Too Many Attempts

Please wait before trying again

30
Cyber Intelligence Platform

See what
others can't.

AI-assisted vulnerability scanning, attack surface discovery, and CVE monitoring for teams that need clear, repeatable security checks.

All Systems Operational · Threat Level Nominal
Threat IntelligenceAttack Surface MappingAutonomous ResponseZero-Day DetectionNetwork ForensicsAdversary SimulationVulnerability OrchestrationContinuous MonitoringThreat IntelligenceAttack Surface MappingAutonomous ResponseZero-Day DetectionNetwork ForensicsAdversary SimulationVulnerability OrchestrationContinuous Monitoring
Collaborating with global innovators
Working natively with leading platforms
Accepted into global startup programs
NVIDIA
Inception Program
Zendesk
for Startups
Capabilities

Built for the threats that haven't happened yet.

001

Threat Cartography

Continuous mapping of your attack surface across every layer — from exposed APIs to shadow infrastructure nobody told you about.

002

Risk Prioritisation

Correlates scan findings with CVE intelligence and severity data so teams can focus on the exposures most likely to matter.

003

Automated Validation

Runs repeatable security checks and rescans to help confirm findings and verify whether remediation changed the exposed attack surface.

004

Protocol & Configuration Checks

Reviews exposed services, TLS configuration, DNS, headers, and detected technologies for common weaknesses and outdated components.

005

Adversary Emulation

Continuous red-team operations powered by threat actor profiles. We think like them so you don't have to.

006

Sentinel Protocol

Distributed sensor mesh across your infrastructure. Silent watchers that leap into action the moment anomalies surface.

Real-Time Intelligence

The network never sleeps.

0
NVD Sync Interval
0
Scans Executed Daily
0
CVEs in Coverage Database
0
Threat Intel Feeds Integrated
Latest Research

Fresh from our research desk.

Recent vulnerability analysis and defensive notes from the Vesamuni research desk.

Latest research is loading.
Our Approach

Defence in depth,
by design.

01

Map

Comprehensive reconnaissance of your digital terrain. We discover assets, dependencies, and exposures across cloud, on-prem, and hybrid environments.

02

Analyse

Contextual risk scoring powered by threat intelligence feeds, adversary TTPs, and your unique business logic. Not just CVEs — real-world exploitability.

03

Fortify

Automated hardening recommendations deployed through your existing CI/CD pipeline. Security becomes part of the build, not an afterthought.

04

Evolve

Continuous learning from global threat landscapes. The platform adapts its defensive posture as adversary capabilities shift and new vectors emerge.

Ready to see
everything?

Join the organisations that refuse to be reactive. Get early access to the Vesamuni intelligence platform.

Powered By

Built on industry-leading intelligence.

We integrate with the world's most trusted security data sources and infrastructure providers to deliver comprehensive threat intelligence.

Documentation

Platform Documentation

Overview

Vesamuni is an early-stage cyber security platform that brings vulnerability scanning, CVE intelligence, attack surface discovery, and security reporting into a single dashboard.

Account access uses server-side sessions, Argon2 password hashing, CSRF protection, secure cookies, and optional authenticator-based two-factor authentication.

Getting Started

Vesamuni is currently in early access. Approved clients receive an account from the team.

Step 1
Receive and accept your client invitation.

Step 2
Sign in and add the public URL you want to monitor.

Step 3
Enable two-factor authentication from the security dashboard.

Step 4
Contact the team to confirm scan scope during early access.

Authentication

The current client dashboard uses secure server-side sessions. Public API credentials are not generally available during early access.

API Reference

A public scanning API is planned but not yet released. Current HTTP endpoints support the website, account management, billing, and internal administration.

Integrations

Stripe billing is available now. Additional workflow integrations and public SDKs are roadmap items and will be documented only when released.

About

We build what defenders need.

Vesamuni was founded with a singular conviction: the asymmetry between attackers and defenders is a design problem, not an inevitability.

Our Philosophy

We don't believe in security theatre. Every feature should help teams discover, understand, or remediate a real exposure. Vesamuni is being built iteratively with feedback from security-minded operators and developers.

Global Presence

We operate from Melbourne, Australia and Colombo, Sri Lanka. Our distributed startup team combines product development with security research across the APAC region.

Why Two Continents?

Melbourne connects us to Australia's security market. Colombo connects us to South Asia's rapidly growing tech ecosystem. The two locations give the team access to different customers, talent pools, and perspectives.

The Name

Vesamuni (වෙසමුනි) — In Sri Lankan folklore, Vesamuni is the fearsome king of demons. He rules the Yakkas with an iron fist, commanding spirits that once spread chaos across the land. Yet he chose to protect rather than destroy — forbidding his demons from killing, transforming them into instruments of order.

Armed with a magical golden sword that flies from his hand to strike down enemies before they see it coming, Vesamuni embodies power turned to protection.

We do the same. The tools of attackers, wielded by defenders.

Careers

Join us.

We're a small team building something meaningful. If you're passionate about security and want to make an impact, we'd love to hear from you.

founders@vesamuni.com

Melbourne, Australia · Colombo, Sri Lanka · Remote

Research

Coming soon.

We're working on publishing our security research. Follow us to get notified when we release new findings.

research@vesamuni.com
Blog

Security notes, product thinking, and threat intelligence.

Updates from the Vesamuni team on defensive engineering, attack surface management, vulnerability research, and practical security operations.

CVE-2026-86551: Z80Ultra (NX741J) product contains a vulnerability whe
21/09/2026 / CVE, CWE-668, Security Research

CVE-2026-86551: Z80Ultra (NX741J) product contains a vulnerability whe

ApplicationThe Z80Ultra (NX741J) product
TypeSoftware weakness
Read post
CVE-2026-93957: A vulnerability has been found in olivier-ls PHP-FTS u
21/09/2026 / CVE, CWE-697, Security Research

CVE-2026-93957: A vulnerability has been found in olivier-ls PHP-FTS u

Applicationolivier-ls PHP-FTS
TypeSoftware weakness
Read post
CVE-2026-93958: A vulnerability was found in D-Link R95 BE9500_1.00.16
21/09/2026 / CVE, CWE-77, Security Research

CVE-2026-93958: A vulnerability was found in D-Link R95 BE9500_1.00.16

ApplicationD-Link R95 BE9500_1.00.16.
TypeSoftware weakness
Read post
CVE-2026-94083: Suricata before 8.0.7 has a DoH2 type confusion that c
21/09/2026 / CVE, CWE-843, Security Research

CVE-2026-94083: Suricata before 8.0.7 has a DoH2 type confusion that c

ApplicationSuricata
TypeSoftware weakness
Read post
CVE-2026-94084: Suricata before 8.0.7 has an Http2ThreadMultiBuf use-a
21/09/2026 / CVE, CWE-416, Security Research

CVE-2026-94084: Suricata before 8.0.7 has an Http2ThreadMultiBuf use-a

ApplicationSuricata
TypeSoftware weakness
Read post
CVE-2026-77875: application protects access through its calculator-sty
20/09/2026 / CVE, CWE-922, Security Research

CVE-2026-77875: application protects access through its calculator-sty

ApplicationThe application protects access
TypeSoftware weakness
Read post
CVE-2026-93921: SiYuan versions through 3.8.4 fail to enforce publish
20/09/2026 / CVE, CWE-862, Security Research

CVE-2026-93921: SiYuan versions through 3.8.4 fail to enforce publish

ApplicationSiYuan
TypeSoftware weakness
Read post
CVE-2026-93922: SiYuan through 3.8.4 renders notebook names as raw HTM
20/09/2026 / CVE, CWE-79, Security Research

CVE-2026-93922: SiYuan through 3.8.4 renders notebook names as raw HTM

ApplicationSiYuan
TypeCross-site scripting
Read post
CVE-2026-93923: SiYuan through 3.8.4 fails to escape heading style att
20/09/2026 / CVE, CWE-79, Security Research

CVE-2026-93923: SiYuan through 3.8.4 fails to escape heading style att

ApplicationSiYuan
TypeCross-site scripting
Read post
CVE-2026-77820: WPComplete plugin for WordPress
20/09/2026 / CVE, CWE-79, Security Research

CVE-2026-77820: WPComplete plugin for WordPress

ApplicationThe WPComplete plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-18441: Appointment Booking Plugin – LatePoint | Calendar & Sc
19/09/2026 / CVE, CWE-639, Security Research

CVE-2026-18441: Appointment Booking Plugin – LatePoint | Calendar & Sc

Applicationall
TypeIDOR access control flaw
Read post
CVE-2026-2585: Brizy – Page Builder plugin for WordPress
19/09/2026 / CVE, CWE-79, Security Research

CVE-2026-2585: Brizy – Page Builder plugin for WordPress

ApplicationThe Brizy – Page Builder plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-62874: Insufficient verification of data authenticity in Azur
19/09/2026 / CVE, CWE-345, Security Research

CVE-2026-62874: Insufficient verification of data authenticity in Azur

ApplicationInsufficient verification of data authenticity in Azure Billing
TypeSoftware weakness
Read post
CVE-2026-69843: Authentication bypass by spoofing in Microsoft Fabric
19/09/2026 / CVE, CWE-290, Security Research

CVE-2026-69843: Authentication bypass by spoofing in Microsoft Fabric

ApplicationAuthentication bypass by spoofing in Microsoft Fabric
TypeSoftware weakness
Read post
CVE-2026-83946: Improper neutralization of input during web page gener
19/09/2026 / CVE, CWE-79, Security Research

CVE-2026-83946: Improper neutralization of input during web page gener

ApplicationAzure Portal
TypeCross-site scripting
Read post
CVE-2026-81546: Affinity by Canva application before 3.3.0 (September
18/09/2026 / CVE, CWE-121, Security Research

CVE-2026-81546: Affinity by Canva application before 3.3.0 (September

ApplicationThe Affinity by Canva application
TypeSoftware weakness
Read post
CVE-2026-92838: A DLL hijacking
vulnerability exists in the GeoVision
18/09/2026 / CVE, CWE-427, Security Research

CVE-2026-92838: A DLL hijacking vulnerability exists in the GeoVision

Applicationthe GeoVision GV-Remote E-Map desktop application
TypeSoftware weakness
Read post
CVE-2026-89064: All-in-One WP Migration and Backup plugin for WordPres
18/09/2026 / CVE, CWE-522, Security Research

CVE-2026-89064: All-in-One WP Migration and Backup plugin for WordPres

ApplicationThe All-in-One WP Migration and Backup plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-50603: A vulnerability has been identified in the Acer Agent
18/09/2026 / CVE, CWE-321, Security Research

CVE-2026-50603: A vulnerability has been identified in the Acer Agent

Applicationthe Acer Agent
TypeSoftware weakness
Read post
CVE-2026-86311: Photo Gallery by 10Web – Mobile-Friendly Image Gallery
18/09/2026 / CVE, CWE-79, Security Research

CVE-2026-86311: Photo Gallery by 10Web – Mobile-Friendly Image Gallery

ApplicationThe Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-15638: An unauthenticated user with access to Secret Server c
17/09/2026 / CVE, CWE-327, Security Research

CVE-2026-15638: An unauthenticated user with access to Secret Server c

ApplicationApplication not specified
TypeWeak cryptography
Read post
CVE-2026-15639: An attacker can craft a malicious link that, if used b
17/09/2026 / CVE, CWE-79, Security Research

CVE-2026-15639: An attacker can craft a malicious link that, if used b

ApplicationAn attacker can craft a malicious link that
TypeCross-site scripting
Read post
CVE-2026-15640: Under certain conditions a valid SAML IdP response may
17/09/2026 / CVE, CWE-290, Security Research

CVE-2026-15640: Under certain conditions a valid SAML IdP response may

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-73446: On affected platforms running Arista EOS with IS-IS co
17/09/2026 / CVE, CWE-696, Security Research

CVE-2026-73446: On affected platforms running Arista EOS with IS-IS co

ApplicationOn affected platforms running Arista EOS with
TypeSoftware weakness
Read post
CVE-2026-73459: On affected platforms running Arista EOS with IS-IS co
17/09/2026 / CVE, CWE-354, Security Research

CVE-2026-73459: On affected platforms running Arista EOS with IS-IS co

ApplicationOn affected platforms running Arista EOS with
TypeSoftware weakness
Read post
CVE-2026-90840: A vulnerability was identified in PHPGurukul Blood Don
16/09/2026 / CVE, CWE-287, Security Research

CVE-2026-90840: A vulnerability was identified in PHPGurukul Blood Don

ApplicationPHPGurukul Blood Donor
TypeImproper authentication
Read post
CVE-2026-90841: A security flaw has been discovered in PHPGurukul Bloo
16/09/2026 / CVE, CWE-74, Security Research

CVE-2026-90841: A security flaw has been discovered in PHPGurukul Bloo

ApplicationA security flaw
TypeInjection vulnerability
Read post
CVE-2026-90842: A weakness has been identified in PHPGurukul Blood Don
16/09/2026 / CVE, CWE-312, Security Research

CVE-2026-90842: A weakness has been identified in PHPGurukul Blood Don

ApplicationPHPGurukul Blood Donor
TypeSoftware weakness
Read post
CVE-2026-85575: ShopEngine Elementor WooCommerce Builder Addon – All i
16/09/2026 / CVE, CWE-79, Security Research

CVE-2026-85575: ShopEngine Elementor WooCommerce Builder Addon – All i

Applicationall
TypeCross-site scripting
Read post
CVE-2026-85657: Co-Authors, Multiple Authors and Guest Authors in an A
16/09/2026 / CVE, CWE-79, Security Research

CVE-2026-85657: Co-Authors, Multiple Authors and Guest Authors in an A

ApplicationThe Co-Authors
TypeCross-site scripting
Read post
CVE-2022-42917: In FRRouting FRR before 8.5, the service user (usually
15/09/2026 / CVE, CWE-367, Security Research

CVE-2022-42917: In FRRouting FRR before 8.5, the service user (usually

ApplicationIn FRRouting FRR
TypeSoftware weakness
Read post
CVE-2024-53922: An issue was discovered in the buffer queue driver in
15/09/2026 / CVE, CWE-1284, Security Research

CVE-2024-53922: An issue was discovered in the buffer queue driver in

ApplicationAn
TypeSoftware weakness
Read post
CVE-2025-63842: A Cross-Site Scripting (XSS) vulnerability in the web
15/09/2026 / CVE, CWE-79, Security Research

CVE-2025-63842: A Cross-Site Scripting (XSS) vulnerability in the web

Applicationthe web backend for the Repetico app 1
TypeCross-site scripting
Read post
CVE-2026-90604: A security flaw has been discovered in Totolink A3002M
15/09/2026 / CVE, CWE-79, Security Research

CVE-2026-90604: A security flaw has been discovered in Totolink A3002M

ApplicationA security flaw
TypeCross-site scripting
Read post
CVE-2026-90605: A weakness has been identified in Totolink A3002MU Hh-
15/09/2026 / CVE, CWE-119, Security Research

CVE-2026-90605: A weakness has been identified in Totolink A3002MU Hh-

ApplicationTotolink A3002MU Hh-B20211125.1046.
TypeSoftware weakness
Read post
CVE-2026-90488: A vulnerability was determined in Xuxueli xxl-job up t
14/09/2026 / CVE, CWE-74, Security Research

CVE-2026-90488: A vulnerability was determined in Xuxueli xxl-job up t

ApplicationXuxueli xxl-job
TypeInjection vulnerability
Read post
CVE-2026-90489: A vulnerability was identified in Xuxueli xxl-job up t
14/09/2026 / CVE, CWE-79, Security Research

CVE-2026-90489: A vulnerability was identified in Xuxueli xxl-job up t

ApplicationXuxueli xxl-job
TypeCross-site scripting
Read post
CVE-2026-90648: wasm2c in WebAssembly wabt through 1.0.41 allows sandb
14/09/2026 / CVE, CWE-252, Security Research

CVE-2026-90648: wasm2c in WebAssembly wabt through 1.0.41 allows sandb

Applicationwasm2c in WebAssembly wabt
TypeSoftware weakness
Read post
CVE-2026-90651: Socket Firewall (socketdev/socket-registry-firewall) i
14/09/2026 / CVE, CWE-295, Security Research

CVE-2026-90651: Socket Firewall (socketdev/socket-registry-firewall) i

ApplicationSocket Firewall (socketdev/socket-registry-firewall) in registry mode
TypeSoftware weakness
Read post
CVE-2026-90490: A security flaw has been discovered in lenve vhr 1.0-S
14/09/2026 / CVE, CWE-20, Security Research

CVE-2026-90490: A security flaw has been discovered in lenve vhr 1.0-S

ApplicationA security flaw
TypeSoftware weakness
Read post
CVE-2026-89266: stb_vorbis through 1.22 contains a heap buffer overflo
13/09/2026 / CVE, CWE-787, Security Research

CVE-2026-89266: stb_vorbis through 1.22 contains a heap buffer overflo

Applicationstb_vorbis
TypeOut-of-bounds write
Read post
CVE-2026-89267: starlette-admin versions 0.16.1 through 0.17.1 fail to
13/09/2026 / CVE, CWE-863, Security Research

CVE-2026-89267: starlette-admin versions 0.16.1 through 0.17.1 fail to

Applicationstarlette-admin
TypeSoftware weakness
Read post
CVE-2026-89268: QloApps through 1.7.0 renders back-office list filter
13/09/2026 / CVE, CWE-79, Security Research

CVE-2026-89268: QloApps through 1.7.0 renders back-office list filter

ApplicationQloApps
TypeCross-site scripting
Read post
CVE-2026-90467: aiosmtplib before 5.1.3 fails to properly validate ema
13/09/2026 / CVE, CWE-88, Security Research

CVE-2026-90467: aiosmtplib before 5.1.3 fails to properly validate ema

Applicationaiosmtplib
TypeSoftware weakness
Read post
CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecti
13/09/2026 / CVE, CWE-22, Security Research

CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecti

ApplicationGitLab
TypePath traversal
Read post
CVE-2026-17176: An OS
command injection vulnerability in the TDDP modu
12/09/2026 / CVE, CWE-78, Security Research

CVE-2026-17176: An OS command injection vulnerability in the TDDP modu

ApplicationAn OS command injection vulnerability in the TDDP module of Deco BE11000
TypeCommand injection
Read post
CVE-2026-18121: Concrete CMS 9.5.2 and below is vulnerable to an autho
12/09/2026 / CVE, CWE-639, Security Research

CVE-2026-18121: Concrete CMS 9.5.2 and below is vulnerable to an autho

ApplicationConcrete CMS 9
TypeIDOR access control flaw
Read post
CVE-2026-77807: AcyMailing – An Ultimate Newsletter Plugin and Marketi
12/09/2026 / CVE, CWE-22, Security Research

CVE-2026-77807: AcyMailing – An Ultimate Newsletter Plugin and Marketi

Applicationall
TypePath traversal
Read post
CVE-2026-81905: Concrete CMS below 9.5.3 stores user validation hashes
12/09/2026 / CVE, CWE-640, Security Research

CVE-2026-81905: Concrete CMS below 9.5.3 stores user validation hashes

ApplicationConcrete CMS below 9
TypeSoftware weakness
Read post
CVE-2026-81906: Concrete CMS OAuth callback login path prior to versio
12/09/2026 / CVE, CWE-288, Security Research

CVE-2026-81906: Concrete CMS OAuth callback login path prior to versio

ApplicationConcrete CMS OAuth callback login path
TypeSoftware weakness
Read post
CVE-2026-87925: A vulnerability was detected in Rizwan17 inventory-man
11/09/2026 / CVE, CWE-74, Security Research

CVE-2026-87925: A vulnerability was detected in Rizwan17 inventory-man

ApplicationRizwan17 inventory-management-system
TypeInjection vulnerability
Read post
CVE-2026-87926: A flaw has been found in Rizwan17 inventory-management
11/09/2026 / CVE, CWE-79, Security Research

CVE-2026-87926: A flaw has been found in Rizwan17 inventory-management

ApplicationRizwan17 inventory-management-system
TypeCross-site scripting
Read post
CVE-2026-87931: A vulnerability has been found in Behavioral Technolog
11/09/2026 / CVE, CWE-119, Security Research

CVE-2026-87931: A vulnerability has been found in Behavioral Technolog

ApplicationBehavioral Technology Group
TypeSoftware weakness
Read post
CVE-2026-87933: A vulnerability was found in DaveGamble cJSON up to 1.
11/09/2026 / CVE, CWE-119, Security Research

CVE-2026-87933: A vulnerability was found in DaveGamble cJSON up to 1.

