| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-47670 | Cri | 0.54 | — | 0.02 | Jul 23, 2026 | DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the… | ||
| CVE-2026-47669 | Cri | 0.53 | — | 0.01 | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes… | ||
| CVE-2026-6516 | Cri | 0.00 | 10.0 | 0.05 | Jul 23, 2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. | ||
| CVE-2026-65701 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the… | ||
| CVE-2026-65700 | Cri | 0.00 | 9.8 | 0.02 | Jul 23, 2026 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The… | ||
| CVE-2026-47752 | Cri | 0.00 | 9.9 | 0.01 | Jul 23, 2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed… | ||
| CVE-2026-47668 | Cri | 0.58 | 10.0 | 0.04 | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated… | ||
| CVE-2026-44210 | Cri | 0.57 | 9.9 | 0.01 | Jul 23, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into… | ||
| CVE-2026-65761 | Cri | 0.00 | — | 0.01 | Jul 23, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. | ||
| CVE-2026-65760 | Cri | 0.00 | — | 0.00 | Jul 23, 2026 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system. | ||
| CVE-2026-15617 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. | ||
| CVE-2026-15616 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. | ||
| CVE-2026-15612 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. | ||
| CVE-2026-15611 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account. | ||
| CVE-2026-65689 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65688 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65687 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65907 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | ||
| CVE-2026-65606 | Cri | 0.62 | 9.6 | 0.01 | Jul 23, 2026 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/ link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab… | ||
| CVE-2026-65605 | Cri | 0.62 | 9.6 | 0.01 | Jul 23, 2026 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true;… | ||
| CVE-2026-65471 | Cri | 0.00 | 9.6 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | ||
| CVE-2026-65461 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | ||
| CVE-2026-65455 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-64813 | Cri | 0.00 | 10.0 | 0.01 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | ||
| CVE-2026-64812 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | ||
| CVE-2026-61951 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | ||
| CVE-2026-61950 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | ||
| CVE-2026-61949 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | ||
| CVE-2026-61948 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | ||
| CVE-2026-59555 | Cri | 0.00 | 10.0 | 0.01 | Jul 23, 2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | ||
| CVE-2026-59544 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | ||
| CVE-2026-59543 | Cri | 0.00 | 9.9 | 0.01 | Jul 23, 2026 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | ||
| CVE-2026-59540 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | ||
| CVE-2026-59526 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-59525 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | ||
| CVE-2026-59514 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | ||
| CVE-2026-57784 | Cri | 0.00 | 9.6 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||
| CVE-2026-27064 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | ||
| CVE-2026-65431 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. | ||
| CVE-2026-64874 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. | ||
| CVE-2026-64873 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | ||
| CVE-2026-15015 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | ||
| CVE-2026-15011 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation.… | ||
| CVE-2026-14282 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the… | ||
| CVE-2026-16723 | Cri | 0.00 | 9.0 | 0.01 | Jul 23, 2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. | ||
| CVE-2026-60372 | Cri | 0.00 | 9.8 | 0.01 | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with… | ||
| CVE-2026-60369 | Cri | 0.00 | 9.9 | 0.00 | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network… | ||
| CVE-2026-60367 | Cri | 0.00 | 9.8 | 0.01 | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with… | ||
| CVE-2026-60366 | Cri | 0.00 | 10.0 | 0.01 | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with… | ||
| CVE-2026-64798 | Cri | 0.00 | 9.1 | 0.00 | Jul 22, 2026 | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. |
- risk 0.54cvss —epss 0.02
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the…
- risk 0.53cvss —epss 0.01
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes…
- risk 0.00cvss 10.0epss 0.05
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
- risk 0.00cvss 9.1epss 0.01
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…
- risk 0.00cvss 9.8epss 0.02
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…
- risk 0.00cvss 9.9epss 0.01
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed…
- risk 0.58cvss 10.0epss 0.04
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated…
- risk 0.57cvss 9.9epss 0.01
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into…
- risk 0.00cvss —epss 0.01
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
- risk 0.00cvss —epss 0.00
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.
- risk 0.00cvss 9.1epss 0.00
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.
- risk 0.00cvss 9.1epss 0.01
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
- risk 0.00cvss 9.1epss 0.00
Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.
- risk 0.00cvss 9.1epss 0.00
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 9.1epss 0.01
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
- risk 0.62cvss 9.6epss 0.01
SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/ link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab…
- risk 0.62cvss 9.6epss 0.01
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true;…
- risk 0.00cvss 9.6epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
- risk 0.00cvss 9.1epss 0.01
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- risk 0.00cvss 9.1epss 0.01
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 10.0epss 0.01
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- risk 0.00cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
- risk 0.00cvss 10.0epss 0.01
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
- risk 0.00cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
- risk 0.00cvss 9.9epss 0.01
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
- risk 0.00cvss 9.6epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
- risk 0.00cvss 9.1epss 0.01
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
- risk 0.00cvss 9.8epss 0.01
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
- risk 0.00cvss 9.8epss 0.01
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
- risk 0.00cvss 9.8epss 0.01
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
- risk 0.00cvss 9.8epss 0.01
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation.…
- risk 0.00cvss 9.8epss 0.01
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the…
- risk 0.00cvss 9.0epss 0.01
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
- risk 0.00cvss 9.8epss 0.01
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…
- risk 0.00cvss 9.9epss 0.00
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…
- risk 0.00cvss 9.8epss 0.01
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…
- risk 0.00cvss 10.0epss 0.01
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…
- risk 0.00cvss 9.1epss 0.00
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.