2026-18718
misc
Patched | CVE-2026-18718 | misc | HIGH 7.5 | Patched | 2026-08-09 |
| CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)
KEV
RW
EPSS 95% CVE-2024-51378
web
Patched | CVE-2024-51378 | web | CRITICAL 10 | Patched | 2026-08-09 |
| Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)
KEV
EPSS 72% CVE-2026-16232
network
Patched | CVE-2026-16232 | network | CRITICAL 9.1 | Patched | 2026-08-09 |
| Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640
cloud
Patched | CVE-2026-64640 | cloud | HIGH 8.1 | Patched | 2026-08-09 |
| Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)
NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier)
binary
Unverified | NotCVE-2026-0010 | binary | HIGH | Unverified | 2026-08-01 |
| Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
CVE-2026-65694 (VulnCheck advisory)
web
Patched | CVE-2026-65694 | web | HIGH 7.5 | Patched | 2026-07-31 |
| IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)
KEV
EPSS 35% CVE-2026-9198
web
Patched | CVE-2026-9198 | web | CRITICAL 9.8 | Patched | 2026-07-31 |
| CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)
KEV
RW
EPSS 100% CVE-2022-40684
network
Unverified | CVE-2022-40684 | network | CRITICAL 9.8 | Unverified | 2026-07-31 |
| Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)
KEV
EPSS 100% CVE-2025-32432
web
Patched | CVE-2025-32432 | web | CRITICAL 10 | Patched | 2026-07-31 |
| Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988)
EPSS 15% CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459)
web
Patched | CVE-2025-54988 | web | CRITICAL 9.8 | Patched | 2026-07-31 |
| Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723)
EPSS 16% CVE-2026-16723
web
Unpatched | CVE-2026-16723 | web | CRITICAL 9 | Unpatched | 2026-07-31 |
| Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)
CVE-2026-49176
binary
Patched | CVE-2026-49176 | binary | HIGH 7.8 | Patched | 2026-07-27 |
| Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)
CVE-2026-54992
network
Patched | CVE-2026-54992 | network | HIGH 8.4 | Patched | 2026-07-27 |
| Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)
EPSS 28% CVE-2026-66066 (GHSA-xr9x-r78c-5hrm)
web
Patched | CVE-2026-66066 | web | CRITICAL 9.5 | Patched | 2026-07-27 |
| MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports & Sharing Groups (CVE-2026-56423)
CVE-2026-56423
web
Patched | CVE-2026-56423 | web | HIGH 8.8 | Patched | 2026-07-27 |
| Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)
KEV
EPSS 85% CVE-2026-50522
web
Patched | CVE-2026-50522 | web | CRITICAL 9.8 | Patched | 2026-07-27 |
| Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)
CVE-2026-57830
web
Patched | CVE-2026-57830 | web | CRITICAL 9.1 | Patched | 2026-07-27 |
| Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)
KEV
EPSS 15% CVE-2026-56291
web
Unverified | CVE-2026-56291 | web | CRITICAL 9.8 | Unverified | 2026-07-27 |
| ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)
CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc)
binary
Patched | CVE-2026-46316 | binary | CRITICAL 9.3 | Patched | 2026-07-27 |
| GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)
N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27)
binary
Unpatched | N/A | binary | HIGH | Unpatched | 2026-07-27 |
| GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)
N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News)
web
Unverified | N/A | web | CRITICAL | Unverified | 2026-07-27 |
| Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
CVE-2026-53753 (GHSA-qxjp-w3pj-48m7)
web
Patched | CVE-2026-53753 | web | CRITICAL 9.8 | Patched | 2026-07-27 |
| ClickFix Social-Engineering Technique — Fortinet-Branded Multi-Stage Lure (Fake File-Access Page + Fake CAPTCHA + Clipboard Injection)
N/A (social-engineering technique, not a software vulnerability)
social-engineering
Unverified | N/A | social-engineering | HIGH | Unverified | 2026-07-27 |
| ClickFix Social Engineering Technique — Fake Cloudflare Turnstile Just a Moment Verification Lure
N/A (social-engineering technique, not a software vulnerability)
social-engineering
Unverified | N/A | social-engineering | HIGH | Unverified | 2026-07-27 |
| ClickFix Fake-CAPTCHA Social-Engineering Kit with IP Fencing and 19-Language Localization
N/A (social-engineering technique, not a software vulnerability)
social-engineering
Unverified | N/A | social-engineering | HIGH | Unverified | 2026-07-27 |
| ClickFix Fake reCAPTCHA to mshta/HTA Execution Chain
N/A (social-engineering technique, not a software vulnerability)
social-engineering
Unverified | N/A | social-engineering | HIGH | Unverified | 2026-07-27 |
| Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)
CVE-2026-54350 (GHSA-8qv3-p479-cj62)
web
Patched | CVE-2026-54350 | web | CRITICAL 10 | Patched | 2026-07-27 |
| Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
CVE-2026-49230
web
Patched | CVE-2026-49230 | web | CRITICAL 9.1 | Patched | 2026-07-27 |
| AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CVE-2026-54121
network
Patched | CVE-2026-54121 | network | HIGH 8.8 | Patched | 2026-07-27 |
| wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
KEV
EPSS 97% CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf
web
Patched | CVE-2026-63030 | web | CRITICAL 9.1 | Patched | 2026-07-19 |
| V8 Array Iterator Maglev Type Confusion — addrof/fakeobj Primitives (CVE-2026-14431)
CVE-2026-14431
binary
Unpatched | CVE-2026-14431 | binary | HIGH 8.8 | Unpatched | 2026-07-19 |
| SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)
KEV
EPSS 12% CVE-2026-48558
web
Patched | CVE-2026-48558 | web | CRITICAL 10 | Patched | 2026-07-19 |
| LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)
CVE-2026-58116
web
Patched | CVE-2026-58116 | web | CRITICAL 9.8 | Patched | 2026-07-19 |
| LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability
binary
Patched | — | binary | HIGH | Patched | 2026-07-19 |
| Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)
KEV CVE-2026-55255 (GHSA-qrpv-q767-xqq2)
web
Patched | CVE-2026-55255 | web | HIGH 8.4 | Patched | 2026-07-19 |
| Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)
KEV
EPSS 88% CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW)
network
Patched | CVE-2026-20230 | network | CRITICAL 8.6 | Patched | 2026-07-19 |
| Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)
KEV
EPSS 42% CVE-2026-48282 (Adobe APSB26-68)
web
Patched | CVE-2026-48282 | web | CRITICAL 10 | Patched | 2026-07-19 |
| SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)
KEV
RW
EPSS 84% CVE-2026-15409 (SNWLID-2026-0008)
network
Patched | CVE-2026-15409 | network | CRITICAL 10 | Patched | 2026-07-15 |
| OpenSSH Forwarded-Agent Lock/Unlock State Confusion → Unauthorized PKCS#11 Provider Load (No CVE)
network
Unpatched | — | network | HIGH | Unpatched | 2026-07-12 |
| Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8)
web
Patched | CVE-2026-56271 | web | CRITICAL 9.8 | Patched | 2026-07-12 |
| Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg)
web
Patched | CVE-2026-56260 | web | CRITICAL 9.1 | Patched | 2026-07-12 |
| ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)
KEV
EPSS 85% CVE-2023-38950
web
Patched | CVE-2023-38950 | web | HIGH 7.5 | Patched | 2026-07-11 |
| Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)
KEV
EPSS 20% CVE-2026-48939
web
Patched | CVE-2026-48939 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)
KEV
RW
EPSS 98% CVE-2021-42237 (Sitecore advisory SC2021-003-499266)
web
Patched | CVE-2021-42237 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)
KEV
EPSS 72% CVE-2021-25296
web
Patched | CVE-2021-25296 | web | HIGH 8.8 | Patched | 2026-07-11 |
| Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)
KEV
EPSS 57% CVE-2021-25297
web
Patched | CVE-2021-25297 | web | HIGH 8.8 | Patched | 2026-07-11 |
| Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)
KEV
EPSS 75% CVE-2021-25298
web
Patched | CVE-2021-25298 | web | HIGH 8.8 | Patched | 2026-07-11 |
| LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
KEV
EPSS 89% CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)
web
Patched | CVE-2026-42208 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4)
web
Patched | CVE-2026-20896 | web | CRITICAL 9.8 | Patched | 2026-07-11 |
| D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
KEV
EPSS 80% CVE-2022-26258
network
Unverified | CVE-2022-26258 | network | CRITICAL 9.8 | Unverified | 2026-07-11 |
| XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
network
Unpatched | — | network | CRITICAL | Unpatched | 2026-07-08 |
| Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)
CVE-2026-43499 (aka "GhostLock")
binary
Patched | CVE-2026-43499 | binary | HIGH 7.8 | Patched | 2026-07-08 |
| XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)
KEV
EPSS 100% CVE-2025-24893
web
Patched | CVE-2025-24893 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)
EPSS 15% CVE-2025-54322
network
Unpatched | CVE-2025-54322 | network | CRITICAL 10 | Unpatched | 2026-07-06 |
| Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856
hardware
Unverified | CVE-2025-65856 | hardware | CRITICAL 9.8 | Unverified | 2026-07-06 |
| WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170
web
Unpatched | CVE-2025-11170 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390
web
Patched | CVE-2025-13390 | web | CRITICAL 10 | Patched | 2026-07-06 |
| WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401
web
Unverified | CVE-2025-39401 | web | CRITICAL 10 | Unverified | 2026-07-06 |
| WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901
web
Patched | CVE-2025-49901 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
CVE-2025-5947
web
Unverified | CVE-2025-5947 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860
web
Unpatched | CVE-2025-68860 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)
EPSS 31% CVE-2025-6440
web
Unverified | CVE-2025-6440 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)
KEV
EPSS 93% CVE-2025-47812
web
Patched | CVE-2025-47812 | web | CRITICAL 10 | Patched | 2026-07-06 |
| Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009
web
Patched | CVE-2025-29009 | web | CRITICAL 10 | Patched | 2026-07-06 |
| WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057
web
Unverified | CVE-2025-12057 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315)
EPSS 33% CVE-2025-13315
network
Unpatched | CVE-2025-13315 | network | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539
web
Patched | CVE-2025-12539 | web | CRITICAL 10 | Patched | 2026-07-06 |
| tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416
cloud
Patched | CVE-2025-54416 | cloud | CRITICAL 9.1 | Patched | 2026-07-06 |
| ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888
web
Unverified | CVE-2025-63888 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
CVE-2025-34282
web
Patched | CVE-2025-34282 | web | CRITICAL 9.1 | Patched | 2026-07-06 |
| Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384
network
Unpatched | CVE-2025-29384 | network | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463)
KEV
EPSS 59% CVE-2025-32463
binary
Patched | CVE-2025-32463 | binary | CRITICAL 9.3 | Patched | 2026-07-06 |
| StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)
EPSS 39% CVE-2025-7441
web
Unpatched | CVE-2025-7441 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
EPSS 15% CVE-2025-48148
web
Unverified | CVE-2025-48148 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168)
EPSS 63% CVE-2025-62168
network
Patched | CVE-2025-62168 | network | CRITICAL 10 | Patched | 2026-07-06 |
| Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
CVE-2025-41243
web
Unpatched | CVE-2025-41243 | web | CRITICAL 10 | Unpatched | 2026-07-06 |
| Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)
EPSS 76% CVE-2025-6389
web
Unverified | CVE-2025-6389 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)
KEV
RW
EPSS 86% CVE-2025-52691
web
Patched | CVE-2025-52691 | web | CRITICAL 10 | Patched | 2026-07-06 |
| Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
CVE-2025-4334
web
Unverified | CVE-2025-4334 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580
web
Patched | CVE-2025-53580 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324)
KEV
RW
EPSS 100% CVE-2025-31324
web
Patched | CVE-2025-31324 | web | CRITICAL 10 | Patched | 2026-07-06 |
| Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)
KEV
EPSS 24% CVE-2025-4632
web
Patched | CVE-2025-4632 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735
misc
Patched | CVE-2025-12735 | misc | CRITICAL 9.8 | Patched | 2026-07-06 |
| RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)
EPSS 31% CVE-2025-68926
cloud
Patched | CVE-2025-68926 | cloud | CRITICAL 9.8 | Patched | 2026-07-06 |
| Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113)
KEV
EPSS 99% CVE-2025-49113
web
Patched | CVE-2025-49113 | web | CRITICAL 9.9 | Patched | 2026-07-06 |
| RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209
web
Unpatched | CVE-2025-9209 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)
EPSS 87% CVE-2025-49844
binary
Patched | CVE-2025-49844 | binary | CRITICAL 9.9 | Patched | 2026-07-06 |
| Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758
web
Unverified | CVE-2025-6758 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182)
KEV
RW
EPSS 100% CVE-2025-55182
web
Patched | CVE-2025-55182 | web | CRITICAL 10 | Patched | 2026-07-06 |
| React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)
KEV
EPSS 94% CVE-2025-11953
network
Patched | CVE-2025-11953 | network | CRITICAL 9.8 | Patched | 2026-07-06 |
| Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