ApplicationDaveGamble cJSON
TypeSoftware weakness
Read post
CVE-2026-18351: Drag and Drop File Upload for Elementor Forms plugin f
11/09/2026 / CVE, CWE-434, Security Research

CVE-2026-18351: Drag and Drop File Upload for Elementor Forms plugin f

ApplicationThe Drag and Drop File Upload for Elementor Forms plugin for WordPress
TypeFile upload vulnerability
Read post
CVE-2026-19201: An uncontrolled recursion vulnerability in the Windows
10/09/2026 / CVE, CWE-674, Security Research

CVE-2026-19201: An uncontrolled recursion vulnerability in the Windows

Applicationthe Windows SIPA event log parser of Google go-attestation
TypeSoftware weakness
Read post
CVE-2026-53937: MCP Kotlin SDK is the Kotlin Multiplatform software de
10/09/2026 / CVE, CWE-400, Security Research

CVE-2026-53937: MCP Kotlin SDK is the Kotlin Multiplatform software de

ApplicationMCP Kotlin SDK
TypeSoftware weakness
Read post
CVE-2026-53938: OpenIDC/cjose is a C library implementing the Javascri
10/09/2026 / CVE, CWE-122, Security Research

CVE-2026-53938: OpenIDC/cjose is a C library implementing the Javascri

ApplicationOpenIDC/cjose
TypeSoftware weakness
Read post
CVE-2026-53939: OpenIDC/cjose is a C library implementing the Javascri
10/09/2026 / CVE, CWE-321, Security Research

CVE-2026-53939: OpenIDC/cjose is a C library implementing the Javascri

ApplicationOpenIDC/cjose
TypeSoftware weakness
Read post
CVE-2026-87429: Missing authorization in ServiceWorker in Google Chrom
10/09/2026 / CVE, CWE-862, Security Research

CVE-2026-87429: Missing authorization in ServiceWorker in Google Chrom

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-44756: A memory safety vulnerability exists in the Extended P
09/09/2026 / CVE, CWE-120, Security Research

CVE-2026-44756: A memory safety vulnerability exists in the Extended P

Applicationthe Extended Passport Protocol (EPP) processing library
TypeSoftware weakness
Read post
CVE-2026-44766: SAP S/4HANA (Intercompany Matching and Reconciliation)
09/09/2026 / CVE, CWE-89, Security Research

CVE-2026-44766: SAP S/4HANA (Intercompany Matching and Reconciliation)

ApplicationSAP S/4HANA (Intercompany Matching and Reconciliation)
TypeSQL injection
Read post
CVE-2026-58234: SAP Process Integration (SOAP Adapter) allows a privil
09/09/2026 / CVE, CWE-776, Security Research

CVE-2026-58234: SAP Process Integration (SOAP Adapter) allows a privil

ApplicationSAP Process Integration (SOAP Adapter)
TypeSoftware weakness
Read post
CVE-2026-58240: SAP NetWeaver Message Server does not sufficiently val
09/09/2026 / CVE, CWE-308, Security Research

CVE-2026-58240: SAP NetWeaver Message Server does not sufficiently val

Applicationa high impact on the confidentiality
TypeSoftware weakness
Read post
CVE-2026-66767: SAP NetWeaver Application Server for ABAP and ABAP Pla
09/09/2026 / CVE, CWE-191, Security Research

CVE-2026-66767: SAP NetWeaver Application Server for ABAP and ABAP Pla

ApplicationSAP NetWeaver Application Server for ABAP and ABAP Platform
TypeSoftware weakness
Read post
CVE-2026-86233: A security vulnerability has been detected in itsource
08/09/2026 / CVE, CWE-74, Security Research

CVE-2026-86233: A security vulnerability has been detected in itsource

Applicationitsourcecode Sales and
TypeInjection vulnerability
Read post
CVE-2026-86234: A vulnerability was detected in itsourcecode Sales and
08/09/2026 / CVE, CWE-74, Security Research

CVE-2026-86234: A vulnerability was detected in itsourcecode Sales and

Applicationitsourcecode Sales and
TypeInjection vulnerability
Read post
CVE-2026-86235: A flaw has been found in itsourcecode Sales and Invent
08/09/2026 / CVE, CWE-74, Security Research

CVE-2026-86235: A flaw has been found in itsourcecode Sales and Invent

Applicationitsourcecode Sales and
TypeInjection vulnerability
Read post
CVE-2026-86236: A vulnerability has been found in itsourcecode Sales a
08/09/2026 / CVE, CWE-74, Security Research

CVE-2026-86236: A vulnerability has been found in itsourcecode Sales a

Applicationitsourcecode Sales and
TypeInjection vulnerability
Read post
CVE-2026-86237: A vulnerability was found in openagents-org openagents
08/09/2026 / CVE, CWE-918, Security Research

CVE-2026-86237: A vulnerability was found in openagents-org openagents

Applicationopenagents-org openagents
TypeServer-side request forgery
Read post
CVE-2026-86151: A vulnerability was detected in Tenda CP3 27.5.57.101.
07/09/2026 / CVE, CWE-77, Security Research

CVE-2026-86151: A vulnerability was detected in Tenda CP3 27.5.57.101.

ApplicationTenda CP3 27.5.57.101.
TypeSoftware weakness
Read post
CVE-2026-86152: A flaw has been found in Tenda CP3 27.5.57.101.
07/09/2026 / CVE, CWE-77, Security Research

CVE-2026-86152: A flaw has been found in Tenda CP3 27.5.57.101.

ApplicationTenda CP3 27.5.57.101.
TypeSoftware weakness
Read post
CVE-2026-86153: A vulnerability has been found in Tenda CP3 27.5.57.10
07/09/2026 / CVE, CWE-266, Security Research

CVE-2026-86153: A vulnerability has been found in Tenda CP3 27.5.57.10

ApplicationTenda CP3 27.5.57.101.
TypeIncorrect privilege assignment
Read post
CVE-2026-16310: MemberDash plugin for WordPress
07/09/2026 / CVE, CWE-639, Security Research

CVE-2026-16310: MemberDash plugin for WordPress

ApplicationThe MemberDash plugin for WordPress
TypeIDOR access control flaw
Read post
CVE-2026-18056: HivePress Authentication plugin for WordPress
07/09/2026 / CVE, CWE-287, Security Research

CVE-2026-18056: HivePress Authentication plugin for WordPress

ApplicationThe HivePress Authentication plugin for WordPress
TypeImproper authentication
Read post
CVE-2026-52762: YesWiki is a wiki system written in PHP.
06/09/2026 / CVE, CWE-1336, Security Research

CVE-2026-52762: YesWiki is a wiki system written in PHP.

ApplicationYesWiki
TypeSoftware weakness
Read post
CVE-2026-52763: YesWiki is a wiki system written in PHP.
06/09/2026 / CVE, CWE-89, Security Research

CVE-2026-52763: YesWiki is a wiki system written in PHP.

ApplicationYesWiki
TypeSQL injection
Read post
CVE-2026-52766: YesWiki is a wiki system written in PHP.
06/09/2026 / CVE, CWE-276, Security Research

CVE-2026-52766: YesWiki is a wiki system written in PHP.

ApplicationYesWiki
TypeSoftware weakness
Read post
CVE-2026-52767: YesWiki is a wiki system written in PHP.
06/09/2026 / CVE, CWE-347, Security Research

CVE-2026-52767: YesWiki is a wiki system written in PHP.

ApplicationYesWiki
TypeSoftware weakness
Read post
CVE-2026-52769: YesWiki is a wiki system written in PHP.
06/09/2026 / CVE, CWE-918, Security Research

CVE-2026-52769: YesWiki is a wiki system written in PHP.

ApplicationYesWiki
TypeServer-side request forgery
Read post
CVE-2026-49509: Out-of-bounds read vulnerability in Samsung Opensource
05/09/2026 / CVE, CWE-125, Security Research

CVE-2026-49509: Out-of-bounds read vulnerability in Samsung Opensource

ApplicationOut-of-bounds read vulnerability in Samsung Opensource Escargot
TypeOut-of-bounds read
Read post
CVE-2026-67397: Path traversal in Plesk 18.0.79.9 and earlier and 18.0
05/09/2026 / CVE, CWE-22, Security Research

CVE-2026-67397: Path traversal in Plesk 18.0.79.9 and earlier and 18.0

ApplicationPath traversal in Plesk 18
TypePath traversal
Read post
CVE-2026-67398: Missing authorization vulnerability has been discovere
05/09/2026 / CVE, CWE-862, Security Research

CVE-2026-67398: Missing authorization vulnerability has been discovere

ApplicationMissing authorization vulnerability
TypeSoftware weakness
Read post
CVE-2026-67402: An insecure Apache configuration in ConfigServer Secur
05/09/2026 / CVE, CWE-552, Security Research

CVE-2026-67402: An insecure Apache configuration in ConfigServer Secur

ApplicationConfigServer Security & Firewall maps /usr/bin as CGI programs
TypeSoftware weakness
Read post
CVE-2026-85379: A security flaw has been discovered in light0011 cms c
05/09/2026 / CVE, CWE-74, Security Research

CVE-2026-85379: A security flaw has been discovered in light0011 cms c

ApplicationA security flaw
TypeInjection vulnerability
Read post
CVE-2026-66048: Rejected reason: This CVE ID has been rejected or with
04/09/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-66048: Rejected reason: This CVE ID has been rejected or with

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2026-66049: Rejected reason: This CVE ID has been rejected or with
04/09/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-66049: Rejected reason: This CVE ID has been rejected or with

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2026-84394: fast-uri accepts a host that contains an unbalanced or
04/09/2026 / CVE, CWE-436, Security Research

CVE-2026-84394: fast-uri accepts a host that contains an unbalanced or

Applicationopenjsf fast-uri 2.4.5
TypeSoftware weakness
Read post
CVE-2026-84851: An uncontrolled recursion issue exists in Amazon Ion-C
04/09/2026 / CVE, CWE-674, Security Research

CVE-2026-84851: An uncontrolled recursion issue exists in Amazon Ion-C

ApplicationAn uncontrolled recursion
TypeSoftware weakness
Read post
CVE-2026-84885: A vulnerability has been found in simular-ai Agent-S 0
04/09/2026 / CVE, CWE-404, Security Research

CVE-2026-84885: A vulnerability has been found in simular-ai Agent-S 0

Applicationsimular-ai Agent-S 0.3.1
TypeSoftware weakness
Read post
CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory ex
03/09/2026 / CVE, CWE-674, Security Research

CVE-2026-81928: Net::DNS versions before 1.57 for Perl allow memory ex

Applicationsig_data when re-encoding a message with a misplaced TSIG record
TypeSoftware weakness
Read post
CVE-2026-84323: Missing authorization in FileSystem in Google Chrome p
03/09/2026 / CVE, CWE-862, Security Research

CVE-2026-84323: Missing authorization in FileSystem in Google Chrome p

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-84324: Use after free in Proxy in Google Chrome prior to 152.
03/09/2026 / CVE, CWE-416, Security Research

CVE-2026-84324: Use after free in Proxy in Google Chrome prior to 152.

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-84325: Improper input validation in DataTransfer in Google Ch
03/09/2026 / CVE, CWE-20, Security Research

CVE-2026-84325: Improper input validation in DataTransfer in Google Ch

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-84326: Uninitialized resource in V8 in Google Chrome prior to
03/09/2026 / CVE, CWE-908, Security Research

CVE-2026-84326: Uninitialized resource in V8 in Google Chrome prior to

Applicationgoogle chrome
TypeUninitialized resource use
Read post
CVE-2026-19820: A vulnerability in the Backblaze Client allows a local
02/09/2026 / CVE, CWE-59, Security Research

CVE-2026-19820: A vulnerability in the Backblaze Client allows a local

Applicationthe Backblaze Client
TypeSoftware weakness
Read post
CVE-2026-18743: A flaw was found in popt.
02/09/2026 / CVE, CWE-131, Security Research

CVE-2026-18743: A flaw was found in popt.

Applicationpopt. This vulnerability
TypeSoftware weakness
Read post
CVE-2026-48932: A flaw in Node.js HTTP client can cause a request desy
02/09/2026 / CVE, CWE-444, Security Research

CVE-2026-48932: A flaw in Node.js HTTP client can cause a request desy

ApplicationA flaw in Node
TypeSoftware weakness
Read post
CVE-2026-65643: Eval injection in cPanel 11.138.0.0 and earlier allows
02/09/2026 / CVE, CWE-95, Security Research

CVE-2026-65643: Eval injection in cPanel 11.138.0.0 and earlier allows

ApplicationEval injection in cPanel 11
TypeSoftware weakness
Read post
CVE-2026-67394: A critical local privilege escalation via OS command i
02/09/2026 / CVE, CWE-78, Security Research

CVE-2026-67394: A critical local privilege escalation via OS command i

ApplicationA critical local privilege escalation via OS command injection vulnerability
TypeCommand injection
Read post
CVE-2026-82593: A flaw has been found in D-Link DIR-825M 1.1.8.
01/09/2026 / CVE, CWE-119, Security Research

CVE-2026-82593: A flaw has been found in D-Link DIR-825M 1.1.8.

ApplicationD-Link DIR-825M 1.1.8.
TypeSoftware weakness
Read post
CVE-2026-82594: A vulnerability has been found in LogNet grpc-spring-b
01/09/2026 / CVE, CWE-266, Security Research

CVE-2026-82594: A vulnerability has been found in LogNet grpc-spring-b

ApplicationLogNet grpc-spring-boot-starter
TypeIncorrect privilege assignment
Read post
CVE-2026-82595: A vulnerability was found in D-Link DIR-825M 1.1.8.
01/09/2026 / CVE, CWE-74, Security Research

CVE-2026-82595: A vulnerability was found in D-Link DIR-825M 1.1.8.

ApplicationD-Link DIR-825M 1.1.8.
TypeInjection vulnerability
Read post
CVE-2026-82596: A vulnerability was determined in LatencyUtils up to 2
01/09/2026 / CVE, CWE-119, Security Research

CVE-2026-82596: A vulnerability was determined in LatencyUtils up to 2

ApplicationLatencyUtils
TypeSoftware weakness
Read post
CVE-2026-77956: Improper Control of Generation of Code (Code Injection
01/09/2026 / CVE, CWE-94, Security Research

CVE-2026-77956: Improper Control of Generation of Code (Code Injection

Applicationash-project ash_ai
TypeSoftware weakness
Read post
CVE-2026-82417: ### Summary



`qs.stringify` throws a `TypeError` whe
31/08/2026 / CVE, CWE-248, Security Research

CVE-2026-82417: ### Summary `qs.stringify` throws a `TypeError` whe

Application### Summary `qs
TypeSoftware weakness
Read post
CVE-2026-75847: Cleartext Storage of Sensitive Information vulnerabili
31/08/2026 / CVE, CWE-312, Security Research

CVE-2026-75847: Cleartext Storage of Sensitive Information vulnerabili

Applicationash-project ash_paper_trail
TypeSoftware weakness
Read post
CVE-2026-77831: Inefficient Algorithmic Complexity vulnerability in as
31/08/2026 / CVE, CWE-407, Security Research

CVE-2026-77831: Inefficient Algorithmic Complexity vulnerability in as

ApplicationInefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail
TypeSoftware weakness
Read post
CVE-2026-77970: Cleartext Storage of Sensitive Information vulnerabili
31/08/2026 / CVE, CWE-312, Security Research

CVE-2026-77970: Cleartext Storage of Sensitive Information vulnerabili

Applicationash-project ash_paper_trail
TypeSoftware weakness
Read post
CVE-2026-82562: ### Summary



When `qs.parse` is called with `comma:
31/08/2026 / CVE, CWE-770, Security Research

CVE-2026-82562: ### Summary When `qs.parse` is called with `comma:

Application### Summary When `qs
TypeSoftware weakness
Read post
CVE-2026-41012: Traffic interception vulnerability in BOSH Director vC
30/08/2026 / CVE, CWE-295, Security Research

CVE-2026-41012: Traffic interception vulnerability in BOSH Director vC

ApplicationTraffic interception vulnerability in BOSH Director vCenter CPI
TypeSoftware weakness
Read post
CVE-2026-10522: MemberHero  WordPress plugin through 6.9 does not rest
30/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-10522: MemberHero WordPress plugin through 6.9 does not rest

ApplicationThe MemberHero WordPress plugin
TypeVulnerability Management
Read post
CVE-2026-16061: Rest Routes  WordPress plugin through 5.5.5 does not s
30/08/2026 / CVE, CWE-89, Security Research

CVE-2026-16061: Rest Routes WordPress plugin through 5.5.5 does not s

ApplicationThe Rest Routes WordPress plugin
TypeSQL injection
Read post
CVE-2026-16259: Uix UserCenter WordPress plugin through 1.0.3 does not
30/08/2026 / CVE, CWE-269, Security Research

CVE-2026-16259: Uix UserCenter WordPress plugin through 1.0.3 does not

ApplicationThe Uix UserCenter WordPress plugin
TypeSoftware weakness
Read post
CVE-2026-16600: SmartAIPress WordPress plugin through 1.2.0 does not p
30/08/2026 / CVE, CWE-918, Security Research

CVE-2026-16600: SmartAIPress WordPress plugin through 1.2.0 does not p

ApplicationThe SmartAIPress WordPress plugin
TypeServer-side request forgery
Read post
CVE-2025-30156: Ceph is an open-source distributed storage platform pr
29/08/2026 / CVE, CWE-327, Security Research

CVE-2025-30156: Ceph is an open-source distributed storage platform pr

ApplicationCeph
TypeWeak cryptography
Read post
CVE-2026-17610: In SiSDK v2026.6.0 and earlier, high network traffic l
29/08/2026 / CVE, CWE-404, Security Research

CVE-2026-17610: In SiSDK v2026.6.0 and earlier, high network traffic l

ApplicationIn SiSDK v2026
TypeSoftware weakness
Read post
CVE-2026-18717: ASE2000 2.35 through 2.37 is vulnerable to an improper
29/08/2026 / CVE, CWE-295, Security Research

CVE-2026-18717: ASE2000 2.35 through 2.37 is vulnerable to an improper

ApplicationASE2000 2
TypeSoftware weakness
Read post
CVE-2026-18965: PayRange API is missing proper authorization on manage
29/08/2026 / CVE, CWE-862, Security Research

CVE-2026-18965: PayRange API is missing proper authorization on manage

ApplicationPayRange API
TypeSoftware weakness
Read post
CVE-2026-38343: An integer overflow in the libavfilter/vf_scale.c comp
29/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-38343: An integer overflow in the libavfilter/vf_scale.c comp

ApplicationAn integer overflow in the libavfilter/vf_scale
TypeVulnerability Management
Read post
CVE-2026-47845: In specific scenarios, Reactor Netty HTTP Server may i
28/08/2026 / CVE, CWE-290, Security Research

CVE-2026-47845: In specific scenarios, Reactor Netty HTTP Server may i

ApplicationIn specific scenarios
TypeSoftware weakness
Read post
CVE-2026-47850: Spring Data REST does not preserve the persisted versi
28/08/2026 / CVE, CWE-915, Security Research

CVE-2026-47850: Spring Data REST does not preserve the persisted versi

ApplicationSpring Data REST does not preserve the persisted
TypeSoftware weakness
Read post
CVE-2026-47851: Analyzing a PDF with a deeply nested or cyclic table o
28/08/2026 / CVE, CWE-674, Security Research

CVE-2026-47851: Analyzing a PDF with a deeply nested or cyclic table o

Applicationthe ingestion thread
TypeSoftware weakness
Read post
CVE-2026-47852: A local attacker on a multi-user host can pre-create t
28/08/2026 / CVE, CWE-377, Security Research

CVE-2026-47852: A local attacker on a multi-user host can pre-create t

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-47856: Spring Integration's JSON to object conversion uses th
28/08/2026 / CVE, CWE-502, Security Research

CVE-2026-47856: Spring Integration's JSON to object conversion uses th

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-19632: TranslatePress – Translate Multilingual sites with AI
27/08/2026 / CVE, CWE-640, Security Research

CVE-2026-19632: TranslatePress – Translate Multilingual sites with AI

Applicationall
TypeSoftware weakness
Read post
CVE-2026-29988: A cleartext transmission of sensitive information vuln
27/08/2026 / CVE, CWE-319, Security Research

CVE-2026-29988: A cleartext transmission of sensitive information vuln

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-52776: Compliance-trestle (Trestle) is a tooling platform for
27/08/2026 / CVE, CWE-184, Security Research

CVE-2026-52776: Compliance-trestle (Trestle) is a tooling platform for

ApplicationCompliance-trestle (Trestle)
TypeSoftware weakness
Read post
CVE-2026-54467: On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platf
27/08/2026 / CVE, CWE-283, Security Research

CVE-2026-54467: On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platf

ApplicationOn the Trusted Firmware-M (TF-M) 2
TypeSoftware weakness
Read post
CVE-2026-57170: Compliance-trestle (Trestle) is a Python SDK and comma
27/08/2026 / CVE, CWE-94, Security Research

CVE-2026-57170: Compliance-trestle (Trestle) is a Python SDK and comma

ApplicationCompliance-trestle (Trestle)
TypeSoftware weakness
Read post
CVE-2026-54920: OpenEXR is the reference implementation and specificat
26/08/2026 / CVE, CWE-190, Security Research

CVE-2026-54920: OpenEXR is the reference implementation and specificat

ApplicationOpenEXR
TypeSoftware weakness
Read post
CVE-2026-55059: OpenEXR is the reference implementation and specificat
26/08/2026 / CVE, CWE-787, Security Research

CVE-2026-55059: OpenEXR is the reference implementation and specificat

ApplicationOpenEXR
TypeOut-of-bounds write
Read post
CVE-2026-55371: OpenEXR is the reference implementation and specificat
26/08/2026 / CVE, CWE-20, Security Research

CVE-2026-55371: OpenEXR is the reference implementation and specificat

ApplicationOpenEXR
TypeSoftware weakness
Read post
CVE-2026-55373: OpenEXR is the reference implementation and specificat
26/08/2026 / CVE, CWE-190, Security Research

CVE-2026-55373: OpenEXR is the reference implementation and specificat

ApplicationOpenEXR
TypeSoftware weakness
Read post
CVE-2026-59183: OpenEXR is the reference implementation and specificat
26/08/2026 / CVE, CWE-190, Security Research

CVE-2026-59183: OpenEXR is the reference implementation and specificat

ApplicationOpenEXR
TypeSoftware weakness
Read post
CVE-2026-78157: A vulnerability was detected in Open5GS 2.8.0.
25/08/2026 / CVE, CWE-119, Security Research

CVE-2026-78157: A vulnerability was detected in Open5GS 2.8.0.

ApplicationOpen5GS 2.8.0. This
TypeSoftware weakness
Read post
CVE-2026-78158: A flaw has been found in Open5GS 2.8.0.
25/08/2026 / CVE, CWE-266, Security Research

CVE-2026-78158: A flaw has been found in Open5GS 2.8.0.

ApplicationOpen5GS 2.8.0. This
TypeIncorrect privilege assignment
Read post
CVE-2026-78160: A vulnerability has been found in Dolibarr ERP up to 1
25/08/2026 / CVE, CWE-285, Security Research

CVE-2026-78160: A vulnerability has been found in Dolibarr ERP up to 1

ApplicationDolibarr ERP
TypeAuthorization bypass
Read post
CVE-2026-78161: A vulnerability was found in warmcat libwebsockets 4.5
25/08/2026 / CVE, CWE-119, Security Research

CVE-2026-78161: A vulnerability was found in warmcat libwebsockets 4.5

Applicationwarmcat libwebsockets 4.5.0.
TypeSoftware weakness
Read post
CVE-2026-78203: Ghostwriter before 7.1.2 fails to validate template ow
25/08/2026 / CVE, CWE-639, Security Research

CVE-2026-78203: Ghostwriter before 7.1.2 fails to validate template ow

ApplicationGhostwriter
TypeIDOR access control flaw
Read post
CVE-2026-0551: PPWP – Password Protect Pages plugin for WordPress
24/08/2026 / CVE, CWE-502, Security Research

CVE-2026-0551: PPWP – Password Protect Pages plugin for WordPress

ApplicationThe PPWP – Password Protect Pages plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-16149: Security Hardener plugin for WordPress
24/08/2026 / CVE, CWE-269, Security Research

CVE-2026-16149: Security Hardener plugin for WordPress

ApplicationThe Security Hardener plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-18027: WebToffee WooCommerce PDF Invoices, Packing Slips, Del
24/08/2026 / CVE, CWE-22, Security Research

CVE-2026-18027: WebToffee WooCommerce PDF Invoices, Packing Slips, Del

ApplicationThe WebToffee WooCommerce PDF Invoices
TypePath traversal
Read post
CVE-2026-5723: Rejected reason: This CVE ID has been rejected or with
24/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-5723: Rejected reason: This CVE ID has been rejected or with

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2026-78050: A vulnerability was found in Comfast CF-N1-S 2.6.0.1.
24/08/2026 / CVE, CWE-119, Security Research

CVE-2026-78050: A vulnerability was found in Comfast CF-N1-S 2.6.0.1.

