CVEs NewScan detects

Every CVE NewScan detects, newest first, with the technology it affects and the day the detection landed. Most are version-matched against a fingerprinted component — those link to a page with the affected range, the release that fixes it, and how the scanner reports it. The rest are reported by a check that observes the vulnerability or its precondition directly rather than matching a version, so the row names that check instead of linking to a version range. The list is generated from the detection packs themselves and grows daily — local, in-band scanning is free, so you can check any of these against your own systems without a licence.

504 CVEs · 264 critical · 195 high · 43 medium · 2 low · 389 with a detail page

CVETechSeverity DescriptionAdded
CVE-2026-85984 miniorange-otp-verification critical miniOrange OTP Login, Verification and SMS Notifications (WordPress) authentication bypass - mo_wp_login_intent=otp logs an unauthenticated caller in as any administrator 2026-09-27
CVE-2026-82901 ultimate-addons-for-contact-form-7 critical Ultra Addons for Contact Form 7 (WordPress) unauthenticated arbitrary file upload in uacf7_wpcf7_mail_components -> possible RCE 2026-09-27
CVE-2026-100857 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100856 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100855 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100853 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100852 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100851 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100849 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100848 AzuraCast high Covered by the AzuraCast batch fix for CVE-2026-100847 2026-09-27
CVE-2026-100847 AzuraCast high AzuraCast pre-0.23.8 batch: DQL injection via the sortOrder API parameter, plus SSRF, command/code injection and unauthenticated media download 2026-09-27
CVE-2026-87902 WordPress critical WordPress core unauthenticated local file inclusion - get_page_template() resolves a page template outside the active theme and includes a chosen readable local .php file 2026-09-26
CVE-2026-65660 Microsoft SharePoint Server critical SharePoint Server code injection - an authenticated caller executes code on the server over the network (CVSS 8.8), actively exploited September 2026 2026-09-26
CVE-2026-100418 Flame medium Reported by NewScan's exposure path probe: Flame start-page configuration, weather API key included, answers an unauthenticated GET - CVE-2026-100418 2026-09-26
CVE-2026-89055 customer-reviews-woocommerce high Customer Reviews for WooCommerce authorization bypass - a plugin endpoint does not check the caller's capability before acting 2026-09-25
CVE-2026-63645 OpenObserve high Reported by NewScan's exposure path probe: OpenObserve runtime configuration answers an unauthenticated GET - CVE-2026-63645 2026-09-25
CVE-2026-97056 SigNoz critical Covered by the SigNoz batch fix for CVE-2026-97055 2026-09-24
CVE-2026-97055 SigNoz critical SigNoz ships an EMPTY default JWT signing secret, so anyone can forge an admin session (CVSS 9.2) 2026-09-24
CVE-2026-82077 PaperCut MF/NG high PaperCut MF/NG Scan-to-Fax path traversal reaching command execution on the host (CVSS 7.3) 2026-09-24
CVE-2026-14780 PaperCut MF/NG high Covered by the PaperCut MF/NG batch fix for CVE-2026-82077 2026-09-24
CVE-2026-87739 PaperCut MF/NG medium PaperCut MF/NG generates reports for an unauthenticated caller - user permissions are never evaluated (CVSS 6.9) 2026-09-24
CVE-2026-94127 F5 BIG-IP critical F5 BIG-IP APM heap overflow in OAuth request handling -> unauthenticated RCE (zero-day, exploited in the wild) 2026-09-23
CVE-2026-93616 Check Point Security Gateway critical Check Point Management Server directory traversal + file upload -> unauthenticated arbitrary script execution 2026-09-23
CVE-2026-85102 Check Point Security Gateway critical Check Point Quantum Security Gateway improper certificate trust validation during VPN negotiation -> unauthenticated RCE 2026-09-23
CVE-2026-73546 envoy critical Reported by NewScan's unauthenticated interface: Unauthenticated Envoy admin interface 2026-09-22
CVE-2026-84990 ntopng high ntopng before 6.7.260718: the system-configuration backup REST endpoints list and hand out configuration backups to a caller that should not be able to read them, exposing the moni… 2026-09-22
CVE-2026-82412 ntopng high ntopng before 6.7.260717: the vulnerability-scan REST endpoints pass a caller-supplied host into the scanner shell, so a request to the monitoring UI runs commands on the appliance… 2026-09-22
CVE-2026-73553 Envoy high Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… 2026-09-22
CVE-2026-73552 Envoy high Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… 2026-09-22
CVE-2026-73551 Envoy high Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… 2026-09-22
CVE-2026-73548 Envoy high Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgrade is forwarded as a tunnel (request smuggling… 2026-09-22
CVE-2026-73511 Envoy high Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… 2026-09-22
CVE-2026-82187 web-to-print-online-designer critical WooCommerce Online Product Designer unauthenticated arbitrary file upload -> RCE (no type/extension validation, upload token handed to any visitor) 2026-09-21
CVE-2026-86802 todo-lists-for-membership-sites high To Do List Member unauthenticated import - no authorisation or nonce check, and the fetched location is unvalidated (content injection + SSRF) 2026-09-21
CVE-2025-12999 HTTP high Reported by NewScan's named-CVE check: test_base_url_poisoning 2026-09-21
CVE-2026-85113 give medium GiveWP stored shortcode injection - donor-supplied values are rendered on public pages with shortcode delimiters intact 2026-09-21
CVE-2026-85010 restropress medium RestroPress client-side add-on price trusted by the server - unauthenticated order-total manipulation 2026-09-21
CVE-2026-87067 forminator high Forminator Forms (WordPress) PHP object injection: the XML-RPC path deserialises a request value with no allow-list of instantiable classes 2026-09-20
CVE-2026-81654 nextgen-gallery high Covered by the nextgen-gallery batch fix for CVE-2026-81652 2026-09-20
CVE-2026-81652 nextgen-gallery high NextGEN Gallery (WordPress) before 4.5.0: any logged-in user reads any image record, and any logged-in user writes the gallery's image-sizing settings 2026-09-20
CVE-2026-93964 Nginx Proxy Manager medium nginx-proxy-manager through 2.15.1: internalCertificate.validate mishandles an uploaded certificate bundle 2026-09-20
CVE-2026-93598 arcadedb high Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously 2026-09-19
CVE-2026-93595 arcadedb high Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously 2026-09-19
CVE-2026-93594 arcadedb high Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously 2026-09-19
CVE-2026-93593 arcadedb high Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously 2026-09-19
CVE-2026-61833 zot high zot before 2.1.18: the bearer authentication handler accepts a token it should reject, so an OCI registry configured for bearer auth can be read and written without a valid credent… 2026-09-19
CVE-2026-92947 vm2 critical vm2 shared Buffer pool host-memory exposure (version advisory) 2026-09-18
CVE-2026-92599 joi high Joi isoDate validation denial of service (17.x version advisory) 2026-09-18
CVE-2026-91992 tornado medium Tornado CurlAsyncHTTPClient credential reuse (version advisory) 2026-09-18
CVE-2026-89013 Dolibarr high Dolibarr authorization bypass - hashp=shared skips token validation in document.php and viewimage.php, giving an unauthenticated caller arbitrary file read 2026-09-14
CVE-2026-42018 JFrog Artifactory high JFrog Artifactory returns an internal anonymous-user token to an unauthenticated caller even when anonymous access is DISABLED (CISA KEV, exploited in the wild) 2026-09-14
