Year Archive: 2026

EUVD Vulnerabilities (2026)

Browse security threats, CVE catalog items, and software security flaws mapped under the EUVD sequence for the year 2026.

CRITICAL (9.9) CVSS 3.1 Source: GitLab

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Aliases:
CVE-2026-78155
Published: 2026-08-23 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. ...

Aliases:
CVE-2026-78050 GHSA-j397-vxh8-xhw3
Published: 2026-08-22 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.

Aliases:
GHSA-7mjm-m5wm-mfgg CVE-2026-76605
Published: 2026-08-22 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.

Aliases:
CVE-2026-76604 GHSA-fq44-8wg9-5qfj
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.5) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

Aliases:
GHSA-gvj7-4928-2j6w CVE-2026-77992
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input fr...

Aliases:
GHSA-hpc2-mqfw-fq4q CVE-2026-4703
Published: 2026-08-22 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.

Aliases:
GHSA-p5vh-m7cp-f4v4 CVE-2026-76606
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

Aliases:
CVE-2026-76602 GHSA-pcxq-w35v-gcxv
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the...

Aliases:
GHSA-49rr-hfxh-8f4c CVE-2026-76571
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validatio...

Aliases:
CVE-2026-78003 GHSA-jr9c-873v-948h
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GoogleCloud

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal d...

Aliases:
CVE-2026-12710 GHSA-m95m-h7f9-f822
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $has...

Aliases:
CVE-2026-77414
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to a...

Aliases:
CVE-2026-77413
Published: 2026-08-21 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: GitHub_M

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model...

Aliases:
CVE-2026-61539
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: GitHub_M

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

Aliases:
CVE-2026-76904 GHSA-mqjf-5f49-2fjh
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: VulnCheck

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by st...

Aliases:
CVE-2026-39909 GHSA-fpvp-jgx3-4w9q
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: cisa-cg

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once ...

Aliases:
CVE-2026-75932 GHSA-cm72-j98h-q99g
Published: 2026-08-21 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: microsoft

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Aliases:
CVE-2026-69502 GHSA-cc49-67hv-4hv5
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: CIRCL

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the dr...

Aliases:
GHSA-gh7r-589j-33x7 CVE-2026-77812
Published: 2026-08-21 View Complete Profile →
MEDIUM (6.3) CVSS 4.0 Source: CIRCL

A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document ...

Aliases:
GHSA-q62h-w723-22p2 CVE-2026-77761
Published: 2026-08-21 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: CIRCL

A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several parsing and loadin...

Aliases:
GHSA-65gx-wjvj-88j8 CVE-2026-77755
Published: 2026-08-21 View Complete Profile →
MEDIUM (6.9) CVSS 4.0 Source: CIRCL

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the intern...

Aliases:
CVE-2026-77710 GHSA-pqpx-w6cx-7q9c
Published: 2026-08-21 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: microsoft

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Aliases:
CVE-2026-69555 GHSA-m9j2-qfhx-hm42
Published: 2026-08-20 View Complete Profile →

EUVD-2026-63693

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: microsoft

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Aliases:
CVE-2026-69836 GHSA-v6wh-624g-vvmv
Published: 2026-08-20 View Complete Profile →
CRITICAL (9.1) CVSS 4.0 Source: EEF

Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_...

Aliases:
GHSA-5x87-gf34-8ww7 CVE-2026-53424
Published: 2026-08-20 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: GitHub_M

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attri...

Aliases:
CVE-2026-55085
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-...

Aliases:
CVE-2026-72717
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-l...

Aliases:
CVE-2026-71868
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into...

Aliases:
CVE-2026-71871
Published: 2026-08-19 View Complete Profile →

EUVD-2026-62588

Actively Exploited
CRITICAL (9.5) CVSS 4.0 Source: Kaspersky

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to...

Aliases:
GHSA-f8q9-f337-2p3r CVE-2026-72530
Published: 2026-08-19 View Complete Profile →

EUVD-2026-62587

Actively Exploited
CRITICAL (9.3) CVSS 4.0 Source: Kaspersky

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by ca...

Aliases:
GHSA-xc2x-q39j-746f CVE-2026-72529
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead ...

Aliases:
GHSA-6rxv-jchw-qjv3 CVE-2026-76003
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: oracle

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthen...

Aliases:
GHSA-v3hv-vxr8-r858 CVE-2026-71152
Published: 2026-08-18 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: oracle

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. ...

Aliases:
CVE-2026-71036 GHSA-5pxc-m8gx-mp6h
Published: 2026-08-18 View Complete Profile →

EUVD-2026-58069

Actively Exploited
HIGH (8.9) CVSS 3.1 Source: mitre

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitiz...

Aliases:
GHSA-jqh7-pchh-v74j CVE-2026-73570
Published: 2026-08-13 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

Aliases:
CVE-2026-66915 GHSA-ch8m-c7x9-7r7f
Published: 2026-08-10 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: redhat

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when...

Aliases:
GHSA-7jcp-v9w4-wjmg CVE-2026-7374
Published: 2026-05-26 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulDB

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of ...

Aliases:
CVE-2026-8836 GHSA-3w8m-3w76-f6mh
Published: 2026-05-18 View Complete Profile →