CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2026-55111

    Last Modified: 31 Jul 2026

    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.

    Published: 2 Jul 2026
    7.7
    High

    CVE-2026-54401

    Last Modified: 1 Aug 2026

    A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.

    Published: 2 Jul 2026
    9.9
    Critical

    CVE-2026-54402

    Last Modified: 12 Aug 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

    Published: 2 Jul 2026
    9.9
    Critical

    CVE-2026-50747

    Last Modified: 3 Aug 2026

    A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.

    Published: 2 Jul 2026
    10
    Critical

    CVE-2026-50746

    Last Modified: 4 Aug 2026

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

    Published: 2 Jul 2026
    7.5
    High

    CVE-2026-55110

    Last Modified: 13 Aug 2026

    A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.

    Published: 2 Jul 2026
    8.8
    High

    CVE-2026-54404

    Last Modified: 3 Aug 2026

    A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.

    Published: 2 Jul 2026
    9.1
    Critical

    CVE-2026-54400

    Last Modified: 17 Aug 2026

    A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

    Published: 2 Jul 2026
    8.7
    High

    CVE-2026-54406

    Last Modified: 28 Jul 2026

    A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.

    Published: 2 Jul 2026
    9.9
    Critical

    CVE-2026-50748

    Last Modified: 17 Aug 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

    Published: 2 Jul 2026
    8.6
    High

    CVE-2026-54408

    Last Modified: 13 Aug 2026

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.

    Published: 2 Jul 2026
    7.5
    High

    CVE-2026-54409

    Last Modified: 31 Jul 2026

    A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

    Published: 2 Jul 2026
    8.6
    High

    CVE-2026-54403

    Last Modified: 4 Aug 2026

    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.

    Published: 2 Jul 2026
    7.5
    High

    CVE-2026-54405

    Last Modified: 31 Jul 2026

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.

    Published: 2 Jul 2026
    8.6
    High

    CVE-2026-54407

    Last Modified: 3 Aug 2026

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

    Published: 2 Jul 2026
    7.8
    High

    CVE-2026-12168

    Last Modified: 4 Aug 2026

    An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.

    Published: 2 Jul 2026
    5.5
    Medium

    CVE-2026-12166

    Last Modified: 3 Aug 2026

    A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests that trigger a system crash.

    Published: 2 Jul 2026
    7.8
    High

    CVE-2026-12167

    Last Modified: 4 Aug 2026

    The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that lacks appropriate access restrictions.

    Published: 2 Jul 2026
    8.7
    High

    CVE-2026-8079

    Last Modified: 2 Jul 2026

    In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.

    Published: 2 Jul 2026
    8.7
    High

    CVE-2026-9272

    Last Modified: 2 Jul 2026

    In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.

    Published: 2 Jul 2026
    9.8
    Critical

    CVE-2026-4767

    Last Modified: 29 Jul 2026

    Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.

    Published: 2 Jul 2026
    5.4
    Medium

    CVE-2026-4772

    Last Modified: 29 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.

    Published: 2 Jul 2026
    4.6
    Medium

    CVE-2026-4770

    Last Modified: 29 Jul 2026

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.

    Published: 2 Jul 2026
    9.8
    Critical

    CVE-2026-5524

    Last Modified: 2 Jul 2026

    The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin's .htaccess protection which only blocks .php files specifically. Additionally, on Nginx-based servers, the .htaccess protection is completely ineffective as Nginx does not process .htaccess files. This makes it possible for unauthenticated attackers (who can obtain a nonce from any public page containing a form) to upload executable PHP files to the publicly accessible /wp-content/uploads/de_fb_uploads/ directory and achieve Remote Code Execution by accessing the uploaded file via HTTP. The vulnerability was partially patched in version 5.1.3.

    Published: 2 Jul 2026
    5.3
    Medium

    CVE-2026-58653

    Last Modified: 2 Jul 2026

    PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation without workspace constraints.