CVE-2026-42016 JFrog Artifactory high JFrog Artifactory (self-hosted) privilege escalation - access tokens are validated on signature and issuer but never on SCOPE (CISA KEV, exploited in the wild) 2026-09-14
CVE-2026-90549 AVideo medium Reported by NewScan's exposure path probe: AVideo mobile video feed returns the video owner's email and last-login to an anonymous caller - CVE-2026-90549 2026-09-14
CVE-2026-90541 AVideo medium Reported by NewScan's exposure path probe: AVideo TopMenu administration menu list answers an unauthenticated GET - CVE-2026-90541 2026-09-14
CVE-2026-89012 Dolibarr medium Dolibarr case-sensitive denylist bypass in the sqlfilters API parameter - uppercase field names reach protected columns as a boolean oracle 2026-09-14
CVE-2026-84869 ConnectWise ScreenConnect critical ScreenConnect build distributes a client that can be made to transfer and execute files over an active remote session without Host authorization 2026-09-12
CVE-2026-72710 SPIP critical SPIP remote code execution via the editer_objet action - attacker rows injected into the spip_jobs queue are unserialized and executed by cron 2026-09-12
CVE-2026-72709 SPIP critical SPIP missing authorization on the ecrire/action/ endpoints - unauthenticated password reset of any account, including the administrator 2026-09-12
CVE-2026-72708 SPIP high SPIP unauthenticated blind SQL injection in the public sitemap - leaks the alea_ephemere nonce-signing secret 2026-09-12
CVE-2026-88877 Traefik critical Traefik Kubernetes Ingress NGINX provider authentication bypass - an Ingress carrying both an auth annotation and from-to-www-redirect generates a sibling host-only router that rea… 2026-09-11
CVE-2026-88007 Traefik critical Traefik HTTP/3 backend connection reuse across users - the HTTP/3 entrypoint's ConnContext never calls service.AddTransportOnContext, so a backend connection already authenticated … 2026-09-11
CVE-2026-89054 Apache HTTP Server high Reported by NewScan's named-CVE check: test_http_method_authz 2026-09-11
CVE-2026-88009 Traefik high Traefik rootless HTTP/1 request-target is routed as "/" but forwarded to the backend verbatim - Go parks a rootless target in URL.Opaque, so path-scoped routing rules, path-scoped … 2026-09-11
CVE-2026-88008 Traefik high Traefik request smuggling and incorrect authorization from inconsistent HTTP request interpretation between Traefik and the backend (CVSS 7.0) 2026-09-11
CVE-2026-88004 Traefik high Traefik entrypoint header-name sanitization bypassed via request trailers - a header Traefik strips or rewrites on the request can be reintroduced in the HTTP trailer section, whic… 2026-09-11
CVE-2026-89248 AVideo medium Reported by NewScan's exposure path probe: AVideo WebRTC plugin status endpoint answers anonymously - CVE-2026-89248 2026-09-11
CVE-2026-88879 Traefik medium Traefik canonicalizes header names on dashes only, so X-Auth-User, X_Auth_User and X.Auth.User are three headers to Traefik and ONE variable to a CGI/WSGI/PHP/NGINX backend - a cli… 2026-09-11
CVE-2026-88878 Traefik medium Traefik respondingTimeouts (readTimeout, on by default at 60s) are not applied to the HTTP/3 request path - readTimeout is a TCP connection deadline that cannot bind a QUIC stream,… 2026-09-11
CVE-2026-88012 Traefik medium Traefik respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded (CVSS 5.3) 2026-09-11
CVE-2026-88011 Traefik medium Traefik ForwardAuth identity spoofing via a dot-form header alias - the client supplies X.Authenticated.User alongside the canonical X-Authenticated-User that ForwardAuth writes, a… 2026-09-11
CVE-2026-20079 Cisco Secure Firewall Management Center critical Cisco Secure Firewall Management Center authentication bypass - a hardcoded internal session id is accepted from the network, giving an unauthenticated attacker the authenticated c… 2026-09-10
CVE-2026-19490 Citrix NetScaler ADC/Gateway critical NetScaler ADC/Gateway authentication bypass leading to account takeover (CVSS 9.3, CISA KEV) 2026-09-10
CVE-2023-6553 backup-backup critical Backup Migration unauthenticated remote code execution through attacker-controlled includes in backup-heart.php 2026-09-10
CVE-2025-25249 FortiOS SSL-VPN high FortiOS heap-based buffer overflow (CVSS 8.1, CISA KEV) - exploited in the wild by the PivotC2 FortiGate RAT 2026-09-10
CVE-2026-86218 N-able N-central critical N-able N-central pre-authentication remote code execution (CVSS 10.0, actively exploited) 2026-09-09
CVE-2026-87819 GitPython high GitPython Actor author/committer parsing regular-expression denial of service 2026-09-09
CVE-2026-86081 n8n high n8n Git node clone destination-path regular-expression denial of service 2026-09-09
CVE-2026-86543 knowns critical Reported by NewScan's unauthenticated interface: Unauthenticated knowns management API (no password set) 2026-09-08
CVE-2026-13190 Telerik UI for ASP.NET AJAX critical Telerik UI for ASP.NET AJAX unsafe type instantiation from persisted state in the persistence utilities -> remote code execution 2026-09-07
CVE-2026-13186 Telerik UI for ASP.NET AJAX critical Telerik UI for ASP.NET AJAX path traversal in the file-based persistence storage provider -> attacker-controlled deserialization and remote code execution 2026-09-07
CVE-2026-13185 Telerik UI for ASP.NET AJAX critical Telerik UI for ASP.NET AJAX deserialization of attacker-controlled cookie state in RadPersistenceManager / RadDockLayout -> unauthenticated remote code execution 2026-09-07
CVE-2026-13181 Telerik UI for ASP.NET AJAX critical Telerik UI for ASP.NET AJAX unsafe type resolution in RadAsyncUpload AsyncUploadTypeName -> remote code execution 2026-09-07
CVE-2026-13184 Telerik UI for ASP.NET AJAX high Telerik UI for ASP.NET AJAX predictable default upload-metadata integrity key when Telerik.Upload.ConfigurationHashKey and machineKey are both unset 2026-09-07
CVE-2026-13183 Telerik UI for ASP.NET AJAX high Telerik UI for ASP.NET AJAX timing oracle in RadAsyncUpload metadata processing -> recovery of protected metadata when detailed errors are suppressed 2026-09-07
CVE-2026-13182 Telerik UI for ASP.NET AJAX high Telerik UI for ASP.NET AJAX padding oracle in RadAsyncUpload client-state handling -> disclosure and forgery of protected upload metadata 2026-09-07
CVE-2026-2390 powerkit medium Powerkit (WordPress) stored cross-site scripting via the Lazy Load module's regex-based image-attribute parser 2026-09-07
CVE-2026-85595 Traefik critical Traefik digestAuth authentication bypass - an unknown username is answered with an empty secret instead of a rejection, so any username with no password authenticates (CVSS 9.3) 2026-09-04
CVE-2026-85597 Traefik high Traefik mTLS bypass - conflicting TLS options on routers sharing a hostname fall back to the default TLS config, dropping client-certificate authentication for every host in the ru… 2026-09-04
CVE-2026-85596 Traefik high Traefik Kubernetes Ingress NGINX provider mTLS bypass - Ingresses sharing a host and client CA generate distinct TLS option names, are read as a conflict, and fall back to a defaul… 2026-09-04
CVE-2026-85391 JSON Web Token high Reported by NewScan's named-CVE check: crack_jwt_secret 2026-09-04
CVE-2026-85180 Ollama high Ollama 0.30.0-0.33.2: SSRF when pulling tensor-layer models - blob downloads follow a cross-host redirect unvalidated, so a model reference the operator pulls can steer the server … 2026-09-04
CVE-2026-49869 Kestra critical Kestra authentication bypass -> unauthenticated RCE as root (CVSS 10.0, CISA KEV) 2026-09-03
CVE-2026-59822 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-09-03
CVE-2025-22871 RoadRunner critical RoadRunner request smuggling via bare-LF chunk-size line (bundled Go net/http) 2026-09-02
CVE-2026-84304 google.golang.org/grpc high gRPC-Go heap exhaustion through fragmented HTTP/2 DATA frames 2026-09-02
CVE-2026-83619 @xmldom/xmldom high xmldom quadratic end-tag parsing denial of service 2026-09-02