ApplicationComfast CF-N1-S 2.6.0.1.
TypeSoftware weakness
Read post
CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will t
23/08/2026 / CVE, CWE-248, Security Research

CVE-2026-77781: Tie::Hash::Regex versions before 2.0.0 for Perl will t

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-19883: WPeMatico RSS Feed Fetcher plugin for WordPress
23/08/2026 / CVE, CWE-269, Security Research

CVE-2026-19883: WPeMatico RSS Feed Fetcher plugin for WordPress

ApplicationThe WPeMatico RSS Feed Fetcher plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-75027: Themify Builder plugin for WordPress
23/08/2026 / CVE, CWE-862, Security Research

CVE-2026-75027: Themify Builder plugin for WordPress

ApplicationThe Themify Builder plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-76057: AutomatorWP – Automator plugin for no-code automations
23/08/2026 / CVE, CWE-862, Security Research

CVE-2026-76057: AutomatorWP – Automator plugin for no-code automations

ApplicationThe AutomatorWP – Automator plugin for no-code automations
TypeSoftware weakness
Read post
CVE-2026-76074: AutomatorWP – Automator plugin for no-code automations
23/08/2026 / CVE, CWE-862, Security Research

CVE-2026-76074: AutomatorWP – Automator plugin for no-code automations

ApplicationThe AutomatorWP – Automator plugin for no-code automations
TypeSoftware weakness
Read post
CVE-2026-16520: Improper input validation and Exposure of sensitive in
22/08/2026 / CVE, CWE-20, Security Research

CVE-2026-16520: Improper input validation and Exposure of sensitive in

ApplicationImproper input validation and Exposure of sensitive information
TypeSoftware weakness
Read post
CVE-2026-20679: issue was addressed with improved checks.
22/08/2026 / CVE, CWE-125, Security Research

CVE-2026-20679: issue was addressed with improved checks.

ApplicationThe
TypeOut-of-bounds read
Read post
CVE-2026-43679: This issue was addressed with improved permissions che
22/08/2026 / CVE, CWE-284, Security Research

CVE-2026-43679: This issue was addressed with improved permissions che

ApplicationThis
TypeAccess control vulnerability
Read post
CVE-2026-77649: internment crate 0.8.7 for Rust can trigger execution
22/08/2026 / CVE, CWE-506, Security Research

CVE-2026-77649: internment crate 0.8.7 for Rust can trigger execution

ApplicationThe internment crate 0
TypeSoftware weakness
Read post
CVE-2026-77650: append-only-vec crate 0.1.9 for Rust can trigger execu
22/08/2026 / CVE, CWE-506, Security Research

CVE-2026-77650: append-only-vec crate 0.1.9 for Rust can trigger execu

ApplicationThe append-only-vec crate 0
TypeSoftware weakness
Read post
CVE-2022-4996: A flaw has been found in mruby 3.1.0.
21/08/2026 / CVE, CWE-1077, Security Research

CVE-2022-4996: A flaw has been found in mruby 3.1.0.

Applicationmruby 3.1.0. Affected
TypeSoftware weakness
Read post
CVE-2026-76762: A vulnerability was detected in code-projects Assessme
21/08/2026 / CVE, CWE-74, Security Research

CVE-2026-76762: A vulnerability was detected in code-projects Assessme

Applicationcode-projects Assessment Management
TypeInjection vulnerability
Read post
CVE-2026-76764: A flaw has been found in code-projects Employee Manage
21/08/2026 / CVE, CWE-74, Security Research

CVE-2026-76764: A flaw has been found in code-projects Employee Manage

Applicationcode-projects Employee Management
TypeInjection vulnerability
Read post
CVE-2026-8619: An
unauthenticated denial-of-service vulnerability was
21/08/2026 / CVE, CWE-476, Security Research

CVE-2026-8619: An unauthenticated denial-of-service vulnerability was

ApplicationTP-Link TL-MR100 v3.2
TypeNull pointer denial of service
Read post
CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an at
21/08/2026 / CVE, CWE-601, Security Research

CVE-2026-75628: Punk::OAuth2 versions before 0.03 for Perl allow an at

Applicationthe return parameter
TypeSoftware weakness
Read post
CVE-2025-11729: PPWP: Password Protect Pages, Posts & Full or Partial
20/08/2026 / CVE, CWE-285, Security Research

CVE-2025-11729: PPWP: Password Protect Pages, Posts & Full or Partial

Applicationall
TypeAuthorization bypass
Read post
CVE-2026-75976: A weakness has been identified in TRENDnet TEW-823DRU
20/08/2026 / CVE, CWE-119, Security Research

CVE-2026-75976: A weakness has been identified in TRENDnet TEW-823DRU

ApplicationTRENDnet TEW-823DRU 1.1.02b01.
TypeSoftware weakness
Read post
CVE-2026-75978: A security vulnerability has been detected in xianrend
20/08/2026 / CVE, CWE-266, Security Research

CVE-2026-75978: A security vulnerability has been detected in xianrend

Applicationxianrendzw EasyReport
TypeIncorrect privilege assignment
Read post
CVE-2026-75979: A vulnerability was found in xianrendzw EasyReport up
20/08/2026 / CVE, CWE-791, Security Research

CVE-2026-75979: A vulnerability was found in xianrendzw EasyReport up

Applicationxianrendzw EasyReport
TypeSoftware weakness
Read post
CVE-2026-75984: A vulnerability was detected in TRENDnet TEW-823DRU 1.
20/08/2026 / CVE, CWE-74, Security Research

CVE-2026-75984: A vulnerability was detected in TRENDnet TEW-823DRU 1.

ApplicationTRENDnet TEW-823DRU 1.1.02b01.
TypeInjection vulnerability
Read post
CVE-2026-75079: A weakness has been identified in SourceCodester Class
19/08/2026 / CVE, CWE-74, Security Research

CVE-2026-75079: A weakness has been identified in SourceCodester Class

ApplicationSourceCodester Class and
TypeInjection vulnerability
Read post
CVE-2026-75080: A security vulnerability has been detected in SourceCo
19/08/2026 / CVE, CWE-74, Security Research

CVE-2026-75080: A security vulnerability has been detected in SourceCo

ApplicationSourceCodester Class and
TypeInjection vulnerability
Read post
CVE-2026-75081: A vulnerability was detected in Webkul Bagisto up to 2
19/08/2026 / CVE, CWE-840, Security Research

CVE-2026-75081: A vulnerability was detected in Webkul Bagisto up to 2

ApplicationWebkul Bagisto
TypeSoftware weakness
Read post
CVE-2026-75082: A flaw has been found in Webkul Bagisto up to 2.4.4.
19/08/2026 / CVE, CWE-74, Security Research

CVE-2026-75082: A flaw has been found in Webkul Bagisto up to 2.4.4.

ApplicationWebkul Bagisto
TypeInjection vulnerability
Read post
CVE-2026-75086: A vulnerability has been found in itsourcecode Hospita
19/08/2026 / CVE, CWE-74, Security Research

CVE-2026-75086: A vulnerability has been found in itsourcecode Hospita

Applicationitsourcecode Hospital Management
TypeInjection vulnerability
Read post
CVE-2026-19962: A flaw has been found in Edimax EW-7478APC 1.04.
18/08/2026 / CVE, CWE-74, Security Research

CVE-2026-19962: A flaw has been found in Edimax EW-7478APC 1.04.

ApplicationEdimax EW-7478APC 1.04.
TypeInjection vulnerability
Read post
CVE-2026-19963: A vulnerability has been found in Edimax EW-7478APC 1.
18/08/2026 / CVE, CWE-74, Security Research

CVE-2026-19963: A vulnerability has been found in Edimax EW-7478APC 1.

ApplicationEdimax EW-7478APC 1.04.
TypeInjection vulnerability
Read post
CVE-2026-19964: A vulnerability was found in Jij-Inc Jij-MCP-Server 0.
18/08/2026 / CVE, CWE-74, Security Research

CVE-2026-19964: A vulnerability was found in Jij-Inc Jij-MCP-Server 0.

ApplicationJij-Inc Jij-MCP-Server 0.1.0.
TypeInjection vulnerability
Read post
CVE-2026-19965: A vulnerability was determined in automad up to 2.0.0-
18/08/2026 / CVE, CWE-203, Security Research

CVE-2026-19965: A vulnerability was determined in automad up to 2.0.0-

Applicationautomad
TypeSoftware weakness
Read post
CVE-2026-19966: A vulnerability was identified in CodeCanyon TimeCamp
18/08/2026 / CVE, CWE-285, Security Research

CVE-2026-19966: A vulnerability was identified in CodeCanyon TimeCamp

ApplicationCodeCanyon TimeCamp Integration
TypeAuthorization bypass
Read post
CVE-2026-19918: A vulnerability has been found in SpaceX Starlink Rout
17/08/2026 / CVE, CWE-266, Security Research

CVE-2026-19918: A vulnerability has been found in SpaceX Starlink Rout

ApplicationSpaceX Starlink Router
TypeIncorrect privilege assignment
Read post
CVE-2026-19919: A vulnerability was found in code-projects Online Shop
17/08/2026 / CVE, CWE-74, Security Research

CVE-2026-19919: A vulnerability was found in code-projects Online Shop

Applicationcode-projects Online Shopping
TypeInjection vulnerability
Read post
CVE-2026-19920: A vulnerability was determined in code-projects Online
17/08/2026 / CVE, CWE-74, Security Research

CVE-2026-19920: A vulnerability was determined in code-projects Online

Applicationcode-projects Online Shopping System 1
TypeInjection vulnerability
Read post
CVE-2026-19921: A vulnerability was identified in code-projects Online
17/08/2026 / CVE, CWE-74, Security Research

CVE-2026-19921: A vulnerability was identified in code-projects Online

Applicationcode-projects Online Shopping
TypeInjection vulnerability
Read post
CVE-2026-19922: A security flaw has been discovered in code-projects O
17/08/2026 / CVE, CWE-79, Security Research

CVE-2026-19922: A security flaw has been discovered in code-projects O

ApplicationA security flaw
TypeCross-site scripting
Read post
CVE-2026-12128: Pinpoint Booking System – Version 2 plugin for WordPre
16/08/2026 / CVE, CWE-20, Security Research

CVE-2026-12128: Pinpoint Booking System – Version 2 plugin for WordPre

ApplicationThe Pinpoint Booking System
TypeSoftware weakness
Read post
CVE-2026-14433: Online Booking & Scheduling Calendar for WordPress by
16/08/2026 / CVE, CWE-79, Security Research

CVE-2026-14433: Online Booking & Scheduling Calendar for WordPress by

Applicationall
TypeCross-site scripting
Read post
CVE-2026-14484: RapiSafe – Secure Multi File Upload for Contact Form 7
16/08/2026 / CVE, CWE-22, Security Research

CVE-2026-14484: RapiSafe – Secure Multi File Upload for Contact Form 7

ApplicationThe RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress
TypePath traversal
Read post
CVE-2026-15001: bLoyal: Loyalty & Promotions by bLoyal plugin for Word
16/08/2026 / CVE, CWE-269, Security Research

CVE-2026-15001: bLoyal: Loyalty & Promotions by bLoyal plugin for Word

Applicationall
TypeSoftware weakness
Read post
CVE-2026-15162: Object Sync for Salesforce plugin is vulnerable to una
16/08/2026 / CVE, CWE-89, Security Research

CVE-2026-15162: Object Sync for Salesforce plugin is vulnerable to una

ApplicationThe Object Sync for Salesforce plugin
TypeSQL injection
Read post
CVE-2026-19757: A vulnerability was found in Dromara lamp-cloud up to
15/08/2026 / CVE, CWE-22, Security Research

CVE-2026-19757: A vulnerability was found in Dromara lamp-cloud up to

ApplicationDromara lamp-cloud
TypePath traversal
Read post
CVE-2026-19758: A vulnerability was determined in dromara lamp-cloud u
15/08/2026 / CVE, CWE-22, Security Research

CVE-2026-19758: A vulnerability was determined in dromara lamp-cloud u

Applicationdromara lamp-cloud
TypePath traversal
Read post
CVE-2026-19761: A vulnerability has been found in DTStack Taier 1.4.0.
15/08/2026 / CVE, CWE-22, Security Research

CVE-2026-19761: A vulnerability has been found in DTStack Taier 1.4.0.

ApplicationDTStack Taier 1.4.0.
TypePath traversal
Read post
CVE-2026-19762: A vulnerability was found in DTStack Taier 1.4.0.
15/08/2026 / CVE, CWE-22, Security Research

CVE-2026-19762: A vulnerability was found in DTStack Taier 1.4.0.

ApplicationDTStack Taier 1.4.0.
TypePath traversal
Read post
CVE-2026-19763: A vulnerability was determined in DTStack Taier 1.4.0.
15/08/2026 / CVE, CWE-22, Security Research

CVE-2026-19763: A vulnerability was determined in DTStack Taier 1.4.0.

ApplicationDTStack Taier 1
TypePath traversal
Read post
CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argume
14/08/2026 / CVE, CWE-88, Security Research

CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argume

Applicationthe source document
TypeSoftware weakness
Read post
CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS com
14/08/2026 / CVE, CWE-73, Security Research

CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS com

Applicationto_pdf and of stylesheet paths in _style_tag_for
TypeSoftware weakness
Read post
CVE-2026-46382: Meeting Room Booking System (MRBS) is a PHP-based appl
14/08/2026 / CVE, CWE-918, Security Research

CVE-2026-46382: Meeting Room Booking System (MRBS) is a PHP-based appl

ApplicationThe Meeting Room Booking System (MRBS)
TypeServer-side request forgery
Read post
CVE-2026-46688: Meeting Room Booking System (MRBS) is a PHP-based appl
14/08/2026 / CVE, CWE-601, Security Research

CVE-2026-46688: Meeting Room Booking System (MRBS) is a PHP-based appl

ApplicationThe Meeting Room Booking System (MRBS)
TypeSoftware weakness
Read post
CVE-2026-48791: sigstore-java is a sigstore java client for interactin
14/08/2026 / CVE, CWE-347, Security Research

CVE-2026-48791: sigstore-java is a sigstore java client for interactin

Applicationsigstore-java
TypeSoftware weakness
Read post
CVE-2024-14043: A vulnerability was determined in Open5GS up to 2.7.1.
13/08/2026 / CVE, CWE-119, Security Research

CVE-2024-14043: A vulnerability was determined in Open5GS up to 2.7.1.

ApplicationOpen5GS
TypeSoftware weakness
Read post
CVE-2026-68429: In the Linux kernel, the following vulnerability has b
13/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-68429: In the Linux kernel, the following vulnerability has b

ApplicationIn the Linux kernel
TypeVulnerability Management
Read post
CVE-2026-68430: In the Linux kernel, the following vulnerability has b
13/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-68430: In the Linux kernel, the following vulnerability has b

ApplicationIn the Linux kernel
TypeVulnerability Management
Read post
CVE-2026-68431: In the Linux kernel, the following vulnerability has b
13/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-68431: In the Linux kernel, the following vulnerability has b

ApplicationIn the Linux kernel
TypeVulnerability Management
Read post
CVE-2026-68432: In the Linux kernel, the following vulnerability has b
13/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-68432: In the Linux kernel, the following vulnerability has b

ApplicationIn the Linux kernel
TypeVulnerability Management
Read post
CVE-2026-34265: SAP NetWeaver Application Server ABAP allows an unauth
12/08/2026 / CVE, CWE-787, Security Research

CVE-2026-34265: SAP NetWeaver Application Server ABAP allows an unauth

ApplicationSAP NetWeaver Application Server ABAP
TypeOut-of-bounds write
Read post
CVE-2026-40130: SAP SAPSPrint Service has memory corruption vulnerabil
12/08/2026 / CVE, CWE-121, Security Research

CVE-2026-40130: SAP SAPSPrint Service has memory corruption vulnerabil

ApplicationSAP SAPSPrint Service
TypeSoftware weakness
Read post
CVE-2026-44758: SAP Manufacturing Integration and Intelligence (MII) a
12/08/2026 / CVE, CWE-94, Security Research

CVE-2026-44758: SAP Manufacturing Integration and Intelligence (MII) a

ApplicationSAP Manufacturing Integration and Intelligence (MII)
TypeSoftware weakness
Read post
CVE-2026-44762: SAP Data Services Management Console allows an overly
12/08/2026 / CVE, CWE-1021, Security Research

CVE-2026-44762: SAP Data Services Management Console allows an overly

ApplicationSAP Data Services Management Console
TypeSoftware weakness
Read post
CVE-2026-44763: SAP Manufacturing Integration and Intelligence allows
12/08/2026 / CVE, CWE-22, Security Research

CVE-2026-44763: SAP Manufacturing Integration and Intelligence allows

ApplicationSAP Manufacturing Integration and Intelligence
TypePath traversal
Read post
CVE-2026-19375: A vulnerability was detected in dmitriiweb article-scr
11/08/2026 / CVE, CWE-918, Security Research

CVE-2026-19375: A vulnerability was detected in dmitriiweb article-scr

Applicationdmitriiweb article-scraper-mcp 1.0.0.
TypeServer-side request forgery
Read post
CVE-2026-19376: A vulnerability has been found in Uasoft Badaso 3.0.0-
11/08/2026 / CVE, CWE-266, Security Research

CVE-2026-19376: A vulnerability has been found in Uasoft Badaso 3.0.0-

ApplicationUasoft Badaso 3.0.0-alpha.
TypeIncorrect privilege assignment
Read post
CVE-2026-19378: A vulnerability was found in code-projects Task Manage
11/08/2026 / CVE, CWE-79, Security Research

CVE-2026-19378: A vulnerability was found in code-projects Task Manage

Applicationcode-projects Task Management
TypeCross-site scripting
Read post
CVE-2026-19379: A vulnerability was determined in EFM ipTIME AX8004M 1
11/08/2026 / CVE, CWE-77, Security Research

CVE-2026-19379: A vulnerability was determined in EFM ipTIME AX8004M 1

ApplicationEFM ipTIME AX8004M 15
TypeSoftware weakness
Read post
CVE-2026-19380: A vulnerability was identified in Mullvad wireguard.sy
11/08/2026 / CVE, CWE-664, Security Research

CVE-2026-19380: A vulnerability was identified in Mullvad wireguard.sy

ApplicationMullvad wireguard.sys 0.10.1.
TypeSoftware weakness
Read post
CVE-2026-19323: A security flaw has been discovered in azer react-anal
10/08/2026 / CVE, CWE-22, Security Research

CVE-2026-19323: A security flaw has been discovered in azer react-anal

ApplicationA security flaw
TypePath traversal
Read post
CVE-2026-71984: MSI Radix AXE6600 router firmware version v781521 cont
10/08/2026 / CVE, CWE-78, Security Research

CVE-2026-71984: MSI Radix AXE6600 router firmware version v781521 cont

ApplicationMSI Radix AXE6600 router firmware
TypeCommand injection
Read post
CVE-2026-71985: MSI Radix AXE6600 router firmware version v781521 cont
10/08/2026 / CVE, CWE-78, Security Research

CVE-2026-71985: MSI Radix AXE6600 router firmware version v781521 cont

ApplicationMSI Radix AXE6600 router firmware
TypeCommand injection
Read post
CVE-2026-71986: MSI Radix AXE6600 router firmware version v781521 cont
10/08/2026 / CVE, CWE-78, Security Research

CVE-2026-71986: MSI Radix AXE6600 router firmware version v781521 cont

ApplicationMSI Radix AXE6600 router firmware
TypeCommand injection
Read post
CVE-2026-71987: MSI Radix AXE6600 router firmware version v781521 cont
10/08/2026 / CVE, CWE-78, Security Research

CVE-2026-71987: MSI Radix AXE6600 router firmware version v781521 cont

ApplicationMSI Radix AXE6600 router firmware
TypeCommand injection
Read post
CVE-2026-8798: In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips
09/08/2026 / CVE, CWE-835, Security Research

CVE-2026-8798: In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips

ApplicationIn Bouncy Castle for Java FIPS (BC-FJA)
TypeSoftware weakness
Read post
CVE-2026-13505: In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips
09/08/2026 / CVE, CWE-772, Security Research

CVE-2026-13505: In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips

ApplicationIn Bouncy Castle for Java FIPS (BC-FJA)
TypeSoftware weakness
Read post
CVE-2026-18988: Easy Accordion plugin for WordPress
09/08/2026 / CVE, CWE-79, Security Research

CVE-2026-18988: Easy Accordion plugin for WordPress

ApplicationThe Easy Accordion plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-14526: AI Copilot – Content Generator plugin for WordPress
09/08/2026 / CVE, CWE-269, Security Research

CVE-2026-14526: AI Copilot – Content Generator plugin for WordPress

ApplicationThe AI Copilot – Content Generator plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-16267: Newsletters WordPress plugin before 4.16 does not rest
09/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-16267: Newsletters WordPress plugin before 4.16 does not rest

ApplicationThe Newsletters WordPress plugin
TypeVulnerability Management
Read post
CVE-2026-15805: Rejected reason: This CVE ID has been rejected or with
08/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-15805: Rejected reason: This CVE ID has been rejected or with

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2026-17264: Opening a crafted DICOM file containing malicious JPEG
08/08/2026 / CVE, CWE-787, Security Research

CVE-2026-17264: Opening a crafted DICOM file containing malicious JPEG

ApplicationApplication not specified
TypeOut-of-bounds write
Read post
CVE-2026-49163: Improper limitation of a pathname to a restricted dire
08/08/2026 / CVE, CWE-22, Security Research

CVE-2026-49163: Improper limitation of a pathname to a restricted dire

ApplicationApplication Insights Profiler
TypePath traversal
Read post
CVE-2026-50481: Modification of assumed-immutable data (maid) in Azure
08/08/2026 / CVE, CWE-471, Security Research

CVE-2026-50481: Modification of assumed-immutable data (maid) in Azure

Applicationmicrosoft azure active directory
TypeSoftware weakness
Read post
CVE-2026-50515: Deserialization of untrusted data in Azure Service Bus
08/08/2026 / CVE, CWE-502, Security Research

CVE-2026-50515: Deserialization of untrusted data in Azure Service Bus

Applicationmicrosoft azure service bus
TypeSoftware weakness
Read post
CVE-2023-54375: Rejected reason: Erroneously reserved under wrong year
07/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2023-54375: Rejected reason: Erroneously reserved under wrong year

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2023-54376: Rejected reason: Erroneously reserved under wrong year
07/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2023-54376: Rejected reason: Erroneously reserved under wrong year

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2023-54377: Rejected reason: Erroneously reserved under wrong year
07/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2023-54377: Rejected reason: Erroneously reserved under wrong year

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2023-54378: Rejected reason: Erroneously reserved under wrong year
07/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2023-54378: Rejected reason: Erroneously reserved under wrong year

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2023-54379: Rejected reason: Erroneously reserved under wrong year
07/08/2026 / CVE, Vulnerability Management, Security Research

CVE-2023-54379: Rejected reason: Erroneously reserved under wrong year

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2026-18103: A flaw was found in dhcp-server.
06/08/2026 / CVE, CWE-120, Security Research

CVE-2026-18103: A flaw was found in dhcp-server.