CVE-2025-4517
misc
Patched | CVE-2025-4517 | misc | CRITICAL 9.4 | Patched | 2026-07-06 |
| Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)
EPSS 53% CVE-2025-49132
web
Patched | CVE-2025-49132 | web | CRITICAL 10 | Patched | 2026-07-06 |
| PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
CVE-2025-61922
web
Patched | CVE-2025-61922 | web | CRITICAL 9.1 | Patched | 2026-07-06 |
| PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391
web
Patched | CVE-2025-11391 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147
web
Unverified | CVE-2025-10147 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780
web
Unverified | CVE-2025-13780 | web | CRITICAL 9.1 | Unverified | 2026-07-06 |
| pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)
EPSS 54% CVE-2025-2945
web
Patched | CVE-2025-2945 | web | CRITICAL 9.9 | Patched | 2026-07-06 |
| Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757)
KEV
EPSS 88% CVE-2025-61757
web
Unpatched | CVE-2025-61757 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934)
EPSS 25% CVE-2025-6934
web
Unverified | CVE-2025-6934 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)
EPSS 73% CVE-2025-34299
network
Patched | CVE-2025-34299 | network | CRITICAL 9.8 | Patched | 2026-07-06 |
| Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061
web
Patched | CVE-2025-23061 | web | CRITICAL 9 | Patched | 2026-07-06 |
| Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
CVE-2025-52913
network
Unverified | CVE-2025-52913 | network | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068)
KEV
EPSS 96% CVE-2025-54068
web
Patched | CVE-2025-54068 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515
web
Patched | CVE-2025-27515 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966)
EPSS 34% CVE-2026-27966 (GHSA-3645-fxcv-hqr4)
web
Patched | CVE-2026-27966 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)
EPSS 78% CVE-2025-2294
web
Unverified | CVE-2025-2294 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674
web
Unverified | CVE-2025-12674 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
CVE-2025-14440
web
Unverified | CVE-2025-14440 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)
EPSS 84% CVE-2025-47916
web
Patched | CVE-2025-47916 | web | CRITICAL 10 | Patched | 2026-07-06 |
| IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)
EPSS 100% CVE-2025-1974
cloud
Unverified | CVE-2025-1974 | cloud | CRITICAL 9.8 | Unverified | 2026-07-06 |
| HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164)
KEV
EPSS 90% CVE-2025-37164
network
Unpatched | CVE-2025-37164 | network | CRITICAL 10 | Unpatched | 2026-07-06 |
| Hoverfly Middleware Command Injection to RCE (CVE-2025-54123)
EPSS 11% CVE-2025-54123
web
Patched | CVE-2025-54123 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115)
EPSS 19% CVE-2025-41115
web
Patched | CVE-2025-41115 | web | CRITICAL 10 | Patched | 2026-07-06 |
| Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)
KEV
EPSS 53% CVE-2025-14611
web
Unverified | CVE-2025-14611 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777
web
Patched | CVE-2025-22777 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342
web
Patched | CVE-2025-13342 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
KEV
EPSS 88% CVE-2025-57819
web
Patched | CVE-2025-57819 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039
network
Patched | CVE-2025-66039 | network | CRITICAL 9.8 | Patched | 2026-07-06 |
| Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156
web
Unverified | CVE-2025-14156 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)
KEV
EPSS 92% CVE-2025-64446
network
Unverified | CVE-2025-64446 | network | CRITICAL 9.8 | Unverified | 2026-07-06 |
| FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)
KEV
EPSS 69% CVE-2025-59718 (Fortinet advisory FG-IR-25-647; related: CVE-2025-59719)
network
Patched | CVE-2025-59718 | network | CRITICAL 9.8 | Patched | 2026-07-06 |
| Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071
web
Unverified | CVE-2025-49071 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
EPSS 50% CVE-2025-58434
web
Patched | CVE-2025-58434 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
EPSS 87% CVE-2025-59528
web
Patched | CVE-2025-59528 | web | CRITICAL 10 | Patched | 2026-07-06 |
| FiberHome HG6145F1 Predictable Default Wi-Fi PSK Derived from Broadcast SSID (CVE-2025-63353)
CVE-2025-63353 / GHSA-cg2x-c25f-6327
network
Patched | CVE-2025-63353 / GHSA-cg2x-c25f-6327 | network | CRITICAL 9.8 | Patched | 2026-07-06 |
| Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)
CVE-2025-54957
binary
Unverified | CVE-2025-54957 | binary | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459)
EPSS 19% CVE-2025-64459
web
Patched | CVE-2025-64459 | web | CRITICAL 9.1 | Patched | 2026-07-06 |
| DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002)
EPSS 47% CVE-2025-49002
web
Patched | CVE-2025-49002 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854
network
Patched | CVE-2025-60854 | network | CRITICAL 9.8 | Patched | 2026-07-06 |
| CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309)
KEV
EPSS 95% CVE-2025-54309
web
Patched | CVE-2025-54309 | web | CRITICAL 9 | Patched | 2026-07-06 |
| Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)
CVE-2025-14700
web
Unverified | CVE-2025-14700 | web | CRITICAL 9.9 | Unverified | 2026-07-06 |
| ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)
CVE-2025-11492
network
Patched | CVE-2025-11492 | network | CRITICAL 9.6 | Patched | 2026-07-06 |
| Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393)
KEV
EPSS 30% CVE-2025-20393
network
Unverified | CVE-2025-20393 | network | CRITICAL 10 | Unverified | 2026-07-06 |
| Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)
KEV
EPSS 71% CVE-2025-20333
network
Unverified | CVE-2025-20333 | network | CRITICAL 9.9 | Unverified | 2026-07-06 |
| Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595
web
Unverified | CVE-2025-13595 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
CVE-2026-33453
web
Unverified | CVE-2026-33453 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315)
EPSS 66% CVE-2025-55315
network
Patched | CVE-2025-55315 | network | CRITICAL 9.9 | Patched | 2026-07-06 |
| Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065)
EPSS 43% CVE-2025-30065
misc
Patched | CVE-2025-30065 | misc | CRITICAL 9.8 | Patched | 2026-07-06 |
| Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)
CVE-2025-23048
web
Patched | CVE-2025-23048 | web | CRITICAL 9.1 | Patched | 2026-07-06 |
| Apache Druid Kerberos Cookie-Signing Secret Recovery via ThreadLocalRandom Seed Inversion (CVE-2025-59390)
CVE-2025-59390
crypto
Patched | CVE-2025-59390 | crypto | CRITICAL 9.8 | Patched | 2026-07-06 |
| Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)
CVE-2026-27172
web
Patched | CVE-2026-27172 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597
web
Unverified | CVE-2025-13597 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749)
EPSS 75% CVE-2025-11749
web
Unverified | CVE-2025-11749 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)
KEV
EPSS 95% CVE-2025-54236
web
Patched | CVE-2025-54236 | web | CRITICAL 9.1 | Patched | 2026-07-06 |
| Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253)
KEV
EPSS 88% CVE-2025-54253
web
Unverified | CVE-2025-54253 | web | CRITICAL 10 | Unverified | 2026-07-06 |
| ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486)
EPSS 68% CVE-2025-13486
web
Unverified | CVE-2025-13486 | web | CRITICAL 9.8 | Unverified | 2026-07-06 |
| "Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354
web
Unpatched | CVE-2025-65354 | web | CRITICAL 9.8 | Unpatched | 2026-07-06 |
| Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
CVE-2026-1459
network
Unverified | CVE-2026-1459 | network | HIGH | Unverified | 2026-07-05 |
| ZXIC/Sanechips ZX297520V3 BootROM Arbitrary Memory Write via USB Download Mode (CVE-2026-40003)
CVE-2026-40003
hardware
Unverified | CVE-2026-40003 | hardware | HIGH | Unverified | 2026-07-05 |
| ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)
EPSS 25% CVE-2026-34474
network
Unverified | CVE-2026-34474 | network | HIGH | Unverified | 2026-07-05 |
| ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472
network
Unverified | CVE-2026-34472 | network | CRITICAL | Unverified | 2026-07-05 |
| ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473
network
Unverified | CVE-2026-34473 | network | HIGH | Unverified | 2026-07-05 |
| ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
CVE-2026-27470
web
Patched | CVE-2026-27470 | web | HIGH 8.8 | Patched | 2026-07-05 |
| ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
CVE-2026-28286
web
Unverified | CVE-2026-28286 | web | CRITICAL | Unverified | 2026-07-05 |
| ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
CVE-2026-25807
network
Patched | CVE-2026-25807 | network | CRITICAL | Patched | 2026-07-05 |
| YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937
web
Unverified | CVE-2026-1937 | web | HIGH 7.2 | Unverified | 2026-07-05 |
| YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)
CVE-2026-44595 / GHSA-p2rj-mrmc-9w29
web
Patched | CVE-2026-44595 / GHSA-p2rj-mrmc-9w29 | web | MEDIUM 4.3 | Patched | 2026-07-05 |
| YAMCS Missing Rate Limiting on Authentication Endpoint (CVE-2026-44596)
CVE-2026-44596 / GHSA-w5r6-mcgq-7pq4
web
Patched | CVE-2026-44596 / GHSA-w5r6-mcgq-7pq4 | web | MEDIUM 5.3 | Patched | 2026-07-05 |
| YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)
CVE-2026-42568 / GHSA-cqh3-jg8p-336j
network
Patched | CVE-2026-42568 / GHSA-cqh3-jg8p-336j | network | MEDIUM | Patched | 2026-07-05 |
| XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
CVE-2026-33137
web
Patched | CVE-2026-33137 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)
CVE-2026-20698
binary
Patched | CVE-2026-20698 | binary | HIGH | Patched | 2026-07-05 |
| XIGNCODE3 Anti-Cheat Driver PPL-Bypass LSASS Credential Dump (CVE-2026-3609)
CVE-2026-3609
binary
Patched | CVE-2026-3609 | binary | HIGH | Patched | 2026-07-05 |
| Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912
web
Patched | CVE-2026-39912 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)
CVE-2026-38698
network
Unverified | CVE-2026-38698 | network | CRITICAL | Unverified | 2026-07-05 |
| WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)
EPSS 33% CVE-2026-1357
web
Unverified | CVE-2026-1357 | web | CRITICAL | Unverified | 2026-07-05 |
| WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
CVE-2026-49105
web
Unverified | CVE-2026-49105 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
CVE-2026-40791
web
Patched | CVE-2026-40791 | web | HIGH 7.2 | Patched | 2026-07-05 |
| WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379
web
Patched | CVE-2026-6379 | web | CRITICAL 8.6 | Patched | 2026-07-05 |
| WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
CVE-2026-49085
web
Unverified | CVE-2026-49085 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415
web
Unverified | CVE-2026-5415 | web | HIGH 8.8 | Unverified | 2026-07-05 |
| WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
CVE-2026-54806
web
Patched | CVE-2026-54806 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| WordPress User Language Switch Plugin SSRF — CVE-2026-0745
CVE-2026-0745 (GHSA-m38c-5p3m-p7gm)
web
Unverified | CVE-2026-0745 | web | MEDIUM | Unverified | 2026-07-05 |
| WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
CVE-2026-12416, CVE-2026-12417
web
Unverified | CVE-2026-12416, CVE-2026-12417 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740
EPSS 63% CVE-2026-0740
web
Unverified | CVE-2026-0740 | web | HIGH | Unverified | 2026-07-05 |
| WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)
CVE-2026-4106
web
Unverified | CVE-2026-4106 | web | HIGH | Unverified | 2026-07-05 |
| WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
CVE-2026-39676
web
Unverified | CVE-2026-39676 | web | MEDIUM | Unverified | 2026-07-05 |
| WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180
web
Unverified | CVE-2026-3180 | web | HIGH | Unverified | 2026-07-05 |
| WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844)
EPSS 28% CVE-2026-3844
web
Unverified | CVE-2026-3844 | web | CRITICAL | Unverified | 2026-07-05 |
| WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)
CVE-2026-0594
web
Unverified | CVE-2026-0594 | web | MEDIUM | Unverified | 2026-07-05 |
| WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
CVE-2026-3629
web
Unverified | CVE-2026-3629 | web | CRITICAL | Unverified | 2026-07-05 |
| WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
CVE-2026-3359
web
Unverified | CVE-2026-3359 | web | CRITICAL | Unverified | 2026-07-05 |
| WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364
web
Unverified | CVE-2026-5364 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540)
web
Unverified | CVE-2026-27542 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807
web
Unverified | CVE-2026-54807 | web | INFO | Unverified | 2026-07-05 |
| Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)
CVE-2026-44403
web
Patched | CVE-2026-44403 | web | HIGH | Patched | 2026-07-05 |
| Windows ShellLink (.lnk) Remote Code Execution — CVE-2026-21510 LNK-Stomping Generator
KEV
EPSS 26% CVE-2026-21510
social-engineering
Unverified | CVE-2026-21510 | social-engineering | HIGH | Unverified | 2026-07-05 |
| Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202
KEV
EPSS 64% CVE-2026-32202 (related: CVE-2026-21510)
binary
Unverified | CVE-2026-32202 | binary | HIGH | Unverified | 2026-07-05 |
| Windows Server 2025 Local NTLM Reflection LPE via SMB Arbitrary Port + PetitPotam (CVE-2026-24294)