CVE-2026-81578 PaperCut MF/NG critical PaperCut MF/NG unauthenticated management-interface access control bypass chained to code execution (CISA KEV) 2026-09-01
CVE-2026-81891 elFinder high Covered by the elFinder batch fix for CVE-2026-81889 2026-09-01
CVE-2026-81890 elFinder high Covered by the elFinder batch fix for CVE-2026-81889 2026-09-01
CVE-2026-81889 elFinder high elFinder URL-upload SSRF filter bypass, archive-extraction MIME bypass and netmount left out of the CSRF-protected command list 2026-09-01
CVE-2026-77348 Wallos high Wallos SSRF through HTTP proxy environment variables - the incomplete fix for CVE-2026-33407 2026-09-01
CVE-2026-61641 Wallos high Covered by the Wallos batch fix for CVE-2026-61639 2026-09-01
CVE-2026-61640 Wallos high Covered by the Wallos batch fix for CVE-2026-61639 2026-09-01
CVE-2026-61639 Wallos high Wallos zip-slip on database restore, SSRF through the admin-set OIDC and SMTP endpoints, and OIDC identity linking by email 2026-09-01
CVE-2026-61638 Wallos high Covered by the Wallos batch fix for CVE-2026-61639 2026-09-01
CVE-2026-54600 Wallos high Wallos unauthenticated database import and schema migration over HTTP, plus an unchecked OIDC state nonce 2026-09-01
CVE-2026-54599 Wallos high Covered by the Wallos batch fix for CVE-2026-54600 2026-09-01
CVE-2026-54598 Wallos high Covered by the Wallos batch fix for CVE-2026-54600 2026-09-01
CVE-2026-33407 Wallos high Covered by the Wallos batch fix for CVE-2026-77348 2026-09-01
CVE-2026-82880 YaCy high YaCy Search Server XML external entity injection - the SVG, FreeMind and OpenSearch parsers resolve external entities 2026-08-31
CVE-2026-82654 SiYuan high Covered by the SiYuan batch fix for CVE-2026-82653 2026-08-31
CVE-2026-82653 SiYuan high SiYuan stored cross-site scripting - package and notebook names in confirmDialog(), and block name/alias/memo in hint, backlink and breadcrumb rendering, are interpolated into inne… 2026-08-31
CVE-2026-82456 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-30
CVE-2026-75807 miniorange-saml-20-single-sign-on high SAML Single Sign On - SSO Login (miniOrange) authentication bypass - mo_saml_login_validate() trusts an unverified assertion, so any account can be logged into 2026-08-30
CVE-2026-82476 Memos medium Memos server-side request forgery - the link-metadata fetcher omits the 100.64.0.0/10 CGNAT range from its SSRF guard 2026-08-30
CVE-2026-81766 really-simple-ssl medium Really Simple Security missing capability check on plugin installation - a subsite admin installs arbitrary plugins from a supplied URL 2026-08-30
CVE-2026-81660 groundhogg medium Groundhogg stored cross-site scripting - optional web-form fields are stored and rendered unescaped 2026-08-30
CVE-2026-76585 customer-reviews-woocommerce medium Customer Reviews for WooCommerce stored cross-site scripting - review content from one of its endpoints is neither sanitised nor escaped 2026-08-30
CVE-2026-78364 mw-wp-form low MW WP Form stored cross-site scripting - form settings are echoed unescaped in an admin dashboard page 2026-08-30
CVE-2026-82266 redpanda critical Reported by NewScan's unauthenticated interface: Unauthenticated Redpanda Admin API 2026-08-29
CVE-2026-19295 Langflow critical Covered by the Langflow batch fix for CVE-2026-19286 2026-08-29
CVE-2026-19294 Langflow critical Covered by the Langflow batch fix for CVE-2026-19286 2026-08-29
CVE-2026-19286 Langflow critical Langflow 1.0.0 - 1.11.1: remote code execution via the A2A public endpoint, plus 7 further IBM Langflow OSS advisories fixed in the same range 2026-08-29
CVE-2026-18904 Langflow critical Covered by the Langflow batch fix for CVE-2026-19286 2026-08-29
CVE-2026-18899 Langflow critical Covered by the Langflow batch fix for CVE-2026-19286 2026-08-29
CVE-2026-18891 Langflow critical Covered by the Langflow batch fix for CVE-2026-19286 2026-08-29
CVE-2026-18729 Langflow critical Covered by the Langflow batch fix for CVE-2026-19286 2026-08-29
CVE-2026-18545 Langflow critical Covered by the Langflow batch fix for CVE-2026-19286 2026-08-29
CVE-2026-82288 Stable Diffusion WebUI high Reported by NewScan's exposure path probe: Stable Diffusion WebUI leaks its own UI password - CVE-2026-82288 2026-08-29
CVE-2026-82246 Budibase critical Covered by the Budibase batch fix for CVE-2026-82244 2026-08-28
CVE-2026-82245 Budibase critical Covered by the Budibase batch fix for CVE-2026-82244 2026-08-28
CVE-2026-82244 Budibase critical Budibase before 3.41.3: remote code execution via plugin upload (CVE-2026-82244), plus datasource-query authorization bypass, builder-role escalation, cross-app resource injection,… 2026-08-28
CVE-2026-82243 Budibase critical Covered by the Budibase batch fix for CVE-2026-82244 2026-08-28
CVE-2026-82242 Budibase critical Covered by the Budibase batch fix for CVE-2026-82244 2026-08-28
CVE-2026-82240 Budibase critical Covered by the Budibase batch fix for CVE-2026-82244 2026-08-28
CVE-2026-82239 Budibase critical Covered by the Budibase batch fix for CVE-2026-82244 2026-08-28
CVE-2023-49105 ownCloud critical ownCloud before 10.13.1: WebDAV API authentication bypass reads, writes and deletes any user's files (CISA KEV) 2026-08-28
CVE-2023-49103 ownCloud critical Covered by the ownCloud batch fix for CVE-2023-49105 2026-08-28
CVE-2026-82241 Budibase high Budibase 3.33.4 before 3.41.3: the default SSRF blacklist omits the shared address space 100.64.0.0/10 2026-08-28
CVE-2026-82237 FileBrowser high Covered by the FileBrowser batch fix for CVE-2026-82235 2026-08-28
CVE-2026-82235 FileBrowser high FileBrowser through 2.63.23: a named pipe in a shared directory blocks the archive and public-download handlers, and renaming a shared file leaves its share link live - NO FIX WILL… 2026-08-28
CVE-2026-82238 FileBrowser low FileBrowser 2.24.0 through 2.63.23: concurrent TUS PATCH uploads race past the declared Upload-Length - NO FIX WILL SHIP 2026-08-28
CVE-2026-60004 Gitea critical Gitea diffpatch API remote code execution via Git hook installation (CVSS 9.8, CISA KEV) 2026-08-27
CVE-2026-8452 Citrix NetScaler ADC/Gateway high NetScaler ADC/Gateway memory-overflow denial of service when configured as a Gateway (CVSS 8.8) 2026-08-27
CVE-2021-23758 AjaxPro high Reported by NewScan's exposure path probe: AjaxPro handler exposed - .NET deserialization RCE (CVE-2021-23758) 2026-08-27
CVE-2026-79782 rclone critical rclone S3 backend leaks the X-Amz-Security-Token over plaintext HTTP on an HTTPS->HTTP redirect 2026-08-26
CVE-2026-79781 rclone medium rclone serve s3 path traversal via dot-dot object keys - read and overwrite root-level files 2026-08-26
CVE-2026-79780 rclone medium rclone before 1.75.0: credential exposure on redirect, WebDAV TUS DoS panic, and RC API stack-trace disclosure 2026-08-26
CVE-2026-79779 rclone medium Covered by the rclone batch fix for CVE-2026-79780 2026-08-26
CVE-2026-79778 rclone medium Covered by the rclone batch fix for CVE-2026-79780 2026-08-26
CVE-2026-79777 rclone medium Covered by the rclone batch fix for CVE-2026-79780 2026-08-26
CVE-2026-79776 rclone medium Covered by the rclone batch fix for CVE-2026-79780 2026-08-26
CVE-2026-78678 GitPython critical Covered by the GitPython batch fix for CVE-2026-78676 2026-08-25
CVE-2026-78677 GitPython critical Covered by the GitPython batch fix for CVE-2026-78676 2026-08-25
CVE-2026-78676 GitPython critical GitPython git-config injection reaching core.hooksPath -> code execution, plus clone and blame option-denylist gaps (the 3.1.59 fix train) 2026-08-25
CVE-2026-56706 Adminer critical Covered by the Adminer batch fix for CVE-2026-56705 2026-08-25
CVE-2026-56705 Adminer critical Adminer unauthenticated PDO/ODBC DSN injection from the login form -> code execution (heads a 7-CVE batch all fixed in 5.4.3) 2026-08-25
CVE-2026-56704 Adminer critical Covered by the Adminer batch fix for CVE-2026-56705 2026-08-25
