Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-72851 CRITICAL Patched 10.0 2026-08-13 Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-contro…
CVE-2026-61962 CRITICAL 10.0 2026-08-13 Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVE-2026-27544 CRITICAL 10.0 2026-08-13 Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
CVE-2026-59500 CRITICAL 10.0 2026-08-13 : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Prio&hellip;
CVE-2026-15413 CRITICAL 10.0 2026-08-13 The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ &hellip;
CVE-2026-72841 CRITICAL 9.9 2026-08-13 luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary file&hellip;
CVE-2026-72842 CRITICAL 9.9 2026-08-13 luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper au&hellip;
CVE-2026-73656 CRITICAL Patched 9.9 2026-08-13 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls &hellip;
CVE-2026-72776 CRITICAL 9.8 2026-08-13 AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by subm&hellip;
CVE-2026-72839 CRITICAL 9.8 2026-08-13 filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can r&hellip;
CVE-2026-17482 CRITICAL Patched 9.8 2026-08-13 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
CVE-2026-19747 CRITICAL 9.8 2026-08-13 A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd &hellip;
CVE-2026-73649 CRITICAL Patched 9.8 2026-08-13 Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and p&hellip;
CVE-2026-67614 CRITICAL Patched 9.8 2026-08-13 CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid au&hellip;
CVE-2026-56654 CRITICAL 9.8 2026-08-13 Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-73532 CRITICAL 9.8 2026-08-13 Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered &hellip;
CVE-2026-73533 CRITICAL 9.8 2026-08-13 Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered&hellip;
CVE-2026-66691 CRITICAL 9.8 2026-08-13 Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
CVE-2026-66465 CRITICAL 9.8 2026-08-13 Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
CVE-2026-66453 CRITICAL 9.8 2026-08-13 Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
CVE-2026-66424 CRITICAL 9.8 2026-08-13 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
CVE-2026-61967 CRITICAL 9.8 2026-08-13 Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVE-2026-28185 CRITICAL 9.8 2026-08-13 Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CVE-2026-28149 CRITICAL 9.8 2026-08-13 Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVE-2026-28008 CRITICAL 9.8 2026-08-13 Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.