CVE-2026-24294 (Microsoft Security Response Center)
network
Patched | CVE-2026-24294 | network | CRITICAL | Patched | 2026-07-05 |
| Windows Secure Kernel (VTL1/VSM) Memory Corruption PoC (CVE-2026-26179 / ZDI-26-276)
CVE-2026-26179 / ZDI-26-276
binary
Unverified | CVE-2026-26179 / ZDI-26-276 | binary | HIGH | Unverified | 2026-07-05 |
| Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)
CVE-2026-42978
binary
Unverified | CVE-2026-42978 | binary | HIGH 7.8 | Unverified | 2026-07-05 |
| Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923
CVE-2026-29923
binary
Unverified | CVE-2026-29923 | binary | CRITICAL | Unverified | 2026-07-05 |
| Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)
CVE-2026-40369
binary
Unverified | CVE-2026-40369 | binary | HIGH | Unverified | 2026-07-05 |
| Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)
CVE-2026-26128
network
Unverified | CVE-2026-26128 | network | CRITICAL | Unverified | 2026-07-05 |
| Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824
KEV
EPSS 73% CVE-2026-33824
network
Patched | CVE-2026-33824 | network | CRITICAL | Patched | 2026-07-05 |
| Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)
EPSS 54% CVE-2026-49160
binary
Patched | CVE-2026-49160 | binary | HIGH | Patched | 2026-07-05 |
| Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)
CVE-2026-20817
binary
Unverified | CVE-2026-20817 | binary | HIGH | Unverified | 2026-07-05 |
| Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)
CVE-2026-2636
binary
Patched | CVE-2026-2636 | binary | MEDIUM | Patched | 2026-07-05 |
| WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)
CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp
web
Patched | CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp | web | HIGH | Patched | 2026-07-05 |
| WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555
web
Unverified | CVE-2026-1555 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| WebSocket Authentication Brute-Force via Missing Rate Limiting (CVE-2026-27778)
CVE-2026-27778
web
Patched | CVE-2026-27778 | web | MEDIUM | Patched | 2026-07-05 |
| Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126
web
Patched | CVE-2026-24126 | web | HIGH 6.5 | Patched | 2026-07-05 |
| WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)
CVE-2026-43700
web
Unverified | CVE-2026-43700 | web | HIGH | Unverified | 2026-07-05 |
| WebKit Navigation API Cross-Port canIntercept Bypass (CVE-2026-20643)
CVE-2026-20643
web
Unverified | CVE-2026-20643 | web | MEDIUM | Unverified | 2026-07-05 |
| WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)
CVE-2026-43735
web
Unverified | CVE-2026-43735 | web | HIGH | Unverified | 2026-07-05 |
| VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615
CVE-2026-5615
web
Patched | CVE-2026-5615 | web | HIGH 8.5 | Patched | 2026-07-05 |
| Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748
web
Unverified | CVE-2026-37748 | web | HIGH 7.2 | Unverified | 2026-07-05 |
| VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)
CVE-2026-35250
binary
Unverified | CVE-2026-35250 | binary | LOW 2.3 | Unverified | 2026-07-05 |
| Vim Modeline `path` Option Backtick-Expansion Command Injection (CVE-2026-44656)
CVE-2026-44656
binary
Patched | CVE-2026-44656 | binary | HIGH | Patched | 2026-07-05 |
| Veno File Manager Unauthenticated User Enumeration (CVE-2026-37064)
CVE-2026-37064
web
Unverified | CVE-2026-37064 | web | MEDIUM | Unverified | 2026-07-05 |
| Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
CVE-2026-37066
web
Unverified | CVE-2026-37066 | web | HIGH | Unverified | 2026-07-05 |
| Veno File Manager Incorrect Access Control — Application Log Extraction (CVE-2026-37067)
CVE-2026-37067
web
Unverified | CVE-2026-37067 | web | MEDIUM | Unverified | 2026-07-05 |
| Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
CVE-2026-37068
web
Unverified | CVE-2026-37068 | web | CRITICAL | Unverified | 2026-07-05 |
| Veno File Manager Arbitrary File Deletion (CVE-2026-37065)
CVE-2026-37065
web
Unverified | CVE-2026-37065 | web | HIGH | Unverified | 2026-07-05 |
| Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
CVE-2026-37069
web
Unverified | CVE-2026-37069 | web | LOW | Unverified | 2026-07-05 |
| Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
CVE-2026-37072
web
Unverified | CVE-2026-37072 | web | CRITICAL | Unverified | 2026-07-05 |
| Veno File Manager 4.4.9 — Unauthenticated Email Hijack via SMTP Relay (CVE-2026-37073)
CVE-2026-37073
web
Unverified | CVE-2026-37073 | web | MEDIUM | Unverified | 2026-07-05 |
| Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)
CVE-2026-37070
web
Unverified | CVE-2026-37070 | web | MEDIUM | Unverified | 2026-07-05 |
| Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)
CVE-2026-37071
web
Unverified | CVE-2026-37071 | web | HIGH | Unverified | 2026-07-05 |
| Vendure GraphQL Admin API Authentication Timing Attack / User Enumeration (CVE-2026-25050)
CVE-2026-25050
web
Patched | CVE-2026-25050 | web | MEDIUM | Patched | 2026-07-05 |
| Vaultwarden Organization Collection Permissions Bypass & Cipher Enumeration (CVE-2026-26012)
CVE-2026-26012 (GHSA-h265-g7rm-h337)
web
Patched | CVE-2026-26012 | web | MEDIUM 6.5 | Patched | 2026-07-05 |
| V8 JavaScript Engine Exploit — "Longinus" Kit (CVE-2026-6307)
CVE-2026-6307
binary
Unverified | CVE-2026-6307 | binary | CRITICAL | Unverified | 2026-07-05 |
| User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882
web
Unverified | CVE-2026-4882 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492)
EPSS 24% CVE-2026-1492
web
Unverified | CVE-2026-1492 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| User Registration & Membership for WordPress — Unauthenticated Admin Approval Bypass (CVE-2026-6145)
CVE-2026-6145
web
Unverified | CVE-2026-6145 | web | MEDIUM 5.3 | Unverified | 2026-07-05 |
| UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
CVE-2026-10795
web
Unverified | CVE-2026-10795 | web | CRITICAL | Unverified | 2026-07-05 |
| UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
CVE-2026-36851
misc
Unverified | CVE-2026-36851 | misc | HIGH 7.5 | Unverified | 2026-07-05 |
| Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
CVE-2026-35037
web
Patched | CVE-2026-35037 | web | HIGH | Patched | 2026-07-05 |
| Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)
CVE-2026-36522
network
Unverified | CVE-2026-36522 | network | CRITICAL 9.1 | Unverified | 2026-07-05 |
| TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)
CVE-2026-27621 (GHSA-xfvg-8v67-j7wp)
web
Patched | CVE-2026-27621 | web | MEDIUM | Patched | 2026-07-05 |
| Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
CVE-2026-33712
web
Patched | CVE-2026-33712 | web | HIGH | Patched | 2026-07-05 |
| TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653)
network
Unverified | CVE-2026-0651 | network | CRITICAL | Unverified | 2026-07-05 |
| TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834
network
Unverified | CVE-2026-11834 | network | CRITICAL | Unverified | 2026-07-05 |
| TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)
CVE-2026-8697
network
Unverified | CVE-2026-8697 | network | CRITICAL 9.3 | Unverified | 2026-07-05 |
| Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)
CVE-2026-7671
web
Unverified | CVE-2026-7671 | web | MEDIUM | Unverified | 2026-07-05 |
| Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
CVE-2026-41901
web
Patched | CVE-2026-41901 | web | CRITICAL | Patched | 2026-07-05 |
| The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772
web
Patched | CVE-2026-49772 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)
CVE-2026-22804 (GHSA-m3cv-5hgp-hv35)
web
Patched | CVE-2026-22804 | web | HIGH | Patched | 2026-07-05 |
| Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499
network
Unverified | CVE-2026-11499 | network | HIGH | Unverified | 2026-07-05 |
| Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)
CVE-2026-38426
network
Patched | CVE-2026-38426 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
CVE-2026-38427
network
Patched | CVE-2026-38427 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)
CVE-2026-38422
network
Patched | CVE-2026-38422 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| TanStack Query — Unbounded Recursion Denial of Service in `replaceEqualDeep` (CVE-2026-26903)
CVE-2026-26903
web
Patched | CVE-2026-26903 | web | MEDIUM | Patched | 2026-07-05 |
| Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 (GHSA-6485-jr28-52xx)
web
Patched | CVE-2026-25964 | web | MEDIUM 4.9 | Patched | 2026-07-05 |
| Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
CVE-2026-11417
cloud
Patched | CVE-2026-11417 | cloud | HIGH 3.1 | Patched | 2026-07-05 |
| strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)
CVE-2026-35333
network
Unverified | CVE-2026-35333 | network | MEDIUM | Unverified | 2026-07-05 |
| strongSwan EAP-SIM/EAP-AKA Pre-Auth Heap Buffer Overflow via Integer Underflow (CVE-2026-35330)
CVE-2026-35330
network
Unverified | CVE-2026-35330 | network | HIGH | Unverified | 2026-07-05 |
| Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
CVE-2026-27886
web
Patched | CVE-2026-27886 | web | CRITICAL | Patched | 2026-07-05 |
| Spring Security Lazy Header Writing Security Header Bypass (CVE-2026-22732)
CVE-2026-22732
web
Patched | CVE-2026-22732 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
CVE-2026-22738
web
Patched | CVE-2026-22738 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251)
EPSS 32% CVE-2026-20251
web
Unverified | CVE-2026-20251 | web | HIGH 8.8 | Unverified | 2026-07-05 |
| Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
CVE-2026-32604 (CWE-78)
cloud
Patched | CVE-2026-32604 | cloud | CRITICAL 10 | Patched | 2026-07-05 |
| Spectra Gutenberg Blocks Authenticated Remote Code Execution — CVE-2026-7465
CVE-2026-7465
web
Unverified | CVE-2026-7465 | web | CRITICAL 8.8 | Unverified | 2026-07-05 |
| Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
CVE-2026-42096
network
Unverified | CVE-2026-42096 | network | CRITICAL | Unverified | 2026-07-05 |
| SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh)
web
Patched | CVE-2026-48909 | web | CRITICAL 9.5 | Patched | 2026-07-05 |
| SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
CVE-2026-4112 (SonicWall Advisory SNWLID-2026-0003)
network
Unverified | CVE-2026-4112 | network | HIGH 7.2 | Unverified | 2026-07-05 |
| Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)
EPSS 12% CVE-2026-1056
web
Unverified | CVE-2026-1056 | web | CRITICAL | Unverified | 2026-07-05 |
| snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)
CVE-2026-3888
binary
Patched | CVE-2026-3888 | binary | HIGH | Patched | 2026-07-05 |
| SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
CVE-2026-0001 (tracked publicly as WT-2026-0001)
web
Patched | CVE-2026-0001 | web | CRITICAL 9 | Patched | 2026-07-05 |
| SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423
KEV
RW
EPSS 88% CVE-2026-24423
web
Unverified | CVE-2026-24423 | web | CRITICAL | Unverified | 2026-07-05 |
| SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)
KEV
RW
EPSS 96% CVE-2026-23760
web
Patched | CVE-2026-23760 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| Sliver C2 Server mTLS Nil-Pointer Panic / Infrastructure Kill-Switch — CVE-2026-29781
CVE-2026-29781 (GHSA-hx52-cv84-jr5v)
network
Unverified | CVE-2026-29781 | network | HIGH | Unverified | 2026-07-05 |
| Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
CVE-2026-34227 (GHSA-6fpf-248c-m7wm)
web
Unverified | CVE-2026-34227 | web | HIGH | Unverified | 2026-07-05 |
| SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)
KEV
EPSS 12% CVE-2026-48558
web
Patched | CVE-2026-48558 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459
web
Unverified | CVE-2026-7459 | web | HIGH 7.5 | Unverified | 2026-07-05 |
| Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912
web
Patched | CVE-2026-11912 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
CVE-2026-23498
web
Patched | CVE-2026-23498 | web | HIGH | Patched | 2026-07-05 |
| Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
CVE-2026-44590
cloud
Patched | CVE-2026-44590 | cloud | CRITICAL 9.3 | Patched | 2026-07-05 |
| Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951
CVE-2026-30951
web
Patched | CVE-2026-30951 | web | HIGH | Patched | 2026-07-05 |
| sealed-env Unseal Token TOTP/Enterprise Secret Disclosure (CVE-2026-45091)
CVE-2026-45091
crypto
Patched | CVE-2026-45091 | crypto | HIGH | Patched | 2026-07-05 |
| School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
CVE-2026-37750
web
Unverified | CVE-2026-37750 | web | MEDIUM 6.1 | Unverified | 2026-07-05 |
| Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
CVE-2026-9067
web
Unverified | CVE-2026-9067 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)
CVE-2026-21018 (Samsung SVE-2026-0478, SMR May 2026)
binary
Unverified | CVE-2026-21018 | binary | HIGH | Unverified | 2026-07-05 |
| Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)
CVE-2026-20980 (chained with CVE-2026-20981 and CVE-2026-20982)
binary
Unverified | CVE-2026-20980 | binary | CRITICAL | Unverified | 2026-07-05 |
| samlify SAML AttributeValue XML Injection → Privilege Escalation (CVE-2026-46490)
CVE-2026-46490 / GHSA-34r5-q4jw-r36m
web
Patched | CVE-2026-46490 / GHSA-34r5-q4jw-r36m | web | HIGH 8.8 | Patched | 2026-07-05 |
| Samba spoolss Print Job Command Injection RCE (CVE-2026-4480)
EPSS 14% CVE-2026-4480
network
Patched | CVE-2026-4480 | network | CRITICAL | Patched | 2026-07-05 |
| Saleor Stored XSS via Unrestricted File Upload (CVE-2026-23499)
CVE-2026-23499
web
Patched | CVE-2026-23499 | web | HIGH | Patched | 2026-07-05 |