CVE-2026-56703 Adminer critical Covered by the Adminer batch fix for CVE-2026-56705 2026-08-25
CVE-2026-56702 Adminer critical Covered by the Adminer batch fix for CVE-2026-56705 2026-08-25
CVE-2026-40877 iTop critical Covered by the iTop batch fix for CVE-2026-34741 2026-08-25
CVE-2026-39975 iTop critical Covered by the iTop batch fix for CVE-2026-34741 2026-08-25
CVE-2026-34968 Adminer critical Covered by the Adminer batch fix for CVE-2026-56705 2026-08-25
CVE-2026-34967 Adminer critical Covered by the Adminer batch fix for CVE-2026-56705 2026-08-25
CVE-2026-30864 iTop critical Covered by the iTop batch fix for CVE-2026-34741 2026-08-25
CVE-2026-21962 Oracle WebLogic Server critical WebLogic Server Proxy Plug-in for Apache HTTP Server: unauthenticated remote access to critical data (CVSS 10.0, exploited in the wild) 2026-08-25
CVE-2026-16434 Adminer critical Covered by the Adminer batch fix for CVE-2026-56705 2026-08-25
CVE-2026-34964 Adminer medium Adminer SSRF and open redirect via the login-form server field and X-Forwarded-Prefix (the 5.5.0 fix train) 2026-08-25
CVE-2026-34959 Adminer medium Covered by the Adminer batch fix for CVE-2026-34964 2026-08-25
CVE-2026-78207 exceljs-hardened critical exceljs-hardened prototype pollution and unbounded XLSX decompression 2026-08-24
CVE-2026-78206 exceljs-hardened critical Covered by the exceljs-hardened batch fix for CVE-2026-78207 2026-08-24
CVE-2026-8445 justhtml critical justhtml Markdown text-node escaping cross-site scripting 2026-08-23
CVE-2026-7808 justhtml critical justhtml HTML sanitization bypass permits dangerous active content 2026-08-23
CVE-2026-76217 GitPython critical Covered by the GitPython batch fix for CVE-2026-78676 2026-08-23
CVE-2026-73080 SeaweedFS critical SeaweedFS unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle 2026-08-23
CVE-2026-5388 justhtml critical justhtml URL sanitization and HTML serialization bypasses 2026-08-23
CVE-2026-73624 GitPython high Covered by the GitPython batch fix for CVE-2026-73620 2026-08-23
CVE-2026-73620 GitPython high GitPython argument injection via unguarded git option forwarding (IndexFile.checkout / TagReference.create) 2026-08-23
CVE-2026-73619 GitPython high Covered by the GitPython batch fix for CVE-2026-73620 2026-08-23
CVE-2026-73246 kestra high Reported by NewScan's unauthenticated interface: Unauthenticated Kestra /worker endpoint exposes live task state and configuration 2026-08-23
CVE-2026-71324 Traefik high Traefik cross-user response poisoning via proxied CONNECT (HTTP/2/3 CONNECT smuggled into the backend keep-alive pool) 2026-08-23
CVE-2026-4671 justhtml high justhtml CSS selector and linkification denial of service 2026-08-23
CVE-2026-19351 sql-query high node-sql-query SelectQuery SQL injection (Select.js from/build parameter manipulation) 2026-08-23
CVE-2026-17601 Nexus Repository high Nexus Repository 3 wildcard-privilege self-escalation to administrator 2026-08-23
CVE-2026-73245 kestra medium Reported by NewScan's unauthenticated interface: Unauthenticated Kestra management endpoint (Micronaut actuator) 2026-08-23
CVE-2026-77806 SPIP critical SPIP unauthenticated remote code execution via an X-Spip-Filtre request header (exploited in the wild) 2026-08-22
CVE-2026-73570 Zimbra Collaboration critical Zimbra Collaboration SNMP notification command injection -> remote code execution (CVSS 8.9, CISA KEV) 2026-08-22
CVE-2026-34949 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-34948 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-34836 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-34741 iTop critical Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE batch all fixed in 3.2.3) 2026-08-22
CVE-2026-33240 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-33047 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-31936 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-31880 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-31803 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-30890 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-30866 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-30865 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-30826 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-30819 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-27490 iTop critical Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… 2026-08-22
CVE-2026-27463 iTop critical Covered by the iTop batch fix for CVE-2026-34741 2026-08-22
CVE-2026-48050 Go pprof high Reported by NewScan's exposure path probe: Exposed Go pprof debug endpoints 2026-08-22
CVE-2026-77647 SPIP critical SPIP unauthenticated remote code execution via incorrect identification of PHP open tags (exploited in the wild) 2026-08-21
CVE-2026-72530 TrueConf Server critical Pre-auth server-side template injection over TrueConf's client port 4307/TCP -> code execution on the conferencing server (CVSS 9.5) 2026-08-21
CVE-2026-72529 TrueConf Server critical Pre-auth account takeover over TrueConf's client port 4307/TCP -> arbitrary command execution as a server account (CVSS 9.3) 2026-08-21
CVE-2026-67448 Mailpit high Mailpit origin middleware checks the raw RequestURI for the /api/ prefix, so a re-spelled path reaches the whole mailbox API without the browser-origin gate 2026-08-21
CVE-2026-67447 Mailpit high Covered by the Mailpit batch fix for CVE-2026-67448 2026-08-21
CVE-2026-67446 Mailpit high Covered by the Mailpit batch fix for CVE-2026-67448 2026-08-21
CVE-2026-67445 Mailpit high Covered by the Mailpit batch fix for CVE-2026-67448 2026-08-21
CVE-2026-77082 n8n critical Covered by the n8n batch fix for CVE-2026-77068 2026-08-20
CVE-2026-77080 n8n critical Covered by the n8n batch fix for CVE-2026-77068 2026-08-20
CVE-2026-77075 n8n critical Covered by the n8n batch fix for CVE-2026-77068 2026-08-20
CVE-2026-77072 n8n critical Covered by the n8n batch fix for CVE-2026-77068 2026-08-20
CVE-2026-77068 n8n critical n8n 1.x August 2026 batch: node-schema loader path traversal -> RCE, Snowflake node arbitrary file read/write, resource-locator expression injection, Form-node stored XSS and Filte… 2026-08-20
CVE-2026-55089 Etherpad critical Etherpad OAuth authorization_code path authorizes /api/2/* requests without a valid API key 2026-08-20
CVE-2026-32475 elementor-pro critical Elementor Pro unauthenticated arbitrary file upload -> RCE via the Forms widget file-upload field 2026-08-20
CVE-2026-55085 Etherpad high Etherpad stored XSS via a numbered-list start attribute interpolated into unquoted HTML 2026-08-20
CVE-2026-59310 VMware vCenter Server critical vCenter Syslog server directory traversal -> arbitrary code execution (CVSS 9.8) 2026-08-19
CVE-2026-55040 Microsoft SharePoint Server critical SharePoint Server JWT authentication bypass - an unsigned (alg:none) Bearer token authenticates an anonymous caller on /_api/* (CVSS 9.1) 2026-08-19
CVE-2025-55315 Kestrel critical Kestrel HTTP request smuggling security-feature bypass 2026-08-19
CVE-2024-35264 Kestrel critical Kestrel HTTP/3 data corruption remote code execution 2026-08-19
CVE-2023-44487 Kestrel high Kestrel HTTP/2 Rapid Reset denial of service 2026-08-19
CVE-2023-38180 Kestrel high Kestrel fails to disconnect some malicious clients, enabling denial of service 2026-08-19
CVE-2026-64849 MLflow critical MLflow webhook-test SSRF via redirect re-validation bypass 2026-08-18
CVE-2025-62593 Ray critical Ray Jobs API driven from a victim browser (User-Agent-gated dashboard, KEV) 2026-08-18
CVE-2026-68520 Glances high Reported by NewScan's exposure path probe: Glances config API leaking export credentials 2026-08-18
CVE-2026-74842 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-17
CVE-2026-74799 Go pprof high Reported by NewScan's exposure path probe: Exposed Go pprof debug endpoints 2026-08-17
CVE-2026-19984 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-17
