CVEs NewScan detects
Every CVE NewScan detects, newest first, with the technology it affects and the day the detection landed. Most are version-matched against a fingerprinted component — those link to a page with the affected range, the release that fixes it, and how the scanner reports it. The rest are reported by a check that observes the vulnerability or its precondition directly rather than matching a version, so the row names that check instead of linking to a version range. The list is generated from the detection packs themselves and grows daily — local, in-band scanning is free, so you can check any of these against your own systems without a licence.
504 CVEs · 264 critical · 195 high · 43 medium · 2 low · 389 with a detail page
| CVE | Tech | Severity | Description | Added |
|---|---|---|---|---|
| CVE-2026-85984 | miniorange-otp-verification | critical | miniOrange OTP Login, Verification and SMS Notifications (WordPress) authentication bypass - mo_wp_login_intent=otp logs an unauthenticated caller in as any administrator | 2026-09-27 |
| CVE-2026-82901 | ultimate-addons-for-contact-form-7 | critical | Ultra Addons for Contact Form 7 (WordPress) unauthenticated arbitrary file upload in uacf7_wpcf7_mail_components -> possible RCE | 2026-09-27 |
| CVE-2026-100857 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100856 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100855 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100853 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100852 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100851 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100849 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100848 | AzuraCast | high | Covered by the AzuraCast batch fix for CVE-2026-100847 | 2026-09-27 |
| CVE-2026-100847 | AzuraCast | high | AzuraCast pre-0.23.8 batch: DQL injection via the sortOrder API parameter, plus SSRF, command/code injection and unauthenticated media download | 2026-09-27 |
| CVE-2026-87902 | WordPress | critical | WordPress core unauthenticated local file inclusion - get_page_template() resolves a page template outside the active theme and includes a chosen readable local .php file | 2026-09-26 |
| CVE-2026-65660 | Microsoft SharePoint Server | critical | SharePoint Server code injection - an authenticated caller executes code on the server over the network (CVSS 8.8), actively exploited September 2026 | 2026-09-26 |
| CVE-2026-100418 | Flame | medium | Reported by NewScan's exposure path probe: Flame start-page configuration, weather API key included, answers an unauthenticated GET - CVE-2026-100418 | 2026-09-26 |
| CVE-2026-89055 | customer-reviews-woocommerce | high | Customer Reviews for WooCommerce authorization bypass - a plugin endpoint does not check the caller's capability before acting | 2026-09-25 |
| CVE-2026-63645 | OpenObserve | high | Reported by NewScan's exposure path probe: OpenObserve runtime configuration answers an unauthenticated GET - CVE-2026-63645 | 2026-09-25 |
| CVE-2026-97056 | SigNoz | critical | Covered by the SigNoz batch fix for CVE-2026-97055 | 2026-09-24 |
| CVE-2026-97055 | SigNoz | critical | SigNoz ships an EMPTY default JWT signing secret, so anyone can forge an admin session (CVSS 9.2) | 2026-09-24 |
| CVE-2026-82077 | PaperCut MF/NG | high | PaperCut MF/NG Scan-to-Fax path traversal reaching command execution on the host (CVSS 7.3) | 2026-09-24 |
| CVE-2026-14780 | PaperCut MF/NG | high | Covered by the PaperCut MF/NG batch fix for CVE-2026-82077 | 2026-09-24 |
| CVE-2026-87739 | PaperCut MF/NG | medium | PaperCut MF/NG generates reports for an unauthenticated caller - user permissions are never evaluated (CVSS 6.9) | 2026-09-24 |
| CVE-2026-94127 | F5 BIG-IP | critical | F5 BIG-IP APM heap overflow in OAuth request handling -> unauthenticated RCE (zero-day, exploited in the wild) | 2026-09-23 |
| CVE-2026-93616 | Check Point Security Gateway | critical | Check Point Management Server directory traversal + file upload -> unauthenticated arbitrary script execution | 2026-09-23 |
| CVE-2026-85102 | Check Point Security Gateway | critical | Check Point Quantum Security Gateway improper certificate trust validation during VPN negotiation -> unauthenticated RCE | 2026-09-23 |
| CVE-2026-73546 | envoy | critical | Reported by NewScan's unauthenticated interface: Unauthenticated Envoy admin interface | 2026-09-22 |
| CVE-2026-84990 | ntopng | high | ntopng before 6.7.260718: the system-configuration backup REST endpoints list and hand out configuration backups to a caller that should not be able to read them, exposing the moni… | 2026-09-22 |
| CVE-2026-82412 | ntopng | high | ntopng before 6.7.260717: the vulnerability-scan REST endpoints pass a caller-supplied host into the scanner shell, so a request to the monitoring UI runs commands on the appliance… | 2026-09-22 |
| CVE-2026-73553 | Envoy | high | Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… | 2026-09-22 |
| CVE-2026-73552 | Envoy | high | Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… | 2026-09-22 |
| CVE-2026-73551 | Envoy | high | Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… | 2026-09-22 |
| CVE-2026-73548 | Envoy | high | Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgrade is forwarded as a tunnel (request smuggling… | 2026-09-22 |
| CVE-2026-73511 | Envoy | high | Reported by NewScan's component version range: Envoy before 1.36.10 / 1.37.6 / 1.38.4 / 1.39.1: one advisory batch of six routing and access-control bypasses - a non-WebSocket upgr… | 2026-09-22 |
| CVE-2026-82187 | web-to-print-online-designer | critical | WooCommerce Online Product Designer unauthenticated arbitrary file upload -> RCE (no type/extension validation, upload token handed to any visitor) | 2026-09-21 |
| CVE-2026-86802 | todo-lists-for-membership-sites | high | To Do List Member unauthenticated import - no authorisation or nonce check, and the fetched location is unvalidated (content injection + SSRF) | 2026-09-21 |
| CVE-2025-12999 | HTTP | high | Reported by NewScan's named-CVE check: test_base_url_poisoning | 2026-09-21 |
| CVE-2026-85113 | give | medium | GiveWP stored shortcode injection - donor-supplied values are rendered on public pages with shortcode delimiters intact | 2026-09-21 |
| CVE-2026-85010 | restropress | medium | RestroPress client-side add-on price trusted by the server - unauthenticated order-total manipulation | 2026-09-21 |
| CVE-2026-87067 | forminator | high | Forminator Forms (WordPress) PHP object injection: the XML-RPC path deserialises a request value with no allow-list of instantiable classes | 2026-09-20 |
| CVE-2026-81654 | nextgen-gallery | high | Covered by the nextgen-gallery batch fix for CVE-2026-81652 | 2026-09-20 |
| CVE-2026-81652 | nextgen-gallery | high | NextGEN Gallery (WordPress) before 4.5.0: any logged-in user reads any image record, and any logged-in user writes the gallery's image-sizing settings | 2026-09-20 |
| CVE-2026-93964 | Nginx Proxy Manager | medium | nginx-proxy-manager through 2.15.1: internalCertificate.validate mishandles an uploaded certificate bundle | 2026-09-20 |
| CVE-2026-93598 | arcadedb | high | Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously | 2026-09-19 |
| CVE-2026-93595 | arcadedb | high | Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously | 2026-09-19 |
| CVE-2026-93594 | arcadedb | high | Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously | 2026-09-19 |
| CVE-2026-93593 | arcadedb | high | Reported by NewScan's unauthenticated interface: ArcadeDB Studio console reachable anonymously | 2026-09-19 |
| CVE-2026-61833 | zot | high | zot before 2.1.18: the bearer authentication handler accepts a token it should reject, so an OCI registry configured for bearer auth can be read and written without a valid credent… | 2026-09-19 |
| CVE-2026-92947 | vm2 | critical | vm2 shared Buffer pool host-memory exposure (version advisory) | 2026-09-18 |
| CVE-2026-92599 | joi | high | Joi isoDate validation denial of service (17.x version advisory) | 2026-09-18 |
| CVE-2026-91992 | tornado | medium | Tornado CurlAsyncHTTPClient credential reuse (version advisory) | 2026-09-18 |
| CVE-2026-89013 | Dolibarr | high | Dolibarr authorization bypass - hashp=shared skips token validation in document.php and viewimage.php, giving an unauthenticated caller arbitrary file read | 2026-09-14 |
| CVE-2026-42018 | JFrog Artifactory | high | JFrog Artifactory returns an internal anonymous-user token to an unauthenticated caller even when anonymous access is DISABLED (CISA KEV, exploited in the wild) | 2026-09-14 |