| Saleor Rich Text (EditorJS) Field Stored XSS (CVE-2026-22849)
CVE-2026-22849 (GHSA-8jcj-r5g2-qrpv)
web
Patched | CVE-2026-22849 | web | HIGH | Patched | 2026-07-05 |
| Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
CVE-2026-24136
web
Patched | CVE-2026-24136 | web | HIGH 7.5 | Patched | 2026-07-05 |
| RustFS — Presigned POST Policy Condition Bypass (CVE-2026-27607)
CVE-2026-27607 (GHSA-w5fh-f8xh-5x3p)
cloud
Patched | CVE-2026-27607 | cloud | HIGH | Patched | 2026-07-05 |
| RTF Protected-View Bypass (CVE-2026-21514) Chained with ShellLink RCE (CVE-2026-21510) — Builder Scripts
KEV CVE-2026-21514, CVE-2026-21510
social-engineering
Unverified | CVE-2026-21514, CVE-2026-21510 | social-engineering | HIGH | Unverified | 2026-07-05 |
| Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
CVE-2026-29198
web
Patched | CVE-2026-29198 | web | CRITICAL | Patched | 2026-07-05 |
| rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)
CVE-2026-27831
binary
Patched | CVE-2026-27831 | binary | MEDIUM | Patched | 2026-07-05 |
| Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
CVE-2026-39023
web
Unpatched | CVE-2026-39023 | web | CRITICAL | Unpatched | 2026-07-05 |
| Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
CVE-2026-4802
web
Unpatched | CVE-2026-4802 | web | HIGH | Unpatched | 2026-07-05 |
| Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)
CVE-2026-27579 (GHSA-qh5m-p8jh-hx88)
web
Unverified | CVE-2026-27579 | web | HIGH 7.4 | Unverified | 2026-07-05 |
| Realtek rtl819x Jungle SDK Unauthenticated Kernel Memory R/W via Debug IOCTLs (CVE-2026-36355)
CVE-2026-36355
network
Unverified | CVE-2026-36355 | network | CRITICAL | Unverified | 2026-07-05 |
| rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
CVE-2026-41179
web
Patched | CVE-2026-41179 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Rapid7 Nexpose Weak Keystore Entropy Credential Decryption — CVE-2026-1814
CVE-2026-1814
misc
Unverified | CVE-2026-1814 | misc | HIGH | Unverified | 2026-07-05 |
| Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)
CVE-2026-39324 / GHSA-33qg-7wpp-89cq
web
Patched | CVE-2026-39324 / GHSA-33qg-7wpp-89cq | web | CRITICAL | Patched | 2026-07-05 |
| pypdf Circular Outline Reference Infinite-Loop DoS (CVE-2026-24688)
CVE-2026-24688
misc
Patched | CVE-2026-24688 | misc | HIGH | Patched | 2026-07-05 |
| PX4-Autopilot tattu_can Driver — CAN Bus Stack Buffer Overflow DoS (CVE-2026-32707)
CVE-2026-32707 (GHSA-wxwm-xmx9-hr32, CWE-121)
hardware
Patched | CVE-2026-32707 | hardware | HIGH 7.5 | Patched | 2026-07-05 |
| PX4 Autopilot MAVLink FTP Stack Buffer Overflow (CVE-2026-32743)
CVE-2026-32743
hardware
Patched | CVE-2026-32743 | hardware | MEDIUM 6.5 | Patched | 2026-07-05 |
| psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
CVE-2026-31900 (GHSA-v53h-f6m7-xcgm)
misc
Patched | CVE-2026-31900 | misc | HIGH 8.7 | Patched | 2026-07-05 |
| ProjeQtor Unauthenticated Login SQL Injection (CVE-2026-41462)
CVE-2026-41462
web
Patched | CVE-2026-41462 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167
network
Patched | CVE-2026-42167 | network | HIGH 8.1 | Patched | 2026-07-05 |
| Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
CVE-2026-0926
web
Unverified | CVE-2026-0926 | web | HIGH | Unverified | 2026-07-05 |
| Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a)
web
Patched | CVE-2026-5366 | web | HIGH | Patched | 2026-07-05 |
| PraisonAI API Server Missing Authentication (CVE-2026-44338)
EPSS 29% CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6rmh-7xcm-cpxj)
web
Patched | CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj] | web | HIGH | Patched | 2026-07-05 |
| Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
CVE-2026-40487 / GHSA-44wg-r34q-hvfx
web
Patched | CVE-2026-40487 / GHSA-44wg-r34q-hvfx | web | HIGH 8.9 | Patched | 2026-07-05 |
| PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005
CVE-2026-2005
binary
Unverified | CVE-2026-2005 | binary | CRITICAL | Unverified | 2026-07-05 |
| Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)
CVE-2026-3437
binary
Unverified | CVE-2026-3437 | binary | HIGH | Unverified | 2026-07-05 |
| PolarLearn Forum Vote Count Manipulation (CVE-2026-25126)
CVE-2026-25126
web
Patched | CVE-2026-25126 | web | MEDIUM | Patched | 2026-07-05 |
| PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w)
web
Patched | CVE-2026-44166 / [GHSA-pq7p-mc74-g65w] | web | MEDIUM 6.1 | Patched | 2026-07-05 |
| Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
CVE-2026-32096
cloud
Patched | CVE-2026-32096 | cloud | CRITICAL 9.3 | Patched | 2026-07-05 |
| PJSIP DNS Compression Pointer Heap Out-of-Bounds Read (CVE-2026-32945)
CVE-2026-32945
network
Patched | CVE-2026-32945 | network | MEDIUM | Patched | 2026-07-05 |
| PJSIP / PJNATH ICE Session Stack Buffer Overflow via SDP ice-ufrag (CVE-2026-25994)
CVE-2026-25994
network
Patched | CVE-2026-25994 | network | HIGH | Patched | 2026-07-05 |
| Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885
web
Unverified | CVE-2026-4885 | web | CRITICAL | Unverified | 2026-07-05 |
| PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)
CVE-2026-43494
binary
Patched | CVE-2026-43494 | binary | HIGH | Patched | 2026-07-05 |
| phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
CVE-2026-42569
web
Patched | CVE-2026-42569 | web | CRITICAL | Patched | 2026-07-05 |
| phpSysInfo IP Allowlist Bypass via X-Forwarded-For Spoofing — CVE-2026-55584
CVE-2026-55584 / GHSA-786w-p5pm-cvgh
web
Patched | CVE-2026-55584 / GHSA-786w-p5pm-cvgh | web | HIGH 7.5 | Patched | 2026-07-05 |
| PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664
CVE-2026-6664
network
Patched | CVE-2026-6664 | network | HIGH | Patched | 2026-07-05 |
| Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350
web
Unverified | CVE-2026-4350 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212
web
Patched | CVE-2026-25212 | web | CRITICAL 9.9 | Patched | 2026-07-05 |
| pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801
web
Patched | CVE-2026-26801 | web | HIGH | Patched | 2026-07-05 |
| PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239
web
Unverified | CVE-2026-36239 | web | CRITICAL | Unverified | 2026-07-05 |
| Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)
CVE-2026-14459 (also covers CVE-2026-14460)
binary
Patched | CVE-2026-14459 | binary | HIGH 8.8 | Patched | 2026-07-05 |
| PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)
CVE-2026-41651
binary
Patched | CVE-2026-41651 | binary | HIGH | Patched | 2026-07-05 |
| pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
CVE-2026-29000
web
Patched | CVE-2026-29000 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876)
EPSS 14% CVE-2026-21876
web
Patched | CVE-2026-21876 | web | CRITICAL | Patched | 2026-07-05 |
| OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940
cloud
Patched | CVE-2026-34940 | cloud | HIGH 8.7 | Patched | 2026-07-05 |
| Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)
CVE-2026-23947
misc
Patched | CVE-2026-23947 | misc | HIGH | Patched | 2026-07-05 |
| oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)
CVE-2026-33331 (GHSA-7f6v-3gx7-27q8)
web
Patched | CVE-2026-33331 | web | HIGH | Patched | 2026-07-05 |
| Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr)
web
Patched | CVE-2026-26198 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Oracle VirtualBox Shared Folders Kernel Memory Exhaustion DoS (CVE-2026-21986)
CVE-2026-21986
binary
Patched | CVE-2026-21986 | binary | MEDIUM 7.1 | Patched | 2026-07-05 |
| OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
CVE-2026-45777
web
Patched | CVE-2026-45777 | web | CRITICAL | Patched | 2026-07-05 |
| OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
EPSS 26% CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj)
web
Unverified | CVE-2026-0766 | web | HIGH 8.8 | Unverified | 2026-07-05 |
| OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
CVE-2026-24418
web
Patched | CVE-2026-24418 | web | HIGH 8.8 | Patched | 2026-07-05 |
| OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)
CVE-2026-24415 (GHSA-jfgp-g7x7-j25j)
web
Patched | CVE-2026-24415 | web | MEDIUM | Patched | 2026-07-05 |
| OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
CVE-2026-24419
web
Patched | CVE-2026-24419 | web | HIGH | Patched | 2026-07-05 |
| OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417
CVE-2026-24417
web
Patched | CVE-2026-24417 | web | HIGH | Patched | 2026-07-05 |
| OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
CVE-2026-24416
web
Patched | CVE-2026-24416 | web | HIGH | Patched | 2026-07-05 |
| OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
CVE-2026-39842 / GHSA-7mqr-33rv-p3mp
web
Patched | CVE-2026-39842 / GHSA-7mqr-33rv-p3mp | web | CRITICAL 10 | Patched | 2026-07-05 |
| OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156
CVE-2026-31156
hardware
Unverified | CVE-2026-31156 | hardware | HIGH | Unverified | 2026-07-05 |
| OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw)
cloud
Patched | CVE-2026-41900 | cloud | HIGH 8.6 | Patched | 2026-07-05 |
| OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
CVE-2026-24849
web
Patched | CVE-2026-24849 | web | CRITICAL 6.5 | Patched | 2026-07-05 |
| OpenCode Unauthenticated Local HTTP Server -> Remote Code Execution (CVE-2026-22812)
EPSS 17% CVE-2026-22812 (GHSA-vxw4-wv6m-9hhh)
web
Patched | CVE-2026-22812 | web | HIGH 8.8 | Patched | 2026-07-05 |
| OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
CVE-2026-28466
network
Patched | CVE-2026-28466 | network | CRITICAL | Patched | 2026-07-05 |
| OpenBSD slaacd/rad Infinite Loop via Malformed ND Option (CVE-2026-41285)
CVE-2026-41285
network
Patched | CVE-2026-41285 | network | HIGH | Patched | 2026-07-05 |
| OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439)
EPSS 10% CVE-2026-33439
web
Patched | CVE-2026-33439 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Open WebUI SSRF via HTTP Redirect Bypass of validate_url() (CVE-2026-45401)
CVE-2026-45401
web
Patched | CVE-2026-45401 | web | HIGH | Patched | 2026-07-05 |
| OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)
CVE-2026-33317 (GHSA-8cqw-mg7v-c9p9)
binary
Patched | CVE-2026-33317 | binary | HIGH 8.7 | Patched | 2026-07-05 |
| Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482
CVE-2026-7482
misc
Patched | CVE-2026-7482 | misc | MEDIUM | Patched | 2026-07-05 |
| OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
CVE-2026-27626 / GHSA-49gm-hh7w-wfvf
web
Unverified | CVE-2026-27626 / GHSA-49gm-hh7w-wfvf | web | CRITICAL 9.9 | Unverified | 2026-07-05 |
| NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only)
network
Patched | CVE-2026-24207 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| npm `tar` Package Unicode-Normalization Race Condition / File Collision (CVE-2026-2395)
CVE-2026-2395
misc
Unverified | CVE-2026-2395 | misc | MEDIUM | Unverified | 2026-07-05 |
| Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008
CVE-2026-3008
binary
Unverified | CVE-2026-3008 | binary | MEDIUM | Unverified | 2026-07-05 |
| Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242
web
Patched | CVE-2026-41242 | web | CRITICAL | Patched | 2026-07-05 |
| Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
CVE-2026-29786
misc
Patched | CVE-2026-29786 | misc | HIGH | Patched | 2026-07-05 |
| node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
CVE-2026-23745 / GHSA-8qq5-rm4j-mr97
misc
Patched | CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 | misc | HIGH | Patched | 2026-07-05 |
| Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
CVE-2026-34200 (GHSA-6c5x-3h35-vvw2)
web
Patched | CVE-2026-34200 | web | CRITICAL 9.6 | Patched | 2026-07-05 |
| nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
CVE-2026-40701
web
Patched | CVE-2026-40701 | web | MEDIUM 6.3 | Patched | 2026-07-05 |
| Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability)
web
Unverified | CVE-2026-0211 | web | HIGH | Unverified | 2026-07-05 |
| nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift")
web
Unverified | CVE-2026-9256 | web | CRITICAL | Unverified | 2026-07-05 |
| NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926
web
Patched | CVE-2026-42926 | web | HIGH | Patched | 2026-07-05 |
| Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh)
web
Patched | CVE-2026-53519 | web | INFO | Patched | 2026-07-05 |
| NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)
CVE-2026-3228
web
Unverified | CVE-2026-3228 | web | MEDIUM 6.4 | Unverified | 2026-07-05 |
| Nextcloud user_oidc ID4me JWT Signature Bypass (CVE-2026-45156)
CVE-2026-45156
web
Patched | CVE-2026-45156 | web | HIGH 8.1 | Patched | 2026-07-05 |
| Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
CVE-2026-33671
web
Patched | CVE-2026-33671 | web | HIGH | Patched | 2026-07-05 |
| Netflix Conductor Unauthenticated RCE via INLINE GraalVM Evaluator — CVE-2026-58138
CVE-2026-58138 ([VulnCheck advisory](https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators))
misc
Patched | CVE-2026-58138 | misc | CRITICAL 9.8 | Patched | 2026-07-05 |
| Neo4j Bolt Transaction Metadata Log Injection (CVE-2026-1337)
CVE-2026-1337
network
Unverified | CVE-2026-1337 | network | LOW | Unverified | 2026-07-05 |
| n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613
EPSS 78% CVE-2026-21858, CVE-2025-68613
web
Patched | CVE-2026-21858, CVE-2025-68613 | web | CRITICAL 10 | Patched | 2026-07-05 |
| n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)
CVE-2026-44789 / GHSA-c8xv-5998-g76h
web
Patched | CVE-2026-44789 / GHSA-c8xv-5998-g76h | web | CRITICAL 9.4 | Patched | 2026-07-05 |