CVE-2026-19964 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-17
CVE-2026-19958 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-17
CVE-2026-19957 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-17
CVE-2026-19956 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-17
CVE-2026-14832 shopsmart-loyalty-for-woocommerce high ShopSmart Loyalty for WooCommerce unauthenticated customer-record disclosure - shopsmart_check_phone returns a loyalty profile to anyone who supplies a phone number, with no owners… 2026-08-17
CVE-2026-13700 wooms high WooMS unauthenticated SSRF in the data-sync feature - the plugin attaches its stored third-party integration credentials to a request aimed at an attacker-supplied URL, so the cred… 2026-08-17
CVE-2026-19474 @fastify/multipart high @fastify/multipart 3.0.0-10.1.0: aborted multipart uploads leak temporary files (and, from 5.3.0, hang the request handler), letting an unauthenticated client exhaust disk 2026-08-16
CVE-2026-18549 @fastify/multipart high Covered by the @fastify/multipart batch fix for CVE-2026-19474 2026-08-16
CVE-2026-18500 @fastify/jwt high @fastify/jwt before 10.2.2: a per-request verification key is silently overridden by the global secret, so a token signed with the global secret passes a check that demanded a diff… 2026-08-16
CVE-2026-19898 vmauth medium vmauth authentication-endpoint brute force (requestHandler) 2026-08-16
CVE-2026-18165 @fastify/oauth2 medium @fastify/oauth2 7.2.0-8.2.0: OAuth state and PKCE verifier live in unprefixed cookies, so anyone who can write a cookie on a related host can log a victim into the ATTACKER's accou… 2026-08-16
CVE-2026-50027 mcp-memory-service critical Reported by NewScan's unauthenticated interface: Unauthenticated mcp-memory-service document/memory API 2026-08-15
CVE-2026-49989 CrateDB high CrateDB blob HTTP handler authorization bypass - any authenticated user reads, deletes or plants blobs by SHA-1 digest 2026-08-15
CVE-2026-73302 Budibase critical Budibase before 3.39.30: OIDC login accepts an unverified email, allowing account takeover by email collision 2026-08-14
CVE-2026-72857 Budibase critical Covered by the Budibase batch fix for CVE-2026-72851 2026-08-14
CVE-2026-72856 Budibase critical Covered by the Budibase batch fix for CVE-2026-72851 2026-08-14
CVE-2026-72855 Budibase critical Covered by the Budibase batch fix for CVE-2026-72851 2026-08-14
CVE-2026-72853 Budibase critical Covered by the Budibase batch fix for CVE-2026-72851 2026-08-14
CVE-2026-72851 Budibase critical Budibase before 3.40.0: unauthenticated SQL injection via webhook automations (CVE-2026-72851), plus arbitrary file write, tenant-owner auth bypass, Oracle-connector SQLi, SSRF, cr… 2026-08-14
CVE-2026-72850 Budibase critical Covered by the Budibase batch fix for CVE-2026-72851 2026-08-14
CVE-2026-72849 Budibase critical Covered by the Budibase batch fix for CVE-2026-72851 2026-08-14
CVE-2026-72836 FileBrowser critical FileBrowser before 2.63.19: self-registration home-directory takeover on case-insensitive filesystems 2026-08-14
CVE-2026-73500 etcd high etcd 3.5.x before 3.5.33: remote denial of service on the TLS listener (CVE-2026-73500), plus CVE-2026-73499 2026-08-14
CVE-2026-73499 etcd high Covered by the etcd batch fix for CVE-2026-73500 2026-08-14
CVE-2026-73408 Budibase high Budibase before 3.39.18: MySQL connector enables multipleStatements and interpolates an unescaped table name into DESCRIBE 2026-08-14
CVE-2026-73305 Budibase high Budibase before 3.39.24: POST /api/public/v1/roles/assign skips the app-scope check, allowing cross-app privilege escalation 2026-08-14
CVE-2026-72859 Budibase high Budibase 3.39.4 before 3.40.0: authorization regression hands BASIC users S3 PutObject presigned URLs 2026-08-14
CVE-2026-73604 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73603 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73602 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73601 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73488 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73487 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73486 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73485 Flowise critical Covered by the Flowise batch fix for CVE-2026-73483 2026-08-13
CVE-2026-73483 Flowise critical Flowise before 3.1.4: sandbox escapes and agent-node code injection - remote code execution on the Flowise host, unauthenticated in two of them 2026-08-13
CVE-2026-72794 SiYuan critical Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API 2026-08-13
CVE-2026-72793 SiYuan critical Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API 2026-08-13
CVE-2026-47717 FUXA high Reported by NewScan's unauthenticated interface: Unauthenticated FUXA SCADA/HMI project 2026-08-13
CVE-2026-73211 PeerTube critical PeerTube unauthenticated SQL injection from a federated peer, plus cross-origin video takeover 2026-08-12
CVE-2026-73090 PeerTube critical PeerTube cross-origin video takeover via a federated Update activity 2026-08-12
CVE-2026-20349 Cisco ASA/FTD WebVPN high Cisco ASA/FTD Remote Access SSL VPN unauthenticated reload - a single crafted HTTP request takes the VPN down (CVSS 8.6, KEV 2026-08-12) 2026-08-12
CVE-2026-72899 Metabase critical Covered by the Metabase batch fix for CVE-2026-72898 2026-08-11
CVE-2026-72898 Metabase critical Metabase unauthenticated SQL injection to administrator (/api/session/reset_password, and public-link field filters) 2026-08-11
CVE-2023-38646 Metabase critical Metabase pre-authentication remote code execution via a public setup token 2026-08-11
CVE-2026-69086 SiYuan critical Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API 2026-08-10
CVE-2026-69083 SiYuan critical Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API 2026-08-10
CVE-2026-68586 SiYuan critical Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API 2026-08-10
CVE-2026-68585 SiYuan critical Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API 2026-08-10
CVE-2026-68584 SiYuan critical Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API 2026-08-10
CVE-2026-21858 n8n critical n8n Form Webhook Content-Type confusion allows unauthenticated arbitrary file read ("Ni8mare") 2026-08-10
CVE-2025-68613 n8n critical n8n expression sandbox escape allows authenticated remote code execution 2026-08-10
CVE-2019-9193 PostgreSQL high Covered by the PostgreSQL batch fix for CVE-2018-1058 2026-08-10
CVE-2018-1058 PostgreSQL high PostgreSQL search_path privilege escalation: an unprivileged user can create objects that a superuser then executes 2026-08-10
CVE-2026-12971 learnpress medium LearnPress SSRF: the instructor-role AI image-import feature fetches an arbitrary attacker-supplied URL server-side 2026-08-10
CVE-2026-67620 REST APIs high Reported by NewScan's named-CVE check: test_ssrf 2026-08-09
CVE-2026-10595 Web apps high Reported by NewScan's named-CVE check: test_url_path_traversal 2026-08-09
CVE-2026-8037 Progress Kemp LoadMaster critical Pre-auth OS command injection in the LoadMaster API (/accessv2) -> arbitrary command execution on the appliance (CVSS 9.6) 2026-08-08
CVE-2026-61808 lightrag critical Reported by NewScan's unauthenticated interface: Unauthenticated LightRAG API server (authentication disabled) 2026-08-08
CVE-2026-64638 WordPress high XSS2Shell: WordPress core pre-auth reflected XSS on wp-login.php via a strip_tags()/KSES parser differential 2026-08-08
CVE-2026-14812 Premium-SEO critical Premium-SEO is a malicious WordPress plugin, not a compromised one: every build ships an unauthenticated backdoor that creates a hidden administrator account (login prefix resource… 2026-08-07
CVE-2026-11976 google-analytics-premium critical MonsterInsights Pro 10.2.0 shipped from a compromised update bucket: backdoored class-system-check.php hijacks the MonsterInsights/ExactMetrics update channel to an attacker server… 2026-08-07