Applicationdhcp-server. A remote
TypeSoftware weakness
Read post
CVE-2026-18852: A vulnerability has been found in epsilla-cloud vector
06/08/2026 / CVE, CWE-754, Security Research

CVE-2026-18852: A vulnerability has been found in epsilla-cloud vector

Applicationepsilla-cloud vectordb
TypeSoftware weakness
Read post
CVE-2026-18853: A security vulnerability has been detected in ZomboDro
06/08/2026 / CVE, CWE-22, Security Research

CVE-2026-18853: A security vulnerability has been detected in ZomboDro

ApplicationZomboDroid Meme Generator
TypePath traversal
Read post
CVE-2026-18854: A vulnerability has been found in Shandong Hoteam PDM
06/08/2026 / CVE, CWE-74, Security Research

CVE-2026-18854: A vulnerability has been found in Shandong Hoteam PDM

ApplicationShandong Hoteam PDM
TypeInjection vulnerability
Read post
CVE-2026-45705: OpenSIPS is a Session Initiation Protocol (SIP) server
06/08/2026 / CVE, CWE-125, Security Research

CVE-2026-45705: OpenSIPS is a Session Initiation Protocol (SIP) server

ApplicationOpenSIPS
TypeOut-of-bounds read
Read post
CVE-2026-11835: Time-of-check time-of-use (TOCTOU) vulnerability combi
05/08/2026 / CVE, CWE-20, Security Research

CVE-2026-11835: Time-of-check time-of-use (TOCTOU) vulnerability combi

Applicationsubsystem mode
TypeSoftware weakness
Read post
CVE-2026-11836: Insufficient verification of data authenticity in Cali
05/08/2026 / CVE, CWE-345, Security Research

CVE-2026-11836: Insufficient verification of data authenticity in Cali

Applicationsubsystem mode
TypeSoftware weakness
Read post
CVE-2026-18685: A security vulnerability has been detected in GL.iNet
05/08/2026 / CVE, CWE-74, Security Research

CVE-2026-18685: A security vulnerability has been detected in GL.iNet

ApplicationGL.iNet GL-MT3000
TypeInjection vulnerability
Read post
CVE-2026-18686: A vulnerability was detected in GL.iNet GL-MT3000 up t
05/08/2026 / CVE, CWE-74, Security Research

CVE-2026-18686: A vulnerability was detected in GL.iNet GL-MT3000 up t

ApplicationGL.iNet GL-MT3000
TypeInjection vulnerability
Read post
CVE-2026-62870: Use after free in Microsoft Office Excel allows an una
05/08/2026 / CVE, CWE-416, Security Research

CVE-2026-62870: Use after free in Microsoft Office Excel allows an una

ApplicationUse after free in Microsoft Office Excel
TypeSoftware weakness
Read post
CVE-2026-3245: A deserialization vulnerability in PRISMAproduction Ve
04/08/2026 / CVE, CWE-502, Security Research

CVE-2026-3245: A deserialization vulnerability in PRISMAproduction Ve

ApplicationA deserialization vulnerability in PRISMAproduction
TypeSoftware weakness
Read post
CVE-2026-12185: In Bouncy Castle for Java before 1.85, BKS/UBER keysto
04/08/2026 / CVE, CWE-789, Security Research

CVE-2026-12185: In Bouncy Castle for Java before 1.85, BKS/UBER keysto

ApplicationIn Bouncy Castle for Java
TypeSoftware weakness
Read post
CVE-2026-15055: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2
04/08/2026 / CVE, CWE-770, Security Research

CVE-2026-15055: In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2

ApplicationIn Bouncy Castle for Java
TypeSoftware weakness
Read post
CVE-2026-18581: A vulnerability was determined in ggml-org llama.cpp e
04/08/2026 / CVE, CWE-617, Security Research

CVE-2026-18581: A vulnerability was determined in ggml-org llama.cpp e

Applicationggml-org llama
TypeSoftware weakness
Read post
CVE-2026-59638: In Bouncy Castle for Java before 1.85, JSSE hostname v
04/08/2026 / CVE, CWE-297, Security Research

CVE-2026-59638: In Bouncy Castle for Java before 1.85, JSSE hostname v

ApplicationIn Bouncy Castle for Java
TypeSoftware weakness
Read post
CVE-2026-13339: CubeWP Framework plugin for WordPress
03/08/2026 / CVE, CWE-22, Security Research

CVE-2026-13339: CubeWP Framework plugin for WordPress

ApplicationThe CubeWP Framework plugin for WordPress
TypePath traversal
Read post
CVE-2026-18352: User Access Manager plugin for WordPress
03/08/2026 / CVE, CWE-22, Security Research

CVE-2026-18352: User Access Manager plugin for WordPress

ApplicationThe User Access Manager plugin for WordPress
TypePath traversal
Read post
CVE-2026-8457: WooCommerce - Social Login plugin for WordPress
03/08/2026 / CVE, CWE-289, Security Research

CVE-2026-8457: WooCommerce - Social Login plugin for WordPress

ApplicationThe WooCommerce - Social Login plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-9335: A vulnerability in keras-team/keras versions = 3.14.0
03/08/2026 / CVE, CWE-22, Security Research

CVE-2026-9335: A vulnerability in keras-team/keras versions = 3.14.0

Applicationkeras-team/keras
TypePath traversal
Read post
CVE-2025-15675: Charitable  WordPress plugin before 1.8.5.3 does not s
03/08/2026 / CVE, CWE-79, Security Research

CVE-2025-15675: Charitable WordPress plugin before 1.8.5.3 does not s

ApplicationThe Charitable WordPress plugin
TypeCross-site scripting
Read post
CVE-2026-13362: SendPulse Email Marketing Newsletter plugin for WordPr
02/08/2026 / CVE, CWE-79, Security Research

CVE-2026-13362: SendPulse Email Marketing Newsletter plugin for WordPr

ApplicationThe SendPulse Email Marketing Newsletter plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-15006: Bit integrations – Form Integration, Webhook, Spreadsh
02/08/2026 / CVE, CWE-22, Security Research

CVE-2026-15006: Bit integrations – Form Integration, Webhook, Spreadsh

ApplicationThe Bit integrations – Form Integration
TypePath traversal
Read post
CVE-2026-15403: Pinpoint Booking System – Version 2 plugin for WordPre
02/08/2026 / CVE, CWE-89, Security Research

CVE-2026-15403: Pinpoint Booking System – Version 2 plugin for WordPre

ApplicationThe Pinpoint Booking System
TypeSQL injection
Read post
CVE-2026-15414: Subscriptions for WooCommerce plugin for WordPress
02/08/2026 / CVE, CWE-269, Security Research

CVE-2026-15414: Subscriptions for WooCommerce plugin for WordPress

ApplicationThe Subscriptions for WooCommerce plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-7623: SureForms – Contact Form, Payment Form & Other Custom F
02/08/2026 / CVE, CWE-79, Security Research

CVE-2026-7623: SureForms – Contact Form, Payment Form & Other Custom F

ApplicationThe SureForms – Contact Form
TypeCross-site scripting
Read post
CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows
01/08/2026 / CVE, CWE-284, Security Research

CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows

ApplicationA flaw in Node
TypeAccess control vulnerability
Read post
CVE-2026-14537: Incorrect Authorization in the direct HTTP API tool in
01/08/2026 / CVE, CWE-863, Security Research

CVE-2026-14537: Incorrect Authorization in the direct HTTP API tool in

Applicationthe direct HTTP API tool invocation endpoint in Google mcp-toolbox
TypeSoftware weakness
Read post
CVE-2026-14538: An improper authorization and security-boundary bypass
01/08/2026 / CVE, CWE-285, Security Research

CVE-2026-14538: An improper authorization and security-boundary bypass

Applicationthe bigquery-execute-sql tool component of Google mcp-toolbox
TypeAuthorization bypass
Read post
CVE-2026-14539: An allocation of resources without limits vulnerabilit
01/08/2026 / CVE, CWE-770, Security Research

CVE-2026-14539: An allocation of resources without limits vulnerabilit

Applicationthe HTTP handler component of Google mcp-toolbox
TypeSoftware weakness
Read post
CVE-2026-14540: A Server-Side Request Forgery (SSRF) vulnerability exi
01/08/2026 / CVE, CWE-918, Security Research

CVE-2026-14540: A Server-Side Request Forgery (SSRF) vulnerability exi

Applicationthe generic HTTP source and tool components of Google mcp-toolbox
TypeServer-side request forgery
Read post
CVE-2026-62343: ImageMagick is free and open-source software used for
31/07/2026 / CVE, CWE-190, Security Research

CVE-2026-62343: ImageMagick is free and open-source software used for

ApplicationImageMagick
TypeSoftware weakness
Read post
CVE-2026-62363: ImageMagick is free and open-source software used for
31/07/2026 / CVE, CWE-787, Security Research

CVE-2026-62363: ImageMagick is free and open-source software used for

ApplicationImageMagick
TypeOut-of-bounds write
Read post
CVE-2026-62946: ImageMagick is free and open-source software used for
31/07/2026 / CVE, CWE-190, Security Research

CVE-2026-62946: ImageMagick is free and open-source software used for

ApplicationImageMagick
TypeSoftware weakness
Read post
CVE-2026-64685: ImageMagick is free and open-source software used for
31/07/2026 / CVE, CWE-125, Security Research

CVE-2026-64685: ImageMagick is free and open-source software used for

ApplicationImageMagick
TypeOut-of-bounds read
Read post
CVE-2026-17650: Use after free in Compositing in Google Chrome prior t
31/07/2026 / CVE, CWE-416, Security Research

CVE-2026-17650: Use after free in Compositing in Google Chrome prior t

ApplicationUse after free in Compositing in Google Chrome
TypeSoftware weakness
Read post
CVE-2026-56821: Netty is an asynchronous, event-driven network applica
30/07/2026 / CVE, CWE-299, Security Research

CVE-2026-56821: Netty is an asynchronous, event-driven network applica

ApplicationNetty
TypeSoftware weakness
Read post
CVE-2026-56822: Netty is an asynchronous, event-driven network applica
30/07/2026 / CVE, CWE-367, Security Research

CVE-2026-56822: Netty is an asynchronous, event-driven network applica

ApplicationNetty
TypeSoftware weakness
Read post
CVE-2026-12144: Wholesale for WooCommerce plugin for WordPress
30/07/2026 / CVE, CWE-269, Security Research

CVE-2026-12144: Wholesale for WooCommerce plugin for WordPress

ApplicationThe Wholesale for WooCommerce plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-12938: Newsletters Lite plugin for WordPress
30/07/2026 / CVE, CWE-79, Security Research

CVE-2026-12938: Newsletters Lite plugin for WordPress

ApplicationThe Newsletters Lite plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-12939: Newsletters Lite plugin for WordPress
30/07/2026 / CVE, CWE-79, Security Research

CVE-2026-12939: Newsletters Lite plugin for WordPress

ApplicationThe Newsletters Lite plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-17524: Versions of the package zip-lib before 1.1.0 are vulne
29/07/2026 / CVE, CWE-22, Security Research

CVE-2026-17524: Versions of the package zip-lib before 1.1.0 are vulne

ApplicationVersions of the package zip-lib
TypePath traversal
Read post
CVE-2026-17528: Versions of the package nice-select2 before 2.4.1 are
29/07/2026 / CVE, CWE-79, Security Research

CVE-2026-17528: Versions of the package nice-select2 before 2.4.1 are

ApplicationVersions of the package nice-select2
TypeCross-site scripting
Read post
CVE-2026-12124: PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed
29/07/2026 / CVE, CWE-862, Security Research

CVE-2026-12124: PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed

ApplicationThe PDFDraft – Drag & Drop PDF Builder
TypeSoftware weakness
Read post
CVE-2026-14490: Demi – One Click Demo Import, WP Backup & Site Migrati
29/07/2026 / CVE, CWE-22, Security Research

CVE-2026-14490: Demi – One Click Demo Import, WP Backup & Site Migrati

ApplicationThe Demi – One Click Demo Import
TypePath traversal
Read post
CVE-2026-14545: TrueBooker  WordPress plugin before 1.2.4 does not val
29/07/2026 / CVE, CWE-269, Security Research

CVE-2026-14545: TrueBooker WordPress plugin before 1.2.4 does not val

ApplicationThe TrueBooker WordPress plugin
TypeSoftware weakness
Read post
CVE-2026-17500: A vulnerability was detected in ggml-org llama.cpp d00
28/07/2026 / CVE, CWE-404, Security Research

CVE-2026-17500: A vulnerability was detected in ggml-org llama.cpp d00

Applicationggml-org llama.cpp d006858
TypeSoftware weakness
Read post
CVE-2026-17501: A flaw has been found in ggml-org llama.cpp e15efe0.
28/07/2026 / CVE, CWE-400, Security Research

CVE-2026-17501: A flaw has been found in ggml-org llama.cpp e15efe0.

Applicationggml-org llama.cpp e15efe0.
TypeSoftware weakness
Read post
CVE-2026-15928: XMLRPC-C Library versions 1.07 through 1.67.01 are vul
28/07/2026 / CVE, CWE-79, Security Research

CVE-2026-15928: XMLRPC-C Library versions 1.07 through 1.67.01 are vul

ApplicationXMLRPC-C Library
TypeCross-site scripting
Read post
CVE-2025-15662: Printcart Web to Print Product Designer for WooCommerc
28/07/2026 / CVE, CWE-918, Security Research

CVE-2025-15662: Printcart Web to Print Product Designer for WooCommerc

ApplicationThe Printcart Web to Print Product Designer for WooCommerce WordPress plugin
TypeServer-side request forgery
Read post
CVE-2026-10082: Advanced Ads  WordPress plugin before 2.0.23 does not
28/07/2026 / CVE, CWE-79, Security Research

CVE-2026-10082: Advanced Ads WordPress plugin before 2.0.23 does not

ApplicationThe Advanced Ads WordPress plugin
TypeCross-site scripting
Read post
CVE-2026-17432: A vulnerability was detected in NousResearch hermes-ag
27/07/2026 / CVE, CWE-266, Security Research

CVE-2026-17432: A vulnerability was detected in NousResearch hermes-ag

ApplicationNousResearch hermes-agent 2026.6.5.
TypeIncorrect privilege assignment
Read post
CVE-2026-15962: Fluent Forms Pro Add On Pack plugin for WordPress
27/07/2026 / CVE, CWE-502, Security Research

CVE-2026-15962: Fluent Forms Pro Add On Pack plugin for WordPress

ApplicationThe Fluent Forms Pro Add On Pack plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-17433: A vulnerability was detected in nanocoai NanoClaw up t
27/07/2026 / CVE, CWE-266, Security Research

CVE-2026-17433: A vulnerability was detected in nanocoai NanoClaw up t

Applicationnanocoai NanoClaw
TypeIncorrect privilege assignment
Read post
CVE-2026-17434: A flaw has been found in nanocoai NanoClaw up to 2.0.6
27/07/2026 / CVE, CWE-266, Security Research

CVE-2026-17434: A flaw has been found in nanocoai NanoClaw up to 2.0.6

Applicationnanocoai NanoClaw
TypeIncorrect privilege assignment
Read post
CVE-2026-63720: datamodel-code-generator prior to version 0.70.0 conta
27/07/2026 / CVE, CWE-94, Security Research

CVE-2026-63720: datamodel-code-generator prior to version 0.70.0 conta

Applicationdatamodel-code-generator
TypeSoftware weakness
Read post
CVE-2026-66373: Redis before 8.8.0, in the unusual case where an authe
26/07/2026 / CVE, CWE-415, Security Research

CVE-2026-66373: Redis before 8.8.0, in the unusual case where an authe

ApplicationRedis
TypeSoftware weakness
Read post
CVE-2026-66374: Knot Resolver before 6.4.1 allows remote code executio
26/07/2026 / CVE, CWE-1284, Security Research

CVE-2026-66374: Knot Resolver before 6.4.1 allows remote code executio

ApplicationKnot Resolver
TypeSoftware weakness
Read post
CVE-2026-10818: WPForms Pro plugin for WordPress
26/07/2026 / CVE, CWE-434, Security Research

CVE-2026-10818: WPForms Pro plugin for WordPress

ApplicationThe WPForms Pro plugin for WordPress
TypeFile upload vulnerability
Read post
CVE-2026-14955: Checkout Field Editor for WooCommerce (Pro) plugin for
26/07/2026 / CVE, CWE-22, Security Research

CVE-2026-14955: Checkout Field Editor for WooCommerce (Pro) plugin for

ApplicationThe Checkout Field Editor for WooCommerce (Pro) plugin for WordPress
TypePath traversal
Read post
CVE-2026-15425: Yoast SEO – Advanced SEO with real-time guidance and b
26/07/2026 / CVE, CWE-79, Security Research

CVE-2026-15425: Yoast SEO – Advanced SEO with real-time guidance and b

ApplicationAI plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-35425: Improper access control in Azure API Management (APIM)
25/07/2026 / CVE, CWE-284, Security Research

CVE-2026-35425: Improper access control in Azure API Management (APIM)

ApplicationImproper access control in Azure API Management (APIM)
TypeAccess control vulnerability
Read post
CVE-2026-49159: Exposure of sensitive information to an unauthorized a
25/07/2026 / CVE, CWE-200, Security Research

CVE-2026-49159: Exposure of sensitive information to an unauthorized a

ApplicationExposure of sensitive information to an unauthorized actor in Microsoft Graph
TypeSoftware weakness
Read post
CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allo
25/07/2026 / CVE, CWE-502, Security Research

CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allo

ApplicationDeserialization of untrusted data in M365 Copilot
TypeSoftware weakness
Read post
CVE-2026-54120: Improper input validation in Microsoft Surface allows
25/07/2026 / CVE, CWE-20, Security Research

CVE-2026-54120: Improper input validation in Microsoft Surface allows

ApplicationImproper input validation in Microsoft Surface
TypeSoftware weakness
Read post
CVE-2026-56160: Improper authorization in Azure Red Hat OpenShift (ARO
25/07/2026 / CVE, CWE-285, Security Research

CVE-2026-56160: Improper authorization in Azure Red Hat OpenShift (ARO

ApplicationImproper authorization in Azure Red Hat OpenShift (ARO)
TypeAuthorization bypass
Read post
CVE-2026-16653: A security flaw has been discovered in boazsegev facil
24/07/2026 / CVE, CWE-22, Security Research

CVE-2026-16653: A security flaw has been discovered in boazsegev facil

ApplicationA security flaw
TypePath traversal
Read post
CVE-2026-21723: alertmanager templates test endpoint (/api/alertmanage
24/07/2026 / CVE, CWE-400, Security Research

CVE-2026-21723: alertmanager templates test endpoint (/api/alertmanage

Applicationa short period causes OOM and crashes the Grafana service
TypeSoftware weakness
Read post
CVE-2026-15074: @fastify/static up to and including version 10.1.0 fai
24/07/2026 / CVE, CWE-22, Security Research

CVE-2026-15074: @fastify/static up to and including version 10.1.0 fai

Application@fastify/static
TypePath traversal
Read post
CVE-2026-7120: @fastify/static evaluates the allowedPath callback bef
24/07/2026 / CVE, CWE-180, Security Research

CVE-2026-7120: @fastify/static evaluates the allowedPath callback bef

Application@fastify/static evaluates the allowedPath callback
TypeSoftware weakness
Read post
CVE-2026-6390: A flaw was found in GNU nano's multi-buffer error mess
24/07/2026 / CVE, CWE-134, Security Research

CVE-2026-6390: A flaw was found in GNU nano's multi-buffer error mess

ApplicationGNU nano
TypeSoftware weakness
Read post
CVE-2026-16488: A vulnerability was determined in QUSETIONS MiniCode-P
23/07/2026 / CVE, CWE-77, Security Research

CVE-2026-16488: A vulnerability was determined in QUSETIONS MiniCode-P

ApplicationQUSETIONS MiniCode-Python 0
TypeSoftware weakness
Read post
CVE-2026-16489: A vulnerability was identified in jsforce up to 3.10.1
23/07/2026 / CVE, CWE-77, Security Research

CVE-2026-16489: A vulnerability was identified in jsforce up to 3.10.1

Applicationjsforce up to
TypeSoftware weakness
Read post
CVE-2026-63262: Missing Authorization (CWE-862) in Kibana can lead to
23/07/2026 / CVE, CWE-862, Security Research

CVE-2026-63262: Missing Authorization (CWE-862) in Kibana can lead to

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-63263: Uncontrolled Resource Consumption (CWE-400) in Elastic
23/07/2026 / CVE, CWE-400, Security Research

CVE-2026-63263: Uncontrolled Resource Consumption (CWE-400) in Elastic

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-16490: A security flaw has been discovered in itsourcecode Ho
23/07/2026 / CVE, CWE-74, Security Research

CVE-2026-16490: A security flaw has been discovered in itsourcecode Ho

ApplicationA security flaw
TypeInjection vulnerability
Read post
CVE-2026-16327: A vulnerability was determined in D-Link DNS-320 1.0.2
22/07/2026 / CVE, CWE-284, Security Research

CVE-2026-16327: A vulnerability was determined in D-Link DNS-320 1.0.2

ApplicationD-Link DNS-320 1
TypeAccess control vulnerability
Read post
CVE-2026-55831: Netty is a network application framework for developme
22/07/2026 / CVE, CWE-400, Security Research

CVE-2026-55831: Netty is a network application framework for developme

Applicationnetty netty
TypeSoftware weakness
Read post
CVE-2026-55833: Netty is a network application framework for developme
22/07/2026 / CVE, CWE-400, Security Research

CVE-2026-55833: Netty is a network application framework for developme

Applicationnetty netty
TypeSoftware weakness
Read post
CVE-2026-63728: Gitleaks prior to 8.30.1 contains a template injection
22/07/2026 / CVE, CWE-1336, Security Research

CVE-2026-63728: Gitleaks prior to 8.30.1 contains a template injection

ApplicationGitleaks
TypeSoftware weakness
Read post
CVE-2026-16329: A vulnerability was identified in D-Link DNS-320 1.0.2
22/07/2026 / CVE, CWE-284, Security Research

CVE-2026-16329: A vulnerability was identified in D-Link DNS-320 1.0.2

ApplicationD-Link DNS-320 1.0.2.
TypeAccess control vulnerability
Read post
CVE-2026-42566: Meshtastic is an open source mesh networking solution.
21/07/2026 / CVE, CWE-20, Security Research

CVE-2026-42566: Meshtastic is an open source mesh networking solution.

ApplicationMeshtastic
TypeSoftware weakness
Read post
CVE-2026-44359: Meshtastic is an open source mesh networking solution.
21/07/2026 / CVE, CWE-94, Security Research

CVE-2026-44359: Meshtastic is an open source mesh networking solution.

