Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 13 August 2026
RSS1404 vulnerabilities published on 13 August 2026
Severity:
Budibase before 3.40.0: Unauthenticated SQL Injection via Webhook
CVE-2026-72851
GHSA-x7h8-ww3q-xv7c
Budibase, a low-code platform, has a security issue that allows attackers to inject malicious SQL code without being authenticated. This could lead to sensitive data being stolen, modified, or permane...
9.0
WP BASE Booking versions <= 6.3.0 allow hackers to run code
CVE-2026-61962
The WP BASE Booking plugin has a security issue that allows an attacker to execute malicious code on your website without needing a password. This could lead to unauthorized access, data theft, or oth...
10.0
QA Analytics Remote Code Execution Risk Through Unauthenticated Access
CVE-2026-27544
A security flaw in QA Analytics versions up to 5.2.0.0 allows attackers to run malicious code without needing a password. This puts sensitive data at risk and could lead to system compromise. Update t...
10.0
Priority - CWE-287: Improper Authentication
CVE-2026-59500
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft ...
10.0
Link Factory WordPress Plugin - Unsecured Admin Access
CVE-2026-15413
The Link Factory WordPress plugin contains a hidden backdoor that allows unauthorized access to the plugin's functionality. This could allow an attacker to manipulate or steal sensitive data, posing a...
10.0
OpenVPN Configuration File Upload Allows Unauthorized Code Execution
CVE-2026-72841
Authenticated users can upload malicious files to gain root access. This happens because the system doesn't properly check where uploaded files are saved. To fix this, administrators should update the...
9.4
OpenWrt luci-app-lxc allows unauthorized access to containers
CVE-2026-72842
A security issue affects OpenWrt's luci-app-lxc, allowing users with limited access to control containers and potentially gain root access on the device. This means that an attacker could gain control...
9.4
Trigger.dev: Attacker can hijack another project's deployment
CVE-2026-73656
GHSA-j6vv-pq9h-f4wj
An attacker with an API key for one Trigger.dev project can hijack another project's deployment by linking their own worker to it. This can cause the hijacked project to move to the wrong deployment s...
9.9
Argo Workflows: Incomplete Fix for Security Bypass
CVE-2026-54526
GHSA-48p8-g2fx-3wwm
GO-2026-6223
Argo Workflows versions before 3.7.15 and 4.0.6 have a security issue. This issue allows attackers to inject malicious code into a workflow, potentially giving them control over the workflow's environ...
8.9
AgenticSeek Unprotected API Allows Code Execution
CVE-2026-72776
AgenticSeek's API endpoint is accessible to anyone on the network, allowing an attacker to execute arbitrary commands on the system. This could result in unauthorized access to sensitive data or the c...
9.3
Filebrowser 2.63.16 allows unauthorized access to all files
CVE-2026-72839
GHSA-6759-996p-gpj6
An attacker can create an account with full access to all files on the server, even if they're not supposed to have any permissions. This is a significant risk because it allows unauthorized access to...
9.3
IBM Documentation Offline allows remote code execution
CVE-2026-17482
IBM Documentation Offline is a software that stores and displays documentation offline. If exploited, an attacker could gain unauthorized access and execute malicious code on a vulnerable system. To p...
9.8
IBM Documentation Offline allows remote code execution
CVE-2026-17481
IBM Documentation Offline, a tool for offline documentation access, has a security issue that could allow an attacker to run malicious code on your system. This is a serious issue because it could lea...
9.8
IBM i 7.x Buffer Overflow Allows Remote Code Execution
CVE-2026-17206
A buffer overflow vulnerability in IBM i 7.6, 7.5, 7.4, and 7.3 allows a remote attacker to potentially take control of your system. This is a serious issue because it could allow an attacker to execu...
9.8
IBM i Db2 Mirror SQL Injection Risk
CVE-2026-16961
IBM i systems running Db2 Mirror are vulnerable to a SQL injection attack. This could allow a remote attacker to access or modify sensitive data in the database. IBM i users should update their system...
9.8
IBM i: Unauthorized Access via NTLM Session Negotiation
CVE-2026-16867
IBM i systems with affected versions are vulnerable to unauthorized access. An attacker can exploit this vulnerability if they can trick a legitimate user into authenticating with the system. Users sh...
9.8
Tenda Router Command Injection Through Remote Access
CVE-2026-19747
Tenda routers with certain models are vulnerable to a command injection attack when accessed remotely. This means that an attacker could potentially take control of the router and disrupt its operatio...
8.9
IBM i Host Servers May Allow Unauthorized Access
CVE-2026-17197
IBM i versions 7.6, 7.5, 7.4, and 7.3 may be vulnerable to unauthorized access by a remote attacker. This means an attacker could potentially bypass security controls and gain access to sensitive data...
9.8
Velocity.js: Malicious Code Can Run on Your Server
CVE-2026-73649
GHSA-7gfh-x38p-prh3
A vulnerability in Velocity.js, a JavaScript templating engine, allows an attacker to inject and run malicious code on your server if you're using a version prior to 2.1.7. This is particularly concer...
9.8
CyberPanel WebTerminal Authentication Bypass via Websocket
CVE-2026-67614
A vulnerability in CyberPanel's WebTerminal allows attackers to bypass authentication and gain root access. This could let unauthorized users access sensitive parts of the system. CyberPanel users sho...
9.3
Gitea: Leaked Token Creates Full Access Tokens
GHSA-683j-3ff6-hh2x
CVE-2026-56654
An attacker with a restricted Gitea token can create a full-access token without knowing the account password. This happens when the attacker passes the token in a specific format in the API request. ...
8.7
Fluent Forms Pro Malicious Code Injection via Tampered Plugin
CVE-2026-73532
Fluent Forms Pro plugins may be compromised by malicious code. This can lead to unauthorized access to your website and data. To protect yourself, update to the latest version of Fluent Forms Pro and ...
9.3
Ninja Tables Pro Malicious Code Injection
CVE-2026-73533
Ninja Tables Pro, a WordPress plugin, contains a critical security flaw that allows malicious code to be injected and executed on a website. This can lead to unauthorized access, data theft, and other...
9.3
CoreDNS versions prior to 1.14.3 allow unauthorized DNS access
OESA-2026-3371
If you use CoreDNS to manage your DNS data, a security update is available to prevent unauthorized access to your DNS settings. This update is necessary to ensure that only authorized users can perfor...
9.8
CoreDNS versions before 1.14.3 allow unauthorized access
OESA-2026-3370
A security update is available for CoreDNS, a DNS server software. In previous versions, an attacker could bypass security checks and access sensitive features like zone transfers and dynamic DNS upda...
9.8