CVE-2026-9205 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-9196 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-9130 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-9081 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-8478 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-8470 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-8446 Langflow critical Covered by the Langflow batch fix for CVE-2026-8182 2026-08-06
CVE-2026-8183 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-8182 Langflow critical Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixed in the same range 2026-08-06
CVE-2026-7869 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-7658 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-7657 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-7646 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-68746 livebook critical Reported by NewScan's unauthenticated interface: Unauthenticated Livebook notebook server 2026-08-06
CVE-2026-56164 Microsoft SharePoint Server critical SharePoint Server on-premises remote code execution - actively exploited July 2026, chained for IIS machine-key theft 2026-08-06
CVE-2026-45659 Microsoft SharePoint Server critical SharePoint Server on-premises remote code execution - actively exploited July 2026 2026-08-06
CVE-2026-41940 cPanel / WHM critical cPanel / WHM authentication bypass - unauthenticated administrative control of the hosting server, all supported versions 2026-08-06
CVE-2026-35616 FortiClient EMS critical FortiClient EMS improper access control - unauthenticated code/command execution via crafted requests 2026-08-06
CVE-2026-32201 Microsoft SharePoint Server critical SharePoint Server spoofing via improper input validation - a manipulated Referer plus a malformed query string bypasses the front-end authorization check 2026-08-06
CVE-2026-21643 FortiClient EMS critical FortiClient EMS 7.4.4 pre-authentication SQL injection in the management server 2026-08-06
CVE-2026-18577 N-able N-central critical N-able N-central authentication bypass - unauthenticated administrative control of the RMM server, and therefore of every endpoint it manages 2026-08-06
CVE-2026-17633 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-17632 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-17630 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-17625 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-17624 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-17623 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-16232 Check Point Security Gateway critical Check Point SmartConsole/management authentication bypass - exploited in the wild 2026-08-06
CVE-2026-10547 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2026-10128 Langflow critical Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… 2026-08-06
CVE-2025-64446 FortiWeb critical FortiWeb path traversal + authentication bypass - crafted HTTP(S) runs administrative commands and creates admin accounts on the WAF itself 2026-08-06
CVE-2025-61882 Oracle E-Business Suite critical Oracle E-Business Suite pre-auth RCE in the internet-facing web tier - the Cl0p mass-extortion campaign (CVSS 9.8) 2026-08-06
CVE-2025-59287 Microsoft WSUS critical Windows Server Update Services unauthenticated deserialization -> RCE as SYSTEM (CVSS 9.8) 2026-08-06
CVE-2025-5777 Citrix NetScaler ADC/Gateway critical CitrixBleed 2: out-of-bounds memory disclosure on the login endpoint leaks session tokens, replayed to hijack sessions and bypass MFA (CVSS 9.3) 2026-08-06
CVE-2025-49844 Redis critical RediShell: Lua use-after-free reachable from a crafted EVAL script -> remote code execution (CVSS 10.0) 2026-08-06
CVE-2025-20333 Cisco ASA/FTD WebVPN critical Cisco ASA/FTD VPN web server buffer overflow - unauthenticated root RCE (ArcaneDoor-class; CISA ED 25-03) 2026-08-06
CVE-2025-10035 GoAnywhere MFT critical GoAnywhere MFT License Servlet deserialization -> command injection, unauthenticated with a forged license-response signature (CVSS 10.0) 2026-08-06
CVE-2026-49331 HTTP high Reported by NewScan's named-CVE check: test_header_trust 2026-08-06
CVE-2026-42586 Redis high Reported by NewScan's named-CVE check: test_redis_injection 2026-08-06
CVE-2026-25589 RedisBloom high Invalid memory access in RESTORE when used with the RedisBloom module -> potential remote code execution 2026-08-06
CVE-2026-25588 RedisTimeSeries high Invalid memory access in RESTORE when used with the RedisTimeSeries module -> potential remote code execution 2026-08-06
CVE-2026-25243 Redis high Invalid memory access in the RESTORE command from a crafted serialized payload -> remote code execution 2026-08-06
CVE-2026-23479 Redis high Use-after-free in the unblock-client flow -> remote code execution 2026-08-06
CVE-2026-0257 PaloAlto GlobalProtect high PAN-OS GlobalProtect authentication bypass - an attacker establishes VPN connections without valid credentials 2026-08-06
CVE-2025-32023 Redis high Hyperloglog out-of-bounds write from a crafted hyperloglog value -> remote code execution 2026-08-06
CVE-2025-20362 Cisco ASA/FTD WebVPN high Cisco ASA/FTD WebVPN unauthorized access to restricted URL endpoints - chained with CVE-2025-20333 for pre-auth RCE 2026-08-06
CVE-2024-55656 RedisBloom high RedisBloom integer overflow via CMS.INITBYDIM with large WIDTH/DEPTH -> heap overflow, potential remote code execution 2026-08-06
CVE-2024-51737 RediSearch high RediSearch integer overflow via crafted FT.SEARCH/FT.AGGREGATE LIMIT or KNN arguments -> heap overflow, potential remote code execution 2026-08-06
CVE-2024-51480 RedisTimeSeries high RedisTimeSeries integer overflow via crafted TS.QUERYINDEX/TS.MGET/TS.MRANGE/TS.MREVRANGE arguments -> heap overflow, potential remote code execution 2026-08-06
CVE-2024-46981 Redis high Lua use-after-free (garbage-collector manipulation) -> remote code execution 2026-08-06
CVE-2024-31449 Redis high Lua library stack overflow via a crafted EVAL script -> remote code execution as the Redis process 2026-08-06
CVE-2026-23631 Redis medium Lua use-after-free via master-replica synchronization -> remote code execution 2026-08-06
CVE-2026-70494 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70493 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70492 Open WebUI high Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in the web loader and vega renderer, cross-tenant re… 2026-08-05
CVE-2026-70491 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70490 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70489 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70488 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70487 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70486 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70485 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70484 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70483 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70482 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70481 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70480 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-70479 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-54020 Open WebUI high Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… 2026-08-05
CVE-2026-67200 Rocket.Chat critical Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read 2026-08-04
CVE-2026-56845 Rocket.Chat critical Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read 2026-08-04
CVE-2021-43798 Rocket.Chat critical Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read 2026-08-04
CVE-2026-69243 aiohttp medium aiohttp HTTP parser request smuggling (WebSocket upgrade handling) 2026-08-04
CVE-2026-8763 Bouncy Castle critical Bouncy Castle for Java certificate/signature verification bypasses (X.509 name-constraint bypass, CMS zero-signer accept, RSA PKCS#1 hash truncation) plus unbounded-KDF DoS 2026-08-03
