Recent vulnerabilities


ID CVSS Description Vendor Product Published Updated
cve-2026-55593 Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint —… froxlor
froxlor
2026-08-18T20:18:01.526Z 2026-08-19T18:20:14.720Z
cve-2026-53456 Blueprint Studio terminal SSH private key written to disk ha-china
blueprint-studio
2026-08-18T20:50:21.016Z 2026-08-19T18:20:06.837Z
cve-2026-48796 CefSharp: `FolderSchemeHandlerFactory` path boundary c… cefsharp
CefSharp
2026-08-18T21:17:16.861Z 2026-08-19T18:19:59.005Z
cve-2026-62377 libheif: Reachable assertion in HeifContext::get_track… strukturag
libheif
2026-08-18T21:22:29.899Z 2026-08-19T18:19:50.593Z
cve-2026-52876 Streambert: Arbitrary File Execution via VLC/mpv Launc… truelockmc
streambert
2026-08-18T21:29:08.476Z 2026-08-19T18:19:44.618Z
cve-2026-50191 4gaBoards: Pre-Account Takeover via SSO Email Linkage RARgames
4gaBoards
2026-08-18T21:33:16.270Z 2026-08-19T18:19:36.054Z
cve-2026-62682 Orval: RCE via servers[].url -> unescaped request-URL … orval-labs
orval
2026-08-19T17:40:17.061Z 2026-08-19T18:19:27.462Z
cve-2026-44829 Gotenberg: Path traversal in zip entry name via Window… gotenberg
gotenberg
2026-08-19T14:35:06.966Z 2026-08-19T18:19:27.164Z
cve-2026-45272 MyBooks: Remote Code Execution via SOCIAL_AUTH Key Nam… PoxenStudio
talebook
2026-08-19T14:39:49.973Z 2026-08-19T18:19:19.525Z
cve-2026-49283 SimpleSAMLphp HTTP-Artifact TLS validator confusion al… simplesamlphp
saml2
2026-08-19T14:47:05.519Z 2026-08-19T18:19:10.978Z
cve-2026-52834 jxl-oxide: Out-of-bounds writes due to integer overflo… tirr-c
jxl-oxide
2026-08-19T14:55:32.138Z 2026-08-19T18:19:05.526Z
cve-2026-61842 Grav: Twig sandbox config exfiltration via grav.offset… getgrav
grav
2026-08-19T15:23:27.038Z 2026-08-19T18:18:54.336Z
cve-2026-62669 Grav Login Plugin: 2FA Bypass via 'login.regenerate2FA… getgrav
grav
2026-08-19T15:40:03.252Z 2026-08-19T18:18:46.380Z
cve-2026-63408 Grav API Plugin: JWT Access Token Accepted via `?token… getgrav
grav-plugin-api
2026-08-19T15:53:08.681Z 2026-08-19T18:18:38.809Z
cve-2026-44254 Wazuh: Stack Out-of-Bounds Write in remoted Decompress… wazuh
wazuh
2026-08-19T16:09:55.307Z 2026-08-19T18:18:27.247Z
cve-2026-49441 Wazuh : peer-controlled metadata key in process_files_… wazuh
wazuh
2026-08-19T16:19:37.206Z 2026-08-19T18:18:21.696Z
cve-2026-44256 Wazuh: CRLF Log Injection via Unsanitized Basic-Auth U… wazuh
wazuh
2026-08-19T16:21:49.920Z 2026-08-19T18:18:11.834Z
cve-2026-55191 FreeRDP: Heap-buffer-overflow write in AVC444 YUV buff… FreeRDP
FreeRDP
2026-08-19T17:44:52.392Z 2026-08-19T18:17:07.147Z
cve-2026-63652 FreeRDP: Double-free of `client_formats` in the rdpsnd… FreeRDP
FreeRDP
2026-08-19T17:59:07.480Z 2026-08-19T18:13:15.780Z
cve-2026-17565 N/A Animation Addons for Elementor < 2.7.2 - Unauthenticat… Unknown
Animation Addons for Elementor
2026-08-19T06:00:18.230Z 2026-08-19T18:09:30.528Z
cve-2026-60682 Vulnerability in the Oracle Hyperion Financial Re… Oracle Corporation
Oracle Hyperion Financial Reporting
2026-08-18T20:58:57.884Z 2026-08-19T18:08:45.784Z
cve-2026-16979 N/A SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post T… Unknown
SmartCrawl SEO checker, analyzer & optimizer
2026-08-19T06:00:17.806Z 2026-08-19T18:08:30.359Z
cve-2026-16950 N/A Product Shortlist <= 1.0.4 - Unauthenticated SQL Injec… Unknown
Product Shortlist
2026-08-19T06:00:17.567Z 2026-08-19T18:07:47.631Z
cve-2026-62680 Orval: Generation-time SSRF + remote/local file inclus… orval-labs
orval
2026-08-19T17:42:11.227Z 2026-08-19T18:06:47.948Z
cve-2026-52889 Formie: Server-Side Template Injection in Formie Hidde… verbb
formie
2026-08-19T14:57:12.928Z 2026-08-19T18:05:26.381Z
cve-2026-49289 SimpleSAMLphp SAML2: Possible DoS via XPath Transform simplesamlphp
saml2
2026-08-19T14:48:52.694Z 2026-08-19T18:04:15.406Z
cve-2026-71866 Orval: Import-time RCE via schema property name -> com… orval-labs
orval
2026-08-19T17:27:28.222Z 2026-08-19T18:03:13.730Z
cve-2026-60699 Vulnerability in the Oracle WebLogic Server produ… Oracle Corporation
Oracle WebLogic Server
2026-08-18T20:58:59.177Z 2026-08-19T18:01:51.801Z
cve-2026-62672 Grav: Authenticated ReDoS via regex_replace in Twig Sandbox getgrav
grav
2026-08-19T15:44:36.287Z 2026-08-19T18:00:39.622Z
cve-2026-60707 Vulnerability in the Oracle Identity Manager prod… Oracle Corporation
Oracle Identity Manager
2026-08-18T20:58:59.821Z 2026-08-19T17:57:49.946Z
ID CVSS Description Vendor Product Published Updated
ID Description Package Published Updated
ID Description Type
ID Description Updated
ID Description Updated
ID Description Updated
ID Description