| CVE-2026-42016 | JFrog Artifactory | high | JFrog Artifactory (self-hosted) privilege escalation - access tokens are validated on signature and issuer but never on SCOPE (CISA KEV, exploited in the wild) | 2026-09-14 |
| CVE-2026-90549 | AVideo | medium | Reported by NewScan's exposure path probe: AVideo mobile video feed returns the video owner's email and last-login to an anonymous caller - CVE-2026-90549 | 2026-09-14 |
| CVE-2026-90541 | AVideo | medium | Reported by NewScan's exposure path probe: AVideo TopMenu administration menu list answers an unauthenticated GET - CVE-2026-90541 | 2026-09-14 |
| CVE-2026-89012 | Dolibarr | medium | Dolibarr case-sensitive denylist bypass in the sqlfilters API parameter - uppercase field names reach protected columns as a boolean oracle | 2026-09-14 |
| CVE-2026-84869 | ConnectWise ScreenConnect | critical | ScreenConnect build distributes a client that can be made to transfer and execute files over an active remote session without Host authorization | 2026-09-12 |
| CVE-2026-72710 | SPIP | critical | SPIP remote code execution via the editer_objet action - attacker rows injected into the spip_jobs queue are unserialized and executed by cron | 2026-09-12 |
| CVE-2026-72709 | SPIP | critical | SPIP missing authorization on the ecrire/action/ endpoints - unauthenticated password reset of any account, including the administrator | 2026-09-12 |
| CVE-2026-72708 | SPIP | high | SPIP unauthenticated blind SQL injection in the public sitemap - leaks the alea_ephemere nonce-signing secret | 2026-09-12 |
| CVE-2026-88877 | Traefik | critical | Traefik Kubernetes Ingress NGINX provider authentication bypass - an Ingress carrying both an auth annotation and from-to-www-redirect generates a sibling host-only router that rea… | 2026-09-11 |
| CVE-2026-88007 | Traefik | critical | Traefik HTTP/3 backend connection reuse across users - the HTTP/3 entrypoint's ConnContext never calls service.AddTransportOnContext, so a backend connection already authenticated … | 2026-09-11 |
| CVE-2026-89054 | Apache HTTP Server | high | Reported by NewScan's named-CVE check: test_http_method_authz | 2026-09-11 |
| CVE-2026-88009 | Traefik | high | Traefik rootless HTTP/1 request-target is routed as "/" but forwarded to the backend verbatim - Go parks a rootless target in URL.Opaque, so path-scoped routing rules, path-scoped … | 2026-09-11 |
| CVE-2026-88008 | Traefik | high | Traefik request smuggling and incorrect authorization from inconsistent HTTP request interpretation between Traefik and the backend (CVSS 7.0) | 2026-09-11 |
| CVE-2026-88004 | Traefik | high | Traefik entrypoint header-name sanitization bypassed via request trailers - a header Traefik strips or rewrites on the request can be reintroduced in the HTTP trailer section, whic… | 2026-09-11 |
| CVE-2026-89248 | AVideo | medium | Reported by NewScan's exposure path probe: AVideo WebRTC plugin status endpoint answers anonymously - CVE-2026-89248 | 2026-09-11 |
| CVE-2026-88879 | Traefik | medium | Traefik canonicalizes header names on dashes only, so X-Auth-User, X_Auth_User and X.Auth.User are three headers to Traefik and ONE variable to a CGI/WSGI/PHP/NGINX backend - a cli… | 2026-09-11 |
| CVE-2026-88878 | Traefik | medium | Traefik respondingTimeouts (readTimeout, on by default at 60s) are not applied to the HTTP/3 request path - readTimeout is a TCP connection deadline that cannot bind a QUIC stream,… | 2026-09-11 |
| CVE-2026-88012 | Traefik | medium | Traefik respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded (CVSS 5.3) | 2026-09-11 |
| CVE-2026-88011 | Traefik | medium | Traefik ForwardAuth identity spoofing via a dot-form header alias - the client supplies X.Authenticated.User alongside the canonical X-Authenticated-User that ForwardAuth writes, a… | 2026-09-11 |
| CVE-2026-20079 | Cisco Secure Firewall Management Center | critical | Cisco Secure Firewall Management Center authentication bypass - a hardcoded internal session id is accepted from the network, giving an unauthenticated attacker the authenticated c… | 2026-09-10 |
| CVE-2026-19490 | Citrix NetScaler ADC/Gateway | critical | NetScaler ADC/Gateway authentication bypass leading to account takeover (CVSS 9.3, CISA KEV) | 2026-09-10 |
| CVE-2023-6553 | backup-backup | critical | Backup Migration unauthenticated remote code execution through attacker-controlled includes in backup-heart.php | 2026-09-10 |
| CVE-2025-25249 | FortiOS SSL-VPN | high | FortiOS heap-based buffer overflow (CVSS 8.1, CISA KEV) - exploited in the wild by the PivotC2 FortiGate RAT | 2026-09-10 |
| CVE-2026-86218 | N-able N-central | critical | N-able N-central pre-authentication remote code execution (CVSS 10.0, actively exploited) | 2026-09-09 |
| CVE-2026-87819 | GitPython | high | GitPython Actor author/committer parsing regular-expression denial of service | 2026-09-09 |
| CVE-2026-86081 | n8n | high | n8n Git node clone destination-path regular-expression denial of service | 2026-09-09 |
| CVE-2026-86543 | knowns | critical | Reported by NewScan's unauthenticated interface: Unauthenticated knowns management API (no password set) | 2026-09-08 |
| CVE-2026-13190 | Telerik UI for ASP.NET AJAX | critical | Telerik UI for ASP.NET AJAX unsafe type instantiation from persisted state in the persistence utilities -> remote code execution | 2026-09-07 |
| CVE-2026-13186 | Telerik UI for ASP.NET AJAX | critical | Telerik UI for ASP.NET AJAX path traversal in the file-based persistence storage provider -> attacker-controlled deserialization and remote code execution | 2026-09-07 |
| CVE-2026-13185 | Telerik UI for ASP.NET AJAX | critical | Telerik UI for ASP.NET AJAX deserialization of attacker-controlled cookie state in RadPersistenceManager / RadDockLayout -> unauthenticated remote code execution | 2026-09-07 |
| CVE-2026-13181 | Telerik UI for ASP.NET AJAX | critical | Telerik UI for ASP.NET AJAX unsafe type resolution in RadAsyncUpload AsyncUploadTypeName -> remote code execution | 2026-09-07 |
| CVE-2026-13184 | Telerik UI for ASP.NET AJAX | high | Telerik UI for ASP.NET AJAX predictable default upload-metadata integrity key when Telerik.Upload.ConfigurationHashKey and machineKey are both unset | 2026-09-07 |
| CVE-2026-13183 | Telerik UI for ASP.NET AJAX | high | Telerik UI for ASP.NET AJAX timing oracle in RadAsyncUpload metadata processing -> recovery of protected metadata when detailed errors are suppressed | 2026-09-07 |
| CVE-2026-13182 | Telerik UI for ASP.NET AJAX | high | Telerik UI for ASP.NET AJAX padding oracle in RadAsyncUpload client-state handling -> disclosure and forgery of protected upload metadata | 2026-09-07 |
| CVE-2026-2390 | powerkit | medium | Powerkit (WordPress) stored cross-site scripting via the Lazy Load module's regex-based image-attribute parser | 2026-09-07 |
| CVE-2026-85595 | Traefik | critical | Traefik digestAuth authentication bypass - an unknown username is answered with an empty secret instead of a rejection, so any username with no password authenticates (CVSS 9.3) | 2026-09-04 |
| CVE-2026-85597 | Traefik | high | Traefik mTLS bypass - conflicting TLS options on routers sharing a hostname fall back to the default TLS config, dropping client-certificate authentication for every host in the ru… | 2026-09-04 |
| CVE-2026-85596 | Traefik | high | Traefik Kubernetes Ingress NGINX provider mTLS bypass - Ingresses sharing a host and client CA generate distinct TLS option names, are read as a conflict, and fall back to a defaul… | 2026-09-04 |
| CVE-2026-85391 | JSON Web Token | high | Reported by NewScan's named-CVE check: crack_jwt_secret | 2026-09-04 |
| CVE-2026-85180 | Ollama | high | Ollama 0.30.0-0.33.2: SSRF when pulling tensor-layer models - blob downloads follow a cross-host redirect unvalidated, so a model reference the operator pulls can steer the server … | 2026-09-04 |
| CVE-2026-49869 | Kestra | critical | Kestra authentication bypass -> unauthenticated RCE as root (CVSS 10.0, CISA KEV) | 2026-09-03 |
| CVE-2026-59822 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-09-03 |
| CVE-2025-22871 | RoadRunner | critical | RoadRunner request smuggling via bare-LF chunk-size line (bundled Go net/http) | 2026-09-02 |
| CVE-2026-84304 | google.golang.org/grpc | high | gRPC-Go heap exhaustion through fragmented HTTP/2 DATA frames | 2026-09-02 |
| CVE-2026-83619 | @xmldom/xmldom | high | xmldom quadratic end-tag parsing denial of service | 2026-09-02 |
