- CVE-2026-62668 - Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols
- CVE-2026-62670 - Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny)
- CVE-2026-19672 - tarfile extraction filter bypass allows creation of directories outside the destination
- CVE-2026-61842 - Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)
- CVE-2026-61690 - Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits
- CVE-2026-61607 - Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer
- CVE-2026-76614 - OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore
- CVE-2026-75956 - Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3
- CVE-2026-76203 - CSS sanitizer bypass in Pentestify report themes allows forced outbound requests
- CVE-2026-75954 - Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3
- CVE-2026-75955 - Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3
- CVE-2026-75950 - Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3
- CVE-2026-75951 - Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
- CVE-2026-75953 - Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3
- CVE-2026-75949 - Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3
- CVE-2026-75952 - Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3
- CVE-2026-71961 - Cudy WR3000 2.0 OS Command Injection via Mesh MQTT Command Handler
- CVE-2026-71176 - Dell OpenManage Enterprise SQL Injection Vulnerability
- CVE-2026-71960 - Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
- CVE-2026-67266 - Dell Command Update Incorrect Authorization Elevation of Privilege Vulnerability
- CVE-2026-67267 - Dell Command Update Information Disclosure Vulnerability
- CVE-2026-67268 - Dell Command Update XML External Entity Injection Vulnerability
- CVE-2026-58565 - Dell Command Update Missing Authorization Vulnerability
- CVE-2026-58562 - Dell Command Update Missing Authorization Vulnerability
- CVE-2026-58564 - Dell Command Update Incorrect Default Permissions Vulnerability
- CVE-2026-54796 - Dell OpenManage Enterprise OS Command Injection Vulnerability
- CVE-2026-65612 - Shell Command Injection in nnn
- CVE-2026-65611 - Shell Command Injection in nnn
- CVE-2026-65610 - Numeric Truncation Error in nnn
- CVE-2026-65609 - Out-of-bounds write in nnn
- CVE-2026-76235 - Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html
- CVE-2026-73394 - WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability
- CVE-2026-73387 - WordPress Resido theme <= 1.5 - Local File Inclusion vulnerability
- CVE-2026-73388 - WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability
- CVE-2026-73389 - WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability
- CVE-2026-73390 - WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability
- CVE-2026-73391 - WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability
- CVE-2026-73385 - WordPress Outranking plugin Options plugin <= 1.1.3 - Broken Access Control vulnerability
- CVE-2026-73386 - WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability
- CVE-2026-73347 - WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability
- CVE-2026-73354 - WordPress SimplyRETS Real Estate IDX plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-73363 - WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access Control vulnerability
- CVE-2026-73364 - WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability
- CVE-2026-73384 - WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure vulnerability
- CVE-2026-73182 - WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-73183 - WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability
- CVE-2026-73184 - WordPress Global Gallery plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-73185 - WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability
- CVE-2026-66596 - WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-66613 - WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability
- CVE-2026-66668 - WordPress Community by PeepSo plugin <= 9.0.5.2 - SQL Injection vulnerability
- CVE-2026-67363 - Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-67364 - Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2
- CVE-2026-61986 - WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-32552 - WordPress YITH WooCommerce Membership Premium plugin <= 2.33.0 - SQL Injection vulnerability
- CVE-2026-16440 - Eclipse OpenJ9 Stack Overflow Vulnerability
- CVE-2026-76166 - Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast datagram
- CVE-2026-76164 - Authenticated Server-Side Request Forgery in AIL Framework Crawler Allows Access to Internal Network Resources
- CVE-2026-75900 - Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch
- CVE-2026-58083 - Use-after-free in kqueue copy-on-fork
- CVE-2026-58084 - Kernel stack disclosure via timer_settime(2)
- CVE-2026-58085 - Missing MAC validation in wg(4) packet decryption
- CVE-2026-58086 - ktrace(2) privilege incorrectly validated in jails
- CVE-2026-58087 - Heap out-of-bounds access in semctl(2)
- CVE-2026-58088 - Race condition in ELF core dump segment counting
- CVE-2026-75589 - Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify
- CVE-2026-58082 - Stack based buffer overflow in iconv(3)
- CVE-2026-58081 - Heap based buffer overflow in iconv(3)
- CVE-2026-72889 - Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify
- CVE-2026-75981 - TranslatePress – Translate Multilingual sites with AI Translation <= 3.2.5 - Unauthenticated Stored Cross-Site Scripting
- CVE-2026-49423 - Remote DOS via uninitialized memory access in KTLS receive
- CVE-2026-15446 - EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content
- CVE-2026-15780 - WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter
- CVE-2026-49425 - Kernel stack disclosure in 32-bit compatibility support
- CVE-2026-49424 - Kernel stack disclosure in Linux compatibility layer
- CVE-2026-8810 - HDD Password leakage vulnerability
- CVE-2026-49428 - posixshm: system calls can incorrectly free memory of largepage objects
- CVE-2026-49421 - unlinkat(2) ignores AT_RESOLVE_BENEATH flag
- CVE-2026-49422 - Use-after-free in TCP RACK stack option handler
- CVE-2026-49426 - Incorrect audit records for ptrace(2) syscall requests
- CVE-2026-49427 - posixshm: largepage shared memory objects not explicitly wired
- CVE-2026-19417 - KiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR
- CVE-2026-19709 - Membership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass
- CVE-2026-19782 - WPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_users
- CVE-2026-19842 - SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite
- CVE-2026-49420 - Buffer overflow in libalias RTSP handler
- CVE-2026-19416 - KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR
- CVE-2026-70408 - acmailer Improper Authorization Vulnerability
- CVE-2026-66358 - acmailer Cross-Site Scripting Vulnerability
- CVE-2026-49419 - Jail reference count underflow
- CVE-2026-49415 - Local privilege escalation via execve(2) TOCTOU race
- CVE-2026-49418 - Use-after-free in device pager page list
- CVE-2026-19942 - Atarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta
- CVE-2026-49431 - Incorrect user validation in ZFS_IOC_SET_PROP ioctl
- CVE-2026-49430 - Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl
- CVE-2026-49429 - Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl
- CVE-2026-76050 - SourceCodester Simple Online Food Ordering System ajax.php delete_menu sql injection
- CVE-2026-76008 - Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow
- CVE-2026-76014 - BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference
- CVE-2026-76048 - SourceCodester Simple Online Food Ordering System ajax.php login sql injection