| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-72841 | Cri | 0.64 | 9.9 | 0.01 | Aug 13, 2026 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code… | ||
| CVE-2026-72839 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and… | ||
| CVE-2026-72776 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard… | ||
| CVE-2026-8715 | Cri | 0.55 | 9.6 | 0.00 | Aug 13, 2026 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and… | ||
| CVE-2026-19297 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | ||
| CVE-2026-17482 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. | ||
| CVE-2026-73656 | Cri | 0.57 | 9.9 | 0.01 | Aug 13, 2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWo… | ||
| CVE-2026-19747 | Cri | 0.64 | 9.8 | 0.03 | Aug 13, 2026 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is… | ||
| CVE-2026-14525 | Cri | 0.61 | 9.4 | 0.01 | Aug 13, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. | ||
| CVE-2026-73653 | Cri | 0.54 | 9.4 | 0.01 | Aug 13, 2026 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without… | ||
| CVE-2026-73649 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in… | ||
| CVE-2026-73644 | Cri | 0.55 | 9.6 | 0.00 | Aug 13, 2026 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy… | ||
| CVE-2026-73567 | Cri | 0.52 | 9.1 | 0.00 | Aug 13, 2026 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by [email protected], which… | ||
| CVE-2026-67614 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a… | ||
| CVE-2026-58508 | Cri | 0.59 | 9.1 | 0.00 | Aug 13, 2026 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | ||
| CVE-2026-58443 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Public-only repository tokens can update private PR head branches | ||
| CVE-2026-58433 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting | ||
| CVE-2026-56750 | Cri | 0.52 | 9.1 | 0.00 | Aug 13, 2026 | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | ||
| CVE-2026-56654 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | Privilege Escalation via Access Token Scope Escalation in API | ||
| CVE-2026-56443 | Cri | 0.55 | 9.6 | 0.01 | Aug 13, 2026 | Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 | ||
| CVE-2026-55982 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | ||
| CVE-2026-13051 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the… | ||
| CVE-2022-4993 | Cri | 0.52 | 9.1 | 0.01 | Aug 13, 2026 | HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first… | ||
| CVE-2026-73533 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor… | ||
| CVE-2026-73532 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added… | ||
| CVE-2026-53791 | Cri | 0.52 | 9.1 | 0.01 | Aug 13, 2026 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync… | ||
| CVE-2026-66691 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | ||
| CVE-2026-66478 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | ||
| CVE-2026-66472 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | ||
| CVE-2026-66465 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | ||
| CVE-2026-66458 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | ||
| CVE-2026-66453 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||
| CVE-2026-66446 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||
| CVE-2026-66436 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | ||
| CVE-2026-66424 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||
| CVE-2026-61969 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. | ||
| CVE-2026-61967 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | ||
| CVE-2026-61966 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. | ||
| CVE-2026-61962 | Cri | 0.65 | 10.0 | 0.01 | Aug 13, 2026 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | ||
| CVE-2026-28185 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | ||
| CVE-2026-28149 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | ||
| CVE-2026-28148 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | ||
| CVE-2026-28142 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | ||
| CVE-2026-28008 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | ||
| CVE-2026-28001 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||
| CVE-2026-27544 | Cri | 0.65 | 10.0 | 0.01 | Aug 13, 2026 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | ||
| CVE-2026-49827 | Cri | 0.57 | 9.8 | 0.01 | Aug 13, 2026 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open… | ||
| CVE-2026-73602 | Cri | 0.57 | 9.9 | 0.01 | Aug 13, 2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path… | ||
| CVE-2026-73487 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate… | ||
| CVE-2026-59507 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP… |
- risk 0.64cvss 9.9epss 0.01
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code…
- risk 0.57cvss 9.8epss 0.01
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and…
- risk 0.57cvss 9.8epss 0.01
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard…
- risk 0.55cvss 9.6epss 0.00
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and…
- risk 0.59cvss 9.1epss 0.01
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
- risk 0.64cvss 9.8epss 0.01
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
- risk 0.57cvss 9.9epss 0.01
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWo…
- risk 0.64cvss 9.8epss 0.03
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is…
- risk 0.61cvss 9.4epss 0.01
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
- risk 0.54cvss 9.4epss 0.01
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without…
- risk 0.57cvss 9.8epss 0.01
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in…
- risk 0.55cvss 9.6epss 0.00
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy…
- risk 0.52cvss 9.1epss 0.00
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by [email protected], which…
- risk 0.57cvss 9.8epss 0.01
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a…
- risk 0.59cvss 9.1epss 0.00
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
- risk 0.59cvss 9.1epss 0.01
Public-only repository tokens can update private PR head branches
- risk 0.59cvss 9.1epss 0.01
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
- risk 0.52cvss 9.1epss 0.00
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
- risk 0.57cvss 9.8epss 0.01
Privilege Escalation via Access Token Scope Escalation in API
- risk 0.55cvss 9.6epss 0.01
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
- risk 0.59cvss 9.1epss 0.01
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
- risk 0.59cvss 9.1epss 0.01
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the…
- risk 0.52cvss 9.1epss 0.01
HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first…
- risk 0.64cvss 9.8epss 0.01
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor…
- risk 0.64cvss 9.8epss 0.01
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added…
- risk 0.52cvss 9.1epss 0.01
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync…
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
- risk 0.60cvss 9.3epss 0.00
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
- risk 0.60cvss 9.3epss 0.00
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
- risk 0.57cvss 9.8epss 0.01
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open…
- risk 0.57cvss 9.9epss 0.01
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path…
- risk 0.64cvss 9.8epss 0.01
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate…
- risk 0.60cvss 9.3epss 0.00
: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP…