#
20 entries
2026-08-03
ID: 740
CVE-2026-15962 - Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field
2026-08-03
ID: 736
CVE-2026-66013 - OpenRemote before 1.26.2 Authentication Bypass via Console Registration
2026-08-03
ID: 711
CVE-2026-16766 - Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
2026-08-03
ID: 703
CVE-2026-10818 - WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
2026-08-03
ID: 701
CVE-2026-15425 - Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)
2026-08-02
ID: 692
CVE-2026-66338 - Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()
2026-08-02
ID: 690
CVE-2026-55985 - Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information
2026-08-02
ID: 689
CVE-2026-61884 - Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel
2026-08-02
ID: 679
CVE-2026-48032 - Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
2026-08-02
ID: 678
CVE-2026-48033 - Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name
2026-08-02
ID: 677
CVE-2026-48034 - HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
2026-08-02
ID: 669
CVE-2026-65623 - Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
2026-08-02
ID: 668
CVE-2026-65707 - Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint
2026-08-01
ID: 635
CVE-2026-65693 - Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates