Vulnerability Notes
- CVE-2026-13439 - Easy Form Builder by WhiteStudio <= 4.0.11 - Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint
- CVE-2026-63728 - Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
- CVE-2026-64624 - FreeRDP RDP File Parser Remote Code Execution via CLI Options
- CVE-2026-57495 - AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
- CVE-2026-47255 - AgenticMail API/storage and outbound relay hardening
- CVE-2026-47198 - Paymenter: URL parameter injection bypasses paid plan limits at checkout
- CVE-2026-44508 - Rsync: Integer overflow in compressed-token decoding
- CVE-2026-13380 - VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
- CVE-2026-63766 - GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
- CVE-2026-53591 - FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails
- CVE-2026-16337 - dotCMS Improper Authorization and Remote Code Execution
- CVE-2026-64619 - FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
- CVE-2026-63108 - Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
- CVE-2026-61424 - Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
- CVE-2026-60034 - Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0