ApplicationMeshtastic
TypeSoftware weakness
Read post
CVE-2026-45138: CI4MS is a CodeIgniter 4-based content management syst
21/07/2026 / CVE, CWE-79, Security Research

CVE-2026-45138: CI4MS is a CodeIgniter 4-based content management syst

ApplicationCI4MS
TypeCross-site scripting
Read post
CVE-2026-10081: Unlimited Elements For Elementor WordPress plugin befo
21/07/2026 / CVE, CWE-79, Security Research

CVE-2026-10081: Unlimited Elements For Elementor WordPress plugin befo

ApplicationThe Unlimited Elements For Elementor WordPress plugin
TypeCross-site scripting
Read post
CVE-2026-10724: Reviews Feed  WordPress plugin before 2.6.5 does not n
21/07/2026 / CVE, CWE-345, Security Research

CVE-2026-10724: Reviews Feed WordPress plugin before 2.6.5 does not n

ApplicationThe Reviews Feed WordPress plugin
TypeSoftware weakness
Read post
CVE-2026-16198: A vulnerability was detected in Sipeed PicoClaw up to
20/07/2026 / CVE, CWE-287, Security Research

CVE-2026-16198: A vulnerability was detected in Sipeed PicoClaw up to

ApplicationSipeed PicoClaw
TypeImproper authentication
Read post
CVE-2026-16199: A flaw has been found in nextlevelbuilder GoClaw up to
20/07/2026 / CVE, CWE-266, Security Research

CVE-2026-16199: A flaw has been found in nextlevelbuilder GoClaw up to

Applicationnextlevelbuilder GoClaw
TypeIncorrect privilege assignment
Read post
CVE-2026-16200: A vulnerability has been found in zevorn rt-claw up to
20/07/2026 / CVE, CWE-285, Security Research

CVE-2026-16200: A vulnerability has been found in zevorn rt-claw up to

Applicationzevorn rt-claw
TypeAuthorization bypass
Read post
CVE-2026-16201: A vulnerability was found in zevorn rt-claw up to 0.2.
20/07/2026 / CVE, CWE-200, Security Research

CVE-2026-16201: A vulnerability was found in zevorn rt-claw up to 0.2.

Applicationzevorn rt-claw
TypeSoftware weakness
Read post
CVE-2026-16202: A vulnerability was determined in SourceCodester Class
20/07/2026 / CVE, CWE-79, Security Research

CVE-2026-16202: A vulnerability was determined in SourceCodester Class

ApplicationSourceCodester Class and Exam Timetabling System 1
TypeCross-site scripting
Read post
CVE-2026-16075: A flaw has been found in AstrBotDevs AstrBot up to 4.2
19/07/2026 / CVE, CWE-285, Security Research

CVE-2026-16075: A flaw has been found in AstrBotDevs AstrBot up to 4.2

ApplicationAstrBotDevs AstrBot
TypeAuthorization bypass
Read post
CVE-2026-9734: W3SC Elementor to Zoho CRM plugin for WordPress
19/07/2026 / CVE, CWE-352, Security Research

CVE-2026-9734: W3SC Elementor to Zoho CRM plugin for WordPress

ApplicationThe W3SC Elementor to Zoho CRM plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-16076: A vulnerability has been found in AstrBotDevs AstrBot
19/07/2026 / CVE, CWE-287, Security Research

CVE-2026-16076: A vulnerability has been found in AstrBotDevs AstrBot

ApplicationAstrBotDevs AstrBot
TypeImproper authentication
Read post
CVE-2026-16077: A vulnerability was found in AstrBotDevs AstrBot up to
19/07/2026 / CVE, CWE-59, Security Research

CVE-2026-16077: A vulnerability was found in AstrBotDevs AstrBot up to

ApplicationAstrBotDevs AstrBot
TypeSoftware weakness
Read post
CVE-2026-16081: A vulnerability was determined in Sipeed PicoClaw up t
19/07/2026 / CVE, CWE-352, Security Research

CVE-2026-16081: A vulnerability was determined in Sipeed PicoClaw up t

ApplicationSipeed PicoClaw
TypeSoftware weakness
Read post
CVE-2026-33434: Wazuh is a free and open source platform used for thre
18/07/2026 / CVE, CWE-799, Security Research

CVE-2026-33434: Wazuh is a free and open source platform used for thre

ApplicationWazuh
TypeSoftware weakness
Read post
CVE-2026-33754: Wazuh is a free and open source platform used for thre
18/07/2026 / CVE, CWE-400, Security Research

CVE-2026-33754: Wazuh is a free and open source platform used for thre

ApplicationWazuh
TypeSoftware weakness
Read post
CVE-2026-34150: Wazuh is a free and open source platform used for thre
18/07/2026 / CVE, CWE-122, Security Research

CVE-2026-34150: Wazuh is a free and open source platform used for thre

ApplicationWazuh
TypeSoftware weakness
Read post
CVE-2026-39359: Wazuh is a free and open source platform used for thre
18/07/2026 / CVE, CWE-22, Security Research

CVE-2026-39359: Wazuh is a free and open source platform used for thre

ApplicationWazuh
TypePath traversal
Read post
CVE-2026-54340: h2o is an HTTP server with support for HTTP/1.x, HTTP/
18/07/2026 / CVE, CWE-400, Security Research

CVE-2026-54340: h2o is an HTTP server with support for HTTP/1.x, HTTP/

Applicationh2o
TypeSoftware weakness
Read post
CVE-2026-15907: A flaw has been found in H3C SecPath F1000-C8300 up to
17/07/2026 / CVE, CWE-74, Security Research

CVE-2026-15907: A flaw has been found in H3C SecPath F1000-C8300 up to

ApplicationH3C SecPath F1000-C8300
TypeInjection vulnerability
Read post
CVE-2026-15909: A vulnerability has been found in RafyMrX TOKO-ONLINE-
17/07/2026 / CVE, CWE-285, Security Research

CVE-2026-15909: A vulnerability has been found in RafyMrX TOKO-ONLINE-

ApplicationRafyMrX TOKO-ONLINE-ROTI
TypeAuthorization bypass
Read post
CVE-2026-1609: A flaw was found in Keycloak.
17/07/2026 / CVE, CWE-284, Security Research

CVE-2026-1609: A flaw was found in Keycloak.

ApplicationKeycloak. When the
TypeAccess control vulnerability
Read post
CVE-2026-23538: A vulnerability was identified in the Feast Feature Se
17/07/2026 / CVE, CWE-770, Security Research

CVE-2026-23538: A vulnerability was identified in the Feast Feature Se

Applicationthe Feast Feature
TypeSoftware weakness
Read post
CVE-2026-3842: A flaw was found in QEMU.
17/07/2026 / CVE, CWE-787, Security Research

CVE-2026-3842: A flaw was found in QEMU.

ApplicationQEMU. This vulnerability
TypeOut-of-bounds write
Read post
CVE-2026-13230: An information disclosure vulnerability was identified
16/07/2026 / CVE, CWE-200, Security Research

CVE-2026-13230: An information disclosure vulnerability was identified

ApplicationTP-Link Kasa EC70
TypeSoftware weakness
Read post
CVE-2026-9770: Kasa EC71 v4 and EC70 v4 firmware contains a static cr
16/07/2026 / CVE, CWE-321, Security Research

CVE-2026-9770: Kasa EC71 v4 and EC70 v4 firmware contains a static cr

ApplicationKasa EC71 v4 and EC70 v4 firmware
TypeSoftware weakness
Read post
CVE-2026-11851: Improper Neutralization of Special Elements used in an
16/07/2026 / CVE, CWE-89, Security Research

CVE-2026-11851: Improper Neutralization of Special Elements used in an

Applicationthe web management interface of certain ASUS router models
TypeSQL injection
Read post
CVE-2026-13385: An Improper Validation of Integrity Check Value and Im
16/07/2026 / CVE, CWE-295, Security Research

CVE-2026-13385: An Improper Validation of Integrity Check Value and Im

Applicationcertain ASUS router models
TypeSoftware weakness
Read post
CVE-2026-13585: Allocation of Resources Without Limits and Throttling
16/07/2026 / CVE, CWE-226, Security Research

CVE-2026-13585: Allocation of Resources Without Limits and Throttling

ApplicationResource Not Removed
TypeSoftware weakness
Read post
CVE-2026-15618: A security flaw has been discovered in mosaxiv clawlet
15/07/2026 / CVE, CWE-693, Security Research

CVE-2026-15618: A security flaw has been discovered in mosaxiv clawlet

ApplicationA security flaw
TypeProtection mechanism failure
Read post
CVE-2026-15619: A weakness has been identified in mosaxiv clawlet up t
15/07/2026 / CVE, CWE-918, Security Research

CVE-2026-15619: A weakness has been identified in mosaxiv clawlet up t

Applicationmosaxiv clawlet
TypeServer-side request forgery
Read post
CVE-2026-0487: SAProuter on Microsoft Windows allows an unauthenticat
15/07/2026 / CVE, CWE-427, Security Research

CVE-2026-0487: SAProuter on Microsoft Windows allows an unauthenticat

ApplicationSAProuter on Microsoft Windows
TypeSoftware weakness
Read post
CVE-2026-15620: A security vulnerability has been detected in mosaxiv
15/07/2026 / CVE, CWE-918, Security Research

CVE-2026-15620: A security vulnerability has been detected in mosaxiv

Applicationmosaxiv clawlet
TypeServer-side request forgery
Read post
CVE-2026-15621: A vulnerability was detected in mosaxiv clawlet up to
15/07/2026 / CVE, CWE-59, Security Research

CVE-2026-15621: A vulnerability was detected in mosaxiv clawlet up to

Applicationmosaxiv clawlet
TypeSoftware weakness
Read post
CVE-2026-15515: A security vulnerability has been detected in Tencent
14/07/2026 / CVE, CWE-426, Security Research

CVE-2026-15515: A security vulnerability has been detected in Tencent

ApplicationTencent PC Manager
TypeSoftware weakness
Read post
CVE-2026-15516: A vulnerability was detected in MacCMS Pro up to 2022.
14/07/2026 / CVE, CWE-285, Security Research

CVE-2026-15516: A vulnerability was detected in MacCMS Pro up to 2022.

ApplicationMacCMS Pro
TypeAuthorization bypass
Read post
CVE-2026-15517: A flaw has been found in Jinher OA 1.0.
14/07/2026 / CVE, CWE-74, Security Research

CVE-2026-15517: A flaw has been found in Jinher OA 1.0.

ApplicationJinher OA 1.0.
TypeInjection vulnerability
Read post
CVE-2026-15518: A vulnerability has been found in AREA 17 Twill CMS up
14/07/2026 / CVE, CWE-284, Security Research

CVE-2026-15518: A vulnerability has been found in AREA 17 Twill CMS up

ApplicationAREA 17 Twill
TypeAccess control vulnerability
Read post
CVE-2026-15551: Integer overflow or wraparound vulnerability in Samsun
14/07/2026 / CVE, CWE-190, Security Research

CVE-2026-15551: Integer overflow or wraparound vulnerability in Samsun

ApplicationInteger overflow or wraparound vulnerability in Samsung Open Source rlottie
TypeSoftware weakness
Read post
CVE-2026-15470: A vulnerability has been found in Eleveo Call Recordin
13/07/2026 / CVE, CWE-266, Security Research

CVE-2026-15470: A vulnerability has been found in Eleveo Call Recordin

ApplicationEleveo Call Recording
TypeIncorrect privilege assignment
Read post
CVE-2026-15471: A vulnerability was found in Eleveo Call Recording Sof
13/07/2026 / CVE, CWE-266, Security Research

CVE-2026-15471: A vulnerability was found in Eleveo Call Recording Sof

ApplicationEleveo Call Recording
TypeIncorrect privilege assignment
Read post
CVE-2026-15472: A vulnerability was determined in Eleveo Call Recordin
13/07/2026 / CVE, CWE-266, Security Research

CVE-2026-15472: A vulnerability was determined in Eleveo Call Recordin

ApplicationEleveo Call Recording Software 9
TypeIncorrect privilege assignment
Read post
CVE-2026-15473: A vulnerability was identified in Eleveo Call Recordin
13/07/2026 / CVE, CWE-266, Security Research

CVE-2026-15473: A vulnerability was identified in Eleveo Call Recordin

ApplicationEleveo Call Recording
TypeIncorrect privilege assignment
Read post
CVE-2026-15474: A security flaw has been discovered in Eleveo Call Rec
13/07/2026 / CVE, CWE-266, Security Research

CVE-2026-15474: A security flaw has been discovered in Eleveo Call Rec

ApplicationA security flaw
TypeIncorrect privilege assignment
Read post
CVE-2026-11426: UnderConstructionPage PRO plugin for WordPress
12/07/2026 / CVE, CWE-22, Security Research

CVE-2026-11426: UnderConstructionPage PRO plugin for WordPress

ApplicationThe UnderConstructionPage PRO plugin for WordPress
TypePath traversal
Read post
CVE-2026-13756: WP Grid Builder plugin for WordPress
12/07/2026 / CVE, CWE-269, Security Research

CVE-2026-13756: WP Grid Builder plugin for WordPress

ApplicationThe WP Grid Builder plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-10628: Points and Rewards for WooCommerce plugin for WordPres
12/07/2026 / CVE, CWE-862, Security Research

CVE-2026-10628: Points and Rewards for WooCommerce plugin for WordPres

ApplicationThe Points and Rewards for WooCommerce plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-12426: Members – Membership & User Role Editor Plugin plugin
12/07/2026 / CVE, CWE-200, Security Research

CVE-2026-12426: Members – Membership & User Role Editor Plugin plugin

ApplicationThe Members – Membership & User Role Editor Plugin plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-13114: Motors – Car Dealership & Classified Listings Plugin p
12/07/2026 / CVE, CWE-79, Security Research

CVE-2026-13114: Motors – Car Dealership & Classified Listings Plugin p

ApplicationThe Motors – Car Dealership & Classified Listings Plugin plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-15318: A weakness has been identified in Sipeed PicoClaw up t
11/07/2026 / CVE, CWE-285, Security Research

CVE-2026-15318: A weakness has been identified in Sipeed PicoClaw up t

ApplicationSipeed PicoClaw
TypeAuthorization bypass
Read post
CVE-2026-15319: A security vulnerability has been detected in Sipeed P
11/07/2026 / CVE, CWE-266, Security Research

CVE-2026-15319: A security vulnerability has been detected in Sipeed P

ApplicationSipeed PicoClaw
TypeIncorrect privilege assignment
Read post
CVE-2026-15320: A vulnerability was detected in Sipeed PicoClaw up to
11/07/2026 / CVE, CWE-862, Security Research

CVE-2026-15320: A vulnerability was detected in Sipeed PicoClaw up to

ApplicationSipeed PicoClaw
TypeSoftware weakness
Read post
CVE-2026-11392: WP Hotel Booking plugin for WordPress
11/07/2026 / CVE, CWE-79, Security Research

CVE-2026-11392: WP Hotel Booking plugin for WordPress

ApplicationThe WP Hotel Booking plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-11818: WPCafe – Restaurant Menu, Online Food Ordering & Table
11/07/2026 / CVE, CWE-862, Security Research

CVE-2026-11818: WPCafe – Restaurant Menu, Online Food Ordering & Table

ApplicationThe WPCafe – Restaurant Menu
TypeSoftware weakness
Read post
CVE-2026-15134: A vulnerability was determined in CodeAstro Simple Onl
10/07/2026 / CVE, CWE-74, Security Research

CVE-2026-15134: A vulnerability was determined in CodeAstro Simple Onl

ApplicationCodeAstro Simple Online Leave Management System 1
TypeInjection vulnerability
Read post
CVE-2026-15135: A security flaw has been discovered in code-projects O
10/07/2026 / CVE, CWE-74, Security Research

CVE-2026-15135: A security flaw has been discovered in code-projects O

ApplicationA security flaw
TypeInjection vulnerability
Read post
CVE-2026-15137: A weakness has been identified in code-projects Interv
10/07/2026 / CVE, CWE-74, Security Research

CVE-2026-15137: A weakness has been identified in code-projects Interv

Applicationcode-projects Interview Management
TypeInjection vulnerability
Read post
CVE-2026-47646: Improper neutralization of input during web page gener
10/07/2026 / CVE, CWE-79, Security Research

CVE-2026-47646: Improper neutralization of input during web page gener

Applicationmicrosoft dynamics 365 customer voice
TypeCross-site scripting
Read post
CVE-2026-15138: A security vulnerability has been detected in tumf mcp
10/07/2026 / CVE, CWE-22, Security Research

CVE-2026-15138: A security vulnerability has been detected in tumf mcp

Applicationtumf mcp-text-editor
TypePath traversal
Read post
CVE-2026-55430: Coder allows organizations to provision remote develop
09/07/2026 / CVE, CWE-345, Security Research

CVE-2026-55430: Coder allows organizations to provision remote develop

Applicationcoder coder
TypeSoftware weakness
Read post
CVE-2026-55431: Coder allows organizations to provision remote develop
09/07/2026 / CVE, CWE-522, Security Research

CVE-2026-55431: Coder allows organizations to provision remote develop

Applicationcoder coder
TypeSoftware weakness
Read post
CVE-2026-55432: Coder allows organizations to provision remote develop
09/07/2026 / CVE, CWE-862, Security Research

CVE-2026-55432: Coder allows organizations to provision remote develop

Applicationcoder coder
TypeSoftware weakness
Read post
CVE-2026-55433: Coder allows organizations to provision remote develop
09/07/2026 / CVE, CWE-862, Security Research

CVE-2026-55433: Coder allows organizations to provision remote develop

Applicationcoder coder
TypeSoftware weakness
Read post
CVE-2026-55436: Coder allows organizations to provision remote develop
09/07/2026 / CVE, CWE-295, Security Research

CVE-2026-55436: Coder allows organizations to provision remote develop

Applicationcoder coder
TypeSoftware weakness
Read post
CVE-2024-56141: Minosoft is an open-source, multi-version Minecraft Ja
08/07/2026 / CVE, CWE-329, Security Research

CVE-2024-56141: Minosoft is an open-source, multi-version Minecraft Ja

ApplicationMinosoft
TypeSoftware weakness
Read post
CVE-2026-13356: A malicious webpage could interrupt a pending navigati
08/07/2026 / CVE, CWE-451, Security Research

CVE-2026-13356: A malicious webpage could interrupt a pending navigati

Applicationmozilla firefox
TypeSoftware weakness
Read post
CVE-2026-53647: FOSSBilling is a free, open-source billing and client
08/07/2026 / CVE, CWE-200, Security Research

CVE-2026-53647: FOSSBilling is a free, open-source billing and client

ApplicationFOSSBilling
TypeSoftware weakness
Read post
CVE-2026-53648: FOSSBilling is a free, open-source billing and client
08/07/2026 / CVE, CWE-73, Security Research

CVE-2026-53648: FOSSBilling is a free, open-source billing and client

ApplicationFOSSBilling
TypeSoftware weakness
Read post
CVE-2026-11328: Exclusive Addons for Elementor plugin for WordPress
08/07/2026 / CVE, CWE-79, Security Research

CVE-2026-11328: Exclusive Addons for Elementor plugin for WordPress

ApplicationThe Exclusive Addons for Elementor plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-14777: A weakness has been identified in SourceCodester Onlne
07/07/2026 / CVE, CWE-284, Security Research

CVE-2026-14777: A weakness has been identified in SourceCodester Onlne

ApplicationSourceCodester Onlne Examination
TypeAccess control vulnerability
Read post
CVE-2026-14778: A security vulnerability has been detected in SourceCo
07/07/2026 / CVE, CWE-266, Security Research

CVE-2026-14778: A security vulnerability has been detected in SourceCo

ApplicationSourceCodester Onlne Examination
TypeIncorrect privilege assignment
Read post
CVE-2026-14783: A vulnerability was determined in NousResearch hermes-
07/07/2026 / CVE, CWE-22, Security Research

CVE-2026-14783: A vulnerability was determined in NousResearch hermes-

ApplicationNousResearch hermes-agent 2026
TypePath traversal
Read post
CVE-2026-14784: A vulnerability was identified in vxcontrol PentAGI up
07/07/2026 / CVE, CWE-264, Security Research

CVE-2026-14784: A vulnerability was identified in vxcontrol PentAGI up

Applicationvxcontrol PentAGI
TypeSoftware weakness
Read post
CVE-2026-14786: A security flaw has been discovered in radareorg radar
07/07/2026 / CVE, CWE-189, Security Research

CVE-2026-14786: A security flaw has been discovered in radareorg radar

Applicationradare radare2
TypeSoftware weakness
Read post
CVE-2026-14684: A flaw has been found in HdrHistogram up to 2.2.2.
06/07/2026 / CVE, CWE-400, Security Research

CVE-2026-14684: A flaw has been found in HdrHistogram up to 2.2.2.

ApplicationHdrHistogram up to
TypeSoftware weakness
Read post
CVE-2026-14685: A vulnerability has been found in HdrHistogram up to 2
06/07/2026 / CVE, CWE-371, Security Research

CVE-2026-14685: A vulnerability has been found in HdrHistogram up to 2

ApplicationHdrHistogram up to
TypeSoftware weakness
Read post
CVE-2026-14686: A vulnerability was found in HdrHistogram up to 2.2.2.
06/07/2026 / CVE, CWE-697, Security Research

CVE-2026-14686: A vulnerability was found in HdrHistogram up to 2.2.2.

