Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 7 August 2026

RSS

522 vulnerabilities published on 7 August 2026

Severity:
Plesk XML-RPC API Allows Unauthorized Root Access
CVE-2026-64637
Plesk's XML-RPC API has a security issue that lets an authenticated reseller access the root user account without permission. This is a serious issue because it allows someone who shouldn't have acces...
9.9
LightRAG API: Unauthenticated Access to Critical Functions
CVE-2026-61808 GHSA-mmg5-8x8q-v934
The LightRAG API server is open to the internet without password protection. This allows unauthorized users to access and modify sensitive data, and potentially disrupt the service. To fix this, updat...
9.8
CodeIgniter: Malicious Files Can Be Uploaded via Client-Supplied Filenames
UBUNTU-CVE-2026-63223 CVE-2026-63223 GHSA-mmj4-63m4-r6h5
CodeIgniter, a popular web framework, had a security issue where malicious files could be uploaded if a website allowed users to choose their own filenames and store those files in a location where th...
9.8
Postiz Social Media Scheduling Tool Allows Unauthorized Access
CVE-2026-19264
An attacker can access sensitive files on the server and use this information to take control of the Postiz instance without a password. This is a serious risk because it could allow unauthorized acce...
9.3
Weaver E-cology 9.0 allows unauthorized file uploads
CVE-2022-4995
Weaver E-cology versions 9.0 to 10.51 are vulnerable to a file upload security risk. This means an attacker can upload malicious files without permission, potentially allowing them to take control of ...
9.3
Dell OpenManage Server Administrator: Unauthorized Remote Access
CVE-2026-56793
Dell OpenManage Server Administrator versions before 11.1.0.2 are at risk of unauthorized remote access. An attacker with remote access could gain access to the system without a password. Update to ve...
9.8
Apache Fory: Malicious Data Can Crash or Hijack Server
CVE-2026-71558
Apache Fory's C++ deserialization feature is affected by a security flaw. If exploited, this could cause your server to crash or allow attackers to take control of it. To fix this, upgrade to the late...
9.8
Ajax Search Lite < 4.14.5 - Unauthenticated Code Execution via Search Statistics
CVE-2026-16258
The Ajax Search Lite plugin for WordPress allows attackers to inject malicious code without a password. This can lead to unauthorized access and control of your website. Update the plugin to version 4...
9.8
WP Events Manager Paid Events Can Be Bypassed by Malicious Users
CVE-2026-14205
WP Events Manager, a popular WordPress plugin, has a security issue that allows any authenticated user to book paid events without paying. This can lead to financial losses for event organizers. To fi...
9.8
TrueBooker plugin for WordPress: Unauthorized access to user accounts
CVE-2026-14365
The TrueBooker plugin for WordPress is affected if you use it on your site. An attacker could change passwords for any user, including administrators, allowing them to gain access to those accounts. T...
9.8
TrueBooker Plugin for WordPress: Unauthenticated Password Reset
CVE-2026-14364
The TrueBooker plugin for WordPress has a security flaw that allows attackers to change anyone's password without needing a password. This means they could gain access to administrator accounts and po...
9.8
OpenYak Desktop Backend Unsecured Local Server
CVE-2026-46409 GHSA-ccxp-q2w5-27jw
OpenYak's desktop backend, used in a local workspace, allows malicious web pages to access and control the local server. This allows hackers to execute commands on the host, access sensitive data, and...
9.6
Kata Containers: Malicious files can be loaded on host systems
CVE-2026-50540 GHSA-mp2j-xm59-qfgw
Kata Containers versions prior to 4.0.0 allow a user to load any file from the host system, potentially allowing an attacker to execute malicious code on the host with root privileges. This can be exp...
9.6
TeamDavid Webbox: Server Crash from Malicious JSON
CVE-2026-54212
The TeamDavid Webbox application has a security issue that allows an attacker to crash the server by sending a specially crafted JSON message. This could lead to the server being unavailable, and pote...
9.5
TeamDavid: Server Crash from Excessively Long Form Data
CVE-2026-54211
The TeamDavid Webbox application is vulnerable to a server crash when it receives excessively long form data. This could be exploited by an attacker to shut down the server. To protect against this, i...
9.5
TeamDavid Webbox: Server Crash with Malicious File Names
CVE-2026-54210
The TeamDavid Webbox application allows an attacker to crash the server by uploading a file with a very long name. This could potentially be used to take control of the server. To fix this, update to ...
9.5
CodeIgniter 4.3.0-4.7.3: User Input Injects into SQL Queries
UBUNTU-CVE-2026-63221 CVE-2026-63221 GHSA-c9w5-rwh3-7pm9
Using CodeIgniter's deleteBatch() function between versions 4.3.0 and 4.7.3 can allow malicious users to inject their own SQL code. This could lead to unauthorized data changes or even complete databa...
9.4
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-64638 CVE-2026-64638 UBUNTU-CVE-2026-64638
A security issue in Debian Linux's package manager allows an attacker to run malicious code on a system without being authenticated. This could happen if a user installs a compromised package. To prot...
9.4
SEBLOD for Joomla - Unauthenticated File Access
CVE-2026-66914
An unauthenticated attacker can access and download files from your Joomla website. This is a serious issue because it allows an attacker to potentially steal sensitive information or disrupt your sit...
9.2
TeamDavid Webbox: Unauthenticated Server Shutdown
CVE-2026-54213
An attacker can shut down the TeamDavid Webbox server without a password, causing it to be unavailable. This is a concern because it can lead to lost productivity and revenue. To protect against this,...
9.2
TeamDavid: Unauthorized Access to Sensitive User Data
CVE-2026-54203
The TeamDavid Webbox allows unauthorized access to sensitive user information, including passwords, without needing a login. This can happen when an attacker repeatedly requests a specific URL. Update...
9.2
scimPatch allows attackers to modify system settings
GHSA-9m6g-wc8r-q59c CVE-2026-48170
The scimPatch library in Node.js versions up to 0.9.0 can be exploited by an attacker to modify system settings and potentially gain unauthorized access or disrupt system functionality. This vulnerabi...
9.1
Craft CMS: Passkey login can be reused with captured data
GHSA-wg23-69c2-gjc8
Craft CMS's passkey login system can be tricked into accepting previously captured login data, allowing an attacker to reuse a legitimate user's passkey. This is a concern because it weakens the secur...
9.1
Apache Fory: Out-of-bounds heap read when deserializing data
CVE-2026-71560
Apache Fory versions from 0.14.0 to 1.4.9 are at risk of exposing sensitive information or crashing if given a specially crafted input. To fix this, update to version 1.5.0 if you use Apache Fory C++....
9.1
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Gateways
CVE-2026-16038
The MStore API WordPress plugin allows an attacker to mark an order as paid without payment, potentially giving them free access to goods or services. This affects any sites using MStore API version 4...
9.1