| CVE-2026-81578 | PaperCut MF/NG | critical | PaperCut MF/NG unauthenticated management-interface access control bypass chained to code execution (CISA KEV) | 2026-09-01 |
| CVE-2026-81891 | elFinder | high | Covered by the elFinder batch fix for CVE-2026-81889 | 2026-09-01 |
| CVE-2026-81890 | elFinder | high | Covered by the elFinder batch fix for CVE-2026-81889 | 2026-09-01 |
| CVE-2026-81889 | elFinder | high | elFinder URL-upload SSRF filter bypass, archive-extraction MIME bypass and netmount left out of the CSRF-protected command list | 2026-09-01 |
| CVE-2026-77348 | Wallos | high | Wallos SSRF through HTTP proxy environment variables - the incomplete fix for CVE-2026-33407 | 2026-09-01 |
| CVE-2026-61641 | Wallos | high | Covered by the Wallos batch fix for CVE-2026-61639 | 2026-09-01 |
| CVE-2026-61640 | Wallos | high | Covered by the Wallos batch fix for CVE-2026-61639 | 2026-09-01 |
| CVE-2026-61639 | Wallos | high | Wallos zip-slip on database restore, SSRF through the admin-set OIDC and SMTP endpoints, and OIDC identity linking by email | 2026-09-01 |
| CVE-2026-61638 | Wallos | high | Covered by the Wallos batch fix for CVE-2026-61639 | 2026-09-01 |
| CVE-2026-54600 | Wallos | high | Wallos unauthenticated database import and schema migration over HTTP, plus an unchecked OIDC state nonce | 2026-09-01 |
| CVE-2026-54599 | Wallos | high | Covered by the Wallos batch fix for CVE-2026-54600 | 2026-09-01 |
| CVE-2026-54598 | Wallos | high | Covered by the Wallos batch fix for CVE-2026-54600 | 2026-09-01 |
| CVE-2026-33407 | Wallos | high | Covered by the Wallos batch fix for CVE-2026-77348 | 2026-09-01 |
| CVE-2026-82880 | YaCy | high | YaCy Search Server XML external entity injection - the SVG, FreeMind and OpenSearch parsers resolve external entities | 2026-08-31 |
| CVE-2026-82654 | SiYuan | high | Covered by the SiYuan batch fix for CVE-2026-82653 | 2026-08-31 |
| CVE-2026-82653 | SiYuan | high | SiYuan stored cross-site scripting - package and notebook names in confirmDialog(), and block name/alias/memo in hint, backlink and breadcrumb rendering, are interpolated into inne… | 2026-08-31 |
| CVE-2026-82456 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-30 |
| CVE-2026-75807 | miniorange-saml-20-single-sign-on | high | SAML Single Sign On - SSO Login (miniOrange) authentication bypass - mo_saml_login_validate() trusts an unverified assertion, so any account can be logged into | 2026-08-30 |
| CVE-2026-82476 | Memos | medium | Memos server-side request forgery - the link-metadata fetcher omits the 100.64.0.0/10 CGNAT range from its SSRF guard | 2026-08-30 |
| CVE-2026-81766 | really-simple-ssl | medium | Really Simple Security missing capability check on plugin installation - a subsite admin installs arbitrary plugins from a supplied URL | 2026-08-30 |
| CVE-2026-81660 | groundhogg | medium | Groundhogg stored cross-site scripting - optional web-form fields are stored and rendered unescaped | 2026-08-30 |
| CVE-2026-76585 | customer-reviews-woocommerce | medium | Customer Reviews for WooCommerce stored cross-site scripting - review content from one of its endpoints is neither sanitised nor escaped | 2026-08-30 |
| CVE-2026-78364 | mw-wp-form | low | MW WP Form stored cross-site scripting - form settings are echoed unescaped in an admin dashboard page | 2026-08-30 |
| CVE-2026-82266 | redpanda | critical | Reported by NewScan's unauthenticated interface: Unauthenticated Redpanda Admin API | 2026-08-29 |
| CVE-2026-19295 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-19286 | 2026-08-29 |
| CVE-2026-19294 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-19286 | 2026-08-29 |
| CVE-2026-19286 | Langflow | critical | Langflow 1.0.0 - 1.11.1: remote code execution via the A2A public endpoint, plus 7 further IBM Langflow OSS advisories fixed in the same range | 2026-08-29 |
| CVE-2026-18904 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-19286 | 2026-08-29 |
| CVE-2026-18899 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-19286 | 2026-08-29 |
| CVE-2026-18891 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-19286 | 2026-08-29 |
| CVE-2026-18729 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-19286 | 2026-08-29 |
| CVE-2026-18545 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-19286 | 2026-08-29 |
| CVE-2026-82288 | Stable Diffusion WebUI | high | Reported by NewScan's exposure path probe: Stable Diffusion WebUI leaks its own UI password - CVE-2026-82288 | 2026-08-29 |
| CVE-2026-82246 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-82244 | 2026-08-28 |
| CVE-2026-82245 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-82244 | 2026-08-28 |
| CVE-2026-82244 | Budibase | critical | Budibase before 3.41.3: remote code execution via plugin upload (CVE-2026-82244), plus datasource-query authorization bypass, builder-role escalation, cross-app resource injection,… | 2026-08-28 |
| CVE-2026-82243 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-82244 | 2026-08-28 |
| CVE-2026-82242 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-82244 | 2026-08-28 |
| CVE-2026-82240 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-82244 | 2026-08-28 |
| CVE-2026-82239 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-82244 | 2026-08-28 |
| CVE-2023-49105 | ownCloud | critical | ownCloud before 10.13.1: WebDAV API authentication bypass reads, writes and deletes any user's files (CISA KEV) | 2026-08-28 |
| CVE-2023-49103 | ownCloud | critical | Covered by the ownCloud batch fix for CVE-2023-49105 | 2026-08-28 |
| CVE-2026-82241 | Budibase | high | Budibase 3.33.4 before 3.41.3: the default SSRF blacklist omits the shared address space 100.64.0.0/10 | 2026-08-28 |
| CVE-2026-82237 | FileBrowser | high | Covered by the FileBrowser batch fix for CVE-2026-82235 | 2026-08-28 |
| CVE-2026-82235 | FileBrowser | high | FileBrowser through 2.63.23: a named pipe in a shared directory blocks the archive and public-download handlers, and renaming a shared file leaves its share link live - NO FIX WILL… | 2026-08-28 |
| CVE-2026-82238 | FileBrowser | low | FileBrowser 2.24.0 through 2.63.23: concurrent TUS PATCH uploads race past the declared Upload-Length - NO FIX WILL SHIP | 2026-08-28 |
| CVE-2026-60004 | Gitea | critical | Gitea diffpatch API remote code execution via Git hook installation (CVSS 9.8, CISA KEV) | 2026-08-27 |
| CVE-2026-8452 | Citrix NetScaler ADC/Gateway | high | NetScaler ADC/Gateway memory-overflow denial of service when configured as a Gateway (CVSS 8.8) | 2026-08-27 |
| CVE-2021-23758 | AjaxPro | high | Reported by NewScan's exposure path probe: AjaxPro handler exposed - .NET deserialization RCE (CVE-2021-23758) | 2026-08-27 |
| CVE-2026-79782 | rclone | critical | rclone S3 backend leaks the X-Amz-Security-Token over plaintext HTTP on an HTTPS->HTTP redirect | 2026-08-26 |
| CVE-2026-79781 | rclone | medium | rclone serve s3 path traversal via dot-dot object keys - read and overwrite root-level files | 2026-08-26 |
| CVE-2026-79780 | rclone | medium | rclone before 1.75.0: credential exposure on redirect, WebDAV TUS DoS panic, and RC API stack-trace disclosure | 2026-08-26 |
| CVE-2026-79779 | rclone | medium | Covered by the rclone batch fix for CVE-2026-79780 | 2026-08-26 |
| CVE-2026-79778 | rclone | medium | Covered by the rclone batch fix for CVE-2026-79780 | 2026-08-26 |
| CVE-2026-79777 | rclone | medium | Covered by the rclone batch fix for CVE-2026-79780 | 2026-08-26 |
| CVE-2026-79776 | rclone | medium | Covered by the rclone batch fix for CVE-2026-79780 | 2026-08-26 |
| CVE-2026-78678 | GitPython | critical | Covered by the GitPython batch fix for CVE-2026-78676 | 2026-08-25 |
| CVE-2026-78677 | GitPython | critical | Covered by the GitPython batch fix for CVE-2026-78676 | 2026-08-25 |
| CVE-2026-78676 | GitPython | critical | GitPython git-config injection reaching core.hooksPath -> code execution, plus clone and blame option-denylist gaps (the 3.1.59 fix train) | 2026-08-25 |
| CVE-2026-56706 | Adminer | critical | Covered by the Adminer batch fix for CVE-2026-56705 | 2026-08-25 |
| CVE-2026-56705 | Adminer | critical | Adminer unauthenticated PDO/ODBC DSN injection from the login form -> code execution (heads a 7-CVE batch all fixed in 5.4.3) | 2026-08-25 |
| CVE-2026-56704 | Adminer | critical | Covered by the Adminer batch fix for CVE-2026-56705 | 2026-08-25 |
| CVE-2026-56703 | Adminer | critical | Covered by the Adminer batch fix for CVE-2026-56705 | 2026-08-25 |
| CVE-2026-56702 | Adminer | critical | Covered by the Adminer batch fix for CVE-2026-56705 | 2026-08-25 |