ApplicationHdrHistogram up to
TypeSoftware weakness
Read post
CVE-2026-14687: A vulnerability was determined in 666ghj BettaFish up
06/07/2026 / CVE, CWE-187, Security Research

CVE-2026-14687: A vulnerability was determined in 666ghj BettaFish up

Application666ghj BettaFish
TypeSoftware weakness
Read post
CVE-2026-14688: A vulnerability was identified in itsourcecode Online
06/07/2026 / CVE, CWE-74, Security Research

CVE-2026-14688: A vulnerability was identified in itsourcecode Online

Applicationitsourcecode Online Hotel
TypeInjection vulnerability
Read post
CVE-2026-54424: An Incorrect Use of Privileged APIs vulnerability in U
05/07/2026 / CVE, CWE-648, Security Research

CVE-2026-54424: An Incorrect Use of Privileged APIs vulnerability in U

ApplicationUnity Parsec on Windows hosts leads to a potential Elevation of Privilege
TypeSoftware weakness
Read post
CVE-2025-71342: picklescan before 0.0.30 fails to detect malicious pic
05/07/2026 / CVE, CWE-502, Security Research

CVE-2025-71342: picklescan before 0.0.30 fails to detect malicious pic

Applicationpicklescan
TypeSoftware weakness
Read post
CVE-2025-71343: picklescan before 0.0.30 fails to detect malicious pic
05/07/2026 / CVE, CWE-502, Security Research

CVE-2025-71343: picklescan before 0.0.30 fails to detect malicious pic

Applicationpicklescan
TypeSoftware weakness
Read post
CVE-2025-71345: picklescan before 0.0.30 fails to detect malicious pic
05/07/2026 / CVE, CWE-502, Security Research

CVE-2025-71345: picklescan before 0.0.30 fails to detect malicious pic

Applicationpicklescan
TypeSoftware weakness
Read post
CVE-2025-71347: picklescan before 0.0.33 fails to detect malicious pic
05/07/2026 / CVE, CWE-502, Security Research

CVE-2025-71347: picklescan before 0.0.33 fails to detect malicious pic

Applicationpicklescan
TypeSoftware weakness
Read post
CVE-2026-13050: An Out-of-bounds Write vulnerability in WatchGuard Fir
04/07/2026 / CVE, CWE-787, Security Research

CVE-2026-13050: An Out-of-bounds Write vulnerability in WatchGuard Fir

ApplicationApplication not specified
TypeOut-of-bounds write
Read post
CVE-2026-13053: An Out-of-bounds Write vulnerability in WatchGuard Fir
04/07/2026 / CVE, CWE-787, Security Research

CVE-2026-13053: An Out-of-bounds Write vulnerability in WatchGuard Fir

ApplicationApplication not specified
TypeOut-of-bounds write
Read post
CVE-2026-13054: A path traversal vulnerability in the WatchGuard Firew
04/07/2026 / CVE, CWE-22, Security Research

CVE-2026-13054: A path traversal vulnerability in the WatchGuard Firew

ApplicationA path traversal vulnerability in the WatchGuard Fireware OS Management Web UI
TypePath traversal
Read post
CVE-2026-13079: A local privilege escalation vulnerability in the Watc
04/07/2026 / CVE, CWE-732, Security Research

CVE-2026-13079: A local privilege escalation vulnerability in the Watc

Applicationthe WatchGuard Mobile VPN with SSL client for Windows
TypeSoftware weakness
Read post
CVE-2026-13084: A null pointer dereference vulnerability in WatchGuard
04/07/2026 / CVE, CWE-476, Security Research

CVE-2026-13084: A null pointer dereference vulnerability in WatchGuard

ApplicationApplication not specified
TypeNull pointer denial of service
Read post
CVE-2026-50279: Craft CMS is a content management system (CMS).
03/07/2026 / CVE, CWE-285, Security Research

CVE-2026-50279: Craft CMS is a content management system (CMS).

ApplicationCraft CMS
TypeAuthorization bypass
Read post
CVE-2026-50280: Craft CMS is a content management system (CMS).
03/07/2026 / CVE, CWE-284, Security Research

CVE-2026-50280: Craft CMS is a content management system (CMS).

ApplicationCraft CMS
TypeAccess control vulnerability
Read post
CVE-2026-55791: Craft CMS is a content management system (CMS).
03/07/2026 / CVE, CWE-79, Security Research

CVE-2026-55791: Craft CMS is a content management system (CMS).

ApplicationCraft CMS
TypeCross-site scripting
Read post
CVE-2026-55792: Craft CMS is a content management system (CMS).
03/07/2026 / CVE, CWE-200, Security Research

CVE-2026-55792: Craft CMS is a content management system (CMS).

ApplicationCraft CMS
TypeSoftware weakness
Read post
CVE-2026-55794: Craft CMS is a content management system (CMS).
03/07/2026 / CVE, CWE-94, Security Research

CVE-2026-55794: Craft CMS is a content management system (CMS).

ApplicationCraft CMS
TypeSoftware weakness
Read post
CVE-2026-54500: Oj (Optimized JSON) is a JSON parser and Object marsha
02/07/2026 / CVE, CWE-125, Security Research

CVE-2026-54500: Oj (Optimized JSON) is a JSON parser and Object marsha

ApplicationOj (Optimized JSON)
TypeOut-of-bounds read
Read post
CVE-2026-54502: Oj (Optimized JSON) is a JSON parser and Object marsha
02/07/2026 / CVE, CWE-121, Security Research

CVE-2026-54502: Oj (Optimized JSON) is a JSON parser and Object marsha

ApplicationOj (Optimized JSON)
TypeSoftware weakness
Read post
CVE-2026-54592: Oj (Optimized JSON) is a JSON parser and Object marsha
02/07/2026 / CVE, CWE-125, Security Research

CVE-2026-54592: Oj (Optimized JSON) is a JSON parser and Object marsha

ApplicationOj (Optimized JSON)
TypeOut-of-bounds read
Read post
CVE-2026-54896: Oj (Optimized JSON) is a JSON parser and Object marsha
02/07/2026 / CVE, CWE-122, Security Research

CVE-2026-54896: Oj (Optimized JSON) is a JSON parser and Object marsha

ApplicationOj (Optimized JSON)
TypeSoftware weakness
Read post
CVE-2026-54897: Oj (Optimized JSON) is a JSON parser and Object marsha
02/07/2026 / CVE, CWE-416, Security Research

CVE-2026-54897: Oj (Optimized JSON) is a JSON parser and Object marsha

ApplicationOj (Optimized JSON)
TypeSoftware weakness
Read post
CVE-2026-12243: NLTK version 3.9.4 is vulnerable to a path traversal a
01/07/2026 / CVE, CWE-22, Security Research

CVE-2026-12243: NLTK version 3.9.4 is vulnerable to a path traversal a

Applicationnltk nltk 3.9.4
TypePath traversal
Read post
CVE-2026-58302: rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9
01/07/2026 / CVE, CWE-22, Security Research

CVE-2026-58302: rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9

Applicationrtapi_app in linuxcnc-uspace in LinuxCNC
TypePath traversal
Read post
CVE-2026-12114: Team Members – Multi Language Supported Team Plugin pl
01/07/2026 / CVE, CWE-79, Security Research

CVE-2026-12114: Team Members – Multi Language Supported Team Plugin pl

ApplicationThe Team Members – Multi Language Supported Team Plugin plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-14160: Time-of-check time-of-use (TOCTOU) race condition vuln
01/07/2026 / CVE, CWE-367, Security Research

CVE-2026-14160: Time-of-check time-of-use (TOCTOU) race condition vuln

ApplicationSamsung Open Source Escargot
TypeSoftware weakness
Read post
CVE-2026-11367: PixMagix – WordPress Image Editor plugin for WordPress
01/07/2026 / CVE, CWE-22, Security Research

CVE-2026-11367: PixMagix – WordPress Image Editor plugin for WordPress

ApplicationThe PixMagix – WordPress Image Editor plugin for WordPress
TypePath traversal
Read post
CVE-2026-13513: A security flaw has been discovered in MyScale MyScale
30/06/2026 / CVE, CWE-345, Security Research

CVE-2026-13513: A security flaw has been discovered in MyScale MyScale

ApplicationA security flaw
TypeSoftware weakness
Read post
CVE-2026-13514: A weakness has been identified in Chess Play and Learn
30/06/2026 / CVE, CWE-285, Security Research

CVE-2026-13514: A weakness has been identified in Chess Play and Learn

ApplicationChess Play and
TypeAuthorization bypass
Read post
CVE-2026-13515: A security vulnerability has been detected in Tenda JD
30/06/2026 / CVE, CWE-119, Security Research

CVE-2026-13515: A security vulnerability has been detected in Tenda JD

ApplicationTenda JD12L 16.03.53.23.
TypeSoftware weakness
Read post
CVE-2026-13516: A vulnerability was detected in Tenda JD12L 16.03.53.2
30/06/2026 / CVE, CWE-119, Security Research

CVE-2026-13516: A vulnerability was detected in Tenda JD12L 16.03.53.2

ApplicationTenda JD12L 16.03.53.23.
TypeSoftware weakness
Read post
CVE-2026-13517: A flaw has been found in Tenda JD12L 16.03.53.23.
30/06/2026 / CVE, CWE-119, Security Research

CVE-2026-13517: A flaw has been found in Tenda JD12L 16.03.53.23.

ApplicationTenda JD12L 16.03.53.23.
TypeSoftware weakness
Read post
CVE-2026-10643: Zephyr's IP socket recvmsg() implementation (subsys/ne
29/06/2026 / CVE, CWE-787, Security Research

CVE-2026-10643: Zephyr's IP socket recvmsg() implementation (subsys/ne

ApplicationZephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet
TypeOut-of-bounds write
Read post
CVE-2026-8095: Frontend File Manager Plugin plugin for WordPress
29/06/2026 / CVE, CWE-73, Security Research

CVE-2026-8095: Frontend File Manager Plugin plugin for WordPress

ApplicationThe Frontend File Manager Plugin plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-58049: FFmpeg's RASC video decoder (decode_dlta in libavcodec
29/06/2026 / CVE, CWE-787, Security Research

CVE-2026-58049: FFmpeg's RASC video decoder (decode_dlta in libavcodec

ApplicationFFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc
TypeOut-of-bounds write
Read post
CVE-2026-58050: libssh2 through 1.11.1 reads an attacker-controlled 32
29/06/2026 / CVE, CWE-190, Security Research

CVE-2026-58050: libssh2 through 1.11.1 reads an attacker-controlled 32

Applicationlibssh2
TypeSoftware weakness
Read post
CVE-2026-58051: libssh2 through 1.11.1 grows its publickey list with S
29/06/2026 / CVE, CWE-908, Security Research

CVE-2026-58051: libssh2 through 1.11.1 grows its publickey list with S

Applicationlibssh2
TypeUninitialized resource use
Read post
CVE-2023-37524: HCL Traveler for Microsoft Outlook (HTMO) is susceptib
28/06/2026 / CVE, CWE-1104, Security Research

CVE-2023-37524: HCL Traveler for Microsoft Outlook (HTMO) is susceptib

ApplicationHCL Traveler for Microsoft Outlook (HTMO)
TypeSoftware weakness
Read post
CVE-2025-59868: HCL Traveler for Microsoft Outlook (HTMO) is susceptib
28/06/2026 / CVE, CWE-532, Security Research

CVE-2025-59868: HCL Traveler for Microsoft Outlook (HTMO) is susceptib

ApplicationHCL Traveler for Microsoft Outlook (HTMO)
TypeSoftware weakness
Read post
CVE-2026-11356: Ivory Search – WordPress Search Plugin plugin for Word
28/06/2026 / CVE, CWE-79, Security Research

CVE-2026-11356: Ivory Search – WordPress Search Plugin plugin for Word

ApplicationThe Ivory Search – WordPress Search Plugin plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-13331: Groundhogg — CRM, Newsletters, and Marketing Automatio
28/06/2026 / CVE, CWE-89, Security Research

CVE-2026-13331: Groundhogg — CRM, Newsletters, and Marketing Automatio

ApplicationThe Groundhogg — CRM
TypeSQL injection
Read post
CVE-2026-13333: Groundhogg — CRM, Newsletters, and Marketing Automatio
28/06/2026 / CVE, CWE-89, Security Research

CVE-2026-13333: Groundhogg — CRM, Newsletters, and Marketing Automatio

ApplicationThe Groundhogg — CRM
TypeSQL injection
Read post
CVE-2026-13226: Groundhogg — CRM, Newsletters, and Marketing Automatio
27/06/2026 / CVE, CWE-89, Security Research

CVE-2026-13226: Groundhogg — CRM, Newsletters, and Marketing Automatio

ApplicationThe Groundhogg — CRM
TypeSQL injection
Read post
CVE-2026-48615: A flaw in Node.js proxy tunnel error handling could ex
27/06/2026 / CVE, CWE-359, Security Research

CVE-2026-48615: A flaw in Node.js proxy tunnel error handling could ex

Applicationnodejs node.js 22.22.3
TypePrivacy data exposure
Read post
CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node
27/06/2026 / CVE, CWE-176, Security Research

CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node

Applicationnodejs node.js 22.22.3
TypeSoftware weakness
Read post
CVE-2026-48619: A flaw in Node.js HTTP/2 client allows a server to sen
27/06/2026 / CVE, CWE-400, Security Research

CVE-2026-48619: A flaw in Node.js HTTP/2 client allows a server to sen

Applicationnodejs node.js 22.22.3
TypeSoftware weakness
Read post
CVE-2026-48928: A inconsistency in Node.js hostname matching can cause
27/06/2026 / CVE, CWE-284, Security Research

CVE-2026-48928: A inconsistency in Node.js hostname matching can cause

Applicationnodejs node.js 22.22.3
TypeAccess control vulnerability
Read post
CVE-2025-60466: A use-after-free in the gf_filter_pid_get_packet funct
26/06/2026 / CVE, CWE-416, Security Research

CVE-2025-60466: A use-after-free in the gf_filter_pid_get_packet funct

Applicationthe gf_filter_pid_get_packet function (/filter_core/filter_pid
TypeSoftware weakness
Read post
CVE-2025-60473: A NULL pointer dereference in the gf_filter_in_parent_
26/06/2026 / CVE, CWE-476, Security Research

CVE-2025-60473: A NULL pointer dereference in the gf_filter_in_parent_

Applicationthe gf_filter_in_parent_chain function (/filter_core/filter_pid
TypeNull pointer denial of service
Read post
CVE-2026-39951: Cacti is an open source performance and fault manageme
26/06/2026 / CVE, CWE-89, Security Research

CVE-2026-39951: Cacti is an open source performance and fault manageme

Applicationcacti cacti
TypeSQL injection
Read post
CVE-2026-40079: Cacti is an open source performance and fault manageme
26/06/2026 / CVE, CWE-78, Security Research

CVE-2026-40079: Cacti is an open source performance and fault manageme

Applicationcacti cacti
TypeCommand injection
Read post
CVE-2026-7569: Quest NetVault Backup viewclient Cross-Site Scripting
26/06/2026 / CVE, CWE-79, Security Research

CVE-2026-7569: Quest NetVault Backup viewclient Cross-Site Scripting

Applicationquest netvault backup
TypeCross-site scripting
Read post
CVE-2026-5818: Incorrect check of function return value in Caliptra C
25/06/2026 / CVE, CWE-253, Security Research

CVE-2026-5818: Incorrect check of function return value in Caliptra C

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-6458: Missing cryptographic step in Caliptra Core Firmware (
25/06/2026 / CVE, CWE-325, Security Research

CVE-2026-6458: Missing cryptographic step in Caliptra Core Firmware (

Applicationan incorrect GCM authentication tag
TypeSoftware weakness
Read post
CVE-2026-7574: Anthropic Claude Desktop Cowork VM image handling (con
25/06/2026 / CVE, CWE-353, Security Research

CVE-2026-7574: Anthropic Claude Desktop Cowork VM image handling (con

ApplicationAnthropic Claude Desktop Cowork VM image handling (confirmed across v1
TypeSoftware weakness
Read post
CVE-2026-54639: Style Dictionary, a build system for creating cross-pl
25/06/2026 / CVE, CWE-1321, Security Research

CVE-2026-54639: Style Dictionary, a build system for creating cross-pl

ApplicationStyle Dictionary
TypeSoftware weakness
Read post
CVE-2026-12681: Improper Validation of Specified Index, Position, or O
25/06/2026 / CVE, CWE-1285, Security Research

CVE-2026-12681: Improper Validation of Specified Index, Position, or O

ApplicationImproper Validation of Specified Index
TypeSoftware weakness
Read post
CVE-2026-10645: Zephyr's ext2 directory-entry parser does not fully va
24/06/2026 / CVE, CWE-125, Security Research

CVE-2026-10645: Zephyr's ext2 directory-entry parser does not fully va

Applicationext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops
TypeOut-of-bounds read
Read post
CVE-2026-10651: A malformed Bluetooth Classic SDP attribute can trigge
24/06/2026 / CVE, CWE-20, Security Research

CVE-2026-10651: A malformed Bluetooth Classic SDP attribute can trigge

ApplicationZephyr's SDP parser
TypeSoftware weakness
Read post
CVE-2026-10658: A missing length validation in the Zephyr Bluetooth Ho
24/06/2026 / CVE, CWE-125, Security Research

CVE-2026-10658: A missing length validation in the Zephyr Bluetooth Ho

ApplicationA missing length validation in the Zephyr Bluetooth Host
TypeOut-of-bounds read
Read post
CVE-2026-11833: Overview: 
A vulnerability has been found in FAST/TOOL
24/06/2026 / CVE, CWE-319, Security Research

CVE-2026-11833: Overview: A vulnerability has been found in FAST/TOOL

ApplicationFAST
TypeSoftware weakness
Read post
CVE-2026-55653: A flaw was found in OpenSSH.
24/06/2026 / CVE, CWE-415, Security Research

CVE-2026-55653: A flaw was found in OpenSSH.

ApplicationOpenSSH. A malicious
TypeSoftware weakness
Read post
CVE-2026-12815: A vulnerability has been found in coollabsio coolify 4
23/06/2026 / CVE, CWE-77, Security Research

CVE-2026-12815: A vulnerability has been found in coollabsio coolify 4

Applicationcoollabsio coolify 4.0.0.
TypeSoftware weakness
Read post
CVE-2026-12821: A vulnerability was determined in FlowiseAI Flowise up
23/06/2026 / CVE, CWE-22, Security Research

CVE-2026-12821: A vulnerability was determined in FlowiseAI Flowise up

ApplicationFlowiseAI Flowise
TypePath traversal
Read post
CVE-2026-12822: A vulnerability was identified in langflow-ai langflow
23/06/2026 / CVE, CWE-74, Security Research

CVE-2026-12822: A vulnerability was identified in langflow-ai langflow

Applicationlangflow-ai langflow
TypeInjection vulnerability
Read post
CVE-2026-12823: A security flaw has been discovered in Browserbase up
23/06/2026 / CVE, CWE-266, Security Research

CVE-2026-12823: A security flaw has been discovered in Browserbase up

ApplicationA security flaw
TypeIncorrect privilege assignment
Read post
CVE-2026-11745: A vulnerability has been identified in centraldogma-se
23/06/2026 / CVE, CWE-322, Security Research

CVE-2026-11745: A vulnerability has been identified in centraldogma-se

Applicationcentraldogma-server-mirror-git versions
TypeSoftware weakness
Read post
CVE-2026-12770: A vulnerability was determined in BerriAI litellm up t
22/06/2026 / CVE, CWE-266, Security Research

CVE-2026-12770: A vulnerability was determined in BerriAI litellm up t

ApplicationBerriAI litellm
TypeIncorrect privilege assignment
Read post
CVE-2026-12771: A vulnerability was identified in BerriAI litellm up t
22/06/2026 / CVE, CWE-266, Security Research

CVE-2026-12771: A vulnerability was identified in BerriAI litellm up t

ApplicationBerriAI litellm
TypeIncorrect privilege assignment
Read post
CVE-2026-12772: A security flaw has been discovered in BerriAI litellm
22/06/2026 / CVE, CWE-613, Security Research

CVE-2026-12772: A security flaw has been discovered in BerriAI litellm

ApplicationA security flaw
TypeSoftware weakness
Read post
CVE-2026-12773: A weakness has been identified in BerriAI litellm up t
22/06/2026 / CVE, CWE-287, Security Research

CVE-2026-12773: A weakness has been identified in BerriAI litellm up t

ApplicationBerriAI litellm
TypeImproper authentication
Read post
CVE-2026-12774: A security vulnerability has been detected in BerriAI
22/06/2026 / CVE, CWE-918, Security Research

CVE-2026-12774: A security vulnerability has been detected in BerriAI

ApplicationBerriAI litellm
TypeServer-side request forgery
Read post
CVE-2026-48908: A vulnerability in SP Page Builder for Joomla allows u
22/06/2026 / CVE, CWE-284, Security Research

CVE-2026-48908: A vulnerability in SP Page Builder for Joomla allows u

ApplicationSP Page Builder for Joomla
TypeAccess control vulnerability
Read post
CVE-2026-48909: SP LMS (com_splms)  4.1.4 by JoomShaper deserializes
22/06/2026 / CVE, CWE-502, Security Research

CVE-2026-48909: SP LMS (com_splms) 4.1.4 by JoomShaper deserializes

ApplicationSP LMS (com_splms) 4
TypeSoftware weakness
Read post
CVE-2026-48939: A vulnerability in the iCagenda extension for Joomla a
22/06/2026 / CVE, CWE-284, Security Research

CVE-2026-48939: A vulnerability in the iCagenda extension for Joomla a

Applicationthe iCagenda extension for Joomla
TypeAccess control vulnerability
Read post
CVE-2019-25763: WordPress Ultimate Addons for Beaver Builder 1.2.4.1 c
22/06/2026 / CVE, CWE-288, Security Research

CVE-2019-25763: WordPress Ultimate Addons for Beaver Builder 1.2.4.1 c

ApplicationWordPress Ultimate Addons for Beaver Builder 1
TypeSoftware weakness
Read post
CVE-2020-37255: WordPress Time Capsule Plugin 1.21.16 contains an auth
22/06/2026 / CVE, CWE-288, Security Research

CVE-2020-37255: WordPress Time Capsule Plugin 1.21.16 contains an auth

ApplicationWordPress Time Capsule Plugin 1
TypeSoftware weakness
Read post
CVE-2026-11775: User Admin Simplifier plugin for WordPress
20/06/2026 / CVE, CWE-352, Security Research

CVE-2026-11775: User Admin Simplifier plugin for WordPress

ApplicationThe User Admin Simplifier plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-8805: Integer Overflow or Wraparound vulnerability in the Et
20/06/2026 / CVE, CWE-190, Security Research

CVE-2026-8805: Integer Overflow or Wraparound vulnerability in the Et

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-8806: Expected Behavior Violation vulnerability in Mitsubish
20/06/2026 / CVE, CWE-440, Security Research

CVE-2026-8806: Expected Behavior Violation vulnerability in Mitsubish

Applicationa short period of time
TypeSoftware weakness
Read post
CVE-2025-7737: DoS Vulnerability in 10G iSCSI Interface of Hitachi Vi
20/06/2026 / CVE, CWE-770, Security Research

CVE-2025-7737: DoS Vulnerability in 10G iSCSI Interface of Hitachi Vi

ApplicationDoS Vulnerability in 10G
TypeSoftware weakness
Read post
CVE-2026-10034: WP DSGVO Tools (GDPR) plugin for WordPress
20/06/2026 / CVE, CWE-862, Security Research

CVE-2026-10034: WP DSGVO Tools (GDPR) plugin for WordPress

ApplicationThe WP DSGVO Tools (GDPR) plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-12569: A critical remote code execution (RCE) vulnerability h
19/06/2026 / CVE, CWE-20, Security Research

CVE-2026-12569: A critical remote code execution (RCE) vulnerability h

ApplicationA critical remote code execution (RCE) vulnerability
TypeSoftware weakness
Read post
CVE-2026-10023: Dokan: AI Powered WooCommerce Multivendor Marketplace
19/06/2026 / CVE, CWE-639, Security Research

