- CVE-2026-64852 - Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account
- CVE-2026-64851 - Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers
- CVE-2026-64850 - Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
- CVE-2026-63407 - Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses
- CVE-2026-62673 - Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
- CVE-2026-62666 - Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super
- CVE-2026-62667 - Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL
- CVE-2026-53451 - Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution
- CVE-2026-52792 - Algernon: Server-side script source disclosure on Windows via NTFS filename
- CVE-2026-52889 - Formie: Server-Side Template Injection in Formie Hidden field defaults
- CVE-2026-49283 - SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
- CVE-2026-49255 - electerm: Command Injection in File System Operations (rmrf, mv, cp)
- CVE-2026-47187 - SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write
- CVE-2026-45272 - MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File
- CVE-2026-45273 - MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint
- CVE-2026-44829 - Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename
- CVE-2026-16816 - Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-76243 - stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth
- CVE-2026-76244 - stigmem-node Insecure Federation Transport Configuration
- CVE-2026-76242 - stigmem Federation Peer Registration Authentication Bypass
- CVE-2026-76237 - stigmem before 0.9.0a12 Cross-Tenant BOLA via quarantine
- CVE-2026-76234 - libcrux before 0.0.6 Cryptographic Implementation Bug Fixes
- CVE-2026-76229 - Renovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomize
- CVE-2026-76230 - Renovate 35.63.0 before 40.33.0 Command Injection via npm
- CVE-2026-76231 - Renovate 32.135.0 before 40.33.0 Command Injection via hermit
- CVE-2026-76232 - Renovate 31.51.0 before 40.33.0 Command Injection via helmv3
- CVE-2026-76233 - Renovate 39.53.0 before 40.33.0 Command Injection via gleam manager
- CVE-2026-76225 - ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV
- CVE-2026-76228 - Renovate before 42.68.5 Remote Code Execution via Gradle Wrapper
- CVE-2026-76220 - GitPython before 3.1.58 Command Execution via split_single_char_options
- CVE-2026-76221 - GitPython before 3.1.58 Config Injection via option-name
- CVE-2026-76222 - GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name
- CVE-2026-76219 - GitPython before 3.1.58 Arbitrary File Overwrite via read-tree
- CVE-2026-76224 - ArcadeDB before 26.8.1 Remote Code Execution via Groovy Fallback
- CVE-2026-76214 - phpMyFAQ before 4.1.7 WebAuthn Replay Attack via Challenge
- CVE-2026-76213 - phpMyFAQ before 4.1.7 2FA Brute-Force via Session-Scoped Throttle
- CVE-2026-76207 - phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie
- CVE-2026-76208 - phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP
- CVE-2026-76205 - phpMyFAQ before 4.1.7 SQL Injection via Glossary
- CVE-2026-75918 - phpMyFAQ before 4.1.7 Authentication Bypass via Tracking File
- CVE-2026-75916 - SiYuan XSS-to-RCE via unescaped block metadata in hint popup
- CVE-2026-75917 - SiYuan before v3.7.4 XSS-to-RCE via pathName.ts
- CVE-2026-19490 - NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
- CVE-2026-19489 - NetScaler ADC and NetScaler Gateway Information Disclosure Vulnerability
- CVE-2026-12983 - Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
- CVE-2026-13169 - Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR
- CVE-2026-11565 - Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
- CVE-2026-15315 - Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C200
- CVE-2026-73930 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73931 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73929 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73921 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73922 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73924 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73925 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73917 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73920 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73912 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73916 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73905 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-71167 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73865 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-73866 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-71159 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-71164 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-71166 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-71155 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-71150 - Vulnerability in the Oracle Hyperion Financial Man
- CVE-2026-71152 - Vulnerability in the Helidon product of Oracle Fus
- CVE-2026-71131 - Vulnerability in the Oracle VM VirtualBox product
- CVE-2026-75936 - Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java
- CVE-2026-75935 - Memory-amplification denial of service via declared-length preallocation in Amazon ion-java
- CVE-2025-9210 - Missing JSON Web Token signature validation in Otalio Ship Property Management System
- CVE-2026-50161 - libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow
- CVE-2026-50143 - Actor MCP path authority injection leaks Apify token
- CVE-2026-48508 - Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission
- CVE-2026-44472 - Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge
- CVE-2026-75625 - Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass
- CVE-2026-71879 - Authentication bypass in Integrated Publishing Toolkit
- CVE-2026-71878 - Authentication bypass in Integrated Publishing Toolkit
- CVE-2026-66780 - Submariner-operator: submariner-operator: flat broker trust model grants every spoke full crud on all endpoints, secrets, and endpointslices in broker namespace
- CVE-2026-67262 - Dell PowerStore Missing Authorization Vulnerability
- CVE-2026-75897 - Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards
- CVE-2026-70415 - Dell PowerStore NFS/RPC Buffer Overflow
- CVE-2026-66783 - Submariner-operator: submariner-operator: arbitrary image override enables privileged code execution on every node
- CVE-2026-67271 - Dell PowerStore SMB/CIFS Out-of-Bounds Write Vulnerability
- CVE-2026-54730 - authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView
- CVE-2026-57580 - authentik: Account Takeover via SAML NameID Comment Truncation
- CVE-2026-52723 - ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust
- CVE-2026-61574 - authentik RAC: access any endpoint via an unrelated application
- CVE-2026-49225 - Vvveb product revision authorization bypass allows Vendors to read, restore, or delete other Vendors' product revisions
- CVE-2026-49228 - Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products
- CVE-2026-18963 - Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2026-49224 - Vvveb post revision authorization bypass allows Authors to read, restore, or delete other Authors' post revisions
- CVE-2026-12564 - Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf
- CVE-2026-75926 - Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant
- CVE-2026-75914 - CodeWhale before 0.8.64 Path Traversal via image_analyze symlink
- CVE-2026-75915 - CodeWhale before 0.8.64 Environment Variable Leak via js_execution
- CVE-2026-75913 - CodeWhale before 0.8.64 Argument Injection via git_show
- CVE-2026-75912 - CodeWhale before 0.8.64 Argument Injection via git_blame