| CVE-2026-40877 | iTop | critical | Covered by the iTop batch fix for CVE-2026-34741 | 2026-08-25 |
| CVE-2026-39975 | iTop | critical | Covered by the iTop batch fix for CVE-2026-34741 | 2026-08-25 |
| CVE-2026-34968 | Adminer | critical | Covered by the Adminer batch fix for CVE-2026-56705 | 2026-08-25 |
| CVE-2026-34967 | Adminer | critical | Covered by the Adminer batch fix for CVE-2026-56705 | 2026-08-25 |
| CVE-2026-30864 | iTop | critical | Covered by the iTop batch fix for CVE-2026-34741 | 2026-08-25 |
| CVE-2026-21962 | Oracle WebLogic Server | critical | WebLogic Server Proxy Plug-in for Apache HTTP Server: unauthenticated remote access to critical data (CVSS 10.0, exploited in the wild) | 2026-08-25 |
| CVE-2026-16434 | Adminer | critical | Covered by the Adminer batch fix for CVE-2026-56705 | 2026-08-25 |
| CVE-2026-34964 | Adminer | medium | Adminer SSRF and open redirect via the login-form server field and X-Forwarded-Prefix (the 5.5.0 fix train) | 2026-08-25 |
| CVE-2026-34959 | Adminer | medium | Covered by the Adminer batch fix for CVE-2026-34964 | 2026-08-25 |
| CVE-2026-78207 | exceljs-hardened | critical | exceljs-hardened prototype pollution and unbounded XLSX decompression | 2026-08-24 |
| CVE-2026-78206 | exceljs-hardened | critical | Covered by the exceljs-hardened batch fix for CVE-2026-78207 | 2026-08-24 |
| CVE-2026-8445 | justhtml | critical | justhtml Markdown text-node escaping cross-site scripting | 2026-08-23 |
| CVE-2026-7808 | justhtml | critical | justhtml HTML sanitization bypass permits dangerous active content | 2026-08-23 |
| CVE-2026-76217 | GitPython | critical | Covered by the GitPython batch fix for CVE-2026-78676 | 2026-08-23 |
| CVE-2026-73080 | SeaweedFS | critical | SeaweedFS unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle | 2026-08-23 |
| CVE-2026-5388 | justhtml | critical | justhtml URL sanitization and HTML serialization bypasses | 2026-08-23 |
| CVE-2026-73624 | GitPython | high | Covered by the GitPython batch fix for CVE-2026-73620 | 2026-08-23 |
| CVE-2026-73620 | GitPython | high | GitPython argument injection via unguarded git option forwarding (IndexFile.checkout / TagReference.create) | 2026-08-23 |
| CVE-2026-73619 | GitPython | high | Covered by the GitPython batch fix for CVE-2026-73620 | 2026-08-23 |
| CVE-2026-73246 | kestra | high | Reported by NewScan's unauthenticated interface: Unauthenticated Kestra /worker endpoint exposes live task state and configuration | 2026-08-23 |
| CVE-2026-71324 | Traefik | high | Traefik cross-user response poisoning via proxied CONNECT (HTTP/2/3 CONNECT smuggled into the backend keep-alive pool) | 2026-08-23 |
| CVE-2026-4671 | justhtml | high | justhtml CSS selector and linkification denial of service | 2026-08-23 |
| CVE-2026-19351 | sql-query | high | node-sql-query SelectQuery SQL injection (Select.js from/build parameter manipulation) | 2026-08-23 |
| CVE-2026-17601 | Nexus Repository | high | Nexus Repository 3 wildcard-privilege self-escalation to administrator | 2026-08-23 |
| CVE-2026-73245 | kestra | medium | Reported by NewScan's unauthenticated interface: Unauthenticated Kestra management endpoint (Micronaut actuator) | 2026-08-23 |
| CVE-2026-77806 | SPIP | critical | SPIP unauthenticated remote code execution via an X-Spip-Filtre request header (exploited in the wild) | 2026-08-22 |
| CVE-2026-73570 | Zimbra Collaboration | critical | Zimbra Collaboration SNMP notification command injection -> remote code execution (CVSS 8.9, CISA KEV) | 2026-08-22 |
| CVE-2026-34949 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-34948 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-34836 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-34741 | iTop | critical | Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE batch all fixed in 3.2.3) | 2026-08-22 |
| CVE-2026-33240 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-33047 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-31936 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-31880 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-31803 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-30890 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-30866 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-30865 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-30826 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-30819 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-27490 | iTop | critical | Reported by NewScan's component version range: Combodo iTop authentication bypass lets an unauthenticated attacker execute arbitrary PHP files from env-production (heads a 19-CVE b… | 2026-08-22 |
| CVE-2026-27463 | iTop | critical | Covered by the iTop batch fix for CVE-2026-34741 | 2026-08-22 |
| CVE-2026-48050 | Go pprof | high | Reported by NewScan's exposure path probe: Exposed Go pprof debug endpoints | 2026-08-22 |
| CVE-2026-77647 | SPIP | critical | SPIP unauthenticated remote code execution via incorrect identification of PHP open tags (exploited in the wild) | 2026-08-21 |
| CVE-2026-72530 | TrueConf Server | critical | Pre-auth server-side template injection over TrueConf's client port 4307/TCP -> code execution on the conferencing server (CVSS 9.5) | 2026-08-21 |
| CVE-2026-72529 | TrueConf Server | critical | Pre-auth account takeover over TrueConf's client port 4307/TCP -> arbitrary command execution as a server account (CVSS 9.3) | 2026-08-21 |
| CVE-2026-67448 | Mailpit | high | Mailpit origin middleware checks the raw RequestURI for the /api/ prefix, so a re-spelled path reaches the whole mailbox API without the browser-origin gate | 2026-08-21 |
| CVE-2026-67447 | Mailpit | high | Covered by the Mailpit batch fix for CVE-2026-67448 | 2026-08-21 |
| CVE-2026-67446 | Mailpit | high | Covered by the Mailpit batch fix for CVE-2026-67448 | 2026-08-21 |
| CVE-2026-67445 | Mailpit | high | Covered by the Mailpit batch fix for CVE-2026-67448 | 2026-08-21 |
| CVE-2026-77082 | n8n | critical | Covered by the n8n batch fix for CVE-2026-77068 | 2026-08-20 |
| CVE-2026-77080 | n8n | critical | Covered by the n8n batch fix for CVE-2026-77068 | 2026-08-20 |
| CVE-2026-77075 | n8n | critical | Covered by the n8n batch fix for CVE-2026-77068 | 2026-08-20 |
| CVE-2026-77072 | n8n | critical | Covered by the n8n batch fix for CVE-2026-77068 | 2026-08-20 |
| CVE-2026-77068 | n8n | critical | n8n 1.x August 2026 batch: node-schema loader path traversal -> RCE, Snowflake node arbitrary file read/write, resource-locator expression injection, Form-node stored XSS and Filte… | 2026-08-20 |
| CVE-2026-55089 | Etherpad | critical | Etherpad OAuth authorization_code path authorizes /api/2/* requests without a valid API key | 2026-08-20 |
| CVE-2026-32475 | elementor-pro | critical | Elementor Pro unauthenticated arbitrary file upload -> RCE via the Forms widget file-upload field | 2026-08-20 |
| CVE-2026-55085 | Etherpad | high | Etherpad stored XSS via a numbered-list start attribute interpolated into unquoted HTML | 2026-08-20 |
| CVE-2026-59310 | VMware vCenter Server | critical | vCenter Syslog server directory traversal -> arbitrary code execution (CVSS 9.8) | 2026-08-19 |
| CVE-2026-55040 | Microsoft SharePoint Server | critical | SharePoint Server JWT authentication bypass - an unsigned (alg:none) Bearer token authenticates an anonymous caller on /_api/* (CVSS 9.1) | 2026-08-19 |
| CVE-2025-55315 | Kestrel | critical | Kestrel HTTP request smuggling security-feature bypass | 2026-08-19 |
| CVE-2024-35264 | Kestrel | critical | Kestrel HTTP/3 data corruption remote code execution | 2026-08-19 |
| CVE-2023-44487 | Kestrel | high | Kestrel HTTP/2 Rapid Reset denial of service | 2026-08-19 |
| CVE-2023-38180 | Kestrel | high | Kestrel fails to disconnect some malicious clients, enabling denial of service | 2026-08-19 |
| CVE-2026-64849 | MLflow | critical | MLflow webhook-test SSRF via redirect re-validation bypass | 2026-08-18 |
| CVE-2025-62593 | Ray | critical | Ray Jobs API driven from a victim browser (User-Agent-gated dashboard, KEV) | 2026-08-18 |
| CVE-2026-68520 | Glances | high | Reported by NewScan's exposure path probe: Glances config API leaking export credentials | 2026-08-18 |
| CVE-2026-74842 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-17 |
| CVE-2026-74799 | Go pprof | high | Reported by NewScan's exposure path probe: Exposed Go pprof debug endpoints | 2026-08-17 |
| CVE-2026-19984 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-17 |