CVE-2026-10023: Dokan: AI Powered WooCommerce Multivendor Marketplace

Applicationall
TypeIDOR access control flaw
Read post
CVE-2026-12407: E2Pdf – Export Pdf Tool for WordPress plugin for WordP
19/06/2026 / CVE, CWE-862, Security Research

CVE-2026-12407: E2Pdf – Export Pdf Tool for WordPress plugin for WordP

ApplicationThe E2Pdf – Export Pdf Tool for WordPress plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-12505: A flaw was found in the cifs-utils package where the c
19/06/2026 / CVE, CWE-250, Security Research

CVE-2026-12505: A flaw was found in the cifs-utils package where the c

Applicationthe cifs-utils package
TypeSoftware weakness
Read post
CVE-2026-10029: Event Koi Lite – Events Calendar, Event Management, RS
19/06/2026 / CVE, CWE-862, Security Research

CVE-2026-10029: Event Koi Lite – Events Calendar, Event Management, RS

ApplicationThe Event Koi Lite – Events Calendar
TypeSoftware weakness
Read post
CVE-2024-31435: : Missing Authorization vulnerability in Inisev Social
19/06/2026 / CVE, CWE-862, Security Research

CVE-2024-31435: : Missing Authorization vulnerability in Inisev Social

ApplicationInisev Social Media & Share Icons
TypeSoftware weakness
Read post
CVE-2024-32729: Improper Limitation of a Pathname to a Restricted Dire
19/06/2026 / CVE, CWE-22, Security Research

CVE-2024-32729: Improper Limitation of a Pathname to a Restricted Dire

ApplicationQuantumCloud Conversational Forms for ChatBot
TypePath traversal
Read post
CVE-2024-32949: Missing Authorization vulnerability in Prince Integrat
19/06/2026 / CVE, CWE-862, Security Research

CVE-2024-32949: Missing Authorization vulnerability in Prince Integrat

ApplicationMissing Authorization vulnerability in Prince Integrate Google Drive
TypeSoftware weakness
Read post
CVE-2024-33685: Missing Authorization vulnerability in Jegstudio Start
19/06/2026 / CVE, CWE-862, Security Research

CVE-2024-33685: Missing Authorization vulnerability in Jegstudio Start

ApplicationMissing Authorization vulnerability in Jegstudio Startupzy startupzy
TypeSoftware weakness
Read post
CVE-2026-35263: Vulnerability in the WebLogic Server product of Oracle
19/06/2026 / CVE, CWE-284, Security Research

CVE-2026-35263: Vulnerability in the WebLogic Server product of Oracle

Applicationoracle weblogic server 14.1.2.0.0
TypeAccess control vulnerability
Read post
CVE-2026-12348: Address bar spoofing in Arc Search for Android allows
18/06/2026 / CVE, CWE-1021, Security Research

CVE-2026-12348: Address bar spoofing in Arc Search for Android allows

ApplicationAddress bar spoofing in Arc Search for Android
TypeSoftware weakness
Read post
CVE-2026-35258: Vulnerability in the WebLogic Server product of Oracle
18/06/2026 / CVE, CWE-601, Security Research

CVE-2026-35258: Vulnerability in the WebLogic Server product of Oracle

Applicationoracle weblogic server 14.1.2.0.0
TypeSoftware weakness
Read post
CVE-2026-35259: Vulnerability in the WebLogic Server product of Oracle
18/06/2026 / CVE, CWE-601, Security Research

CVE-2026-35259: Vulnerability in the WebLogic Server product of Oracle

Applicationoracle weblogic server 14.1.2.0.0
TypeSoftware weakness
Read post
CVE-2026-35261: Vulnerability in the Oracle Access Manager product of
18/06/2026 / CVE, CWE-287, Security Research

CVE-2026-35261: Vulnerability in the Oracle Access Manager product of

Applicationoracle access manager 12.2.1.4.0
TypeImproper authentication
Read post
CVE-2026-35262: Vulnerability in the Oracle Data Integrator product of
18/06/2026 / CVE, CWE-284, Security Research

CVE-2026-35262: Vulnerability in the Oracle Data Integrator product of

Applicationoracle data integrator 12.2.1.4.0
TypeAccess control vulnerability
Read post
CVE-2026-12192: A vulnerability was determined in GALAYOU Y4 1.0.0.
16/06/2026 / CVE, CWE-119, Security Research

CVE-2026-12192: A vulnerability was determined in GALAYOU Y4 1.0.0.

ApplicationGALAYOU Y4 1
TypeSoftware weakness
Read post
CVE-2026-12193: A vulnerability was identified in VS Revo RevoUninstal
16/06/2026 / CVE, CWE-119, Security Research

CVE-2026-12193: A vulnerability was identified in VS Revo RevoUninstal

ApplicationVS Revo RevoUninstaller
TypeSoftware weakness
Read post
CVE-2026-12197: A security flaw has been discovered in Ruijie EG105G-P
16/06/2026 / CVE, CWE-74, Security Research

CVE-2026-12197: A security flaw has been discovered in Ruijie EG105G-P

ApplicationA security flaw
TypeInjection vulnerability
Read post
CVE-2026-12198: A weakness has been identified in Microweber up to 2.0
16/06/2026 / CVE, CWE-22, Security Research

CVE-2026-12198: A weakness has been identified in Microweber up to 2.0

ApplicationMicroweber up to
TypePath traversal
Read post
CVE-2026-12200: A security vulnerability has been detected in Ritlabs
16/06/2026 / CVE, CWE-119, Security Research

CVE-2026-12200: A security vulnerability has been detected in Ritlabs

ApplicationRitlabs TinyWeb Server
TypeSoftware weakness
Read post
CVE-2026-12176: A vulnerability has been found in SourceCodester CET A
15/06/2026 / CVE, CWE-79, Security Research

CVE-2026-12176: A vulnerability has been found in SourceCodester CET A

ApplicationSourceCodester CET Automated
TypeCross-site scripting
Read post
CVE-2026-54420: LiteSpeed cPanel plugin before 2.4.8 (as distributed i
15/06/2026 / CVE, CWE-61, Security Research

CVE-2026-54420: LiteSpeed cPanel plugin before 2.4.8 (as distributed i

Applicationlitespeedtech litespeed cpanel plugin
TypeSoftware weakness
Read post
CVE-2026-54421: In OpenStack Ironic through 35.0.1, when applying a PA
15/06/2026 / CVE, CWE-212, Security Research

CVE-2026-54421: In OpenStack Ironic through 35.0.1, when applying a PA

ApplicationIn OpenStack Ironic
TypeSoftware weakness
Read post
CVE-2025-15546: Iptanus File Upload WordPress plugin before 5.1.7 does
15/06/2026 / CVE, Vulnerability Management, Security Research

CVE-2025-15546: Iptanus File Upload WordPress plugin before 5.1.7 does

ApplicationThe Iptanus File Upload WordPress plugin
TypeVulnerability Management
Read post
CVE-2026-11526: GD versions before 2.86 for Perl allow OS command inje
15/06/2026 / CVE, CWE-73, Security Research

CVE-2026-11526: GD versions before 2.86 for Perl allow OS command inje

ApplicationGD
TypeSoftware weakness
Read post
CVE-2026-11442: Allegra exportReport Directory Traversal Information D
14/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11442: Allegra exportReport Directory Traversal Information D

ApplicationAllegra exportReport Directory Traversal Information Disclosure Vulnerability
TypePath traversal
Read post
CVE-2026-11443: Allegra downloadAttachment Cross-Site Scripting Authen
14/06/2026 / CVE, CWE-79, Security Research

CVE-2026-11443: Allegra downloadAttachment Cross-Site Scripting Authen

Applicationthat the target must visit a malicious page or open a malicious file
TypeCross-site scripting
Read post
CVE-2026-12089: LWS Optimize – All-in-One Speed Booster & Cache Tools
14/06/2026 / CVE, CWE-22, Security Research

CVE-2026-12089: LWS Optimize – All-in-One Speed Booster & Cache Tools

ApplicationThe LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress
TypePath traversal
Read post
CVE-2026-54228: A time-of-check time-of-use (TOCTOU) race condition wa
14/06/2026 / CVE, CWE-367, Security Research

CVE-2026-54228: A time-of-check time-of-use (TOCTOU) race condition wa

Applicationthe abrt-dbus D-Bus
TypeSoftware weakness
Read post
CVE-2026-54229: A race condition was found in the abrt-dbus D-Bus serv
14/06/2026 / CVE, CWE-362, Security Research

CVE-2026-54229: A race condition was found in the abrt-dbus D-Bus serv

Applicationthe abrt-dbus D-Bus
TypeSoftware weakness
Read post
CVE-2026-10676: Rejected reason: This CVE Record has been rejected by
13/06/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-10676: Rejected reason: This CVE Record has been rejected by

Applicationany released
TypeVulnerability Management
Read post
CVE-2026-49482: ClipBucket v5 is an open source video sharing platform
13/06/2026 / CVE, CWE-155, Security Research

CVE-2026-49482: ClipBucket v5 is an open source video sharing platform

ApplicationClipBucket v5
TypeSoftware weakness
Read post
CVE-2026-11933: A use-after-free vulnerability exists in MongoDB Serve
13/06/2026 / CVE, CWE-787, Security Research

CVE-2026-11933: A use-after-free vulnerability exists in MongoDB Serve

Applicationdisclosure of information from the mongod process memory or a denial of service
TypeOut-of-bounds write
Read post
CVE-2026-45170: Idira Privilege Cloud Connector versions prior 1.1.100
13/06/2026 / CVE, CWE-295, Security Research

CVE-2026-45170: Idira Privilege Cloud Connector versions prior 1.1.100

ApplicationIdira Privilege Cloud Connector
TypeSoftware weakness
Read post
CVE-2026-9125: Presto Player plugin for WordPress
13/06/2026 / CVE, CWE-79, Security Research

CVE-2026-9125: Presto Player plugin for WordPress

ApplicationThe Presto Player plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-2827: Open User Map PRO plugin for WordPress
12/06/2026 / CVE, CWE-79, Security Research

CVE-2026-2827: Open User Map PRO plugin for WordPress

ApplicationThe Open User Map PRO plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools
12/06/2026 / CVE, CWE-306, Security Research

CVE-2026-35273: Vulnerability in the PeopleSoft Enterprise PeopleTools

Applicationoracle peoplesoft enterprise peopletools 8.61
TypeMissing authentication
Read post
CVE-2026-40985: Applications that configure the WebFlowELExpressionPar
12/06/2026 / CVE, CWE-917, Security Research

CVE-2026-40985: Applications that configure the WebFlowELExpressionPar

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-10795: UpdraftPlus: WP Backup & Migration Plugin plugin for W
12/06/2026 / CVE, CWE-347, Security Research

CVE-2026-10795: UpdraftPlus: WP Backup & Migration Plugin plugin for W

Applicationall
TypeSoftware weakness
Read post
CVE-2026-40986: Spring Web Flow's JavaScript RemotingHandler renders t
12/06/2026 / CVE, CWE-79, Security Research

CVE-2026-40986: Spring Web Flow's JavaScript RemotingHandler renders t

Applicationa scripting attack in the user's browser if the error response from the server
TypeCross-site scripting
Read post
CVE-2026-40988: An application using spring-security-saml2-service-pro
11/06/2026 / CVE, CWE-400, Security Research

CVE-2026-40988: An application using spring-security-saml2-service-pro

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-40991: When using spring-restdocs-webtestclient or spring-res
11/06/2026 / CVE, CWE-611, Security Research

CVE-2026-40991: When using spring-restdocs-webtestclient or spring-res

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-40993: An attacker with write permissions to the database tab
11/06/2026 / CVE, CWE-502, Security Research

CVE-2026-40993: An attacker with write permissions to the database tab

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-41003: An attacker able to influence values in RelyingPartyRe
11/06/2026 / CVE, CWE-79, Security Research

CVE-2026-41003: An attacker able to influence values in RelyingPartyRe

ApplicationApplication not specified
TypeCross-site scripting
Read post
CVE-2026-41008: Spring Security Authorization Server's authorization e
11/06/2026 / CVE, CWE-601, Security Research

CVE-2026-41008: Spring Security Authorization Server's authorization e

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-11628: Use after free in Ozone in Google Chrome prior to 149.
10/06/2026 / CVE, CWE-416, Security Research

CVE-2026-11628: Use after free in Ozone in Google Chrome prior to 149.

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-11629: Use after free in Ozone in Google Chrome prior to 149.
10/06/2026 / CVE, CWE-416, Security Research

CVE-2026-11629: Use after free in Ozone in Google Chrome prior to 149.

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-11630: Use after free in File Input in Google Chrome prior to
10/06/2026 / CVE, CWE-416, Security Research

CVE-2026-11630: Use after free in File Input in Google Chrome prior to

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-11631: Use after free in Aura in Google Chrome on Windows pri
10/06/2026 / CVE, CWE-416, Security Research

CVE-2026-11631: Use after free in Aura in Google Chrome on Windows pri

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-11632: Use after free in TabStrip in Google Chrome prior to 1
10/06/2026 / CVE, CWE-416, Security Research

CVE-2026-11632: Use after free in TabStrip in Google Chrome prior to 1

Applicationgoogle chrome
TypeSoftware weakness
Read post
CVE-2026-11467: A security vulnerability has been detected in jishengh
09/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11467: A security vulnerability has been detected in jishengh

Applicationjishenghua jshERP
TypePath traversal
Read post
CVE-2026-11468: A vulnerability was detected in SourceCodester Hospita
09/06/2026 / CVE, CWE-79, Security Research

CVE-2026-11468: A vulnerability was detected in SourceCodester Hospita

ApplicationSourceCodester Hospitals Patient
TypeCross-site scripting
Read post
CVE-2026-11469: A flaw has been found in jishenghua jshERP up to 3.6.
09/06/2026 / CVE, CWE-918, Security Research

CVE-2026-11469: A flaw has been found in jishenghua jshERP up to 3.6.

Applicationjishenghua jshERP
TypeServer-side request forgery
Read post
CVE-2026-11470: A vulnerability has been found in hs-web hsweb-framewo
09/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11470: A vulnerability has been found in hs-web hsweb-framewo

Applicationhs-web hsweb-framework
TypePath traversal
Read post
CVE-2026-11471: A vulnerability was found in SourceCodester Class and
09/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11471: A vulnerability was found in SourceCodester Class and

ApplicationSourceCodester Class and
TypeInjection vulnerability
Read post
CVE-2026-11447: A security flaw has been discovered in GL.iNet GL-MT30
08/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11447: A security flaw has been discovered in GL.iNet GL-MT30

ApplicationA security flaw
TypeInjection vulnerability
Read post
CVE-2026-11448: A weakness has been identified in GL.iNet GL-MT3000 up
08/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11448: A weakness has been identified in GL.iNet GL-MT3000 up

ApplicationGL.iNet GL-MT3000
TypeInjection vulnerability
Read post
CVE-2026-11449: A security vulnerability has been detected in GL.iNet
08/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11449: A security vulnerability has been detected in GL.iNet

ApplicationGL.iNet GL-MT3000 4.4.5.
TypeInjection vulnerability
Read post
CVE-2026-11450: A vulnerability was detected in GL.iNet GL-MT3000 4.4.
08/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11450: A vulnerability was detected in GL.iNet GL-MT3000 4.4.

ApplicationGL.iNet GL-MT3000 4.4.5.
TypeInjection vulnerability
Read post
CVE-2026-11451: A flaw has been found in GL.iNet GL-MT3000 4.4.5.
08/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11451: A flaw has been found in GL.iNet GL-MT3000 4.4.5.

ApplicationGL.iNet GL-MT3000 4.4.5.
TypeInjection vulnerability
Read post
CVE-2026-10725: Protocol::HTTP2 versions through 1.12 for Perl is vuln
08/06/2026 / CVE, CWE-409, Security Research

CVE-2026-10725: Protocol::HTTP2 versions through 1.12 for Perl is vuln

ApplicationApplication not specified
TypeSoftware weakness
Read post
CVE-2026-11406: A vulnerability was determined in GL.iNet MT3000 up to
08/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11406: A vulnerability was determined in GL.iNet MT3000 up to

ApplicationGL
TypeInjection vulnerability
Read post
CVE-2026-11408: A vulnerability was identified in vertex-app vertex up
08/06/2026 / CVE, CWE-77, Security Research

CVE-2026-11408: A vulnerability was identified in vertex-app vertex up

Applicationvertex-app vertex
TypeSoftware weakness
Read post
CVE-2026-11411: A security flaw has been discovered in iAI Lab PDF AI
08/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11411: A security flaw has been discovered in iAI Lab PDF AI

ApplicationA security flaw
TypePath traversal
Read post
CVE-2026-11412: A weakness has been identified in Jinher OA C6.
08/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11412: A weakness has been identified in Jinher OA C6.

ApplicationJinher OA C6.
TypeInjection vulnerability
Read post
CVE-2026-7537: MDJM Event Management plugin for WordPress
07/06/2026 / CVE, CWE-434, Security Research

CVE-2026-7537: MDJM Event Management plugin for WordPress

ApplicationThe MDJM Event Management plugin for WordPress
TypeFile upload vulnerability
Read post
CVE-2026-7565: LearnPress – Backup & Migration Tool plugin for WordPre
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-7565: LearnPress – Backup & Migration Tool plugin for WordPre

ApplicationThe LearnPress – Backup & Migration Tool plugin for WordPress
TypePath traversal
Read post
CVE-2026-7566: LearnPress – Backup & Migration Tool plugin for WordPre
07/06/2026 / CVE, CWE-502, Security Research

CVE-2026-7566: LearnPress – Backup & Migration Tool plugin for WordPre

ApplicationThe LearnPress – Backup & Migration Tool plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-7665: Essential Addons for Elementor – Popular Elementor Temp
07/06/2026 / CVE, CWE-639, Security Research

CVE-2026-7665: Essential Addons for Elementor – Popular Elementor Temp

Applicationall
TypeIDOR access control flaw
Read post
CVE-2026-8438: All-In-One Security (AIOS) – Security and Firewall plug
07/06/2026 / CVE, CWE-79, Security Research

CVE-2026-8438: All-In-One Security (AIOS) – Security and Firewall plug

ApplicationThe All-In-One Security (AIOS) – Security and Firewall plugin for WordPress
TypeCross-site scripting
Read post
CVE-2026-8901: Integration for Freshsales – Contact Form 7, WPForms, E
07/06/2026 / CVE, CWE-79, Security Research

CVE-2026-8901: Integration for Freshsales – Contact Form 7, WPForms, E

ApplicationThe Integration for Freshsales – Contact Form 7
TypeCross-site scripting
Read post
CVE-2026-9008: Page-list plugin for WordPress
07/06/2026 / CVE, CWE-862, Security Research

CVE-2026-9008: Page-list plugin for WordPress

ApplicationThe Page-list plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-9281: Master Addons For Elementor – Widgets, Extensions, Them
07/06/2026 / CVE, CWE-79, Security Research

CVE-2026-9281: Master Addons For Elementor – Widgets, Extensions, Them

ApplicationThe Master Addons For Elementor – Widgets
TypeCross-site scripting
Read post
CVE-2026-2500: Quick Playground plugin for WordPress
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-2500: Quick Playground plugin for WordPress

ApplicationThe Quick Playground plugin for WordPress
TypePath traversal
Read post
CVE-2026-34123: On Tapo
C520WS v2, restricted accounts (for example, h
07/06/2026 / CVE, CWE-287, Security Research

CVE-2026-34123: On Tapo C520WS v2, restricted accounts (for example, h

ApplicationOn Tapo C520WS v2
TypeImproper authentication
Read post
CVE-2026-6239: A stack‑based
buffer overflow vulnerability exists in
07/06/2026 / CVE, CWE-121, Security Research

CVE-2026-6239: A stack‑based buffer overflow vulnerability exists in

ApplicationTapo C520WS v2 in the ONVIF CreateUsers service
TypeSoftware weakness
Read post
CVE-2026-6240: A stack-based buffer overflow vulnerability exists in
07/06/2026 / CVE, CWE-121, Security Research

CVE-2026-6240: A stack-based buffer overflow vulnerability exists in

ApplicationTapo C520WS v2 in the ONVIF DeleteUsers service
TypeSoftware weakness
Read post
CVE-2026-7523: Alba Board plugin for WordPress
07/06/2026 / CVE, CWE-862, Security Research

CVE-2026-7523: Alba Board plugin for WordPress

ApplicationThe Alba Board plugin for WordPress
TypeSoftware weakness
Read post
CVE-2026-7654: Admin Columns plugin for WordPress
07/06/2026 / CVE, CWE-502, Security Research

CVE-2026-7654: Admin Columns plugin for WordPress

ApplicationThe Admin Columns plugin for WordPress
TypeSoftware weakness
Read post
CVE-2025-12656: Migration, Backup, Staging – WPvivid Backup & Migratio
07/06/2026 / CVE, CWE-73, Security Research

CVE-2025-12656: Migration, Backup, Staging – WPvivid Backup & Migratio

ApplicationThe Migration
TypeSoftware weakness
Read post
CVE-2026-10038: Charitable – Donation Plugin for WordPress – Fundraisi
07/06/2026 / CVE, CWE-639, Security Research

CVE-2026-10038: Charitable – Donation Plugin for WordPress – Fundraisi

Applicationversions
TypeIDOR access control flaw
Read post
CVE-2026-11429: A path traversal vulnerability exists in the Git Servi
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11429: A path traversal vulnerability exists in the Git Servi

Applicationthe Git Service component shared by Altium Enterprise Server and Altium 365
TypePath traversal
Read post
CVE-2026-11431: A path traversal vulnerability exists in the Projects
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11431: A path traversal vulnerability exists in the Projects

ApplicationApplication not specified
TypePath traversal
Read post
CVE-2026-45409: Internationalized Domain Names in Applications (IDNA)
07/06/2026 / CVE, CWE-1333, Security Research

CVE-2026-45409: Internationalized Domain Names in Applications (IDNA)

ApplicationApplications (IDNA) and Unicode IDNA Compatibility Processing
TypeSoftware weakness
Read post
CVE-2026-11416: MoviePilot contains a path traversal vulnerability in
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11416: MoviePilot contains a path traversal vulnerability in

ApplicationMoviePilot
TypePath traversal
Read post
CVE-2026-11424: A server-side request forgery (SSRF) vulnerability exi
07/06/2026 / CVE, CWE-200, Security Research

CVE-2026-11424: A server-side request forgery (SSRF) vulnerability exi

Applicationa GraphQL service component shared by Altium Enterprise Server and Altium 365
TypeSoftware weakness
Read post
CVE-2026-46401: HAX CMS helps manage microsite universe with PHP or No
07/06/2026 / CVE, CWE-613, Security Research

CVE-2026-46401: HAX CMS helps manage microsite universe with PHP or No

ApplicationHAX CMS helps manage microsite universe with PHP or NodeJs backends
TypeSoftware weakness
Read post
CVE-2026-46493: HAX CMS helps manage microsite universe with PHP or No
07/06/2026 / CVE, CWE-338, Security Research

CVE-2026-46493: HAX CMS helps manage microsite universe with PHP or No

ApplicationHAX CMS helps manage microsite universe with PHP or NodeJs backends
TypeSoftware weakness
Read post
CVE-2026-11422: Markdown Preview Enhanced 0.8.x with crossnote engine
07/06/2026 / CVE, CWE-95, Security Research

CVE-2026-11422: Markdown Preview Enhanced 0.8.x with crossnote engine

ApplicationMarkdown Preview Enhanced 0
TypeSoftware weakness
Read post
CVE-2026-11423: A path traversal vulnerability exists in the Altium En
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11423: A path traversal vulnerability exists in the Altium En

Applicationthe MCAD and Simulation file download flows
TypePath traversal
Read post
CVE-2026-36785: Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.
07/06/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-36785: Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.

