Common Vulnerabilities and Exposures (CVE)

CVE-2026-50749

Aug 6, 2026 15:27:21 UTC

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on t...

CVE-2026-43622

Aug 6, 2026 15:27:07 UTC

llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap meta...

CVE-2026-68075

Aug 6, 2026 15:26:23 UTC

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which f...

CVE-2025-3193

Aug 6, 2026 15:25:42 UTC

Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error....

CVE-2025-11362

Aug 6, 2026 15:25:29 UTC

Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash ...

CVE-2024-21549

Aug 6, 2026 15:25:17 UTC

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allo...

CVE-2026-65576

Aug 6, 2026 15:24:09 UTC

Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

CVE-2026-65571

Aug 6, 2026 15:23:11 UTC

Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

CVE-2026-65559

Aug 6, 2026 15:22:19 UTC

Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.

CVE-2026-3430

Aug 6, 2026 15:21:18 UTC

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

CVE-2026-65549

Aug 6, 2026 15:20:51 UTC

Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.

CVE-2026-65544

Aug 6, 2026 15:20:11 UTC

Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.

CVE-2026-53985

Aug 6, 2026 15:19:44 UTC

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process ...

CVE-2026-67553

Aug 6, 2026 15:19:37 UTC

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, whic...

CVE-2026-65520

Aug 6, 2026 15:19:31 UTC

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.