| CVE-2026-19964 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-17 |
| CVE-2026-19958 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-17 |
| CVE-2026-19957 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-17 |
| CVE-2026-19956 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-17 |
| CVE-2026-14832 | shopsmart-loyalty-for-woocommerce | high | ShopSmart Loyalty for WooCommerce unauthenticated customer-record disclosure - shopsmart_check_phone returns a loyalty profile to anyone who supplies a phone number, with no owners… | 2026-08-17 |
| CVE-2026-13700 | wooms | high | WooMS unauthenticated SSRF in the data-sync feature - the plugin attaches its stored third-party integration credentials to a request aimed at an attacker-supplied URL, so the cred… | 2026-08-17 |
| CVE-2026-19474 | @fastify/multipart | high | @fastify/multipart 3.0.0-10.1.0: aborted multipart uploads leak temporary files (and, from 5.3.0, hang the request handler), letting an unauthenticated client exhaust disk | 2026-08-16 |
| CVE-2026-18549 | @fastify/multipart | high | Covered by the @fastify/multipart batch fix for CVE-2026-19474 | 2026-08-16 |
| CVE-2026-18500 | @fastify/jwt | high | @fastify/jwt before 10.2.2: a per-request verification key is silently overridden by the global secret, so a token signed with the global secret passes a check that demanded a diff… | 2026-08-16 |
| CVE-2026-19898 | vmauth | medium | vmauth authentication-endpoint brute force (requestHandler) | 2026-08-16 |
| CVE-2026-18165 | @fastify/oauth2 | medium | @fastify/oauth2 7.2.0-8.2.0: OAuth state and PKCE verifier live in unprefixed cookies, so anyone who can write a cookie on a related host can log a victim into the ATTACKER's accou… | 2026-08-16 |
| CVE-2026-50027 | mcp-memory-service | critical | Reported by NewScan's unauthenticated interface: Unauthenticated mcp-memory-service document/memory API | 2026-08-15 |
| CVE-2026-49989 | CrateDB | high | CrateDB blob HTTP handler authorization bypass - any authenticated user reads, deletes or plants blobs by SHA-1 digest | 2026-08-15 |
| CVE-2026-73302 | Budibase | critical | Budibase before 3.39.30: OIDC login accepts an unverified email, allowing account takeover by email collision | 2026-08-14 |
| CVE-2026-72857 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-72851 | 2026-08-14 |
| CVE-2026-72856 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-72851 | 2026-08-14 |
| CVE-2026-72855 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-72851 | 2026-08-14 |
| CVE-2026-72853 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-72851 | 2026-08-14 |
| CVE-2026-72851 | Budibase | critical | Budibase before 3.40.0: unauthenticated SQL injection via webhook automations (CVE-2026-72851), plus arbitrary file write, tenant-owner auth bypass, Oracle-connector SQLi, SSRF, cr… | 2026-08-14 |
| CVE-2026-72850 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-72851 | 2026-08-14 |
| CVE-2026-72849 | Budibase | critical | Covered by the Budibase batch fix for CVE-2026-72851 | 2026-08-14 |
| CVE-2026-72836 | FileBrowser | critical | FileBrowser before 2.63.19: self-registration home-directory takeover on case-insensitive filesystems | 2026-08-14 |
| CVE-2026-73500 | etcd | high | etcd 3.5.x before 3.5.33: remote denial of service on the TLS listener (CVE-2026-73500), plus CVE-2026-73499 | 2026-08-14 |
| CVE-2026-73499 | etcd | high | Covered by the etcd batch fix for CVE-2026-73500 | 2026-08-14 |
| CVE-2026-73408 | Budibase | high | Budibase before 3.39.18: MySQL connector enables multipleStatements and interpolates an unescaped table name into DESCRIBE | 2026-08-14 |
| CVE-2026-73305 | Budibase | high | Budibase before 3.39.24: POST /api/public/v1/roles/assign skips the app-scope check, allowing cross-app privilege escalation | 2026-08-14 |
| CVE-2026-72859 | Budibase | high | Budibase 3.39.4 before 3.40.0: authorization regression hands BASIC users S3 PutObject presigned URLs | 2026-08-14 |
| CVE-2026-73604 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73603 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73602 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73601 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73488 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73487 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73486 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73485 | Flowise | critical | Covered by the Flowise batch fix for CVE-2026-73483 | 2026-08-13 |
| CVE-2026-73483 | Flowise | critical | Flowise before 3.1.4: sandbox escapes and agent-node code injection - remote code execution on the Flowise host, unauthenticated in two of them | 2026-08-13 |
| CVE-2026-72794 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-13 |
| CVE-2026-72793 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-13 |
| CVE-2026-47717 | FUXA | high | Reported by NewScan's unauthenticated interface: Unauthenticated FUXA SCADA/HMI project | 2026-08-13 |
| CVE-2026-73211 | PeerTube | critical | PeerTube unauthenticated SQL injection from a federated peer, plus cross-origin video takeover | 2026-08-12 |
| CVE-2026-73090 | PeerTube | critical | PeerTube cross-origin video takeover via a federated Update activity | 2026-08-12 |
| CVE-2026-20349 | Cisco ASA/FTD WebVPN | high | Cisco ASA/FTD Remote Access SSL VPN unauthenticated reload - a single crafted HTTP request takes the VPN down (CVSS 8.6, KEV 2026-08-12) | 2026-08-12 |
| CVE-2026-72899 | Metabase | critical | Covered by the Metabase batch fix for CVE-2026-72898 | 2026-08-11 |
| CVE-2026-72898 | Metabase | critical | Metabase unauthenticated SQL injection to administrator (/api/session/reset_password, and public-link field filters) | 2026-08-11 |
| CVE-2023-38646 | Metabase | critical | Metabase pre-authentication remote code execution via a public setup token | 2026-08-11 |
| CVE-2026-69086 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-69083 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-68586 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-68585 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-68584 | SiYuan | critical | Reported by NewScan's unauthenticated interface: Unauthenticated SiYuan kernel API | 2026-08-10 |
| CVE-2026-21858 | n8n | critical | n8n Form Webhook Content-Type confusion allows unauthenticated arbitrary file read ("Ni8mare") | 2026-08-10 |
| CVE-2025-68613 | n8n | critical | n8n expression sandbox escape allows authenticated remote code execution | 2026-08-10 |
| CVE-2019-9193 | PostgreSQL | high | Covered by the PostgreSQL batch fix for CVE-2018-1058 | 2026-08-10 |
| CVE-2018-1058 | PostgreSQL | high | PostgreSQL search_path privilege escalation: an unprivileged user can create objects that a superuser then executes | 2026-08-10 |
| CVE-2026-12971 | learnpress | medium | LearnPress SSRF: the instructor-role AI image-import feature fetches an arbitrary attacker-supplied URL server-side | 2026-08-10 |
| CVE-2026-67620 | REST APIs | high | Reported by NewScan's named-CVE check: test_ssrf | 2026-08-09 |
| CVE-2026-10595 | Web apps | high | Reported by NewScan's named-CVE check: test_url_path_traversal | 2026-08-09 |
| CVE-2026-8037 | Progress Kemp LoadMaster | critical | Pre-auth OS command injection in the LoadMaster API (/accessv2) -> arbitrary command execution on the appliance (CVSS 9.6) | 2026-08-08 |
| CVE-2026-61808 | lightrag | critical | Reported by NewScan's unauthenticated interface: Unauthenticated LightRAG API server (authentication disabled) | 2026-08-08 |
| CVE-2026-64638 | WordPress | high | XSS2Shell: WordPress core pre-auth reflected XSS on wp-login.php via a strip_tags()/KSES parser differential | 2026-08-08 |
| CVE-2026-14812 | Premium-SEO | critical | Premium-SEO is a malicious WordPress plugin, not a compromised one: every build ships an unauthenticated backdoor that creates a hidden administrator account (login prefix resource… | 2026-08-07 |
| CVE-2026-11976 | google-analytics-premium | critical | MonsterInsights Pro 10.2.0 shipped from a compromised update bucket: backdoored class-system-check.php hijacks the MonsterInsights/ExactMetrics update channel to an attacker server… | 2026-08-07 |
| CVE-2026-9205 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-9196 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-9130 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-9081 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8478 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8470 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8446 | Langflow | critical | Covered by the Langflow batch fix for CVE-2026-8182 | 2026-08-06 |
| CVE-2026-8183 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-8182 | Langflow | critical | Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixed in the same range | 2026-08-06 |
| CVE-2026-7869 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-7658 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-7657 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-7646 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-68746 | livebook | critical | Reported by NewScan's unauthenticated interface: Unauthenticated Livebook notebook server | 2026-08-06 |
| CVE-2026-56164 | Microsoft SharePoint Server | critical | SharePoint Server on-premises remote code execution - actively exploited July 2026, chained for IIS machine-key theft | 2026-08-06 |
| CVE-2026-45659 | Microsoft SharePoint Server | critical | SharePoint Server on-premises remote code execution - actively exploited July 2026 | 2026-08-06 |
| CVE-2026-41940 | cPanel / WHM | critical | cPanel / WHM authentication bypass - unauthenticated administrative control of the hosting server, all supported versions | 2026-08-06 |
| CVE-2026-35616 | FortiClient EMS | critical | FortiClient EMS improper access control - unauthenticated code/command execution via crafted requests | 2026-08-06 |
| CVE-2026-32201 | Microsoft SharePoint Server | critical | SharePoint Server spoofing via improper input validation - a manipulated Referer plus a malformed query string bypasses the front-end authorization check | 2026-08-06 |
| CVE-2026-21643 | FortiClient EMS | critical | FortiClient EMS 7.4.4 pre-authentication SQL injection in the management server | 2026-08-06 |
| CVE-2026-18577 | N-able N-central | critical | N-able N-central authentication bypass - unauthenticated administrative control of the RMM server, and therefore of every endpoint it manages | 2026-08-06 |
| CVE-2026-17633 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17632 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17630 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17625 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17624 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-17623 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-16232 | Check Point Security Gateway | critical | Check Point SmartConsole/management authentication bypass - exploited in the wild | 2026-08-06 |
| CVE-2026-10547 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2026-10128 | Langflow | critical | Reported by NewScan's component version range: Langflow 1.0.0 - 1.10.3: unauthenticated remote code execution in two HTTP requests, plus 20 further IBM Langflow OSS advisories fixe… | 2026-08-06 |
| CVE-2025-64446 | FortiWeb | critical | FortiWeb path traversal + authentication bypass - crafted HTTP(S) runs administrative commands and creates admin accounts on the WAF itself | 2026-08-06 |
| CVE-2025-61882 | Oracle E-Business Suite | critical | Oracle E-Business Suite pre-auth RCE in the internet-facing web tier - the Cl0p mass-extortion campaign (CVSS 9.8) | 2026-08-06 |
| CVE-2025-59287 | Microsoft WSUS | critical | Windows Server Update Services unauthenticated deserialization -> RCE as SYSTEM (CVSS 9.8) | 2026-08-06 |
| CVE-2025-5777 | Citrix NetScaler ADC/Gateway | critical | CitrixBleed 2: out-of-bounds memory disclosure on the login endpoint leaks session tokens, replayed to hijack sessions and bypass MFA (CVSS 9.3) | 2026-08-06 |
| CVE-2025-49844 | Redis | critical | RediShell: Lua use-after-free reachable from a crafted EVAL script -> remote code execution (CVSS 10.0) | 2026-08-06 |
| CVE-2025-20333 | Cisco ASA/FTD WebVPN | critical | Cisco ASA/FTD VPN web server buffer overflow - unauthenticated root RCE (ArcaneDoor-class; CISA ED 25-03) | 2026-08-06 |
| CVE-2025-10035 | GoAnywhere MFT | critical | GoAnywhere MFT License Servlet deserialization -> command injection, unauthenticated with a forged license-response signature (CVSS 10.0) | 2026-08-06 |
| CVE-2026-49331 | HTTP | high | Reported by NewScan's named-CVE check: test_header_trust | 2026-08-06 |
| CVE-2026-42586 | Redis | high | Reported by NewScan's named-CVE check: test_redis_injection | 2026-08-06 |
| CVE-2026-25589 | RedisBloom | high | Invalid memory access in RESTORE when used with the RedisBloom module -> potential remote code execution | 2026-08-06 |
| CVE-2026-25588 | RedisTimeSeries | high | Invalid memory access in RESTORE when used with the RedisTimeSeries module -> potential remote code execution | 2026-08-06 |
| CVE-2026-25243 | Redis | high | Invalid memory access in the RESTORE command from a crafted serialized payload -> remote code execution | 2026-08-06 |
| CVE-2026-23479 | Redis | high | Use-after-free in the unblock-client flow -> remote code execution | 2026-08-06 |
| CVE-2026-0257 | PaloAlto GlobalProtect | high | PAN-OS GlobalProtect authentication bypass - an attacker establishes VPN connections without valid credentials | 2026-08-06 |
| CVE-2025-32023 | Redis | high | Hyperloglog out-of-bounds write from a crafted hyperloglog value -> remote code execution | 2026-08-06 |
| CVE-2025-20362 | Cisco ASA/FTD WebVPN | high | Cisco ASA/FTD WebVPN unauthorized access to restricted URL endpoints - chained with CVE-2025-20333 for pre-auth RCE | 2026-08-06 |
| CVE-2024-55656 | RedisBloom | high | RedisBloom integer overflow via CMS.INITBYDIM with large WIDTH/DEPTH -> heap overflow, potential remote code execution | 2026-08-06 |
| CVE-2024-51737 | RediSearch | high | RediSearch integer overflow via crafted FT.SEARCH/FT.AGGREGATE LIMIT or KNN arguments -> heap overflow, potential remote code execution | 2026-08-06 |
| CVE-2024-51480 | RedisTimeSeries | high | RedisTimeSeries integer overflow via crafted TS.QUERYINDEX/TS.MGET/TS.MRANGE/TS.MREVRANGE arguments -> heap overflow, potential remote code execution | 2026-08-06 |
| CVE-2024-46981 | Redis | high | Lua use-after-free (garbage-collector manipulation) -> remote code execution | 2026-08-06 |
| CVE-2024-31449 | Redis | high | Lua library stack overflow via a crafted EVAL script -> remote code execution as the Redis process | 2026-08-06 |
| CVE-2026-23631 | Redis | medium | Lua use-after-free via master-replica synchronization -> remote code execution | 2026-08-06 |
| CVE-2026-70494 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70493 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70492 | Open WebUI | high | Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in the web loader and vega renderer, cross-tenant re… | 2026-08-05 |
| CVE-2026-70491 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70490 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70489 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70488 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70487 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70486 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70485 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70484 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70483 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70482 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70481 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70480 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-70479 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-54020 | Open WebUI | high | Reported by NewScan's component version range: Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in th… | 2026-08-05 |
| CVE-2026-67200 | Rocket.Chat | critical | Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read | 2026-08-04 |
| CVE-2026-56845 | Rocket.Chat | critical | Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read | 2026-08-04 |
| CVE-2021-43798 | Rocket.Chat | critical | Reported by NewScan's exposure path probe: Unauthenticated path traversal - arbitrary file read | 2026-08-04 |
| CVE-2026-69243 | aiohttp | medium | aiohttp HTTP parser request smuggling (WebSocket upgrade handling) | 2026-08-04 |
| CVE-2026-8763 | Bouncy Castle | critical | Bouncy Castle for Java certificate/signature verification bypasses (X.509 name-constraint bypass, CMS zero-signer accept, RSA PKCS#1 hash truncation) plus unbounded-KDF DoS | 2026-08-03 |