ApplicationShenzhen Tenda Technology Co
TypeVulnerability Management
Read post
CVE-2026-11400: An untrusted search path issue in the GlobalDatabasePl
07/06/2026 / CVE, CWE-426, Security Research

CVE-2026-11400: An untrusted search path issue in the GlobalDatabasePl

ApplicationAn untrusted search path
TypeSoftware weakness
Read post
CVE-2026-11401: An untrusted search path issue in the GlobalDatabasePl
07/06/2026 / CVE, CWE-426, Security Research

CVE-2026-11401: An untrusted search path issue in the GlobalDatabasePl

ApplicationAn untrusted search path
TypeSoftware weakness
Read post
CVE-2026-11414: A hard-coded cryptographic key is used by Altium Enter
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11414: A hard-coded cryptographic key is used by Altium Enter

ApplicationA hard-coded cryptographic key
TypePath traversal
Read post
CVE-2026-11419: A path traversal vulnerability exists in the Altium En
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11419: A path traversal vulnerability exists in the Altium En

Applicationimage upload requests
TypePath traversal
Read post
CVE-2026-11420: Two path traversal vulnerabilities in the Network Inst
07/06/2026 / CVE, CWE-22, Security Research

CVE-2026-11420: Two path traversal vulnerabilities in the Network Inst

ApplicationApplication not specified
TypePath traversal
Read post
CVE-2026-10580: Hippoo Mobile App for WooCommerce plugin for WordPress
07/06/2026 / CVE, CWE-285, Security Research

CVE-2026-10580: Hippoo Mobile App for WooCommerce plugin for WordPress

ApplicationThe Hippoo Mobile App for WooCommerce plugin for WordPress
TypeAuthorization bypass
Read post
CVE-2026-46389: UDS Identity Config builds the Keycloak configuration
07/06/2026 / CVE, CWE-287, Security Research

CVE-2026-46389: UDS Identity Config builds the Keycloak configuration

ApplicationUDS Identity Config builds the Keycloak configuration image (realm
TypeImproper authentication
Read post
CVE-2026-46390: HAX CMS helps manage microsite universe with PHP or No
07/06/2026 / CVE, CWE-639, Security Research

CVE-2026-46390: HAX CMS helps manage microsite universe with PHP or No

ApplicationHAX CMS helps manage microsite universe with PHP or NodeJs backends
TypeIDOR access control flaw
Read post
CVE-2026-46391: HAX CMS helps manage microsite universe with PHP or No
07/06/2026 / CVE, CWE-183, Security Research

CVE-2026-46391: HAX CMS helps manage microsite universe with PHP or No

ApplicationHAX CMS helps manage microsite universe with PHP or NodeJs backends
TypeSoftware weakness
Read post
CVE-2026-46392: HAX CMS helps manage microsite universe with PHP or No
07/06/2026 / CVE, CWE-178, Security Research

CVE-2026-46392: HAX CMS helps manage microsite universe with PHP or No

ApplicationHAX CMS helps manage microsite universe with PHP or NodeJs backends
TypeSoftware weakness
Read post
CVE-2025-71317: NetMan 204 contains a hard-coded backdoor account with
07/06/2026 / CVE, CWE-798, Security Research

CVE-2025-71317: NetMan 204 contains a hard-coded backdoor account with

ApplicationNetMan 204
TypeSoftware weakness
Read post
CVE-2025-71318: NetMan 204 fails to enforce authentication on its admi
07/06/2026 / CVE, CWE-306, Security Research

CVE-2025-71318: NetMan 204 fails to enforce authentication on its admi

ApplicationApplication not specified
TypeMissing authentication
Read post
CVE-2026-11341: A flaw has been found in D-Link DWR-M920 up to 1.1.50.
07/06/2026 / CVE, CWE-77, Security Research

CVE-2026-11341: A flaw has been found in D-Link DWR-M920 up to 1.1.50.

ApplicationD-Link DWR-M920
TypeSoftware weakness
Read post
CVE-2026-11342: A vulnerability has been found in code-projects Hotel
07/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11342: A vulnerability has been found in code-projects Hotel

Applicationcode-projects Hotel and
TypeInjection vulnerability
Read post
CVE-2026-11344: A vulnerability was found in code-projects Vehicle Man
07/06/2026 / CVE, CWE-284, Security Research

CVE-2026-11344: A vulnerability was found in code-projects Vehicle Man

Applicationcode-projects Vehicle Management
TypeAccess control vulnerability
Read post
CVE-2025-5088: An authenticated Redis session could be used to obtain
07/06/2026 / CVE, CWE-269, Security Research

CVE-2025-5088: An authenticated Redis session could be used to obtain

Applicationthe CVX cluster
TypeSoftware weakness
Read post
CVE-2025-5089: In a CVX cluster, an EOS switch connected to a CVX ser
07/06/2026 / CVE, CWE-20, Security Research

CVE-2025-5089: In a CVX cluster, an EOS switch connected to a CVX ser

ApplicationIn a CVX cluster
TypeSoftware weakness
Read post
CVE-2025-5090: CVX is not resilient to unexpected messages from a con
07/06/2026 / CVE, CWE-20, Security Research

CVE-2025-5090: CVX is not resilient to unexpected messages from a con

ApplicationCVX
TypeSoftware weakness
Read post
CVE-2026-11337: A vulnerability was found in tittuvarghese CollegeMana
07/06/2026 / CVE, CWE-79, Security Research

CVE-2026-11337: A vulnerability was found in tittuvarghese CollegeMana

Applicationtittuvarghese CollegeManagementSystem
TypeCross-site scripting
Read post
CVE-2026-11338: A security vulnerability has been detected in SourceCo
07/06/2026 / CVE, CWE-79, Security Research

CVE-2026-11338: A security vulnerability has been detected in SourceCo

ApplicationSourceCodester Ship Ferry
TypeCross-site scripting
Read post
CVE-2026-11336: A vulnerability has been found in tittuvarghese Colleg
07/06/2026 / CVE, CWE-266, Security Research

CVE-2026-11336: A vulnerability has been found in tittuvarghese Colleg

Applicationtittuvarghese CollegeManagementSystem
TypeIncorrect privilege assignment
Read post
CVE-2026-11362: DataDog::DogStatsd versions through 0.07 for Perl allo
07/06/2026 / CVE, CWE-93, Security Research

CVE-2026-11362: DataDog::DogStatsd versions through 0.07 for Perl allo

ApplicationApplication not specified
TypeHeader injection
Read post
CVE-2026-48101: 7-Zip is a file archiver with a high compression ratio
07/06/2026 / CVE, CWE-908, Security Research

CVE-2026-48101: 7-Zip is a file archiver with a high compression ratio

Application7-Zip
TypeUninitialized resource use
Read post
CVE-2026-48102: 7-Zip is a file archiver with a high compression ratio
07/06/2026 / CVE, CWE-125, Security Research

CVE-2026-48102: 7-Zip is a file archiver with a high compression ratio

Application7-Zip
TypeOut-of-bounds read
Read post
CVE-2026-9270: DataDog::DogStatsd versions through 0.07 for Perl allo
07/06/2026 / CVE, CWE-93, Security Research

CVE-2026-9270: DataDog::DogStatsd versions through 0.07 for Perl allo

ApplicationApplication not specified
TypeHeader injection
Read post
CVE-2020-25900: HelloTalk through 3.4.1 stores full-precision GPS coor
07/06/2026 / CVE, CWE-359, Security Research

CVE-2020-25900: HelloTalk through 3.4.1 stores full-precision GPS coor

ApplicationHelloTalk
TypePrivacy data exposure
Read post
CVE-2025-59174: Ericsson Packet Core Controller (PCC) versions prior t
07/06/2026 / CVE, CWE-228, Security Research

CVE-2025-59174: Ericsson Packet Core Controller (PCC) versions prior t

ApplicationEricsson Packet Core Controller (PCC)
TypeMalformed input handling
Read post
CVE-2026-10879: DBI versions before 1.648 for Perl have a heap overflo
07/06/2026 / CVE, CWE-787, Security Research

CVE-2026-10879: DBI versions before 1.648 for Perl have a heap overflo

ApplicationDBI
TypeOut-of-bounds write
Read post
CVE-2026-11333: A security vulnerability has been detected in tittuvar
07/06/2026 / CVE, CWE-284, Security Research

CVE-2026-11333: A security vulnerability has been detected in tittuvar

Applicationtittuvarghese CollegeManagementSystem
TypeAccess control vulnerability
Read post
CVE-2026-11334: A vulnerability was detected in tittuvarghese CollegeM
07/06/2026 / CVE, CWE-74, Security Research

CVE-2026-11334: A vulnerability was detected in tittuvarghese CollegeM

Applicationtittuvarghese CollegeManagementSystem
TypeInjection vulnerability
Read post
CVE-2026-11329: A vulnerability has been found in onnx onnx-mlir up to
07/06/2026 / CVE, CWE-327, Security Research

CVE-2026-11329: A vulnerability has been found in onnx onnx-mlir up to

Applicationonnx onnx-mlir
TypeWeak cryptography
Read post
CVE-2026-11330: A weakness has been identified in thedotmack claude-me
07/06/2026 / CVE, CWE-327, Security Research

CVE-2026-11330: A weakness has been identified in thedotmack claude-me

Applicationthedotmack claude-mem
TypeWeak cryptography
Read post
CVE-2026-11369: Comment API (GET /api/Comment and POST /api/Comment) i
07/06/2026 / CVE, CWE-639, Security Research

CVE-2026-11369: Comment API (GET /api/Comment and POST /api/Comment) i

ApplicationApplication not specified
TypeIDOR access control flaw
Read post
CVE-2026-38500: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.
07/06/2026 / CVE, Vulnerability Management, Security Research

CVE-2026-38500: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.

ApplicationApplication not specified
TypeVulnerability Management
Read post
CVE-2026-50230: Lyrion Music Server 9.2.0 contains an unauthenticated
07/06/2026 / CVE, CWE-79, Security Research

CVE-2026-50230: Lyrion Music Server 9.2.0 contains an unauthenticated

ApplicationLyrion Music Server 9
TypeCross-site scripting
Read post
CVE-2026-11345: An Improper Authentication vulnerability in the /api/C
07/06/2026 / CVE, CWE-287, Security Research

CVE-2026-11345: An Improper Authentication vulnerability in the /api/C

Applicationthe /api/Cdn/GetFile endpoint of linqi
TypeImproper authentication
Read post
CVE-2026-11346: A Server-Side Request Forgery (SSRF) vulnerability in
07/06/2026 / CVE, CWE-918, Security Research

CVE-2026-11346: A Server-Side Request Forgery (SSRF) vulnerability in

Applicationthe custom process creation feature of linqi
TypeServer-side request forgery
Read post
CVE-2026-25657: Ericsson Packet Core Gateway (PCG) versions prior to 1
07/06/2026 / CVE, CWE-228, Security Research

CVE-2026-25657: Ericsson Packet Core Gateway (PCG) versions prior to 1

ApplicationEricsson Packet Core Gateway (PCG)
TypeMalformed input handling
Read post
CVE-2026-25658: Ericsson
Packet Core Gateway (PCG) versions prior to 1
07/06/2026 / CVE, CWE-230, Security Research

CVE-2026-25658: Ericsson Packet Core Gateway (PCG) versions prior to 1

ApplicationEricsson Packet Core Gateway (PCG)
TypeInput validation issue
Read post
CVE-2026-25659: Ericsson
Packet Core Gateway (PCG) versions prior to 1
07/06/2026 / CVE, CWE-230, Security Research

CVE-2026-25659: Ericsson Packet Core Gateway (PCG) versions prior to 1

ApplicationEricsson Packet Core Gateway (PCG)
TypeInput validation issue
Read post
CVE-2026-21025: Incorrect privilege assignment in Telephony prior to S
07/06/2026 / CVE, NVD-CWE-Other, Security Research

CVE-2026-21025: Incorrect privilege assignment in Telephony prior to S

Applicationsamsung android 14.0
TypeNVD-CWE-Other
Read post
CVE-2026-21026: Improper export of android application components in S
07/06/2026 / CVE, NVD-CWE-Other, Security Research

CVE-2026-21026: Improper export of android application components in S

Applicationsamsung android 16.0
TypeNVD-CWE-Other
Read post
CVE-2026-21027: Improper export of android application components in I
07/06/2026 / CVE, NVD-CWE-Other, Security Research

CVE-2026-21027: Improper export of android application components in I

Applicationsamsung android 14.0
TypeNVD-CWE-Other
Read post
CVE-2026-11347: linqi application contains hardcoded cryptographic key
07/06/2026 / CVE, CWE-321, Security Research

CVE-2026-11347: linqi application contains hardcoded cryptographic key

ApplicationThe linqi application
TypeSoftware weakness
Read post
CVE-2026-21017: Improper handling of insufficient privileges in SecTel
07/06/2026 / CVE, NVD-CWE-Other, Security Research

CVE-2026-21017: Improper handling of insufficient privileges in SecTel

Applicationsamsung android 14.0
TypeNVD-CWE-Other
Read post
CVE-2026-48907: A vulnerability in the JCE editor extension for Joomla
07/06/2026 / CVE, CWE-284, Security Research

CVE-2026-48907: A vulnerability in the JCE editor extension for Joomla

Applicationthe JCE editor extension for Joomla
TypeAccess control vulnerability
Read post
CVE-2026-9088: A flaw was found in org.keycloak.services.
07/06/2026 / CVE, CWE-1220, Security Research

CVE-2026-9088: A flaw was found in org.keycloak.services.

Applicationorg.keycloak.services. An administrator
TypeSoftware weakness
Read post
CVE-2026-11332: A flaw was found in ansible-core.
07/06/2026 / CVE, CWE-88, Security Research

CVE-2026-11332: A flaw was found in ansible-core.

Applicationansible-core. The ansible-galaxy
TypeSoftware weakness
Read post
CVE-2026-49777: Improper Validation of Specified Quantity in Input vul
07/06/2026 / CVE, CWE-1284, Security Research

CVE-2026-49777: Improper Validation of Specified Quantity in Input vul

ApplicationImproper Validation of Specified Quantity in Input vulnerability in ShapedPlugin
TypeSoftware weakness
Read post
CVE-2026-6274: Improper Authentication, Missing authentication for cr
07/06/2026 / CVE, CWE-287, Security Research

CVE-2026-6274: Improper Authentication, Missing authentication for cr

ApplicationImproper Authentication
TypeImproper authentication
Read post
CVE-2026-4782: Avada Builder plugin for WordPress
16/05/2026 / CVE, CWE-36, Security Research

CVE-2026-4782: Avada Builder plugin for WordPress

ApplicationThe Avada Builder plugin for WordPress
TypeArbitrary file read
Read post
CVE-2026-28388: When a delta CRL that contains a Delta CRL Indicator e
16/05/2026 / CVE, CWE-476, Security Research

CVE-2026-28388: When a delta CRL that contains a Delta CRL Indicator e

Applicationopenssl openssl
TypeNull pointer denial of service
Read post
CVE-2026-2673: An OpenSSL TLS 1.3 server may fail to negotiate the ex
16/05/2026 / CVE, CWE-757, Security Research

CVE-2026-2673: An OpenSSL TLS 1.3 server may fail to negotiate the ex

Applicationopenssl openssl
TypeCryptographic negotiation flaw
Read post
CVE-2026-31431: Linux Kernel algif_aead KEV Vulnerability
16/05/2026 / CVE, CWE-669, Security Research

CVE-2026-31431: Linux Kernel algif_aead KEV Vulnerability

Applicationlinux linux kernel
TypeResource transfer flaw
Read post
CVE-2026-8014: Chrome Preload Cross-Origin Data Leak
16/05/2026 / CVE, CWE-693, Security Research

CVE-2026-8014: Chrome Preload Cross-Origin Data Leak

Applicationgoogle chrome
TypeProtection mechanism failure
Read post
Contact

Let's talk.

Whether you're evaluating the platform, exploring a partnership, or have a security research inquiry, we'd love to hear from you.

hello@vesamuni.com
Melbourne, VIC, Australia
Colombo, Sri Lanka
Response within 24 hours
Required.
Valid email required.
Required.
System Status

Operational Status

All Systems Operational
Threat Intelligence APIOperational
Scan EngineOperational
DashboardOperational
Webhook DeliveryOperational
AuthenticationOperational
CLI / SDKOperational
AI Guided Pentesting Platform

AI Guided Pentesting
that never Stops.

Continuous security testing priced by protected asset, not by scan. Run unlimited rescans, monitor new CVEs, and use monthly AI pentest credits for deeper validation.

Monthly subscriptions. Cancel or change plan from the billing portal.

Network Security
Scout
$79/mo
per month

Network vulnerability assessment, attack surface discovery, cloud checks, and continuous CVE monitoring for small security teams.

Scanning & Testing
  • 5 protected assets with unlimited scans and rescans during each monthly cycle
  • 1 AI pentest scan / month — AI-guided penetration test targeting your highest-risk external asset
  • Full NVD database access — real-time CVE matching against your installed plugins, themes & core version
  • OWASP Top 10 coverage with severity scoring (Critical → Info)
Intelligence & Monitoring
  • NVD-backed plugin & theme vulnerability detection
  • WordPress core version security tracking
  • SSL/TLS certificate monitoring
  • Outdated software & end-of-life component alerts
Reporting
  • Basic reports — scan summary with findings, severity, and remediation steps
  • PDF export of scan results
  • Dashboard access — single-site view
Support
  • Email support
  • Vesamuni knowledge base access
Full-cycle Pentesting
Vanguard
$249/mo
per month

Deep vulnerability testing and reporting with the highest self-service AI pentest allowance, continuous asset monitoring, API access, and configurable exports.

Scanning & Testing
  • 5 protected assets with unlimited vulnerability scans and rescans
  • 10 AI pentest scans / month — deep AI-guided penetration testing with multi-vector attack simulation
  • Real-time NVD/CVE alerts — instant notification when new vulnerabilities affect your environment
  • Full web application, API & infrastructure scanning
  • AI-driven false positive elimination with proof-of-exploit validation
  • On-demand re-scans after remediation (unlimited)
Intelligence & Monitoring
  • Continuous dashboard visibility into monitored assets and findings
  • Continuous attack surface discovery & asset enumeration
  • Threat intelligence feed — CVE tracking + emerging threat advisories
  • Technology stack fingerprinting & change detection
  • SSL/TLS, DNS, domain & certificate transparency monitoring
Reporting & API
  • Custom reports — configurable report templates with branding, scope & audience controls
  • API access — full REST API for scan orchestration, results retrieval & webhook integration
  • Priority remediation guidance — risk-ranked action items with context & fix recommendations
  • Compliance alignment mapping (ISO 27001, SOC 2, PCI-DSS indicators)
  • Risk trend dashboards with historical comparison
  • PDF, CSV & JSON export
Support
  • Priority email + chat support
  • Dedicated onboarding & configuration assistance
  • Vesamuni Threat Advisory bulletins
  • Early access to new platform features
Custom Platform Plan
Enterprise
Custom
tailored to your environment

A custom software plan for larger asset inventories, additional testing capacity, tailored scan schedules, and product onboarding. Scope and limits are agreed before activation.

Scanning & Testing
  • Custom protected asset allowance based on your scope
  • Unlimited automated rescans across included assets
  • Custom monthly AI pentest credit allowance
  • Web application, API, infrastructure, WordPress, SSL/TLS, and cloud checks
  • Configurable scheduled scans and finding notifications
  • AI-assisted finding review and remediation guidance
  • Custom scan profiles for industry-specific threat models
Monitoring & Workflow
  • Continuous attack surface discovery and risk scoring
  • Email alerts for new critical and high-severity findings
  • Scan history and risk trend comparison
  • Webhook-based workflow integration
Reporting & API
  • Custom reports & API access — full REST API, configurable templates and structured output
  • Compliance control mapping indicators for supported frameworks
  • Executive risk summaries and historical trend reporting
  • PDF, CSV, and JSON exports
Product Support
  • Priority email support during published business hours
  • Remote onboarding and configuration assistance
  • Product feedback and roadmap sessions
  • Early access to all new Vesamuni modules & features
At a glance

Side-by-side comparison
across all tiers.

Scout Sentinel Vanguard Enterprise
Price $79/mo $249/mo Custom
Protected Assets 5 assets 5 assets Unlimited
Scans & Rescans Unlimited Unlimited Unlimited
AI Pentest Scans / mo 1 10 Unlimited
NVD Database Access
NVD/CVE Monitoring Real-time Real-time
Reports Basic Custom Custom + Board-ready
Email Alerts Real-time Real-time
API Access Full + Webhooks
Remediation Guidance Basic Priority + Context Priority + Context
Attack Surface Discovery Continuous Full ASM
Web App Scanning WordPress Full stack Full stack + API + Cloud
Compliance Mapping Control indicators
Custom Report Templates
Pricing Notes
Transparent Monthly Billing

Pay month to month in USD. Change or cancel through Stripe's secure billing portal.

Asset-based Allowances

Plans limit unique protected assets, not scans. Rescan covered assets as often as needed.

Researchers & Non-profits

Introductory rates for independent security researchers, academic institutions, and registered non-profits. Reach out and mention your organisation type.

Upgrades

Start on any tier and upgrade at any time. Your scan history, configurations, and discovered assets carry over seamlessly.

Enterprise

Custom software plan for larger asset allowances, additional testing credits, tailored scan schedules, onboarding, and priority product support.

Ready to see
everything?

Join the organisations that refuse to be reactive. Get early access to the Vesamuni intelligence platform.

Protected Workspace

Security Dashboard

Monitor your subscription, protected perimeter, and account security.

Plan Checking... Loading billing status
Protected Assets 0 / 0 No perimeter configured
Account Security Checking... Reviewing controls
Subscription Renewal Not scheduled Managed securely by Stripe
Protected Perimeter

Primary monitored asset

Pending setup

HTTPS is recommended. Private network and local addresses are rejected.

Credentials

Change password

At least 12 characters Passwords match Different from current password

Changing your password invalidates every other active session.

🐸