| Multiparty Denial of Service via Prototype-Pollution Field Name (CVE-2026-8161)
CVE-2026-8161 / GHSA-qxch-whhj-8956
misc
Patched | CVE-2026-8161 / GHSA-qxch-whhj-8956 | misc | MEDIUM | Patched | 2026-07-05 |
| Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304
CVE-2026-3304
web
Patched | CVE-2026-3304 | web | HIGH 8.7 | Patched | 2026-07-05 |
| MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
CVE-2026-6992
network
Unverified | CVE-2026-6992 | network | HIGH | Unverified | 2026-07-05 |
| MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
CVE-2026-0596 (GHSA-rvhj-8chj-8v3c)
web
Unverified | CVE-2026-0596 | web | CRITICAL 9.6 | Unverified | 2026-07-05 |
| MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668
CVE-2026-1668
binary
Unverified | CVE-2026-1668 | binary | CRITICAL | Unverified | 2026-07-05 |
| MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)
CVE-2026-36981
binary
Patched | CVE-2026-36981 | binary | HIGH | Patched | 2026-07-05 |
| MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)
CVE-2026-36980
binary
Patched | CVE-2026-36980 | binary | MEDIUM | Patched | 2026-07-05 |
| MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483)
EPSS 11% CVE-2026-27483
web
Patched | CVE-2026-27483 | web | CRITICAL | Patched | 2026-07-05 |
| MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)
CVE-2026-34220
web
Patched | CVE-2026-34220 | web | HIGH | Patched | 2026-07-05 |
| midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306
web
Unverified | CVE-2026-1306 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030
misc
Patched | CVE-2026-26030 | misc | CRITICAL | Patched | 2026-07-05 |
| Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504
web
Patched | CVE-2026-45504 | web | HIGH | Patched | 2026-07-05 |
| Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091)
KEV CVE-2026-41091
binary
Unpatched | CVE-2026-41091 | binary | HIGH 7.8 | Unpatched | 2026-07-05 |
| Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
CVE-2026-49345
web
Unverified | CVE-2026-49345 | web | CRITICAL | Unverified | 2026-07-05 |
| MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)
EPSS 14% CVE-2026-36356
network
Unverified | CVE-2026-36356 | network | CRITICAL | Unverified | 2026-07-05 |
| MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744)
EPSS 45% CVE-2026-23744
web
Patched | CVE-2026-23744 | web | CRITICAL | Patched | 2026-07-05 |
| MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
CVE-2026-23520
web
Patched | CVE-2026-23520 | web | CRITICAL | Patched | 2026-07-05 |
| mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825)
EPSS 13% CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4)
web
Patched | CVE-2026-27825 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)
CVE-2026-40897
web
Patched | CVE-2026-40897 | web | CRITICAL | Patched | 2026-07-05 |
| Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484
web
Unverified | CVE-2026-4484 | web | HIGH 8.8 | Unverified | 2026-07-05 |
| Marlin Firmware M421 G-code Handler Out-of-Bounds Write — CVE-2026-56111
CVE-2026-56111
hardware
Patched | CVE-2026-56111 | hardware | HIGH 8.3 | Patched | 2026-07-05 |
| MariaDB server_audit Plugin Logging Bypass via Inline Comments (CVE-2026-3494)
CVE-2026-3494
network
Patched | CVE-2026-3494 | network | MEDIUM | Patched | 2026-07-05 |
| MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)
CVE-2026-32710
binary
Patched | CVE-2026-32710 | binary | CRITICAL | Patched | 2026-07-05 |
| MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
CVE-2026-30849
web
Patched | CVE-2026-30849 | web | HIGH | Patched | 2026-07-05 |
| Malicious DOCX/OLE CLSID Object Embedding Builder (CVE-2026-21509)
KEV
EPSS 73% CVE-2026-21509
misc
Unverified | CVE-2026-21509 | misc | HIGH | Unverified | 2026-07-05 |
| MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
CVE-2026-42281
web
Patched | CVE-2026-42281 | web | CRITICAL 9.2 | Patched | 2026-07-05 |
| lwIP SNMPv3 USM Stack-Based Buffer Overflow (CVE-2026-8836)
CVE-2026-8836
network
Patched | CVE-2026-8836 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| local-mcp exec Tool Sandbox/Restriction Bypass (CVE-2026-6130)
CVE-2026-6130
misc
Unverified | CVE-2026-6130 | misc | MEDIUM | Unverified | 2026-07-05 |
| LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420
KEV CVE-2026-54420
network
Unverified | CVE-2026-54420 | network | HIGH 8.5 | Unverified | 2026-07-05 |
| LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468
web
Patched | CVE-2026-49468 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102
web
Patched | CVE-2026-47102 | web | HIGH 8.8 | Patched | 2026-07-05 |
| LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217)
EPSS 15% CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29)
web
Patched | CVE-2026-40217 | web | CRITICAL 8.8 | Patched | 2026-07-05 |
| LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
CVE-2026-35030
web
Patched | CVE-2026-35030 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| LiteLLM /config/update Broken Access Control (CVE-2026-35029)
EPSS 26% CVE-2026-35029
web
Patched | CVE-2026-35029 | web | HIGH 8.8 | Patched | 2026-07-05 |
| LiquidJS Template Engine Path Traversal — CVE-2026-30952
CVE-2026-30952 (GHSA-wmfp-5q7x-987x)
misc
Patched | CVE-2026-30952 | misc | HIGH 8.7 | Patched | 2026-07-05 |
| Linux Kernel PPP Unprivileged User-Namespace Precondition Probe — CVE-2026-53075
CVE-2026-53075
binary
Patched | CVE-2026-53075 | binary | INFO | Patched | 2026-07-05 |
| Linux Kernel mm/mseal VMA-Merge Stale-Bound Bug (CVE-2026-23416)
CVE-2026-23416
binary
Patched | CVE-2026-23416 | binary | MEDIUM | Patched | 2026-07-05 |
| Linux Kernel KFENCE Cross-Cache Free of SKB Head via bpf_prog_test_run_skb — CVE-2026-31429
CVE-2026-31429
binary
Patched | CVE-2026-31429 | binary | MEDIUM | Patched | 2026-07-05 |
| Linux Kernel ICMP Fragmentation-Needed NULL Pointer Dereference (CVE-2026-23398)
CVE-2026-23398
network
Patched | CVE-2026-23398 | network | HIGH | Patched | 2026-07-05 |
| Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)
CVE-2026-43499
binary
Patched | CVE-2026-43499 | binary | HIGH 7.8 | Patched | 2026-07-05 |
| Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694
CVE-2026-31694
binary
Patched | CVE-2026-31694 | binary | HIGH | Patched | 2026-07-05 |
| Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413
CVE-2026-31413
binary
Patched | CVE-2026-31413 | binary | CRITICAL | Patched | 2026-07-05 |
| Lightspeed Classroom Management Weak Authentication / Device Takeover — CVE-2026-30368
CVE-2026-30368
web
Unverified | CVE-2026-30368 | web | HIGH | Unverified | 2026-07-05 |
| LibRaw pana8.cpp GetDBit() Out-of-Bounds Array Read (CVE-2026-36834)
CVE-2026-36834
binary
Unverified | CVE-2026-36834 | binary | MEDIUM 6.5 | Unverified | 2026-07-05 |
| libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)
CVE-2026-0006
binary
Unverified | CVE-2026-0006 | binary | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Lenovo LDE (LdeApi.Server.exe) Unimpersonated Junction-Based Arbitrary File Write to SYSTEM (CVE-2026-0827)
CVE-2026-0827 (Lenovo advisory LEN-210693)
binary
Unverified | CVE-2026-0827 | binary | HIGH | Unverified | 2026-07-05 |
| LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
CVE-2026-49083
web
Unverified | CVE-2026-49083 | web | HIGH 8.8 | Unverified | 2026-07-05 |
| LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741
web
Patched | CVE-2026-6741 | web | HIGH 8.8 | Patched | 2026-07-05 |
| Lansweeper lsrunase 2.0 / lsencrypt 2.0 — RC4 Password Recovery (CVE-2026-39031)
CVE-2026-39031
crypto
Unverified | CVE-2026-39031 | crypto | HIGH | Unverified | 2026-07-05 |
| Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770)
KEV
EPSS 63% CVE-2026-0770
web
Patched | CVE-2026-0770 | web | CRITICAL | Patched | 2026-07-05 |
| Langflow Remote Code Execution — CVE-2026-27966
EPSS 34% CVE-2026-27966
web
Patched | CVE-2026-27966 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
CVE-2026-42048 (GHSA-9whx-c884-c68q)
web
Patched | CVE-2026-42048 | web | HIGH | Patched | 2026-07-05 |
| Langflow Custom Component Remote Code Execution — CVE-2026-33017
KEV
EPSS 96% CVE-2026-33017
web
Patched | CVE-2026-33017 | web | CRITICAL | Patched | 2026-07-05 |
| LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920
web
Unverified | CVE-2026-0920 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360
CVE-2026-53360
binary
Patched | CVE-2026-53360 | binary | HIGH | Patched | 2026-07-05 |
| Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
CVE-2026-46680
cloud
Patched | CVE-2026-46680 | cloud | HIGH | Patched | 2026-07-05 |
| Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)
CVE-2026-38526
web
Unverified | CVE-2026-38526 | web | CRITICAL | Unverified | 2026-07-05 |
| KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426
web
Unverified | CVE-2026-5426 | web | CRITICAL | Unverified | 2026-07-05 |
| Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206
web
Unverified | CVE-2026-8206 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| KillChain — Vulnerable Kernel Driver IOCTL Protected-Process Termination (CVE-2026-0828)
CVE-2026-0828
binary
Unverified | CVE-2026-0828 | binary | HIGH | Unverified | 2026-07-05 |
| Keycloak Unauthorized Organization Registration via Invitation Token Flaw — CVE-2026-1529
CVE-2026-1529
web
Unverified | CVE-2026-1529 | web | CRITICAL | Unverified | 2026-07-05 |
| Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f
web
Patched | CVE-2026-25924 / GHSA-grch-p7vf-vc4f | web | HIGH 8.4 | Patched | 2026-07-05 |
| Kan SSRF via Attachment Download Endpoint — CVE-2026-32255
EPSS 21% CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg)
web
Patched | CVE-2026-32255 | web | HIGH 8.6 | Patched | 2026-07-05 |
| JupyterHub Cross-Origin Form POST XSRF Bypass (CVE-2026-40864)
CVE-2026-40864 (GHSA-m68r-v472-jgq9)
web
Patched | CVE-2026-40864 | web | MEDIUM | Patched | 2026-07-05 |
| Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290
KEV
EPSS 30% CVE-2026-56290
web
Patched | CVE-2026-56290 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
CVE-2026-21627
web
Patched | CVE-2026-21627 | web | CRITICAL 9.5 | Patched | 2026-07-05 |
| JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001)
web
Unpatched | CVE-2026-49048 | web | CRITICAL 8.7 | Unpatched | 2026-07-05 |
| Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526
web
Patched | CVE-2026-25526 | web | CRITICAL | Patched | 2026-07-05 |
| JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079
web
Unverified | CVE-2026-49079 | web | HIGH 7.5 | Unverified | 2026-07-05 |
| Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435
EPSS 53% CVE-2026-53435 (Jenkins SECURITY-3707)
web
Patched | CVE-2026-53435 | web | HIGH 9.1 | Patched | 2026-07-05 |
| JeecgBoot mLogin Endpoint CAPTCHA Bypass Enabling Credential Brute Force (CVE-2026-8196)
CVE-2026-8196
web
Unverified | CVE-2026-8196 | web | HIGH | Unverified | 2026-07-05 |
| Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340)
KEV
EPSS 82% CVE-2026-1281, CVE-2026-1340
network
Patched | CVE-2026-1281, CVE-2026-1340 | network | CRITICAL | Patched | 2026-07-05 |
| ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597
web
Unverified | CVE-2026-54597 | web | HIGH | Unverified | 2026-07-05 |
| ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
CVE-2026-54596
web
Unverified | CVE-2026-54596 | web | HIGH | Unverified | 2026-07-05 |
| iOS App Intents Path Traversal — CVE-2026-28995
CVE-2026-28995
misc
Patched | CVE-2026-28995 | misc | HIGH | Patched | 2026-07-05 |
| InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491
web
Patched | CVE-2026-23491 | web | CRITICAL | Patched | 2026-07-05 |
| Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
CVE-2026-49104
web
Unverified | CVE-2026-49104 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691
web
Unpatched | CVE-2026-9691 | web | HIGH 8.1 | Unpatched | 2026-07-05 |
| Immich Stored XSS to API Key Exfiltration and Account Hijacking (CVE-2026-35455)
CVE-2026-35455
web
Patched | CVE-2026-35455 | web | HIGH | Patched | 2026-07-05 |
| Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911
web
Unverified | CVE-2026-0911 | web | HIGH | Unverified | 2026-07-05 |
| HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)
CVE-2026-23813
network
Patched | CVE-2026-23813 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580
web
Unverified | CVE-2026-10580 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
CVE-2026-46395
web
Patched | CVE-2026-46395 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394
web
Patched | CVE-2026-46394 | web | HIGH 7.2 | Patched | 2026-07-05 |
| HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
CVE-2026-4660 / HCSEC-2026-04
cloud
Patched | CVE-2026-4660 / HCSEC-2026-04 | cloud | HIGH 7.5 | Patched | 2026-07-05 |
| HAProxy HTTP/3 (QUIC) Standalone FIN Body Validation Bypass Leading to Request Smuggling — CVE-2026-33555
CVE-2026-33555
network
Patched | CVE-2026-33555 | network | HIGH | Patched | 2026-07-05 |
| Handlebars AST Injection Remote Code Execution — CVE-2026-33937
CVE-2026-33937
web
Patched | CVE-2026-33937 | web | CRITICAL | Patched | 2026-07-05 |
| gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
CVE-2026-33186 (GHSA-p77j-4mvh-x3m3)
network
Patched | CVE-2026-33186 | network | HIGH | Patched | 2026-07-05 |
| Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512)
EPSS 19% CVE-2026-25512
web
Patched | CVE-2026-25512 | web | CRITICAL 9.4 | Patched | 2026-07-05 |
| Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 (GHSA-h22j-frrf-5vxq)
web
Patched | CVE-2026-34838 | web | CRITICAL | Patched | 2026-07-05 |
| Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
CVE-2026-4406
web
Patched | CVE-2026-4406 | web | MEDIUM 6.1 | Patched | 2026-07-05 |
| Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
CVE-2026-48866
web
Patched | CVE-2026-48866 | web | CRITICAL 9.6 | Patched | 2026-07-05 |
| GRASSMARLIN XML External Entity (XXE) Out-of-Band File Exfiltration (CVE-2026-6807)
CVE-2026-6807
network
Unverified | CVE-2026-6807 | network | HIGH | Unverified | 2026-07-05 |
| graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
CVE-2026-32247 (GHSA, getzep/graphiti)
web
Patched | CVE-2026-32247 | web | HIGH 8.1 | Patched | 2026-07-05 |
| Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
CVE-2026-21721
web
Patched | CVE-2026-21721 | web | HIGH | Patched | 2026-07-05 |
| Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589
web
Patched | CVE-2026-42589 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)
CVE-2026-24135 (GHSA-jp7c-wj6q-3qf2)
web
Patched | CVE-2026-24135 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
CVE-2026-52813
web
Patched | CVE-2026-52813 | web | INFO | Patched | 2026-07-05 |
| GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372
CVE-2026-28372
binary
Patched | CVE-2026-28372 | binary | HIGH 7.4 | Patched | 2026-07-05 |
| GNU InetUtils telnetd LINEMODE SLC Pre-Auth Buffer Overflow (CVE-2026-32746)
EPSS 24% CVE-2026-32746
network
Unverified | CVE-2026-32746 | network | CRITICAL 9.8 | Unverified | 2026-07-05 |
| GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173
web
Patched | CVE-2026-5173 | web | HIGH | Patched | 2026-07-05 |
| Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
CVE-2026-28699
web
Patched | CVE-2026-28699 | web | HIGH | Patched | 2026-07-05 |
| Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
CVE-2026-27771
web
Patched | CVE-2026-27771 | web | CRITICAL | Patched | 2026-07-05 |
| Ghost CMS Theme JSONPath Remote Code Execution — CVE-2026-29053
CVE-2026-29053 (GHSA-cgc2-rcrh-qr5x)
web
Patched | CVE-2026-29053 | web | HIGH | Patched | 2026-07-05 |
| Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980)
EPSS 70% CVE-2026-26980
web
Patched | CVE-2026-26980 | web | CRITICAL | Patched | 2026-07-05 |
| gdk-pixbuf JPEG Loader Heap Buffer Overflow — CVE-2026-5201
CVE-2026-5201
binary
Patched | CVE-2026-5201 | binary | HIGH 7.5 | Patched | 2026-07-05 |
| FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)
EPSS 11% CVE-2026-25895
web
Patched | CVE-2026-25895 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Friendly Functions for Welcart WordPress Plugin CSRF (CVE-2026-1208)
CVE-2026-1208
web
Patched | CVE-2026-1208 | web | MEDIUM 4.3 | Patched | 2026-07-05 |
| FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289
EPSS 31% CVE-2026-28289
web
Patched | CVE-2026-28289 | web | CRITICAL 10 | Patched | 2026-07-05 |
| FreePBX Unauthenticated UCP Access via Hard-Coded Credentials (CVE-2026-46376)
CVE-2026-46376 (GHSA-m55x-h47x-v3gx)
web
Patched | CVE-2026-46376 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)
CVE-2026-45250
binary
Unverified | CVE-2026-45250 | binary | CRITICAL | Unverified | 2026-07-05 |
| FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)
CVE-2026-49417
binary
Unverified | CVE-2026-49417 | binary | HIGH | Unverified | 2026-07-05 |
| FreeBSD Linuxulator AT_SECURE=0 Local Privilege Escalation via LD_PRELOAD (CVE-2026-49413)
CVE-2026-49413
binary
Unverified | CVE-2026-49413 | binary | HIGH | Unverified | 2026-07-05 |
| FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)
CVE-2026-7270
binary
Unverified | CVE-2026-7270 | binary | CRITICAL | Unverified | 2026-07-05 |
| FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)
CVE-2026-45258
binary
Unverified | CVE-2026-45258 | binary | CRITICAL | Unverified | 2026-07-05 |
| FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646)
web
Patched | CVE-2026-53647 | web | MEDIUM 6.9 | Patched | 2026-07-05 |
| FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)
KEV
EPSS 93% CVE-2026-39808
network
Unverified | CVE-2026-39808 | network | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089)
KEV
EPSS 76% CVE-2026-25089
network
Patched | CVE-2026-25089 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| Fortinet FortiClientLinux VPN Config Symlink/Shared-Object Loading LPE — CVE-2026-24018
CVE-2026-24018
binary
Unverified | CVE-2026-24018 | binary | HIGH | Unverified | 2026-07-05 |
| FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277
web
Patched | CVE-2026-44277 | web | CRITICAL | Patched | 2026-07-05 |
| Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
CVE-2026-5229
web
Patched | CVE-2026-5229 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824
EPSS 36% CVE-2026-30824
web
Patched | CVE-2026-30824 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx))
web
Unverified | CVE-2026-54337 | web | INFO | Unverified | 2026-07-05 |
| Firefox/Tor Browser IndexedDB Ordering Fingerprint — CVE-2026-6770
CVE-2026-6770
binary
Unverified | CVE-2026-6770 | binary | MEDIUM | Unverified | 2026-07-05 |
| Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121
CVE-2026-56121
misc
Patched | CVE-2026-56121 | misc | CRITICAL 9.8 | Patched | 2026-07-05 |
| exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
CVE-2026-43893 / GHSA-cw26-7653-2rp5
misc
Patched | CVE-2026-43893 / GHSA-cw26-7653-2rp5 | misc | HIGH 8.2 | Patched | 2026-07-05 |
| ExifTool Metadata Field Command Injection (macOS) — CVE-2026-3102
CVE-2026-3102
binary
Patched | CVE-2026-3102 | binary | HIGH | Patched | 2026-07-05 |
| Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296
web
Patched | CVE-2026-3296 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300)
EPSS 39% CVE-2026-3300
web
Unverified | CVE-2026-3300 | web | CRITICAL | Unverified | 2026-07-05 |
| EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657
web
Patched | CVE-2026-1657 | web | MEDIUM | Patched | 2026-07-05 |
| Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7
web
Patched | CVE-2026-40776 / Patchstack PSID 85de025d71e7 | web | HIGH 7.5 | Patched | 2026-07-05 |
| EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
CVE-2026-33656
web
Patched | CVE-2026-33656 | web | CRITICAL | Patched | 2026-07-05 |
| EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
CVE-2026-33657
web
Patched | CVE-2026-33657 | web | MEDIUM | Patched | 2026-07-05 |
| EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
CVE-2026-33534
web
Patched | CVE-2026-33534 | web | MEDIUM | Patched | 2026-07-05 |
| ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600
web
Patched | CVE-2026-2600 | web | MEDIUM 6.4 | Patched | 2026-07-05 |
| EGroupware Nextmatch Filter Authenticated SQL Injection (CVE-2026-22243)
CVE-2026-22243
web
Patched | CVE-2026-22243 | web | CRITICAL | Patched | 2026-07-05 |
| EcoOnline EHS Android App — Deep Link Validation Bypass to WebView Open Redirect (CVE-2026-26897)
CVE-2026-26897
web
Patched | CVE-2026-26897 | web | MEDIUM 6.3 | Patched | 2026-07-05 |
| Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
CVE-2026-9018
web
Patched | CVE-2026-9018 | web | HIGH 8.8 | Patched | 2026-07-05 |
| Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)
CVE-2026-34036
web
Patched | CVE-2026-34036 | web | MEDIUM | Patched | 2026-07-05 |
| Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
CVE-2026-23500 / GHSA-w5j3-8fcr-h87w
web
Patched | CVE-2026-23500 / GHSA-w5j3-8fcr-h87w | web | CRITICAL | Patched | 2026-07-05 |
| docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009
CVE-2026-24009
misc
Patched | CVE-2026-24009 | misc | HIGH | Patched | 2026-07-05 |
| dnsmasq extract_addresses() RDLEN/RDATA Buffer Overflow — CVE-2026-5172
CVE-2026-5172
network
Patched | CVE-2026-5172 | network | INFO | Patched | 2026-07-05 |
| dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)
CVE-2026-4893
network
Patched | CVE-2026-4893 | network | MEDIUM | Patched | 2026-07-05 |
| Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033
CVE-2026-33033
web
Patched | CVE-2026-33033 | web | MEDIUM | Patched | 2026-07-05 |
| Django GIS RasterField SQL Injection (CVE-2026-1207)
EPSS 13% CVE-2026-1207
web
Patched | CVE-2026-1207 | web | HIGH | Patched | 2026-07-05 |
| Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
CVE-2026-5118
web
Unverified | CVE-2026-5118 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| diskover-community — CSRF Leading to Authentication Bypass (CVE-2026-38934)
CVE-2026-38934
web
Unverified | CVE-2026-38934 | web | HIGH 8.8 | Unverified | 2026-07-05 |
| Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11)
web
Unverified | CVE-2026-49952 | web | CRITICAL | Unverified | 2026-07-05 |
| Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)
CVE-2026-0776 (ZDI-CAN-27057, credit: Trend Micro Zero Day Initiative)
binary
Unverified | CVE-2026-0776 | binary | HIGH 7.3 | Unverified | 2026-07-05 |
| DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635
CVE-2026-31635
binary
Patched | CVE-2026-31635 | binary | HIGH | Patched | 2026-07-05 |
| dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39)
web
Patched | CVE-2026-44262 / [GHSA-4rm2-28vj-fj39] | web | CRITICAL | Patched | 2026-07-05 |
| DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
CVE-2026-47668
web
Patched | CVE-2026-47668 | web | CRITICAL 3.1 | Patched | 2026-07-05 |
| DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
CVE-2026-48017 / GHSA-hv83-ggc4-v385
web
Patched | CVE-2026-48017 / GHSA-hv83-ggc4-v385 | web | HIGH 8.8 | Patched | 2026-07-05 |
| Dagster Database I/O Manager SQL Injection via Dynamic Partition Keys (CVE-2026-41490)
CVE-2026-41490 (GHSA-mjw2-v2hm-wj34)
web
Patched | CVE-2026-41490 | web | HIGH | Patched | 2026-07-05 |
| curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)
CVE-2026-3805
network
Patched | CVE-2026-3805 | network | HIGH | Patched | 2026-07-05 |
| CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)
CVE-2026-34975
web
Patched | CVE-2026-34975 | web | HIGH 8.5 | Patched | 2026-07-05 |
| Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp)
web
Patched | CVE-2026-34038 | web | CRITICAL 10 | Patched | 2026-07-05 |
| Control Web Panel Pre-Auth Blind SQL Injection to RCE — CVE-2026-57517
CVE-2026-57517
web
Patched | CVE-2026-57517 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257)
EPSS 41% CVE-2026-4257
web
Unverified | CVE-2026-4257 | web | CRITICAL | Unverified | 2026-07-05 |
| CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749
web
Unverified | CVE-2026-37749 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
EPSS 15% CVE-2026-4631 (GHSA-m4gv-x78h-3427)
web
Patched | CVE-2026-4631 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316
CVE-2026-54316 (GHSA-fg94-h982-f3mm)
misc
Patched | CVE-2026-54316 | misc | MEDIUM | Patched | 2026-07-05 |
| Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182
KEV
EPSS 92% CVE-2026-20182
network
Patched | CVE-2026-20182 | network | CRITICAL 10 | Patched | 2026-07-05 |
| ChatterBot Denial of Service via SQLAlchemy Connection Pool Exhaustion (CVE-2026-23842)
CVE-2026-23842
misc
Patched | CVE-2026-23842 | misc | HIGH 7.5 | Patched | 2026-07-05 |
| Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
CVE-2026-33715 / GHSA-mxc9-9335-45mc
web
Unverified | CVE-2026-33715 / GHSA-mxc9-9335-45mc | web | HIGH 7.5 | Unverified | 2026-07-05 |
| Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041
web
Patched | CVE-2026-29041 | web | HIGH 8.8 | Patched | 2026-07-05 |
| Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751)
web
Patched | CVE-2026-2749 | web | CRITICAL | Patched | 2026-07-05 |
| Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
CVE-2026-6815
web
Unverified | CVE-2026-6815 | web | HIGH | Unverified | 2026-07-05 |
| Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
CVE-2026-39949
web
Patched | CVE-2026-39949 | web | HIGH | Patched | 2026-07-05 |
| Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576
web
Patched | CVE-2026-2576 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)
EPSS 15% CVE-2026-8181
web
Patched | CVE-2026-8181 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816
EPSS 15% CVE-2026-31816
web
Unverified | CVE-2026-31816 | web | CRITICAL | Unverified | 2026-07-05 |
| Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551
web
Patched | CVE-2026-11551 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513
CVE-2026-5513
web
Patched | CVE-2026-5513 | web | HIGH 7.2 | Patched | 2026-07-05 |
| BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960
web
Unverified | CVE-2026-6960 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387
web
Patched | CVE-2026-39387 | web | HIGH | Patched | 2026-07-05 |
| Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099
web
Patched | CVE-2026-25099 | web | HIGH | Patched | 2026-07-05 |
| BIRD/BIRD2 BGP AS_PATH Mask Matching Stack Buffer Overflow (CVE-2026-49943)
CVE-2026-49943
network
Patched | CVE-2026-49943 | network | HIGH 3.1 | Patched | 2026-07-05 |
| BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
CVE-2026-7515
web
Unverified | CVE-2026-7515 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)
CVE-2026-41653
web
Patched | CVE-2026-41653 | web | CRITICAL | Patched | 2026-07-05 |
| Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332
CVE-2026-30332
binary
Unverified | CVE-2026-30332 | binary | HIGH | Unverified | 2026-07-05 |
| Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415
web
Patched | CVE-2026-54415 | web | HIGH 3.1 | Patched | 2026-07-05 |
| Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
CVE-2026-6279
web
Unverified | CVE-2026-6279 | web | CRITICAL | Unverified | 2026-07-05 |
| AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
CVE-2026-30950 (GHSA-q58p-v9r9-7gqj)