CVE-2026-59652 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-59648 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-59647 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-59643 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-59640 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-59639 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-58063 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-15055 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-13586 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2026-12860 Bouncy Castle critical Covered by the Bouncy Castle batch fix for CVE-2026-8763 2026-08-03
CVE-2024-45519 Zimbra Collaboration critical Zimbra postjournal service command injection - unauthenticated RCE via crafted SMTP message 2026-08-02
CVE-2024-40766 SonicWall SMA/SSL-VPN critical SonicOS management access-control flaw - unauthorized resource access / firewall crash 2026-08-02
CVE-2024-4040 CrushFTP critical CrushFTP VFS sandbox escape via server-side template injection - unauthenticated file read / RCE 2026-08-02
CVE-2024-38475 Apache httpd critical Apache mod_rewrite improper substitution escaping - source disclosure and code execution via crafted URLs 2026-08-02
CVE-2024-36401 GeoServer critical GeoServer unauthenticated RCE - OGC request property names evaluated as XPath expressions 2026-08-02
CVE-2024-23897 Jenkins critical Jenkins CLI arbitrary file read via expandAtFiles - reads secrets, then full takeover 2026-08-02
CVE-2024-1709 ConnectWise ScreenConnect critical ScreenConnect SetupWizard authentication bypass - create an administrator, then RCE 2026-08-02
CVE-2023-50164 Apache Struts critical Struts file-upload path traversal -> upload a webshell (RCE) 2026-08-02
CVE-2023-35078 Ivanti EPMM / MobileIron Core critical Ivanti EPMM unauthenticated API access - read/modify enrolled-device and user data 2026-08-02
CVE-2023-29300 Adobe ColdFusion critical ColdFusion WDDX deserialization - unauthenticated remote code execution 2026-08-02
CVE-2023-26360 Adobe ColdFusion critical ColdFusion improper access control / deserialization - unauthenticated arbitrary file read and RCE 2026-08-02
CVE-2023-25690 Apache httpd critical Apache mod_proxy HTTP request smuggling via a RewriteRule/ProxyPassMatch substitution 2026-08-02
CVE-2023-22518 Atlassian Confluence critical Confluence improper authorization - unauthenticated restore/takeover of the instance 2026-08-02
CVE-2023-22515 Atlassian Confluence critical Confluence broken access control - unauthenticated administrator account creation 2026-08-02
CVE-2023-20198 Cisco IOS XE Web UI critical IOS XE web UI privilege escalation - unauthenticated admin account creation (mass implant campaign) 2026-08-02
CVE-2022-37042 Zimbra Collaboration critical Covered by the Zimbra Collaboration batch fix for CVE-2022-27925 2026-08-02
CVE-2022-28346 Django critical Django SQL injection via crafted dictionary expansion in QuerySet.annotate()/aggregate() 2026-08-02
CVE-2022-27925 Zimbra Collaboration critical Zimbra mboximport archive extraction path traversal -> RCE (chained with CVE-2022-37042 auth bypass) 2026-08-02
CVE-2022-26134 Atlassian Confluence critical Confluence OGNL injection - unauthenticated remote code execution 2026-08-02
CVE-2022-1040 Sophos Firewall critical Sophos Firewall User Portal/Webadmin authentication bypass -> RCE 2026-08-02
CVE-2021-45046 Log4j critical Log4j Thread Context lookup bypass of the 2.15.0 fix - RCE in some configurations 2026-08-02
CVE-2021-41773 Apache httpd critical Apache path traversal outside the document root (cgi-bin -> RCE) 2026-08-02
CVE-2021-40539 ManageEngine ADSelfService Plus critical ADSelfService Plus REST API authentication bypass -> remote code execution 2026-08-02
CVE-2021-22005 VMware vCenter Server critical vCenter Analytics service arbitrary file upload -> RCE 2026-08-02
CVE-2021-21972 VMware vCenter Server critical vCenter vRealize Operations plugin unauthenticated file upload -> RCE 2026-08-02
CVE-2021-20016 SonicWall SMA/SSL-VPN critical SonicWall SMA100 SQL injection - unauthenticated credential/session access 2026-08-02
CVE-2020-14882 Oracle WebLogic Server critical WebLogic administration console path-traversal authentication bypass -> RCE 2026-08-02
CVE-2020-12271 Sophos Firewall critical Sophos XG SQL injection -> remote code execution (Asnarok) 2026-08-02
CVE-2019-7609 Kibana critical Kibana Timelion prototype pollution -> arbitrary code execution as the Kibana process 2026-08-02
CVE-2019-6340 Drupal critical Drupal RESTful Web Services unsafe deserialization -> remote code execution 2026-08-02
CVE-2018-7600 Drupal critical Drupalgeddon2 - unauthenticated remote code execution via Form API render arrays 2026-08-02
CVE-2018-12613 phpMyAdmin critical phpMyAdmin file inclusion via the index.php target parameter -> code execution 2026-08-02
CVE-2017-5638 Apache Struts critical Struts Jakarta multipart parser OGNL injection - unauthenticated RCE via the Content-Type header (Equifax) 2026-08-02
CVE-2017-10271 Oracle WebLogic Server critical WebLogic WLS-WSAT XML deserialization - unauthenticated RCE 2026-08-02
CVE-2014-0160 OpenSSL critical Heartbleed - TLS heartbeat over-read leaks up to 64KB of process memory (keys, sessions, credentials) 2026-08-02
CVE-2026-68578 Model Context Protocol high Reported by NewScan's named-CVE check: scan_mcp 2026-08-02
CVE-2024-38816 Spring Framework high Spring path traversal - functional web resource handlers serve files outside the configured location 2026-08-02
CVE-2024-29041 Express high Express open redirect - res.location()/res.redirect() accept a malformed URL that browsers follow off-site 2026-08-02
CVE-2024-24919 Check Point Security Gateway high Check Point Remote Access VPN arbitrary file read (password hashes, certificates) 2026-08-02
CVE-2024-1708 ConnectWise ScreenConnect high ScreenConnect path traversal - write outside the extension sandbox 2026-08-02
CVE-2024-1135 Gunicorn high Gunicorn HTTP request smuggling - improper Transfer-Encoding validation desyncs it from the front-end proxy 2026-08-02
CVE-2023-38408 OpenSSH high OpenSSH ssh-agent PKCS#11 provider remote code execution (agent forwarding to a hostile host) 2026-08-02
CVE-2023-35081 Ivanti EPMM / MobileIron Core high Ivanti EPMM administrator path traversal - arbitrary file write (chained with CVE-2023-35078) 2026-08-02
CVE-2023-30861 Flask high Flask session cookie can be cached by a proxy and served to another client (session disclosure) 2026-08-02
CVE-2023-23752 Joomla high Joomla improper access check on the web-service endpoints - unauthenticated config/credential disclosure 2026-08-02
CVE-2023-20273 Cisco IOS XE Web UI high IOS XE web UI command injection - root after the CVE-2023-20198 account creation 2026-08-02
CVE-2022-3602 OpenSSL high OpenSSL X.509 email-address punycode buffer overflow (4-byte stack overwrite) 2026-08-02
CVE-2022-24999 Express high qs prototype pollution via bracketed query keys -> denial of service 2026-08-02
CVE-2021-35042 Django high Django SQL injection through QuerySet.order_by() with an unvalidated column name 2026-08-02
CVE-2024-37032 ollama medium Reported by NewScan's unauthenticated interface: Unauthenticated Ollama model API 2026-08-02
CVE-2021-44832 Log4j medium Log4j JDBC Appender remote code execution when an attacker controls the logging configuration 2026-08-02
CVE-2016-2107 OpenSSL medium OpenSSL AES-NI CBC MAC-check padding oracle (Lucky-13 variant) - plaintext recovery 2026-08-02
CVE-2026-68771 comfyui critical Reported by NewScan's unauthenticated interface: Unauthenticated ComfyUI interface 2026-08-01
CVE-2026-3141 formgent critical FormGent unauthenticated arbitrary file deletion via REST API (wp-config.php -> site takeover) 2026-08-01
CVE-2026-14919 shopmonitor critical ShopMonitor.io authentication bypass via email redirection -> unauthenticated administrator account takeover 2026-08-01