    Published: 2 Jul 2026
    7.7
    High

    CVE-2026-58652

    Last Modified: 28 Aug 2026

    luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads the raw UCI 'script' and 'script_args' values and executes the configured path when the captive-portal auto-login branch (f_check() in travelmate-functions.sh) is reached. An attacker with delegated write permissions can set script to /bin/sh and script_args to attacker-controlled arguments, resulting in arbitrary command execution as root. Confirmed in luci-app-travelmate/travelmate 2.4.5-r3; the sink is still present in travelmate 2.4.6-1 and no patched version is known.

    Published: 2 Jul 2026
    6.4
    Medium

    CVE-2026-14449

    Last Modified: 29 Jul 2026

    u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components

    Published: 2 Jul 2026
    5.3
    Medium

    CVE-2026-57760

    Last Modified: 6 Jul 2026

    Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

    Published: 2 Jul 2026
    7.1
    High

    CVE-2026-57678

    Last Modified: 3 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS. This issue affects Slider Revolution: from 7.0.0 through 7.0.16.

    Published: 2 Jul 2026
    8.8
    High

    CVE-2026-56037

    Last Modified: 2 Jul 2026

    Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.

    Published: 2 Jul 2026
    8.8
    High

    CVE-2026-57766

    Last Modified: 2 Jul 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

    Published: 2 Jul 2026
    8.5
    High

    CVE-2026-57765

    Last Modified: 2 Jul 2026

    Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

    Published: 2 Jul 2026
    6.5
    Medium

    CVE-2026-57764

    Last Modified: 6 Jul 2026

    Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

    Published: 2 Jul 2026
    6.5
    Medium

    CVE-2026-57763

    Last Modified: 6 Jul 2026

    Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

    Published: 2 Jul 2026
    5.9
    Medium

    CVE-2026-57762

    Last Modified: 6 Jul 2026

    Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

    Published: 2 Jul 2026
    7.1
    High

    CVE-2026-57761

    Last Modified: 6 Jul 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

    Published: 2 Jul 2026
    8.8
    High

    CVE-2026-57759

    Last Modified: 2 Jul 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

    Published: 2 Jul 2026
    7.1
    High

    CVE-2026-57758

    Last Modified: 2 Jul 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

    Published: 2 Jul 2026
    7.1
    High

    CVE-2026-57757

    Last Modified: 6 Jul 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

    Published: 2 Jul 2026
    8.5
    High

    CVE-2026-57756

    Last Modified: 6 Jul 2026

    Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

    Published: 2 Jul 2026
    6.5
    Medium

    CVE-2026-57755

    Last Modified: 6 Jul 2026

    Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

    Published: 2 Jul 2026
    6.5
    Medium

    CVE-2026-57754

    Last Modified: 2 Jul 2026

    Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

    Published: 2 Jul 2026
    5.3
    Medium

    CVE-2026-57753

    Last Modified: 6 Jul 2026

    Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

    Published: 2 Jul 2026
    8.5
    High

    CVE-2026-57752

    Last Modified: 2 Jul 2026

    Contributor SQL Injection in iNET Webkit 1.2.4 versions.

    Published: 2 Jul 2026
    8.1
    High

    CVE-2026-57751

    Last Modified: 6 Jul 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

    Published: 2 Jul 2026
    5.3
    Medium

    CVE-2026-57750

    Last Modified: 6 Jul 2026

    Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

    Published: 2 Jul 2026
    7.5
    High

    CVE-2026-57749

    Last Modified: 2 Jul 2026

    Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

    Published: 2 Jul 2026
    7.5
    High

    CVE-2026-57748

    Last Modified: 6 Jul 2026

    Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

    Published: 2 Jul 2026
    6.5
    Medium

    CVE-2026-57747

    Last Modified: 2 Jul 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

    Published: 2 Jul 2026
    7.1
    High

    CVE-2026-57746

    Last Modified: 2 Jul 2026

    Subscriber Broken Access Control in Booked <= 3.0.0 versions.

    Published: 2 Jul 2026