web
Patched | CVE-2026-30950 | web | HIGH 7.1 | Patched | 2026-07-05 |
| ASUSTOR ADM vpnupload.cgi Format String / Stack Buffer Overflow RCE — CVE-2026-6643
CVE-2026-6643
binary
Unverified | CVE-2026-6643 | binary | CRITICAL | Unverified | 2026-07-05 |
| ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880
CVE-2026-1880
binary
Patched | CVE-2026-1880 | binary | MEDIUM | Patched | 2026-07-05 |
| ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074)
web
Patched | CVE-2026-5076 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Arista EOS Tunnel Decapsulation Protocol-Type Bypass — CVE-2026-7473
KEV CVE-2026-7473
network
Unverified | CVE-2026-7473 | network | MEDIUM 5.8 | Unverified | 2026-07-05 |
| Appsmith Table Widget Stored XSS to Admin Account Takeover — CVE-2026-30862
CVE-2026-30862 (GHSA-5hw4-whxv-6794)
web
Patched | CVE-2026-30862 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)
CVE-2026-20637
binary
Patched | CVE-2026-20637 | binary | HIGH | Patched | 2026-07-05 |
| AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)
CVE-2026-43655
binary
Unverified | CVE-2026-43655 | binary | HIGH | Unverified | 2026-07-05 |
| AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)
CVE-2026-20687
binary
Patched | CVE-2026-20687 | binary | HIGH | Patched | 2026-07-05 |
| ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
CVE-2026-32731
web
Patched | CVE-2026-32731 | web | HIGH | Patched | 2026-07-05 |
| Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)
CVE-2026-39973
misc
Patched | CVE-2026-39973 | misc | HIGH | Patched | 2026-07-05 |
| Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486)
KEV
EPSS 99% CVE-2026-34486
web
Patched | CVE-2026-34486 | web | CRITICAL | Patched | 2026-07-05 |
| Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)
CVE-2026-43515
web
Patched | CVE-2026-43515 | web | HIGH | Patched | 2026-07-05 |
| Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145
CVE-2026-29145
web
Patched | CVE-2026-29145 | web | CRITICAL 9.1 | Patched | 2026-07-05 |
| Apache Tomcat LoadBalancerDrainingValve — Cross-System Open Redirect / Session Fixation (CVE-2026-25854)
CVE-2026-25854
web
Patched | CVE-2026-25854 | web | MEDIUM 6.1 | Patched | 2026-07-05 |
| Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980
web
Patched | CVE-2026-23980 | web | MEDIUM 6.5 | Patched | 2026-07-05 |
| Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
CVE-2026-44825
web
Patched | CVE-2026-44825 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| Apache Solr UNC Path Validation Bypass to RCE (CVE-2026-22444)
CVE-2026-22444
web
Patched | CVE-2026-22444 | web | CRITICAL | Patched | 2026-07-05 |
| Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
CVE-2026-39816
web
Patched | CVE-2026-39816 | web | CRITICAL | Patched | 2026-07-05 |
| Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779
network
Patched | CVE-2026-42779 | network | CRITICAL 9.8 | Patched | 2026-07-05 |
| Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072
CVE-2026-24072
web
Patched | CVE-2026-24072 | web | MEDIUM | Patched | 2026-07-05 |
| Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006
CVE-2026-33006
web
Patched | CVE-2026-33006 | web | MEDIUM 4.8 | Patched | 2026-07-05 |
| Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975)
EPSS 31% CVE-2026-49975
network
Unverified | CVE-2026-49975 | network | HIGH | Unverified | 2026-07-05 |
| Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)
CVE-2026-40564
cloud
Patched | CVE-2026-40564 | cloud | HIGH | Patched | 2026-07-05 |
| Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
CVE-2026-33453
web
Patched | CVE-2026-33453 | web | CRITICAL 10 | Patched | 2026-07-05 |
| Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
CVE-2026-31908
web
Patched | CVE-2026-31908 | web | CRITICAL 10 | Patched | 2026-07-05 |
| Apache Airflow AWS Auth Manager SAML Host Header Injection (CVE-2026-25604)
CVE-2026-25604
web
Patched | CVE-2026-25604 | web | HIGH | Patched | 2026-07-05 |
| Apache ActiveMQ Jolokia addNetworkConnector Spring Bean RCE (CVE-2026-42588)
CVE-2026-42588
web
Patched | CVE-2026-42588 | web | HIGH 8.1 | Patched | 2026-07-05 |
| Apache ActiveMQ Classic Jolokia addNetworkConnector Xbean Spring-XML RCE (CVE-2026-34197)
KEV
EPSS 97% CVE-2026-34197 (related bypass: CVE-2026-42588)
network
Patched | CVE-2026-34197 | network | CRITICAL | Patched | 2026-07-05 |
| Android ActivityManagerService dumpBitmapsProto() Missing Permission Check (CVE-2026-0047)
CVE-2026-0047
binary
Unpatched | CVE-2026-0047 | binary | CRITICAL 8.4 | Unpatched | 2026-07-05 |
| Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)
CVE-2026-7791
cloud
Unverified | CVE-2026-7791 | cloud | HIGH | Unverified | 2026-07-05 |
| Algorithmic Complexity DoS in musl libc `iconv` GB18030 Decoder — CVE-2026-6042
CVE-2026-6042
network
Unverified | CVE-2026-6042 | network | HIGH 7.5 | Unverified | 2026-07-05 |
| AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
CVE-2026-22807
misc
Patched | CVE-2026-22807 | misc | HIGH | Patched | 2026-07-05 |
| adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980
web
Patched | CVE-2026-33980 | web | HIGH 8.8 | Patched | 2026-07-05 |
| Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
CVE-2026-8809
web
Unverified | CVE-2026-8809 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h)
web
Patched | CVE-2026-21440 | web | CRITICAL 9.2 | Patched | 2026-07-05 |
| Adobe Acrobat/Reader PDF Exploit Generator — Claimed Prototype Pollution (CVE-2026-3462)
CVE-2026-3462 (repo internally references CVE-2026-34621 — CVE-ID mismatch, see Notes)
misc
Patched | CVE-2026-3462 | misc | CRITICAL | Patched | 2026-07-05 |
| AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498
CVE-2026-30498 (reserved by MITRE)
web
Unverified | CVE-2026-30498 | web | HIGH | Unverified | 2026-07-05 |
| AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
CVE-2026-1729
web
Unverified | CVE-2026-1729 | web | CRITICAL | Unverified | 2026-07-05 |
| @haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)
CVE-2026-46391 (GHSA-4fg7-f244-3j49)
web
Unverified | CVE-2026-46391 | web | HIGH | Unverified | 2026-07-05 |
| PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE
None assigned as of 2026-07-04
network
Unverified | None assigned as of 2026-07-04 | network | HIGH | Unverified | 2026-07-04 |
| VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | MEDIUM | Unverified | 2026-07-03 |
| System Informer phsvc Trusted-Host Confused Deputy LPE
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | HIGH | Unverified | 2026-07-03 |
| RustDesk Relay Session Downgrade and FileTransfer Authorization Scope Bypass
None assigned as of 2026-07-03
network
Unverified | None assigned as of 2026-07-03 | network | HIGH | Unverified | 2026-07-03 |
| Redis Vector Set Duplicate HNSW Node ID RCE
None assigned as of 2026-07-03
network
Unverified | None assigned as of 2026-07-03 | network | CRITICAL | Unverified | 2026-07-03 |
| QEMU CXL Type-3 Mailbox Guest-to-Host Escape
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | CRITICAL | Unverified | 2026-07-03 |
| Pillow ImageCms Mutable output_mode Heap OOB Write
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | HIGH | Unverified | 2026-07-03 |
| PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | CRITICAL | Unverified | 2026-07-03 |
| OpenVPN Connect Server-Pushed Option Current-User Command Execution
None assigned as of 2026-07-03
network
Unverified | None assigned as of 2026-07-03 | network | HIGH | Unverified | 2026-07-03 |
| objdump DLX ELF Backend Out-of-Bounds Write (Crash-to-Calc)
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | MEDIUM | Unverified | 2026-07-03 |
| NodeBB ActivityPub attributedTo Local UID Spoof
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | HIGH | Unverified | 2026-07-03 |
| Nmap IPv6 Extension-Header Length Wrap
None assigned as of 2026-07-03
network
Unverified | None assigned as of 2026-07-03 | network | LOW | Unverified | 2026-07-03 |
| nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning
None assigned as of 2026-07-03
network
Patched | None assigned as of 2026-07-03 | network | HIGH | Patched | 2026-07-03 |
| Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | HIGH | Unverified | 2026-07-03 |
| Next.js unstable_cache Object-Argument Cache-Key Collision
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | HIGH | Unverified | 2026-07-03 |
| MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
None assigned as of 2026-07-03 (see Notes — CVE-2026-45115 identifies a separate, already-patched MyBB issue)
web
Unpatched | None assigned as of 2026-07-03 | web | HIGH | Unpatched | 2026-07-03 |
| Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | CRITICAL 3.1 | Unverified | 2026-07-03 |
| libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)
CVE-2026-55200
network
Patched | CVE-2026-55200 | network | CRITICAL | Patched | 2026-07-03 |
| libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
None assigned as of 2026-07-03
network
Unverified | None assigned as of 2026-07-03 | network | CRITICAL | Unverified | 2026-07-03 |
| libarchive ZIP Declared-Size Boundary Bypass via debuginfod
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | MEDIUM | Unverified | 2026-07-03 |
| Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)
KEV
RW
EPSS 100% CVE-2025-3248
web
Patched | CVE-2025-3248 | web | CRITICAL 9.8 | Patched | 2026-07-03 |
| Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | CRITICAL | Unverified | 2026-07-03 |
| ImageMagick Ghostscript Delegate Search Path Hijack
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | HIGH | Unverified | 2026-07-03 |
| Gogs Admin User Edit CSRF to Git Hook RCE
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | CRITICAL | Unverified | 2026-07-03 |
| Gitea act_runner container.options Host Namespace Escape
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | HIGH | Unverified | 2026-07-03 |
| Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | MEDIUM | Unverified | 2026-07-03 |
| Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)
KEV
EPSS 91% CVE-2026-35616
network
Patched | CVE-2026-35616 | network | CRITICAL 9.1 | Patched | 2026-07-03 |
| Flowise Custom MCP Environment Variable Case Bypass
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | HIGH | Unverified | 2026-07-03 |
| Floci API Gateway VTL RCE + IAM Scope Bypass
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | CRITICAL | Unverified | 2026-07-03 |
| Firefox Smart Window Private URL Exfiltration
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | HIGH | Unverified | 2026-07-03 |
| FFmpeg RASC Decoder DLTA Heap Out-of-Bounds Write
None assigned as of 2026-07-03
binary
Unpatched | None assigned as of 2026-07-03 | binary | CRITICAL | Unpatched | 2026-07-03 |
| Docker cp Copy-Out Destination Escape via Symlink Race
None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | MEDIUM | Unverified | 2026-07-03 |
| Discourse Scoped API Key Pre-Route Authorization Bypass
None assigned as of 2026-07-03
web
Unverified | None assigned as of 2026-07-03 | web | HIGH | Unverified | 2026-07-03 |
| curl SMTP EXPN Recipient CRLF Command Injection
None assigned as of 2026-07-03
network
Unverified | None assigned as of 2026-07-03 | network | MEDIUM | Unverified | 2026-07-03 |
| Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451)
EPSS 16% CVE-2026-8451
network
Unverified | CVE-2026-8451 | network | HIGH 7.5 | Unverified | 2026-07-03 |
| c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution
None assigned as of 2026-07-03
network
Unverified | None assigned as of 2026-07-03 | network | HIGH | Unverified | 2026-07-03 |
| AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation
None assigned as of 2026-07-03
binary
Unverified | None assigned as of 2026-07-03 | binary | HIGH | Unverified | 2026-07-03 |
| 7-Zip RAR5 Mark-of-the-Web / ADS Full-Chain Bypass
None assigned as of 2026-07-03
misc
Unverified | None assigned as of 2026-07-03 | misc | HIGH | Unverified | 2026-07-03 |
| WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)
KEV
RW
EPSS 95% CVE-2025-8088
misc
Patched | CVE-2025-8088 | misc | HIGH 8.4 | Patched | 2026-07-01 |
| Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)
KEV
EPSS 28% CVE-2026-45247
web
Unverified | CVE-2026-45247 | web | CRITICAL 9.3 | Unverified | 2026-07-01 |
| Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)
KEV
EPSS 78% CVE-2026-48907
web
Patched | CVE-2026-48907 | web | CRITICAL 10 | Patched | 2026-07-01 |
| Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729
network
Patched | CVE-2026-47729 | network | MEDIUM | Patched | 2026-07-01 |
| PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)
KEV
RW
EPSS 94% CVE-2026-0257
web
Unverified | CVE-2026-0257 | web | HIGH 7.8 | Unverified | 2026-07-01 |
| Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645)
KEV CVE-2026-11645
web
Unverified | CVE-2026-11645 | web | HIGH 8.8 | Unverified | 2026-07-01 |
| Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)
KEV
EPSS 88% CVE-2026-20230
network
Unverified | CVE-2026-20230 | network | CRITICAL 8.6 | Unverified | 2026-07-01 |
| Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)
KEV
EPSS 28% CVE-2026-20262
network
Unverified | CVE-2026-20262 | network | MEDIUM 6.5 | Unverified | 2026-07-01 |
| Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271)
KEV
EPSS 84% CVE-2026-42271
web
Patched | CVE-2026-42271 | web | HIGH 8.7 | Patched | 2026-07-01 |
| SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)
KEV
EPSS 15% CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p)
web
Patched | CVE-2026-48908 | web | CRITICAL 10 | Patched | 2026-06-30 |
| Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)
CVE-2026-46331
binary
Patched | CVE-2026-46331 | binary | HIGH 7.8 | Patched | 2026-06-30 |
| libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200
network
Patched | CVE-2026-55200 | network | CRITICAL 9.8 | Patched | 2026-06-30 |
| libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)
CVE-2026-8932
network
Patched | CVE-2026-8932 | network | LOW | Patched | 2026-06-30 |
| GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061)
KEV
EPSS 98% CVE-2026-24061
network
Patched | CVE-2026-24061 | network | CRITICAL 9.8 | Patched | 2026-06-30 |
| GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485
network
Patched | CVE-2026-12485 | network | CRITICAL 10 | Patched | 2026-06-30 |
| FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461
binary
Patched | CVE-2026-8461 | binary | HIGH 8.8 | Patched | 2026-06-30 |
| Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)
CVE-2026-7574
binary
Unverified | CVE-2026-7574 | binary | HIGH 8.7 | Unverified | 2026-06-30 |
| Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)
CVE-2026-45586
binary
Patched | CVE-2026-45586 | binary | HIGH 7.8 | Patched | 2026-06-28 |
| Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)
KEV
EPSS 85% CVE-2026-34908, CVE-2026-34909, CVE-2026-34910
network
Patched | CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 | network | CRITICAL 10 | Patched | 2026-06-28 |
| Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)
KEV
EPSS 97% CVE-2026-20253
web
Patched | CVE-2026-20253 | web | CRITICAL | Patched | 2026-06-28 |
| Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)
KEV
EPSS 100% CVE-2026-10520, CVE-2026-10523
network
Patched | CVE-2026-10520, CVE-2026-10523 | network | CRITICAL 10 | Patched | 2026-06-28 |
| DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)
CVE-2026-43503
binary
Patched | CVE-2026-43503 | binary | HIGH 8.8 | Patched | 2026-06-28 |
| Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)
KEV
EPSS 25% CVE-2026-20245
network
Unpatched | CVE-2026-20245 | network | HIGH 7.8 | Unpatched | 2026-06-28 |
| Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)
KEV
RW
EPSS 84% CVE-2026-50751
network
Patched | CVE-2026-50751 | network | CRITICAL 9.3 | Patched | 2026-06-28 |
| YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)
CVE-2026-45585
misc
Patched | CVE-2026-45585 | misc | MEDIUM 6.1 | Patched | 2026-06-26 |
| CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)
EPSS 11% CVE-2026-50656
binary
Patched | CVE-2026-50656 | binary | HIGH 7.8 | Patched | 2026-06-26 |
| RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition
EPSS 11% CVE-2026-50656
binary
Unpatched | CVE-2026-50656 | binary | HIGH 7.8 | Unpatched | 2026-06-10 |
| FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition
web
Unpatched | — | web | CRITICAL 9.3 | Unpatched | 2026-06-08 |
| ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)
CVE-2026-46333
binary
Patched | CVE-2026-46333 | binary | HIGH | Patched | 2026-06-05 |
| Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089)
EPSS 80% CVE-2026-41089
network
Patched | CVE-2026-41089 | network | CRITICAL 9.8 | Patched | 2026-06-04 |
| LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172)
KEV
EPSS 19% CVE-2026-48172
web
Unverified | CVE-2026-48172 | web | HIGH | Unverified | 2026-05-30 |
| Drupal Core PostgreSQL SQL Injection (CVE-2026-9082)
KEV
EPSS 88% CVE-2026-9082 / SA-CORE-2026-004
web
Patched | CVE-2026-9082 / SA-CORE-2026-004 | web | CRITICAL | Patched | 2026-05-30 |
| Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)
CVE-2026-48770, CVE-2026-48778, CVE-2026-48800
binary
Patched | CVE-2026-48770, CVE-2026-48778, CVE-2026-48800 | binary | HIGH 5 | Patched | 2026-05-28 |
| PinTheft: RDS Double-Free → LPE
binary
Unverified | — | binary | HIGH | Unverified | 2026-05-20 |
| TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
N/A (vendor confirmed TOS4 is EOL; no fix planned)
network
Unpatched | N/A | network | CRITICAL | Unpatched | 2026-05-18 |
| DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)
N/A (reported as duplicate by kernel maintainers; patched on mainline)
binary
Unverified | N/A | binary | HIGH | Unverified | 2026-05-18 |
| Chrome WebGPU Use-After-Free (CVE-2026-5281)
KEV CVE-2026-5281
web
Unverified | CVE-2026-5281 | web | HIGH 8.8 | Unverified | 2026-05-18 |
| Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054
KEV
EPSS 59% CVE-2025-24054
binary
Unverified | CVE-2025-24054 | binary | MEDIUM 6.5 | Unverified | 2026-05-17 |
| Windows MMC MSC EvilTwin - CVE-2025-26633
KEV
RW
EPSS 30% CVE-2025-26633
binary
Unverified | CVE-2025-26633 | binary | HIGH | Unverified | 2026-05-17 |
| Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215)
KEV CVE-2025-62215
binary
Patched | CVE-2025-62215 | binary | HIGH 7 | Patched | 2026-05-17 |
| ToolShell - SharePoint Unauthenticated RCE Chain
KEV
RW
EPSS 100% CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706
web
Patched | CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 | web | CRITICAL | Patched | 2026-05-17 |
| React2Shell - Next.js RSC Unauthenticated RCE
KEV
RW
EPSS 100% CVE-2025-55182
web
Patched | CVE-2025-55182 | web | CRITICAL 10 | Patched | 2026-05-17 |
| Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)
KEV
RW
EPSS 100% CVE-2024-3400
web
Patched | CVE-2024-3400 | web | CRITICAL 10 | Patched | 2026-05-17 |
| Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
CVE-2026-44572
web
Patched | CVE-2026-44572 | web | LOW 3.1 | Patched | 2026-05-17 |
| Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)
EPSS 39% CVE-2026-44578
web
Patched | CVE-2026-44578 | web | HIGH 8.6 | Patched | 2026-05-17 |
| Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870
web
Patched | CVE-2026-23870 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Next.js RSC Response Cache Poisoning (CVE-2026-44576)
CVE-2026-44576
web
Patched | CVE-2026-44576 | web | MEDIUM 5.4 | Patched | 2026-05-17 |
| Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
CVE-2026-44582
web
Patched | CVE-2026-44582 | web | LOW 3.7 | Patched | 2026-05-17 |
| Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)
CVE-2026-44577
web
Patched | CVE-2026-44577 | web | MEDIUM 5.9 | Patched | 2026-05-17 |
| Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573
web
Patched | CVE-2026-44573 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
CVE-2026-44574
web
Patched | CVE-2026-44574 | web | HIGH 8.1 | Patched | 2026-05-17 |
| Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)
CVE-2026-44581
web
Patched | CVE-2026-44581 | web | MEDIUM 4.7 | Patched | 2026-05-17 |
| Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)
CVE-2026-44579
web
Patched | CVE-2026-44579 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Next.js beforeInteractive Script XSS (CVE-2026-44580)
CVE-2026-44580
web
Patched | CVE-2026-44580 | web | MEDIUM 6.1 | Patched | 2026-05-17 |
| Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
CVE-2026-44575
web
Patched | CVE-2026-44575 | web | HIGH 7.5 | Patched | 2026-05-17 |
| Linux vsock Use-After-Free VM Escape (CVE-2025-21756)
CVE-2025-21756
binary
Patched | CVE-2025-21756 | binary | HIGH 7.8 | Patched | 2026-05-17 |
| Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)
KEV
RW
EPSS 28% CVE-2024-1086
binary
Patched | CVE-2024-1086 | binary | HIGH 7.8 | Patched | 2026-05-17 |
| Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)
KEV
RW
EPSS 100% CVE-2024-23897
web
Patched | CVE-2024-23897 | web | CRITICAL 9.8 | Patched | 2026-05-17 |
| Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)
KEV
RW
EPSS 100% CVE-2025-0282
network
Unverified | CVE-2025-0282 | network | CRITICAL 9 | Unverified | 2026-05-17 |
| IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE
EPSS 100% CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514
cloud
Unverified | CVE-2025-1974 | cloud | CRITICAL 9.8 | Unverified | 2026-05-17 |
| Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575)
KEV
EPSS 95% CVE-2024-47575
network
Unverified | CVE-2024-47575 | network | CRITICAL 9.8 | Unverified | 2026-05-17 |
| Fortinet FortiCloud SSO Authentication Bypass
KEV
EPSS 69% CVE-2025-59718, CVE-2025-59719 (Advisory: FG-IR-25-647)
network
Unverified | CVE-2025-59718, CVE-2025-59719 | network | CRITICAL 9.8 | Unverified | 2026-05-17 |
| Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433
KEV
EPSS 99% CVE-2025-32433
network
Patched | CVE-2025-32433 | network | CRITICAL 10 | Patched | 2026-05-17 |
| Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431)
KEV
EPSS 100% CVE-2026-31431
binary
Patched | CVE-2026-31431 | binary | HIGH | Patched | 2026-05-17 |
| Confluence SSTI RCE - CVE-2023-22527
KEV
RW
EPSS 100% CVE-2023-22527
web
Patched | CVE-2023-22527 | web | CRITICAL 10 | Patched | 2026-05-17 |
| Confluence Post-Auth RCE - CVE-2024-21683
EPSS 88% CVE-2024-21683
web
Unverified | CVE-2024-21683 | web | HIGH 8.3 | Unverified | 2026-05-17 |
| Azure Networking Privilege Escalation via Missing Privilege Check
CVE-2025-54914
cloud
Patched | CVE-2025-54914 | cloud | CRITICAL 10 | Patched | 2026-05-17 |
| Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918
EPSS 50% CVE-2026-23918
web
Patched | CVE-2026-23918 | web | CRITICAL | Patched | 2026-05-17 |
| Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)
EPSS 81% CVE-2025-21298
binary
Patched | CVE-2025-21298 | binary | CRITICAL 9.8 | Patched | 2026-05-16 |
| VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079)
KEV
EPSS 22% CVE-2024-37079
network
Patched | CVE-2024-37079 | network | CRITICAL 9.8 | Patched | 2026-05-16 |
| VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)
KEV
RW
EPSS 27% CVE-2024-37085
network
Patched | CVE-2024-37085 | network | MEDIUM 6.8 | Patched | 2026-05-16 |
| QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain
binary
Unverified | — | binary | CRITICAL | Unverified | 2026-05-16 |
| Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
KEV
EPSS 98% CVE-2025-0108
web
Patched | CVE-2025-0108 | web | CRITICAL 9.1 | Patched | 2026-05-16 |
| OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387)
EPSS 100% CVE-2024-6387
network
Patched | CVE-2024-6387 | network | HIGH 8.1 | Patched | 2026-05-16 |
| Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762)
KEV
RW
EPSS 84% CVE-2024-21762
web
Patched | CVE-2024-21762 | web | CRITICAL 9.6 | Patched | 2026-05-16 |
| Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)
KEV
RW
EPSS 98% CVE-2024-55591 (Fortinet FG-IR-24-535)
web
Unverified | CVE-2024-55591 | web | CRITICAL 9.6 | Unverified | 2026-05-16 |
| cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)
KEV
RW
EPSS 99% CVE-2026-41940
web
Patched | CVE-2026-41940 | web | CRITICAL 10 | Patched | 2026-05-16 |
| Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777)
KEV
RW
EPSS 100% CVE-2025-5777
web
Patched | CVE-2025-5777 | web | CRITICAL 9.3 | Patched | 2026-05-16 |
| Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441)
KEV
EPSS 22% CVE-2026-2441
web
Unpatched | CVE-2026-2441 | web | HIGH 8.8 | Unpatched | 2026-05-16 |
| Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065)
EPSS 43% CVE-2025-30065
misc
Patched | CVE-2025-30065 | misc | CRITICAL 10 | Patched | 2026-05-16 |
| Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621)
KEV CVE-2026-34621
binary
Unverified | CVE-2026-34621 | binary | CRITICAL 9.8 | Unverified | 2026-05-16 |
| WinRAR Archive Extraction Path Traversal (CVE-2025-6218)
KEV
EPSS 90% CVE-2025-6218
misc
Unverified | CVE-2025-6218 | misc | HIGH | Unverified | 2026-05-15 |
| RedSun Privileged File Write (CVE-2026-33825)
KEV
RW CVE-2026-33825
binary
Patched | CVE-2026-33825 | binary | HIGH 7.8 | Patched | 2026-05-15 |
| Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927)
EPSS 99% CVE-2025-29927
web
Patched | CVE-2025-29927 | web | CRITICAL 9.1 | Patched | 2026-05-15 |
| MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)
EPSS 27% CVE-2020-17103
binary
Patched | CVE-2020-17103 | binary | HIGH 7.8 | Patched | 2026-05-15 |
| LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113)
EPSS 83% CVE-2024-49113
network
Patched | CVE-2024-49113 | network | CRITICAL | Patched | 2026-05-15 |
| HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)
KEV
EPSS 100% CVE-2021-31166
network
Patched | CVE-2021-31166 | network | CRITICAL 9.8 | Patched | 2026-05-15 |
| Exchange Health Checker Outbound Rule Blind Spot (CVE-2026-42897)
KEV
EPSS 71% CVE-2026-42897
web
Unverified | CVE-2026-42897 | web | MEDIUM 5.3 | Unverified | 2026-05-15 |
| CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel
KEV
RW
EPSS 60% CVE-2024-21338
binary
Patched | CVE-2024-21338 | binary | HIGH 7.8 | Patched | 2026-05-15 |
| BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)
KEV
RW CVE-2026-33825
binary
Patched | CVE-2026-33825 | binary | HIGH 7.8 | Patched | 2026-05-15 |
| BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)
CVE-2023-45866
network
Patched | CVE-2023-45866 | network | HIGH 8.8 | Patched | 2026-05-15 |
| NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945)
EPSS 68% CVE-2026-42945
web
Unverified | CVE-2026-42945 | web | CRITICAL 9.8 | Unverified | 2026-05-14 |
| Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)
CVE-2026-46300
binary
Patched | CVE-2026-46300 | binary | HIGH 7.8 | Patched | 2026-05-14 |
| Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE
EPSS 93% CVE-2026-43500, CVE-2026-43284
binary
Patched | CVE-2026-43500, CVE-2026-43284 | binary | CRITICAL 7.8 | Patched | 2026-05-14 |
| CVE-2026-27876: Grafana SQL Expressions Arbitrary File Write to RCE
Unverified | — | Unverified | 0001-01-01 |
No PoCs match the current filters.