| CVE-2026-59652 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59648 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59647 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59643 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59640 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-59639 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-58063 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-15055 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-13586 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2026-12860 | Bouncy Castle | critical | Covered by the Bouncy Castle batch fix for CVE-2026-8763 | 2026-08-03 |
| CVE-2024-45519 | Zimbra Collaboration | critical | Zimbra postjournal service command injection - unauthenticated RCE via crafted SMTP message | 2026-08-02 |
| CVE-2024-40766 | SonicWall SMA/SSL-VPN | critical | SonicOS management access-control flaw - unauthorized resource access / firewall crash | 2026-08-02 |
| CVE-2024-4040 | CrushFTP | critical | CrushFTP VFS sandbox escape via server-side template injection - unauthenticated file read / RCE | 2026-08-02 |
| CVE-2024-38475 | Apache httpd | critical | Apache mod_rewrite improper substitution escaping - source disclosure and code execution via crafted URLs | 2026-08-02 |
| CVE-2024-36401 | GeoServer | critical | GeoServer unauthenticated RCE - OGC request property names evaluated as XPath expressions | 2026-08-02 |
| CVE-2024-23897 | Jenkins | critical | Jenkins CLI arbitrary file read via expandAtFiles - reads secrets, then full takeover | 2026-08-02 |
| CVE-2024-1709 | ConnectWise ScreenConnect | critical | ScreenConnect SetupWizard authentication bypass - create an administrator, then RCE | 2026-08-02 |
| CVE-2023-50164 | Apache Struts | critical | Struts file-upload path traversal -> upload a webshell (RCE) | 2026-08-02 |
| CVE-2023-35078 | Ivanti EPMM / MobileIron Core | critical | Ivanti EPMM unauthenticated API access - read/modify enrolled-device and user data | 2026-08-02 |
| CVE-2023-29300 | Adobe ColdFusion | critical | ColdFusion WDDX deserialization - unauthenticated remote code execution | 2026-08-02 |
| CVE-2023-26360 | Adobe ColdFusion | critical | ColdFusion improper access control / deserialization - unauthenticated arbitrary file read and RCE | 2026-08-02 |
| CVE-2023-25690 | Apache httpd | critical | Apache mod_proxy HTTP request smuggling via a RewriteRule/ProxyPassMatch substitution | 2026-08-02 |
| CVE-2023-22518 | Atlassian Confluence | critical | Confluence improper authorization - unauthenticated restore/takeover of the instance | 2026-08-02 |
| CVE-2023-22515 | Atlassian Confluence | critical | Confluence broken access control - unauthenticated administrator account creation | 2026-08-02 |
| CVE-2023-20198 | Cisco IOS XE Web UI | critical | IOS XE web UI privilege escalation - unauthenticated admin account creation (mass implant campaign) | 2026-08-02 |
| CVE-2022-37042 | Zimbra Collaboration | critical | Covered by the Zimbra Collaboration batch fix for CVE-2022-27925 | 2026-08-02 |
| CVE-2022-28346 | Django | critical | Django SQL injection via crafted dictionary expansion in QuerySet.annotate()/aggregate() | 2026-08-02 |
| CVE-2022-27925 | Zimbra Collaboration | critical | Zimbra mboximport archive extraction path traversal -> RCE (chained with CVE-2022-37042 auth bypass) | 2026-08-02 |
| CVE-2022-26134 | Atlassian Confluence | critical | Confluence OGNL injection - unauthenticated remote code execution | 2026-08-02 |
| CVE-2022-1040 | Sophos Firewall | critical | Sophos Firewall User Portal/Webadmin authentication bypass -> RCE | 2026-08-02 |
| CVE-2021-45046 | Log4j | critical | Log4j Thread Context lookup bypass of the 2.15.0 fix - RCE in some configurations | 2026-08-02 |
| CVE-2021-41773 | Apache httpd | critical | Apache path traversal outside the document root (cgi-bin -> RCE) | 2026-08-02 |
| CVE-2021-40539 | ManageEngine ADSelfService Plus | critical | ADSelfService Plus REST API authentication bypass -> remote code execution | 2026-08-02 |
| CVE-2021-22005 | VMware vCenter Server | critical | vCenter Analytics service arbitrary file upload -> RCE | 2026-08-02 |
| CVE-2021-21972 | VMware vCenter Server | critical | vCenter vRealize Operations plugin unauthenticated file upload -> RCE | 2026-08-02 |
| CVE-2021-20016 | SonicWall SMA/SSL-VPN | critical | SonicWall SMA100 SQL injection - unauthenticated credential/session access | 2026-08-02 |
| CVE-2020-14882 | Oracle WebLogic Server | critical | WebLogic administration console path-traversal authentication bypass -> RCE | 2026-08-02 |
| CVE-2020-12271 | Sophos Firewall | critical | Sophos XG SQL injection -> remote code execution (Asnarok) | 2026-08-02 |
| CVE-2019-7609 | Kibana | critical | Kibana Timelion prototype pollution -> arbitrary code execution as the Kibana process | 2026-08-02 |
| CVE-2019-6340 | Drupal | critical | Drupal RESTful Web Services unsafe deserialization -> remote code execution | 2026-08-02 |
| CVE-2018-7600 | Drupal | critical | Drupalgeddon2 - unauthenticated remote code execution via Form API render arrays | 2026-08-02 |
| CVE-2018-12613 | phpMyAdmin | critical | phpMyAdmin file inclusion via the index.php target parameter -> code execution | 2026-08-02 |
| CVE-2017-5638 | Apache Struts | critical | Struts Jakarta multipart parser OGNL injection - unauthenticated RCE via the Content-Type header (Equifax) | 2026-08-02 |
| CVE-2017-10271 | Oracle WebLogic Server | critical | WebLogic WLS-WSAT XML deserialization - unauthenticated RCE | 2026-08-02 |
| CVE-2014-0160 | OpenSSL | critical | Heartbleed - TLS heartbeat over-read leaks up to 64KB of process memory (keys, sessions, credentials) | 2026-08-02 |
| CVE-2026-68578 | Model Context Protocol | high | Reported by NewScan's named-CVE check: scan_mcp | 2026-08-02 |
| CVE-2024-38816 | Spring Framework | high | Spring path traversal - functional web resource handlers serve files outside the configured location | 2026-08-02 |
| CVE-2024-29041 | Express | high | Express open redirect - res.location()/res.redirect() accept a malformed URL that browsers follow off-site | 2026-08-02 |
| CVE-2024-24919 | Check Point Security Gateway | high | Check Point Remote Access VPN arbitrary file read (password hashes, certificates) | 2026-08-02 |
| CVE-2024-1708 | ConnectWise ScreenConnect | high | ScreenConnect path traversal - write outside the extension sandbox | 2026-08-02 |
| CVE-2024-1135 | Gunicorn | high | Gunicorn HTTP request smuggling - improper Transfer-Encoding validation desyncs it from the front-end proxy | 2026-08-02 |
| CVE-2023-38408 | OpenSSH | high | OpenSSH ssh-agent PKCS#11 provider remote code execution (agent forwarding to a hostile host) | 2026-08-02 |
| CVE-2023-35081 | Ivanti EPMM / MobileIron Core | high | Ivanti EPMM administrator path traversal - arbitrary file write (chained with CVE-2023-35078) | 2026-08-02 |
| CVE-2023-30861 | Flask | high | Flask session cookie can be cached by a proxy and served to another client (session disclosure) | 2026-08-02 |
| CVE-2023-23752 | Joomla | high | Joomla improper access check on the web-service endpoints - unauthenticated config/credential disclosure | 2026-08-02 |
| CVE-2023-20273 | Cisco IOS XE Web UI | high | IOS XE web UI command injection - root after the CVE-2023-20198 account creation | 2026-08-02 |
| CVE-2022-3602 | OpenSSL | high | OpenSSL X.509 email-address punycode buffer overflow (4-byte stack overwrite) | 2026-08-02 |
| CVE-2022-24999 | Express | high | qs prototype pollution via bracketed query keys -> denial of service | 2026-08-02 |
| CVE-2021-35042 | Django | high | Django SQL injection through QuerySet.order_by() with an unvalidated column name | 2026-08-02 |
| CVE-2024-37032 | ollama | medium | Reported by NewScan's unauthenticated interface: Unauthenticated Ollama model API | 2026-08-02 |
| CVE-2021-44832 | Log4j | medium | Log4j JDBC Appender remote code execution when an attacker controls the logging configuration | 2026-08-02 |
| CVE-2016-2107 | OpenSSL | medium | OpenSSL AES-NI CBC MAC-check padding oracle (Lucky-13 variant) - plaintext recovery | 2026-08-02 |
| CVE-2026-68771 | comfyui | critical | Reported by NewScan's unauthenticated interface: Unauthenticated ComfyUI interface | 2026-08-01 |
| CVE-2026-3141 | formgent | critical | FormGent unauthenticated arbitrary file deletion via REST API (wp-config.php -> site takeover) | 2026-08-01 |
| CVE-2026-14919 | shopmonitor | critical | ShopMonitor.io authentication bypass via email redirection -> unauthenticated administrator account takeover | 2026-08-01 |
| CVE-2026-6540 | HTTP routing | high | Reported by NewScan's named-CVE check: test_path_acl_bypass | 2026-08-01 |
| CVE-2026-53501 | Thumbor | high | Reported by NewScan's named-CVE check: test_media_proxy_ssrf | 2026-08-01 |
| CVE-2026-53500 | Thumbor | high | Reported by NewScan's named-CVE check: test_media_proxy_ssrf | 2026-08-01 |
| CVE-2026-17566 | pgadmin | high | Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable | 2026-08-01 |
| CVE-2026-17349 | pgadmin | high | Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable | 2026-08-01 |
| CVE-2026-17347 | pgadmin | high | Reported by NewScan's unauthenticated interface: Unauthenticated pgAdmin interface reachable | 2026-08-01 |
| CVE-2026-16144 | kali-forms | high | Kali Forms remote code execution via improper code-generation control | 2026-08-01 |
| CVE-2026-15988 | ai-engine | high | AI Engine cross-site request forgery -> actions as an authenticated user | 2026-08-01 |
| CVE-2026-15450 | nex-forms | high | NEX-Forms authenticated path traversal -> arbitrary file deletion | 2026-08-01 |
| CVE-2026-15414 | subscriptions-for-woocommerce | high | Subscriptions for WooCommerce authenticated privilege escalation | 2026-08-01 |
| CVE-2026-15258 | webappick-product-feed-for-woocommerce | high | Product Feed Manager for WooCommerce authenticated SQL injection | 2026-08-01 |
| CVE-2026-13609 | acf-frontend-form-element | high | Frontend Admin unauthenticated stored cross-site scripting | 2026-08-01 |
| CVE-2026-12721 | kirki | high | Kirki Customizer Framework SQL injection | 2026-08-01 |
| CVE-2026-12695 | miniorange-2-factor-authentication | high | miniOrange 2FA authentication bypass (unauthenticated MFA circumvention) | 2026-08-01 |
| CVE-2026-12251 | ultimate-member | high | Ultimate Member improper privilege management -> unauthorized access / permission elevation | 2026-08-01 |
| CVE-2021-3129 | Laravel Ignition | critical | Reported by NewScan's exposure path probe: Exposed Laravel Ignition debug handler | 2026-07-31 |
| CVE-2026-44578 | Next.js | high | Next.js May 2026 coordinated security release (13 advisories): SSRF via the middleware/proxy request path, plus middleware and proxy bypass CVE-2026-44573, cache poisoning on middl… | 2026-07-30 |
| CVE-2026-44577 | Next.js | high | Covered by the Next.js batch fix for CVE-2026-44578 | 2026-07-30 |
| CVE-2026-44573 | Next.js | high | Covered by the Next.js batch fix for CVE-2026-44578 | 2026-07-30 |
| CVE-2026-44572 | Next.js | high | Covered by the Next.js batch fix for CVE-2026-44578 | 2026-07-30 |
| CVE-2022-31129 | moment | high | moment regular-expression denial of service parsing a long attacker-supplied date string | 2026-07-30 |
| CVE-2021-23337 | lodash | high | lodash command injection via _.template's variable option | 2026-07-30 |
| CVE-2020-8203 | lodash | high | lodash prototype pollution in zipObjectDeep/set/setWith | 2026-07-30 |
| CVE-2024-21490 | Angular | medium | AngularJS regular-expression denial of service via ng-srcset with untrusted input | 2026-07-30 |
| CVE-2023-45857 | axios | medium | axios leaks the XSRF-TOKEN cookie value to a third-party host in the Authorization-style header | 2026-07-30 |
| CVE-2019-11358 | jQuery | medium | jQuery prototype pollution via $.extend(true, {}, attackerJSON) | 2026-07-30 |
| CVE-2018-14042 | Bootstrap | medium | Bootstrap XSS in data-container of the tooltip/popover plugin | 2026-07-30 |
| CVE-2026-18072 | advanced-responsive-video-embedder | critical | ARVE hardcoded-backdoor authentication bypass -> admin takeover (malicious release) | 2026-07-29 |
| CVE-2026-14512 | IBM WebSphere Application Server | critical | WebSphere pre-authentication unsafe deserialization -> auth bypass / RCE | 2026-07-29 |
| CVE-2026-14446 | IBM WebSphere Application Server | critical | WebSphere admin-console broken access control -> privilege escalation | 2026-07-29 |
| CVE-2026-13423 | streamit | critical | Streamit theme unauthenticated AJAX arbitrary-function call -> privilege escalation / RCE | 2026-07-29 |
| CVE-2026-16498 | Model Context Protocol | high | Reported by NewScan's named-CVE check: test_mcp_session_isolation | 2026-07-29 |
| CVE-2026-16723 | Fastjson | high | Reported by NewScan's named-CVE check: test_fastjson_rce | 2026-07-27 |
| CVE-2025-3248 | Langflow | critical | Langflow before 1.3.0: unauthenticated remote code execution via POST /api/v1/validate/code | 2026-07-23 |
| CVE-2026-0770 | Langflow | high | Reported by NewScan's named-CVE check: test_langflow_rce | 2026-07-23 |
| CVE-2026-42533 | nginx | critical | nginx script-engine capture/map heap overflow (DoS; RCE where ASLR bypassable) | 2026-07-21 |
| CVE-2025-55752 | Apache Tomcat | critical | Tomcat rewrite dir-traversal -> RCE | 2026-07-21 |
| CVE-2025-29927 | Next.js | critical | Next.js middleware authorization bypass - the internal x-middleware-subrequest header skips middleware entirely | 2026-07-21 |
| CVE-2024-34351 | Next.js | high | Next.js Server Actions SSRF - a crafted Host header makes the server fetch an attacker-chosen origin | 2026-07-21 |
| CVE-2026-63030 | WordPress | critical | WP2Shell: REST API batch-route confusion -> SQLi (CVE-2026-60137) -> unauthenticated RCE | 2026-07-19 |
| CVE-2026-60137 | WordPress | critical | Covered by the WordPress batch fix for CVE-2026-63030 | 2026-07-19 |
| CVE-2021-44228 | Log4j | critical | Log4Shell - JNDI lookup in a logged string gives unauthenticated remote code execution | 2026-07-17 |
| CVE-2022-42889 | Apache Commons Text | high | Reported by NewScan's named-CVE check: test_text4shell | 2026-07-17 |
| CVE-2024-3400 | PaloAlto GlobalProtect | critical | PAN-OS GlobalProtect command injection -> pre-auth RCE | 2026-07-13 |
| CVE-2024-21887 | Ivanti Connect Secure | critical | Ivanti Connect Secure command injection (chained -> pre-auth RCE) | 2026-07-13 |
| CVE-2024-21762 | FortiOS SSL-VPN | critical | FortiOS SSL-VPN out-of-bounds write -> pre-auth RCE | 2026-07-13 |
| CVE-2023-4966 | Citrix NetScaler ADC/Gateway | critical | Citrix Bleed: sensitive session-token disclosure | 2026-07-13 |
| CVE-2023-46747 | F5 BIG-IP | critical | F5 BIG-IP Traffic Management UI auth bypass -> RCE | 2026-07-13 |
| CVE-2023-35708 | MOVEit Transfer | critical | MOVEit Transfer SQL injection -> privilege escalation | 2026-07-13 |
| CVE-2023-35036 | MOVEit Transfer | critical | MOVEit Transfer SQL injection (follow-up) | 2026-07-13 |
| CVE-2023-34362 | MOVEit Transfer | critical | MOVEit Transfer SQL injection -> RCE (Cl0p mass-exploitation) | 2026-07-13 |
| CVE-2023-0669 | GoAnywhere MFT | critical | GoAnywhere MFT deserialization -> RCE (Cl0p) | 2026-07-13 |
| CVE-2022-1388 | F5 BIG-IP | critical | F5 BIG-IP iControl REST authentication bypass -> RCE | 2026-07-13 |
| CVE-2021-34473 | Microsoft Exchange OWA | critical | ProxyShell: pre-auth RCE | 2026-07-13 |
| CVE-2021-26855 | Microsoft Exchange OWA | critical | ProxyLogon: pre-auth SSRF | 2026-07-13 |
| CVE-2023-46805 | Ivanti Connect Secure | high | Ivanti Connect Secure authentication bypass | 2026-07-13 |
| CVE-2025-14847 | MongoDB | high | MongoBleed: unauthenticated zlib-decompression heap memory disclosure | 2026-07-11 |
| CVE-2020-25213 | wp-file-manager | critical | WP File Manager unauthenticated arbitrary file upload -> RCE | 2026-07-07 |
| CVE-2017-1001000 | WordPress | critical | WordPress REST API unauthenticated content injection / privilege escalation | 2026-07-07 |
| CVE-2017-9066 | WordPress | high | WordPress SSRF via HTTP request handling (unpatched pre-4.7.5 branch) | 2026-07-07 |
| CVE-2025-24813 | Apache Tomcat | critical | Tomcat partial-PUT deserialization RCE | 2026-06-29 |
| CVE-2024-6387 | OpenSSH | critical | regreSSHion: unauthenticated RCE in sshd | 2026-06-29 |
| CVE-2024-4577 | PHP | critical | PHP-CGI argument injection → RCE (Windows) | 2026-06-29 |
| CVE-2022-22965 | Spring Framework | critical | Spring4Shell RCE via data binding | 2026-06-29 |
| CVE-2021-42013 | Apache httpd | critical | Apache path traversal → RCE | 2026-06-29 |
| CVE-2021-23017 | nginx | critical | nginx resolver off-by-one heap overwrite (RCE) | 2026-06-29 |
| CVE-2024-49767 | Werkzeug | high | Werkzeug multipart resource exhaustion | 2026-06-29 |
| CVE-2023-25577 | Werkzeug | high | Werkzeug multipart DoS (resource exhaustion) | 2026-06-29 |
| CVE-2021-40438 | Apache httpd | high | mod_proxy SSRF | 2026-06-29 |
| CVE-2020-11022 | jQuery | medium | jQuery htmlPrefilter XSS | 2026-06-29 |
| CVE-2019-8331 | Bootstrap | medium | Bootstrap XSS in tooltip/popover data-template | 2026-06-29 |
| CVE-2018-2783 | Angular | medium | AngularJS (1.x) is end-of-life; multiple sandbox-escape XSS | 2026-06-29 |
No CVE matches that filter.
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →