|
cve-2026-55593
|
|
Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint —…
|
froxlor
|
froxlor
|
2026-08-18T20:18:01.526Z |
2026-08-19T18:20:14.720Z |
|
cve-2026-53456
|
|
Blueprint Studio terminal SSH private key written to disk
|
ha-china
|
blueprint-studio
|
2026-08-18T20:50:21.016Z |
2026-08-19T18:20:06.837Z |
|
cve-2026-48796
|
|
CefSharp: `FolderSchemeHandlerFactory` path boundary c…
|
cefsharp
|
CefSharp
|
2026-08-18T21:17:16.861Z |
2026-08-19T18:19:59.005Z |
|
cve-2026-62377
|
|
libheif: Reachable assertion in HeifContext::get_track…
|
strukturag
|
libheif
|
2026-08-18T21:22:29.899Z |
2026-08-19T18:19:50.593Z |
|
cve-2026-52876
|
|
Streambert: Arbitrary File Execution via VLC/mpv Launc…
|
truelockmc
|
streambert
|
2026-08-18T21:29:08.476Z |
2026-08-19T18:19:44.618Z |
|
cve-2026-50191
|
|
4gaBoards: Pre-Account Takeover via SSO Email Linkage
|
RARgames
|
4gaBoards
|
2026-08-18T21:33:16.270Z |
2026-08-19T18:19:36.054Z |
|
cve-2026-62682
|
|
Orval: RCE via servers[].url -> unescaped request-URL …
|
orval-labs
|
orval
|
2026-08-19T17:40:17.061Z |
2026-08-19T18:19:27.462Z |
|
cve-2026-44829
|
|
Gotenberg: Path traversal in zip entry name via Window…
|
gotenberg
|
gotenberg
|
2026-08-19T14:35:06.966Z |
2026-08-19T18:19:27.164Z |
|
cve-2026-45272
|
|
MyBooks: Remote Code Execution via SOCIAL_AUTH Key Nam…
|
PoxenStudio
|
talebook
|
2026-08-19T14:39:49.973Z |
2026-08-19T18:19:19.525Z |
|
cve-2026-49283
|
|
SimpleSAMLphp HTTP-Artifact TLS validator confusion al…
|
simplesamlphp
|
saml2
|
2026-08-19T14:47:05.519Z |
2026-08-19T18:19:10.978Z |
|
cve-2026-52834
|
|
jxl-oxide: Out-of-bounds writes due to integer overflo…
|
tirr-c
|
jxl-oxide
|
2026-08-19T14:55:32.138Z |
2026-08-19T18:19:05.526Z |
|
cve-2026-61842
|
|
Grav: Twig sandbox config exfiltration via grav.offset…
|
getgrav
|
grav
|
2026-08-19T15:23:27.038Z |
2026-08-19T18:18:54.336Z |
|
cve-2026-62669
|
|
Grav Login Plugin: 2FA Bypass via 'login.regenerate2FA…
|
getgrav
|
grav
|
2026-08-19T15:40:03.252Z |
2026-08-19T18:18:46.380Z |
|
cve-2026-63408
|
|
Grav API Plugin: JWT Access Token Accepted via `?token…
|
getgrav
|
grav-plugin-api
|
2026-08-19T15:53:08.681Z |
2026-08-19T18:18:38.809Z |
|
cve-2026-44254
|
|
Wazuh: Stack Out-of-Bounds Write in remoted Decompress…
|
wazuh
|
wazuh
|
2026-08-19T16:09:55.307Z |
2026-08-19T18:18:27.247Z |
|
cve-2026-49441
|
|
Wazuh : peer-controlled metadata key in process_files_…
|
wazuh
|
wazuh
|
2026-08-19T16:19:37.206Z |
2026-08-19T18:18:21.696Z |
|
cve-2026-44256
|
|
Wazuh: CRLF Log Injection via Unsanitized Basic-Auth U…
|
wazuh
|
wazuh
|
2026-08-19T16:21:49.920Z |
2026-08-19T18:18:11.834Z |
|
cve-2026-55191
|
|
FreeRDP: Heap-buffer-overflow write in AVC444 YUV buff…
|
FreeRDP
|
FreeRDP
|
2026-08-19T17:44:52.392Z |
2026-08-19T18:17:07.147Z |
|
cve-2026-63652
|
|
FreeRDP: Double-free of `client_formats` in the rdpsnd…
|
FreeRDP
|
FreeRDP
|
2026-08-19T17:59:07.480Z |
2026-08-19T18:13:15.780Z |
|
cve-2026-17565
|
N/A
|
Animation Addons for Elementor < 2.7.2 - Unauthenticat…
|
Unknown
|
Animation Addons for Elementor
|
2026-08-19T06:00:18.230Z |
2026-08-19T18:09:30.528Z |
|
cve-2026-60682
|
|
Vulnerability in the Oracle Hyperion Financial Re…
|
Oracle Corporation
|
Oracle Hyperion Financial Reporting
|
2026-08-18T20:58:57.884Z |
2026-08-19T18:08:45.784Z |
|
cve-2026-16979
|
N/A
|
SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post T…
|
Unknown
|
SmartCrawl SEO checker, analyzer & optimizer
|
2026-08-19T06:00:17.806Z |
2026-08-19T18:08:30.359Z |
|
cve-2026-16950
|
N/A
|
Product Shortlist <= 1.0.4 - Unauthenticated SQL Injec…
|
Unknown
|
Product Shortlist
|
2026-08-19T06:00:17.567Z |
2026-08-19T18:07:47.631Z |
|
cve-2026-62680
|
|
Orval: Generation-time SSRF + remote/local file inclus…
|
orval-labs
|
orval
|
2026-08-19T17:42:11.227Z |
2026-08-19T18:06:47.948Z |
|
cve-2026-52889
|
|
Formie: Server-Side Template Injection in Formie Hidde…
|
verbb
|
formie
|
2026-08-19T14:57:12.928Z |
2026-08-19T18:05:26.381Z |
|
cve-2026-49289
|
|
SimpleSAMLphp SAML2: Possible DoS via XPath Transform
|
simplesamlphp
|
saml2
|
2026-08-19T14:48:52.694Z |
2026-08-19T18:04:15.406Z |
|
cve-2026-71866
|
|
Orval: Import-time RCE via schema property name -> com…
|
orval-labs
|
orval
|
2026-08-19T17:27:28.222Z |
2026-08-19T18:03:13.730Z |
|
cve-2026-60699
|
|
Vulnerability in the Oracle WebLogic Server produ…
|
Oracle Corporation
|
Oracle WebLogic Server
|
2026-08-18T20:58:59.177Z |
2026-08-19T18:01:51.801Z |
|
cve-2026-62672
|
|
Grav: Authenticated ReDoS via regex_replace in Twig Sandbox
|
getgrav
|
grav
|
2026-08-19T15:44:36.287Z |
2026-08-19T18:00:39.622Z |
|
cve-2026-60707
|
|
Vulnerability in the Oracle Identity Manager prod…
|
Oracle Corporation
|
Oracle Identity Manager
|
2026-08-18T20:58:59.821Z |
2026-08-19T17:57:49.946Z |