Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 24 August 2026

RSS

568 vulnerabilities published on 24 August 2026

Severity:
ContextForge python sandbox can execute arbitrary code
GHSA-xm98-3vcf-fph7 CVE-2026-53710
The python sandbox used by ContextForge’s MCP server can be tricked into running any command because it exposes a function that bypasses its safety checks. An attacker could send specially crafted cod...
10.0
OpenThread can be crashed by malicious network packets
CVE-2025-36939
If someone with permission on your Thread network sends specially crafted messages, OpenThread may stop working, leading to a denial of service. The problem is caused by errors in how OpenThread proce...
10.0
miniOrange OAuth Client lets attackers take over any Joomla account
CVE-2026-77995
The miniOrange OAuth Client extension for Joomla (versions before 3.2.0) can be fooled by changing a small piece of data stored in the web browser, allowing someone to log in as any user, even an admi...
10.0
ipTIME T16000M router can be accessed without proper login
CVE-2026-78167
The T16000M router (firmware 14.20.2) has a flaw in its session‑checking routine that lets an attacker bypass the normal authentication process. This means a remote user could gain access to the devic...
9.3
UltimateAI versions up to 3.1 let attackers upload any file
CVE-2026-32559
The file‑upload feature in UltimateAI version 3.1 and earlier does not properly check what is being uploaded. A malicious user could place a harmful file on your server, potentially gaining control or...
9.9
LXD can let attacker overwrite host files as root
CVE-2026-66897 GHSA-q39m-8fx9-42fv UBUNTU-CVE-2026-66897
LXD’s template feature can be tricked into writing any file on the underlying server, even system files that require administrator rights. An attacker who can edit containers or launch a specially cra...
9.9
UTT HiPER 1250GW remote overflow lets attackers take control
CVE-2026-78169
Versions of UTT HiPER 1250GW up to 3.2.7‑210907‑180535 mishandle a specific web request, causing the system to overflow its memory. An attacker on the network can send a crafted request and potentiall...
8.6
TranslatePress up to 3.3.2 lets anyone become admin
CVE-2026-78267
The TranslatePress plugin versions up to 3.3.2 allow a person who is not logged in to gain full administrator privileges on your website. This means an attacker could change settings, install maliciou...
9.8
WP Project Manager plugin can be taken over remotely
CVE-2026-78262
Versions of the WP Project Manager plugin up to 4.0.6 let anyone on the internet send specially crafted data that can make the website run their own code. This could let attackers steal data, change s...
9.8
The Events Calendar plugin lets attackers run code remotely
CVE-2026-78265
Versions of The Events Calendar up to 6.17.2 can be tricked into loading malicious data without requiring any login. This could let an attacker execute commands on your server, potentially stealing da...
9.8
ACPT Pro plugin lets attackers run code on site
CVE-2026-32563
The Advanced Custom Post Types (ACPT) Pro plugin for WordPress up to version 2.0.63 can be tricked into executing malicious code when a low‑privilege user (subscriber) provides specially crafted input...
9.8
Apache Camel may route messages to wrong destination
CVE-2026-78329 GHSA-v7h8-xhh6-gfj4
Certain versions of Apache Camel that use the Undertow connector do not properly screen extra information attached to incoming messages. This can let a specially crafted request cause data to be sent ...
9.8
Apache Camel Websocket can misdirect client messages
CVE-2026-71300 GHSA-m5r8-w65q-8wjf
Older versions of Apache Camel that handle WebSocket connections let outside data decide which client receives a message. An attacker could hide a notification or send it to a different client they co...
9.8
DrayTek VigorSwitch allows remote code execution before login
CVE-2026-71921
Several DrayTek VigorSwitch network switches let an attacker send specially crafted data to the setget.cgi page, even before any user logs in. This can let the attacker run any command on the device w...
9.3
NetworkManager allows local user to bypass Wi‑Fi security check
DEBIAN-CVE-2026-19685 CVE-2026-19685 UBUNTU-CVE-2026-19685
The NetworkManager program on Linux does not properly limit a setting that tells the system where to look for trusted Wi‑Fi authentication files. This lets a regular user point a secure Wi‑Fi (WPA‑Ent...
9.8
DrayTek VigorAP access points let attackers run commands
CVE-2026-71914
Several DrayTek VigorAP Wi‑Fi devices can be tricked into running any code they want when they receive a specially crafted network message. An attacker from outside could gain full control of the devi...
9.3
Netis NC63 router firmware lets remote attacker run code
CVE-2026-76071
The Netis NC63 router’s firmware up to version 3.0.0.3327 can be tricked into running malicious code when a specially crafted request is sent. An attacker does not need to log in and can gain full con...
9.3
rConfig allows anyone to register as admin
GHSA-w3hx-9cxg-5ccr CVE-2026-77915
Versions of rConfig from 8.0.0 through 8.2.12 let a person who is not logged in create a new account that automatically receives administrator rights. With that access they can view saved device passw...
9.3
Netis NC63 firmware lets attacker run code via login
CVE-2026-76070
The web interface on Netis NC63 routers (up to firmware version V3.0.0.3327) can be fooled by sending an overly long, specially encoded password. This overload lets an unauthenticated remote user take...
9.3
WordPress FreightCo theme (up to 1.1.15) lets attackers run code
CVE-2026-66650
The FreightCo theme for WordPress, versions up to 1.1.15, can be accessed by anyone on the internet to inject malicious data that causes the server to execute unwanted commands. This could let a hacke...
9.8
WordPress Jawn theme allows attackers to gain admin rights
CVE-2026-66648
The Jawn theme for WordPress, in versions up to 1.4.2, can be used by anyone on the internet to take control of the site. An attacker could give themselves administrator privileges and change or steal...
9.8
WordPress WP Cafe Pro < 3.0.15 can expose server files
CVE-2026-66587
The WP Cafe Pro add‑on for WordPress, in any version older than 3.0.15, lets anyone on the internet view files stored on your web server. This could reveal sensitive information such as passwords, con...
9.8
WordPress Affiliate Pro plugin can let attackers become admin
CVE-2026-32558
The Affiliate Pro add‑on for WordPress and WooCommerce (versions up to 8.9.1) lets anyone on the internet gain full administrative control of your site. An attacker could change settings, view sensiti...
9.8
WordPress Digits plugin may let attackers become admins
CVE-2026-28165
Websites that use the Digits extra feature for WordPress, up to version 9.2, can be accessed by anyone on the internet who can then gain administrator privileges. This could let an attacker change sit...
9.8
4MOSAn GCB Doctor allows remote attackers to run commands on the server
CVE-2026-78211
The GCB Doctor tool from 4MOSAn Security Technology contains a web page that was left in place for testing. Because it does not require any login, an outsider can send specially crafted data to that p...
9.3