Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72851 | CRITICAL | Patched | 10.0 | 2026-08-13 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-contro… |
| CVE-2026-61962 | CRITICAL | 10.0 | 2026-08-13 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | |
| CVE-2026-27544 | CRITICAL | 10.0 | 2026-08-13 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | |
| CVE-2026-59500 | CRITICAL | 10.0 | 2026-08-13 | : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Prio… | |
| CVE-2026-15413 | CRITICAL | 10.0 | 2026-08-13 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ … | |
| CVE-2026-72841 | CRITICAL | 9.9 | 2026-08-13 | luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary file… | |
| CVE-2026-72842 | CRITICAL | 9.9 | 2026-08-13 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper au… | |
| CVE-2026-73656 | CRITICAL | Patched | 9.9 | 2026-08-13 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls … |
| CVE-2026-72776 | CRITICAL | 9.8 | 2026-08-13 | AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by subm… | |
| CVE-2026-72839 | CRITICAL | 9.8 | 2026-08-13 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can r… | |
| CVE-2026-17482 | CRITICAL | Patched | 9.8 | 2026-08-13 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. |
| CVE-2026-19747 | CRITICAL | 9.8 | 2026-08-13 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd … | |
| CVE-2026-73649 | CRITICAL | Patched | 9.8 | 2026-08-13 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and p… |
| CVE-2026-67614 | CRITICAL | Patched | 9.8 | 2026-08-13 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid au… |
| CVE-2026-56654 | CRITICAL | 9.8 | 2026-08-13 | Privilege Escalation via Access Token Scope Escalation in API | |
| CVE-2026-73532 | CRITICAL | 9.8 | 2026-08-13 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered … | |
| CVE-2026-73533 | CRITICAL | 9.8 | 2026-08-13 | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered… | |
| CVE-2026-66691 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | |
| CVE-2026-66465 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | |
| CVE-2026-66453 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | |
| CVE-2026-66424 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | |
| CVE-2026-61967 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | |
| CVE-2026-28185 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | |
| CVE-2026-28149 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | |
| CVE-2026-28008 | CRITICAL | 9.8 | 2026-08-13 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. |