| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-56654 | Cri | 0.57 | 9.8 | — | Aug 13, 2026 | Privilege Escalation via Access Token Scope Escalation in API | ||
| CVE-2026-56443 | Cri | 0.62 | 9.6 | — | Aug 13, 2026 | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | ||
| CVE-2026-55982 | Cri | 0.59 | 9.1 | — | Aug 13, 2026 | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | ||
| CVE-2026-13051 | Cri | 0.59 | 9.1 | — | Aug 13, 2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the… | ||
| CVE-2022-4993 | Cri | 0.59 | 9.1 | — | Aug 13, 2026 | HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first… | ||
| CVE-2026-73533 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor… | ||
| CVE-2026-73532 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added… | ||
| CVE-2026-53791 | Cri | 0.52 | 9.1 | — | Aug 13, 2026 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync… | ||
| CVE-2026-66691 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | ||
| CVE-2026-66478 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | ||
| CVE-2026-66472 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | ||
| CVE-2026-66465 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | ||
| CVE-2026-66458 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | ||
| CVE-2026-66453 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||
| CVE-2026-66446 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||
| CVE-2026-66436 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | ||
| CVE-2026-66424 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||
| CVE-2026-61969 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. | ||
| CVE-2026-61967 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | ||
| CVE-2026-61966 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. | ||
| CVE-2026-61962 | Cri | 0.65 | 10.0 | — | Aug 13, 2026 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | ||
| CVE-2026-28185 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | ||
| CVE-2026-28149 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | ||
| CVE-2026-28148 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | ||
| CVE-2026-28142 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | ||
| CVE-2026-28008 | Cri | 0.64 | 9.8 | — | Aug 13, 2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | ||
| CVE-2026-28001 | Cri | 0.60 | 9.3 | — | Aug 13, 2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||
| CVE-2026-27544 | Cri | 0.65 | 10.0 | — | Aug 13, 2026 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | ||
| CVE-2026-49827 | Cri | 0.57 | 9.8 | — | Aug 13, 2026 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open… | ||
| CVE-2026-73602 | Cri | 0.52 | — | — | Aug 13, 2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path… | ||
| CVE-2026-73601 | Cri | 0.59 | — | — | Aug 13, 2026 | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can… | ||
| CVE-2026-73487 | Cri | 0.59 | — | — | Aug 13, 2026 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate… | ||
| CVE-2026-73486 | Cri | 0.59 | — | — | Aug 13, 2026 | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques,… | ||
| CVE-2026-73485 | Cri | 0.59 | — | — | Aug 13, 2026 | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a… | ||
| CVE-2026-73483 | Cri | 0.61 | — | — | Aug 13, 2026 | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled… | ||
| CVE-2026-59507 | — | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control | |
| CVE-2026-59506 | — | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | CWE-306: Missing Authentication for Critical Function | |
| CVE-2026-59504 | — | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2026 | CWE-602: Client-Side Enforcement of Server-Side Security | |
| CVE-2026-59503 | — | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2026 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor | |
| CVE-2026-59500 | — | Cri | 0.65 | 10.0 | 0.00 | Aug 13, 2026 | CWE-287: Improper Authentication | |
| CVE-2026-15413 | Cri | 0.65 | 10.0 | 0.00 | Aug 13, 2026 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except… | ||
| CVE-2026-14182 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and… | ||
| CVE-2026-49819 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any… | ||
| CVE-2026-16770 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through… | ||
| CVE-2026-71193 | Cri | 0.55 | 9.6 | 0.01 | Aug 12, 2026 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter… | ||
| CVE-2026-49481 | Cri | 0.55 | 9.6 | 0.01 | Aug 12, 2026 | UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be… | ||
| CVE-2026-73519 | Cri | 0.57 | 9.8 | 0.01 | Aug 12, 2026 | WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to… | ||
| CVE-2026-73501 | Cri | 0.52 | 9.1 | 0.00 | Aug 12, 2026 | kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution… | ||
| CVE-2026-71471 | Cri | 0.59 | 9.0 | 0.01 | Aug 12, 2026 | A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an… | ||
| CVE-2026-18749 | Cri | 0.57 | 9.8 | 0.00 | Aug 12, 2026 | The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released… |
- risk 0.57cvss 9.8epss —
Privilege Escalation via Access Token Scope Escalation in API
- risk 0.62cvss 9.6epss —
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
- risk 0.59cvss 9.1epss —
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
- risk 0.59cvss 9.1epss —
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the…
- risk 0.59cvss 9.1epss —
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first…
- risk 0.64cvss 9.8epss —
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor…
- risk 0.64cvss 9.8epss —
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added…
- risk 0.52cvss 9.1epss —
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync…
- risk 0.64cvss 9.8epss —
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
- risk 0.60cvss 9.3epss —
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
- risk 0.60cvss 9.3epss —
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
- risk 0.60cvss 9.3epss —
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
- risk 0.60cvss 9.3epss —
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
- risk 0.60cvss 9.3epss —
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
- risk 0.60cvss 9.3epss —
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
- risk 0.60cvss 9.3epss —
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
- risk 0.65cvss 10.0epss —
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
- risk 0.60cvss 9.3epss —
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
- risk 0.64cvss 9.8epss —
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
- risk 0.60cvss 9.3epss —
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
- risk 0.65cvss 10.0epss —
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
- risk 0.57cvss 9.8epss —
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open…
- risk 0.52cvss —epss —
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path…
- risk 0.59cvss —epss —
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can…
- risk 0.59cvss —epss —
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate…
- risk 0.59cvss —epss —
Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques,…
- risk 0.59cvss —epss —
Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a…
- risk 0.61cvss —epss —
Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled…
- risk 0.60cvss 9.3epss 0.00
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
- risk 0.60cvss 9.3epss 0.00
CWE-306: Missing Authentication for Critical Function
- risk 0.59cvss 9.1epss 0.00
CWE-602: Client-Side Enforcement of Server-Side Security
- risk 0.59cvss 9.1epss 0.00
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
- risk 0.65cvss 10.0epss 0.00
CWE-287: Improper Authentication
- risk 0.65cvss 10.0epss 0.00
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except…
- risk 0.64cvss 9.8epss 0.00
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and…
- risk 0.57cvss 9.8epss 0.01
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any…
- risk 0.64cvss 9.8epss 0.00
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through…
- risk 0.55cvss 9.6epss 0.01
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter…
- risk 0.55cvss 9.6epss 0.01
UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be…
- risk 0.57cvss 9.8epss 0.01
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to…
- risk 0.52cvss 9.1epss 0.00
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution…
- risk 0.59cvss 9.0epss 0.01
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an…
- risk 0.57cvss 9.8epss 0.00
The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released…