CVE-2026-6540 HTTP routing high Reported by NewScan's named-CVE check: test_path_acl_bypass 2026-08-01
CVE-2026-53501 Thumbor high Reported by NewScan's named-CVE check: test_media_proxy_ssrf 2026-08-01
CVE-2026-53500 Thumbor high Reported by NewScan's named-CVE check: test_media_proxy_ssrf 2026-08-01
CVE-2026-17566 pgadmin high Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable 2026-08-01
CVE-2026-17349 pgadmin high Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable 2026-08-01
CVE-2026-17347 pgadmin high Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable 2026-08-01
CVE-2026-16144 kali-forms high Kali Forms remote code execution via improper code-generation control 2026-08-01
CVE-2026-15988 ai-engine high AI Engine cross-site request forgery -> actions as an authenticated user 2026-08-01
CVE-2026-15450 nex-forms high NEX-Forms authenticated path traversal -> arbitrary file deletion 2026-08-01
CVE-2026-15414 subscriptions-for-woocommerce high Subscriptions for WooCommerce authenticated privilege escalation 2026-08-01
CVE-2026-15258 webappick-product-feed-for-woocommerce high Product Feed Manager for WooCommerce authenticated SQL injection 2026-08-01
CVE-2026-13609 acf-frontend-form-element high Frontend Admin unauthenticated stored cross-site scripting 2026-08-01
CVE-2026-12721 kirki high Kirki Customizer Framework SQL injection 2026-08-01
CVE-2026-12695 miniorange-2-factor-authentication high miniOrange 2FA authentication bypass (unauthenticated MFA circumvention) 2026-08-01
CVE-2026-12251 ultimate-member high Ultimate Member improper privilege management -> unauthorized access / permission elevation 2026-08-01
CVE-2021-3129 Laravel Ignition critical Reported by NewScan's exposure path probe: Exposed Laravel Ignition debug handler 2026-07-31
CVE-2026-44578 Next.js high Next.js May 2026 coordinated security release (13 advisories): SSRF via the middleware/proxy request path, plus middleware and proxy bypass CVE-2026-44573, cache poisoning on middl… 2026-07-30
CVE-2026-44577 Next.js high Covered by the Next.js batch fix for CVE-2026-44578 2026-07-30
CVE-2026-44573 Next.js high Covered by the Next.js batch fix for CVE-2026-44578 2026-07-30
CVE-2026-44572 Next.js high Covered by the Next.js batch fix for CVE-2026-44578 2026-07-30
CVE-2022-31129 moment high moment regular-expression denial of service parsing a long attacker-supplied date string 2026-07-30
CVE-2021-23337 lodash high lodash command injection via _.template's variable option 2026-07-30
CVE-2020-8203 lodash high lodash prototype pollution in zipObjectDeep/set/setWith 2026-07-30
CVE-2024-21490 Angular medium AngularJS regular-expression denial of service via ng-srcset with untrusted input 2026-07-30
CVE-2023-45857 axios medium axios leaks the XSRF-TOKEN cookie value to a third-party host in the Authorization-style header 2026-07-30
CVE-2019-11358 jQuery medium jQuery prototype pollution via $.extend(true, {}, attackerJSON) 2026-07-30
CVE-2018-14042 Bootstrap medium Bootstrap XSS in data-container of the tooltip/popover plugin 2026-07-30
CVE-2026-18072 advanced-responsive-video-embedder critical ARVE hardcoded-backdoor authentication bypass -> admin takeover (malicious release) 2026-07-29
CVE-2026-14512 IBM WebSphere Application Server critical WebSphere pre-authentication unsafe deserialization -> auth bypass / RCE 2026-07-29
CVE-2026-14446 IBM WebSphere Application Server critical WebSphere admin-console broken access control -> privilege escalation 2026-07-29
CVE-2026-13423 streamit critical Streamit theme unauthenticated AJAX arbitrary-function call -> privilege escalation / RCE 2026-07-29
CVE-2026-16498 Model Context Protocol high Reported by NewScan's named-CVE check: test_mcp_session_isolation 2026-07-29
CVE-2026-16723 Fastjson high Reported by NewScan's named-CVE check: test_fastjson_rce 2026-07-27
CVE-2025-3248 Langflow critical Langflow before 1.3.0: unauthenticated remote code execution via POST /api/v1/validate/code 2026-07-23
CVE-2026-0770 Langflow high Reported by NewScan's named-CVE check: test_langflow_rce 2026-07-23
CVE-2026-42533 nginx critical nginx script-engine capture/map heap overflow (DoS; RCE where ASLR bypassable) 2026-07-21
CVE-2025-55752 Apache Tomcat critical Tomcat rewrite dir-traversal -> RCE 2026-07-21
CVE-2025-29927 Next.js critical Next.js middleware authorization bypass - the internal x-middleware-subrequest header skips middleware entirely 2026-07-21
CVE-2024-34351 Next.js high Next.js Server Actions SSRF - a crafted Host header makes the server fetch an attacker-chosen origin 2026-07-21
CVE-2026-63030 WordPress critical WP2Shell: REST API batch-route confusion -> SQLi (CVE-2026-60137) -> unauthenticated RCE 2026-07-19
CVE-2026-60137 WordPress critical Covered by the WordPress batch fix for CVE-2026-63030 2026-07-19
CVE-2021-44228 Log4j critical Log4Shell - JNDI lookup in a logged string gives unauthenticated remote code execution 2026-07-17
CVE-2022-42889 Apache Commons Text high Reported by NewScan's named-CVE check: test_text4shell 2026-07-17
CVE-2024-3400 PaloAlto GlobalProtect critical PAN-OS GlobalProtect command injection -> pre-auth RCE 2026-07-13
CVE-2024-21887 Ivanti Connect Secure critical Ivanti Connect Secure command injection (chained -> pre-auth RCE) 2026-07-13
CVE-2024-21762 FortiOS SSL-VPN critical FortiOS SSL-VPN out-of-bounds write -> pre-auth RCE 2026-07-13
CVE-2023-4966 Citrix NetScaler ADC/Gateway critical Citrix Bleed: sensitive session-token disclosure 2026-07-13
CVE-2023-46747 F5 BIG-IP critical F5 BIG-IP Traffic Management UI auth bypass -> RCE 2026-07-13
CVE-2023-35708 MOVEit Transfer critical MOVEit Transfer SQL injection -> privilege escalation 2026-07-13
CVE-2023-35036 MOVEit Transfer critical MOVEit Transfer SQL injection (follow-up) 2026-07-13
CVE-2023-34362 MOVEit Transfer critical MOVEit Transfer SQL injection -> RCE (Cl0p mass-exploitation) 2026-07-13
CVE-2023-0669 GoAnywhere MFT critical GoAnywhere MFT deserialization -> RCE (Cl0p) 2026-07-13
CVE-2022-1388 F5 BIG-IP critical F5 BIG-IP iControl REST authentication bypass -> RCE 2026-07-13
CVE-2021-34473 Microsoft Exchange OWA critical ProxyShell: pre-auth RCE 2026-07-13
CVE-2021-26855 Microsoft Exchange OWA critical ProxyLogon: pre-auth SSRF 2026-07-13
CVE-2023-46805 Ivanti Connect Secure high Ivanti Connect Secure authentication bypass 2026-07-13
CVE-2025-14847 MongoDB high MongoBleed: unauthenticated zlib-decompression heap memory disclosure 2026-07-11
CVE-2020-25213 wp-file-manager critical WP File Manager unauthenticated arbitrary file upload -> RCE 2026-07-07
CVE-2017-1001000 WordPress critical WordPress REST API unauthenticated content injection / privilege escalation 2026-07-07
CVE-2017-9066 WordPress high WordPress SSRF via HTTP request handling (unpatched pre-4.7.5 branch) 2026-07-07
CVE-2025-24813 Apache Tomcat critical Tomcat partial-PUT deserialization RCE 2026-06-29
CVE-2024-6387 OpenSSH critical regreSSHion: unauthenticated RCE in sshd 2026-06-29
CVE-2024-4577 PHP critical PHP-CGI argument injection → RCE (Windows) 2026-06-29
CVE-2022-22965 Spring Framework critical Spring4Shell RCE via data binding 2026-06-29
CVE-2021-42013 Apache httpd critical Apache path traversal → RCE 2026-06-29
CVE-2021-23017 nginx critical nginx resolver off-by-one heap overwrite (RCE) 2026-06-29
CVE-2024-49767 Werkzeug high Werkzeug multipart resource exhaustion 2026-06-29
CVE-2023-25577 Werkzeug high Werkzeug multipart DoS (resource exhaustion) 2026-06-29
CVE-2021-40438 Apache httpd high mod_proxy SSRF 2026-06-29
CVE-2020-11022 jQuery medium jQuery htmlPrefilter XSS 2026-06-29
CVE-2019-8331 Bootstrap medium Bootstrap XSS in tooltip/popover data-template 2026-06-29
CVE-2018-2783 Angular medium AngularJS (1.x) is end-of-life; multiple sandbox-escape XSS 2026-06-29

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →