| medium |
CVE-2026-66638 — Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. |
vulnerability |
nvd |
CVE-2026-66638 |
|
2026-08-18 |
| medium |
CVE-2026-66637 — Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. |
vulnerability |
nvd |
CVE-2026-66637 |
|
2026-08-18 |
| medium |
CVE-2026-66636 — Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. |
vulnerability |
nvd |
CVE-2026-66636 |
|
2026-08-18 |
| high |
CVE-2026-66635 — Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. |
vulnerability |
nvd |
CVE-2026-66635 |
|
2026-08-18 |
| medium |
CVE-2026-66634 — Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. |
vulnerability |
nvd |
CVE-2026-66634 |
|
2026-08-18 |
| high |
CVE-2026-66633 — Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. |
vulnerability |
nvd |
CVE-2026-66633 |
|
2026-08-18 |
| high |
CVE-2026-66629 — Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. |
vulnerability |
nvd |
CVE-2026-66629 |
|
2026-08-18 |
| critical |
CVE-2026-66627 — Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. |
vulnerability |
nvd |
CVE-2026-66627 |
|
2026-08-18 |
| high |
CVE-2026-66622 — Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. |
vulnerability |
nvd |
CVE-2026-66622 |
|
2026-08-18 |
| high |
CVE-2026-66621 — Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. |
vulnerability |
nvd |
CVE-2026-66621 |
|
2026-08-18 |
| high |
CVE-2026-66620 — Editor PHP Object Injection in OptionTree <= 2.7.3 versions. |
vulnerability |
nvd |
CVE-2026-66620 |
|
2026-08-18 |
| high |
CVE-2026-66046 — Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic compl… |
vulnerability |
nvd |
CVE-2026-66046 |
|
2026-08-18 |
| low |
CVE-2026-63632 — Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From… |
vulnerability |
nvd |
CVE-2026-63632 |
|
2026-08-18 |
| high |
CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Acce… |
vulnerability |
nvd |
CVE-2026-61407 |
|
2026-08-18 |
| medium |
CVE-2026-59949 — yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementation… |
vulnerability |
nvd |
CVE-2026-59949 |
|
2026-08-18 |
| critical |
CVE-2026-59940 — Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap… |
vulnerability |
nvd |
CVE-2026-59940 |
rce |
2026-08-18 |
| high |
CVE-2026-59825 — Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from… |
vulnerability |
nvd |
CVE-2026-59825 |
|
2026-08-18 |
| high |
CVE-2026-56684 — Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey… |
vulnerability |
nvd |
CVE-2026-56684, CVE-2026-63639 |
rce |
2026-08-18 |
| high |
CVE-2026-50187 — Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the d… |
vulnerability |
nvd |
CVE-2026-50187 |
|
2026-08-18 |
| medium |
CVE-2026-50139 — goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share to… |
vulnerability |
nvd |
CVE-2026-50139 |
|
2026-08-18 |
| high |
CVE-2026-50138 — goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with Web… |
vulnerability |
nvd |
CVE-2026-50138 |
|
2026-08-18 |
| high |
CVE-2026-48798 — SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string… |
vulnerability |
nvd |
CVE-2026-48798 |
|
2026-08-18 |
| high |
CVE-2026-45733 — Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe… |
vulnerability |
nvd |
CVE-2026-45733 |
|
2026-08-18 |
| high |
CVE-2026-32553 — Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. |
vulnerability |
nvd |
CVE-2026-32553 |
|
2026-08-18 |
| high |
CVE-2026-32549 — Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. |
vulnerability |
nvd |
CVE-2026-32549 |
|
2026-08-18 |
| high |
CVE-2026-32547 — Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. |
vulnerability |
nvd |
CVE-2026-32547 |
|
2026-08-18 |
| high |
CVE-2026-32481 — Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. |
vulnerability |
nvd |
CVE-2026-32481 |
|
2026-08-18 |
| critical |
CVE-2026-32474 — Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. |
vulnerability |
nvd |
CVE-2026-32474 |
|
2026-08-18 |
| high |
CVE-2026-32473 — Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versio… |
vulnerability |
nvd |
CVE-2026-32473 |
|
2026-08-18 |
| high |
CVE-2026-32472 — Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. |
vulnerability |
nvd |
CVE-2026-32472 |
|
2026-08-18 |
| critical |
CVE-2026-32470 — Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
vulnerability |
nvd |
CVE-2026-32470, CVE-2026-73993 |
|
2026-08-18 |
| high |
CVE-2026-18534 — ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated… |
vulnerability |
nvd |
CVE-2026-18534 |
|
2026-08-18 |
| high |
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps |
threat-intel |
otx |
45.192.12.34, 209.99.184.50, 209.99.187.28, 104.251.180.179, 45.150.34.77 | b7e9072e5bda17e0…, d472e984c6e8f3d4… |
maas, octagon, android, accessibility abuse, cryptocurrency, vnc, overlay attack, banking trojan, botnet |
2026-08-18 |
| unknown |
Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities |
news |
general-news |
|
|
2026-08-18 |
| unknown |
NASA Ground Control Software Flaw Enables Unauthenticated Commands |
news |
general-news |
|
|
2026-08-18 |
| high |
CVE-2026-50575 — BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly inv… |
vulnerability |
nvd |
CVE-2026-50575 |
ransomware |
2026-08-18 |
| high |
CVE-2026-32468 — Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. |
vulnerability |
nvd |
CVE-2026-32468 |
|
2026-08-18 |
| medium |
CVE-2026-32467 — Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. |
vulnerability |
nvd |
CVE-2026-32467 |
|
2026-08-18 |
| high |
CVE-2026-32466 — Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. |
vulnerability |
nvd |
CVE-2026-32466 |
|
2026-08-18 |
| high |
CVE-2026-32465 — Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. |
vulnerability |
nvd |
CVE-2026-32465 |
|
2026-08-18 |
| high |
CVE-2026-32464 — Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. |
vulnerability |
nvd |
CVE-2026-32464 |
|
2026-08-18 |
| critical |
CVE-2026-32463 — Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. |
vulnerability |
nvd |
CVE-2026-32463 |
|
2026-08-18 |
| critical |
CVE-2026-32444 — Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. |
vulnerability |
nvd |
CVE-2026-32444 |
rce |
2026-08-18 |
| high |
CVE-2026-32333 — Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. |
vulnerability |
nvd |
CVE-2026-32333 |
|
2026-08-18 |
| high |
CVE-2026-28571 — Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. |
vulnerability |
nvd |
CVE-2026-28571 |
|
2026-08-18 |
| high |
CVE-2026-28570 — Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. |
vulnerability |
nvd |
CVE-2026-28570 |
|
2026-08-18 |
| high |
CVE-2026-28569 — Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. |
vulnerability |
nvd |
CVE-2026-28569 |
|
2026-08-18 |
| high |
CVE-2026-28568 — Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. |
vulnerability |
nvd |
CVE-2026-28568 |
|
2026-08-18 |
| high |
CVE-2026-28567 — Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. |
vulnerability |
nvd |
CVE-2026-28567 |
|
2026-08-18 |
| critical |
CVE-2026-28192 — Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. |
vulnerability |
nvd |
CVE-2026-28192 |
|
2026-08-18 |